Communication method and communication device

By introducing a first key mechanism into the 5G communication system, the security protection problem when terminal equipment communicates directly with other communication nodes in the core network is solved, secure encrypted communication is achieved, the load pressure on the AMF is reduced, and control plane signaling collapse is avoided.

WO2026030857A1PCT designated stage Publication Date: 2026-02-12GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/109872
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-05
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

In 5G communication systems, when terminal devices communicate directly with communication nodes other than the AMF in the core network, there are security protection issues, which can lead to excessive load on the AMF and make it easy for the control plane to crash due to faults.

Method used

A first key mechanism is introduced, which establishes a secure connection between the terminal device and the first communication node in the core network, and uses the first key to encrypt and decrypt information, thereby enabling secure communication between the terminal device and other communication nodes in the core network.

Benefits of technology

It improves the security between terminal equipment and other communication nodes in the core network, reduces the load pressure on the AMF, and avoids the risk of control plane signaling collapse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024109872_12022026_PF_FP_ABST
    Figure CN2024109872_12022026_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a communication method and a communication device. The method comprises: a terminal device generates a first key; and the terminal device performs secure communication with a first communication node in a core network on the basis of the first key, wherein the first communication node is used for discovering other communication nodes in the core network.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication device TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, and more particularly, to a communication method and a communication device. BACKGROUND

[0002] With the development of technology, the application of wireless communication technology is more and more widely. Correspondingly, the communication security problem of wireless communication system has become the focus of attention.

[0003] SUMMARY

[0004] The present application provides a communication method and a communication device. The various aspects involved in the present application are introduced below.

[0005] In a first aspect, a communication method is provided, comprising: a terminal device generating a first key; the terminal device performing secure communication with a first communication node in a core network according to the first key; wherein the first communication node is configured to discover other communication nodes in the core network.

[0006] In a second aspect, a communication method is provided, comprising: a first communication node in a core network obtaining a first key; the first communication node performing secure communication with a terminal device according to the first key; wherein the first communication node is configured to discover other communication nodes in the core network.

[0007] In a third aspect, a communication method is provided, comprising: a fourth communication node in a core network generating a first key, the fourth communication node being configured to authenticate a terminal device, the first key being used for secure communication between a first communication node in the core network and the terminal device, the first communication node being configured to discover other network elements in the core network; the fourth communication node sending the first key and / or an identifier of the first key to the first communication node.

[0008] In a fourth aspect, a communication device is provided, the communication device being a terminal device, the communication device comprising: a generating module configured to generate a first key; a communication module configured to perform secure communication with a first communication node in a core network according to the first key; wherein the first communication node is configured to discover other communication nodes in the core network.

[0009] In a fifth aspect, a communication device is provided, the communication device being a first communication node in a core network, the communication device comprising: an obtaining module configured to obtain a first key; a communication module configured to perform secure communication with a terminal device according to the first key; wherein the first communication node is configured to discover other communication nodes in the core network.

[0010] In a sixth aspect, a communication device is provided, the communication device being a fourth communication node in a core network, the communication device comprising: a generating module configured to generate a first key, the fourth communication node being configured to authenticate a terminal device, the first key being used for secure communication between a first communication node in the core network and the terminal device, the first communication node being configured to discover other network elements in the core network; and a communication module configured to send the first key and / or an identifier of the first key to the first communication node.

[0011] In a seventh aspect, a communication device is provided, comprising a transceiver, a memory and a processor, the memory being configured to store a program, the processor being configured to invoke the program in the memory and control the transceiver to receive or send a signal, so that the communication device performs the method according to the first aspect, the second aspect or the third aspect.

[0012] In an eighth aspect, an apparatus is provided, comprising a processor configured to invoke a program from a memory, so that the apparatus performs the method according to the first aspect, the second aspect or the third aspect.

[0013] In a ninth aspect, a chip is provided, comprising a processor configured to invoke a program from a memory, so that a device installed with the chip performs the method according to the first aspect, the second aspect or the third aspect.

[0014] In a tenth aspect, a computer readable storage medium is provided, having a program stored thereon, the program causing a computer to perform the method according to the first aspect, the second aspect or the third aspect.

[0015] In an eleventh aspect, a computer program product is provided, comprising a program, the program causing a computer to perform the method according to the first aspect, the second aspect or the third aspect.

[0016] In a twelfth aspect, a computer program is provided, the computer program causing a computer to perform the method according to the first aspect, the second aspect or the third aspect.

[0017] Embodiments of the present application introduce a first key, and implement secure communication between a terminal device and a first communication node (used to discover other communication nodes in the core network) based on the first key. BRIEF DESCRIPTION OF DRAWINGS

[0018] FIG. 1 is an example diagram of a system architecture of a wireless communication system to which embodiments of the present application can be applied.

[0019] FIG. 2 is an example diagram of a key acquisition manner provided by the related art.

[0020] FIG. 3 is another example diagram of a key acquisition manner provided by the related art.

[0021] FIG. 4 is another example diagram of a key acquisition method provided by the related art.

[0022] FIG. 5 is another example diagram of a key acquisition method provided by the related art.

[0023] FIG. 6 is a flow diagram of a non-access stratum security mode command (NAS SMC) procedure provided by the related art.

[0024] FIG. 7 is a flow diagram of a communication method provided by an embodiment of the present application.

[0025] FIG. 8 is a flow diagram of a communication method provided by another embodiment of the present application.

[0026] FIG. 9 is an example diagram of a key architecture provided by an embodiment of the present application.

[0027] FIG. 10 is a flow diagram of a communication method provided by another embodiment of the present application.

[0028] FIG. 11 is a flow diagram of a key acquisition method provided by an embodiment of the present application.

[0029] FIG. 12 is an example diagram of a secure communication method provided by an embodiment of the present application.

[0030] FIG. 13 is an example diagram of a secure communication method provided by another embodiment of the present application.

[0031] FIG. 14 is an example diagram of a secure communication method provided by another embodiment of the present application.

[0032] FIG. 15 is an example diagram of a secure communication method provided by another embodiment of the present application.

[0033] FIG. 16 is an example diagram of a secure communication method provided by another embodiment of the present application.

[0034] FIG. 17 is an example diagram of a secure communication method provided by another embodiment of the present application.

[0035] FIG. 18 is an example diagram of a secure communication method provided by another embodiment of the present application.

[0036] FIG. 19 is a structural diagram of a communication device provided by an embodiment of the present application.

[0037] FIG. 20 is a structural diagram of a communication device provided by another embodiment of the present application.

[0038] FIG. 21 is a structural diagram of a communication device provided by another embodiment of the present application.

[0039] FIG. 22 is a diagram of an apparatus to which embodiments of the present application can be applied. Detailed Implementation

[0040] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0041] Wireless communication system

[0042] Figure 1 is a system architecture example diagram of a wireless communication system 100 applicable to embodiments of this application. The wireless communication system 100 may include a network device 110 and a terminal device 120. The network device 110 may be a device that communicates with the terminal device 120. The network device 110 can provide network coverage for a specific geographical area and can communicate with the terminal device 120 located within that coverage area. The terminal device 120 can access a network (such as a wireless network) through the network device 110. Optionally, the wireless communication system 100 may also include other network entities such as a network controller and a mobility management entity; this embodiment of the application does not limit this.

[0043] It should be understood that the technical solutions of the embodiments of this application can be applied to various communication systems, such as 5G systems or new radio (NR), long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc. The technical solutions provided in this application can also be applied to future communication systems, such as sixth-generation mobile communication systems, satellite communication systems, and so on.

[0044] The terminal device in the embodiments of the present application can also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile terminal (MT), a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent or a user apparatus. The terminal device in the embodiments of the present application can refer to a device providing voice and / or data connectivity for a user, and can be used to connect people, things and machines, such as handheld devices with wireless connection function, vehicle-mounted devices, etc. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. Optionally, the terminal device can be used to act as a base station. For example, the terminal device can act as a scheduling entity, which provides sidelink signals between terminal devices in vehicle to everything (V2X) or device to device (D2D), etc. For example, a cellular phone and a car communicate with each other using sidelink signals. The cellular phone and the smart home device communicate with each other without relaying the communication signals through the base station.

[0045] The network device in the embodiments of the present application can be a device for communicating with a terminal device. The network device may, for example, be an access network device or a radio access network device. For example, the network device can be a base station. The base station can broadly cover various names in the following or replace the names in the following: Node B (Node B), evolved Node B (eNB), next generation Node B (gNB), relay station, access point, transmitting and receiving point (TRP), transmitting point (TP), home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof.

[0046] Transport layer security (TLS) connection establishment based on pre-shared key (PSK)

[0047] The authentication and security establishment between the UE and the network application function (NAF) can be based on the TLS 1.3 protocol and the PSK. The index information of the authentication and security establishment process in the standard is shown in the following table. In summary, in the authentication and security establishment process, the shared key can be generated based on the generic bootstrapping architecture (GBA) or the authentication and key management for applications (AKMA).

[0048] The specific process of the PSK-based TLS security establishment can be summarized as the following steps.

[0049] Step one: The client in the UE selects an authentication method and sends a client hello message to the server of the NAF. The message informs the NAF of the authentication method selected by the UE through the PSK-identity name space field. If the UE selects GBA-based authentication, the field can be "3GPP-bootstrapping-uicc", "3GPP-bootstrapping", "3GPP-bootstrapping-digest"; if the UE selects AKMA-based authentication, the field can be "3GPP-AKMA". In addition to this field, the client hello message can also carry the identity of the key. In GBA-based authentication, the identity of the key is the bootstrapping transaction identifier (B-TID); in AKMA-based authentication, the identity of the key is the AKMA key identifier (A-KID).

[0050] Step two: The NAF determines whether to support the authentication method according to local configuration. In the case of supporting the authentication method, the NAF uses the B-TID to ask the BSF for the shared key K NAF between the UE, or uses the A-KID to ask the AKMA anchor function (AAnF) for the shared key K AF between the UE, and returns a Server Hello message to the UE, which contains the index of the PSK identity.

