Communication method and communication apparatus

By including the task identifier in the communication request and generating a security context, the problem of task-granular security protection in 5G systems is solved, and task-granular security protection and signaling security verification are simplified.

WO2026036950A1PCT designated stage Publication Date: 2026-02-19HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/104818
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-15
Filing Date
2025-06-27
Publication Date
2026-02-19

AI Technical Summary

Technical Problem

In existing 5G systems, once a secure connection is established between the terminal device and the AMF, task-level security protection cannot be achieved, and effective security protection cannot be provided for the processes of different tasks.

Method used

By including the task identifier in the communication request, security protection of signaling is generated and used based on the task identifier, including integrity protection of the task identifier using message authentication codes, and negotiation or acquisition of the security context of network elements when necessary to achieve task-level security protection.

Benefits of technology

It achieves security protection for different tasks, improves the transmission security of task identifiers, reduces the latency of security verification, and simplifies the security protection process of signaling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025104818_19022026_PF_FP_ABST
    Figure CN2025104818_19022026_PF_FP_ABST
Patent Text Reader

Abstract

A communication method, comprising: a first communication apparatus sending to a first network element a first request message for requesting execution of a first task, the first request message comprising an identifier of the first task; and receiving a first response message from the first network element in response to the first request message, wherein the first response message undergoes security protection on the basis of a first security context, and the first security context is determined on the basis of the identifier of the first task. The first security context is determined on the basis of the identifier of the first task, meaning that during execution of the first task, a security context for security protection of signaling associated with the first task is determined on the basis of the identifier of the first task, thereby implementing security protection at a task granularity.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication apparatus

[0001] The present application claims priority to the Chinese patent application No. 202411124061.9, filed on August 15, 2024, entitled "Communication method and communication apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication, and more particularly, to a communication method and a communication apparatus. BACKGROUND

[0003] The fifth-generation (5G) system architecture includes two parts of an access network and a core network. Messages that are not processed by the access node are called non-access layer messages, such as messages sent by a terminal device to a subsequent node through a wireless access node. The terminal device transmits the non-access layer messages to the access and mobility management function (AMF) in the 5G core network, and the terminal device transmits other types of non-access layer messages to the AMF through the access network first, and then routes them to other network functions (NFs) through the AMF. Therefore, the current protocol defines a non-access layer security connection establishment process for the security connection establishment between the terminal device and the AMF.

[0004] Under the premise of establishing a security connection between the terminal device and the AMF, the terminal device can establish communication between the AMF and other core network elements, and can protect the process of establishing communication between the terminal device and other core network elements based on the security context negotiated with the AMF. However, this security protection method cannot independently protect different tasks requested by the terminal device to perform, such as the process of requesting to establish different protocol data unit (PDU) sessions. Therefore, how to achieve task granularity security protection in the task execution process has become a problem to be solved. SUMMARY

[0005] The present application provides a communication method, which realizes task granularity security protection in the task execution process.

[0006] In a first aspect, a communication method is provided. The method can be performed by a first communication apparatus. In the present disclosure, the first communication apparatus can refer to the first communication device itself (e.g., a terminal device), a component in the first communication device (e.g., a processor, a chip, or a chip system, such as a circuit or a chip responsible for communication functions in a terminal device (e.g., a Modem chip, also known as a baseband chip, or a system on chip (SoC) chip or a system in package (SIP) chip containing a modem core)), or a logic module or software capable of implementing all or part of the functions of the first communication device. For ease of description, the first communication apparatus is taken as an example in the following description.

[0007] The communication method includes: sending a first request message to a first network element, the first request message being used to request to perform a first task, and the first request message including an identifier of the first task; and receiving a first response message from the first network element in response to the first request message, the first response message being secured based on a first security context, and the first security context being determined based on the identifier of the first task.

[0008] Based on the above technical solution, when the first communication apparatus has a demand to perform the first task, the first communication apparatus can send the first request message to the first network element, which is a network element providing a service related to the first task. This solution can be understood as follows: in the process of performing the first task, the security context for securing the signaling related to the first task is determined based on the identifier of the first task, thereby achieving security protection at the task granularity. For example, different tasks can be protected by different security contexts.

[0009] In a possible design, before the first request message is sent to the first network element, the method further includes: generating the identifier of the first task.

[0010] In another possible design, the first request message further includes security information, the security information being determined based on a second security context, and the security information being used to secure the identifier of the first task.

[0011] Based on the above technical solution, the first request message sent by the first communication apparatus includes security information used to secure the identifier of the first task, thereby improving the security in the transmission of the identifier of the first task.

[0012] In yet another possible design, the security information used to secure the identifier of the first task includes that the security information is used to secure the first request message.

[0013] Based on the technical solution, the security information can protect the identity of the first task by protecting the first request message carrying the identity of the first task, thereby improving the security of the transmission of other information in the first request message.

[0014] In another possible design, the security information includes a message authentication code (MAC).

[0015] Based on the technical solution, the security information can be a MAC, i.e., the security information is used for integrity protection of the identity of the first task, and the receiver of the first request message can perform integrity check. In addition, integrity protection of the identity of the first task can prevent tampering of the identity of the first task by an attacker, thereby ensuring the correctness and integrity of the identity of the first task.

[0016] In another possible design, the second security context is different from the first security context, and after receiving the first response message from the first network element in response to the first request message, the method further includes: determining the first security context based on the identity of the first task and the second security context, where the first security context is used for security protection and / or security verification of signaling related to the first task.

[0017] Based on the technical solution, the first communication device determines the second security context based on the third security context and the identity of the first task before sending the first request message, so that the identity of the first task can be protected based on the second security context. In addition, the first communication device has generated the second security context based on the identity of the first task before sending the first request message, and can directly perform security protection and / or security verification of signaling related to the first task based on the second security context, without generating the second security context based on the identity of the first task after receiving the first response message to perform security verification on the first response message, thereby reducing the time delay of security verification.

[0018] In another possible design, the second security context is different from the first security context, and after receiving the first response message from the first network element in response to the first request message, the method further includes: determining the first security context based on the identity of the first task and the second security context, where the first security context is used for security protection and / or security verification of signaling related to the first task.

[0019] Based on the technical solution, the first communication device can generate the first security context based on the identity of the first task after receiving the first response message, and perform security verification on the first response message based on the first security context, while the first request message can be secured based on the second security context.

[0020] In yet another possible design, the method further includes: sending a second request message to the first network element, the second request message being used to request establishment of a first non-access stratum (NAS) connection between the first communication device and the first network element, and the second request message including the identity of the first communication device; and receiving a second response message from the first network element, the second response message being used to negotiate determination of a security context of the first NAS connection, wherein the third security context or the second security context is determined based on the security context of the first NAS connection.

[0021] Based on the technical solution, the first network element and the first communication device first generate a security context of a first NAS connection, and then generate a first security context required for protecting the execution of the first task based on the security context of the first NAS connection, and the security context of the first NAS connection and the first security context can be mastered by the first network element. When the first network element needs the security context to perform security protection and / or security verification on the signaling related to the first task, the corresponding security context can be directly obtained, without the need to obtain it from other network elements, thereby simplifying the process of performing security protection and / or security verification on the signaling related to the first task.

[0022] In yet another possible design, the method further includes: sending a third request message to the security network element, the third request message being used to request establishment of a second NAS connection between the first communication device and the security network element, and the third request message including the identity of the first communication device; and receiving a third response message from the security network element, the third response message being used to negotiate determination of a security context of the second NAS connection, wherein the third security context or the second security context is determined based on the security context of the second NAS connection.

[0023] Based on the technical solution, the security network element and the first communication device generate a security context of a second NAS connection, and generate a first security context required for performing a first task based on the security context of the second NAS connection. When the first network element needs to perform security protection and / or security verification on signaling related to the first task, the first network element can obtain the corresponding security context from the security network element. In this technical solution, the association between the first task and the first network element can be avoided to be exposed due to the generation of the security context. For example, the first network element does not need to generate the first security context based on the identifier of the first task, and therefore the first task whether is served by the first network element or the first communication device does not need to be known.

[0024] In another possible design, the method further includes: receiving first indication information from the security network element, the first indication information being used to indicate a first algorithm; and determining a fourth security context based on the first algorithm and the security context of the second NAS connection, wherein the third security context or the second security context is determined based on the fourth security context.

[0025] Based on the technical solution, the first communication device can determine a fourth security context based on the obtained security context of the second NAS connection and the first algorithm indicated by the first indication information, and the fourth security context is used to determine the third security context or the second security context. That is, the first communication device can use the key derived based on the security context of the second NAS connection to perform security protection and / or security verification on the signaling related to the first task, instead of directly performing security protection and / or security verification based on the security context of the second NAS connection, so as to avoid overuse of the security context of the second NAS connection and reduce security.

[0026] In another possible design, the determining the fourth security context based on the first algorithm and the security context of the second NAS connection includes: determining the fourth security context based on the first algorithm, the security context of the second NAS connection, and second indication information, wherein the second indication information is used to indicate a type of the first task.

[0027] Based on the technical solution, the first communication device can consider the type of the first task when determining the fourth security context, so that the generated fourth security context is related to the type of the task.

[0028] In another possible design, the first task includes any one of the following: establishing a protocol data unit (PDU) session, a sensing service, or an artificial intelligence (AI) service.

[0029] In yet another possible design, the first network element includes any one of the following: a session management function (SMF), a perception function network element, a data analytics function network element, an analytics logic function network element, or a model training logic function network element.

[0030] In a second aspect, a communication method is provided. The method can be performed by a first network element. In the absence of a special description, the "first network element" in the present application can refer to the first network element itself (e.g., an SMF, a perception function network element, a data analytics function network element, an analytics logic function network element, or a model training logic function network element, etc.), a component (e.g., a processor, a chip, or a chip system, etc.) in the first network element, or a logic module or software capable of implementing all or part of the functions of the first network element. For ease of description, the following description is made by way of example with the first network element performing.

[0031] The communication method includes: receiving a first request message from a first communication device, the first request message being used to request to perform a first task, the first request message including an identification of the first task; and sending, to the first communication device, a first response message in response to the first request message, the first response message being secured based on a first security context, the first security context being determined based on the identification of the first task.

[0032] In one possible design, the first request message further includes security information, the security information being determined based on a second security context, and the security information being used to secure the identification of the first task.

[0033] In another possible design, the security information is used to secure the identification of the first task, including that the security information is used to secure the first request message.

[0034] In yet another possible design, the security information includes a message authentication code (MAC).

[0035] In yet another possible design, the method further includes: sending a fourth request message, the fourth request message being used to request to obtain the first security context, the fourth request message including the identification of the first task; and receiving a fourth response message, the fourth response message including the first security context.

[0036] Based on the technical solution, the first network element can obtain the first security context from other network elements, that is, when the first network element needs to protect and / or verify the signaling related to the first task by using the security context, the first network element can obtain the corresponding security context from the security network element. In the technical solution, the association between the first task and the first network element can be avoided to be exposed due to the generation of the security context. For example, in the technical solution, the first network element does not need to generate the first security context based on the identifier of the first task, and thus whether the first task is served by the first network element to the first communication device does not need to be known.

[0037] In yet another possible design, the method further includes: sending a fifth request message, where the fifth request message is used to request security verification of the first request message; and receiving a fifth response message, where the fifth response message is used to indicate a security verification result of the first request message.

[0038] Based on the technical solution, the first network element can request other network elements to perform security verification on the first request message, without performing security verification on the first request message by itself, that is, when the first network element needs to perform security verification on the signaling related to the first task by using the security context, the first network element can request other network elements. In the technical solution, the association between the first task and the first network element can be avoided to be exposed due to the generation of the security context. For example, in the technical solution, the first network element does not need to generate the first security context based on the identifier of the first task, and thus whether the first task is served by the first network element to the first communication device does not need to be known.

[0039] In yet another possible design, the fourth request message further includes second indication information, where the second indication information is used to indicate a type of the first task.

[0040] Based on the technical solution, when the first network element requests to obtain the first security context from other network elements, the first network element can carry the second indication information indicating the type of the first task in the request message, so as to obtain the security context matched with the first task.

[0041] In yet another possible design, the method further includes: receiving a second request message from the first communication device, where the second request message is used to request establishment of a first NAS connection between the first communication device and the first network element, and the second request message includes an identifier of the first communication device; and sending a second response message to the first communication device, where the second response message is used to negotiate and determine a security context of the first NAS connection.

[0042] In yet another possible design, the method further includes determining the first security context according to a security context of the first NAS connection and the identity of the first task, the first security context being used for security protection and / or security verification of signaling related to the first task.

[0043] In yet another possible design, the first task includes any of the following: establishing a protocol data unit (PDU) session, a sensing service, or an artificial intelligence (AI) service.

[0044] In yet another possible design, the first network element includes any of the following: a session management function (SMF) network element, a sensing function network element, a data analysis function network element, an analysis logic function network element, or a model training logic function network element.

[0045] The technical effects of the method described in the above possible designs of the second aspect can be referred to the technical effects in the first aspect and the possible designs thereof.

[0046] In a third aspect, a communication method is provided. The method can be performed by a second network element. In the absence of a special description, the "second network element" in the present application can refer to the second network element itself (e.g., an authentication server function (AUSF), a SEAF, etc.), a component (e.g., a processor, a chip, or a chip system, etc.) in the second network element, or a logic module or software capable of realizing all or part of the functions of the second network element. For ease of description, the following describes an example in which the second network element performs the method.

[0047] The communication method includes: receiving a fourth request message from a first network element, the fourth request message being used to request a first security context, the fourth request message including an identity of a first task, the first security context being used for security protection and / or security verification of signaling related to the first task; determining the first security context according to the identity of the first task; and sending a fourth response message to the first network element, the fourth response message including the first security context.

[0048] In another possible design, the second network element is a security network element, and the method further includes: receiving a third request message from a first communication apparatus, the third request message being used to request establishment of a second NAS connection between the first communication apparatus and the security network element, the third request message including an identity of the first communication apparatus; and sending a third response message to the first communication apparatus, the third response message being used to negotiate a security context of the second NAS connection.

[0049] In another possible design, the determining the first security context according to the identity of the first task includes determining the first security context according to the identity of the first task and the security context of the second NAS connection.

[0050] In another possible design, the method further includes: receiving a fifth request message from the first communication apparatus, the fifth request message being used to request security verification of the first request message, and the fifth request message including security information determined based on the second security context, the security information being used to securely protect the identity of the first task in the first request message, the first request message being used to request establishment of the first task; performing security verification of the first request message based on the second security context; and sending a fifth response message to the first communication apparatus, the fifth response message being used to indicate a security verification result of the first request message.

[0051] In another possible design, the method further includes: sending a sixth request message to a security network element, the sixth request message being used to request acquisition of the second security context, and the sixth request message including second indication information used to indicate the type of the first task; and receiving a sixth response message from the security network element, the sixth response message including the second security context.

[0052] In another possible design, the determining the first security context according to the identity of the first task includes determining the first security context according to the identity of the first task and the second security context.

[0053] The technical effects of the method of the third aspect and possible designs thereof can refer to the technical effects in the second aspect and possible designs thereof.

[0054] A fourth aspect provides a communication method. The method can be performed by a security network element. In the absence of a special description, the "second network element" in the present application can refer to the security network element itself (for example, AUSF, etc.), a component (for example, a processor, a chip, or a chip system, etc.) in the security network element, or a logic module or software capable of realizing all or part of the function of the security network element. For ease of description, the following describes the security network element as an example.

[0055] The communication method comprises: receiving a sixth request message from a second network element, the sixth request message being used for requesting to obtain a first security context, the sixth request message comprising an identifier of the first communication device and / or second indication information, the second indication information being used for indicating a type of the first task; determining the first security context according to a security context of a second NAS connection; and sending a sixth response message to the second network element, the sixth response message comprising the first security context.

[0056] In a possible design of the method, the method further comprises: receiving a third request message from the first communication device, the third request message being used for requesting to establish a second NAS connection between the first communication device and the secure network element, the third request message comprising an identifier of the first communication device; and sending a third response message to the first communication device, the third response message being used for negotiating to determine a security context of the second NAS connection.

[0057] The technical effects of the method of the above fourth aspect and possible designs thereof can refer to the technical effects of the third aspect and possible designs thereof.

[0058] In the fifth aspect, the present application provides a communication device, which has the functions of the first aspect to the fourth aspect, for example, the communication device comprises a module or unit or means corresponding to the operations of the first aspect to the fourth aspect, which can be implemented by software, or by hardware, or by a combination of software and hardware.

[0059] In the sixth aspect, the present application provides a communication device, which comprises at least one processor and a memory. The memory is configured to store part or all of the computer programs or instructions necessary for implementing the functions of the first aspect to the fourth aspect. The at least one processor can execute the computer programs or instructions, and when the computer programs or instructions are executed, the communication device implements the method in any possible design or implementation manner of the first aspect to the fourth aspect.

[0060] In a possible design, the communication device can further comprise an interface circuit, and the processor is configured to communicate with other devices or components through the interface circuit.

[0061] In a possible design, the communication device can further comprise the memory. Optionally, the memory and the processor are integrated together.

[0062] The communication device can be a terminal of the fifth aspect, or a communication module in the terminal, or a chip responsible for communication function in the terminal, such as a Modem chip (also known as a baseband chip) or a SoC or SIP chip containing a modem module.

[0063] In a seventh aspect, the present application provides a chip, which comprises a processor and a communication interface, the processor reads instructions through the communication interface, and executes the method provided in any of the implementation manners of the first aspect to the fourth aspect.

[0064] In an eighth aspect, the present application provides a communication system, which comprises a first network element for executing the method in the second aspect, a second network element for executing the method in the third aspect, and a security network element for executing the method in the fourth aspect.

[0065] Optionally, the communication system further comprises a first communication device for executing the method in the first aspect.

[0066] In a ninth aspect, the present application provides a computer readable storage medium, which stores computer readable instructions, when a computer reads and executes the computer readable instructions, the computer executes the method in any of the possible designs of the first aspect to the fourth aspect.

[0067] In a tenth aspect, the present application provides a computer program product, when a computer reads and executes the computer program product, the computer executes the method in any of the possible designs of the first aspect to the fourth aspect. BRIEF DESCRIPTION OF DRAWINGS

[0068] FIG. 1 is a schematic diagram of a network architecture 100 provided by the present application.

[0069] FIG. 2 is a schematic diagram of a control plane protocol stack between a terminal device and an SMF.

