Key processing method, communication device, and storage medium
By generating corresponding keys for the serving network and home network of user equipment, the complexity of key generation when user equipment is roaming is solved, communication security isolation and simplified management are achieved, and communication security is improved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2026-03-26
AI Technical Summary
In sixth-generation mobile communication systems, existing technologies struggle to quickly generate keys associated with the home network when user equipment is roaming, leading to reduced communication security and complex key management.
By generating corresponding keys for the user equipment's serving network and home network, it ensures that keys related to the home network can be quickly generated even when roaming out of the home network. A unified key generation process and architecture are adopted to simplify key management.
It achieves secure isolation of communication between different networks, improves communication security, and simplifies the key generation and management process.
Smart Images

Figure CN2024120502_26032026_PF_FP_ABST
Abstract
Description
Key processing method, communication device, and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and particularly relates to a key processing method, a communication device, and a storage medium. BACKGROUND
[0002] The sixth generation mobile communication system (6 th Generation, 6G) architecture needs to streamline network functions (NFs). Streamlined network functions (NFs) have significant advantages in terms of capacity, coverage, signaling overhead, scalability, and energy consumption.
[0003] SUMMARY
[0004] The present disclosure provides a key processing method, a communication device, and a storage medium.
[0005] According to a first aspect of an embodiment of the present disclosure, a key processing method is provided, wherein the method is performed by a first node, and the method comprises: generating a first key for a second node of a serving network of a user equipment (UE); generating a second key for a second node of a home network of the UE; wherein the first key is used by the second node of the serving network to generate a third key; the third key is used to protect the security of communication between the UE and a third node of the serving network; and the second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect the security of communication between the UE and a third node of the home network.
[0006] According to a second aspect of an embodiment of the present disclosure, a key processing method is provided, wherein the method is performed by a second node of a home network, and the method comprises: receiving a second key sent by a first node, the second key being used by the second node of the home network to generate a fourth key, and the fourth key being used to protect the security of communication between the UE and a third node of the home network.
[0007] According to a third aspect of an embodiment of the present disclosure, a key processing method is provided, wherein the method is performed by a user equipment (UE), and the method comprises: the serving network of the UE is not a home network, and a sixth key is generated; the sixth key is related to a second node of a home network of the UE, and the sixth key is used by the UE to generate a seventh key; and the seventh key is used to protect the security of communication between the UE and a third node of the home network.
[0008] According to a fourth aspect of the embodiments of the present disclosure, a key processing method is provided, which is performed by a third node of a home network, and the method comprises: sending, to a second node of a home network of a user equipment (UE), a fourth request, the fourth request being used to request the second node of the home network to generate a fourth key; and receiving a fourth response sent by the second node of the home network, the fourth response comprising the fourth key.
[0009] The fourth key is generated by the second node of the home network according to a second key, and the fourth key is used to protect the communication security between the UE and a third node of the home network; and the second key is generated by a first node for the second node.
[0010] According to a fifth aspect of the embodiments of the present disclosure, a key processing method is provided, which is performed by a fourth node, and the method comprises: receiving a second request sent by a first node, the second request being used to request the fourth node to provide authentication information of the UE; and sending, to the first node, a second response according to the second request, the second response comprising the authentication information of the UE and a first indication; the first indication is used to indicate whether the first node generates a second key for a second node of a home network of the UE; and the second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect the communication security between the UE and a third node of the home network.
[0011] According to a sixth aspect of the embodiments of the present disclosure, a first node is provided, and the first node comprises: a processing module configured to generate a first key for a second node of a serving network of a user equipment (UE); and generate a second key for a second node of a home network of the UE; wherein the first key is used by the second node of the serving network to generate a third key; the third key is used to protect the communication security between the UE and a third node of the serving network; and the second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect the communication security between the UE and a third node of the home network.
[0012] According to a seventh aspect of the embodiments of the present disclosure, a second node of a home network is provided, and the second node comprises: a receiving module configured to wherein the first key is used by the second node of the serving network to generate a third key; the third key is used to protect the communication security between the UE and a third node of the serving network; and the second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect the communication security between the UE and a third node of the home network.
[0013] According to an eighth aspect of embodiments of the present disclosure, a third node of a home network is provided, and the third node comprises: a sending module configured to send, to a second node of a home network of a user equipment (UE), a fourth request for requesting the second node of the home network to generate a fourth key; and a receiving module configured to receive a fourth response sent by the second node of the home network, the fourth response comprising the fourth key, wherein the fourth key is generated by the second node of the home network according to a second key, and the fourth key is used to protect security of communication between the UE and the third node of the home network, and the second key is generated by a first node for the second node.
[0014] According to a ninth aspect of embodiments of the present disclosure, a fourth node is provided, and the fourth node comprises:
[0015] a receiving module configured to receive a second request sent by a first node, the second request being used to request the fourth node to provide authentication information of the UE;
[0016] a sending module configured to send, to the first node, a second response comprising the authentication information of the UE and a first indication according to the second request, wherein the first indication is used to indicate whether the first node generates a second key for a second node of a home network of the UE, and the second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect security of communication between the UE and a third node of the home network.
[0017] According to a tenth aspect of embodiments of the present disclosure, a communication system is provided, and the communication system comprises a first node, a second node of a home network, a user equipment (UE), a third node of the home network, and a fourth node;
[0018] the first node is configured to perform the method of any of the technical solutions in the first aspect;
[0019] the second node of the home network is configured to perform the method of any of the technical solutions in the second aspect;
[0020] the UE is configured to perform the method of any of the technical solutions in the third aspect;
[0021] the third node of the home network is configured to perform the method of any of the technical solutions in the fourth aspect;
[0022] the fourth node is configured to perform the method of any of the technical solutions in the fifth aspect.
[0023] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, which, when executed on a communication device, cause the communication device to perform the key processing method provided in any of the first aspect to the fifth aspect.
[0024] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, which, when executed on a communication device, cause the communication device to perform the key processing method provided in any of the first aspect to the fifth aspect.
[0025] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, which, when executed on a communication device, cause the communication device to perform the key processing method provided in any of the first aspect to the fifth aspect.
[0026] The present disclosure,
[0027] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and are not restrictive of the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0028] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and serve to explain the principles of the present disclosure, together with the description.
[0029] FIG. 1A is a schematic diagram of an architecture of a communication system according to an example embodiment;
[0030] FIG. 1B is a schematic diagram of an architecture of a communication system according to an example embodiment;
[0031] FIG. 1C is a schematic diagram of a connection between a user equipment (UE) and a radio access network (RAN) and a core network according to an example embodiment;
[0032] FIG. 1D is a schematic diagram of a connection between another UE and a RAN and a core network according to an example embodiment;
[0033] FIG. 1E is a schematic diagram of a security architecture according to an example embodiment;
[0034] FIG. 1F is a schematic diagram of a security architecture according to an example embodiment;
[0035] FIG. 2A is a schematic diagram of a flow of a key processing method according to an example embodiment;
[0036] FIG. 2B is a flow diagram illustrating a key processing method according to an example embodiment;
[0037] FIG. 3A is a flow diagram illustrating a key processing method according to an example embodiment;
[0038] FIG. 3B is a flow diagram illustrating a key processing method according to an example embodiment;
[0039] FIG. 4A is a flow diagram illustrating a key processing method according to an example embodiment;
[0040] FIG. 4B is a flow diagram illustrating a key processing method according to an example embodiment;
[0041] FIG. 5A is a flow diagram illustrating a key processing method according to an example embodiment;
[0042] FIG. 5B is a flow diagram illustrating a key processing method according to an example embodiment;
[0043] FIG. 6 is a flow diagram illustrating a key processing method according to an example embodiment;
[0044] FIG. 7A is a flow diagram illustrating a key processing method according to an example embodiment;
[0045] FIG. 7B is a flow diagram illustrating a key processing method according to an example embodiment;
[0046] FIG. 8A is a diagram illustrating a structure of a first node according to an example embodiment;
[0047] FIG. 8B is a diagram illustrating a structure of a second node of a home network according to an example embodiment;
[0048] FIG. 8C is a diagram illustrating a structure of a UE of a home network according to an example embodiment;
[0049] FIG. 8D is a diagram illustrating a structure of a third node of a home network according to an example embodiment;
[0050] FIG. 8E is a diagram illustrating a structure of a third node of a home network according to an example embodiment
[0051] FIG. 9A is a diagram illustrating a structure of a communication device according to an example embodiment;
[0052] FIG. 9B is a diagram illustrating a structure of a chip according to an example embodiment. DETAILED DESCRIPTION
[0053] The embodiment of the present disclosure provides a key processing method, a communication device, a communication system and a storage medium.
[0054] The first aspect of the embodiment of the present disclosure provides a key processing method, wherein the method is performed by a first node, and the method comprises the following steps:
[0055] generating a first key for a second node of a serving network of a user equipment (UE);
[0056] generating a second key for a second node of a home network of the UE;
[0057] The first key is used by the second node of the serving network to generate a third key, the third key is used to protect the communication security between the UE and a third node of the serving network, and the second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect the communication security between the UE and a third node of the home network.
[0058] Based on the above scheme, even if the UE roams out of the home network, the first node can still generate the second key related to the second node of the home network for the UE, so that when the UE is in the serving network outside the home network and communicates with the third node of the home network, the corresponding key can still be quickly generated, and the security is met. And in this way, the key generation of the serving network and the home network adopts a unified process and key architecture, simplifying the generation and management of the key.
[0059] In some embodiments of the first aspect, the first key is generated for the second node of the serving network of the UE and the second key is generated for the second node of the home network of the UE, comprising:
[0060] generating the first key for the second node of the serving network of the UE according to the fifth key of the first node and a network name of the serving network;
[0061] generating the second key for the second node of the home network of the UE according to the fifth key of the first node and a network name of the home network.
[0062] Based on the above scheme, the first node will generate the first key and / or the second key according to the fifth key of itself and the network name of the corresponding network, so that the keys of the second nodes of different networks will be different, so that the communication security of the UE in different networks is isolated, and the communication security is improved.
[0063] In some embodiments of the first aspect, the first key is generated for the second node of the serving network of the UE, comprising:
[0064] generating, by a first node, a first key for a second node of a serving network of a user equipment (UE), in response to receiving a first request sent by the second node of the serving network, the first request being used to request authentication of the UE;
[0065] sending, by the first node, a first response to the second node of the serving network, in response to whether the UE is authenticated, the first response comprising at least an authentication result of the UE.
[0066] According to the above scheme, the first node completes the key generation of the second node of the serving network and the home network in the first authentication process of the UE. Thus, even if the UE has a demand for communication with the NF of the home network while in the serving network, the security key of other NFs can be quickly generated based on the second key associated with the second node of the home network that has been generated.
[0067] In some embodiments of the first aspect, the method further comprises:
[0068] sending, by the first node, a second request to a fourth node according to the first request, the second request being used to request the fourth node to provide authentication information of the UE;
[0069] receiving, by the first node, a second response sent by the fourth node, the second response comprising at least authentication information provided by the UE to the fourth node;
[0070] authenticating, by the first node, the UE according to the second response.
[0071] In some embodiments, the first request comprises a network name of the serving network; and the second response further comprises a first indication, the first indication being used to indicate whether the first node generates the second key for the second node of the home network.
[0072] According to the above scheme, the second response sent by the fourth node comprises the first indication. Thus, the first node does not need to determine whether the current serving network of the UE is the home network, which simplifies the work of the first node.
[0073] In some embodiments of the first aspect, the first request comprises a network name of the serving network, and the method further comprises:
[0074] determining, by the first node, whether the serving network of the UE is the home network by comparing the network name of the serving network with a network name of the home network.
[0075] According to the above scheme, the first node can compare whether the current serving network of the UE is the home network, thereby meeting the determination demand of whether the current serving network of the UE is the home network in various scenarios.