[0051] Step three: The UE and the NAF generate a TLS external PSK based on the shared key, and establish a secure connection between the UE and the NAF based on the key.

[0052] Derivation of the shared key by the UE and the AF in AKMA

[0053] As shown in FIG. 2, after completing the initial authentication, the UE and the AUSF obtain the shared key K AUSF . On this basis, the A-KID, K AUSF , and K AKMA can be derived based on K AKMA . Subsequently, the AUSF sends the A-KID, K AKMA to the AAnF.

[0054] On the basis of the above process, the UE triggers K AF negotiation procedure by sending A-KID to the application function (AF). The AAnF derives K AKMA from K AF and sends it to the AF.

[0055] When deriving K AUSF from K AKMA , the following parameters shall be used as inputs to the key derivation function (KDF):

[0056] FC = 0x80,

[0057] P0 = "AKMA", L0 = length of AKMA, (i.e. 0x00 0x04),

[0058] P1 = user subscription permanent identifier (SUPI), L1 = length of SUPI, the input key shall be K AUSF .

[0059] When deriving K AKMA from K AF , the following parameters shall be used as inputs to the KDF:

[0060] FC = 0x82,

[0061] P0 = AF_ID,

[0062] L0 = length of AF_ID, the input key shall be K AKMA . Where AF_ID = FQDN of the AF || Ua* security protocol identifier.

[0063] KID consists of two parts: a routing indicator (RID) and an A-TID. The RID is included in the SUPI, and the A-TID is calculated as follows: when deriving the A-TID from KAUSF, the following parameters shall be used to form the inputs to the KDF:

[0064] - FC = 0x81;

[0065] - P0 = "A-TID";

[0066] - L0 = length of "A-TID"; (i.e. 0x00 0x05)

[0067] - P1 = SUPI;

[0068] - L1 = length of SUPI;

[0069] The input key should be K AUSF .

[0070] UE and NAF acquire shared key in GBA

[0071] When UE needs to communicate with NAF, it first performs GBA request. Then UE and BSF calculate session key according to GBA mechanism. After successful calculation, UE re-initiates communication request to NAF, and NAF connects BSF to perform authentication. Subsequently, NAF and UE perform secure communication using the key derived from Ks. The flow is shown as follows:

[0072] Step one: UE initiates request to NAF for bootstrap initialization, as shown in FIG. 3.

[0073] Step two: BSF and home subscriber server (HSS) perform secure communication, as shown in FIG. 4. BSF performs AKA authentication procedure with UE by contacting HSS. When the authentication is completed, CK (ciphering key) and IK (integrity key) generated by AKA mechanism are concatenated as shared key.

[0074] Step three: UE initiates application request to NAF using B-TID assigned by BSF and negotiated Ks, as shown in FIG. 5. NAF initiates authentication request to BSF. BSF derives session key for Ua interface communication after successful authentication of UE, and sends it to NAF. Subsequently, NAF and UE perform secure communication.

[0075] NAS SMC procedure

[0076] As shown in FIG. 6, NAS SMC procedure is enabled between UE and access and mobility management function (AMF) based on existing key K AMF . AMF can initiate NAS SMC to UE using K AMF derived from K NAS-int . UE also derives integrity protection key K NAS-int , verifies the message integrity, and initiates encryption and integrity protection for uplink NAS message, and returns NAS SMC complete message to AMF. AMF can derive encryption protection key K NAS- enc . After decrypting the message, AMF verifies the message integrity, and initiates encryption for downlink NAS message.

[0077] In the 5G communication system architecture, the anchor point of the control plane signaling in the network is the AMF. Therefore, the control plane signaling transmitted between the terminal device and the core network needs to be sent to the AMF (such as the control plane signaling related to the session management function and the security establishment process). That is, the terminal device cannot directly communicate with other communication nodes in the core network except the AMF, which leads to an excessive load of the AMF. If the AMF fails, the control plane will collapse. Therefore, a service-based control plane signaling transmission method centered on an address (such as an internet protocol (IP) address, which can be IPv4 or IPv6) can be designed to enable the terminal device to directly communicate with the communication nodes in the core network. In this transmission method, the terminal device can be directly connected to the service-based interface (SBI) bus in the core network, the network will allocate a globally unique address (such as an IPv6 address) to the terminal device for network identification and management of the terminal device, and the interface between the terminal device and the SBI bus can be referred to as the SBI N1 interface. Moreover, the terminal device, the access network node, the access network node and the core network, and the terminal device and the core network can all use address-related protocols for communication. The terminal device can establish an end-to-end connection (such as a transport layer-based end-to-end connection) with other communication nodes (such as the session management function (SMF), the location management function (LMF), and the network data analytics function (NWDAF)) in the network. To this end, the terminal device needs to discover the communication node with which the connection is to be established through a communication node with discovery function (such as the network repository function (NRF) in 5G) in the core network before establishing the connection, and obtain the information of the target communication node selected by the terminal device through the communication node with discovery function. The information of the target communication node can include one or more of the IP address, the fully qualified domain name (FQDN), and the network function (NF) type of the target communication node. Therefore, it is necessary to protect the connection between the terminal device and the communication node with discovery function, and how the terminal device and the communication node with discovery function perform security protection is a problem to be solved.

[0078] To solve the above problems, the embodiments of the present application are described in detail below.

[0079] For ease of understanding, the communication nodes that may be involved in the embodiments below are introduced first. It should be noted that the communication nodes mentioned in the embodiments of the present application can also be referred to as communication entities, network elements or NFs.

[0080] The communication nodes mentioned in the embodiments below mainly include a first communication node, a second communication node, a third communication node and a fourth communication node. The first communication node is a node in the core network, and the first communication node is used to discover other communication nodes in the core network. For example, the first communication node can be used to provide the addresses (such as IP addresses, which can be IPv4 addresses or IPv6 addresses) of other communication nodes in the core network. Exemplarily, the first communication node is an NRF, or the first communication node can also be an NF that performs network element discovery function in a future communication system.

[0081] The second communication node is a node in the core network. The second communication node refers to a communication node requested to be discovered by a terminal device. For example, the terminal device can send request information to the first communication node to request the address (such as IP address) of the second communication node. The embodiments of the present application do not limit the specific type of the second communication node. For example, when the terminal device hopes to perform a positioning service, the address of the LMF can be requested through the first communication node. In this case, the LMF is the second communication node.

[0082] The third communication node is a communication node in the core network that provides an address (such as an IP address) for a terminal device. Before providing the address for the terminal device, the third communication node can first request a server to allocate an address for the terminal device. Taking an IP address as an example, the third communication node can be a dynamic host configuration protocol (DHCP) proxy, and the third communication node can request a DHCP server to allocate an IP address for the terminal device. It should be understood that the third communication node can be an independent communication node, or can be integrated with other communication nodes in the core network. For example, the third communication node can be pre-configured on a node (or an authentication function) in the core network related to the registration or authentication of the terminal device. In this case, the third communication node can be a communication node in the core network for registering or authenticating the terminal device. For example, the third communication node can be an AMF, an authentication server function (AUSF), a security anchor function (SEAF) or a unified data management (UDM).

[0083] The fourth communication node is a communication node in the core network that performs authentication for the terminal device. The fourth communication node may, for example, be an AMF, an AUSF, an SEAF, or a UDM. It is indicated above that the third communication node can be preconfigured on a node in the core network that is related to authentication of the terminal device. In this case, the third communication node and the fourth communication node can refer to the same communication node in the core network.

[0084] The communication method provided by the embodiments of the present application is described in detail below in combination with FIG. 7.

[0085] FIG. 7 is a flowchart of a communication method provided by an embodiment of the present application. The method of FIG. 7 can be performed by a terminal device and a first communication node. Referring to FIG. 7, in step S710, the terminal device generates a first key. The first key is used for secure communication with the first communication node. The first key can be a shared key (such as a pre-shared key) between the terminal device and the first communication node. The first key may, for example, be a symmetric key. Taking the first communication node as an NRF for example, the first key can be expressed as K NRF The generation process of the first key will be described in detail below in combination with specific embodiments, which will not be described here in detail.

[0086] In step S720, the terminal device performs secure communication with the first communication node according to the first key. For example, the terminal device can directly use the first key to encrypt or decrypt messages transmitted between the terminal device and the first communication node. For another example, the terminal device can first establish a secure connection with the first communication node based on the first key, and then perform communication with the first communication node based on the secure connection. As mentioned above, the first communication node can be used to discover other communication nodes in the core network. The discovery process of the other communication nodes can be performed after the terminal device establishes the secure connection with the first communication node, or the discovery process of the other communication nodes can be performed in the process of establishing the secure connection. Details can be referred to the embodiments below.

[0087] The embodiments of the present application introduce the first key, which can be used for the terminal device and the first communication node to perform secure communication, thereby effectively protecting the information transmitted between the terminal device and the first communication node.

[0088] The embodiments of the present application do not make specific limitations on the acquisition manner of the first key. In some implementations, the first key can be acquired based on the traditional AKMA mechanism. Alternatively, the first key can also be acquired based on the traditional GBA mechanism. The key acquisition manner of the AKMA mechanism and the GBA mechanism can be referred to the description above.

[0089] In some implementations, the first key can be acquired or determined based on an authentication procedure (or primary authentication) between the terminal device and the core network. For example, the first key can be derived directly based on a key between the terminal device and an authentication node (AMF, AUSF, UDM or SEAF) in the core network, which can be derived based on a root key of the terminal device. Deriving the first key directly based on the key between the terminal device and the authentication node in the core network can simplify the acquisition procedure of the first key. The key acquisition manner is illustrated in more details below from the perspective of the terminal device and the first communication node respectively.