[0070] FIG. 3 is a schematic diagram of a distributed NAS architecture.

[0071] FIG. 4 is a schematic diagram of a NAS security establishment process.

[0072] FIG. 5 is a schematic diagram of a security protection process during PDU session establishment.

[0073] FIG. 6 is a schematic flowchart of a communication method provided by the present application.

[0074] FIG. 7 is a schematic flowchart of another communication method provided by the present application.

[0075] FIG. 8 is a schematic diagram of a key architecture provided by the present application.

[0076] FIG. 9 is a schematic flowchart of still another communication method provided by the present application.

[0077] FIG. 10 is a schematic diagram of another key architecture provided by the present application.

[0078] FIG. 11 is a schematic flowchart of another communication method provided by the present application.

[0079] FIG. 12 is a schematic diagram of another key architecture provided by the present application.

[0080] FIG. 13 is a schematic flowchart of another communication method provided by the present application.

[0081] FIG. 14 is a schematic flowchart of another communication method provided by the present application.

[0082] FIG. 15 is a schematic flowchart of another communication method provided by the present application.

[0083] FIG. 16 is a schematic block diagram of a communication apparatus 10 provided by an embodiment of the present application.

[0084] FIG. 17 is a schematic diagram of another communication apparatus 20 provided by an embodiment of the present application. DETAILED DESCRIPTION

[0085] In order to facilitate understanding of the embodiments of the present application, the following points are first explained.

[0086] First, in the present application, “for indicating” can include for directly indicating and for indirectly indicating. When describing that certain indication information is for indicating A, it can include that the indication information directly indicates A or indirectly indicates A, and does not mean that A must be carried in the indication information.

[0087] The information indicated by the indication information is referred to as to-be-indicated information, and there are many ways to indicate the to-be-indicated information in the specific implementation process, for example but not limited to, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or an index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, where the other information and the to-be-indicated information have an association relationship. The to-be-indicated information can also be only indicated in part, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of a specific information can also be achieved by means of the arrangement order of each information agreed in advance (for example, a protocol stipulates), thereby reducing the indication overhead to a certain extent. Meanwhile, the common part of each information can also be identified and uniformly indicated, so as to reduce the indication overhead caused by separately indicating the same information.

[0088] Second, "at least one" in the present application means one or more, and "more than one" means two or more (including two). In addition, in the embodiments of the present application, "first", "second", and various numerical numbers (for example, "#1", "#2", and the like) are only used for the convenience of description and do not limit the scope of the embodiments of the present application. The size of the serial number of each process below does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. It should be understood that the objects thus described can be interchanged under appropriate circumstances, so as to be able to describe solutions other than the embodiments of the present application. In addition, in the embodiments of the present application, "S610" and the like are only used for the convenience of description and do not limit the order of execution steps.

[0089] Third, in the embodiments of the present application, "exemplary" or "for example" and the like are used to represent an example, illustration or description. Any embodiment or design scheme described as "exemplary" or "for example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the use of "exemplary" or "for example" and the like is intended to present the relevant concept in a specific manner.

[0090] Fourth, in the embodiments of the present application, "saving" can mean saving in one or more memories. The one or more memories can be separately arranged or integrated in the encoder or decoder, processor, or communication device. The one or more memories can be partially separately arranged and partially integrated in the decoder, processor, or communication device. The type of memory can be any form of storage medium, which is not limited in the present application.

[0091] Fifth, in the embodiments of the present application, "protocol" can refer to a standard protocol in the communication field, which can include NR protocol and related protocols applied to future communication systems, which is not limited in the present application.

[0092] Sixth, in the embodiments of the present application, "of", "corresponding", "corresponding" and "associated" can be used interchangeably at times, and it should be pointed out that when the distinction is not emphasized, the meanings expressed are consistent.

[0093] Seventh, in the embodiments of the present application, "in the case of", "when", "if" can be used interchangeably at times, and it should be pointed out that when the distinction is not emphasized, the meanings expressed are consistent.

[0094] Eighth, the term "and / or" in this document is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after it.

[0095] Ninth, the terms "message", "information", or "information element (IE)" can be used interchangeably in this document, and the names of messages or information are not limited in any way as long as the corresponding functions can be implemented.

[0096] Tenth, in this application, "sending" and "receiving" represent the direction of signal transmission. For example, "sending information to XX" can be understood as the destination of the information being XX, and "sending information" can include direct sending or indirect sending through other units or modules. "Receiving information from YY" can be understood as the source of the information being YY, and "receiving information" can include direct reception from YY or indirect reception from YY through other units or modules. In addition to air interface sending or air interface receiving signals implemented by network devices or terminal devices at the whole machine level, "sending" can also be understood as the "output" of the chip interface, and "receiving" can also be understood as the "input" of the chip interface. For example, the Modem or system-level chip (such as SoC chip or SIP chip, etc.) sends or receives signals. "Sending" or "receiving" can also be performed by device components, such as sending or receiving signals through several parts, modules, chips of a device using buses, wires or interfaces.

[0097] The technical solutions in this application will be described below with reference to the accompanying drawings.

[0098] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), 5th generation (5G) system or new radio (NR), and future communication systems, vehicle-to-X (V2X), which can include vehicle-to-network (V2N), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), etc., long term evolution-vehicle (LTE-V), Internet of Vehicles, machine type communication (MTC), Internet of Things (IoT), long term evolution-machine (LTE-M), machine-to-machine (M2M), wireless local area network (WLAN), etc.

[0099] In addition, the technical solutions of the present application can be applied to satellite communication systems, high altitude platform (HAPS) communication, unmanned aerial vehicles and other non-terrestrial network (NTN) systems, such as integrated communication and navigation (IcaN) systems, global navigation satellite system (GNSS) and ultra-dense low-orbit satellite communication systems, etc.

[0100] For the convenience of description, the embodiments of the present application will be described taking the public land mobile network (PLMN) or 5G network as an example.

[0101] FIG. 1 is a schematic diagram of a communication system applicable to the present application. Take the 5G network architecture based on service-oriented architecture in the non-roaming scenario defined in the 3rd generation partnership project (3GPP) standardization process as an example. As shown in the figure, the network architecture can include three parts, namely the terminal device part, the DN and the operator network PLMN part. The functions of the network elements of each part are briefly described below.

[0102] The terminal device part can include a terminal device 110, which can also be referred to as a user equipment (UE). The terminal device can access the above-mentioned communication system, and is a device or module with corresponding communication functions. The terminal device can also be referred to as a user equipment (UE), a terminal, a user apparatus, an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile station (MS), a remote station, a remote terminal, a mobile device, a user terminal, a terminal unit, a terminal station, a terminal apparatus, a wireless communication device, a user agent, or a user device. A communication module, circuit or chip for performing corresponding communication functions is usually provided in the terminal. The terminal also has program instructions configured to perform corresponding communication functions.

[0103] For example, the terminal in the embodiments of the present application can be a mobile phone, a personal digital assistant (PDA) computer, a laptop computer, a tablet computer (Pad), a drone, a computer with wireless transceiver function, a machine type communication (MTC) terminal, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a light UE, a reduced capability UE (REDCAP UE), a wearable device (such as a smart watch, a smart bracelet, a pedometer, smart glasses, etc.), an internet of things (IoT) terminal, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home (such as a game console, a smart TV, a smart speaker, a smart refrigerator, and fitness equipment, etc.), a transport vehicle with wireless communication function, a communication module, a roadside unit (RSU) with terminal function, a flight device (such as a smart robot, a hot air balloon, a drone, an airplane). The terminal device can also be a vehicle device, such as a whole vehicle device, a vehicle-mounted module, a vehicle-mounted chip, an on-board unit (OBU), or a telematics box (T-BOX), etc.

[0104] The operator network PLMN part can include, but is not limited to, the RAN 120 and the core network (CN) part.

[0105] The RAN 120 is an implementation system between the service nodes of the operator network and the terminal device 110. To access the operator network, the terminal device 110 first passes through the RAN 120, and then can be connected with the service nodes of the operator network through the RAN 120.

[0106] The access network device can be a network-side device with wireless transceiver function. The access network device can be an apparatus in a radio access network (RAN) that provides wireless communication function for terminal devices, referred to as a RAN device. The RAN can be a 3rd generation partnership project (3GPP)-related cellular system, such as a 5G mobile communication system, or a future-oriented evolution system (such as a next-generation mobile communication system). The RAN can also be an open radio access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. For example, the access network device can be a base station, an evolved NodeB (eNodeB), a next-generation NodeB (gNB) in a 5G mobile communication system, a base station in a subsequent evolution of 3GPP, a transmission reception point (TRP), an access node in a WiFi system, a wireless relay node, a wireless backhaul node, etc. In a communication system using different radio access technologies (RATs), the name of the device with base station function can be different. For example, it can be referred to as an eNB or eNodeB in an LTE system, and as a gNB in a 5G system or an NR system. The specific name of the base station is not limited in the present application. The access network device can include one or more co-sited or non-co-sited transmission reception points. For another example, the access network device can include at least one of one or more central units (CUs), one or more distributed units (DUs), and one or more radio units (RUs). In different systems, the CU (or CU-CP and CU-UP), DU, or RU can also have different names, but those skilled in the art can understand their meanings. For example, in an open RAN (ORAN) system, the CU can also be referred to as an O-CU (open CU), the DU can also be referred to as an O-DU (open DU), the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. Any of the CU (or CU-CP, CU-UP), DU, and RU in the present application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.Exemplarily, the functions of the CU can be implemented by one entity or different entities. For example, the functions of the CU are further divided, i.e., the control plane and the user plane are separated and implemented by different entities, namely a control plane CU entity (i.e., a CU-CP entity) and a user plane CU entity (i.e., a CU-UP entity), which can be coupled with the DU to jointly complete the functions of the access network device. For example, the CU is responsible for processing non-real-time protocols and services, implementing radio resource control (RRC), and the functions of the packet data convergence protocol (PDCP) layer. The DU is responsible for processing physical layer protocols and real-time services, implementing the functions of the radio link control (RLC) layer, the media access control (MAC) layer, and the physical (PHY) layer. In this way, part of the functions of the wireless access network device can be implemented by multiple network function entities. These network function entities can be network elements in a hardware device, or software functions running on a dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). The access network device can also include an active antenna unit (AAU). The AAU implements part of the physical layer processing functions, radio frequency processing, and related functions of the active antenna. Since the information of the RRC layer will eventually become the information of the PHY layer, or be converted from the information of the PHY layer, in this architecture, high-layer signaling, such as RRC layer signaling, can also be considered as being sent by the DU, or by the DU+AAU. It can be understood that the access network device can be a device including one or more of the CU node, the DU node, and the AAU node. In addition, the CU can be divided into an access network device in the radio access network (RAN), or the CU can be divided into an access network device in the core network (CN), which is not limited in the present application. For another example, in the V2X technology, the access network device can be a road side unit (RSU). The multiple access network devices in the communication system can be the same type of base station, or different types of base stations. The base station can communicate with the terminal device, or communicate with the terminal device through a relay station. In the embodiments of the present application, the device for implementing the functions of the access network device can be the access network device itself, or a device capable of supporting the access network device to implement the functions, such as a chip system or a combination device or component that can implement the functions of the access network device, which can be installed in the access network device. In the embodiments of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices.

[0107] The CN part can include, but is not limited to, the following NFs: a user plane function (UPF) 130, a network exposure function (NEF) 131, a network repository function (NRF) 132, a policy control function (PCF) 133, a unified data management (UDM) 134, a unified data repository (UDR) 135, a network data analytics function (NWDAF) 136, an authentication server function (AUSF) 137, an AMF 138, a session management function (SMF) 139.

[0108] A data network DN 140, which can also be referred to as a packet data network (PDN), is usually a network located outside the operator network, for example, a third-party network. Of course, in some implementations, the DN can also be deployed by the operator, that is, the DN belongs to a part of the PLMN. The present application does not limit whether the DN belongs to the PLMN. The operator network PLMN can access multiple data networks DN 140, and various services can be deployed on the data networks DN 140 to provide data and / or voice services for the terminal device 110. For example, the data network DN 140 can be a private network of a certain smart factory, and the sensors installed in the workshop of the smart factory can be terminal devices 110. A control server of the sensors is deployed in the data network DN 140, and the control server can provide services for the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions, and the like. For another example, the data network DN 140 can be an internal office network of a certain company, and the mobile phones or computers of the employees of the company can be terminal devices 110. The mobile phones or computers of the employees can access information and data resources on the internal office network of the company. The terminal device 110 can establish a connection with the operator network through an interface (for example, N1, etc.) provided by the operator network, and use the data and / or voice services provided by the operator network. The terminal device 110 can also access the data network DN 140 through the operator network, use the operator services and / or third-party services deployed on the data network DN 140.

[0109] The CN includes NF functions, which are further briefly described below.

[0110] 1. The UPF 130 is a gateway provided by an operator and is a gateway for communication between the operator network and a data network DN 140. The UPF 130 includes functions related to a user plane, such as data packet routing and transmission, data packet detection, service usage reporting, quality of service (QoS) processing, uplink data packet detection, and downlink data packet storage.

[0111] 2. The NEF 131 is a control plane function provided by an operator and is mainly used to enable third parties to use services provided by the network, support network exposure of capabilities, event and data analysis, provision of information for PLMN security from external applications, conversion of information for interaction within and outside the PLMN, provision of an application programming interface (API) interface for the operator network to expose to external applications, and interaction between external service providers and internal operator networks.

[0112] 3. The NRF 132 is a control plane function provided by an operator and can be used to maintain real-time information about network functions and services in the network. For example, it supports network service discovery, maintains NF profile supported services for NF instances, supports service discovery for service communication proxy (SCP), maintains SCP profile for SCP instances, sends notifications about new registration, deregistration, and updates for NF and SCP, and maintains health status for running NF and SCP.

[0113] 4. The PCF 133 is a control plane function provided by an operator and supports a unified policy framework to govern network behavior, provides policy rules and subscription information related to policy decisions to other control functions, and the like.

[0114] 5、The UDM 134 is a control plane function provided by an operator, responsible for storing the user permanent identifier (SUPI) of a subscription user in an operator network, the generic public subscription identifier (GPSI) of the subscription user, credential, and the like. The SUPI is first protected in confidentiality during transmission, and the SUPI protected in confidentiality is referred to as a subscription concealed identifier (SUCI). The information stored by the UDM 134 can be used for authentication and authorization of the terminal device 110 accessing the operator network. The subscription user of the operator network described above can be a user using a service provided by the operator network, for example, a user using a subscriber identity module (SIM) card of an operator A, or a user using a SIM card of an operator B, and the like. The credential of the subscription user can be a long-term key stored in the SIM card or a small file stored in relation to SIM card encryption, used for authentication and / or authorization. It should be noted that the permanent identifier, the credential, the security context, the authentication data (cookie), and the token and the like are information related to verification / authentication and authorization, which are not distinguished or limited in the embodiments of the present application for the sake of convenience of description.

[0115] 6、The UDR 135 is a control plane function provided by an operator, providing a function of storing and obtaining subscription data for the UDM, storing and obtaining policy data for the PCF, storing and obtaining the NF group ID information of a user, and the like.

[0116] 7、The NWDAF 136 is a control plane function provided by an operator, and its main function is to collect data from NFs, external application functions (AFs), and operations, administration and maintenance (OAM) systems, and the like, and to provide the NWDAF service registration, data exposure, and analysis data for the NFs and the AFs. In the present application, the NWDAF is mainly responsible for security-related data analysis, and therefore the NWDAF can also be understood as a network element with a security analysis function in the present application. The network element with the security analysis function is referred to as the NWDAF, which is only an example, and other network element names can also be used in the future, which are not limited in the present application.

[0117] 8、The AUSF 137 is a control plane function provided by an operator, and is usually used for primary authentication, i.e., authentication between the terminal device 110 (a subscription user) and the operator network. After receiving an authentication request initiated by a subscription user, the AUSF 137 can authenticate and / or authorize the subscription user through authentication information and / or authorization information stored in the UDM 134, or generate authentication and / or authorization information of the subscription user through the UDM 134. The AUSF 137 can feed back the authentication information and / or authorization information to the subscription user.

[0118] 9、The AMF 138 is a control plane network function provided by an operator network, and is responsible for access control and mobility management of the terminal device 110 accessing the operator network, for example, including functions such as mobile state management, allocation of a user temporary identity, authentication and authorization of a user, etc.

[0119] 10、The SMF 139 is a control plane network function provided by an operator network, and is responsible for managing a PDU session of the terminal device 110. The PDU session is a channel for transmitting PDUs, and the terminal device transmits PDUs with a data network DN 140 through the PDU session. The PDU session is responsible for establishment, maintenance and deletion, etc. by the SMF 139. The SMF 139 includes session management (for example, session establishment, modification and release, including maintenance of a tunnel between a user plane function UPF 130 and a RAN 120), selection and control of the UPF 130, service and session continuity (SSC) mode selection, roaming, and other session-related functions.

[0120] 11、The AF 141 is a control plane network function provided by an operator network, and is used to provide application layer information. It can interact with a policy framework through a network exposure function network element, or directly interact with the policy framework to request a policy decision, etc. It can be located within an operator network, or outside the operator network.

[0121] It can be understood that the above-mentioned network elements or functions can be either a physical entity in a hardware device, or a software instance running on a dedicated hardware, or a virtualized function instantiated on a shared platform (for example, a cloud platform). In short, an NF can be implemented by hardware, or by software.

[0122] Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nausf, Namf, Nsmf, Nran, N1, N2, N3, N4, and N6 in FIG. 1 are interface sequence numbers. For example, the meanings of the above interface sequence numbers can refer to the meanings defined in the 3GPP standard protocol, and the meanings of the above interface sequence numbers are not limited in the present application. It should be noted that the interface names between the various network functions in the figure are only an example, and the interface names of the system architecture in the specific implementation can also be other names, which are not limited in the present application. In addition, the names of the messages (or signaling) transmitted between the above various network elements are also only an example, and do not constitute any limitation on the function of the message itself.

[0123] For convenience of description, the network functions (such as NEF 131…SMF 139) in the embodiments of the present application are collectively / referred to as NF, that is, the NF described hereinafter in the embodiments of the present application can be replaced by any network function. In addition, FIG. 1 only schematically describes part of the network functions, and the NF described hereinafter is not limited to the network functions shown in FIG. 1.