[0076] In some embodiments of the first aspect, the UE is authenticated, and the first response comprises the first key.
[0077] In some embodiments, the UE is authenticated, and the first node returns the first key to the second node of the serving network in the first response, so that unnecessary key generation of the second node of the serving network can be reduced.
[0078] In some embodiments of the first aspect, the method comprises:
[0079] sending, to the second node of the home network, a first message, the first message comprising the second key and an identity of the UE, the serving network of the UE being different from the home network.
[0080] Based on the above scheme, after generating the second key, the first node provides the second key to the second node of the home network of the UE, so that the second node of the home network does not need to request the first node temporarily for use in the future, thereby reducing the delay.
[0081] In some embodiments of the first aspect, the method further comprises:
[0082] receiving a second message sent by the second node of the home network, the second message being used to indicate whether the second node of the home network receives the second key.
[0083] Based on the above scheme, the second node of the home network sends the second message to the first node to indicate whether the second node of the home network receives the second key, so that the transmission of the second key can be ensured to be successful.
[0084] In some embodiments of the first aspect, the method further comprises receiving a third request sent by the second node of the home network, the third request being used to request the first node to generate the second key for the second node.
[0085] Based on the above scheme, the first node can send the second key to the third node of the home network based on the third request of the second node of the home network, so that unnecessary transmission of the second key can be reduced.
[0086] In some embodiments of the first aspect, the method further comprises:
[0087] sending, to the second node of the home network, a third response, the third response comprising the second key.
[0088] Based on the above scheme, the first node can send the second key to the third node of the home network based on the third request of the second node of the home network, so that unnecessary transmission of the second key can be reduced.
[0089] The second aspect provides a key processing method, wherein the method is performed by a second node of a home network, and the method comprises:
[0090] receiving a second key sent by the first node, the second key being used for the second node of the home network to generate a fourth key, the fourth key being used for protecting a communication between the UE and a third node of the home network.
[0091] In some embodiments of the second aspect, the receiving the second key sent by the first node comprises:
[0092] receiving a first message sent by the first node, the first message comprising the second key and an identity of the UE.
[0093] In some embodiments of the second aspect, the method further comprises:
[0094] sending a second message to the first node, the second message being used for indicating whether the second key is received by the second node of the home network.
[0095] In some embodiments of the second aspect, the method further comprises:
[0096] receiving a fourth request sent by a third node of the home network, the fourth request being used for requesting the fourth key;
[0097] sending a third request to the first node, the third request being used for requesting the first node to generate the second key for the second node;
[0098] receiving a third response sent by the first node, the third response comprising the second key of the second node;
[0099] sending a fourth response to the third node of the home network, the fourth response comprising the second key.
[0100] In some embodiments of the second aspect, the method further comprises:
[0101] sending a second indication to the UE, the second indication being used for indicating the UE to generate a sixth key associated with the second node of the home network, the sixth key being used for the UE to generate a seventh key, the seventh key being used for protecting a communication between the UE and a third node of the home network.
[0102] The third aspect provides a key processing method, wherein the method is performed by a user equipment (UE), and the method comprises:
[0103] The service network of the UE is not the home network, and a sixth key is generated; the sixth key is associated with a second node of the home network of the UE, and the sixth key is used by the UE to generate a seventh key; the seventh key is used to protect the communication security between the UE and a third node of the home network.
[0104] In some embodiments of the third aspect, the method further comprises:
[0105] The UE determines whether the service network to which the UE is currently attached is the home network in a process of requesting network registration.
[0106] The service network of the UE to which the UE is currently attached is not the home network, and it is determined that the service network of the UE is not the home network.
[0107] In some embodiments of the third aspect, the service network of the UE is not the home network, and a sixth key is generated, comprising:
[0108] The UE generates the sixth key after the first authentication of the network registration succeeds in the case that the service network of the UE is not the home network.
[0109] In some embodiments of the third aspect, the method further comprises:
[0110] The first authentication of the UE succeeds, and an eighth key is generated, the eighth key is associated with a second node of the service network, and the eighth key is used by the UE to generate a ninth key; the ninth key is used to protect the communication security between the UE and a third node of the service network.
[0111] In some embodiments of the third aspect, the first authentication of the UE succeeds, and an eighth key is generated, comprising:
[0112] The eighth key is generated according to the network name of the service network and a fifth key of the first node.
[0113] In some embodiments of the third aspect, the service network of the UE is not the home network, and a sixth key is generated, comprising:
[0114] The service network of the UE is not the home network, and the network node to which the UE requests communication belongs to the home network, and the sixth key is generated.
[0115] In some embodiments of the third aspect, the service network of the UE is not the home network, and a sixth key is generated, comprising:
[0116] A second indication sent by a second node of the home network is received; the second indication is used to instruct the UE to generate the sixth key.
[0117] receiving the second indication, generating the sixth key.
[0118] In some embodiments of the third aspect, the serving network of the UE is not the home network, and generating the sixth key comprises:
[0119] the serving network of the UE is not the home network, and the sixth key is generated according to a network name of the home network and a fifth key of the first node.
[0120] In some embodiments of the third aspect, the method further comprises:
[0121] determining a network to which a network node requesting communication by the UE belongs;
[0122] the serving network of the UE is not the home network, and generating the sixth key comprises:
[0123] the serving network of the UE is not the home network, and the sixth key is generated when the network node requesting communication by the UE belongs to the home network.
[0124] The fourth aspect provides a key processing method, executed by a third node of a home network, the method comprising: sending, to a second node of the home network of a user equipment (UE), a fourth request, the fourth request being used to request the second node of the home network to generate a fourth key; receiving a fourth response sent by the second node of the home network, the fourth response comprising the fourth key; the fourth key being generated by the second node of the home network according to a second key, the fourth key being used to protect security of communication between the UE and the third node of the home network; and the second key being generated by a first node for the second node.
[0125] The fifth aspect provides a key processing method, executed by a fourth node, the method comprising:
[0126] receiving a second request sent by a first node, the second request being used to request the fourth node to provide authentication information of the UE;
[0127] sending, to the first node, a second response according to the second request, the second response comprising the authentication information of the UE and a first indication; the first indication being used to indicate whether the first node generates a second key for a second node of a home network of the UE; and the second key being used by the second node of the home network to generate a fourth key, the fourth key being used to protect security of communication between the UE and a third node of the home network.
[0128] The sixth aspect provides a first node, wherein the first node comprises:
[0129] The processing module is configured to generate a first key for a second node of a serving network of a user equipment (UE); generate a second key for a second node of a home network of the UE; wherein the first key is used by the second node of the serving network to generate a third key; the third key is used to protect a communication security between the UE and a third node of the serving network; the second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect a communication security between the UE and a third node of the home network.
[0130] The seventh aspect provides a second node of a home network, wherein the second node comprises:
[0131] The receiving module is configured to wherein the first key is used by the second node of the serving network to generate a third key; the third key is used to protect a communication security between the UE and a third node of the serving network; the second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect a communication security between the UE and a third node of the home network.
[0132] The eighth aspect provides a user equipment (UE), wherein the UE comprises:
[0133] The processing module is configured to generate a sixth key when the serving network of the UE is not a home network; the sixth key is related to a second node of a home network of the UE, and the sixth key is used by the UE to generate a seventh key; the seventh key is used to protect a communication security between the UE and a third node of the home network.
[0134] The ninth aspect provides a third node of a home network, wherein the third node comprises:
[0135] The sending module is configured to send a fourth request to a second node of a home network of a user equipment (UE), and the fourth request is used to request the second node of the home network to generate a fourth key.
[0136] The receiving module is configured to receive a fourth response sent by the second node of the home network, and the fourth response comprises the fourth key.
[0137] The fourth key is generated by the second node of the home network according to a second key, and the fourth key is used to protect a communication security between the UE and a third node of the home network; and the second key is generated by a first node for the second node.
[0138] The tenth aspect provides a fourth node, wherein the fourth node comprises:
[0139] The receiving module is configured to receive a second request sent by the first node, the second request being used to request the fourth node to provide authentication information of the UE;
[0140] The sending module is configured to send a second response to the first node according to the second request, the second response including the authentication information of the UE and a first indication; the first indication is used to indicate whether the first node generates a second key for a second node of a home network of the UE; the second key is used for the second node of the home network to generate a fourth key, the fourth key being used to protect communication security between the UE and a third node of the home network.
[0141] The eleventh aspect provides a communication system, wherein the communication system includes a first node, a second node of a home network, a user equipment (UE), a third node of the home network, and a fourth node;
[0142] The first node is configured to perform the method in any of the technical solutions of the first aspect;
[0143] The second node of the home network is configured to perform the method in any of the technical solutions of the second aspect;
[0144] The UE is configured to perform the method in any of the technical solutions of the third aspect;
[0145] The third node of the home network is configured to perform the method in any of the technical solutions of the fourth aspect;
[0146] The fourth node is configured to perform the method in any of the technical solutions of the fifth aspect.
[0147] The twelfth aspect provides a communication device, wherein the communication device includes one or more processors; wherein the processor is used to call instructions to make the communication device perform the key processing method in any of the technical solutions of the first aspect to the fifth aspect.
[0148] The thirteenth aspect provides a program product, wherein the program product includes a computer program, and the computer program is executed by the communication device to enable the communication device to implement the key processing method in any of the technical solutions of the first aspect to the fifth aspect.
[0149] The fourteenth aspect provides a computer program, which, when executed on a computer, enables the computer to perform the key processing method in any of the technical solutions of the first aspect to the fifth aspect.
[0150] It can be understood that the above-mentioned UE, network device, and communication system, program product, and computer program are used to execute the method provided by the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved are referred to the beneficial effects in the corresponding method, which will not be described here.
[0151] The embodiments of the present disclosure provide a key processing method, a communication device, a communication system and a storage medium. The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the mode of removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation modes in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or some or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation modes of other embodiments.
[0152] In the embodiments of the present disclosure, the terms and / or descriptions of the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0153] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.
[0154] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "preceding", "this", etc., can represent "one and only one", or "one or more", "at least one", etc. For example, in the case of using articles such as "a", "an", "the" in English, the noun after the article can be understood as singular expression, or as plural expression.
[0155] In the embodiments of the present disclosure, "a plurality of" means two or more.
[0156] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.
[0157] In some embodiments, the description of "at least one of A, B", "A and / or B", "A or B in one case, A or B in another case", "one of A or B", and the like, can include the following technical manners according to the case: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B are executed (A and B are executed). When there are more branches such as A, B, C, and the like, the above description is similar.
[0158] In some embodiments, the description of "A or B" and the like can include the following technical manners according to the case: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, and the like, the above description is similar.
[0159] The prefix words "first", "second", and the like in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an additional limitation because of the use of the prefix words. For example, the description objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields". "First" and "second" do not limit whether the "fields" modified thereby are in the same message, nor do they limit the order of "first field" and "second field". For another example, the description objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "devices", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different. For another example, the description objects are "information", and "first type of information" and "second type of information" can be the same information or different information, and the content thereof can be the same or different.
[0160] In some embodiments, "including A", "containing A", "for indicating A", "carrying A", can be interpreted as directly carrying A, or indirectly indicating A.
[0161] In some embodiments, the terms "…", "determining …", "in the case of …", "when …", "when …", "if …", and the like can be replaced with each other.
[0162] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above", and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "fewer than", "fewer than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below", and the like can be replaced with each other.
[0163] In some embodiments, an apparatus and the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", and the like can be replaced with each other.
[0164] In some embodiments, "network" can be interpreted as a network-side device or network function included in an access network device, a core network device, and the like in a network.
[0165] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “serving node,” “node (carrier),” “component node,” “bandwidth part (BWP),” and the like can be used interchangeably.