[0090] Acquiring the first key by the terminal device

[0091] Referring to FIG. 8, at step S810, the terminal device receives a second message sent by a third communication node in the core network (the third communication node is introduced above). The second message can contain an address of the terminal device and / or an address of the first communication node. That is, the second message can be used to provide the address of the terminal device and / or the address of the first communication node. The second message can be a NAS message. In some implementations, the second message can be secured, so as to avoid the address of the terminal device and / or the address of the first communication node from being leaked. Exemplarily, the second message can be secured in a conventional protection manner of a downlink message, for example, the second message can be secured in a protection manner of a NAS downlink message.

[0092] At step S820, after receiving the second message, the terminal device can generate the first key. The first key can be generated based on one or more of the following information: the second key, the identity of the terminal device, the address of the terminal device, and the information of the first communication node.

[0093] In some embodiments, the first key can be generated or derived based on the second key. The second key can refer to a key between the terminal device and a node in the core network for mobility management. For example, the node in the core network for mobility management is AMF, and the second key can be K AMF . Alternatively, the second key can refer to a key between the terminal device and an authentication node in the core network for authenticating the terminal device (i.e., the first communication node mentioned above). The authentication node can be, for example, AMF, AUSF, UDM or SEAF. Accordingly, the second key can be K AMF , K AUSF , K UDM or K SEAF . Alternatively, the second key can refer to a key between the terminal device and a node in the core network for securing the terminal device. For example, the node in the core network for security can be SEAF, and the second key can be K SEAF .

[0094] In some embodiments, the first key can be generated or derived based on an identity of the terminal device. The identity of the terminal device can be, for example, a SUPI, a globally unique temporary identity (GUTI), or a subscription concealed identifier (SUCI).

[0095] In some embodiments, the first key can be generated or derived based on an address of the terminal device. The address of the terminal device can be an IP address or a MAC address of the terminal device. For example, the address of the terminal device refers to an IPv6 address or an IPv4 address of the terminal device.

[0096] In some embodiments, the first key can be determined based on information of the first communication node. The information of the first communication node can include one or more of an identity of the first communication node, a name of the first communication node, and an address of the first communication node. Taking the first communication node as an NRF for example, the first key can be determined based on an identity (or indication) of the NRF and / or the string “NRF”.

[0097] As an example, the first key is K NRF , the K NRF may adopt a first key architecture shown in the left part of FIG. 9, or a second key architecture shown in the right part of FIG. 9. In the above two key architectures, K represents a root key of the terminal device, CK represents a derived encryption key based on K, and IK represents a derived integrity protection key based on K. The difference between the above two key architectures lies in the generation manner of K NRF . In the key architecture of the left part of FIG. 9, K NRF is generated by a key K AUSF , and the communication node generating K NRF may be, for example, a UDM or an AUSF. In the right part of FIG. 9, K NRF is generated by a key K SEAF , and the communication node generating K NRF may be a SEAF.

[0098] On the basis of defining the above key architecture, the first key can be generated based on the following manner:

[0099] 1. input a key; K AUSF , K SEAF , or K AMF ;

[0100] 2. input parameters (at least containing the following parts):

[0101] - FC = 0xXX (FC code)

[0102] -P0 = identity of the terminal device

[0103] -L0 = length of P0 (number of bytes contained by P0)

[0104] -P1 = IP address of the terminal device

[0105] -L1 = length of P1 (number of bytes contained by P1)

[0106] -P2 = indication information of the NRF (e.g. identity of the NRF)

[0107] -L2 = length of P2 (number of bytes contained by P2)

[0108] -P3 = "NRF"

[0109] -L3 = length of P3 (number of bytes contained by P3)

[0110] After obtaining the above parameters, the first key can be generated based on the above parameters through a KDF function.

[0111] After receiving the second message, the terminal device can also generate an identity of the first key. The identity of the first key can be generated based on one or more of the following information: the second key, the identity of the terminal device, the address of the terminal device, and the information of the first communication node.

[0112] In some embodiments, the identity of the first key can be generated or derived based on the second key. The second key can refer to a key between the terminal device and a node in the core network for mobility management. For example, the node in the core network for mobility management is an AMF, and the second key can be K AMF . Alternatively, the second key can refer to a key between the terminal device and an authentication node in the core network for authenticating the terminal device (i.e. the first communication node mentioned above). The authentication node can be, for example, an AMF, an AUSF, a UDM, or a SEAF. Accordingly, the second key can be K AMF , K AUSF , K UDM , or K SEAF . Alternatively, the second key can refer to a key between the terminal device and a node in the core network for security protection of the terminal device. For example, the node in the core network for security protection can be a SEAF, and the second key can be K SEAF .

[0113] In some embodiments, the identity of the first key can be generated or derived based on the identity of the terminal device. The identity of the terminal device can be, for example, a SUPI, a GUTI, or a SUCI.

[0114] In some embodiments, the identity of the first key can be generated or derived based on an address of the terminal device. The address of the terminal device can be an IP address or a MAC address of the terminal device. For example, the address of the terminal device refers to an IPv6 address or an IPv4 address of the terminal device.

[0115] In some embodiments, the identity of the first key can be determined based on information of the first communication node. The information of the first communication node can include one or more of an identity of the first communication node, a name of the first communication node, and an address of the first communication node. For example, the first communication node is an NRF, then the identity of the first key can be determined based on the identity (or indication) of the NRF and / or the string "NRF".

[0116] As an example, the identity of the first key can be generated based on the following way:

[0117] 1. Input a key; K AUSF , K SEAF , or K AMF ;

[0118] 2. Input parameters (at least containing the following parts):

[0119] - FC = 0xXX (FC code)

[0120] - P0 = identity of the terminal device

[0121] - L0 = length of P0 (number of bytes contained in P0)

[0122] - P1 = IP address of the terminal device

[0123] - L1 = length of P1 (number of bytes contained in P1)

[0124] - P2 = indication information of the NRF (such as the identity of the NRF)

[0125] - L2 = length of P2 (number of bytes contained in P2)

[0126] - P3 = "NRF"

[0127] - L3 = length of P3 (number of bytes contained in P3)

[0128] After obtaining the above parameters, the identity of the first key can be generated based on the above parameters through a KDF function.

[0129] In some implementations, the identity of the first key can comprise routing information (routing info or RID) of the home network or routing information of the serving network. In this way, the first communication node (e.g., the NRF) can find the relevant network element to retrieve the key according to the routing information in the identity of the first key.

[0130] In the above-described implementations, the terminal device generates the first key after receiving the address of the terminal device and / or the information of the first communication node. In other implementations, the terminal device can first negotiate with the core network whether to perform control plane signaling transmission based on the address. If the terminal device determines to perform control plane signaling transmission based on the address, the terminal device generates the first key.

[0131] Before performing step S810, the terminal device can first perform authentication with the core network. That is, after the terminal device completes authentication (or authentication succeeds), the terminal device obtains the address of the terminal device and / or the address of the first communication node through the second message. Then, the terminal device generates the first key.

[0132] The first communication node obtains the first key

[0133] Referring to FIG. 10, at step S1010, the fourth communication node (an authentication node in the core network, and details of the fourth communication node can be found in the foregoing) generates the first key. Next, at step S1020, the fourth communication node sends the first key and / or the identity of the first key to the first communication node.

[0134] The first key mentioned in step S1010 can be generated based on one or more of the following information: the second key, the identity of the terminal device, the address of the terminal device, and the information of the first communication node.

[0135] In some embodiments, the first key can be generated or derived based on a second key. The second key can refer to a key between the terminal device and a node in the core network for mobility management. For example, the node in the core network for mobility management is an AMF, and the second key can be K AMF . Alternatively, the second key can refer to a key between the terminal device and an authentication node in the core network for authenticating the terminal device (i.e., the first communication node mentioned in the foregoing). The authentication node can be, for example, an AMF, an AUSF, a UDM, or a SEAF. Accordingly, the second key can be K AMF , K AUSF , K UDM , or K SEAF . Alternatively, the second key can refer to a key between the terminal device and a node in the core network for security protection of the terminal device. For example, the node in the core network for security protection can be a SEAF, and the second key can be KSEAF .

[0136] In some embodiments, the first key can be generated or derived based on an identity of the terminal device. The identity of the terminal device can be, for example, a SUPI, a GUTI, or a SUCI.

[0137] In some embodiments, the first key can be generated or derived based on an address of the terminal device. The address of the terminal device can be an IP address or a MAC address of the terminal device. For example, the address of the terminal device refers to an IPv6 address or an IPv4 address of the terminal device.

[0138] In some embodiments, the first key can be determined based on information of the first communication node. The information of the first communication node can include one or more of an identity of the first communication node, a name of the first communication node, and an address of the first communication node. Taking the first communication node as an NRF for example, the first key can be determined based on an identity (or indication) of the NRF and / or the string “NRF”.

[0139] As an example, the first key is K NRF , the K NRF may adopt the first key architecture shown in the left diagram of FIG. 9, or the second key architecture shown in the right diagram of FIG. 9. In the above two key architectures, K represents a root key of the terminal device, CK represents an encryption key, and IK represents an integrity protection key. The difference between the above two key architectures lies in the generation manner of K NRF . In the key architecture of the left diagram of FIG. 9, K NRF is generated from the key K AUSF . In the right diagram of FIG. 9, K NRF is generated from the key K SEAF .

[0140] On the basis of defining the above key architecture, the first key can be generated based on the following manner:

[0141] 1. input a key; K AUSF , K SEAF , or K AMF ;

[0142] 2. input parameters (at least containing the following parts):

[0143] - FC = 0xXX (FC code)

[0144] - P0 = identity of the terminal device

[0145] - L0 = length of P0 (number of bytes contained in P0)

[0146] - P1 = IP address of the terminal device

[0147] - L1 = length of P1 (number of bytes P1 contains)

[0148] - P2 = indication information of NRF (e.g. identity of NRF)

[0149] - L2 = length of P2 (number of bytes P2 contains)

[0150] - P3 = "NRF"

[0151] - L3 = length of P3 (number of bytes P3 contains)

[0152] After obtaining the above parameters, the first key can be generated based on the above parameters through a KDF function.

