Information processing method, and device
By upgrading the N2 interface to the SBI protocol, generating an access coding key based on the core network equipment and verifying it with access credentials, the security policy problem that the base station cannot directly access other network elements on the core network side is solved, and secure communication between the terminal and the core network equipment is realized.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
- Filing Date
- 2024-10-18
- Publication Date
- 2026-04-23
AI Technical Summary
After the existing N2 interface is upgraded to the SBI protocol, the base station cannot directly access other core network elements on the core network side, resulting in a lack of security strategies and an inability to guarantee the security of communication between the terminal and other core network devices.
By generating a key derived from the access code of the first core network device, the message transmission between the terminal and the core network device is protected. Combined with the access credentials, the legitimacy of the access network device is verified, thus ensuring communication security.
This technology enables key-protected message transmission when a terminal accesses core network equipment, improving communication security and ensuring information security between the terminal and the core network equipment.
Smart Images

Figure CN2024125891_23042026_PF_FP_ABST
Abstract
Description
Information processing methods and equipment Technical Field
[0001] This application relates to the field of communications, and more specifically, to an information processing method and apparatus. Background Technology
[0002] In existing technologies, the N2 interface exists between the base station and the AMF (Access and Mobility Management Function). The base station can only access the core network through the N2 interface and cannot directly access other core network elements on the core network side. With the N2 interface being upgraded to the SBI (Service Based Interface) protocol, the base station can access other core network elements on the core network side. However, existing registration and access service policies only include service-related policies and lack security policies. Therefore, the security of terminal communication with other core network devices cannot be guaranteed.
[0003] Summary of the Invention
[0004] This application provides an information processing method and apparatus.
[0005] This application provides an information processing method executed by a terminal, including:
[0006] Receive the first access code from the first core network device;
[0007] Based on the first access code, a first key is generated, wherein the first key is used to protect messages between the terminal and the first core network device.
[0008] This application provides an information processing method executed by a first core network device, including:
[0009] Obtain a first key, wherein the first key is generated based on a first access code of the first core network device, and the first key is used to protect messages between the terminal and the first core network device.
[0010] This application provides an information processing method executed by a first access network device, including:
[0011] Send a first access code from the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.
[0012] This application provides an information processing method executed by a second core network device, including:
[0013] Send a first access code from the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.
[0014] This application provides an information processing method executed by a fourth core network device, including:
[0015] Send the access credential of the first core network device to the first access network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
[0016] This application provides an information processing method executed by a first access network device, including:
[0017] The system receives access credentials from the first core network device, which are used to verify whether the first access network device is allowed to access the first core network device.
[0018] This application provides a terminal, including:
[0019] The first communication unit is used to receive the first access code from the first core network device;
[0020] The first processing unit is configured to generate a first key based on the first access code, wherein the first key is used to protect messages between the terminal and the first core network device.
[0021] This application provides a first core network device, including:
[0022] The second communication unit is used to obtain a first key, wherein the first key is generated based on a first access code of the first core network device, and the first key is used to protect messages between the terminal and the first core network device.
[0023] This application provides a first access network device, including:
[0024] The third communication unit is used to send a first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
[0025] This application provides a second core network device, including:
[0026] The fourth communication unit is used to send a first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
[0027] This application provides a fourth core network device, including:
[0028] The fifth communication unit is used to send the access credential of the first core network device to the first access network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
[0029] This application provides a first access network device, including:
[0030] The third communication unit is used to receive the access credential of the first core network device from the fourth core network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
[0031] By adopting the above scheme, a key is derived between the terminal and the first core network device based on the first access code of the first core network device to protect messages between them. In this way, when the terminal accesses the first core network device, the key derived from the first access code of the first core network device can be used to protect messages between the two parties, thereby ensuring the security of communication. Attached Figure Description
[0032] Figure 1 is a schematic diagram of an application scenario according to an embodiment of this application.
[0033] Figure 2 is a schematic flowchart of an information processing method according to an embodiment of this application.
[0034] Figure 3 is a schematic flowchart of an information processing method according to another embodiment of this application.
[0035] Figure 4 is a schematic flowchart of an information processing method according to another embodiment of this application.