[0166] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user UE," "mobile station (MS)," "mobile UE (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access UE," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.
[0167] In some embodiments, the access network device, the core network device, or the network device can be replaced with the UE. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the UE is replaced with communication between a plurality of UEs (e.g., device-to-device (D2D), vehicle-to-everything (V2X), and so on). In this case, the structure in which the UE has all or part of the functions of the access network device can also be provided. In addition, the terms "uplink," "downlink," and so on can also be replaced with terms corresponding to the inter-UE communication (e.g., "side"). For example, the uplink channel, the downlink channel, and so on can be replaced with the side channel, and the uplink, the downlink, and so on can be replaced with the sidelink.
[0168] In some embodiments, the UE can be replaced with the access network device, the core network device, or the network device. In this case, the structure in which the access network device, the core network device, or the network device has all or part of the functions of the UE can also be provided.
[0169] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.
[0170] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.
[0171] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0172] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0173] As shown in FIG. 1A, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 can include an access network device and / or a core network device. The terminal can also be referred to as a UE.
[0174] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a Pad, a computer with wireless transceiver function, a virtual reality (VR) UE device, an augmented reality (AR) UE device, a wireless UE device in industrial control, a wireless UE device in self-driving, a wireless UE device in remote medical surgery, a wireless UE device in smart grid, a wireless UE device in transportation safety, a wireless UE device in smart city, a wireless UE device in smart home, etc., but is not limited thereto.
[0175] In some embodiments, the UE is also referred to as a User Equipment (UE).
[0176] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a UE to a wireless network, and the access network device may, for example, include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0177] In some embodiments, the technical means of the present disclosure can be applicable to an Open RAN architecture, in which case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0178] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers can be controlled by the CU, while the rest or all of the protocol layers can be distributed in the DU and controlled by the CU, but is not limited thereto.
[0179] In some embodiments, the core network device can be one device including the first network element, or a plurality of devices or device groups each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0180] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical means of the embodiments of the present disclosure, and does not constitute a limitation on the technical means provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new service scenarios appear, the technical means provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0181] The embodiments of the present disclosure described below can be applied to the communication system 100 shown in FIG. 1A or part of the subjects, but are not limited thereto. The subjects shown in FIG. 1A are exemplary, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than those in FIG. 1A. The number and form of each subject is arbitrary, and the connection relationship between the subjects is exemplary. The subjects can not be connected or can be connected, and the connection can be in any manner, can be direct connection or indirect connection, and can be wired connection or wireless connection.
[0182] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other resources, next-generation system extended based thereon, and the like. Further, a plurality of systems can be combined (for example, LTE and NR can be combined).
[0183] As above, the network functions (NFs) in the 6G architecture are streamlined in order to significantly improve performance in terms of capacity, coverage, signaling overhead, scalability, and energy consumption, etc. The dependencies between NFs can lead to unnecessary complexity and even delays. The number of dependencies and processing points can be reduced by redesigning the network functions. One way is the possibility of direct signaling between enhanced NFs of the 6G system to eliminate potential bottlenecks. Today, many services require information to be transmitted from a terminal device through a (5th Generation Core, 5GC) through a New Generation-Radio Access Netork (NG-RAN) node. In the 5th Generation Core (5GC), information is passed to the NG-RAN node through the AMF, and rarely does it not involve the AMF. In order to simplify this transmission, the introduction of a service-based interface (SBI) to the NG-RAN will allow this information to be exchanged directly between the NF and the NG-RAN without going through the Access Management Function (AMF), as shown in FIG. 1B.
[0184] If the RAN is developed in the service direction, it means that the RAN node can be a consumer or producer that provides services for other network functions in addition to the AMF. In the 5th Generation (5G) system, only the AMF in the core network and the UE support Non Access Stratum (NAS) signaling. Usually, NAS signaling is transparently transmitted through the RAN node. If the RAN can be enhanced to communicate directly with other core NFs without going through the AMF, it means that in addition to the AMF, NAS signaling also needs to be supported between the User Equipment (UE) and other core network NFs.
[0185] However, the NAS security of the current NAS signaling is only supported by the UE and the AMF. According to the key hierarchy shown in FIG. 1C, the root key (KAMF) of the NAS security is derived by the UE and the security anchor function (SEAF). The KAMF is used by the UE and the AMF to derive the NAS integrity key KNASint and / or the NAS confidentiality protection key KNASenc, and no other core NF can derive the NAS security key. Since the current key hierarchy design of other core NFs does not support NAS security, the NAS signaling between the UE and other core NFs cannot be protected. If the NAS signaling between the UE and the NF is not protected, there is a risk that the NAS signaling information will be tampered with or eavesdropped when the RAN node forwarding the NAS signaling is attacked. Therefore, it is necessary to study how to protect the security of the 6G multi-NAS architecture. That is, the existing 5G security key hierarchy does not support the security protection of the NAS signaling between the UE and other core network NFs. FIG. 1D is a schematic diagram of a 5G security key hierarchy architecture. The current key hierarchy is based on the root key derived by the SEAF residing in the service network. However, for the NAS signaling between the UE and the NFs (such as PCF, UDM) located in the home network, the use of the root key derived in the service network will no longer be applicable to the NFs in the home network. Therefore, it is necessary to study the security protection of each network function under the security architecture of the 6G multi-non access stratum (NAS). The architecture supports the NFs residing both in the service network and in the home network.
[0186] As shown in FIG. 2A, the embodiments of the present disclosure provide a key processing method, which is performed by a communication system. The method can include:
[0187] S2101: A second node of a service network sends a first request to a first node.
[0188] In some embodiments, after the second node of the service network receives the registration request, the first request is sent to the first node.
[0189] In some embodiments, the first node can be an authentication server function (AUSF).
[0190] In some embodiments, the second node can include, but is not limited to, a security anchor function (SEAF).
[0191] In some embodiments, the first request is used to request authentication of the UE.
[0192] In some embodiments, the first request can be a registration request.
[0193] In some embodiments, the first request can include, but not limited to, at least one of the following:
[0194] an identity of the UE, exemplarily, the identity of the UE can include, but not limited to, a Subscription Concealed Identifier (SUCI) of the UE, a Globally Unique Temporary UE Identity (GUTI) of the UE;
[0195] a name of a network in which the second node is located;
[0196] a Public Land Mobile Network (PLMN) identity of a network in which the second node is located.
[0197] In some embodiments, the UE sends a registration request to the second node of the serving network. As such, the second node of the serving network sends the first request to the first node after receiving the registration request sent by the UE.
[0198] In some embodiments, the registration request can trigger a first authentication request. In some embodiments, the second node can include, but not limited to, a Security Anchor Function (SEAF). In some embodiments, the registration request can include at least an identity of the UE. The identity of the UE, exemplarily, the identity of the UE can include, but not limited to, a Subscription Concealed Identifier (SUCI) of the UE, a Globally Unique Temporary UE Identity (GUTI) of the UE.
[0199] As shown in FIG. 1E and FIG. 1F, if the second node is a SEAF, the keys of other NFs are generated according to K SEAF . The key K AMF of the Accesss Management Function (AMF) is generated according to K SEAF . The key K NF of the NFs other than the AMF is also generated according to K SEAF .
[0200] S2102: The first node sends a second request to a fourth node.
[0201] In some embodiments, the second request is used to request the fourth node to provide authentication information of the UE.
[0202] In some embodiments, the second request can comprise at least an identity of the UE.
[0203] In some embodiments, the fourth node can be a User Data Management (UDM), an Authentication Credential Repository and Processing Function (ARPF).
[0204] S2103: The fourth node sends a second response to the first node.
[0205] In some embodiments, the fourth node sends the second response to the first node according to the received second request.
[0206] In some embodiments, the second response comprises at least authentication information of the UE. Illustratively, the authentication information comprises at least an authentication vector. The authentication vector is used by the first node to authenticate the UE.
[0207] Illustratively, when the second response comprises the authentication information, the first node can return the authentication information to the UE. After receiving the second response, the first node initiates an authentication procedure for the UE via a second node of the serving network, e.g., sends the authentication information to the UE, etc. After receiving the authentication information, the UE compares the authentication information with locally calculated authentication information, and returns the comparison result to the first node. If the comparison result received by the first node indicates that the authentication information provided by the fourth node is consistent with the authentication information calculated by the UE itself, it means that the UE is authenticated, otherwise, the UE is not authenticated.
[0208] In some embodiments, the second response can further comprise a first indication.
[0209] In some embodiments, the first indication can be used to indicate that a second key is generated for the second node of the home network of the UE. In this case, whether the second response contains the first indication can be used by the fourth node to indicate to the first node whether the second key needs to be generated for the second node of the home network of the UE.
[0210] In other embodiments, the first indication can also be used to indicate whether the second key is generated for the second node of the home network of the UE. It can be seen that whether the second response contains the first indication is an optional operation.
[0211] S2104: The first node generates a first key and / or a second key.
[0212] In some embodiments, the first node generates the first key for a second node of a serving network of the UE. In some embodiments, the first node generates the second key for a second node of a home network of the UE.
[0213] In some embodiments, if the first indication is used to indicate that the first node generates the second key for a second node of a home network of the UE, the first node generates the first key for a second node of a serving network of the UE and the second key for a second node of a home network of the UE if the second response contains the first indication.
[0214] In some embodiments, if the first indication is used to indicate that the first node generates the second key for a second node of a home network of the UE, the first node generates the first key for a second node of a serving network of the UE only if the second response does not contain the first indication.
[0215] In some embodiments, the first node generates the second key for a second node of a serving network and a home network of the UE regardless of whether the second response contains the first indication.
[0216] In some embodiments, the first node generates the first key for a second node of a serving network of the UE and the second key for a second node of a home network of the UE if the serving network of the UE is not the home network.
[0217] In some embodiments, the first node can only need to generate the second key for a second node of a home network of the UE if the serving network of the UE is the home network.
[0218] In some embodiments, the first node generates the first key and the second key regardless of whether the current serving network of the UE is the home network. If the current serving network of the UE is the home network, the first key and the second key are the same. If the current serving network of the UE is not the home network, the first key and the second key are different. Further, the second nodes associated with the first key and the second key are different, and the second nodes associated with the first key and the second key belong to different networks.
[0219] S2105: The first node sends the first response to the second node of the serving network.
[0220] In some embodiments, the first response includes the first key of the second node of the serving network.
[0221] In some embodiments, the second node stores the first key and the identity of the UE after receiving the first response.
[0222] In some embodiments, the first response also includes the authentication result. For example, the first node sends the authentication result to the second node through the first response.
[0223] After receiving the first response, the second node of the serving network obtains the authentication result of the UE.
[0224] In some embodiments, the first key is used by the second node of the serving network to generate a third key; the third key is used to protect the communication security between the UE and a third node of the serving network.
[0225] S2106: The first node sends a first message to the second node of the home network.
[0226] In some embodiments, the first message can be a fifth request. Illustratively, the fifth request can be a NAS anchor key register request (Nseaf_NASAnchorKey_Register Request). The first request can include an identity of the UE and a second key of the second node of the HN. The identity of the UE can include, but not limited to, a subscription permanent identifier (SUPI). Illustratively, the first message can also be a notification message including the identity of the UE and the second key of the second node of the HN.
[0227] S2107: The second node of the home network sends a second message to the first node.
[0228] In some embodiments, the second message is used to indicate whether the second node of the home network receives the second key.
[0229] In some embodiments, it is assumed that the second node of the home network can not reply the second message after receiving the first message, since the communication between the first node and the second node of the home network is internal communication of the network, it can be defaulted that the second node of the home network receives the second message, at this time, S2107 is an optional operation.
[0230] In some embodiments, in the case that the first message is a NAS anchor key register request (Nseaf_NASAnchorKey_Register Request), the second message can be a NAS anchor key register response (Nseaf_NASAnchorKey_Register Response).