[0124] It should be understood that the above network architecture applied to the embodiments of the present application is only a network architecture described from the perspective of service architecture, and the network architecture applicable to the embodiments of the present application is not limited thereto, and any network architecture capable of realizing the functions of the above network elements is applicable to the embodiments of the present application. For example, at least one of the network elements, access network devices, or terminal devices in the present application can be deployed in an NTN.

[0125] It should also be understood that the AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown in FIG. 1 can be understood as network elements in the core network for realizing different functions, which can be combined into a network slice as needed, for example. These core network elements can be independent devices, or can be integrated into the same device to realize different functions, and the specific form of the above network elements is not limited in the present application. In addition, the network architecture shown in FIG. 1 can also include other network elements, for example, the network architecture can also include a perception function network element, an artificial intelligence logic function (such as a model training logic function, an analysis logic function) network element, etc.

[0126] It should also be understood that the above naming is only defined for the convenience of distinguishing different functions, and should not constitute any limitation on the present application. The present application does not exclude the possibility of using other names in the 5G network and future other networks. For example, in future communication networks, part or all of the above network elements can use the terms in 5G, or other names, etc.

[0127] For the convenience of understanding the embodiments of the present application, some basic concepts related to the present application are briefly described. It should be understood that the basic concepts introduced below are described by taking the basic concepts defined in the NR protocol as an example, but the embodiments of the present application are not limited to only being applicable to the NR system. Therefore, when the NR system is taken as an example for description, the standard names appearing in the description are functional descriptions, the specific names are not limited, and only represent the function of the device, which can be extended to other systems in the future.

[0128] 1. Non-access stratum message: refers to a message sent between terminal devices through a radio access node to a subsequent node, including: a message sent by a terminal device to a core network through an access network device, or a message sent by a terminal device to a CU through a DU. Because the access node does not process, it is called a non-access stratum message. In order to facilitate description, the message not processed by the access node is referred to as a NAS (Non-Access Stratum) message in the present application, but it should be understood that the name of the message in the present application is not limited, and the message not processed by the access node can also have other names (such as other possible names defined in future communication protocols).

[0129] 2. NAS message classification: according to different core network elements sending the NAS message, the NAS message can be divided into mobility management (MM) NAS message, session management (SM) NAS message, short message service (SMS) NAS message, and call control (CC) NAS message. In addition to MM NAS, other types of NAS messages are first sent to the AMF by the UE through the access network, and then routed to other NFs by the AMF.

[0130] In the protocol stack, the RRC and the radio access network application part (RANAP) layer and the protocol layer below it are called the access layer, and the MM, SM, or CC above the RRC and RANAP are called the non-access layer. Among them, the process in which the base station of the radio access layer participates in processing is called the process of the access layer; the signaling that only the UE and the core network element need to process, and the radio access network base station only needs to route the signaling without processing the signaling is called the process of the non-access layer.

[0131] For ease of understanding, how AMF routes session management NAS message (NAS-SM) is briefly introduced in connection with FIG. 2. FIG. 2 is a schematic diagram of a control plane protocol stack between a terminal device and an SMF. As shown in FIG. 2, the NAS-SM protocol layer is the SM function of the NAS protocol, which supports the establishment, modification and release of the PDU session user plane. The NAS-SM protocol layer supports processing the session management between the UE and the SMF. The NAS-SM signaling is transmitted through the AMF, and the content of the NAS-SM signaling will not be parsed by the AMF. The NAS-SM signaling is processed (created and processed) at the NAS-SM protocol layer between the UE and the SMF.

[0132] The NAS-MM protocol layer processing NAS-SM signaling includes the following two points:

[0133] 1) Transmitting NAS-SM signaling: the NAS-MM protocol layer creates a NAS-MM message, including a security header, an indication of transmitting NAS-SM signaling, information on how to forward and to which NAS-SM signaling is forwarded after receiving the NAS-MM.

[0134] 2) Receiving NAS-SM signaling: processing the NAS-MM part after receiving the NAS-MM message, i.e. performing integrity check, parsing information on how to forward and to which NAS-SM signaling is forwarded.

[0135] 3. Distributed NAS architecture: For ease of understanding, the distributed NAS architecture is explained in connection with FIG. 3. FIG. 3 is a schematic diagram of a distributed NAS architecture.

[0136] The distributed NAS architecture and the N2 service based interface (SBI) can enable the UE to directly communicate with any network element (UE-any NF). Without the need for the AMF to transmit, the (R)AN-NF directly communicates, which can bring the following benefits:

[0137] 1) The (R)AN can directly communicate with the NF corresponding to the service.

[0138] 2) The signaling load is distributed among multiple NFs, and the AMF signaling load is reduced, e.g. without the need to send NAS-SM messages. Reducing the number of signaling hops, reducing the signaling delay.

[0139] 3) Reducing the number of signaling hops, improving the delay.

[0140] 4. NAS security establishment: For ease of understanding, the NAS security establishment process defined by the existing protocol is explained in connection with FIG. 4. FIG. 4 is a schematic diagram of a NAS security establishment process.

[0141] As can be seen from FIG. 4, the NAS security establishment includes the following steps:

[0142] Step 1: UE sends an initial NAS message to AMF.

[0143] Exemplarily, if the UE does not have a NAS security context, the initial NAS message shall contain only clear information elements (IEs), i.e. subscription identifier (e.g. subscription concealed identifier (SUCI) or Globally Unique Temporary Identity (GUTI)), UE security capabilities, ngKSI, etc.

[0144] Exemplarily, if the UE has a NAS security context, the initial NAS message sent shall contain the above clear information elements, and the complete initial NAS message encrypted in an encrypted NAS container. In case the initial NAS message is protected and the AMF has the same security context, steps 2 to 4 below can be omitted, and in this case the AMF shall use the complete initial NAS message in the NAS container as the message to respond to.

[0145] Step 2: If the AMF cannot acquire the NAS security context locally or from the last visited AMF, or if the AMF fails the integrity check of the received initial NAS message, the AMF shall initiate an authentication procedure with the UE (e.g. step 2b in Figure 4). The specific authentication procedure is not limited in the present application, and will not be described here.

[0146] Exemplarily, if the AMF acquires the old NAS security context from the last visited AMF (e.g. step 2a in Figure 4), the AMF can decipher the NAS container with the same security context and acquire the initial NAS message, then steps 2b to 4 can be omitted. If the AMF acquires a new K AMF from the last visited AMF (receiving keyAmfChangeInd), step 2b can be omitted.

[0147] Step 3: If the UE authentication is successful, the AMF shall send a NAS security mode command message (NAS SMC).

[0148] If the initial NAS message is protected but fails integrity check (e.g. due to MAC failure or AMF fails to find the security context used), or the AMF fails to decrypt the complete initial NAS message in the NAS container (e.g. due to receiving "keyAmfChangeInd" from the last visited AMF), the AMF shall include a flag in the NAS Security Mode Command message requesting the UE to send the complete initial NAS message in the NAS Security Mode Complete message.

[0149] Step 4: The UE shall send a NAS Security Mode Complete message to the AMF in response to the NAS Security Mode Command message. The NAS Security Mode Complete message shall be encrypted and integrity protected. In addition, if the AMF requested or the UE sent an unprotected initial NAS message, the NAS Security Mode Complete message shall include the complete initial NAS message in a NAS container. The AMF shall use the complete initial NAS message in the NAS container as the message to respond to.

[0150] Step 5: The AMF shall send a response to the initial NAS message. This message shall be encrypted and integrity protected.

[0151] 5. Security protection at PDU session establishment: For ease of understanding, the security protection procedure at PDU session establishment defined by the existing protocol is explained in combination with FIG. 5. FIG. 5 is a schematic diagram of a security protection procedure at PDU session establishment.

[0152] As can be seen from FIG. 5, the security protection procedure at PDU session establishment includes an access procedure phase and a PDU session establishment procedure phase.

[0153] The access procedure phase includes the following steps:

[0154] S510, the UE sends an initial NAS message to the AMF.

[0155] S520, the AMF sends a NAS SMC message to the UE for negotiating NAS security algorithms and generating a NAS security context.

[0156] S530, NAS security is established between the AMF and the UE.

[0157] Wherein, the detailed procedure of step 3 is referred to the NAS security establishment procedure shown in FIG. 4 described above, the UE and the AMF configure the NAS key, such as configuring Kamf, or configuring Knas, which will not be repeated here.

[0158] It should be noted that the name of the key in the present application is not limited, for example, the above-mentioned UE and AMF configure NAS key can be called AMF key (Kamf), NAS key (Knas), key #1, or key A, etc., which will not be illustrated one by one here.

[0159] Further, after establishing the NAS security between the AMF and the UE, the UE can establish the PDU session through the AMF and the SMF.

[0160] The PDU session establishment process phase includes the following steps:

[0161] S540, the UE sends an uplink (UL) NAS message to the AMF.

[0162] Specifically, the UL NAS message is used to request to establish a PDU session, and the UL NAS message is encrypted based on Knas.

[0163] S550, the AMF decrypts the UL NAS message and verifies the integrity.

[0164] S560, the AMF sends a PDU session establishment request message to the SMF.

[0165] S570, the SMF sends a downlink (DL) NAS message to the UE through the AMF, and responds to the PDU session establishment request.

[0166] The above briefly introduces the scenario to which the communication method provided by the embodiments of the present application can be applied in combination with FIG. 1, and introduces the basic concepts that may be involved in the embodiments of the present application, and introduces the security protection during PDU session establishment in the basic concepts, but in the security protection process during PDU session establishment, the process of the terminal device requesting to establish a PDU session is protected based on the security context negotiated between the terminal device and the AMF, but this security protection method cannot realize independent security protection for different tasks (such as the process of requesting to establish different PDU sessions) requested to be executed by the terminal device. Therefore, how to realize task granularity security protection during task execution has become a problem to be solved.

[0167] In addition, the security protection process during PDU session establishment shown in FIG. 5 described above is not suitable for the distributed NAS architecture, because under the distributed NAS architecture, the NAS message during PDU session establishment is irrelevant to the access process of the AMF.

[0168] In order to solve the problems existing in the above-mentioned security protection process during PDU session establishment, the present application provides a communication method, which can realize task granularity security protection during task execution.

[0169] It should be understood that the embodiments shown below do not particularly limit the specific structure of the subject performing the method provided by the embodiments of the present application, as long as the subject can communicate according to the method provided by the embodiments of the present application by running a program in which the code of the method provided by the embodiments of the present application is recorded. For example, the subject performing the method provided by the embodiments of the present application can be a network element, or a functional module in the network element that can invoke and execute a program.

[0170] FIG. 6 is a schematic flowchart of a communication method provided by the embodiments of the present application. The method includes the following steps:

[0171] S610, the first communication device sends a first request message to the first network element, and correspondingly, the first network element receives the first request message from the first communication device.

[0172] Specifically, the first request message is used to request to perform a first task, and the first request message includes an identifier of the first task.

[0173] Exemplarily, the first communication device can be a terminal device (e.g., the UE shown in FIG. 1), or a component (e.g., a processor, a chip, or a chip system, etc.) in the terminal device, or a logical module or software that can realize all or part of the functions of the terminal device. For ease of description, the following is described by taking the first communication device as an example.

[0174] Exemplarily, the first network element can be a functional network element that provides a service related to performing the first task.

[0175] By way of example but not limitation, the first task can be any one of the following: establishing a PDU session, sensing a service, or AI service, etc.

[0176] By way of example but not limitation, the first network element includes any one of the following: an SMF, a sensing functional network element, a data analysis functional network element, an analysis logic functional network element, or a model training logic functional network element.

[0177] For example, if the first task is to establish a PDU session, the first network element can be a functional network element (e.g., an SMF) that provides a PDU session establishment related service; for another example, if the first task is to perform sensing, the first network element can be a functional network element (e.g., a sensing functional network element) that provides a sensing related service; for another example, if the first task is an AI service, the first network element can be a functional network element (e.g., an analyze logical function (AnLF), a model trains logical function (MTLF), etc.) that provides an AI related service; for another example, if the first task is a data analysis, the first network element can be a functional network element (e.g., a NWDAF, an analyze logical function (AnLF), a model trains logical function (MTLF), etc.) that provides a data analysis related service.

[0178] It should be understood that the above-mentioned possible forms of the first task are only examples and do not limit the protection scope of the present application, and the first task can also be other tasks required to be performed by the first communication device, such as computing power analysis, etc., which will not be illustrated one by one. In addition, the above-mentioned first network element is a network element that provides a first task related service, and the type of the above-mentioned first network element is only an example and does not limit the protection scope of the present application.

[0179] Optionally, the above-mentioned identification of the first task is used to identify the first task, or can be understood as information of the first task, and different tasks correspond to different identifications. For example, if the first task is to establish a PDU session, the identification of the first task can be an identifier (ID) of the PDU session. In the present application, the specific form of the identification of the first task is not limited, as long as it can be used to identify the first task, and different tasks correspond to different identifications.

[0180] As a possible implementation manner, the above-mentioned identification of the first task is generated by the first communication device, and in this implementation manner, before the first communication device sends the first request message to the first network element, the method flow shown in FIG. 6 further includes:

[0181] S601, the first communication device generates an identification of the first task.

[0182] It should be understood that, in the case that the first communication device generates the identity of the first task by itself, the generated identity of the first task can be passed to the network side through a subsequent process to support the first communication device and the network side to establish a security context required according to the identity of the first task, thereby reducing the cost of the network side to generate the security context.

[0183] As another possible implementation, the identity of the first task can also be assigned by the network side. For example, the first communication device sends a message #1 to the first network element, the message #1 being used to request to perform the first task, the first network element assigns an identity to the first task and sends the identity of the first task to the first communication device through a message #2.

[0184] In this implementation, since the identity of the first task has been negotiated and determined, the first communication device can not need to carry the identity of the first task in the first request message sent to the first network element, and the first communication device and the first network element can perform security protection and / or security verification on the signaling related to the first task based on the first security context. The generation of the first security context is related to the identity of the first task.

[0185] It should be understood that the above-mentioned manner of obtaining the identity of the first task is only an example and does not constitute any limitation on the protection scope of the present application, and the identity of the first task can also be determined by a management device (such as an operation administration and maintenance (OAM) device) and provided to the first communication device and the first network element.

[0186] Further, after the first network element receives the first request message, the first network element can respond to the request of the first request message through a first response message, and the method flow shown in FIG. 6 further includes:

[0187] S620, the first communication device receives the first response message from the first network element, and correspondingly, the first network element sends the first response message to the first communication device.

[0188] The first response message is used to respond to the request of the first request message, and the first response message can indicate that the request of the first request message is agreed, the first task is performed, or the request of the first request message is refused, and the first task is refused to be performed. For example, if the first request message is a PDU session establishment request message, the first response message is a PDU session response request message.

[0189] Specifically, the first response message is secured based on the first security context, and the first security context is determined based on the identity of the first task.

[0190] The security protection in this embodiment includes, but is not limited to, integrity protection and / or encryption protection. For example, the security protection of the first response message based on the first security context described above can be integrity protection and / or encryption protection of the first response message based on the first security context. The security context can be a key-related parameter including a key, such as a security context including a key, a key identifier, or a key validity duration, and the like.

[0191] For example, the key included in the security context in this application includes, but is not limited to, a symmetric key, a public key, or a private key, and the like, which is used to encrypt a message. The description will not be repeated below.

[0192] As a possible implementation, this embodiment can be applied to a non-distributed NAS architecture, for example, applied to the session establishment process shown in FIG. 5 above, that is, the process of requesting the SMF to establish a PDU session by the UE through the AMF. The PDU session related signaling can be security protected based on the first security context, and the first security context is determined based on the identifier of the PDU session. It can be understood that different security contexts can be used for security protection in different PDU session establishment processes, to achieve independent protection of the security of PDU session establishment.

[0193] As another possible implementation, this embodiment can be applied to the distributed NAS architecture shown in FIG. 3 above, for example, applied to the scenario where the UE directly communicates with the SMF without the AMF acting as a transmission channel. In the process of requesting the SMF to establish a PDU session by the UE, the PDU session related signaling can be security protected based on the first security context, and the first security context is determined based on the identifier of the PDU session. It can be understood that different security contexts can be used for security protection in different PDU session establishment processes, to achieve independent protection of the security of PDU session establishment.

[0194] It should be understood that the above description of application scenarios is only an example and does not constitute any limitation on the protection scope of this application. The application of the communication method shown in FIG. 6 is not limited in any way, and can be applied to a scenario where the first communication device has a demand for performing a first task, to achieve security protection of the task granularity.

[0195] In a possible implementation, the first network element obtains the first security context before sending the first response message, so that the first response message can be security protected based on the first security context. Therefore, the method flow shown in FIG. 6 further includes:

[0196] S612, the first network element obtains the first security context.

[0197] As a possible implementation, the first network element can determine the first security context by itself. The manner in which the first network element determines the first security context will be described below in connection with specific examples, such as the description of the determination of the first security context by the first network element in the communication method shown in FIG. 7 and FIG. 13, which will not be described herein.

[0198] As another possible implementation, the first network element can receive the first security context from another network element. The manner in which the first network element receives the first security context from another network element will be described below in connection with specific examples, such as the description of the reception of the first security context by the first network element from the security network element in the communication method shown in FIG. 9, FIG. 11, FIG. 14 and FIG. 15, and the description of the acquisition of the first security context by the first network element from the security network element through the second network element, which will not be described herein.

[0199] Exemplarily, the first request message described above further includes security information, which is determined based on the second security context, and the security information is used for security protection of the identification of the first task.

[0200] Optionally, the security information used for security protection of the identification of the first task can be that the security information is used for security protection of the first request message. For example, the security information is used for integrity protection and / or encryption protection of the first request message as a whole, thereby achieving security protection of the identification of the first task carried in the first request message.

[0201] Optionally, the security information in the first request message can be a MAC, which is used for integrity protection of the first request message. The MAC is determined based on the second security context, for example, the MAC is determined based on a key or a lower-level key of the key in the second security context.

[0202] In this embodiment, the second security context based on which the security information is generated and the first security context used for security protection of the first response message can be the same or different security contexts, which will be described below respectively:

[0203] Manner one: the second security context is the same as the first security context.

[0204] In the case described in manner one, before the first communication device sends the first request message to the first network element, the first communication device can determine the second security context described above based on the identification of the first task and the third security context, and the first security context is also determined based on the identification of the first task and the third security context, and then the method flow shown in FIG. 6 further includes:

[0205] S602, the first communication device determines the second security context based on the identification of the first task and the third security context.