[0153] After receiving the second message, the terminal device can further generate an identity of the first key. The identity of the first key can be generated based on one or more of the following information: the second key, the identity of the terminal device, the address of the terminal device, and the information of the first communication node.

[0154] In some embodiments, the identity of the first key can be generated or derived based on the second key. The second key can refer to a key between the terminal device and a node in the core network for mobility management. For example, the node in the core network for mobility management is an AMF, and the second key can be K AMF . Alternatively, the second key can refer to a key between the terminal device and an authentication node (i.e. the first communication node mentioned above) in the core network for authenticating the terminal device. The authentication node can be an AMF, an AUSF, a UDM, or a SEAF, for example. Accordingly, the second key can be K AMF , K AUSF , K UDM , or K SEAF . Alternatively, the second key can refer to a key between the terminal device and a node in the core network for security protection of the terminal device. For example, the node in the core network for security protection can be a SEAF, and the second key can be K SEAF .

[0155] In some embodiments, the identity of the first key can be generated or derived based on the identity of the terminal device. The identity of the terminal device can be a SUPI, a GUTI, or a SUCI, for example.

[0156] In some embodiments, the identity of the first key can be generated or derived based on the address of the terminal device. The address of the terminal device can be an IP address or a MAC address of the terminal device. For example, the address of the terminal device refers to an IPv6 address or an IPv4 address of the terminal device.

[0157] In some embodiments, the identity of the first key can be determined based on information of the first communication node. The information of the first communication node can comprise one or more of an identity of the first communication node, a name of the first communication node, an address of the first communication node. Take the example of the first communication node being an NRF, the identity of the first key can be determined based on an identity (or indication) of the NRF and / or the string "NRF".

[0158] As an example, the identity of the first key can be generated based on the following way:

[0159] 1. Input key; K AUSF , K SEAF , or K AMF ;

[0160] 2. Input parameters (at least containing the following parts):

[0161] - FC = 0xXX (FC code)

[0162] - P0 = identity of the terminal device

[0163] - L0 = length of P0 (number of bytes contained in P0)

[0164] - P1 = IP address of the terminal device

[0165] - L1 = length of P1 (number of bytes contained in P1)

[0166] - P2 = indication information of the NRF (such as identity of the NRF)

[0167] - L2 = length of P2 (number of bytes contained in P2)

[0168] - P3 = "NRF"

[0169] - L3 = length of P3 (number of bytes contained in P3)

[0170] After obtaining the above parameters, the identity of the first key can be generated based on the above parameters through a KDF function.

[0171] In some implementations, the identity of the first key can comprise routing information (routing info or RID) of the home network or routing information of the serving network. In this way, the first communication node (such as the NRF) can find the relevant network element to obtain the key according to the routing information in the identity of the first key.

[0172] The embodiments of the present application do not specifically limit the timing of the fourth communication node generating the first key. For example, the fourth communication node can first send third request information to a fifth communication node (which can refer to the third communication node (such as a DHCP proxy) mentioned above, and when the network function provided by the third communication node is pre-configured on the fourth communication node, the fifth communication node can also refer to a DHCP server). The third request information is used to request the address of the terminal device. Then, the fourth communication node can receive third response information (i.e. response information of the third request information) sent by the fifth communication node. The third response information contains the address of the terminal device. After receiving the address of the terminal device, the fourth communication node can generate and send the first key and / or the identifier of the first key to the first communication node.

[0173] The third request information mentioned above can include one or more of the following: an identifier of the terminal device, third information (used to indicate that the terminal device has completed authentication (or authentication is successful)).

[0174] In addition to generating the first key after receiving the address of the terminal device, the fourth communication node can also select other timing to generate the first key. For example, the fourth communication node can generate the first key after determining that the terminal device transmits control plane signaling based on the address.

[0175] The above describes in detail the way of obtaining the first key from the perspective of the terminal device and the first communication node respectively. Next, taking the terminal device as UE, the first communication node as NRF, and the fourth communication node as an authentication node in the core network as an example, a more specific example of obtaining the first key is given in combination with FIG. 11. In the example of FIG. 11, the UE can generate a key K NRF and / or an identifier of the key based on the negotiation result (the negotiation result of whether to transmit control plane signaling based on the address) or based on the received address of the terminal device or information of the NRF.

[0176] Referring to FIG. 11, at step S1102, the UE performs authentication in an authentication phase. In this phase, the UE is authenticated with the network. The communication node on the network side performing the authentication can include AUSF, UDM, SEAF, etc.

[0177] At step S1104, the authentication node sends the UE ID and an indication of the end of authentication to the DHCP proxy to trigger the DHCP proxy to perform the acquisition of the UE IP address. Alternatively, the DHCP proxy can be pre-configured on the communication node related to the UE registration and authentication process. For example, the DHCP proxy can be pre-configured on the AUSF of the home network or the SEAF of the serving network.

[0178] At step S1106, the DHCP proxy sends an IP address request to the DHCP server. The DHCP proxy queries whether an IP address has been allocated for the UE, and if an IP address has been allocated, there is no need to allocate an IP address again.

[0179] At step S1108, the DHCP server queries an unallocated IP address, and returns the IP address to the DHCP proxy.

[0180] At step S1110a, the DHCP proxy returns an IP address configuration response of the UE to the authentication node, to trigger the authentication node to generate a shared key (corresponding to the first key in the foregoing) between the NRF and the UE. Alternatively, when the DHCP is an AUSF, the AUSF can generate a key according to the shared key K AUSF between the UE and the NRF, for the NRF.

[0181] At step S1110b, the DHCP proxy sends a message to the UE, which can contain the IP address of the UE and / or information of the NRF (such as the identity and / or address of the NRF). The message can use a conventional downlink message protection manner, for example, the message can be protected using a protection manner of a NAS downlink message.

[0182] At step S1112, after receiving the IP address of the UE, the UE generates a shared key K NRF between the NRF and the UE, and can generate an identity of the key. Alternatively, after the UE and the network negotiate whether to use IP address-based control plane signaling transmission, the UE generates a key K NRF between the NRF and the UE according to the negotiation result.

[0183] At step S1114, the authentication node generates a shared key K NRF between the NRF and the UE.

[0184] At step S1116, the authentication node sends the UE ID, the UE IP address, and the key K NRF to the NRF.

[0185] At step S1118, the NRF stores the key and / or the key identity, for protecting communication with the UE.

[0186] It is mentioned in the foregoing that the first key can be used to establish a secure connection between the terminal device and the first communication node. The secure connection can be established in various manners. For example, the first key can be used to establish a secure connection at a transport layer. For another example, the first key can be used to establish a secure connection at a NAS. The manner of establishing the secure connection will be described in more detail in combination with Embodiment One and Embodiment Two.

[0187] Embodiment One: The first key is used to establish a secure transport layer connection with the first communication node

[0188] The secure transport layer connection mentioned in Embodiment One may, for example, be a TLS connection. Further, in some embodiments, the first key can be used to derive a TLS external PSK or a session key in TLS.

[0189] In the process of establishing the secure transport layer connection, the terminal device sends a first message to the first communication node first. Then, the first communication node sends a response message of the first message to the terminal device. After receiving the response message of the first message, the terminal device can establish a transport layer connection with the first communication node.

[0190] Taking a PSK-based authentication mode as an example, the first message mentioned above can be a client hello message; and the response message of the first message can be a server hello message.

[0191] In some implementations, the first message can contain one or more of the following information: first information, an identifier of the first key, an identifier of the terminal device, and an address of the terminal device. The first information is used to indicate an authentication mode selected by the terminal device.

[0192] Further, in some implementations, the authentication mode indicated by the first information can be an AKMA-based authentication mode or a GBA-based authentication mode.

[0193] Alternatively, in other implementations, the authentication mode indicated by the first information can be an authentication mode provided by embodiments of the present application. The authentication mode provided by embodiments of the present application can be referred to as a first authentication mode, which can be based on the first key mentioned above for authentication, and in the first authentication mode, the first key is determined based on an authentication procedure (main authentication) between the terminal device and the core network. For example, the first key can be directly derived based on a key between the terminal device and an authentication node of the core network. As a more specific example, assuming that the authentication mode of the terminal device is a PSK-based authentication mode, the first message can contain a PSK-identity name space, which can carry the first information (such as 3GPP-AKA) indicating that the terminal device adopts the first authentication mode described above.

[0194] If the first key has not been acquired by the first communication node, the first communication node can acquire the first key before sending the response message to the terminal device in response to the first message. If the first information indicates that the authentication is performed using the AKMA mechanism, the first communication node can acquire the first key from the AAnF. If the first information indicates that the authentication is performed using the GBA mechanism, the first communication node can acquire the first key from the BSF. If the first information indicates that the authentication is performed using the first authentication mode mentioned above, the first communication node can send second request information to the fourth communication node. The second request information can be used to request the first key. When sending the second request information to the fourth communication node (an authentication node in the core network for authenticating the terminal device), one or more of the following can be carried in the second request information: an identifier of the first key, an identifier of the terminal device, and an address of the terminal device, so that the fourth communication node identifies the terminal device and returns the correct key to the terminal device.

[0195] As mentioned above, the first communication node is configured to discover other communication nodes in the core network. For example, in a positioning service, the terminal device can discover a positioning service node in the core network through the first communication node, and thus obtain the positioning service. In some implementations, the terminal device can send first request information to the first communication node after establishing a secure transport layer connection with the first communication node, to request discovery of a second communication node in the core network (e.g., to obtain an address of the second communication node). The discovery process of the communication nodes is performed after the secure connection is established, and the modification to the secure establishment process is small.

[0196] In some implementations, the terminal device can also perform the discovery process of the communication nodes to discover the second communication node (e.g., to obtain an address of the second communication node) during the process of establishing a secure transport layer connection with the first communication node. For example, the terminal device can carry the first request information in the first information mentioned above, to request discovery of a second communication node in the core network (e.g., to obtain an address of the second communication node). Accordingly, the first communication node can carry first response information for the first request information in the response message of the first message, and carry the address of the second communication node through the first response information. Performing the discovery process of the communication nodes during the process of establishing a secure connection can simplify the communication process and improve the communication efficiency.