[0231] S2108: The second node of the home network sends a second indication to the UE.
[0232] In some embodiments, the second indication is used to instruct the UE to generate the sixth key.
[0233] In some embodiments, the second node of the home network sends the second indication to the UE after receiving the second key.
[0234] In some embodiments, the second node of the home network sends a second indication to the UE after sending the second message.
[0235] S2109: The UE generates a sixth key and / or an eighth key.
[0236] In some embodiments, the sixth key is associated with the second node of the home network. The eighth key is associated with the second node of the serving network. The UE generates the sixth key and the eighth key respectively when the serving network is not the home network.
[0237] In some embodiments, the sixth key corresponds to the aforementioned second key. The eighth key corresponds to the aforementioned first key.
[0238] In some embodiments, the sixth key is used by the UE to generate a seventh key; the seventh key is used to protect the communication security between the UE and a third node of the home network.
[0239] In some embodiments, the eighth key is used by the UE to generate a ninth key. The ninth key is related to the third node of the serving network.
[0240] In some embodiments, the third node can be any core network function. Illustratively, the third node of the serving network can include but is not limited to an access management function, a session management function, a positioning management function, etc.
[0241] Illustratively, in the embodiments of the present disclosure, the third node of the home network HN can include but is not limited to a policy control function, a user data management, a network data analysis management, etc.
[0242] In some embodiments, the third key can be used to generate an integrity key and / or a confidentiality key for the communication between the third node of the serving network and the UE. In some embodiments, the third key can also be used to generate a ciphering key for the communication between the third node of the serving network and the UE.
[0243] In some embodiments, the UE generates a sixth key for the second node of the home network when the accessed serving network is not the home network.
[0244] In some embodiments, the UE generates the sixth key according to the fifth key of the first node and the network name of the home network.
[0245] In some embodiments, the UE generates the sixth key according to the fifth key of the first node, the network name of the home network, and the length of the network name of the home network.
[0246] In some embodiments, the UE generates an eighth key according to the fifth key of the first node and the network name of the serving network.
[0247] In some embodiments, the UE generates the eighth key according to the fifth key of the first node, the network name of the serving network, and the length of the network name of the serving network.
[0248] In some embodiments, the serving network of the UE is not the home network, and the sixth key is generated.
[0249] In some embodiments, the UE determines whether the serving network to which the UE is currently attached is the home network in a process of requesting network registration.
[0250] The serving network to which the UE is currently attached is not the home network, and it is determined that the serving network of the UE is not the home network.
[0251] In some embodiments, the UE generates the sixth key after the first authentication of the network registration succeeds, in a case that the serving network of the UE is not the home network.
[0252] In some embodiments, the serving network of the UE is not the home network, and the network node with which the UE requests communication belongs to the home network, and the sixth key is generated.
[0253] In some embodiments, the serving network of the UE is not the home network, and the UE receives a second indication sent by a second node of the home network, and the sixth key of the second node of the home network is generated.
[0254] The sixth key can generate any one of the seventh keys, and the seventh key can be further used to generate an integrity key and / or a confidentiality key for communication between the UE and the third node of the home network.
[0255] In some embodiments, the term "information" can be mutually replaced with the terms "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "data", and the like.
[0256] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectionally transmit", "send and / or receive" can be replaced by each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and various meanings. The protocol includes at least one of 3GPP protocol, Wi-Fi protocol, audio and / or video protocol. In some embodiments, the term "send" can be replaced by the terms "transmit", "report", "transmit", and the like.
[0257] In some embodiments, each step in the present embodiment S2101 to S2109 can be independently implemented, or can be combined and implemented in any order without contradiction. For example, S2101 can be implemented alone, for example, the second node sends the first request to the first node, but the first node can not reply to the second node with the first response, so at this time, S2102 to S2105 executed for sending the first response are optional steps. In another embodiment, the first node can locally cache the authentication information of the UE, in which case S2102 and S2103 are optional steps, and S2104 and S2105 can be executed after S2101. In some embodiments, S2106 to 2107 are optional steps, for example, the first node can send the second key to the second node of the home network based on the second node of the home network. For another example, S2108 and S2109 can also be optional steps. For example, the second node of the home network can not send the second indication to the UE after generating the second key. If the current serving network of the UE is not the home network, the UE has a communication demand with the third node of the home network, the sixth key and / or the seventh key are generated, and it can be seen that S2108 is optional. In some embodiments, S2109 can also be an optional step. For example, when the current serving network of the UE is not the home network, there is no demand for communication with the third node of the home network, and assuming that the trigger timing of the UE generating the sixth key and the seventh key is the demand for communication with the third node of the home network, in this case S2108 and S2109 are optional.
[0258] As shown in FIG. 2B, the present disclosure provides a key processing method, which is executed by a communication system. The method can include:
[0259] S2201: The third node of the home network sends a fourth request to the second node of the home network.
[0260] In some examples, when the UE requests to communicate with the third node of the home network, the third node of the home network sends the fourth request to the second node of the home network. For example, the service network of the UE is different from the home network.
[0261] In some embodiments, the fourth request is used to request the fourth key. Exemplarily, the fourth key can be a root key for the third node to generate a security key for communication with the UE.
[0262] S2202: The second node of the home network sends a third request to the first node.
[0263] In some embodiments, the second node of the home network sends the third request to the first node based on the fourth request.
[0264] In some embodiments, the first node can be an authentication server function (AUSF).
[0265] In some embodiments, the second node can include, but is not limited to, a security anchor function (SEAF).
[0266] In some embodiments, the third request is used to request the first node to generate the second key for the second node.
[0267] In some embodiments, the third request can include, but is not limited to, at least one of the following:
[0268] An identity of the UE, exemplarily, the identity of the UE can include, but is not limited to, a subscription concealed identifier (SUCI) of the UE, a globally unique temporary UE identity (GUTI);
[0269] A name of a network in which the second node is located;
[0270] A public land mobile network (PLMN) identity of a network in which the second node is located.
[0271] In some embodiments, the step can be an optional step, for example, when the UE is registered to the network, the second node of the home network has already received the key generated by the first node, and thus the step can be omitted.
[0272] S2203: The first node sends a third response to the second node of the home network.
[0273] In some embodiments, the third response includes the second key. Exemplarily, the third response can also include the identity of the UE.
[0274] Exemplarily, the second key can be generated in the manner as described in the corresponding embodiments of FIG. 2A.
[0275] S2204: The second node of the home network sends a fourth response to the third node of the home network.
[0276] In some embodiments, the fourth response includes a fourth key. The fourth key is generated according to the second key. The optional implementation of the UE generating the fourth key can be referred to the corresponding embodiments of FIG. 2A, which will not be repeated here.
[0277] S2205: The UE generates a sixth key.
[0278] In some embodiments, the UE generates the sixth key according to the second indication. The optional implementation of the UE generating the sixth key can be referred to the corresponding embodiments of FIG. 2A. In some embodiments, S2206 is an optional step. For example, the UE has already generated the sixth key in the process of registering to the network, and can skip the step of generating the sixth key when receiving the second indication.
[0279] In some embodiments, the UE can generate the sixth key when it needs to send a message to the third node of the home network without receiving the second indication.
[0280] S2206: The UE generates a seventh key.
[0281] In some embodiments, the optional implementation of the UE generating the seventh key can be referred to the corresponding steps of FIG. 2A, which will not be repeated here. The seventh key can be a root key of a security key between the UE and the third node of the home network. The security key can include an integrity key and / or a confidentiality key, for example.
[0282] In some embodiments, the term “information” can be mutually replaced with the terms “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “field”, “data”, and the like.
[0283] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be replaced with each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and various meanings. The protocol includes at least one of 3GPP protocol, Wi-Fi protocol, audio and / or video protocol. In some embodiments, the term "send" can be replaced with the terms "transmit", "report", "transmit", and the like.
[0284] In some embodiments, the steps in the present embodiment S2201 to S2206 can be implemented independently, or can be combined and implemented in any order without contradiction. For example, S2202 to S2203 are optional steps. For example, the third node of the home network receives the second key sent by the first node in the process of the first registration of the UE, so it is not necessary to obtain the second key through the transmission of the third request and the third response, that is, S2202 and S2203 can be skipped, and S2204 can be directly executed.
[0285] For another example, the UE can perform the generation of the sixth key and the seventh key at the first registration, and then S2205 and S2206 are optional steps. In some embodiments, the execution order of S2201 to S2206 can be as shown in FIG. 2B, but is not limited to that shown in FIG. 2B. For example, S2204 to S2206 can be executed while the UE requests to communicate with the third node of the home network, and then S2204 to S2206 can be limited to S2201, or can be executed in parallel with S2201.
[0286] As shown in FIG. 3A, the present embodiment provides a key processing method, wherein the method is executed by a first node. The method can include:
[0287] S3101: receiving a first request.
[0288] In some embodiments, the first request is received by the second node of the service network of the UE. In some embodiments, the service network of the UE can be the home network of the UE. In other embodiments, the home network of the UE can not be the service network of the UE.
[0289] In some embodiments, the first request is used to request to authenticate the UE.
[0290] In some embodiments, the related description of the first request can refer to the corresponding embodiment of FIG. 2A, which will not be repeated here.
[0291] S3102: sending a second request.
[0292] In some embodiments, the second request is used to request the fourth node to provide authentication information of the UE.
[0293] In some embodiments, the first node sends a second request to the fourth node. For example, the fourth node, the second request and the like can be understood with reference to the corresponding embodiments of FIG. 2A.
[0294] S3103: receiving a second response.
[0295] In some embodiments, the second response is sent by the fourth node.
[0296] In some embodiments, the second response includes authentication information of the UE. For example, the authentication information can include an authentication vector. For example, the authentication vector can be used to authenticate the UE.
[0297] S3104: generating a first key and / or a second key.
[0298] In some embodiments, the first key is generated for a second node of a serving network of the UE. In some other embodiments, the second key is generated for a second node of a home network of the UE.
[0299] In some embodiments, the second response can include a first indication. The first indication is used to indicate that the second key is generated for the second node of the home network of the UE.
[0300] In some embodiments, the first node generates the second key according to the network name of the serving network of the UE contained in the first request, in the case that the serving network of the UE is not the home network.
[0301] In some other embodiments, the first node generates the first key and the second key respectively regardless of the case. In this case, if the serving network of the UE is the home network, the first key and the second key are the same. If the serving network of the UE is not the home network, the first key and the second key are different.
[0302] In some embodiments, the first key and / or the second key are generated after the UE is authenticated, reducing unnecessary key generation.
[0303] In some embodiments, the way of generating the first key and / or the second key can be understood with reference to S2104 of the corresponding embodiments of FIG. 2A, and the specific implementation is not limited to the above examples. In some embodiments, S3101 to S3103 are optional steps, i.e. the first node generates the first key and the second key for the second node of the serving network of the UE and / or the second node of the home network of the UE, which does not have to be in the first authentication process of the UE, but also can be in the process of the UE requesting communication.
[0304] S3105: sending a first response.
[0305] In some embodiments, the first response is sent to a second node of a serving network of the UE.
[0306] In some embodiments, the first response can comprise a first key.
[0307] S3106: sending the first message.
[0308] In some embodiments, the first node sends the first message to a second node of a home network of the UE.
[0309] In some embodiments, the first message can comprise a second key and an identity of the UE.
[0310] In some embodiments, the description of one or more of the second key, the identity of the UE, and the first message can be found in the corresponding embodiments of FIG. 2A, which will not be repeated here.
[0311] S3107: receiving the second message.
[0312] In some embodiments, the first node receives the second message sent by the second node of the home network.