[0206] The second security context is used for security protection and / or security verification of signaling related to the first task, for example, the first communication device performs security protection on the first request message mentioned above based on the second security context; and for example, the first communication device performs security verification on the first response message mentioned above based on the second security context.

[0207] Optionally, if the first task is to establish a PDU session, after the establishment of the PDU session is completed, the first communication device and the first network element can perform security protection and / or security verification on signaling related to the PDU session (such as update request messages, revocation request messages, close request messages, re-establishment request messages of the PDU session, and corresponding response messages, etc.) based on the first security context.

[0208] Specifically, in the case shown in mode one, the first security context is generated in the same way as the second security context, that is, the first security context is also determined based on the identifier of the first task and the third security context.

[0209] Mode 1.1: The third security context can be determined based on a security context of an established first NAS connection between the first communication device and the first network element.

[0210] In the case shown in mode 1.1, the manner in which the first network element obtains the first security context in step S612 mentioned above can be that the first network element determines the first security context by itself.

[0211] In this implementation mode, the process in which the first communication device determines the second security context and the first network element obtains the first security context will be described in detail below with reference to FIG. 7, which will not be described here.

[0212] Mode 1.2: The third security context can be determined based on a security context of an established second NAS connection between the first communication device and the security network element.

[0213] In the case shown in mode 1.2, the manner in which the first network element obtains the first security context in step S612 mentioned above can be that the first network element receives the first security context from the security network element, wherein the first network element receiving the first security context from the security network element can be that the first network element directly receives the first security context from the security network element, or the first network element receives the first security context from the security network element through other network elements. This will be described in detail below with reference to FIG. 9, which will not be described here.

[0214] Mode 1.3: The third security context can be determined based on a fourth security context, and the fourth security context is determined based on a security context of an established second NAS connection between the first communication device and the security network element.

[0215] In the case shown in manner 1.3, the manner in which the first network element obtains the first security context in step S612 described above can be that the first network element receives the first security context from the security network element, wherein the first network element receiving the first security context from the security network element can be that the first network element directly receives the first security context from the security network element, or that the first network element receives the first security context from the security network element through other network elements. This will be described in detail below in conjunction with FIG. 11, and will not be described here in detail.

[0216] Manner two: the second security context is different from the first security context.

[0217] In the case described in manner two, after the first communication device receives the first response message (or after the first communication device sends the first request message, or before the first communication device sends the first request message), it should be understood that the timing of the generation of the first security context in this application is not limited in any way, and the first communication device can obtain the first security context before performing security verification on the first response message based on the first security context. For ease of description, the first communication device determines the first security context after receiving the first response message is taken as an example for description below.

[0218] The first communication device can determine the first security context based on the identifier of the first task and the second security context, and the method flow shown in FIG. 6 further includes:

[0219] S621, the first communication device determines the first security context based on the identifier of the first task and the second security context.

[0220] The first security context is used for security protection and / or security verification of signaling related to the first task, for example, the first communication device performs security verification on the first response message based on the first security context.

[0221] Optionally, if the first task is to establish a PDU session, after the establishment of the PDU session is completed, the first communication device and the first network element can perform security protection and / or security verification on signaling related to the PDU session (such as update request messages, revocation request messages, close request messages, re-establishment request messages of the PDU session, and corresponding response messages, etc.) based on the first security context.

[0222] Specifically, in the case shown in manner two, the first security context is determined based on the identifier of the first task and the second security context.

[0223] Manner 2.1: The second security context can be determined based on a first NAS connection established between the first communication device and the first network element.

[0224] In the case shown in mode 2.1, the manner in which the first network element obtains the first security context in step S612 can be that the first network element determines the first security context by itself.

[0225] In this implementation mode, the process in which the first communication device determines the first security context and the first network element obtains the first security context will be described in detail below with reference to FIG. 13, and thus will not be described here.

[0226] Mode 2.2: The second security context can be determined based on a security context of the established second NAS connection between the first communication device and the security network element.

[0227] In the case shown in mode 2.2, the manner in which the first network element obtains the first security context in step S612 can be that the first network element receives the first security context from the security network element, where the first network element receiving the first security context from the security network element can be that the first network element directly receives the first security context from the security network element, or that the first network element receives the first security context from the security network element through another network element. The details will be described below with reference to FIG. 14, and thus will not be described here.

[0228] Mode 2.3: The second security context can be determined based on a fourth security context, and the fourth security context is determined based on a security context of the established second NAS connection between the first communication device and the security network element.

[0229] In the case shown in mode 2.3, the manner in which the first network element obtains the first security context in step S612 can be that the first network element receives the first security context from the security network element, where the first network element receiving the first security context from the security network element can be that the first network element directly receives the first security context from the security network element, or that the first network element receives the first security context from the security network element through another network element. The details will be described below with reference to FIG. 15, and thus will not be described here.

[0230] In the communication method shown in FIG. 6, when there is a demand to perform a first task, the first communication device can send a first request message to a first network element, and the first network element is a network element that provides a first task related service. Specifically, the first communication device sends an identifier of the first task to the first network element through the first request message, and a first response message sent by the first network element to the first communication device is securely protected based on a first security context, and the first security context is determined based on the identifier of the first task. It can be considered that the security context for securely protecting the signaling related to the first task in the process of performing the first task is determined based on the identifier of the first task, so that task granularity security protection can be achieved. For example, different tasks can be protected by different security contexts.

[0231] Exemplarily, the communication method flow shown in FIG. 6 can be performed after the first communication device has completed the primary authentication, so as to ensure that the first communication device generating the identity of the first task is a legal access.

[0232] FIG. 7 is a schematic flowchart of another communication method provided by the present application. The method includes the following steps:

[0233] S710, the first communication device sends a second request message to the first network element, and correspondingly, the first network element receives the second request message from the first communication device.

[0234] Specifically, the second request message is used to request the establishment of a first NAS connection between the first communication device and the first network element. For example, the first network element is an SMF, and the first NAS connection can be referred to as a NAS-SM connection.

[0235] Exemplarily, the second request message includes the identity of the first communication device. Optionally, the identity of the first communication device can be at least one of the following information used to identify the first communication device: GUTI of the first communication device, SUCI of the first communication device, SUPI of the first communication device, or other information used to identify the first communication device, etc.

[0236] Optionally, the first NAS connection requested to be established by the second request message can be understood as a NAS connection between the first communication device and the first network element, which can also be referred to as a non-access layer connection, a communication connection between the first communication device and the first network element, a first connection between the first communication device and the first network element, etc. The name of the first NAS connection is not limited in the present application.

[0237] As an example but not limitation, before the first communication device sends the second request message to the first network element, the method flow shown in FIG. 7 can further include:

[0238] S701, the first communication device and the access network device establish an RRC connection.

[0239] In the present application, the process of establishing an RRC connection between the first communication device and the access network device is not limited, and can refer to the description of establishing an RRC connection between the first communication device and the access network device in the existing communication standard (e.g., 3GPP TS 38.331) or future communication standard, which will not be described in detail here.

[0240] S702, the first communication device and the security network element perform primary authentication.

[0241] In this application, the process of the main authentication between the terminal device and the security network element is not limited, and can refer to the description of the main authentication between the terminal device and the security network element in the existing communication standard (such as TS 33.501) or the future communication standard, which will not be described in detail here.

[0242] Further, after the first network element receives the second request message, the first network element feeds back a second response message responding to the second request message to the first communication device, and the method flow shown in FIG. 7 further includes:

[0243] S720, the first network element sends the second response message to the first communication device, and correspondingly, the first communication device receives the second response message from the first network element.

[0244] Specifically, the second response message is used for negotiating and determining the security context of the first NAS connection. Optionally, the second response message can be referred to as a NAS command message.

[0245] Optionally, the first communication device can indicate the completion of the negotiation of the security context of the first NAS connection through a NAS complete message. For example, the first communication device can send a NAS complete message to the first network element, and the NAS complete message is used to indicate the completion of the negotiation of the security context of the first NAS connection.

[0246] S721, the first communication device and the first network element determine the security context of the first NAS connection.

[0247] For example, the first communication device and the first network element determine the key in the security context of the first NAS connection, such as determining Ksmf.

[0248] It should be understood that the determination of the security context of the first NAS connection by the first communication device and the first network element in step S721 includes that the first communication device determines the security context of the first NAS connection, and the first network element determines the security context of the first NAS connection. In this application, the sequence of the determination of the security context of the first NAS connection by the first communication device and the determination of the security context of the first NAS connection by the first network element is not limited, which can be that the first communication device determines the security context of the first NAS connection first, or the first network element determines the security context of the first NAS connection first, or the first communication device and the first network element determine the security context of the first NAS connection at the same time.

[0249] Exemplarily, after the first communication device and the first network element determine the security context of the first NAS connection, the first communication device can determine the second security context based on the identity of the first task and the third security context, where the third security context is determined based on the security context of the first NAS connection, according to the manner 1.1 in FIG. 6. In this embodiment, the second security context is the same as the first security context. The method flow shown in FIG. 7 further includes:

[0250] S730, the first communication device determines to perform the first task, and generates an identity of the first task.

[0251] S740, the first communication device determines the second security context based on the identity of the first task and the third security context.

[0252] Specifically, the third security context is determined based on the security context of the first NAS connection, and can be that the third security context is the security context of the first NAS connection, or the third security context is determined based on the security context of the first NAS connection. For example, the third security context is a third key, which can be the key of the first NAS connection, or the third key can be a lower key of the key of the first NAS connection.

[0253] Optionally, if the security context of the first NAS connection is an SMF key (Ksmf), the third security context can be Ksmf, or can be a key (for example, an SMF integrity key (Ksmf-int)) lower than Ksmf. In this application, how to generate Ksmf-int is not limited, for example, Ksmf-int = KDF (Ksmf, integrity protection algorithm ID), where KDF is a key derivation function, for example, KDF is a key derivation function (KDF). In this application, the lower key of a certain key can also be referred to as the sub-key of the key, or the derivation key derived by the key derivation, etc. In this application, the name of the key is not limited in any way.

[0254] Exemplarily, the second security context can be determined based on the identity of the first task and the third security context by a key derivation function, for example, second security context = KDF (third security context, identity of the first task).

[0255] Optionally, other input parameters of the KDF are not limited, for example, an identity of network slice selection assistance information (NSSAI) can also be input into the KDF, used for guaranteeing slice session granularity key generation, in addition, a count value or an algorithm ID can also be input, used for guaranteeing freshness. The count value can be used to represent count information of the first communication device and the network side sending information for the first task.

[0256] Optionally, the number of times of the KDF is not limited, and the number of layers of the final security protection key is not limited. For example, the second security context can be derived multiple times, for example, second security context #1 = KDF (third security context, identity of the first task), second security context #2 = KDF (second security context #1, encryption algorithm ID), and the second security context can be the second security context #2.

[0257] S750, the first communication device sends a first request message to the first network element, and correspondingly, the first network element receives the first request message from the first communication device.

[0258] Specifically, the first request message is used to request to perform the first task. For example, the first communication device sends the first request message to the first network element through the established first NAS connection.

[0259] For example but not limitation, the first request message includes an identity of the first communication device and an identity of the first task. The identity of the first communication device is used to identify the first communication device, and the identity of the first task is used to identify the first task currently requested to be performed.

[0260] Optionally, the first request message includes a message authentication code (MAC), and the MAC is used to securely protect (such as integrity protection) the first request message. The message authentication code is determined based on the second security context. For example, the message authentication code can be generated based on the key in the second security context, or the message authentication code can be generated based on a lower key of the key in the second security context.

[0261] S760, the first network element determines the first security context based on the identity of the first task and the third security context.

[0262] Specifically, after receiving the first request message, the first network element can obtain the identifier of the first task from the first request message, and then determine the first security context based on the identifier of the first task and the third security context. In the communication method shown in FIG. 7, the second security context is the same as the first security context.

[0263] For example, the process in which the first network element determines the first security context can refer to the description of the process in which the first communication device determines the second security context based on the identifier of the first task and the third security context in step S740, which will not be repeated here.

[0264] It should be understood that in this implementation, the security context is taken as an example for illustration. The derivation processes of the first security context determined by the first communication device side and the first network element are shown in FIG. 8. As shown in FIG. 8, the SMF key (Ksmf) shown in FIG. 8 can be the security context of the first NAS connection, the third security context can be the SMF integrity key (Ksmf-int) or Ksmf shown in FIG. 8, and the determination of the first security context or the second security context based on the identifier of the first task and the third security context can be the PDU key (Kpdu) or the key (Kpdu-enc) derived from the PDU key shown in FIG. 8.

[0265] In addition, as shown in FIG. 8, the Ksmf can be derived from the AUSF key (Kausf) and the SEAF key (Kseaf), and the specific derivation process can refer to the description of the negotiation of the NAS security context between the terminal device and the AMF (such as the process shown in FIG. 4 above), which will not be repeated here.

[0266] S761, the first network element performs security verification on the first request message.

[0267] Specifically, the first network element can perform security verification on the first request message based on the first security context. For example, according to the reception of the first request message, the security information (such as MAC) is obtained, and the security verification is performed through the first security context, such as verifying the integrity protection.

[0268] Optionally, if the first network element fails to perform security verification on the first request message, an indication of verification failure can be returned, so that the first communication device can re-initiate the first request message or give up performing the first task.

[0269] It should be noted that in this embodiment, the first network element can determine the first security context based on the identifier of the first task and the third security context, and the implementation mode in which the first network element performs security verification on the first request message based on the first security context (i.e., the mode of performing steps S760 and S761) can be:

[0270] As a possible implementation, the first communication apparatus can transmit the parameters required for generating the first security context, such as the identity of the first task, to the first network element through a message #1, which can be secured by other security protection manners, for example, can be secured by a hardware security protection manner; for another example, is transmitted by an out-of-band manner; for another example, is transmitted by using a physical layer security technology, and the like. The security protection manner of the message #1 is not limited in this embodiment.

[0271] In this implementation, the first network element can determine the first security context based on the parameters required for generating the first security context transmitted in the message #1 and the third security context, and perform security verification on the first request message based on the first security context, that is, perform steps S760 and S761 described above. In addition, it should be noted that in this implementation, the first request message sent by the first communication apparatus can not carry the parameters required for generating the first security context, such as the identity of the first task, which is transmitted by the message #1 described above, and the first request message can not carry the parameters required for generating the first security context.

[0272] As another possible implementation, the first request message includes the message #1, and the message #1 includes the parameters required for generating the first security context, such as the identity of the first task. And the message #1 is secured by other manners instead of being secured based on the first security context, for example, can be secured by a hardware security protection manner; for another example, is transmitted by an out-of-band manner; for another example, is transmitted by using a physical layer security technology, and the like. The security protection manner of the message #1 is not limited in this embodiment. Or, the parameters required for generating the first security context carried in the first request message are secured by other manners instead of being secured based on the first security context.

[0273] In this implementation, the first network element can obtain the parameters required for generating the first security context based on the first request message, determine the first security context based on the parameters required for generating the first security context and the third security context, and perform security verification on the first request message based on the first security context, that is, perform steps S760 and S761 described above.

[0274] It should be understood that the above two implementation manners of performing the steps S760 and S761 are only examples, and do not limit the protection scope of the present application, and the above manner of transmitting the parameters required for generating the first security context by the first communication device is only an example. For example, the first communication device can also transmit the parameters required for generating the first security context to the first network element through other secure transmission manners, which will not be illustrated one by one here. In this embodiment, the first network element can obtain the parameters required for generating the first security context before generating the first security context, and the parameters required for generating the first security context can be securely protected through a protection manner other than the first security context during transmission.

[0275] S770, the first network element sends a first response message to the first communication device, and correspondingly, the first communication device receives the first response message from the first network element.

[0276] The step S770 can refer to the description of the step S620 in the above FIG. 6, which will not be repeated here.

[0277] Further, after receiving the first response message, the first communication device can perform security verification on the first response message based on the second security context. In addition, the first communication device and the first communication device can use the second security context or the security context associated therewith to perform communication security protection on the signaling related to the first task.

[0278] FIG. 9 is a schematic flowchart of another communication method provided by the present application. The following steps are included:

[0279] S910, the first communication device sends a third request message to the security network element, and correspondingly, the security network element receives the third request message from the first communication device.

[0280] Specifically, the third request message is used to request to establish a second NAS connection with the security network element. For example, if the security network element is an AUSF, the second NAS connection can be referred to as a NAS-AUSF connection.

[0281] As a possible implementation manner, in this embodiment, the related messages in the process of establishing the second NAS connection between the first communication device and the security network element can be directly interacted between the first communication device and the security network element.

[0282] As another possible implementation manner, in this embodiment, the related messages in the process of establishing the second NAS connection between the first communication device and the security network element can be realized through forwarding by other network elements. For example, the forwarding can be realized through a second network element (such as an anchor network element) or an AMF.

[0283] It should be noted that the related messages in the process of establishing the NAS connection between the first communication device and the core network element (e.g., the first network element, the security network element or other core network elements) in the present application are all forwarded through the access network device, for example, the access network device has a routing function to find a suitable core network element and perform message forwarding.

[0284] Exemplarily, the third request message includes an identifier of the first communication device.

[0285] Optionally, the second NAS connection requested to be established by the third request message can be understood as a NAS connection between the first communication device and the security network element, which can also be referred to as a non-access layer connection, a communication connection between the first communication device and the security network element, a second connection between the first communication device and the security network element, etc. The name of the second NAS connection is not limited in the present application.

[0286] Exemplarily, the security network element can be an AUSF network element located in the HPLMN, or other network elements.

[0287] By way of example but not limitation, before the first communication device sends the third request message to the security network element, the method flow shown in FIG. 9 can further include:

[0288] S901, the first communication device and the access network device establish an RRC connection.

[0289] For the description of step S701 in FIG. 7, it will not be repeated here.

[0290] S920, the security network element sends a third response message to the first communication device, and correspondingly, the first communication device receives the third response message from the security network element.

[0291] Specifically, the third response message is used to negotiate and determine the security context of the second NAS connection, so that the first communication device and the security network element determine the security context of the second NAS connection. Optionally, the third response message can be referred to as a NAS command message.

[0292] Optionally, the first communication device can indicate that the negotiation of the security context of the second NAS connection is completed through a NAS complete message.

[0293] S930, the first communication device and the security network element determine the security context of the second NAS connection.