[0197] Two more specific examples are given below, taking the terminal device as UE and the first communication node as NRF as an example, in combination with FIG. 12 and FIG. 13. In the example of FIG. 12, the discovery process of other communication nodes between the UE and the NRF is performed after the secure connection is established, and in the example of FIG. 13, the UE performs the discovery process of other communication nodes during the process of establishing a secure connection with the NRF.

[0198] Example 1: A secure transport layer connection is first established between the UE and the NRF, and then the NF discovery request is transmitted.

[0199] Before executing the process shown in Figure 12, the UE and NRF can store a shared key K. NRF Alternatively, if the NRF does not store the shared key K NRF Then the NRF can request the shared key K from the authentication node. NRF .

[0200] Referring to Figure 12, in step S1202, the UE selects PSK-based authentication. The UE sends a client hello message to the NRF, which includes a PSK-identity namespace field. The value of this field is 3GPP-AKA, indicating that the UE has selected PSK as the authentication method. Furthermore, this authentication method is based on the key K generated from the UE's primary authentication and root key. NRF To perform authentication, the request may contain a key identifier (Key ID).

[0201] In step S1204, the NRF selects PSK-based authentication based on its local configuration and the authentication method chosen by the UE. If the NRF has not obtained the key K before this step... NRF Then the NRF can request key K from the authentication node. NRF The authentication node generates key K. NRF The method can be seen in the description of Figure 11. When requesting key K from the authentication node... NRF At this time, the request may carry one or more of the following information: Key ID, UE ID, UE IP address, etc. Of course, if the UE selects AKMA authentication method, the NRF requests the key K from the ANRF. NRF If the UE selects GBA as the authentication method, the NRF requests key K from the BSF. NRF .

[0202] In step S1206, the NRF returns a server hello message to the UE. This message contains the PSK identity index, indicating that the UE has selected PSK as its authentication method.

[0203] In step S1208, the UE and NRF communicate based on key K. NRF Establish a TLS connection. NRF It can be used to derive TLS external PSK or session key in TLS security.

[0204] At step S1210, the UE sends an NF discovery request to the AN node. The NF discovery request is used to request discovery of other NFs (corresponding to the second communication node in the foregoing).

[0205] At step S1212, the AN node forwards the NF discovery request to the NRF.

[0206] At step S1214, the NRF sends an NF discovery response to the AN node. The NF discovery response contains the address of the other NFs.

[0207] At step S1216, the AN node forwards the NF discovery response to the UE.

[0208] Example Two: UE and NRF perform NF discovery procedure in the process of establishing a secure transport layer connection

[0209] In Example Two, the UE can carry an encrypted / integrity-protected NF discovery request in a client hello message using a key K NRF . Similarly, the NRF can also carry an encrypted / integrity-protected NF discovery response in a server hello message using the key K NRF .

[0210] Before performing the procedure of FIG. 13, the UE and the NRF can have stored a shared key K NRF . Alternatively, if the NRF does not store the shared key K NRF , the NRF can request the shared key K NRF from an authentication node.

[0211] Referring to FIG. 13, at step S1302, the UE selects PSK-based authentication. The UE sends a client hello message to the NRF, which contains a PSK-identity name space field. The value of the field is 3GPP-AKA, indicating that the authentication method selected by the UE is PSK. Moreover, the authentication method is based on the key K NRF generated from the root key of the primary authentication of the UE, and the request can contain a key identity Key ID. Further, the client hello message also carries an NF discovery request, which is used to request discovery of other NFs (corresponding to the second communication node in the foregoing). The NF discovery request can be integrity-protected and / or encrypted based on K NRF .

[0212] At step S1304, the NRF selects PSK-based authentication according to local configuration and the authentication method selected by the UE. If the NRF has not obtained the key K NRF beforehand, the NRF can request the key K NRF from an authentication node.The authentication node generates a key K NRF The description of FIG. 11 can be referred to. When requesting the key K NRF from the authentication node, the request can carry one or more of the following information: key identity Key ID, UE ID, UE IP address, etc. Of course, if the authentication mode selected by the UE is AKMA, the NRF requests the key K NRF from the AAnF; if the authentication mode selected by the UE is GBA, the NRF requests the key K NRF from the BSF.

[0213] In step S1306, the NRF returns a server hello message to the UE. The message contains the index of the PSK identity, indicating that the authentication mode selected by the UE is PSK. Further, the server hello message can carry an NF discovery response. The NF discovery response can be based on K NRF .

[0214] In step S1308, the UE and the NRF establish a TLS connection based on the key K NRF . K NRF may be used to derive a TLS external PSK in TLS security, or a session key.

[0215] Embodiment two: the first key is used to establish a secure NAS connection with the first communication node

[0216] The terminal device can establish a secure NAS connection with the first communication node based on the NAS SMC procedure. An example of the establishment process of the secure NAS connection is given below in conjunction with FIG. 14.

[0217] Referring to FIG. 14, in step S1410, the first communication node sends a NAS SMC message to the terminal device. The NAS SMC message can carry one or more of the following information: the identity of the terminal device, the address of the terminal device, and the second information. The second information mentioned here can be used to indicate that the NAS SMC message is a message transmitted between the terminal device and the first communication node. Taking the first communication node as the NRF for example, the second information can indicate that the NAS SMC message is an indication on NRF-NAS sent by the NRF.

[0218] Before sending the NAS SMC message, the first communication node can first enable integrity protection of the downlink message, and use the first key or an integrity protection key derived based on the first key to perform integrity protection on the NAS SMC message.

[0219] At step S1420, the terminal device verifies the integrity of the NAS SMC message according to the first key. The terminal device can verify the integrity of the NAS SMC message using the first key or an integrity protection key derived from the first key.

[0220] At step S1430, in response to the verification of the NAS SMC message being passed, the terminal device sends a NAS SMC complete message to the first communication node. Before the terminal device sends the NAS SMC complete message to the first communication node, the terminal device can first enable the encryption and / or integrity protection of the uplink message. The integrity protection can be implemented based on the first key or an integrity protection key derived from the first key, and the encryption can be implemented based on the first key or an encryption key derived from the first key.

[0221] Based on the flow shown in FIG. 14, a secure NAS connection can be established between the terminal device and the first communication node, so as to protect the information transmitted between the terminal device and the first communication node.

[0222] In some implementations, after receiving the NAS SMC complete message, the first communication node can enable the encryption protection of the downlink message, which can be implemented based on the first key or an encryption key derived from the first key.

[0223] In some implementations, after the secure NAS connection is established with the first communication node, the terminal device can send first request information to the first communication node to request discovery of a second communication node in the core network (e.g., to obtain the address of the second communication node). The discovery process of the communication node is performed after the secure connection is established, which has less impact on the secure establishment process. In other implementations, the terminal device can perform the discovery process of the communication node to discover the second communication node (e.g., to obtain the address of the second communication node) during the establishment of the secure NAS connection with the first communication node. For example, the first communication node can carry the address of the second communication node in the aforementioned NAS SMC message. Alternatively, the terminal device can include the first request information in the NAS SMC complete message to request the address of the second communication node in the core network. Performing the discovery process of the communication node during the establishment of the secure connection can simplify the communication process and improve the communication efficiency.

[0224] Two more specific examples are given below with the terminal device being a UE and the first communication node being an NRF, in combination with FIG. 15 and FIG. 16. In the example of FIG. 15, the discovery process of the related other communication node between the UE and the NRF is performed after the establishment of the secure connection, and in the example of FIG. 16, the discovery process of the related other communication node is performed during the establishment of the secure connection between the UE and the NRF.

[0225] Example 1: UE performs NAS SMC with NRF first to establish NAS security, then performs NF discovery

[0226] Before performing the flow of FIG. 15, the shared key K NRF may be stored between the UE and the NRF. NRF Alternatively, if the shared key K NRF is not stored in the NRF, the NRF can request the shared key K NRF from an authentication node.

[0227] At step S1502, the NRF enables integrity protection for downlink messages. The integrity protection can be based on the key K NRF , or based on an integrity protection key K NRF derived from K NRF-int .

[0228] At step S1504, the NRF sends a NAS SMC to the UE. The NAS SMC contains the UE ID, the UE IP address, and an indication that the SMC is between the NRF and the UE.

[0229] At step S1506, the UE enables encryption and integrity protection for uplink messages after successfully verifying the integrity of the message. The encryption and integrity protection can be based on the key K NRF . Alternatively, the integrity protection and encryption can also be based on an integrity protection key K NRF and an encryption key K NRF-int derived from K NRF-enc .

[0230] At step S1508, the UE returns a NAS SMC complete message to the NRF.

[0231] At step S1510, the NRF verifies the integrity of the message and enables encryption protection for downlink messages. The encryption protection can be based on the key K NRF . Alternatively, the encryption protection can be based on an encryption key K NRF derived from K NRF-enc .

[0232] At step S1512, the UE sends a NF discovery request to the AN node. The NF discovery request is used to request discovery of other NFs (corresponding to the second communication node in the foregoing).

[0233] At step S1514, the AN node forwards the NF discovery request to the NRF.

[0234] At step S1516, the NFR sends a NF discovery response to the AN node. The NF discovery response contains the addresses of the other NFs.

[0235] At step S1518, the AN node forwards the NF discovery response to the UE.

[0236] Example Two: UE and NRF perform NF discovery in NAS SMC procedure

[0237] The difference between this example two and example one is that, after the integrity protection is turned on, the NRF can use the NAS SMC message to transmit the IP addresses of certain NFs to the UE. Alternatively, the UE can include a NF discovery request in the NAS SMC complete message, which can be encrypted and integrity protected; upon receiving the message, the NRF can use a downlink message to return a NF discovery response message to the UE.

[0238] Before performing the procedure of FIG. 16, the UE and the NRF can have stored a shared key K NRF Alternatively, if the NRF does not store the shared key K NRF , the NRF can request the shared key K NRF from the authentication node.