[0313] In some embodiments, the related description of the second message can be found in the corresponding embodiments of FIG. 2A, which will not be repeated here. It is worth noting that S3107 is an optional step. For example, in the case of the first message being a notification message, the second node of the home network will not send the second message. Exemplarily, in the case of the first message being a request message, the second message can be a response message. The second message can indicate that the second node of the home network receives the message of the second key.
[0314] In some embodiments, the term “information” can be mutually replaced with the terms “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “field”, “data”, and the like.
[0315] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be replaced with each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and various meanings. The protocol includes at least one of 3GPP protocol, Wi-Fi protocol, audio and / or video protocol. In some embodiments, the term "send" can be replaced with the terms "transmit", "report", "transmit", and the like.
[0316] In some embodiments, the steps in the present embodiment S3101 to S3107 can be implemented independently, or can be combined and implemented in any order without contradiction. For example, S3102 to S3103 are optional steps. For example, the first node locally caches the authentication information of the UE, and the first node does not need to request the authentication information from the fourth node. In some embodiments, only one of generating the first key and generating the second key can be performed, for example, the current service network of the UE is the home network, and only the first key can be generated without generating the second key. In another embodiment, regardless of whether the current service network of the UE is the home network of the UE, the first node will generate the first key and the second key at the same time, but in this case, the first key and the second key are the same. In some embodiments, S3106 is an optional step. For example, the first node sends the second key to the second node of the home network when the second node of the home network requests the second key, and the sending step of the first message can be omitted at this time. S3107 is an optional step, for example, the first message is a notification message, and the second message does not need to be answered. For another example, if the first message is not sent, the first node also does not need to receive the second message. That is, in this case, S3107 is also an optional step.
[0317] As shown in FIG. 3B, the present embodiment provides a key processing method, wherein the first node is executed. The method can include:
[0318] S3201: receiving a third request.
[0319] In some embodiments, the third request sent by the second node of the home network of the UE is received, and the service network of the UE is not the home network.
[0320] In some embodiments, the third request is used to request the first node to generate the second key for the second node. For example, the related description of the third request can refer to the corresponding embodiment of FIG. 2A, which will not be repeated here.
[0321] S3202: generating a second key.
[0322] In some embodiments, the second key is related to the second node of the home network.
[0323] In some embodiments, the first node generates the second key according to the third request.
[0324] In some embodiments, the optional implementation of generating the second key can refer to the corresponding embodiments of FIG. 2A and / or FIG. 2B.
[0325] S3203: sending a third response.
[0326] In some embodiments, the third response includes the second key.
[0327] In some embodiments, S3201 and S3203 are optional steps, the first node generates the second key for the second node of the home network of the UE at the same time when generating the first key for the second node of the service network of the UE, therefore, S3201 and S3203 are optional steps. Illustratively, when the first node determines that the service network of the UE is different from the home network, the first node automatically generates the second key for the second node of the home network of the UE in the registration process of the UE or after the registration is completed.
[0328] As shown in FIG. 4A, the embodiments of the present disclosure provide a key processing method, executed by a second node of a home network, the method comprising:
[0329] S4101: receiving a first message.
[0330] In some embodiments, the second node of the home network receives the first message sent by the first node. In some embodiments, the first message includes the second key and the identity of the UE; the service network of the UE is not the home network.
[0331] In some embodiments, the second key included in the first message can be a key generated by the UE in the primary registration process. In some embodiments, the second key can be a key generated by the first node in the case of determining that the service network of the UE is not the home network.
[0332] In some embodiments, the related description of the first message can refer to the corresponding embodiments of FIG. 2A, which will not be repeated here.
[0333] S4102: sending a second message.
[0334] In some embodiments, the second message can be used to indicate whether the second node of the home network receives the second key.
[0335] In some embodiments, the second node of the home network sends the second message to the first node. Illustratively, sending the second message is an optional step.
[0336] In some embodiments, the home network, the first node, the second node and / or the second message can be understood with reference to the corresponding embodiments of FIG. 2A.
[0337] S4103: sending a second indication.
[0338] In some embodiments, the second node of the home network sends the second indication to the UE. The second indication is used to instruct the UE to generate the sixth key.
[0339] In some embodiments, the second node of the home network sends the second indication to the UE after obtaining the second key.
[0340] It is worth noting that S4103 is an optional step. For example, the second node of the home network does not need to send the second indication to the UE. The UE can generate the second key by itself in the case that the serving network is not the home network. In some other embodiments, the UE does not determine whether the serving network and the home network are the same. The UE will generate the first key for the second node of the serving network and the second key for the second node of the home network, respectively. In this case, if the serving network and the home network of the UE are the same, the first key and the second key are the same. If the serving network and the home network of the UE are different, the first key and the second key are different.
[0341] As shown in FIG. 4B, the embodiments of the present disclosure provide a key processing method, which is performed by a second node of a home network, and the method comprises:
[0342] S4201: receiving a fourth request.
[0343] In some embodiments, the second node of the home network receives the fourth request sent by a third node of the home network.
[0344] In some embodiments, the fourth request can be used to request a fourth key of the third node of the home network. For example, the fourth request, the second node of the home network and / or the third node can be understood with reference to the corresponding embodiments of FIG. 2B, which will not be repeated here.
[0345] S4202: sending a third request.
[0346] In some embodiments, the third request is sent to the first node according to the fourth request. In some embodiments, the third request can include the identity of the UE and the identity of the third node sending the fourth request included in the fourth request.
[0347] S4203: receiving a third response.
[0348] In some embodiments, the second node of the home network receives the third response sent by the first node. In some embodiments, the third response comprises the second key. In some embodiments, the optional implementation of the generation of the second key can refer to the corresponding embodiments of FIG. 2A.
[0349] S4204: sending a fourth response.
[0350] In some embodiments, the second node of the home network sends the fourth response to the third node of the home network.
[0351] In some embodiments, the fourth response comprises but is not limited to a fourth key. Illustratively, the fourth key is generated according to the second key. The fourth key can be a root key for the communication between the third node of the home network and the UE. The root key can be used by the third node of the home network to generate an integrity key and / or a confidentiality key for the communication with the UE.
[0352] As shown in FIG. 5A, the embodiments of the present disclosure provide a key processing method, executed by a UE, comprising:
[0353] S5101: receiving a second indication.
[0354] In some embodiments, the UE receives the second indication sent by the second node of the home network.
[0355] In some embodiments, the second indication is used to instruct the UE to generate the sixth key.
[0356] In some embodiments, the second indication sent by the second node of the home network is received during the registration process of the UE or after the UE completes the registration.
[0357] S5102: generating a sixth key.
[0358] In some embodiments, the UE receives the second indication and generates the sixth key.
[0359] It is worth noting that S5101 is an optional step, i.e., the UE can also generate the sixth key without receiving the second indication. Illustratively, the service network of the UE is not the home network, and the sixth key is generated.
[0360] In some embodiments, the service network of the UE is not the home network, and the eighth key and the sixth key are generated. The sixth key is related to the second node of the home network. The eighth key is related to the second node of the service network.
[0361] In some embodiments, the related descriptions of the home network, the second node, the first node, the sixth key, and the eighth key can refer to the corresponding embodiments of FIG. 2A and / or FIG. 2B.
[0362] In some embodiments, the UE generates the sixth key when initiating the network registration procedure, or, the UE generates the sixth key before sending the message to the third node of the home network. The optional implementation of the UE generating the sixth key can refer to the corresponding embodiments of FIG. 2A and / or FIG. 2B.
[0363] S5103: generating a seventh key.
[0364] In some embodiments, the seventh key is generated when there is a communication demand between the UE and the third node of the home network. For example, the seventh key is generated from the sixth key when there is a communication demand between the UE and the third node of the home network.
[0365] In some embodiments, the seventh key can be a root key of security keys for communication between the UE and the third node of the home network.
[0366] It is worth noting that S5103 is an optional step. For example, the UE does not have a communication demand with the third node of the home network after generating the sixth key, and then S5103 can be omitted.
[0367] S5104: generating an eighth key.
[0368] In some embodiments, the eighth key is related to the second node of the service network of the UE. If the UE does not perform the determination of whether the service network is the home network, the sixth key and the eighth key will be generated. If the service network of the UE and the home network are the same, the sixth key and the eighth key are the same. If the service network of the UE and the home network are different, the sixth key and the eighth key are different.
[0369] In some embodiments, the optional implementation of the UE generating the eighth key can refer to the corresponding embodiments of FIG. 2A and / or FIG. 2B.
[0370] S5105: generating a ninth key.
[0371] In some embodiments, the UE generates the ninth key from the eighth key. The ninth key can be a root key of security keys for communication between the UE and the third node of the service network.
[0372] It is worth noting that any one of S5101 to S5104 can be performed alone. For example, if the service network of the UE is the home network, S5102 can be performed alone. The UE finds that it is connected to the home network, and there is no need to wait for the second node of the home network to send the second indication. Other steps are necessary to be performed, and therefore, S5101, S5103 to S5104 are optional steps.
[0373] In some embodiments, if the service network of the UE is not the home network, the UE needs to generate the sixth key and the eighth key.
[0374] As shown in FIG. 5B, the embodiment of the present disclosure provides a key processing method, executed by a UE, comprising:
[0375] S5201: The UE sends a communication request.
[0376] In some embodiments, the UE requests communication with a third node of the home network. Illustratively, the UE requests communication with the third node of the home network through the sending of the communication request.
[0377] In some embodiments, the description of the home network, the third node of the home network, and the like can be referred to the corresponding embodiments of FIG. 2B.
[0378] S5202: The sixth key is generated.
[0379] In some embodiments, the UE generates the sixth key when requesting communication with the third node of the home network. Illustratively, the UE generates the sixth key when the serving network of the UE is not the communication network.
[0380] In some embodiments, the optional implementation of the UE generating the sixth key can be referred to the corresponding embodiments of FIG. 2A and / or FIG. 2B.
[0381] S5203: The seventh key is generated.
[0382] In some embodiments, the seventh key is generated when there is a communication demand between the UE and the third node of the home network. Illustratively, the seventh key is generated according to the sixth key when there is a communication demand between the UE and the third node of the home network.
[0383] In some embodiments, the seventh key can be a root key of a security key for communication between the UE and the third node of the home network.
[0384] It is worth noting that S5203 is an optional step. For example, after the UE generates the sixth key, there is no communication demand with the third node of the home network, and then this S5203 can be omitted.
[0385] S5204: The eighth key is generated.
[0386] In some embodiments, the UE generates the eighth key according to the fifth key.
[0387] In some embodiments, the optional implementation of the UE generating the eighth key can be referred to the corresponding embodiments of FIG. 2A and / or FIG. 2B.
[0388] It is worth noting that any one of S5201 to S5204 can be executed alone. For example, if the serving network of the UE is the home network, S5202 can be executed alone, the UE finds that it is connected to the home network, and there is no need to wait for the second node of the home network to send the second indication, and other steps are necessary to be executed again, therefore, S5201, S5203 to S5204 are optional steps.
[0389] In some embodiments, if the serving network of the UE is not the home network, the UE needs to generate the sixth key and the eighth key.
[0390] As shown in FIG. 6, the embodiments of the present disclosure provide a key processing method, executed by a fourth node. The method can include:
[0391] S6101: receiving a second request.
[0392] In some embodiments, the second request is received from the first node.
[0393] In some embodiments, the second request is used to request the fourth node to provide authentication information of the UE.
[0394] In some embodiments, the second request at least includes identification information of the UE.
[0395] S6102: sending a second response.
[0396] In some embodiments, the second response is sent to the first node according to the second request.
[0397] In some embodiments, the second response includes an authentication result of the UE and a first indication.
[0398] In some embodiments, the first indication is used to indicate whether the first node generates a second key for a second node of the home network of the UE.