[0294] Exemplarily, the first communication device and the security network element perform a primary authentication procedure, for example, an authentication and key agreement (AKA) authentication. After the authentication is completed, the security network element and the first communication device can generate a primary NAS security context (i.e., a security context of the second NAS connection) according to a pre-configured algorithm. The primary NAS security context is used to generate a subsequently required NAS security context.

[0295] It should be understood that the security context of the second NAS connection can be generated in the process of the primary authentication. For example, the first communication device and the security network element can negotiate security parameters in the process of the primary authentication, and then derive the security context of the second NAS connection by using the root key of the first communication device stored at the network side and the security parameters. Alternatively, the security context of the second NAS connection can also be generated after the process of the primary authentication. For example, after the primary authentication is completed, the first communication device and the security network element transmit a NAS security negotiation downlink message to realize negotiation of the security context of the second NAS connection.

[0296] Alternatively, the security network element records an association relationship between the identity of the first communication device and the security context of the second NAS connection, and determines the security capability of the first communication device.

[0297] Exemplarily, the first communication device and the security network element can determine a key in the security context of the second NAS connection, for example, determine a master key (e.g., Knas).

[0298] It should be understood that the determination of the security context of the second NAS connection by the first communication device and the security network element in step S930 includes that the first communication device determines the security context of the second NAS connection, and the security network element determines the security context of the second NAS connection. In the present application, the sequence of the determination of the security context of the second NAS connection by the first communication device and the determination of the security context of the second NAS connection by the security network element is not limited, which can be that the first communication device determines the security context of the second NAS connection first, or the security network element determines the security context of the second NAS connection first, or the first communication device and the security network element determine the security context of the second NAS connection simultaneously.

[0299] Exemplarily, after the first communication device and the first network element determine the security context of the first NAS connection, the first communication device can determine a second security context based on the identity of the first task and a third security context according to the method 1.2 in FIG. 6, wherein the third security context is determined based on the security context of the first NAS connection. In this embodiment, the second security context is the same as the first security context. The method flow shown in FIG. 9 further includes:

[0300] S931, the first communication device determines to perform the first task, and generates an identity of the first task.

[0301] S940, the first communication device determines a second security context based on the identity of the first task and the third security context.

[0302] Specifically, the third security context is determined based on the security context of the second NAS connection, which can be that the third security context is the security context of the second NAS connection, or the third security context is determined based on the security context of the second NAS connection. For example, the third security context is a third key, which can be a key in the security context of the second NAS connection, or the third key can be a lower key of the key in the security context of the second NAS connection.

[0303] Optionally, if the security context of the second NAS connection is a NAS key (Knas), the third security context can be Knas, or a key lower than Knas (such as a NAS integrity key (Knas-int)). In this application, how to generate Knas-int is not limited, for example, Knas-int = KDF (Knas, integrity protection algorithm ID), wherein KDF is a key derivation function.

[0304] Exemplarily, the second security context can be determined based on the identity of the first task and the third security context by a key derivation function. The specific derivation process can refer to the description of the first communication device determining the second security context based on the identity of the first task and the third security context in the communication method shown in FIG. 7, which will not be repeated here.

[0305] S950, the first communication device sends a first request message to the first network element, and correspondingly, the first network element receives the first request message from the first communication device.

[0306] Specifically, the first request message is used to request to perform the first task.

[0307] As an example but not limitation, the first request message includes an identity of the first communication device and an identity of the first task. The identity of the first communication device is used to identify the first communication device, and the identity of the first task is used to identify the first task currently requested to be performed.

[0308] Optionally, the first request message includes a MAC, which is used to securely protect (such as integrity protection) the first request message. The message authentication code is determined based on the second security context. For example, the message authentication code can be generated based on a key in the second security context, or the message authentication code can be generated based on a lower key of the key in the second security context.

[0309] In addition, in this embodiment, the first request message further comprises information of the security network element, which is used by the first network element to determine the security network element, or used by other network elements to determine the security network element.

[0310] For example, the information of the security network element can be an identifier of a home PLMN, such as an HPLMN ID; for another example, the information of the security network element can be address information of the security network element, such as routing indication information. In this application, the specific form of the information of the security network element is not limited, and any information capable of determining the security network element is within the protection scope of this application.

[0311] Optionally, the first request message can further comprise second indication information, which is used to indicate the type of the first task, so that the first network element requests a security context of a corresponding type, for example, a security context of a session type, and the second indication information is used to indicate that the NAS type is SM. Or, the identifier corresponding to the security context of the SM type is 1, and the second indication information is used to indicate that the NAS type is 1.

[0312] Optionally, the type of the first task can be indicated implicitly. For example, the name of the first request message implicitly carries information indicating the type of the first task, such as the first request message being called a session establishment request message, which implicitly indicates that the NAS type is SM.

[0313] In this embodiment, the manner in which the first network element obtains the first security context in step S612 includes but is not limited to the following two manners:

[0314] As a possible implementation manner, the first network element directly obtains the first security context from the security network element.

[0315] In this implementation manner, the method flow shown in FIG. 9 further comprises:

[0316] S961, the first network element sends a fourth request message to the security network element, and correspondingly, the security network element receives the fourth request message from the first network element.

[0317] The first network element can determine the corresponding security network element based on the information of the security network element carried in the received first request message, and request the first security context from the security network element. Specifically, the fourth request message is used to request the first security context, and the fourth request message comprises an identifier of the first communication device and an identifier of the first task. The identifier of the first communication device is used to indicate that the security network element provides a security context corresponding to the first communication device.

[0318] For example, the security context #1 corresponding to the first communication device #1, the security context #2 corresponding to the first communication device #2, and the security context #3 corresponding to the first communication device #3 are included in the security network element, wherein the identity of the first communication device #1, the identity of the first communication device #2, and the identity of the first communication device #3 are different, and by carrying the identity of the first communication device in the fourth request message, it is clear which security context corresponding to the first communication device is required by the first network element.

[0319] Optionally, the fourth request message further includes the second indication information described above, used to indicate the type of the first task. The second indication information can indicate that the security network element provides the security context corresponding to the first task.

[0320] For example, the security network element can determine the security context #1 corresponding to the task #1 of the first communication device, the security context #2 corresponding to the task #2, and the security context #3 corresponding to the task #3, wherein the type of the task #1 and the type of the task #2 are the same, the type of the task #1 and the type of the task #3 are different, and by carrying the second indication information indicating the type of the first task in the fourth request message, it is clear which type of task corresponding to the security context is required by the first network element.

[0321] S962, the security network element determines the first security context based on the identity of the first task and the third security context.

[0322] Specifically, after the security network element receives the fourth request message described above, the identity of the first task can be obtained from the fourth request message, and then the first security context is determined based on the identity of the first task and the third security context. In the communication method shown in FIG. 9, the second security context is the same as the first security context.

[0323] For example, the process of determining the first security context by the security network element can refer to the description of determining the second security context by the first communication device based on the identity of the first task and the third security context in step S940, which will not be described here.

[0324] It should be understood that in this implementation, the security context is taken as an example for illustration. The deduction process of the first security context determined by the first communication device side and the security network element is shown in FIG. 10. As shown in FIG. 10, the NAS key (Knas) shown in FIG. 10 can be the security context of the second NAS connection described above, the third security context can be the NAS integrity key (Knas-int) or Knas shown in FIG. 10, and the first security context or the second security context determined based on the identity of the first task and the third security context can be the PDU key (Kpdu) or the key (Kpdu-enc) derived by the PDU key shown in FIG. 10.

[0325] S963, the security network element sends a fourth response message to the first network element, and correspondingly, the first network element receives the fourth response message from the security network element.

[0326] The fourth response message includes the first security context described above.

[0327] Optionally, in this implementation, the first network element can also request the security network element to perform security verification on the first request message, and the method flow shown in FIG. 9 can further include:

[0328] S964, the first network element sends a fifth request message to the security network element, and correspondingly, the security network element receives the fifth request message from the first network element.

[0329] Specifically, the fifth request message is used to request security verification on the first request message. The fifth request message includes the security information carried by the first request message, such as the MAC. Optionally, the fifth request message can carry the entire first request message, or the digest, hash value, etc. of the first request message, to assist the security network element in performing security verification on the first request message.

[0330] Optionally, the fifth request message can be combined with the fourth request message described above, that is, the fourth request message can request the security network element to perform security verification on the first request message and request to obtain the first security context.

[0331] Optionally, if the first request message described above is a PDU session establishment request message, the fifth request message can be referred to as a session integrity verification request message.

[0332] S965, the security network element performs security verification on the first request message based on the first security context.

[0333] Step S965 can refer to the description of step S761 in FIG. 7 described above, and will not be described here again.

[0334] S966, the security network element sends a fifth response message to the first network element, and correspondingly, the first network element receives the fifth response message from the security network element.

[0335] The fifth response message is used to indicate the security verification result of the first request message, such as indicating that the security verification result is that the first request message is valid or invalid.

[0336] Optionally, the fifth response message can be combined with the fourth response message described above, that is, the fourth response message can feed back the first security context and the security verification result of the first request message.

[0337] As another possible implementation, the first network element can obtain the first security context from the security network element through other network elements.

[0338] In this implementation, the method flow shown in FIG. 9 further includes:

[0339] S971, the first network element sends a fourth request message to the second network element, and correspondingly, the second network element receives the fourth request message from the first network element.

[0340] Specifically, the fourth request message is used to request to obtain the first security context, and the fourth request message includes the identifier of the first communication device and the identifier of the first task.

[0341] Optionally, the fourth request message further includes the second indication information, which is used to indicate the type of the first task.

[0342] In addition, in this implementation, the fourth request message further includes the information of the security network element, and the information of the security network element is used for the second network element to determine the security network element.

[0343] Optionally, the second network element can be an anchor network element, for example, the second network element is a security anchor function (SEAF).

[0344] S972, the second network element sends a request message #1 to the security network element, and correspondingly, the security network element receives the request message #1 from the second network element.

[0345] Specifically, the request message #1 is used to request to obtain the security context of the second NAS connection, and the request message #1 includes the identifier of the first communication device.

[0346] Optionally, the request message #1 further includes the second indication information, which is used to indicate the type of the first task.

[0347] S973, the security network element sends a response message #1 to the second network element, and correspondingly, the second network element receives the response message #1 from the security network element.

[0348] The response message #1 includes the security context of the second NAS connection.

[0349] S974, the second network element determines the first security context based on the identifier of the first task and the third security context.

[0350] Specifically, after the second network element receives the fourth request message, the second network element can obtain the identifier of the first task from the fourth request message, and obtain the security context of the second NAS connection from the response message #1, and then determine the first security context based on the identifier of the first task and the third security context.

[0351] Exemplarily, the process that the security network element determines the first security context can refer to the description that the first communication device determines the second security context based on the identity of the first task and the third security context in step S940, which is not repeated here.

[0352] It should be understood that in this implementation, the security context is taken as an example for illustration. The derivation process of the second network element to determine the first security context is shown in FIG. 10, which is not repeated here.

[0353] S975, the second network element sends a fourth response message to the first network element, and correspondingly, the first network element receives the fourth response message from the second network element.

[0354] The fourth response message includes the first security context described above.

[0355] Optionally, in this implementation, the first network element can request the second network element to perform security verification on the first request message, and then the method flow shown in FIG. 9 can further include:

[0356] S976, the first network element sends a fifth request message to the second network element, and correspondingly, the second network element receives the fifth request message from the first network element.

[0357] Specifically, the fifth request message is used to request security verification on the first request message. The fifth request message includes the security information carried by the first request message, such as the MAC. Optionally, the fifth request message can carry the entire first request message, or the digest, hash value, etc. of the first request message, to assist the security network element in performing security verification on the first request message.

[0358] Optionally, the fifth request message can be combined with the fourth request message described above, that is, the fourth request message can request the security network element to perform security verification on the first request message and request to obtain the first security context.

[0359] S977, the second network element performs security verification on the first request message based on the first security context.

[0360] Step S977 can refer to the description of step S761 in FIG. 7 described above, which is not repeated here.

[0361] S978, the second network element sends a fifth response message to the first network element, and correspondingly, the first network element receives the fifth response message from the second network element.

[0362] The fifth response message is used to indicate the security verification result of the first request message, such as indicating that the security verification result is that the first request message is valid or invalid.

[0363] Optionally, the fifth response message can be combined with the fourth response message described above, that is, the fourth response message can feed back the first security context and the security verification result of the first request message.

[0364] As can be seen from the above, in this embodiment, the first network element can obtain the first security context through the two implementation manners described above. In one implementation manner, the first network element obtains the first security context from the security network element. In this implementation manner, the first network element can establish a communication connection between a border network element such as a security edge protection proxy (SEPP) or a service communication proxy (SCP) and the security network element, and the prerequisite for the first network element and the security network element to be able to interact is that the security network element needs to establish a communication connection with multiple first network elements. In this way, different first network elements can obtain the first security context from the security network element through the border network element. In another implementation manner, the first network element obtains the first security context from the security network element through the second network element. In this implementation manner, the security network element and the second network element establish a communication connection, and then the first network element can obtain the first security context from the security network element through the second network element.

[0365] Further, after the first network element obtains the first security context through the two manners described above, if the first network element does not request the security network element or the second network element to perform security verification on the first request message, the first network element can perform security verification on the first request message based on the first security context, and then the method flow shown in FIG. 9 can further include:

[0366] S970, the first network element performs security verification on the first request message.

[0367] Specifically, the first network element can perform security verification on the first request message based on the first security context.

[0368] S980, the first network element sends a first response message to the first communication device, and correspondingly, the first communication device receives the first response message from the first network element.

[0369] Step S770 can refer to the description of step S620 in FIG. 6 described above, and will not be described here.

[0370] Further, after the first communication device receives the first response message, the first communication device can perform security verification on the first response message based on the second security context described above. In addition, the first communication device and the first communication device can use the second security context or the security context associated therewith to perform communication security protection on the signaling related to the first task.

[0371] FIG. 11 is a schematic flow chart of another communication method provided in the present application. The method comprises the following steps:

[0372] S1110, the first communication device sends a third request message to the security network element, and correspondingly, the security network element receives the third request message from the first communication device.

[0373] S1101, an RRC connection is established between the first communication device and the access network device.

[0374] S1120, the security network element sends a third response message to the first communication device, and correspondingly, the first communication device receives the third response message from the security network element.

[0375] S1130, the first communication device and the security network element determine a security context of the second NAS connection.

[0376] The steps S1110 to S1130 can refer to the description of the steps S910 to S930 in FIG. 9, which will not be repeated here.

[0377] S1140, the security network element sends first indication information to the first communication device, and correspondingly, the first communication device receives the first indication information from the security network element.

[0378] The first indication information is used to indicate the first algorithm. For example, the security network element determines an algorithm identification list (ID list) of the first communication device. The present application does not limit the way how the security network element determines the algorithm supported by the first communication device, for example, the security network element can obtain the algorithm list supported by the first communication device by querying the subscription information of the first communication device before or after the primary authentication.

[0379] S1150, the first communication device determines a fourth security context according to the first algorithm and the security context of the second NAS connection.

[0380] As a possible implementation manner, the first communication device selects different first algorithms corresponding to different types of tasks in the process of generating the fourth security context, for example, the first communication device selects the algorithm according to the algorithm ID, selects the advanced encryption standard (AES)-128 algorithm for NAS-MM, and the algorithm ID is recorded as 001, selects the AES-256 algorithm for NAS-SM, and the algorithm ID is recorded as 002. Then, the fourth security context is determined based on the selected algorithm and the security context of the second NAS connection, for example, the fourth security context = KDF (002, the security context of the second NAS connection). The input parameters of KDF can also have other parameters, which will not be listed here.

[0381] As another possible implementation, in the process of generating the fourth security context by the first communication device, different types of tasks can be identified by the second indication information (e.g., NAS-type). In this implementation, the first algorithm described above can be device-specific for the first communication device, for example, the first communication device selects the algorithm according to the algorithm ID, and selects the AES-128 algorithm for both NAS-MM and NAS-SM, and the algorithm ID is recorded as 001. Then, the fourth security context is determined based on the selected algorithm, the first indication information, and the security context of the second NAS connection, for example, the fourth security context = KDF (NAS-type, security context of the second NAS connection). The input parameters of KDF can also have other parameters, which are not listed here.

[0382] Exemplarily, after the first communication device and the first network element determine the fourth security context, referring to the mode 1.3 in FIG. 6 described above, the first communication device can determine the second security context based on the identification of the first task and the third security context, wherein the third security context is determined based on the fourth security context. In this embodiment, the second security context is the same as the first security context. The method flow shown in FIG. 11 further includes:

[0383] S1160, the first communication device determines to perform the first task, and generates an identification of the first task.

[0384] S1170, the first communication device determines the second security context based on the identification of the first task and the third security context.

[0385] Specifically, the third security context is determined based on the fourth security context, which can be that the third security context is the fourth security context, or the third security context is determined based on the fourth security context. For example, the third security context is a third key, which can be a key in the fourth security context, or the third key can be a lower key of the key in the fourth security context.

[0386] Optionally, if the fourth security context is an SM type NAS key (Knas-sm), the third security context can be Knas-sm, or can be a key (e.g., an SM type NAS integrity key (Knas-sm-int)) based on Knas-sm. In this application, how to generate Knas-sm-int is not limited, for example, Knas-sm-int = KDF (Knas-sm, integrity protection algorithm ID), wherein KDF is a key derivation function.

[0387] Exemplarily, the second security context can be determined based on the identity of the first task and the third security context by a key derivation function. For details, reference can be made to the description of the determination of the second security context by the first communication device based on the identity of the first task and the third security context in the communication method shown in FIG. 7, which is not repeated here.

[0388] In S1180, the first communication device sends a first request message to the first network element, and correspondingly, the first network element receives the first request message from the first communication device.

[0389] S1180 can refer to the description of S950 in FIG. 9, which is not repeated here.

[0390] In this embodiment, the manner in which the first network element obtains the first security context in S612 includes but is not limited to the following two manners:

[0391] As a possible implementation manner, the first network element directly obtains the first security context from the security network element.

[0392] In this implementation manner, the method flow shown in FIG. 11 further includes:

[0393] In S1161, the first network element sends a fourth request message to the security network element, and correspondingly, the security network element receives the fourth request message from the first network element.

[0394] S1161 can refer to the description of S961 in FIG. 9, which is not repeated here.

[0395] In S1162, the security network element determines the fourth security context according to the first algorithm and the security context of the second NAS connection.