[0036] Figure 5 is a schematic flowchart of an information processing method according to another embodiment of this application.
[0037] Figure 6 is a schematic flowchart of an information processing method according to another embodiment of the present application.
[0038] Figure 7 is a schematic flowchart of an information processing method according to another embodiment of this application.
[0039] Figure 8 is a schematic flowchart illustrating the registration process of the first core network device and the process of the first access network device obtaining the access token of the first core network device according to an embodiment of this application.
[0040] Figure 9 is a schematic flowchart of the registration process of the first core network device, the process of the fourth core network device authorizing the first access network device to access and allocating access credentials to the base station, and the process of the base station requesting services, according to an embodiment of this application.
[0041] Figures 10 to 14 are various schematic flowcharts of the authentication and key generation process of a UE according to an embodiment of this application.
[0042] Figures 15 to 17 are various schematic flowcharts of a key generation process according to another embodiment of this application.
[0043] Figure 18 is a schematic flowchart illustrating the process of a first access network device requesting service, a terminal generating a first key, and a first core network device obtaining the first key according to an embodiment of this application.
[0044] Figure 19 is a schematic block diagram of a terminal according to an embodiment of this application.
[0045] Figure 20 is a schematic block diagram of a first core network device according to an embodiment of the present application.
[0046] Figure 21 is a schematic block diagram of a first access network device according to an embodiment of the present application.
[0047] Figure 22 is a schematic block diagram of a second core network device according to an embodiment of the present application.
[0048] Figure 23 is a schematic block diagram of a fourth core network device according to an embodiment of the present application. Detailed Implementation
[0049] The technical solutions of this application embodiment can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.
[0050] This application describes various embodiments in conjunction with network devices and terminals. The terminal can be mobile or fixed, and may also be referred to as a mobile station, user unit, etc. The terminal can be a station in a WLAN, or a smart terminal, wireless modem, laptop, tablet, etc. In this application's embodiments, the terminal can be a VR / AR terminal, industrial control terminal, autonomous driving terminal, telemedicine terminal, smart grid terminal, transportation safety terminal, smart city terminal, or smart home wireless terminal, etc. By way of example and not limitation, in this application's embodiments, the terminal can also be a wearable device.
[0051] In this embodiment, the network device can be a device for communicating with a terminal. The network device can be an access point in a WLAN, an evolved base station in LTE, a relay station, a network device (gNB) in a vehicle-mounted device, wearable device, or NR network, or a network device in a future PLMN network, or a network device in a non-terrestrial network, etc. As an example and not a limitation, in this embodiment, the network device can have mobility characteristics; for example, the network device can be a mobile device.
[0052] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.
[0053] Figure 1 exemplarily illustrates a communication system 100. The communication system includes network devices 110 and terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and each network device 110 may include at least one terminal 120 within its coverage area; this embodiment does not limit this. In another possible implementation, the communication system 100 may also include other network entities such as mobility management entities and access and mobility management functions; this embodiment does not limit this. The network devices may further include access network devices and first core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities; this embodiment does not limit this.
[0054] Figure 2 is a schematic flowchart of an information processing method executed by a terminal according to an embodiment of this application. The method includes at least a portion of the following.
[0055] S210, Receive the first access code from the first core network device;
[0056] S220. Based on the first access code, generate a first key, wherein the first key is used to protect messages between the terminal and the first core network device.
[0057] Figure 3 is a schematic flowchart of an information processing method performed by a first core network device according to an embodiment of this application. The method includes at least some of the following.
[0058] S310. Obtain a first key, wherein the first key is generated based on the first access code of the first core network device, and the first key is used to protect messages between the terminal and the first core network device.
[0059] Figure 4 is a schematic flowchart of an information processing method performed by a first access network device according to an embodiment of this application. The method includes at least some of the following.
[0060] S410. Send the first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
[0061] Figure 5 is a schematic flowchart of an information processing method performed by a second core network device according to an embodiment of this application. The method includes at least some of the following.
[0062] S510. Send the first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
[0063] Figure 6 is a schematic flowchart of an information processing method performed by a fourth core network device according to an embodiment of this application. The method includes at least some of the following.