[0399] In some embodiments, the second key is used for the second node of the home network to generate a fourth key, and the fourth key is used to protect the communication security between the UE and a third node of the home network.
[0400] In some embodiments, the second request, the fourth node, the second request and / or the related description of the second response can refer to the corresponding embodiments of FIG. 2A, which will not be repeated here.
[0401] The related 5G security key hierarchy does not support protection of NAS signaling between the terminal and core NFs other than the AMF. The existing NAS Security Mode Command (SMC) for negotiating NAS security algorithms is only performed between the terminal and the AMF. Other NFs do not support the NAS SMC procedure.
[0402] The existing 5G security key hierarchy does not support protection of NAS signaling between the terminal and core NFs other than the AMF. The existing NAS Security Mode Command (SMC) for negotiating NAS security algorithms is only performed between the terminal and the AMF. Other NFs do not support the NAS SMC procedure.
[0403] Some solutions target security between the UE and NFs of the serving network, and some solutions target security between the UE and NFs of the home network, but for the sixth generation mobile communication (6 th Generation,6G) multi-NAS architecture, these proposals cannot achieve unified security protection between the terminal and NFs.
[0404] Embodiments of the present disclosure provide a method to enhance the existing 5G security key hierarchy, support unified 6G multi-NAS architecture security protection mechanism between the terminal and core NFs, and support NFs residing in both the service network and the home network.
[0405] In the current 5G system, the key of NAS signaling is derived by the terminal and the AMF according to the key hierarchy as shown in FIG. 7A.
[0406] K AMF is the key of the serving network AMF derived by the UE and K SEAF . NASint and K NASenc are NAS keys derived by the UE and the AMF from K AMF . NASint is the integrity key derived based on K AMF . NASenc is the confidentiality key derived based on K AMF .
[0407] The root key of the current NAS security is K SEAF , which is derived by the AUSF in the home network (HN) and delivered to the SEAF in the serving network (SN). In the roaming scenario, the SN is different from the HN, such as K SEAFFrom AUSF in PLMN-1 to SEAF in PLMN-2. In non-roaming scenario, SN is also HN, e.g., K SEAF From AUSF in the same PLMN to SEAF.
[0408] To achieve unified security protection for NAS or NF signaling between UE and core NFs (SN or HN), the embodiments of the present disclosure propose that, in the primary authentication procedure, the AUSF extracts K AUSF from K SEAF key for SEAF in HN and SEAF in SN. AUSF Respectively derived by UE and AUSF during primary authentication. If UE is not roaming (i.e., SN is also HN), it means that K SEAF key for SEAF in HN and SEAF in SN is the same.
[0409] Based on K SEAF , UE and SEAF derive a key K NF for each specific target NF. For NF in HN, K NF is derived by SEAF in HN. For NF in SN, K NF is derived by SEAF in SN.
[0410] NAS or NF security key, i.e., K NFint for NAS or NF signaling integrity protection between UE and target NF and K NFenc for NAS or NF signaling confidentiality protection between UE and target NF, are derived by UE and NF from K NF . Therefore, the new key hierarchy is shown in FIG. 1F.
[0411] When deriving K AUSF from K SEAF , the following parameters are used to form the input S of KDF:
[0412] fc = pending
[0413] p0 = <network name of serving network>;
[0414] l0 = <network name of serving network>;
[0415] The input key is K AUSF .
[0416] When deriving K AUSF from K SEAF , the following parameters are used to form the input S of KDF:
[0417] fc = pending
[0418] p0 = <network name of home network>;
[0419] l0 = length of <network name of home network>;
[0420] The input key is K AUSF . Illustratively, the K AUSF is the aforementioned fifth key.
[0421] When the UE is not roaming, <network name of serving network> = <network name of home network>. When the UE is in roaming state, the AUSF derives the keys for K SEAF , one for the SEAF in the SN where the UE is connected, and the other for the SEAF in the HPLMN of the UE.
[0422] Perform 5G primary authentication procedure, e.g. authenticate the UE during UE registration. A successful 5G primary identity authentication will result in K AUSF being stored in the AUSF and the UE. Figure 7A illustrates the procedure to derive K SEAF for the SEAF in the SN and HN during the primary authentication procedure.
[0423] 1. The UE sends a registration request, which includes SUCI or 5G GUTI.
[0424] 2. According to the policy of the SEAF, whenever the SEAF wishes to initiate identity authentication with the UE in any procedure that establishes a signaling connection with the UE, the SEAF sends an Nausf_UEAuthentication_Authenticate Request message to the AUSF. The request contains the name of the network where the SEAF is located.
[0425] 3. Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF temporarily stores the received network name of the serving network and sends an Nudm_UEAuthentication_Get Request to the UDM, which includes the SUCI / SUPI and the network name of the serving network.
[0426] 4. Upon receiving the Nudm_UEAuthentication_Get request, the UDM / ARPF derives K AUSF and creates a 5G HE authentication vector (AV) containing K AUSF .
[0427] 5. The UDM returns the 5G Home network Environment Authentication Vector (HEAV) to the AUSF in a num_ueauthentication_get response. The UDM also compares the network name of the serving network received to its own network name. If the serving network is different from the home network, the UDM also includes K SEAFHN indication.
[0428] 6. The AUSF derives K AUSF from K SEAF and returns the 5G Service network Environment Authentication Vector (SEAV) to the SEAF in a Nausf_UEAuthentication_UEAuthentication response. K SEAF = KDF(K AUSF , SN-name).
[0429] 7. The SEAF sends a NAS message Authentication Request to the UE.
[0430] 8. The UE returns a NAS message Authentication Response to the SEAF.
[0431] 9. The SEAF determines from the perspective of the serving network whether the authentication was successful. If so, the SEAF will send a Nausf_UEAuthentication_Authenticate Request message to the AUSF.
[0432] 10. The AUSF indicates to the SEAF in a Nausf_UEAuthentication_Authenticate response whether the authentication was successful from the perspective of the home network. If the authentication was successful, K SEAF will be sent to the SEAF in the Nausf_UEAuthentication_Authenticate response.
[0433] 11. If the UDM does not send an indication of K SEAFHN to the AUSF in step 5, the AUSF can compare the network name of the serving network received to its own network name. If the serving network is different from the home network, the AUSF derives K AUSF from K SEAFHN . KsEAFHN =KDF(K AUSF HN-name).
[0434] 12. AUSF will use the derived K key registration request via NAS security key registration. SEAFHN SEAF sent to HN.
[0435] 13. In HN, SEAF returns a NAS security anchor key registration response to AUSF.
[0436] Note: Steps 11-13 are executed during roaming in the initial registration and master authentication process. If the UE does not roam during the initial registration period, the K derived from step 10 will be executed instead. SEAF Also K SEAFHN Therefore, steps 11-13 are not required. If the UE is not roaming, it means that the UE's current serving network is its home network.
[0437] As shown in Figure 7B, this disclosure provides another key processing method, which may include:
[0438] 1. Before the UE initiates NAS message communication to the NF of its home network through the RAN node or the service-based interface, the UE first determines whether the network it is currently camped on is its home network, and / or, the UE detects whether the NF it is currently requesting communication to is the NF of its current serving network.
[0439] A: If the target NF is an NF within the serving network (such as an LMF), the UE checks whether the current serving network is the same one used during initial registration via primary authentication. If the current serving network is the same as the initial registration (the UE has not moved across networks since initial registration), the UE continues with subsequent steps. If the current serving network is different from the initial registration (the UE has moved across networks since initial registration), the UE will proceed from K... AUSF Derive a new K SEAF K SEAF The name of the current service network. K SEAF =KDF(K AUSF (Current SN-name). The UE uses the new K. SEAF Replace the old K SEAF (If available). SN-name represents the network name of the service network.
[0440] New K SEAFDerivation can also be achieved through a new primary authentication procedure triggered by the current serving network (due to UE cross-network mobility). UE cross-network mobility implies that the UE's serving network has changed. For example, the UE's serving network is switched from a home network to a non-home network. If the target NF is a NF in the home network (e.g. PCF), the UE derives K SEAFHN from KAUSF using its home network name. SEAFHN K AUSF = KDF(K SEAFHN , HN-name). HN-name represents the network name of the home network.
[0441] B: If the UE does not roam and stays in the home network after the first registration primary authentication, the derived K SEAF may be the same as the K SEAFHN derived during primary authentication.
[0442] 2. Depending on the network residence of the target NF, if the target NF is a NF in the serving network (e.g. LMF), the UE derives K NF from K SEAF obtained during primary authentication or from the previous step, for example, if the third node of the home network is LMF, then K LMF for LMF. If the target NF is a NF in the home network (e.g. PCF), the UE derives K NF from K SEAFHN derived in sub-step B of step 1, for example, if the third node of the home network is PCF, then K PCF is obtained.
[0443] 3. The UE encapsulates the unprotected NAS or NF message in an RRC message.
[0444] 4. The RAN node forwards the unprotected NAS or NF message and the UE's security capabilities to the UE according to the received NAS or NF message type or the UE specified target NF type.
[0445] 5. When receiving the unprotected NAS or NF message, the NF sends a key generation request message to SEAF. The NF always sends the request to the SEAF in the same network, i.e.:
[0446] a. If the target NF is a NF in the serving network (e.g. LMF), the NF sends the request to the SEAF in the SN.
[0447] b. If the target NF is a NF in the home network (e.g. PCF), the NF sends the request to the SEAF in the HN.
[0448] Upon receiving the key generation request from the NF, if the SEAF does not have available K SEAFThen the SEAF can request the KSEAF to be generated from the AUSF for the following two reasons:
[0449] a. The SEAF in the HN can request the AUSF of the UE to generate the K SEAFHN by sending its network name and the UE ID.
[0450] NOTE 2: At first registration using primary authentication, the UE can not be roaming. In this case, the K SEAFHN will not be derived by the AUSF in the HN and delivered to the SEAF in step 12 in section 2.2.2.1. If the non-roaming UE is roaming when sending the initial NAS or NF signaling message to the NF in the HN in step 3, the SEAF in the HN will receive the key generation request from the NF in the HN in step 5b, and the SEAF in the HN has no available K SEAFHN .
[0451] b. The SEAF in the SN can also request the AUSF of the UE to generate the K SEAF by sending its network name and the UE ID. SEAF Even if the K SEAF has already been derived by the AUSF according to step 10 in Figure 7A. The SEAF in the SN looks up the AUSF of the UE according to the realm part of the UE ID.
[0452] It is worth noting that: assuming the UE is roaming in one serving network (SN-1) during the first registration primary authentication. The UE can later roam to another serving network (SN-2) when sending the initial NAS or NF signaling message to the NF in SN-2 in step 3. The SEAF in SN-2 receiving the key generation request in step 5a then has no available K SEAF because the K SEAF received in step 10 in the first registration procedure shown in Figure 7A is for the SEAF in SN-1.
[0453] The AUSF can return the derived K SEAF or K SEAFHN to the requesting SEAF.
[0454] 8. The SEAF retrieves the K SEAF from the UE ID (SUPI) received from the NF. Depending on the network residence of the NF,
[0455] a. If the target NF is a NF in the serving network (e.g. LMF), the SEAF derives the K SEAF from the K NF received in step 10 shown in Figure 7A or step 7 shown in Figure 7B, e.g. derives the K LMF .
[0456] b. If the target NF is a NF in the home network (e.g. PCF), the SEAF derives K SEAFHN from the K NF received in step 12 of Figure 7A or step 7 of Figure 7B. PCF .
[0457] 9. The SEAF returns a key generation response to the NF containing the derived K
[0458] 10. The NAS or NF security mode performs a command operation between the UE and the NF. From this step onwards, the NAS or NF security context is now available in the UE and the NF.
[0459] 11. The NF sends its response to the initial NAS or NF message, which is protected by the NAS or NF security context.