[0396] Exemplarily, the process in which the security network element determines the fourth security context can refer to the description of the determination of the fourth security context by the first communication device in S1150, which is not repeated here.

[0397] In S1163, the security network element determines the first security context based on the identity of the first task and the third security context.

[0398] Specifically, after receiving the fourth request message, the security network element can obtain the identity of the first task from the fourth request message, and then determine the first security context based on the identity of the first task and the third security context. In the communication method shown in FIG. 11, the second security context is the same as the first security context.

[0399] Exemplarily, the process in which the security network element determines the first security context can refer to the description of the determination of the second security context by the first communication device based on the identity of the first task and the third security context in S1170, which is not repeated here.

[0400] It should be understood that in this implementation, the secure context is taken as an example for illustration. The first communication device side and the secure network element determine the derivation process of the first secure context as shown in FIG. 12. As shown in FIG. 12, the NAS key (Knas) shown in FIG. 12 can be the secure context of the second NAS connection described above, the NAS key of the SM type (Knas-sm) can be the fourth secure context, the third secure context can be the NAS complete key of the SM type (Knas-sm-int) or Knas-sm shown in FIG. 12, and the first secure context or the second secure context determined based on the identity of the first task and the third secure context can be the PDU key (Kpdu) or the key (Kpdu-enc) derived from the PDU key shown in FIG. 12.

[0401] S1164, the secure network element sends a fourth response message to the first network element, and correspondingly, the first network element receives the fourth response message from the secure network element.

[0402] Optionally, in this implementation, the first network element can request the secure network element to perform security verification on the first request message, and then the method flow shown in FIG. 9 can further include:

[0403] S1165, the first network element sends a fifth request message to the secure network element, and correspondingly, the secure network element receives the fifth request message from the first network element.

[0404] S1166, the secure network element performs security verification on the first request message based on the first secure context.

[0405] S1167, the secure network element sends a fifth response message to the first network element, and correspondingly, the first network element receives the fifth response message from the secure network element.

[0406] Steps S1165 to S1167 can refer to the description of steps S964 to S966 of FIG. 9 described above, and will not be described here again.

[0407] As another possible implementation, the first network element can obtain the first secure context from the secure network element through other network elements.

[0408] In this implementation, the method flow shown in FIG. 11 further includes:

[0409] S1171, the first network element sends a fourth request message to the second network element, and correspondingly, the second network element receives the fourth request message from the first network element.

[0410] Step S1171 refers to the description of step S971 of FIG. 9 described above, and will not be described here again.

[0411] S1172, the second network element sends a request message #2 to the security network element, and correspondingly, the security network element receives the request message #2 from the second network element.

[0412] Specifically, the request message #2 is used to request to obtain the fourth security context, and the request message #2 includes the identifier of the first communication device.

[0413] Optionally, the request message #2 further includes the second indication information, which is used to indicate the type of the first task.

[0414] S1173, the security network element determines the fourth security context according to the first algorithm and the security context of the second NAS connection.

[0415] Step S1173 refers to the description of step S1162, which will not be repeated here.

[0416] S1174, the security network element sends a response message #2 to the second network element, and correspondingly, the second network element receives the response message #2 from the security network element.

[0417] The response message #2 includes the fourth security context.

[0418] S1175, the second network element determines the first security context based on the identifier of the first task and the third security context.

[0419] Specifically, after the second network element receives the fourth request message, the second network element can obtain the identifier of the first task from the fourth request message, and obtain the fourth security context from the response message #2, and then determine the first security context based on the identifier of the first task and the third security context. In the communication method shown in FIG. 11, the second security context is the same as the first security context.

[0420] Exemplarily, the process of determining the first security context by the security network element can refer to the description of determining the second security context by the first communication device based on the identifier of the first task and the third security context in step S1170, which will not be repeated here.

[0421] It should be understood that in this implementation, the security context is taken as an example for illustration. The derivation process of the second network element to determine the first security context is shown in FIG. 11, which will not be repeated here.

[0422] S1176, the second network element sends a fourth response message to the first network element, and correspondingly, the first network element receives the fourth response message from the second network element.

[0423] The fourth response message includes the first security context.

[0424] Optionally, in this implementation, the first network element can request the second network element to perform security verification on the first request message, and the method flow shown in FIG. 11 can further include the following steps:

[0425] S1177, the first network element sends a fifth request message to the second network element, and correspondingly, the second network element receives the fifth request message from the first network element.

[0426] S1178, the second network element performs security verification on the first request message based on the first security context.

[0427] S1179, the second network element sends a fifth response message to the first network element, and correspondingly, the first network element receives the fifth response message from the second network element.

[0428] Steps S1177 to S1179 can refer to the description of steps S976 to S978 in FIG. 9 described above, and will not be described here again.

[0429] Further, after the first network element obtains the first security context through the above two manners, if the first network element does not request the security network element or the second network element to perform security verification on the first request message, the first network element can perform security verification on the first request message based on the first security context, and the method flow shown in FIG. 11 can further include the following steps:

[0430] S1181, the first network element verifies the first request message.

[0431] Specifically, the first network element can perform security verification on the first request message based on the first security context.

[0432] S1190, the first network element sends a first response message to the first communication device, and correspondingly, the first communication device receives the first response message from the first network element.

[0433] Step S1190 can refer to the description of step S620 in FIG. 6 described above, and will not be described here again.

[0434] Further, after the first communication device receives the first response message, the first communication device can perform security verification on the first response message based on the second security context described above. In addition, the first communication device and the first communication device can use the second security context or the security context associated therewith to perform communication security protection on the signaling related to the first task.

[0435] FIG. 13 is a schematic flow chart of another communication method provided by the application. The method includes the following steps:

[0436] S1310, the first communication device sends a second request message to the first network element, and correspondingly, the first network element receives the second request message from the first communication device.

[0437] S1301, the RRC connection is established between the first communication device and the access network device.

[0438] S1302, the main authentication is performed between the first communication device and the security network element.

[0439] S1320, the first network element sends the second response message to the first communication device, and correspondingly, the first communication device receives the second response message from the first network element.

[0440] Optionally, the first communication device can indicate the completion of the security context negotiation of the first NAS connection through the NAS complete message.

[0441] S1321, the first communication device and the first network element determine the security context of the first NAS connection.

[0442] Steps S1310 to S1322 can refer to the description of steps S710 to S721 in FIG. 7 described above, and will not be described here.

[0443] Exemplarily, after the first communication device and the first network element determine the security context of the first NAS connection, referring to the method 2.1 in FIG. 6 described above, the first communication device can perform security protection on the first request message based on the second security context, wherein the second security context is determined based on the security context of the first NAS connection. In this embodiment, the second security context is different from the first security context, and the method flow shown in FIG. 13 further includes:

[0444] S1330, the first communication device determines to perform the first task and generates an identifier of the first task.

[0445] S1340, the first communication device sends the first request message to the first network element, and correspondingly, the first network element receives the first request message from the first communication device.

[0446] Optionally, the first request message can be securely protected based on the second security context.

[0447] Specifically, the second security context is determined based on the security context of the first NAS connection, which can be that the second security context is the security context of the first NAS connection, or the second security context is determined based on the security context of the first NAS connection. For example, the second security context is a second key, which can be a key in the security context of the first NAS connection, or the second key can be a lower key of the key in the security context of the first NAS connection.

[0448] Optionally, if the security context of the first NAS connection is a SMF key (Ksmf), the second security context can be the Ksmf, or can be a key based on the Ksmf (e.g. a SMF integrity key (Ksmf-int)). The application does not limit how to generate the Ksmf-int, for example, Ksmf-int = KDF (Ksmf, integrity protection algorithm ID), where KDF is a key derivation function.

[0449] S1350, the first network element performs security verification on the first request message.

[0450] Specifically, the first network element can perform security verification on the first request message based on the security context of the first NAS connection. For example, according to receiving the first request message, obtaining security information (such as MAC), and performing security verification (such as verifying integrity protection) through the security context (such as Ksmf-int or Ksmf) of the first NAS connection.

[0451] S1360, the first network element determines the first security context based on the identity of the first task and the second security context.

[0452] Exemplarily, in the case of successful verification in the above step S1350, the first network element can determine the first security context based on the identity of the first task and the second security context.

[0453] Exemplarily, the first security context can be determined based on the identity of the first task and the second security context through a key derivation function, for example, the first security context = KDF (second security context, identity of the first task).

[0454] Optionally, other input parameters of KDF are not limited, for example, NSSAI ID can also be input in KDF, which is used to ensure slice session granularity key generation, in addition, count value or algorithm ID can also be input, which is used to ensure freshness.

[0455] Optionally, the number of times of KDF and the number of layers of the final security protection key are not limited. For example, the above first security context can be derived multiple times, for example, first security context #1 = KDF (second security context, identity of the first task), first security context #2 = KDF (first security context #1, encryption algorithm ID), and the above first security context can be the first security context #2.

[0456] S1370, the first network element sends a first response message to the first communication device, and correspondingly, the first communication device receives the first response message from the first network element.

[0457] Step S1370 can refer to the description of step S620 in FIG. 6 above, which will not be repeated here.

[0458] S1380, the first communication device determines the first security context based on the identification of the first task and the second security context.

[0459] Exemplarily, the process in which the first communication device determines the first security context can refer to the description of step S1360 in which the first network element determines the first security context based on the identification of the first task and the second security context, which will not be repeated here.

[0460] It should be understood that in this implementation, the security context is taken as an example for illustration. The derivation process of the first security context determined by the first communication device side and the first network element is shown in FIG. 8. As shown in FIG. 8, the SMF key (Ksmf) shown in FIG. 8 can be the security context of the first NAS connection described above, the second security context can be the SMF integrity key (Ksmf-int) or Ksmf shown in FIG. 8, and the first security context determined based on the identification of the first task and the second security context can be the PDU key (Kpdu) or the key (Kpdu-enc) derived from the PDU key shown in FIG. 8.

[0461] Further, after the first communication device receives the first response message, the first communication device can perform security verification on the first response message based on the first security context described above. In addition, the first communication device and the first communication device can use the first security context or the security context associated therewith to perform communication security protection on the signaling related to the first task.

[0462] FIG. 14 is a schematic flowchart of another communication method provided by the present application. The method includes the following steps:

[0463] S1410, the first communication device sends a third request message to the security network element, and correspondingly, the security network element receives the third request message from the first communication device.

[0464] S1401, the first communication device and the access network device establish an RRC connection.

[0465] S1420, the security network element sends a third response message to the first communication device, and correspondingly, the first communication device receives the third response message from the security network element.

[0466] S1430, the first communication device and the security network element determine the security context of the second NAS connection.

[0467] Steps S1410 to S1430 can refer to the description of steps S910 to S930 in FIG. 9 above, which will not be repeated here.

[0468] Exemplarily, after the first communication device and the first network element determine the security context of the second NAS connection, the first communication device can perform security protection on the first request message based on the second security context, where the second security context is determined based on the security context of the second NAS connection, as described above in the manner 2.2 of FIG. 6. In this embodiment, the second security context is different from the first security context, and the method flow shown in FIG. 14 further includes:

[0469] S1440, the first communication device determines to perform the first task and generates an identifier of the first task.

[0470] S1450, the first communication device sends the first request message to the first network element, and correspondingly, the first network element receives the first request message from the first communication device.

[0471] Optionally, the first request message can be security protected based on the second security context.

[0472] Specifically, the second security context is determined based on the security context of the second NAS connection, which can be that the second security context is the security context of the second NAS connection, or the second security context is determined based on the security context of the second NAS connection. For example, the second security context is a second key, which can be a key in the security context of the second NAS connection, or the second key can be a lower key of the key in the security context of the second NAS connection.

[0473] Optionally, if the security context of the second NAS connection is a NAS key (Knas), the second security context can be Knas, or can be a key (e.g., a NAS integrity key (Knas-int)) based on Knas. In this application, how to generate Knas-int is not limited, for example, Knas-int = KDF (Knas, integrity protection algorithm ID), where KDF is a key derivation function.

[0474] In addition, in this embodiment, the first request message can further include information of a security network element, which is used by the first network element to determine the security network element, or is used by other network elements to determine the security network element.

[0475] For example, the information of the security network element can be an identifier of a home PLMN, such as HPLMN ID; for another example, the information of the security network element can be address information of the security network element, such as routing indication information. In this application, the specific form of the information of the security network element is not limited, and any information capable of determining the security network element is within the protection scope of this application.

[0476] Optionally, the first request message can further comprise second indication information, the second indication information being used to indicate the type of the first task, so that the first network element requests a security context of a corresponding type, for example, a security context of a session type, and the second indication information is used to indicate that the NAS type is SM. Alternatively, a security context of the SM type corresponds to an identifier of 1, and the second indication information is used to indicate that the NAS type is 1.

[0477] Optionally, the type of the first task can be implicitly indicated. For example, the name of the first request message implicitly carries information indicating the type of the first task. For example, the first request message is called a session establishment request message, which implicitly indicates that the NAS type is SM.

[0478] In this embodiment, the manner in which the first network element obtains the first security context in step S612 includes but is not limited to the following two manners:

[0479] As a possible implementation manner, the first network element directly obtains the first security context from the security network element.

[0480] In this implementation manner, the method flow shown in FIG. 14 further includes:

[0481] S1461, the first network element sends a fourth request message to the security network element, and correspondingly, the security network element receives the fourth request message from the first network element.

[0482] Step S1461 can refer to the description of step S961 in FIG. 9, and will not be described here.

[0483] S1462, the security network element determines the first security context based on the identifier of the first task and the second security context.

[0484] Specifically, after receiving the fourth request message, the security network element can obtain the identifier of the first task from the fourth request message, and then determine the first security context based on the identifier of the first task and the second security context. In the communication method shown in FIG. 12, the second security context is different from the first security context.

[0485] For example, the process in which the security network element determines the first security context can refer to the description of the process in which the first communication device determines the first security context based on the identifier of the first task and the second security context in step S1280, and will not be described here.

[0486] S1463, the security network element sends a fourth response message to the first network element, and correspondingly, the first network element receives the fourth response message from the security network element.

[0487] Step S1463 can refer to the description of step S963 in FIG. 9, and will not be described here.

[0488] Optionally, in this implementation, the first network element can also request the security network element to perform security verification on the first request message, and the method flow shown in FIG. 9 can further include:

[0489] S1464, the first network element sends a fifth request message to the security network element, and correspondingly, the security network element receives the fifth request message from the first network element.

[0490] The step S1464 can refer to the description of the step S964 in FIG. 9 described above, and will not be described here again.

[0491] S1465, the security network element performs security verification on the first request message based on the second security context.

[0492] Specifically, the security network element can perform security verification on the first request message based on the second security context. For example, according to the received first request message, the security information (such as MAC) is obtained, and the security verification (such as integrity protection verification) is performed through the security context (such as Knas-int or Knas) of the second NAS connection.

[0493] S1466, the security network element sends a fifth response message to the first network element, and correspondingly, the first network element receives the fifth response message from the security network element.

[0494] The step S1466 can refer to the description of the step S966 in FIG. 9 described above, and will not be described here again.

[0495] As another possible implementation, the first network element can obtain the first security context from the security network element through other network elements.

[0496] In this implementation, the method flow shown in FIG. 14 further includes:

[0497] S1471, the first network element sends a fourth request message to the second network element, and correspondingly, the second network element receives the fourth request message from the first network element.

[0498] S1472, the second network element sends a request message #1 to the security network element, and correspondingly, the security network element receives the request message #1 from the second network element.

[0499] S1473, the security network element sends a response message #1 to the second network element, and correspondingly, the second network element receives the response message #1 from the security network element.

[0500] The steps S1471 to S1473 can refer to the description of the steps S971 to S973 in FIG. 9 described above, and will not be described here again.

[0501] S1474, the second network element determines the first security context based on the identifier of the first task and the second security context.

[0502] Specifically, after receiving the fourth request message, the second network element can obtain the first task identifier from the fourth request message, and obtain the second NAS connection security context from the response message #1, and then determine the first security context based on the first task identifier and the second security context.

[0503] Exemplarily, the process of determining the first security context by the security network element can refer to the description of determining the first security context by the first communication device based on the first task identifier and the second security context in step S1380, which will not be repeated here.

[0504] S1475, the second network element sends a fourth response message to the first network element, and correspondingly, the first network element receives the fourth response message from the second network element.

[0505] The fourth response message includes the first security context.

[0506] Optionally, in this implementation, the first network element can also request the second network element to perform security verification on the first request message, and the method flow shown in FIG. 14 can further include:

[0507] S1476, the first network element sends a fifth request message to the second network element, and correspondingly, the second network element receives the fifth request message from the first network element.

[0508] Step S1476 can refer to the description of step S976 in FIG. 9 described above, which will not be repeated here.

[0509] S1477, the second network element performs security verification on the first request message based on the second security context.

[0510] Specifically, the security network element can perform security verification on the first request message based on the security context of the second NAS connection. For example, according to the received first request message, the security information (such as MAC) is obtained, and the security verification is performed through the security context (such as Knas-int or Knas) of the second NAS connection, such as verifying the integrity protection.

[0511] S1478, the second network element sends a fifth response message to the first network element, and correspondingly, the first network element receives the fifth response message from the second network element.

[0512] The fifth response message is used to indicate the security verification result of the first request message, such as indicating that the security verification result is that the first request message is valid or invalid.

[0513] Optionally, the fifth response message can be combined with the fourth response message described above, that is, the fourth response message can feed back the first security context and the security verification result of the first request message.

[0514] For example, if the first network element does not request the security network element or the second network element to perform security verification on the first request message, the first network element can perform security verification on the first request message based on the second security context, and the method flow shown in FIG. 14 can further include:

[0515] S1480, the first network element acquires the security context of the second NAS connection.

[0516] For example, the manner in which the first network element acquires the security context of the second NAS connection can refer to the manner in which the first network element acquires the first security context described above, such as the first network element directly requesting the security network element to acquire the security context of the second NAS connection, or requesting the security network element to acquire the security context of the second NAS connection through the second network element, which will not be described herein again.

[0517] In addition, it should be noted that in the case of performing the above step S1480, the first network element can determine the second security context based on the security context of the second NAS connection, and can determine the first security context based on the identifier of the first task and the second security context, so that the process of acquiring the first security context from the security network element and / or the second network element described above can be omitted. Herein will not be described again.

[0518] S1481, the first network element performs security verification on the first request message.