[0239] At step S1602, the NRF turns on the integrity protection of the downlink message. The integrity protection can be based on the key K NRF , or an integrity protection key K NRF derived from K NRF-int .

[0240] At step S1604, the NRF sends a NAS SMC to the UE. The NAS SMC includes the UE ID, the UE IP address, and an indication that the SMC is between the NRF and the UE. Further, the NAS SMC can include the IP addresses of certain NFs.

[0241] At step S1606, the UE turns on the encryption and integrity protection of the uplink message after successfully verifying the integrity of the message. The encryption and integrity protection can be based on the key K NRF . Alternatively, the integrity protection and encryption can also be based on an integrity protection key K NRF and an encryption key K NRF-int derived from K NRF-enc .

[0242] At step S1608, the UE returns a NAS SMC complete message to the NRF. The NAS SMC complete message can carry a NF discovery request. The NAS SMC complete message can be an encrypted and / or integrity protected message.

[0243] At step S1610, the NRF verifies the integrity of the message and turns on the encryption protection of the downlink message. The encryption protection can be based on the key K NRFimplementation. Alternatively, the encryption protection can be based on a key K NRF derived encryption key K NRF-enc implementation. If the step S1608 contains the NF discovery request, the NRF can return the NF discovery response message to the UE using a downlink message to return the IP address of the NF that the terminal device expects to discover.

[0244] The foregoing describes in detail the establishment process of the secure connection in combination with Embodiment One and Embodiment Two. In some embodiments, the terminal device and the first communication node can also not establish a secure connection, but directly use the first key for secure communication. For example, the terminal device can directly use the first key to perform the discovery process of the communication node with the first communication node, which can greatly simplify the communication process and improve the communication efficiency. The following describes in detail this embodiment in combination with FIG. 17.

[0245] Referring to FIG. 17, in step S1710, the terminal device sends first request information to the first communication node. The first request information is encrypted based on the first key (or a key derived from the first key). The first request information is used to request the address of the second communication node in the core network. For example, the first request information can be carried by a NAS container, and the NAS container is encrypted based on the first key (or a key derived from the first key). In step S1720, after receiving the first request information, the first communication node sends first response information to the terminal device. The first response information is encrypted based on the first key, and the first response information contains the address of the second communication node. For example, the first response information can be carried by a NAS container, and the NAS container is encrypted based on the first key (or a key derived from the first key).

[0246] FIG. 18 takes the terminal device as UE and the first communication node as NRF as an example to give a more specific implementation of FIG. 17. In the example of FIG. 18, the UE and the NRF transmit the messages and parameters related to the NF discovery (such as the IP address, FQDN, type of the NF to be discovered) between each other. The example of FIG. 18 directly uses the shared key K NRF The above messages and parameters are encrypted and integrity-protected, without performing the NAS SMC process. Alternatively, the transmission of the messages between the UE and the NRF can also be relayed through a mobility management node (MM-NF in FIG. 18), which is similar to the traditional implementation of relaying the signaling through the AMF, except that the K NRF The end-to-end protection is enabled.

[0247] The foregoing describes in detail how the terminal device and the first communication node achieve secure communication. After introducing the address-based control plane signaling transmission, the terminal device and other communication nodes (such as the second communication node discovered through the NRF) other than the first communication node can also establish a direct connection. The terminal device and the other communication nodes can establish a secure connection based on the GBA mechanism or the AKMA mechanism. Unlike the traditional GBA or AKMA mechanism, the AF in the AKMA process or the NAF in the GBA process needs to be replaced by the communication node that wants to establish a secure connection.

[0248] It should be understood that the address mentioned in each of the foregoing embodiments can refer to an IP address (such as an IPv4 address or an IPv6 address) or a MAC address.

[0249] The foregoing describes in detail the method embodiments of the present application in combination with FIGS. 1 to 18, and the following describes in detail the device embodiments of the present application in combination with FIGS. 19 to 22. It should be understood that the description of the method embodiments corresponds to the description of the device embodiments, and therefore, the parts not described in detail can be referred to the foregoing method embodiments.

[0250] FIG. 19 is a structural schematic diagram of a communication device provided by an embodiment of the present application. The communication device 1900 shown in FIG. 19 can be the terminal device mentioned in the foregoing. The communication device 1900 includes a generation module 1910 and a communication module 1920. The generation module 1910 is configured to generate a first key. The communication module 1920 is configured to perform secure communication with a first communication node in a core network according to the first key. The first communication node is configured to discover other communication nodes in the core network.

[0251] In some implementations, the first key is used to establish a secure transport layer connection with the first communication node.

[0252] In some implementations, the communication module 1920 is configured to: send a first message to the first communication node; and establish the transport layer connection with the first communication node after receiving a response message to the first message, wherein the first message contains one or more of the following information: first information, the first information being used to indicate an authentication mode selected by the terminal device; an identifier of the first key; an identifier of the terminal device; and an address of the terminal device.

[0253] In some implementations, the first information is used to indicate that the authentication mode selected by the terminal device is a first authentication mode, the first authentication mode is based on the first key for authentication, and the first key is determined based on an authentication process between the terminal device and the core network.

[0254] In some embodiments, the first message is a client hello message; and / or, the response message of the first message is a server hello message.

[0255] In some embodiments, the communication module 1920 is further configured to: after the establishment of the transport layer connection is completed, send first request information to the first communication node, the first request information being used for requesting an address of a second communication node in a core network.

[0256] In some embodiments, the first message comprises first request information, the first request information being used for requesting an address of a second communication node in a core network.

[0257] In some embodiments, the response message of the first message carries first response information, the first response information comprising the address of the second communication node.

[0258] In some embodiments, the transport layer connection is a TLS connection.

[0259] In some embodiments, the first key is used to establish a secure NAS connection with the first communication node.

[0260] In some embodiments, the communication module 1920 is configured to: receive a NAS SMC message sent by the first communication node; verify the integrity of the NAS SMC message according to the first key; and in response to the verification of the NAS SMC message being passed, send a NAS SMC complete message to the first communication node.

[0261] In some embodiments, the NAS SMC message comprises one or more of the following information: an identifier of the terminal device; an address of the terminal device; second information used to indicate that the NAS SMC message is a message transmitted between the terminal device and the first communication node.

[0262] In some embodiments, the communication module 1920 is further configured to: after the terminal device sends the NAS SMC complete message, send first request information to the first communication node, the first request information being used for requesting an address of a second communication node in a core network.

[0263] In some embodiments, the NAS SMC message comprises an address of a second communication node in a core network.

[0264] In some embodiments, the NAS SMC complete message comprises first request information, the first request information being used for requesting an address of a second communication node in a core network.

[0265] In some embodiments, the communication module 1920 is configured to: send first request information to the first communication node, the first request information being encrypted based on the first key, and the first request information being used to request an address of a second communication node in the core network; and receive first response information from the first communication node, the first response information being encrypted based on the first key, and the first response information containing the address of the second communication node.

[0266] In some embodiments, the first request information and / or the first response information is carried in a NAS container, and the first key is used to encrypt the NAS container.

[0267] In some embodiments, the generation module 1910 is configured to: receive a second message sent by a third communication node in the core network, the second message containing an address of the terminal device and / or an address of the first communication node; and generate the first key after receiving the second message.

[0268] In some embodiments, the generation module 1910 is configured to: generate the first key if the terminal device determines to control a control plane signaling transmission based on an address.

[0269] In some embodiments, the communication device 1900 further includes an authentication module configured to perform authentication with the core network before the terminal device generates the first key.

[0270] In some embodiments, the first key is generated based on one or more of: a second key; an identifier of the terminal device; an address of the terminal device; information of the first communication node; wherein the second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and an authentication node in the core network for authenticating the terminal device, or a key between the terminal device and a node in the core network for security protection of the terminal device.

[0271] In some embodiments, the first key is generated based on one or more of: a second key; an identifier of the terminal device; an address of the terminal device; information of the first communication node; wherein the second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and an authentication node in the core network for authenticating the terminal device, or a key between the terminal device and a node in the core network for security protection of the terminal device.

[0272] In some embodiments, the identifier of the first key includes routing information of a home network or routing information of a serving network.

[0273] FIG. 20 is a schematic diagram of a structure of a communication device according to another embodiment of the present application. The communication device 2000 shown in FIG. 20 can be the first communication node mentioned above. The communication device 2000 includes an obtaining module 2010 and a communication module 2020. The obtaining module 2010 is configured to obtain a first key. The communication module 2020 is configured to perform secure communication with a terminal device according to the first key. The first communication node is configured to discover other communication nodes in the core network.

[0274] In some embodiments, the first key is used to establish a secure transport layer connection with the terminal device.

[0275] In some embodiments, the communication module 2020 is configured to receive a first message sent by the terminal device, and establish the transport layer connection with the terminal device after sending a response message to the terminal device in response to the first message. The first message contains one or more of the following information: first information indicating an authentication mode selected by the terminal device, an identifier of the first key, an identifier of the terminal device, and an address of the terminal device.

[0276] In some embodiments, the first information indicates that the authentication mode selected by the terminal device is a first authentication mode, the first authentication mode is based on the first key, and the first key is determined based on an authentication procedure between the terminal device and the core network.

[0277] In some embodiments, the first message is a client hello message, and / or the response message of the first message is a server hello message.

[0278] In some embodiments, the communication module 2020 is further configured to receive first request information sent by the terminal device after the transport layer connection is established, the first request information being used to request an address of a second communication node in the core network.

[0279] In some embodiments, the first message contains first request information, the first request information being used to request an address of a second communication node in the core network.

[0280] In some embodiments, the response message of the first message carries first response information, the first response information containing the address of the second communication node.

[0281] In some embodiments, the communication module 2020 is further configured to send second request information to a fourth communication node before sending the response message of the first message to the terminal device, the second request information being used to request the first key.

[0282] In some embodiments, the second request information comprises one or more of: an identity of the first key; an identity of the terminal device; an address of the terminal device.