[0460] 12. The RAN node encapsulates the protected response message in a RRC message, which is sent to the UE, which can verify the response using its NAS or NF security context.
[0461] Alternatively, the SEAF in the HN can send a message to the UE after step 13 of Figure 7A to initiate the derivation of K SEAFHN by the UE after a successful primary authentication during first registration. If so, step 1 sub-step B of the NAS or NF signaling of Figure 7B can be skipped.
[0462] In some embodiments, the UE should be able to perform at least one of the following:
[0463] The UE needs to determine when to derive K SEAF and / or K SEAFHN by checking the network residence of the target NF, i.e. whether the target NF is in the SN or the HN.
[0464] The UE should be able to determine when to derive a new K SEAF by comparing the serving network of the target NF to the serving network it attached to at first registration.
[0465] The UE should be able to receive and understand an indication from the SEAF in the HN to obtain K SEAFHN after a successful primary authentication. K SEAFHN is a second key of a second node of the home network.
[0466] The user should be able to derive K SEAFHN by using its own home network name.
[0467] In some embodiments, the AUSF should be able to perform at least one of the following:
[0468] K based on UDM SEAFHN Indicate that after successful primary authentication, the AUSF shall be able to determine to derive K SEAFHN .
[0469] By comparing the service network of SEAF and its own network, the AUSF shall be able to determine to derive K after successful primary authentication SEAFHN .
[0470] The AUSF shall be able to derive K by using its own network name SEAFHN .
[0471] The AUSF shall be able to register the derived K SEAFHN and the related UE ID to the SEAF in the HN.
[0472] The AUSF shall be able to derive K SEAF after receiving the request of SEAF.
[0473] The SEAF shall be able to perform at least one of the following operations:
[0474] The SEAF shall be able to decide whether to request the AUSF to generate K SEAF or K SEAFHN according to the key generation request of NF and the availability of K SEAF or K SEAFHN .
[0475] The SEAF shall be able to request the AUSF to generate K SEAF or K SEAFHN by sending its network name and UE ID.
[0476] The SEAF shall be able to determine how to derive KNF from K SEAF or K SEAFHN according to the network residence of the target NF, i.e., whether the target NF is in the SN or the HN.
[0477] The SEAF shall be able to send a message to the UE after successful primary authentication to start the UE to derive K SEAFHN .
[0478] The UDM shall be able to indicate to the AUSF whether K SEAFHN needs to be derived after successful primary authentication by comparing the service network of SEAF and its own network.
[0479] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.
[0480] The embodiments of the present disclosure further provide a device for implementing any of the above methods, for example, a device is provided, and the device includes units or modules for implementing the steps performed by the UE in any of the above methods. For another example, another device is provided, and the device includes units or modules for implementing the steps performed by the network device (for example, an access network device, or a core network device, etc.) in any of the above methods.
[0481] It should be understood that the division of each unit or module in the above device is only a logical function division, and all or part of the units or modules can be integrated into one physical entity, or can be physically separated. In addition, the units or modules in the device can be implemented in the form of processor calling software: for example, the device includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules of the device, wherein the processor is a general processor, for example, a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by designing the hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by designing the logical relationship of elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.
[0482] In embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), etc. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
[0483] As shown in FIG. 8A, embodiments of the present disclosure provide a first node, comprising:
[0484] The processing module 8111 is configured to generate a first key for a second node of a serving network of a user equipment (UE), and generate a second key for a second node of a home network of the UE. The first key is used by the second node of the serving network to generate a third key, the third key is used to protect the communication security between the UE and a third node of the serving network. The second key is used by the second node of the home network to generate a fourth key, and the fourth key is used to protect the communication security between the UE and a third node of the home network.
[0485] In some embodiments, the first node can further include a sending module and / or a receiving module. For example, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first node.
[0486] In some embodiments, the processing module can be configured to perform, by the first node, steps related to information processing in any one of the key processing methods.
[0487] In some embodiments, the sending module can be configured to perform, by the first node, steps related to information sending in any one of the key processing methods.
[0488] In some embodiments, the receiving module can be configured to perform, by the first node, steps related to information sending in any one of the key processing methods.
[0489] In some embodiments, the processing module is configured to generate, according to a fifth key of the first node and a network name of the serving network, a first key for a second node of a serving network of the UE, and generate, according to the fifth key of the first node and a network name of the home network, a second key for a second node of a home network of the UE.
[0490] In some embodiments, the processing module is configured to receive a first request sent by the second node of the serving network, generate a first key for the second node of the serving network of the UE, the first request being used to request authentication of the UE, and send a first response to the second node of the serving network according to whether the UE is authenticated, the first response including at least an authentication result of the UE.
[0491] In some embodiments, the sending module is configured to send, according to the first request, a second request to a fourth node, the second request being used to request the fourth node to provide authentication information of the UE.
[0492] The receiving module is configured to receive a second response sent by the fourth node, the second response including at least authentication information provided by the fourth node to the UE.
[0493] The processing module is configured to authenticate the UE according to the second response.
[0494] In some embodiments, the first request includes a network name of the serving network, and the second response further includes a first indication, the first indication being used to indicate whether the first node generates the second key for the second node of the home network.
[0495] In some embodiments, the first request includes a network name of the serving network, and the method further includes:
[0496] Determining, by comparing the network name of the serving network and the network name of the home network, whether the serving network of the UE is the home network.
[0497] In some embodiments, the UE is authenticated, and the first response comprises the first key.
[0498] In some embodiments, the sending module is configured to send, to a second node of the home network, a first message, the first message comprising the second key and an identity of the UE; and the serving network of the UE is not the home network.
[0499] In some embodiments, the receiving module is configured to receive a second message sent by the second node of the home network, the second message being used to indicate whether the second node of the home network receives the second key.
[0500] In some embodiments, the receiving module is configured to receive a third request sent by the second node of the home network, the third request being used to request the first node to generate the second key for the second node.
[0501] In some embodiments, the sending module is configured to send, to the second node of the home network, a third response, the third response comprising the second key.
[0502] As shown in FIG. 8B, the embodiments of the present disclosure provide a second node of a home network, comprising:
[0503] The receiving module 8211 is configured to receive a second key sent by a first node, the second key being used for the second node of the home network to generate a fourth key, the fourth key being used to protect the communication security between the UE and a third node of the home network.
[0504] In some embodiments, the third node can further comprise a processing module and / or a sending module.
[0505] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the source node.
[0506] In some embodiments, the processing module can be used for the second node of the home network to perform the information processing related steps in any one of the key processing methods.
[0507] In some embodiments, the sending module can be used for the second node of the home network to perform the information sending related steps in any one of the key processing methods.
[0508] In some embodiments, the receiving module can be used for the second node of the home network to perform the information sending related steps in any one of the key processing methods.
[0509] In some embodiments, the receiving module is configured to receive a first message sent by the first node, the first message comprising the second key and an identity of the UE.
[0510] In some embodiments, the sending module is further configured to send a second message to the first node, the second message being used to indicate whether the second key is received by a second node of the home network.
[0511] In some embodiments, the receiving module is configured to receive a fourth request sent by a third node of the home network, the fourth request being used to request the fourth key;
[0512] The sending module is configured to send a third request to the first node, the third request being used to request the first node to generate the second key for the second node;
[0513] The receiving module is configured to receive a third response sent by the first node, the third response comprising the second key of the second node;
[0514] The sending module is configured to send a fourth response to the third node of the home network, the fourth response comprising the second key.
[0515] In some embodiments, the sending module is configured to send a second indication to the UE; the second indication being used to instruct the UE to generate a sixth key associated with a second node of the home network; the sixth key being used by the UE to generate a seventh key; the seventh key being used to protect a communication security between the UE and a third node of the home network.
[0516] As shown in FIG. 8C, the embodiments of the present disclosure provide a UE, wherein the UE comprises:
[0517] The processing module 8311 is configured to generate a sixth key when the serving network of the UE is not the home network; the sixth key being associated with a second node of the home network of the UE, the sixth key being used by the UE to generate a seventh key; the seventh key being used to protect a communication security between the UE and a third node of the home network.
[0518] In some embodiments, the UE can further comprise a sending module and / or a receiving module.
[0519] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the network node.
[0520] In some embodiments, the processing module can be used by the UE to perform steps related to information processing in any one of the key processing methods.
[0521] In some embodiments, the sending module can be configured to perform the steps related to information sending in any one of the key processing methods by the UE.
[0522] In some embodiments, the receiving module can be configured to perform the steps related to information sending in any one of the key processing methods by the UE.
[0523] In some embodiments, the processing module is configured to determine, by the UE in the process of requesting network registration, whether the serving network to which the UE is currently attached is the home network; and determine that the serving network of the UE is not the home network when the serving network to which the UE is currently attached is not the home network.
[0524] In some embodiments, the processing module is configured to generate the sixth key after the first authentication of the UE in the network registration is successful when the serving network of the UE is not the home network.
[0525] In some embodiments, the processing module is configured to generate an eighth key after the first authentication of the UE is successful, the eighth key is associated with a second node of the serving network, and the eighth key is used by the UE to generate a ninth key; the ninth key is used to protect the security of communication between the UE and a third node of the serving network.
[0526] In some embodiments, the processing module is configured to generate the eighth key according to the network name of the serving network and the fifth key of the first node.
[0527] In some embodiments, the processing module is configured to generate the sixth key when the serving network of the UE is not the home network and the network node with which the UE requests communication belongs to the home network.
[0528] In some embodiments, the processing module is configured to receive a second indication sent by a second node of the home network; the second indication is used to instruct the UE to generate the sixth key; and the sixth key is generated after the second indication is received.
[0529] In some embodiments, the processing module is configured to generate the sixth key according to the network name of the home network and the fifth key of the first node when the serving network of the UE is not the home network.
[0530] In some embodiments, the processing module is configured to determine the network to which the network node with which the UE requests communication belongs.
[0531] The sixth key is generated when the serving network of the UE is not the home network and the network node with which the UE requests communication belongs to the home network.
[0532] As shown in FIG. 8D, the embodiments of the present disclosure provide a third node of a home network, the third node of the home network comprising:
[0533] The sending module 8411 is configured to send a fourth request to a second node of a home network of a user equipment (UE), the fourth request being used to request the second node of the home network to generate a fourth key;
[0534] The receiving module 8412 is configured to receive a fourth response sent by the second node of the home network, the fourth response comprising the fourth key.
[0535] The fourth key is generated by the second node of the home network according to a second key, the fourth key being used to protect the communication security between the UE and a third node of the home network; and the second key is generated by a first node for the second node.
[0536] In some embodiments, the third node of the home network further comprises a processing module.
[0537] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the second node.
[0538] In some embodiments, the processing module can be used by the third node of the home network to perform the information processing related steps in any one of the key processing methods.
[0539] In some embodiments, the sending module can be used by the third node of the home network to perform the information sending related steps in any one of the key processing methods.
[0540] In some embodiments, the receiving module can be used by the third node of the home network to perform the information sending related steps in any one of the key processing methods.
[0541] As shown in FIG. 8E, the embodiments of the present disclosure provide a fourth node, the fourth node comprising:
[0542] The receiving module 8511 is configured to receive a second request sent by a first node, the second request being used to request the fourth node to provide authentication information of the UE.
[0543] The sending module is configured to send a second response to the first node according to the second request, the second response comprising the authentication information of the UE and a first indication; the first indication being used to indicate whether the first node generates a second key for a second node of a home network of the UE; and the second key being used by the second node of the home network to generate a fourth key, the fourth key being used to protect the communication security between the UE and a third node of the home network.
[0544] The embodiments of the present disclosure further provide a communication device, which can include one or more processors; wherein the processor is configured to invoke instructions to enable the communication device to perform the key processing method implemented by any one of the preceding embodiments.