[0519] Specifically, the first network element can perform security verification on the first request message based on the second security context.

[0520] S1482, the first network element sends a first response message to the first communication device, and correspondingly, the first communication device receives the first response message from the first network element.

[0521] Step S1482 can refer to the description of step S620 in FIG. 6 described above, which will not be described herein again.

[0522] S1490, the first communication device determines the first security context based on the identifier of the first task and the second security context.

[0523] Step S1490 can refer to the description of step S1380 in FIG. 12 described above, which will not be described herein again.

[0524] It should be understood that in this implementation, the secure context is taken as an example for illustration. The first communication device side, the secure network element, and the second network element determine the derivation process of the first secure context as shown in FIG. 10. As shown in FIG. 10, the NAS key (Knas) shown in FIG. 10 can be the secure context of the second NAS connection described above, the second secure context can be the NAS integrity key (Knas-int) or Knas shown in FIG. 10, and the first secure context determined based on the identity of the first task and the second secure context can be the PDU key (Kpdu) or the key (Kpdu-enc) derived from the PDU key shown in FIG. 10.

[0525] Further, after the first communication device receives the first response message, the first communication device can perform security verification on the first response message based on the first secure context described above. In addition, the first communication device and the first communication device can use the first secure context or the associated secure context to perform communication security protection on the signaling related to the first task.

[0526] FIG. 15 is a schematic flowchart of another communication method provided by the present application. The method includes the following steps:

[0527] S1510, the first communication device sends a third request message to the secure network element, and correspondingly, the secure network element receives the third request message from the first communication device.

[0528] S1501, the first communication device and the access network device establish an RRC connection.

[0529] S1520, the secure network element sends a third response message to the first communication device, and correspondingly, the first communication device receives the third response message from the secure network element.

[0530] S1530, the first communication device and the secure network element determine the secure context of the second NAS connection.

[0531] S1540, the secure network element sends first indication information to the first communication device, and correspondingly, the first communication device receives the first indication information from the secure network element.

[0532] S1550, the first communication device determines a fourth secure context according to a first algorithm and the secure context of the second NAS connection.

[0533] Steps S1510 to S1550 can refer to the description of steps S1110 to S1150 in FIG. 11 described above, and will not be described here.

[0534] Exemplarily, after the first communication device and the first network element determine the fourth security context, the first communication device can perform security protection on the first request message based on a second security context, wherein the second security context is determined based on the fourth security context, as described above in the manner 2.3 in FIG. 6. In this embodiment, the second security context is different from the first security context, and the method flow shown in FIG. 15 further includes:

[0535] S1560, the first communication device determines to perform the first task and generates an identifier of the first task.

[0536] S1570, the first communication device sends the first request message to the first network element, and correspondingly, the first network element receives the first request message from the first communication device.

[0537] Optionally, the first request message can be security protected based on the second security context.

[0538] Specifically, the second security context is determined based on the fourth security context, which can be that the second security context is the fourth security context, or the second security context is determined based on the fourth security context. For example, the second security context is a second key, which can be a key in the fourth security context, or the second key can be a lower key of the key in the fourth security context.

[0539] Optionally, if the fourth security context is an SM type NAS key (Knas-sm), the second security context can be Knas-sm, or can be a key (for example, an SM type NAS integrity key (Knas-sm-int)) lower than Knas-sm. In this application, how to generate Knas-sm-int is not limited, for example, Knas-sm-int = KDF (Knas-sm, integrity protection algorithm ID), wherein KDF is a key derivation function.

[0540] In addition, in this embodiment, the first request message can further include information of a security network element, which is used by the first network element to determine the security network element, or is used by other network elements to determine the security network element.

[0541] For example, the information of the security network element can be an identifier of a home PLMN, such as HPLMN ID; for another example, the information of the security network element can be address information of the security network element, such as routing indication information. In this application, the specific form of the information of the security network element is not limited, and any information capable of determining the security network element is within the protection scope of this application.

[0542] Optionally, the first request message can further comprise second indication information, the second indication information being used to indicate the type of the first task, so that the first network element requests a security context of a corresponding type, for example, a security context of a session type, and the second indication information is used to indicate that the NAS type is SM. Alternatively, the identity corresponding to the security context of the SM type is 1, and the second indication information is used to indicate that the NAS type is 1.

[0543] Optionally, the type of the first task can be implicitly indicated. For example, the name of the first request message implicitly carries the indication, for example, the first request message is called a session establishment request message, which implicitly indicates that the NAS type is SM.

[0544] In this embodiment, the manner in which the first network element obtains the first security context in step S612 includes but is not limited to the following two manners:

[0545] As a possible implementation manner, the first network element directly obtains the first security context from the security network element.

[0546] In this implementation manner, the method flow shown in FIG. 15 further includes:

[0547] S1561, the first network element sends a fourth request message to the security network element, and correspondingly, the security network element receives the fourth request message from the first network element.

[0548] S1562, the security network element determines a fourth security context according to the first algorithm and the security context of the second NAS connection.

[0549] Steps S1561 and S1562 refer to the description of steps S1161 and S1162 in FIG. 11, and will not be described here.

[0550] S1563, the security network element determines the first security context based on the identity of the first task and the second security context.

[0551] Specifically, after receiving the fourth request message, the security network element can obtain the identity of the first task from the fourth request message, and then determine the first security context based on the identity of the first task and the second security context. In the communication method shown in FIG. 15, the second security context is the same as the first security context.

[0552] Exemplarily, the process in which the security network element determines the first security context can refer to the description of the process in which the first network element determines the first security context based on the identity of the first task and the second security context in step S1360, and the difference is that the second security context is determined based on the fourth security context in this embodiment, and will not be described here.

[0553] S1564, the security network element sends a fourth response message to the first network element, and correspondingly, the first network element receives the fourth response message from the security network element.

[0554] Optionally, in this implementation, the first network element can also request the security network element to perform security verification on the first request message, and the method flow shown in FIG. 15 can further include:

[0555] S1565, the first network element sends a fifth request message to the security network element, and correspondingly, the security network element receives the fifth request message from the first network element.

[0556] S1566, the security network element performs security verification on the first request message based on the fourth security context.

[0557] S1567, the security network element sends a fifth response message to the first network element, and correspondingly, the first network element receives the fifth response message from the security network element.

[0558] Steps S1565 to S1567 can refer to the description of steps S964 to S966 in FIG. 9 described above, and will not be described here again.

[0559] As another possible implementation, the first network element can obtain the first security context from the security network element through other network elements.

[0560] In this implementation, the method flow shown in FIG. 15 further includes:

[0561] S1571, the first network element sends a fourth request message to the second network element, and correspondingly, the second network element receives the fourth request message from the first network element.

[0562] S1572, the second network element sends a request message #2 to the security network element, and correspondingly, the security network element receives the request message #2 from the second network element.

[0563] S1573, the security network element determines the fourth security context according to the first algorithm and the security context of the second NAS connection.

[0564] S1574, the security network element sends a response message #2 to the second network element, and correspondingly, the second network element receives the response message #2 from the security network element.

[0565] Steps S1571 to S1574 refer to the description of steps S1171 to S1174 in FIG. 11 described above, and will not be described here again.

[0566] S1575, the second network element determines the first security context based on the identifier of the first task and the second security context.

[0567] Specifically, after receiving the fourth request message, the second network element can obtain the identifier of the first task from the fourth request message, and obtain the fourth security context from the response message #2, and then determine the first security context based on the identifier of the first task and the second security context.

[0568] Exemplarily, the process of determining the first security context by the second network element can refer to the description of determining the first security context by the first network element based on the identifier of the first task and the second security context in step S1360, and the difference is that the second security context is determined based on the fourth security context in this embodiment, which will not be described herein.

[0569] S1576, the second network element sends a fourth response message to the first network element, and correspondingly, the first network element receives the fourth response message from the second network element.

[0570] The fourth response message includes the first security context.

[0571] Optionally, in this implementation, the first network element can request the second network element to perform security verification on the first request message, and then the method flow shown in FIG. 11 can further include:

[0572] S1577, the first network element sends a fifth request message to the second network element, and correspondingly, the second network element receives the fifth request message from the first network element.

[0573] S1578, the second network element performs security verification on the first request message based on the fourth security context.

[0574] S1579, the second network element sends a fifth response message to the first network element, and correspondingly, the first network element receives the fifth response message from the second network element.

[0575] Steps S1577 to S1579 can refer to the description of steps S976 to S978 in FIG. 9, which will not be described herein.

[0576] Exemplarily, if the first network element does not request the security network element or the second network element to perform security verification on the first request message, the first network element can perform security verification on the first request message based on the second security context, and then the method flow shown in FIG. 15 can further include:

[0577] S1580, the first network element obtains the fourth security context.

[0578] Exemplarily, the manner of obtaining the fourth security context by the first network element can refer to the manner of obtaining the fourth security context by the first network element, for example, the first network element directly requests the security network element to obtain the fourth security context, or requests the security network element to obtain the fourth security context through the second network element, which will not be described herein.

[0579] In addition, it should be noted that in the case of performing the step S1580, the first network element can determine the second security context based on the fourth security context, and can determine the first security context based on the identity of the first task and the second security context, so that the process of obtaining the first security context from the security network element and / or the second network element can be omitted. Here, no longer elaborated.

[0580] S1581, the first network element performs security verification on the first request message.

[0581] Specifically, the first network element can perform security verification on the first request message based on the fourth security context.

[0582] S1582, the first network element sends a first response message to the first communication device, and correspondingly, the first communication device receives the first response message from the first network element.

[0583] The step S1582 can refer to the description of the step S620 in the above-mentioned FIG. 6, and here no longer elaborated.

[0584] S1590, the first communication device determines the first security context based on the identity of the first task and the second security context.

[0585] The step S1590 can refer to the description of the step S1380 in the above-mentioned FIG. 12, and here no longer elaborated, the difference is that in this embodiment, the second security context is determined based on the fourth security context, and here no longer elaborated.

[0586] It should be understood that in this implementation, the security context is taken as an example for illustration. The deduction process of the first security context determined by the first communication device side, the security network element, and the second network element is shown in FIG. 12. As shown in FIG. 12, the NAS key (Knas) shown in FIG. 12 can be the security context of the second NAS connection described above, the SM type NAS key (Knas-sm) can be the fourth security context, the second security context can be the SM type NAS integrity key (Knas-sm-int) or Knas-sm shown in FIG. 12, the first security context determined based on the identity of the first task and the second security context can be the PDU key (Kpdu) or the key (Kpdu-enc) derived by the PDU key deduction.

[0587] Further, after the first communication device receives the first response message, the first communication device can perform security verification on the first response message based on the first security context described above. In addition, the first communication device and the first communication device can use the first security context or the security context associated therewith to perform communication security protection on the signaling related to the first task.

[0588] It should be understood that the size of the sequence number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to their functions and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0589] It should also be understood that in various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be referred to each other if there is no special description and logical conflict. In addition, the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0590] The above, in combination with FIG. 6 to FIG. 15, details the communication method provided by the embodiments of the present application. The above communication method is mainly introduced from the perspective of interaction between each entity. It can be understood that the first communication device, the first network element, the second network element and the security network element etc. contain the corresponding hardware structure and / or software module for executing each function in order to realize the above functions.

[0591] Those skilled in the art should realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in the present text can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0592] The communication device provided by the present application is described in detail below in combination with FIG. 16 and FIG. 17. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, the content not described in detail can be referred to the above method embodiment, and part of the content will not be described again for the sake of brevity.

[0593] The embodiments of the present application can divide the function modules of the first communication device, the first network element, the second network element and the security network element according to the above method examples, for example, each function module can be divided according to each function, or two or more functions can be integrated in one processing module. The above integrated module can be realized in the form of hardware or software function module. It should be noted that the division of the modules in the embodiments of the present application is illustrative, and is only a logical function division, and actual implementation can have another division way. The following takes dividing each function module according to each function as an example for description.

[0594] Fig. 16 is a schematic block diagram of the communication apparatus 10 according to an embodiment of the present application. The apparatus 10 includes a transceiver unit 11 and a processing unit 12. The transceiver unit 11 can implement corresponding communication functions, and the processing unit 12 can be configured to perform data processing. In other words, the transceiver unit 11 can be configured to perform operations related to receiving and transmitting, and the processing unit 12 can be configured to perform operations other than receiving and transmitting. The transceiver unit 11 can also be referred to as a communication interface or a communication unit.

[0595] Optionally, the apparatus 10 can further include a storage unit 13, which can be configured to store instructions and / or data. The processing unit 12 can read the instructions and / or data stored in the storage unit 13, so that the apparatus can implement the actions of the devices in the foregoing method embodiments.

[0596] In one design, the apparatus 10 can correspond to, or be a component (e.g., a chip) of, the first communication apparatus in the foregoing method embodiments.

[0597] The apparatus 10 can implement the steps or procedures performed by the first communication apparatus in the foregoing method embodiments. In particular, the transceiver unit 11 can be configured to perform operations related to receiving and transmitting of the first communication apparatus in the foregoing method embodiments, and the processing unit 12 can be configured to perform operations related to processing of the first communication apparatus in the foregoing method embodiments.

[0598] In one possible implementation, the transceiver unit 11 is configured to send a first request message to a first network element, where the first request message is used to request performance of a first task, and the first request message includes an identifier of the first task. The transceiver unit 11 is further configured to receive a first response message from the first network element in response to the first request message, where the first response message is secured based on a first security context, and the first security context is determined based on the identifier of the first task.

[0599] When the apparatus 10 is configured to perform the method in Fig. 6, the transceiver unit 11 can be configured to perform the steps of receiving and transmitting information in the method, such as steps S610 and S620, and the processing unit 12 can be configured to perform the processing steps in the method, such as steps S601, S602 and S621.

[0600] When the apparatus 10 is configured to perform the method in Fig. 7, the transceiver unit 11 can be configured to perform the steps of receiving and transmitting information in the method, such as steps S710, S720, S750 and S770, and the processing unit 12 can be configured to perform the processing steps in the method, such as steps S730 and S740.

[0601] When the apparatus 10 is configured to perform the method in FIG. 9, the transceiver unit 11 can be configured to perform the steps of transceiving information in the method, such as steps S910, S920, S950 and S780; the processing unit 12 can be configured to perform the processing steps in the method, such as steps S931 and S940.

[0602] When the apparatus 10 is configured to perform the method in FIG. 11, the transceiver unit 11 can be configured to perform the steps of transceiving information in the method, such as steps S1110, S1120, S1140, S1180 and S1190; the processing unit 12 can be configured to perform the processing steps in the method, such as steps S1150, S1160 and S1170.

[0603] When the apparatus 10 is configured to perform the method in FIG. 13, the transceiver unit 11 can be configured to perform the steps of transceiving information in the method, such as steps S1310, S1320, S1340 and S1370; the processing unit 12 can be configured to perform the processing steps in the method, such as steps S1330 and S1380.

[0604] When the apparatus 10 is configured to perform the method in FIG. 14, the transceiver unit 11 can be configured to perform the steps of transceiving information in the method, such as steps S1410, S1420, S1450 and S1482; the processing unit 12 can be configured to perform the processing steps in the method, such as steps S1440 and S1490.

[0605] When the apparatus 10 is configured to perform the method in FIG. 15, the transceiver unit 11 can be configured to perform the steps of transceiving information in the method, such as steps S1510, S1520, S1540, S1570 and S1582; the processing unit 12 can be configured to perform the processing steps in the method, such as steps S1550, S1560 and S1590.

[0606] It should be understood that the specific procedures of the respective units performing the corresponding steps above have been described in detail in the method embodiments above, and thus will not be repeated here for brevity.

[0607] In another design, the apparatus 10 can correspond to, or be a component (e.g., a chip) of, the first network element in the method embodiments above.

[0608] The apparatus 10 can implement the steps or procedures performed by the first network element in the method embodiments above, where the transceiver unit 11 can be configured to perform the transceiving-related operations of the first network element in the method embodiments above, and the processing unit 12 can be configured to perform the processing-related operations of the first network element in the method embodiments above.

[0609] In a possible implementation, the transceiver 11 is configured to receive a first request message from a first communication device, the first request message being used to request to perform a first task, and the first request message comprising an identity of the first task. The transceiver 11 is further configured to send, to the first communication device, a first response message in response to the first request message, the first response message being secured based on a first security context, the first security context being determined based on the identity of the first task.

[0610] When the apparatus 10 is configured to perform the method in FIG. 6, the transceiver 11 can be configured to perform the steps of transceiving information in the method, such as steps S610 and S620; and the processor 12 can be configured to perform the steps of processing in the method, such as step S612.

[0611] When the apparatus 10 is configured to perform the method in FIG. 7, the transceiver 11 can be configured to perform the steps of transceiving information in the method, such as steps S710, S720, S750 and S770; and the processor 12 can be configured to perform the steps of processing in the method.

[0612] When the apparatus 10 is configured to perform the method in FIG. 9, the transceiver 11 can be configured to perform the steps of transceiving information in the method, such as steps S950, S961, S963, S964, S966, S971, S975, S976, S978 and S780; and the processor 12 can be configured to perform the steps of processing in the method, such as step S970.

[0613] When the apparatus 10 is configured to perform the method in FIG. 11, the transceiver 11 can be configured to perform the steps of transceiving information in the method, such as steps S1180, S1161, S1164, S1165, S1167, S1171, S1176, S1177, S1179 and S1190; and the processor 12 can be configured to perform the steps of processing in the method, such as step S1181.

[0614] When the apparatus 10 is configured to perform the method in FIG. 13, the transceiver 11 can be configured to perform the steps of transceiving information in the method, such as steps S1310, S1320, S1340 and S1370; and the processor 12 can be configured to perform the steps of processing in the method, such as steps S1350 and S1360.

[0615] When the apparatus 10 is configured to perform the method in FIG. 14, the transceiver 11 can be configured to perform the steps of transceiving information in the method, such as steps S1450, S1461, S1463, S1464, S1466, S1471, S1475, S1476, S1478 and S1482; and the processor 12 can be configured to perform the steps of processing in the method, such as steps S1480 and S1481.

[0616] When the apparatus 10 is configured to perform the method in FIG. 15, the transceiver unit 11 can be configured to perform the steps of transmitting and / or receiving information in the method, such as steps S1570, S1561, S1564, S1565, S1567, S1571, S1576, S1577, S1579 and S1582; the processing unit 12 can be configured to perform the steps of processing in the method, such as steps S1580 and S1581.