[0064] S610. Send the access credential of the first core network device to the first access network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
[0065] Figure 7 is a schematic flowchart of an information processing method performed by a first access network device according to an embodiment of this application. The method includes at least some of the following.
[0066] S710. Receive the access credential from the first core network device of the fourth core network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
[0067] The first core network device is any core network device (or core network element) capable of providing services. This first core network device can be replaced by a Network Function (NF) or a Network Service Provider (NSP).
[0068] For example, the first core network device may include at least one of the following: SMF (Session Management Function), NWDAF (Network Data Analytics Function), UDM (Unified Data Management), PCF (Policy Control Function), AIoT (Ambient Power-enabled IoT) NF, SF (Sensing Function), etc. It should be noted that this is only an exemplary description of the first core network device. In actual processing, the first core network device may include, but is not limited to, the above types of core network elements. However, this is not a limitation or an exhaustive list.
[0069] The second core network device includes at least one of the following: AUSF (Authentication Server Function), SEAF (Security Anchor Function), AMF, and key generation network element. It should be noted that this is merely an illustrative description of the second core network device; in actual processing, the second core network device may include, but is not limited to, the above types of core network elements. Furthermore, the first core network device and the second core network device may be the same or different; this is not a limitation or an exhaustive list.
[0070] The fourth core network device is different from both the first and second core network devices. The fourth core network device can be used for NF service registration and discovery. For example, the fourth core network device can be an NRF (Network Repository Function), etc. It should be noted that this is only an illustrative description of the fourth core network device; in actual processing, the fourth core network device may include, but is not limited to, the above types of core network elements, but this is not a limitation or an exhaustive list.
[0071] In some possible implementations, the first core network device needs to send a security access policy to the fourth core network device.
[0072] In one embodiment, the processing of the first core network device may include: sending the security access policy of the first core network device to the fourth core network device. The processing of the fourth core network device may include: receiving the security access policy of the first core network device.
[0073] Security access policies can also be called security control policies, security access control policies, access control policies, or access policies, etc. This document does not limit or exhaustively list all possible names for security access policies. The method for generating security access policies for the first core network device is not limited in this embodiment.
[0074] Specifically, the first core network device sending its security access policy to the fourth core network device can include sending a registration request for the first core network device to the fourth core network device. This registration request carries the first core network device's security access policy. The registration request can be an Nnrf_NFManagement_NFRegister Request. It should be noted that the registration request can carry other content besides the first core network device's security access policy, such as content specified in relevant protocols, additional scope, etc. These are not limited or exhaustively listed here.
[0075] Accordingly, the fourth core network device receiving the security access policy of the first core network device may include: receiving a registration request from the first core network device and extracting the security access policy of the first core network device from the registration request. Furthermore, after extracting the security access policy of the first core network device, the fourth core network device may save the security access policy of the first core network device.
[0076] Optionally, the security access policy of the first core network device can be included in the configuration file or description file of the first core network device (e.g., it can be represented as the profile of the first core network device). That is, the registration request of the first core network device can carry the profile of the first core network device, which includes the security access policy of the first core network device. Correspondingly, the fourth core network device can store the profile of the first core network device, which includes the security access policy of the first core network device.
[0077] Optionally, the security access policy of the first core network device can be sent separately. Correspondingly, the fourth core network device can store the security access policy of the first core network device in the profile of the first core network device.
[0078] After the fourth core network device saves the security access policy of the first core network device, it can also perform the following processing: send a registration response from the first core network device to the first core network device, which indicates whether the first core network device has successfully registered. Correspondingly, the processing of the first core network device can also include: receiving the registration response from the first core network device received from the fourth core network device. For example, the registration response from the first core network device can be an Nnrf_NFManagement_NFRegister Response.
[0079] Here, if the fourth core network device determines that the first core network device has successfully registered, the registration response of the first core network device can include "Success" to indicate that the first core network device has successfully registered; otherwise, the registration response of the first core network device can include "Failure" to indicate that the first core network device has failed to register. This embodiment does not limit the method by which the fourth core network device determines whether the first core network device has successfully registered.