[0545] In some embodiments, as shown in FIG. 9A and / or FIG. 9B, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memory 8102 can also be located outside the communication device 8100.
[0546] The communication device can be the UE and the network device described above. In some embodiments, the network device can be a master node and / or a secondary node.
[0547] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as transmission and reception in the above method are performed by the transceiver 8103, and the other steps are performed by the processor 8101.
[0548] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.
[0549] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102, and can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read the instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0550] The communication device 8100 described in the above embodiments can be a network device or a UE, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by FIG. 9A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a UE device, a smart UE device, a cellular phone, a wireless device, a handset, a mobile unit, a car-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.
[0551] FIG. 9B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 9B can be referred to, but is not limited thereto.
[0552] The chip 8200 includes one or more processors 8201 for invoking instructions to cause the chip 8200 to perform any of the above key processing methods.
[0553] In some embodiments, the chip 8200 further includes one or more interface circuits 8202 connected with the memory 8203, which can be used to receive signals from the memory 8203 or other devices, and can be used to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201. Alternatively, the terms interface circuit, interface, transceiver pin, and transceiver can be replaced with each other.
[0554] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Alternatively, all or part of the memory 8203 can be outside the chip 8200.
[0555] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 8100, cause the communication device 8100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer-readable storage medium, but can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.
[0556] The present disclosure also provides a program product which, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above key processing methods. Optionally, the program product is a computer program product.
[0557] The present disclosure also provides a computer program which, when executed on a computer, causes the computer to perform any of the above key processing methods.
[0558] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure embodiments following, in general, the principles of the present disclosure and including such features to the extent that they are not disclosed in the prior art. The specification and examples are to be regarded as illustrative only, and the true scope and spirit of the present disclosure embodiments are indicated by the following claims.
[0559] It should be understood that the present embodiments are not limited to the precise structures as herein described and illustrated in the drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of this present disclosure. The scope of the present embodiments should only be limited by the appended claims.
Claims
1. A key processing method, wherein, The method performed by a first node comprises: generating a first key for a second node of a serving network of a user equipment (UE); generating a second key for a second node of a home network of the UE; wherein the first key is used by the second node of the serving network to generate a third key, the third key is used to protect a communication security between the UE and a third node of the serving network; and the second key is used by the second node of the home network to generate a fourth key, the fourth key is used to protect a communication security between the UE and a third node of the home network.
2. The method of claim 1, wherein, The method of generating the first key for the second node of the serving network of the UE and generating the second key for the second node of the home network of the UE comprises: generating the first key for the second node of the serving network of the UE according to a fifth key of the first node and a network name of the serving network; generating the second key for the second node of the home network of the UE according to the fifth key of the first node and a network name of the home network.
3. The method of claim 1 or 2, wherein, The method of generating the first key for the second node of the serving network of the UE comprises: receiving a first request sent by the second node of the serving network, the first request is used to request to authenticate the UE; sending a first response to the second node of the serving network according to whether the UE is authenticated, the first response at least comprises an authentication result of the UE.
4. The method of claim 3, wherein, The method further comprises: sending a second request to a fourth node according to the first request, the second request is used to request the fourth node to provide authentication information of the UE; receiving a second response sent by the fourth node, the second response at least comprises authentication information provided by the fourth node to the UE; authenticating the UE according to the second response.
5. The method of claim 3 or 4, wherein, The first request comprises a network name of the serving network; and the second response further comprises a first indication, the first indication is used to indicate whether the first node generates the second key for the second node of the home network.
6. The method of claim 3 or 5, wherein, The first request comprises a network name of the serving network, and the method further comprises: determining whether the serving network of the UE is the home network by comparing the network name of the serving network and a network name of the home network.
7. The method of claim 3, wherein, The UE is authenticated, and the first response comprises the first key.
8. The method according to any one of claims 1 to 7, wherein, The method comprises: sending a first message to the second node of the home network, the first message comprises the second key and an identity of the UE; and the serving network of the UE is not the home network.
9. The method of claim 8, wherein, The method further comprises: receiving a second message sent by the second node of the home network, the second message is used to indicate whether the second node of the home network receives the second key.
10. The method of claim 1 or 2, wherein, The method further comprises: receiving a third request sent by the second node of the home network, the third request is used to request the first node to generate the second key for the second node.
11. The method of claim 10, wherein, The method further comprises: sending a third response to a second node of the home network, the third response comprising the second key.
12. A key processing method, wherein, The method is performed by a second node of a home network, the method comprising: receiving a second key sent by a first node, the second key being used by the second node of the home network to generate a fourth key, the fourth key being used to protect a communication between the UE and a third node of the home network.
13. The method of claim 12, wherein, The receiving the second key sent by the first node comprises: receiving a first message sent by the first node, the first message comprising the second key and an identity of the UE.
14. The method of claim 13, wherein, The method further comprises: sending a second message to the first node, the second message being used to indicate whether the second node of the home network receives the second key. The method further comprises:
15. The method of claim 12, wherein, receiving a fourth request sent by a third node of the home network, the fourth request being used to request the fourth key; sending a third request to the first node, the third request being used to request the first node to generate the second key for the second node; receiving a third response sent by the first node, the third response comprising the second key of the second node; sending a fourth response to the third node of the home network, the fourth response comprising the second key. The method further comprises:
16. The method according to any one of claims 12 to 15, wherein, sending a second indication to the UE, the second indication being used to indicate the UE to generate a sixth key associated with a second node of the home network, the sixth key being used by the UE to generate a seventh key, the seventh key being used to protect a communication between the UE and a third node of the home network. The method is performed by a user equipment (UE), the method comprising:
17. A key processing method, wherein, the service network of the UE is not the home network, generating a sixth key, the sixth key being associated with a second node of a home network of the UE, the sixth key being used by the UE to generate a seventh key, the seventh key being used to protect a communication between the UE and a third node of the home network.
18. The method of claim 17, the method further comprising: determining, by the UE, whether a service network to which the UE is currently attached is the home network during a process of requesting a network registration; the service network of the UE is not the home network, determining that the service network of the UE is not the home network. the service network of the UE is not the home network, generating the sixth key, comprises:
19. The method of claim 18, wherein, generating the sixth key after a first authentication of the UE in the network registration succeeds, in a case that the service network of the UE is not the home network. The method further comprises:
20. The method of any one of claims 17 to 19, wherein, the first authentication of the UE succeeds, generating an eighth key, the eighth key being associated with a second node of the service network, the eighth key being used by the UE to generate a ninth key, the ninth key being used to protect a communication between the UE and a third node of the service network. the first authentication of the UE succeeds, generating the eighth key, comprises:
21. The method of claim 20, wherein, generating the eighth key according to a network name of the service network and a fifth key of a first node. the service network of the UE is not the home network, generating the sixth key comprises:
22. The method of claim 17, wherein, The service network of the UE is not the home network and the network node to which the UE requests to communicate belongs to the home network, generating the sixth key.
23. The method of claim 17, wherein, The service network of the UE is not the home network, and generating the sixth key comprises: receiving a second indication sent by a second node of the home network; the second indication is used to instruct the UE to generate the sixth key; Upon receiving the second indication, the sixth key is generated.
24. The method of any one of claims 17 to 23, wherein, The service network of the UE is not the home network, and generating the sixth key comprises: The service network of the UE is not the home network, and the sixth key is generated according to a network name of the home network and a fifth key of the first node.
25. The method of claim 17, wherein, The method further comprises: determining the network to which the network node to which the UE requests to communicate belongs; The service network of the UE is not the home network, and generating the sixth key comprises: The service network of the UE is not the home network and the network node to which the UE requests to communicate belongs to the home network, generating the sixth key.
26. A key processing method, performed by a third node of a home network, the method comprising: sending a fourth request to a second node of the home network of a user equipment (UE), the fourth request being used to request the second node of the home network to generate a fourth key; receiving a fourth response sent by the second node of the home network, the fourth response comprising the fourth key; The fourth key is generated by the second node of the home network according to a second key, and the fourth key is used to protect the communication security between the UE and the third node of the home network; the second key is generated by the first node for the second node.
27. A key processing method, performed by a fourth node, the method comprising: receiving a second request sent by a first node, the second request being used to request the fourth node to provide authentication information of the UE; According to the second request, a second response is sent to the first node, the second response comprising the authentication information of the UE and a first indication; The first indication is used to indicate whether the first node generates a second key for a second node of a home network of the UE; the second key is used for the second node of the home network to generate a fourth key, and the fourth key is used to protect the communication security between the UE and the third node of the home network.
28. A first node, wherein, The first node comprises: a processing module configured to generate a first key for a second node of a service network of a user equipment (UE) and generate a second key for a second node of a home network of the UE; wherein the first key is used for the second node of the service network to generate a third key; the third key is used to protect the communication security between the UE and a third node of the service network; the second key is used for the second node of the home network to generate a fourth key, and the fourth key is used to protect the communication security between the UE and the third node of the home network.
29. A second node of a home network, wherein, The second node comprises: The receiving module is configured to generate a third key by a second node of the serving network, where the first key is used for the generation of the third key; the third key is used for protecting communication security between the UE and a third node of the serving network; and the second key is used for a second node of the home network to generate a fourth key, where the fourth key is used for protecting communication security between the UE and a third node of the home network.
30. A user equipment (UE), comprising: The UE comprises: The processing module is configured to generate a sixth key when the serving network of the UE is not the home network, where the sixth key is related to the second node of the home network of the UE, and the sixth key is used for the UE to generate a seventh key, and the seventh key is used for protecting communication security between the UE and a third node of the home network.
31. A third node of a home network, wherein, The third node comprises: The sending module is configured to send a fourth request to a second node of a home network of a user equipment (UE), where the fourth request is used for requesting the second node of the home network to generate a fourth key; The receiving module is configured to receive a fourth response sent by the second node of the home network, where the fourth response comprises the fourth key; The fourth key is generated by the second node of the home network according to a second key, where the fourth key is used for protecting communication security between the UE and a third node of the home network, and the second key is generated by a first node for the second node.
32. A fourth node, wherein, The fourth node comprises: The receiving module is configured to receive a second request sent by a first node, where the second request is used for requesting the fourth node to provide authentication information of the UE; The sending module is configured to send a second response to the first node according to the second request, where the second response comprises the authentication information of the UE and a first indication, and the first indication is used for indicating whether the first node generates a second key for a second node of a home network of the UE, and the second key is used for the second node of the home network to generate a fourth key, where the fourth key is used for protecting communication security between the UE and a third node of the home network.
33. A communication system, wherein, The communication system comprises a first node, a second node of a home network, a user equipment (UE), a third node of the home network, and a fourth node; The first node is configured to perform the method in any one of claims 1 to 11; The second node of the home network is configured to perform the method in any one of claims 12 to 16; The UE is configured to perform the method in any one of claims 17 to 25; The third node of the home network is configured to perform the method in claim 26; The fourth node is configured to perform the method in claim 27.
34. A communications device, comprising: The communication device comprises: One or more processors; The processor is used to invoke instructions to enable the communication device to perform the key processing method in any one of claims 1 to 11, 12 to 16, 17 to 25, 26, or 27.
35. A storage medium, wherein, The storage medium stores instructions which, when executed on the communication device, cause the communication device to perform the key processing method of any one of claims 1-11, 12-16, 17-25, 26, or 27.
36. A program product, wherein, The program product comprises a computer program which, when executed by a communication device, enables the communication device to implement the key processing method of any one of claims 1-11, 12-16, 17-25, 26, or 27.
Citation Information
Patent Citations
Communication method and related device
CN113873492A
Communication method and device, communication equipment and computer storage medium
CN117295068A
An authentication method for next generation systems
US20210144135A1
Key distribution methods, and apparatuses, device, and storage medium
WO2024098219A1
Wireless method and device thereof
WO2024168472A1