[0617] It should be understood that the specific process of each unit performing the corresponding steps described above has been described in detail in the method embodiments described above, and will not be described here for brevity.

[0618] In yet another design, the apparatus 10 can correspond to, or be a component (such as a chip) of, the second network element in the method embodiments described above.

[0619] The apparatus 10 can implement the steps or procedures performed by the second network element in the method embodiments described above, wherein the transceiver unit 11 can be configured to perform the operations related to transmitting and / or receiving of the second network element in the method embodiments described above, and the processing unit 12 can be configured to perform the operations related to processing of the second network element in the method embodiments described above.

[0620] In one possible implementation, the transceiver unit 11 is configured to receive a fourth request message from the first network element, the fourth request message being used to request to obtain a first security context, the fourth request message comprising an identifier of a first task, the first security context being used for security protection and / or security verification of signaling related to the first task. The processing unit 12 is configured to determine the first security context according to the identifier of the first task; and send a fourth response message to the first network element, the fourth response message comprising the first security context.

[0621] When the apparatus 10 is configured to perform the method in FIG. 9, the transceiver unit 11 can be configured to perform the steps of transmitting and / or receiving information in the method, such as steps S971, S972, S973, S975, S976 and S978; the processing unit 12 can be configured to perform the steps of processing in the method, such as steps S974 and S977.

[0622] When the apparatus 10 is configured to perform the method in FIG. 11, the transceiver unit 11 can be configured to perform the steps of transmitting and / or receiving information in the method, such as steps S1171, S1172, S1174, S1176, S1177 and S1179; the processing unit 12 can be configured to perform the steps of processing in the method, such as steps S1175, S1178.

[0623] When the apparatus 10 is configured to perform the method in FIG. 14, the transceiver unit 11 can be configured to perform the steps of transmitting and / or receiving information in the method, such as steps S1471, S1472, S1473, S1475, S1476 and S1478; and the processing unit 12 can be configured to perform the steps of processing in the method, such as steps S1474 and S1477.

[0624] When the apparatus 10 is configured to perform the method in FIG. 15, the transceiver unit 11 can be configured to perform the steps of transmitting and / or receiving information in the method, such as steps S1571, S1572, S1574, S1576, S1577 and S1579; and the processing unit 12 can be configured to perform the steps of processing in the method, such as steps S1575 and S1578.

[0625] It should be understood that the specific procedures of the units performing the corresponding steps are described in detail in the above method embodiments, and thus are not described herein again for simplicity.

[0626] In yet another design, the apparatus 10 can correspond to, or be a component (e.g., a chip) of, the security network element in the above method embodiments.

[0627] The apparatus 10 can implement the steps or procedures performed by the security network element corresponding to the above method embodiments, wherein the transceiver unit 11 can be configured to perform the transmission and / or reception related operations of the security network element in the above method embodiments, and the processing unit 12 can be configured to perform the processing related operations of the security network element in the above method embodiments.

[0628] In one possible implementation, the transceiver unit 11 is configured to receive a sixth request message from a second network element, the sixth request message being used to request to obtain a first security context, the sixth request message including an identity of the first communication apparatus and / or second indication information, the second indication information being used to indicate a type of the first task. The processing unit 12 is configured to determine the first security context according to a security context of a second NAS connection; and send a sixth response message to the second network element, the sixth response message including the first security context.

[0629] When the apparatus 10 is configured to perform the method in FIG. 9, the transceiver unit 11 can be configured to perform the steps of transmitting and / or receiving information in the method, such as steps S961, S963, S964, S966; and the processing unit 12 can be configured to perform the steps of processing in the method, such as steps S962 and S965.

[0630] When the apparatus 10 is configured to perform the method in FIG. 11, the transceiver unit 11 can be configured to perform the steps of transceiving information in the method, such as steps S1161, S1164, S1165, S1167; the processing unit 12 can be configured to perform the processing steps in the method, such as steps S1162, S1163 and S1166.

[0631] When the apparatus 10 is configured to perform the method in FIG. 14, the transceiver unit 11 can be configured to perform the steps of transceiving information in the method, such as steps S1461, S1463, S1464, S1466; the processing unit 12 can be configured to perform the processing steps in the method, such as steps S1462 and S1465.

[0632] When the apparatus 10 is configured to perform the method in FIG. 15, the transceiver unit 11 can be configured to perform the steps of transceiving information in the method, such as steps S1561, S1564, S1565, S1567; the processing unit 12 can be configured to perform the processing steps in the method, such as steps S1562, S1563 and S1566.

[0633] It should be understood that the specific procedures of the respective units performing the above respective steps have been described in detail in the above method embodiments, and thus will not be described herein for the sake of brevity.

[0634] It should also be understood that the apparatus 10 herein is embodied in the form of functional units. The term “unit” herein can refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (e.g., a shared processor, a dedicated processor, or a group processor, etc.) and a memory for executing one or more software or firmware programs, a combination of logic circuitry and / or other suitable components that provide the described functionality. In an alternative example, those skilled in the art can understand that the apparatus 10 can be embodied as the mobile management network element in the above embodiments, and can be configured to perform the respective processes and / or steps in the above method embodiments corresponding to the mobile management network element; or the apparatus 10 can be embodied as the terminal device in the above embodiments, and can be configured to perform the respective processes and / or steps in the above method embodiments corresponding to the terminal device, and thus will not be described herein for the sake of brevity.

[0635] The apparatus 10 of each of the above-mentioned solutions has the function of implementing the corresponding steps performed by the entities (e.g., the first communication apparatus, the first network element, the second network element, and the security network element) in the above-mentioned methods. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above-mentioned functions; for example, the transceiving unit can be replaced by a transceiver (e.g., the transmitting unit in the transceiving unit can be replaced by a transmitter, and the receiving unit in the transceiving unit can be replaced by a receiver), and other units, such as the processing unit, can be replaced by a processor, which respectively performs the transceiving operations and related processing operations in each of the method embodiments.

[0636] In addition, the transceiving unit 11 can also be a transceiving circuit (e.g., which can include a receiving circuit and a transmitting circuit), and the processing unit can be a processing circuit.

[0637] FIG. 17 is a schematic diagram of another communication apparatus 20 provided by an embodiment of the present application. The apparatus 20 includes a processor 21 configured to execute computer programs or instructions stored in a memory 22, or read data / signaling stored in the memory 22, to perform the methods in the above-mentioned method embodiments. Optionally, the processor 21 is one or more.

[0638] Optionally, as shown in FIG. 17, the apparatus 20 further includes the memory 22 configured to store computer programs or instructions and / or data. The memory 22 can be integrated with the processor 21, or can be separately arranged. Optionally, the memory 22 is one or more.

[0639] Optionally, as shown in FIG. 17, the apparatus 20 further includes a transceiver 23 configured to receive and / or transmit signals. For example, the processor 21 is configured to control the transceiver 23 to receive and / or transmit signals.

[0640] As one solution, the apparatus 20 is configured to implement the operations performed by the first communication apparatus, the first network element, the second network element, and the security network element in the above-mentioned method embodiments.

[0641] It should be understood that the processor mentioned in the embodiments of the present application can be one or a combination of a central processing unit (CPU), other general-purpose processors, a digital signal processor (DSP), a microprocessor unit (MPU), a microcontroller unit (MCU), a graphics processing unit (GPU), a field programmable gate array (FPGA), an artificial intelligence processor (AI processor), or a neural network processor (NPU); or the processor mentioned in the embodiments of the present application can be an ASIC or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0642] It should also be understood that the memory mentioned in the embodiments of the present application can be a volatile memory and / or a non-volatile memory. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically EPROM (EEPROM) or a flash memory. The volatile memory can be a cache, a random access memory (RAM). For example, the RAM can be used as an external cache. As an example but not limitation, the RAM includes the following various forms: static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DR RAM).

[0643] It should be noted that when the processor is a general processor, a DSP, an ASIC, a FPGA or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, the memory (storage module) can be integrated in the processor.

[0644] It should also be noted that the memory described herein is intended to include, but not limited to, these and any other suitable types of memory.

[0645] The embodiments of the present application also provide a chip system, which can also be referred to as a processing system, including a logic circuit and an input / output interface.

[0646] Among them, the logic circuit can be a processing circuit in the chip system. The logic circuit can be coupled to the storage unit to call the instructions in the storage unit, so that the chip system can realize the methods and functions of the embodiments of the present application. The input / output interface can be an input / output circuit in the chip system, which outputs the processed information of the chip system or inputs the data or signaling information to be processed into the chip system for processing.

[0647] As a solution, the chip system is configured to implement operations performed by the first communication device, the first network element, the second network element and the security network element in the above method embodiments.

[0648] For example, the logic circuit is configured to implement operations related to processing performed by the first communication device, the first network element, the second network element and the security network element in the above method embodiments; and the input / output interface is configured to implement operations related to sending and / or receiving performed by the first communication device, the first network element, the second network element and the security network element in the above method embodiments.

[0649] The embodiments of the present application further provide a computer readable storage medium, having stored thereon computer instructions for implementing the method performed by the first communication device, the first network element, the second network element and the security network element in the above method embodiments.

[0650] For example, the computer program, when executed by a computer, enables the computer to implement the method performed by the first communication device, the first network element, the second network element and the security network element in the above method embodiments.

[0651] The embodiments of the present application further provide a computer program product, comprising instructions, which, when executed by a computer, implement the method performed by the first communication device, the first network element, the second network element and the security network element in the above method embodiments.

[0652] The embodiments of the present application further provide a communication system, comprising the first network element, the second network element and the security network element as described above. Optionally, the communication system further comprises the first communication device as described above.

[0653] The above-described any device related content can refer to the corresponding method embodiments provided above for explanation and beneficial effects, which will not be described herein again.

[0654] Those skilled in the art can clearly understand that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solutions. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0655] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working process of the above-described system, device and unit can refer to the corresponding process in the above method embodiments, which will not be described herein again.

[0656] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. For example, the apparatus embodiments described above are only illustrative, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, apparatuses or units, and can be electrical, mechanical or other forms.

[0657] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place or distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0658] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0659] If the functions are realized in the form of software functional units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the part of the present application that essentially contributes to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes various program code storage media, such as U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk, etc.

[0660] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method characterized by comprising: The method applied to a first communication device comprises: sending a first request message to a first network element, the first request message being used for requesting to perform a first task, and the first request message comprising an identity of the first task; receiving a first response message from the first network element in response to the first request message, the first response message being secured based on a first security context, and the first security context being determined based on the identity of the first task.

2. The method of claim 1, wherein, Before the sending of the first request message to the first network element, the method further comprises: generating the identity of the first task.

3. The method according to claim 1 or 2, characterized in that, The first request message further comprises security information, the security information being determined based on a second security context, and the security information being used for securing the identity of the first task.

4. The method of claim 3, wherein, The security information is used for securing the identity of the first task, comprising: the security information is used for securing the first request message.

5. The method according to claim 3 or 4, characterized in that, The security information comprises a message authentication code (MAC).

6. The method according to any one of claims 3 to 5, characterized in that, The second security context is the same as the first security context, and before the sending of the first request message to the first network element, the method further comprises: determining the second security context based on the identity of the first task and a third security context, and the second security context being used for securing and / or verifying signaling related to the first task.

7. The method according to any one of claims 3 to 5, characterized in that, The second security context is different from the first security context, and after the receiving of the first response message from the first network element in response to the first request message, the method further comprises: determining the first security context based on the identity of the first task and the second security context, and the first security context being used for securing and / or verifying signaling related to the first task.

8. The method according to claim 6 or 7, characterized in that, The method further comprises: sending a second request message to the first network element, the second request message being used for requesting to establish a first non-access stratum (NAS) connection between the first communication device and the first network element, and the second request message comprising an identity of the first communication device; receiving a second response message from the first network element, the second response message being used for negotiating a security context of the first NAS connection, wherein the third security context or the second security context is determined based on the security context of the first NAS connection.

9. The method according to claim 6 or 7, characterized in that, The method further comprises: sending a third request message to a security network element, the third request message being used for requesting to establish a second non-access stratum (NAS) connection between the first communication device and the security network element, and the third request message comprising the identity of the first communication device; receiving a third response message from the security network element, the third response message being used for negotiating a security context of the second NAS connection, wherein the third security context or the second security context is determined based on the security context of the second NAS connection.

10. The method of claim 9, wherein, The method further comprises: receiving first indication information from the security network element, the first indication information being used for indicating a first algorithm; determining a fourth security context according to the first algorithm and the security context of the second NAS connection, wherein the third security context or the second security context is determined based on the fourth security context.

11. The method of claim 10, wherein, The determining a fourth security context according to the first algorithm and the security context of the second NAS connection comprises: determining a fourth security context according to the first algorithm, the security context of the second NAS connection, and second indication information, wherein the second indication information is used to indicate a type of the first task.

12. The method according to any one of claims 1 to 11, characterized in that, The first task comprises any one of: establishing a protocol data unit (PDU) session, a sensing service, or an artificial intelligence (AI) service.

13. The method according to any one of claims 1 to 12, characterized in that, The first network element comprises any one of: a session management function (SMF), a sensing function network element, a data analysis function network element, an analysis logic function network element, or a model training logic function network element.

14. The method according to any one of claims 1 to 13, characterized in that, Before the sending the first request message to the first network element, the method further comprises: performing a primary authentication procedure, the primary authentication procedure being used to authenticate the first communication device.

15. A method of communication, comprising: The method applied to the first network element comprises: receiving a first request message from a first communication device, the first request message being used to request performing a first task, and the first request message comprising an identity of the first task; sending a first response message to the first communication device in response to the first request message, the first response message being secured based on a first security context, and the first security context being determined based on the identity of the first task.

16. The method of claim 15, wherein, The first request message further comprises security information, the security information being determined based on a second security context, and the security information being used to secure the identity of the first task.

17. The method of claim 16, wherein, The security information used to secure the identity of the first task comprises: the security information used to secure the first request message.

18. The method of claim 16 or 17, wherein, The security information comprises a message authentication code (MAC).

19. The method according to any one of claims 15 to 18, characterized in that, The method further comprises: sending a fourth request message, the fourth request message being used to request obtaining the first security context, and the fourth request message comprising the identity of the first task; receiving a fourth response message, the fourth response message comprising the first security context.

20. The method of claim 19, wherein, The method further comprises: sending a fifth request message, the fifth request message being used to request performing security verification on the first request message; receiving a fifth response message, the fifth response message being used to indicate a security verification result of the first request message.

21. The method according to claim 19 or 20, characterized in that, The fourth request message further comprises second indication information, and the second indication information is used to indicate a type of the first task.

22. The method of any one of claims 15-18, wherein, The method further comprises: receiving a second request message from a first communication device, the second request message being used to request establishing a first non-access stratum (NAS) connection between the first communication device and the first network element, and the second request message comprising an identity of the first communication device; sending a second response message to the first communication device, the second response message being used to negotiate and determine a security context of the first NAS connection.

23. The method of claim 22, wherein, The method further comprises: The first security context is determined according to the security context of the first NAS connection and the identity of the first task, and the first security context is used for security protection and / or security verification of signaling related to the first task.

24. The method of any one of claims 15-23, wherein, The first task includes any one of the following: Establishing a protocol data unit (PDU) session, a sensing service, or an artificial intelligence (AI) service.

25. The method of any one of claims 15-24, wherein, The first network element includes any one of the following: A session management function (SMF) network element, a sensing function network element, a data analysis function network element, an analysis logic function network element, or a model training logic function network element.

26. A method of communication, comprising: The method applied to a second network element includes: Receiving a fourth request message from a first network element, the fourth request message being used to request a first security context, and the fourth request message including an identity of a first task, the first security context being used for security protection and / or security verification of signaling related to the first task; Determining the first security context according to the identity of the first task; Sending a fourth response message to the first network element, the fourth response message including the first security context.

27. The method of claim 26, wherein, The second network element is a security network element, and the method further includes: Receiving a third request message from a first communication device, the third request message being used to request establishment of a second non-access stratum (NAS) connection between the first communication device and the security network element, and the third request message including an identity of the first communication device; Sending a third response message to the first communication device, the third response message being used to negotiate a security context of the second NAS connection.

28. The method of claim 27, wherein, The determining of the first security context according to the identity of the first task includes: Determining the first security context according to the identity of the first task and the security context of the second NAS connection.

29. The method of claim 26, wherein, The method further includes: Receiving a fifth request message from a first communication device, the fifth request message being used to request security verification of a first request message, and the fifth request message including security information determined based on a second security context, the security information being used for security protection of an identity of a first task in the first request message, and the first request message being used to request establishment of the first task; Performing security verification of the first request message based on the second security context; Sending a fifth response message to the first communication device, the fifth response message being used to indicate a security verification result of the first request message.

30. The method of claim 29, wherein, The method further includes: Sending a sixth request message to a security network element, the sixth request message being used to request a second security context, and the sixth request message including second indication information used to indicate a type of the first task; Receiving a sixth response message from the security network element, the sixth response message including the second security context.

31. The method of claim 30, wherein, The determining of the first security context according to the identity of the first task includes: Determining the first security context according to the identity of the first task and the second security context.

32. A communications device, characterized by The method includes: One or more functional modules for performing the method of any one of claims 1 to 14, or one or more functional modules for performing the method of any one of claims 15 to 25, or one or more functional modules for performing the method of any one of claims 26 to 31.

33. A communications device, characterized by An apparatus comprising at least one processor coupled with a memory, the at least one processor configured to execute a computer program in the memory to cause the apparatus to perform the method of any one of claims 1 to 14, or to cause the apparatus to perform the method of any one of claims 15 to 25, or to cause the apparatus to perform the method of any one of claims 26 to 31.

34. A computer program product, characterised in that, The computer program product comprises instructions for performing the method of any one of claims 1 to 31.

35. A computer readable storage medium, characterized in that, Comprising: The computer readable storage medium stores a computer program; the computer program, when running on a computer, causes the computer to perform the method of any one of claims 1 to 31.

36. A chip, comprising: The chip is installed in a communication device, the chip comprises a processor and a communication interface, the processor reads instructions through the communication interface and runs, so that the communication device performs the method of any one of claims 1 to 31.

Citation Information

Patent Citations

  • Safety protection method, device and system

    CN114765827A

  • Security context generation method and device and computer readable storage medium

    CN116601985A

  • Method and apparatus for managing security context

    WO2023072271A1

  • Communication method and communication apparatus

    WO2024169565A1