[0080] It should be noted that the first core network device can be any core network element on the core network side that can provide services. Each core network element that can provide services on the core network side can perform the same processing as the first core network device and interact with the fourth core network device to complete the registration. Finally, the fourth core network device can save the security access policy of each core network element, which will not be elaborated here.
[0081] In one embodiment, the security access policy of the first core network device is used to indicate whether access to the first core network device is permitted. Whether access to the first core network device is permitted may refer to whether access network devices are permitted to access the first core network device. It should be noted that the access network device here does not refer to a specific access network device, but rather to devices on the access network side in general. In the following text, when specifically referring to an access network device connected to the terminal (or an access network device managing the terminal), the access network device connected to the terminal will be referred to as the first access network device. Furthermore, when not specifically referring to the first access network device, but merely describing it as an access network device, it is used to refer to any device on the access network side or all devices on the access network side, and will not be explained again below.
[0082] In one example, the security access policy of the first core network device is granular at the level of service or data type.
[0083] The security access policy of the first core network device is used to indicate whether access to the first core network device is permitted. In this example, whether access to the first core network device is permitted includes at least one of the following: whether the access network device is permitted to access at least one service of the first core network device, and whether the access network device is permitted to access at least one data type of at least one service of the first core network device.
[0084] The security access policy of the first core network device may include at least one access code of the first core network device. In this example, at least one access code of the first core network device includes at least one of the following: the access code corresponding to each service in at least one service that the first core network device allows access network devices to access, and the access code corresponding to at least one data type under each service in at least one service that the first core network device allows access network devices to access.
[0085] Optionally, the security access policy of the first core network device may include: an indication that the access network device is allowed to access at least one service of the first core network device, and an access code corresponding to each service among the at least one service that the first core network device allows the access network device to access.
[0086] An indication allowing an access network device to access at least one service of a first core network device may include: an identifier for each of the at least one services that the first core network device allows the access network device to access. That is, if the security access policy of the first core network device includes the identifier of a certain service, it indicates that the access network device is allowed to access that service of the first core network device; if the security access policy of the first core network device does not include the identifier of a certain service, it implicitly indicates that the access network device is not allowed to access that service of the first core network device.
[0087] The first core network device allows the access network device to access at least one service, which may be at least a portion of all services supported by the first core network device.
[0088] In at least one service that the first core network device allows access network devices to access, the access code corresponding to each service can correspond to or be associated with the service identifier. The access codes corresponding to different services in the at least one service that the first core network device allows access network devices to access may be the same or different.
[0089] For example, a first core network device might support 10 services, but only allow access network devices to access 3 of them (e.g., services 1, 2, and 3). The security access policy of the first core network device could then include: the identifier of service 1 that the first core network device allows access network devices to access; the identifier of service 2 that the first core network device allows access network devices to access; the identifier of service 3 that the first core network device allows access network devices to access; the access code corresponding to service 1; the access code corresponding to service 2; and the access code corresponding to service 3. The access codes for service 1, service 2, and service 3 must be different from each other; alternatively, the access codes for service 1 and service 2 can be the same, while the access code for service 3 must be different from both service 1 and service 2. It should be noted that this is merely an illustrative example and does not constitute a limitation or exhaustive list of all possible scenarios for the security access policy of the first core network device.
[0090] Optionally, the security access policy of the first core network device may include: an indication of at least one data type allowed to be accessed in each service of the first core network device, and an access code corresponding to at least one data type under each service of the at least one service that the first core network device allows the access network device to access.
[0091] It should be noted that the security access policy of the first core network device in this example may also include an indication that allows the access network device to access one or more services of the first core network device. In this case, the indication that allows the access network device to access at least one service of the first core network device may also be the identifier of each service among the at least one service that the first core network device allows the access network device to access.
[0092] The indication of at least one data type allowed for access in each service may include: an identifier for each data type among the at least one data type allowed for access network devices in each service. Each service that the first core network device allows access network devices to access may include multiple data types, and the at least one data type allowed for access under a certain service that the first core network device allows access network devices to access may be at least one of all data types under that service.
[0093] For example, if the security access policy of the first core network device includes an identifier for a certain service and an identifier for a certain data type under that service, it indicates that access network devices are allowed to access that service of the first core network device and that data type under that service is also allowed. Conversely, if the security access policy of the first core network device includes an identifier for a certain service but does not include an identifier for a certain data type under that service, it implicitly indicates that access network devices are not allowed to access that data type under that service of the first core network device.