[0283] In some embodiments, the fourth communication node is an authentication node, AAnF or BSF in a core network for authenticating the terminal device.

[0284] In some embodiments, the authentication node is an AMF, AUSF, UDM or SEAF.

[0285] In some embodiments, the transport layer connection is a TLS connection.

[0286] In some embodiments, the first key is used to establish a secure NAS connection with the first communication node.

[0287] In some embodiments, the communication module 2020 is configured to: send, to the terminal device, a NAS SMC message, wherein the NAS SMC message is integrity protected based on the first key; and after the first communication node receives a NAS SMC complete message sent by the terminal device, verify the integrity of the NAS SMC complete message according to the first key.

[0288] In some embodiments, the NAS SMC message comprises one or more of: an identity of the terminal device; an address of the terminal device; second information indicating that the NAS SMC message is a message transmitted between the terminal device and the first communication node.

[0289] In some embodiments, the communication module 2020 is further configured to: after receiving the NAS SMC complete message sent by the terminal device, receive first request information sent by the terminal device, the first request information being used to request an address of a second communication node in a core network.

[0290] In some embodiments, the NAS SMC message comprises an address of a second communication node in a core network.

[0291] In some embodiments, the NAS SMC complete message comprises first request information, the first request information being used to request an address of a second communication node in a core network.

[0292] In some embodiments, the communication module 2020 is configured to: receive first request information sent by the terminal device, the first request information being encrypted based on the first key, and the first request information being used to request an address of a second communication node in the core network; and send first response information to the terminal device, the first response information being encrypted based on the first key, and the first response information containing the address of the second communication node.

[0293] In some embodiments, the first request information and / or the first response information is carried in a NAS container, and the first key is used to encrypt the NAS container.

[0294] In some embodiments, the first key is generated based on one or more of the following: a second key; an identifier of the terminal device; an address of the terminal device; information of the first communication node; wherein the second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and an authentication node in the core network for authenticating the terminal device, or a key between the terminal device and a node in the core network for security protection of the terminal device.

[0295] In some embodiments, the first key is generated based on one or more of the following: a second key; an identifier of the terminal device; an address of the terminal device; information of the first communication node; wherein the second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and an authentication node in the core network for authenticating the terminal device, or a key between the terminal device and a node in the core network for security protection of the terminal device.

[0296] In some embodiments, the identifier of the first key comprises routing information of a home network or routing information of a serving network.

[0297] FIG. 21 is a structural schematic diagram of a communication device according to another embodiment of the present application. The communication device 2100 shown in FIG. 21 can be the fourth communication node mentioned above. The communication device 2100 comprises a generating module 2110 and a communication module 2120. The generating module 2110 is configured to generate a first key, the fourth communication node is configured to authenticate a terminal device, and the first key is used for secure communication between a first communication node in the core network and the terminal device, and the first communication node is configured to discover other network elements in the core network. The communication module 2120 is configured to send the first key and / or an identifier of the first key to the first communication node.

[0298] In some embodiments, the generating module 2110 is configured to: send third request information to the fifth communication node, the third request information being used to request an address of the terminal device; receive third response information, the third response information comprising the address of the terminal device; and generate the first key after receiving the third response information.

[0299] In some embodiments, the third request information comprises one or more of the following: an identifier of the terminal device; third information used to indicate that the terminal device has completed authentication.

[0300] In some embodiments, the generating module 2110 is configured to: if it is determined that the terminal device controls transmission of control plane signaling based on an address, generate the first key.

[0301] In some embodiments, the fourth communication node is an AMF, an AUSF, a UDM, or an SEAF.

[0302] In some embodiments, the first key is generated based on one or more of the following: a second key; an identifier of the terminal device; an address of the terminal device; information of the first communication node; wherein the second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and the fourth communication node, or a key between the terminal device and a node in the core network for security protection of the terminal device.

[0303] In some embodiments, the identifier of the first key is generated based on one or more of the following: a second key; an identifier of the terminal device; an address of the terminal device; information of the first communication node; wherein the second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and the fourth communication node, or a key between the terminal device and a node in the core network for security protection of the terminal device.

[0304] In some embodiments, the identifier of the first key comprises routing information of a home network or routing information of a serving network.

[0305] FIG. 22 is a schematic structural diagram of a communication apparatus to which embodiments of the present application can be applied. The dashed line in FIG. 22 indicates that the unit or module is optional. The apparatus 2200 can be used to implement the methods described in the above method embodiments. The apparatus 2200 can be a chip, a terminal device, or a network device.

[0306] The apparatus 2200 can include one or more processors 2210. The processor 2210 can support the apparatus 2200 to implement the methods described in the foregoing method embodiments. The processor 2210 can be a general purpose processor or a dedicated processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, etc. The general purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0307] The apparatus 2200 can also include one or more memories 2220. The memory 2220 stores programs, which can be executed by the processor 2210, so that the processor 2210 performs the methods described in the foregoing method embodiments. The memory 2220 can be independent of the processor 2210 or integrated in the processor 2210.

[0308] The apparatus 2200 can also include a transceiver 2230. The processor 2210 can communicate with other devices or chips through the transceiver 2230. For example, the processor 2210 can perform data transceiving with other devices or chips through the transceiver 2230.

[0309] The embodiments of the present application also provide a computer readable storage medium for storing programs. The computer readable storage medium can be applied to the terminal device or the network device provided by the embodiments of the present application, and the programs make the computer execute the methods performed by the communication device in the embodiments of the present application.

[0310] The embodiments of the present application also provide a computer program product. The computer program product includes programs. The computer program product can be applied to the terminal device or the network device provided by the embodiments of the present application, and the programs make the computer execute the methods performed by the communication device in the embodiments of the present application.

[0311] The embodiments of the present application also provide a computer program. The computer program can be applied to the terminal device or the network device provided by the embodiments of the present application, and the computer program makes the computer execute the methods performed by the communication device in the embodiments of the present application.

[0312] It should be understood that the terms "system" and "network" can be used interchangeably in this application. In addition, the terms used in this application are only used to explain the specific embodiments of the application, and are not intended to limit the application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of the application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.

[0313] In embodiments of the present application, the term "indicate" can be direct indication or indirect indication, or can represent an associated relationship. For example, A indicates B, which can mean that B can be obtained by A; or A indirectly indicates B, for example, A indicates C, and B can be obtained by C; or A and B have an associated relationship.

[0314] In embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0315] In embodiments of the present application, the term "corresponding" can represent a direct or indirect corresponding relationship between the two, or can represent an associated relationship between the two, or can represent an indication and being indicated, configuration and being configured, and the like.

[0316] In embodiments of the present application, "predefined" or "preconfigured" can be achieved by pre-saving corresponding codes, tables or other information that can be used to indicate related information in devices (such as terminal devices and network devices), and the specific implementation of the present application is not limited. For example, predefinition can refer to definition in a protocol.

[0317] In embodiments of the present application, the "protocol" can refer to a standard protocol in the communication field, which can include LTE protocol, NR protocol and related protocols applied to future communication systems, and the present application is not limited thereto.

[0318] In embodiments of the present application, the term "and / or" is only used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean that A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents an "or" relationship between the front and rear associated objects.

[0319] In various embodiments of the present application, the size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0320] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the division of the above-described device embodiments is only a logical function division, and there can be another division manner for actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or between the different components, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0321] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.

[0322] In addition, each functional unit in the various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.

[0323] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server, data center and the like integrated with one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)) or semiconductor media (for example, solid state disk (SSD)) and the like.

[0324] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method characterized by comprising: The method comprises: a terminal device generating a first key; the terminal device performing secure communication with a first communication node in a core network according to the first key; wherein the first communication node is configured to discover other communication nodes in the core network.

2. The method of claim 1, wherein, the first key is used to establish a secure transport layer connection with the first communication node.

3. The method of claim 2, wherein, the terminal device performing secure communication with a first communication node in a core network according to the first key comprises: the terminal device sending a first message to the first communication node; after receiving a response message to the first message, the terminal device establishes the transport layer connection with the first communication node; wherein the first message contains one or more of the following information: first information, the first information being used to indicate an authentication mode selected by the terminal device; an identifier of the first key; an identifier of the terminal device; an address of the terminal device.

4. The method of claim 3, wherein, the first information is used to indicate that the authentication mode selected by the terminal device is a first authentication mode, the first authentication mode is based on the first key for authentication, and the first key is determined based on an authentication procedure between the terminal device and the core network.

5. The method according to claim 3 or 4, characterized in that, the first message is a client hello message; and / or, the response message of the first message is a server hello message.

6. The method according to any one of claims 3 to 5, characterized in that, The method further comprises: after the transport layer connection is established, the terminal device sends first request information to the first communication node, the first request information being used to request an address of a second communication node in the core network.

7. The method according to any one of claims 3 to 5, characterized in that, the first message contains first request information, the first request information being used to request an address of a second communication node in the core network.

8. The method of claim 7, wherein, the response message of the first message carries first response information, the first response information containing the address of the second communication node.

9. The method according to any one of claims 2 to 8, characterized in that, the transport layer connection is a transport layer security (TLS) connection.

10. The method of claim 1, wherein, the first key is used to establish a secure non-access stratum (NAS) connection with the first communication node.

11. The method of claim 10, wherein, the terminal device performing secure communication with a first communication node in a core network according to the first key comprises: the terminal device receiving a NAS security mode command (SMC) message sent by the first communication node; the terminal device verifying the integrity of the NAS SMC message according to the first key; in response to the verification of the NAS SMC message being passed, the terminal device sends a NAS SMC complete message to the first communication node.

12. The method of claim 11, wherein, the NAS SMC message contains one or more of the following information: an identifier of the terminal device; an address of the terminal device; second information, the second information being used to indicate that the NAS SMC message is a message transmitted between the terminal device and the first communication node.

13. The method according to claim 11 or 12, characterized in that, The method further comprises: after sending the NAS SMC complete message, the terminal device sends first request information to the first communication node, the first request information being used to request an address of a second communication node in the core network.