[0094] The access code for each data type allowed under each of at least one service that the first core network device allows the access network device to access may correspond to or be associated with the identifier of that data type. The access codes corresponding to different data types allowed under any service that the first core network device allows the access network device to access may be the same or different.
[0095] For example, the first core network device may allow access network devices to access three services (e.g., service 1, service 2, and service 3). Taking service 1 as an example, service 1 may contain five data types. However, the first core network device only allows access network devices to access two data types of service 1: data type 2 of service 1. The security access policy of the first core network device may include: the identifier of service 1 that the first core network device allows access network devices to access; the identifier of data type 1 of service 1 that the first core network device allows access network devices to access; the identifier of data type 2 of service 1 that the first core network device allows access network devices to access; the access code corresponding to data type 1 of service 1; and the access code corresponding to data type 2 of service 1. The access codes for data type 1 and data type 2 of service 1 may be different; or, the access codes for data type 1 and data type 2 of service 1 may be the same. The identifier of the data type may also be replaced with the name of the data type, and / or the number of the data type, etc. It should be noted that this is only an illustrative example and is not intended to limit or exhaustively list all possible situations of the security access policy of the first core network device.
[0096] In one example, the security access policy of the first core network device is at the device level.
[0097] The security access policy of the first core network device may include at least one access code of the first core network device. In this example, at least one access code of the first core network device may include only one access code of the first core network device.
[0098] The first core network device may support at least one service. An access code for the first core network device can be the same access code corresponding to all services supported by that first core network device. In other words, regardless of how many services the first core network device supports, all services supported by the first core network device correspond to the same access code.
[0099] The access code can also be called a secure access code, a security code, or a secure access policy code, etc. We will not limit or exhaust all possible names for the access code here.
[0100] Optionally, the security access policy of the first core network device may include only one access code of the first core network device. In this case, the security access policy of the first core network device can implicitly indicate whether access network devices are allowed to access the first core network device, or implicitly indicate whether access network devices are allowed to access various services of the first core network device, through the access code of the first core network device.
[0101] Optionally, in addition to an access code for the first core network device, the security access policy of the first core network device also includes an indication of whether to allow the access network device to access the first core network device. The indication of whether to allow the access network device to access the first core network device may include: first indication information for indicating that the access network device is allowed to access the first core network device, or second indication information for indicating that the access network device is not allowed to access the first core network device.
[0102] Specifically, the first indication information can be a first indication field. For example, if the first indication field includes any one of the following, such as "allow," "allow access," or "enable," it indicates that the access network device is allowed to access the first core network device. Alternatively, the first indication information can be a first indication value, which can be configured according to actual conditions and can be 1 or 0, etc. Here, we do not limit or exhaustively list all possible first indication values. The second indication information can be a second indication field. For example, if the second indication field includes any one of the following, such as "disallow," "disallow access," or "disable," it indicates that the access network device is not allowed to access the first core network device. Alternatively, the second indication information can be a second indication value, which can be configured according to actual conditions. As long as the second indication value is different from the first indication value, it is within the scope of protection of this embodiment. Here, we do not limit all possible second indication values. It should be understood that this is merely an exemplary description of the specific indication method for whether the access network device is allowed to access the first core network device. This embodiment does not limit or exhaustively list the content of the indication for whether the access network device is allowed to access the first core network device.
[0103] In one scenario, the security access policy of the first core network device includes an access code for the first core network device and first indication information for indicating whether access network devices are permitted to access the first core network device.
[0104] In one scenario, the security access policy of the first core network device includes an access code for the first core network device and second indication information to indicate that access network devices are not allowed to access the first core network device. In this scenario, although the security access policy of the first core network device includes an access code, this access code may not be used because access network devices are not allowed to access the first core network device.
[0105] Optionally, the security access policy of the first core network device may include only second indication information to indicate that access network devices are not allowed to access the first core network device. In this case, since access network devices are not allowed to access the first core network device, the security access policy of the first core network device may not include access coding.