14. The method of claim 11 or 12, wherein, the NAS SMC message contains an address of a second communication node in the core network.

15. The method of claim 11 or 12, wherein, The NAS SMC complete message comprises first request information, the first request information being used to request an address of a second communication node in the core network.

16. The method of claim 1, wherein, The terminal device performs secure communication with a first communication node in the core network according to the first key, comprising: The terminal device sends first request information to the first communication node, the first request information being encrypted based on the first key, and the first request information being used to request an address of a second communication node in the core network; The terminal device receives first response information from the first communication node, the first response information being encrypted based on the first key, and the first response information comprising the address of the second communication node.

17. The method of claim 16, wherein, The first request information and / or the first response information are carried in a NAS container, and the first key is used to encrypt the NAS container.

18. The method of any one of claims 1 to 17, wherein, The terminal device generates a first key, comprising: The terminal device receives a second message sent by a third communication node in the core network, the second message comprising an address of the terminal device and / or an address of the first communication node; After receiving the second message, the terminal device generates the first key.

19. The method of any one of claims 1 to 17, wherein, The terminal device generates a first key, comprising: If the terminal device determines to perform control plane signaling transmission based on an address, the terminal device generates the first key.

20. The method of any one of claims 1 to 19, wherein, Before the terminal device generates a first key, the method further comprises: The terminal device performs authentication with the core network.

21. The method of any one of claims 1 to 20, wherein, The first key is generated based on one or more of the following: A second key; An identity of the terminal device; An address of the terminal device; Information of the first communication node; The second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and an authentication node in the core network for authenticating the terminal device, or a key between the terminal device and a node in the core network for security protection of the terminal device.

22. The method of any one of claims 1 to 21, wherein, An identity of the first key is generated based on one or more of the following: A second key; An identity of the terminal device; An address of the terminal device; Information of the first communication node; The second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and an authentication node in the core network for authenticating the terminal device, or a key between the terminal device and a node in the core network for security protection of the terminal device.

23. The method of claim 22, wherein, The identity of the first key comprises routing information of a home network or routing information of a serving network.

24. A method of communication, comprising: Comprising: A first communication node in the core network acquires a first key; The first communication node performs secure communication with a terminal device according to the first key; The first communication node is used to discover other communication nodes in the core network.

25. The method of claim 24, wherein, The first key is used to establish a secure transport layer connection with the terminal device.

26. The method of claim 25, wherein, The first communication node performs secure communication with a terminal device according to the first key, comprising: The first communication node performs secure communication with a terminal device according to the first key, comprising: The first communication node receives the first message sent by the terminal device; After sending the response message to the terminal device, the first communication node establishes the transport layer connection with the terminal device; The first message contains one or more of the following information: The first information is used to indicate the authentication mode selected by the terminal device; The identity of the first key; The identity of the terminal device; The address of the terminal device.

27. The method of claim 26, wherein, The first information is used to indicate that the authentication mode selected by the terminal device is a first authentication mode, the first authentication mode is based on the first key, and the first key is determined based on the authentication process between the terminal device and the core network.

28. The method of claim 26 or 27, wherein, The first message is a client hello message; and / or, the response message of the first message is a server hello message.

29. The method of any one of claims 26-28, wherein, The method further comprises: After the transport layer connection is established, the first communication node receives the first request information sent by the terminal device, and the first request information is used to request the address of the second communication node in the core network.

30. The method of any one of claims 26-28, wherein, The first message contains the first request information, and the first request information is used to request the address of the second communication node in the core network.

31. The method of claim 30, wherein, The first response information is carried in the response message of the first message, and the first response information contains the address of the second communication node.

32. The method of any one of claims 26-31, wherein, The method further comprises: Before sending the response message of the first message to the terminal device, the first communication node sends the second request information to the fourth communication node, and the second request information is used to request the first key.

33. The method of claim 32, wherein, The second request information contains one or more of the following: The identity of the first key; The identity of the terminal device; The address of the terminal device.

34. The method of claim 32 or 33, wherein, The fourth communication node is an authentication node in the core network for authenticating the terminal device, an authentication and key management anchor function AAnF or a bootstrap service function BSF.

35. The method of claim 34, wherein, The authentication node is an access and mobility management function AMF, an authentication service function AUSF, a unified data management UDM or a security anchor function SEAF.

36. The method of any one of claims 25-35, wherein, The transport layer connection is a transport layer security TLS connection.

37. The method of claim 24, wherein, The first key is used to establish a secure non-access layer NAS connection with the first communication node.

38. The method of claim 37, wherein, The first communication node securely communicates with the terminal device according to the first key, including: The first communication node sends a NAS security mode command SMC message to the terminal device, wherein the NAS SMC message is integrity protected based on the first key; After the first communication node receives the NAS SMC completion message sent by the terminal device, the integrity of the NAS SMC completion message is verified according to the first key.

39. The method of claim 38, wherein, The NAS SMC message contains one or more of the following information: The identity of the terminal device; The address of the terminal device; The second information is used to indicate that the NAS SMC message is a message transmitted between the terminal device and the first communication node.

40. The method of claim 38 or 39, wherein, The method further comprises: After receiving the NAS SMC completion message sent by the terminal device, the first communication node receives first request information sent by the terminal device, the first request information being used for requesting an address of a second communication node in the core network.

41. The method of claim 38 or 39, wherein, The NAS SMC message comprises the address of the second communication node in the core network.

42. The method of claim 38 or 39, wherein, The NAS SMC completion message comprises first request information, the first request information being used for requesting an address of a second communication node in the core network.

43. The method of claim 24, wherein, The first communication node performs secure communication with the terminal device according to the first key, comprising: The first communication node receives first request information sent by the terminal device, the first request information being encrypted based on the first key, and the first request information being used for requesting an address of a second communication node in the core network; The first communication node sends first response information to the terminal device, the first response information being encrypted based on the first key, and the first response information comprising the address of the second communication node.

44. The method of claim 43, wherein, The first request information and / or the first response information are carried in a NAS container, and the first key is used for encrypting the NAS container.

45. The method of any one of claims 24-44, wherein, The first key is generated based on one or more of the following: A second key; An identity of the terminal device; An address of the terminal device; Information of the first communication node; The second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and an authentication node in the core network for authenticating the terminal device, or a key between the terminal device and a node in the core network for security protection of the terminal device.

46. The method of any one of claims 24-45, wherein, The identity of the first key is generated based on one or more of the following: A second key; An identity of the terminal device; An address of the terminal device; Information of the first communication node; The second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and an authentication node in the core network for authenticating the terminal device, or a key between the terminal device and a node in the core network for security protection of the terminal device.

47. The method of claim 46, wherein, The identity of the first key comprises routing information of a home network or routing information of a serving network.

48. A method of communication, the method comprising: Comprising: A fourth communication node in the core network generates a first key, the fourth communication node being used for authenticating a terminal device, the first key being used for secure communication between a first communication node in the core network and the terminal device, the first communication node being used for discovering other network elements in the core network; The fourth communication node sends the first key and / or an identity of the first key to the first communication node.

49. The method of claim 48, wherein, The fourth communication node in the core network generates a first key, comprising: The fourth communication node sends third request information to a fifth communication node, the third request information being used for requesting an address of the terminal device; The fourth communication node receives third response information, the third response information comprising the address of the terminal device; After receiving the third response information, the fourth communication node generates the first key.

50. The method of claim 49, wherein, The third request information comprises one or more of: an identifier of the terminal device; third information indicating that the terminal device has completed authentication.

51. The method of claim 48, wherein, The fourth communication node in the core network generates a first key, comprising: If it is determined that the terminal device controls transmission of control plane signaling based on an address, the fourth communication node generates the first key.

52. The method of any one of claims 48-51, wherein, The fourth communication node is an access and mobility management function (AMF), an authentication service function (AUSF), a unified data management (UDM), or a security anchor function (SEAF).

53. The method of any one of claims 48-52, wherein, The first key is generated based on one or more of: a second key; an identifier of the terminal device; an address of the terminal device; information of the first communication node; wherein the second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and the fourth communication node, or a key between the terminal device and a node in the core network for security protection of the terminal device.

54. The method of any one of claims 48-53, wherein, The identifier of the first key is generated based on one or more of: a second key; an identifier of the terminal device; an address of the terminal device; information of the first communication node; wherein the second key is a key between the terminal device and a node in the core network for mobility management, a key between the terminal device and the fourth communication node, or a key between the terminal device and a node in the core network for security protection of the terminal device.

55. The method of claim 54, wherein, The identifier of the first key comprises routing information of a home network or routing information of a serving network.

56. A communications device, characterized by The communication device is a terminal device, and the communication device comprises: a generating module configured to generate a first key; a communication module configured to perform secure communication with a first communication node in a core network according to the first key; wherein the first communication node is configured to discover other communication nodes in the core network.

57. A communications device, characterized by The communication device is a first communication node in a core network, and the communication device comprises: an obtaining module configured to obtain a first key; a communication module configured to perform secure communication with a terminal device according to the first key; wherein the first communication node is configured to discover other communication nodes in the core network.

58. A communications device, characterized by The communication device is a fourth communication node in a core network, and the communication device comprises: a generating module configured to generate a first key, the fourth communication node being configured to authenticate a terminal device, the first key being used for secure communication between a first communication node in the core network and the terminal device, the first communication node being configured to discover other network elements in the core network; a communication module configured to send the first key and / or an identifier of the first key to the first communication node.

59. A communications device, characterized by The communication device comprises a transceiver, a memory, and a processor, the memory being configured to store a program, the processor being configured to invoke the program in the memory and control the transceiver to receive or send signals, so that the communication device performs the method in any one of claims 1 to 55.

Citation Information

Patent Citations

  • Key management method, device and system

    CN113676901A

  • Communication method and communication device

    CN116074827A

  • Method and apparatus for establishing secure communication

    US20230232228A1

  • Communication method, communication apparatus and communication system

    WO2023246649A1