[0106] In some possible implementations, after the fourth core network device stores the security access policy of the first core network device, it can send the access credentials of the first core network device to the first access network device.
[0107] The processing of the first access network device may include: sending an acquisition request to the fourth core network device, wherein the acquisition request is used to acquire the access credentials of the first core network device. Correspondingly, the processing of the fourth core network device may include: receiving an acquisition request from the first access network device, wherein the acquisition request is used to acquire the access credentials of the first core network device. For example, this acquisition request may be represented as Nnrf_AccessToken_Get Request.
[0108] In this embodiment, the first access network device may refer to the access network device currently accessed by the terminal.
[0109] The trigger for the first access network device to send an acquisition request to the fourth core network device can be that the first access network device receives a request message from the terminal. This request message can be any type of AS (Access Stratum) message. For example, the terminal's request message can be an RRC (Radio Resource Control) message; such as a registration request, authentication request, access request, or access authentication request carried in an RRC message. In other words, as the access network device currently connected to or accessed by the terminal, the first access network device sends an acquisition request to the fourth core network device upon receiving a request message from the terminal.
[0110] The acquisition request may carry at least one of the following: identification information of the first core network device, identifier of the first service, type of the first core network device, type of the first access network device, identifier of the first access network device, and identifier of the first data type. The identifier of the first data type may also be replaced by the name and / or number of the first data type, etc., as long as it can uniquely indicate the first data type, it is within the scope of protection of this embodiment. The identification information of the first core network device may include at least one of the identifier of the first core network device, the name of the first core network device, etc. The identifier of the first service may include at least one of the ID of the first service, the name of the first service, etc. The first data type can be any data type under the first service.
[0111] The processing after the fourth core network device receives the acquisition request also includes: determining whether to authorize the first access network device to access the first core network device based on the security access policy of the first core network device.
[0112] Furthermore, when the fourth core network device determines that it has authorized the first access network device to access the first core network device, the processing of the fourth core network device may include: sending the access credentials of the first core network device to the first access network device. Correspondingly, the processing of the first access network device may include: receiving the access credentials of the first core network device from the fourth core network device.
[0113] The access credentials of the first core network device include at least one of the following: an access token of the first core network device, and a first access code of the first core network device. The access token of the first core network device is generated based on the first access code.
[0114] Specifically, the process of the fourth core network device sending access credentials to the first core network device may include: the fourth core network device generating an access token for the first core network device; and sending the access credentials of the first core network device to the first access network device. Optionally, the access credentials of the first core network device may only include the access token of the first core network device. Optionally, the access credentials of the first core network device may include the access token of the first core network device and a first access code.
[0115] In addition, the processing of the fourth core network device may also include: sending an authorization failure notification to the first access network device if it is determined that the first access network device is not authorized to access the first service of the first core network device.
[0116] In one example, the security access policy of the first core network device is implemented at the device level.
[0117] In this example, the acquisition request may include at least one of the following: the identification information of the first core network device and the type of the first core network device; further, the acquisition request may also include at least one of the type of the first access network device and the identifier of the first access network device. The acquisition request may or may not include the identifier of the first service.
[0118] Based on the security access policy of the first core network device, determining whether to authorize the first access network device to access the first core network device may include one of the following: if the security access policy of the first core network device only includes one access code of the first core network device, determine to authorize the first access network device to access the first core network device; if the security access policy of the first core network device includes an indication that allows the access network device to access the first core network device, determine to authorize the first access network device to access the first core network device; if the security access policy of the first core network device includes an indication that does not allow the access network device to access the first core network device, determine not to authorize the first access network device to access the first core network device.
[0119] The process of the fourth core network device generating the access token of the first core network device may include: obtaining a first access code from the security access policy of the first core network device, and generating the access token of the first core network device based on the first access code.
[0120] Obtaining the first access code from the security access policy of the first core network device may include: if the security access policy of the first core network device includes an access code of the first core network device, using that access code as the first access code.
[0121] The specific method for generating the access token of the first core network device based on the first access code is not limited in this embodiment. For example, the process of generating the access token of the first core network device based on the first access code can be: generating the access token of the first core network device based on the private key of the fourth core network device and the first access code. The specific calculation or processing method for generating the access token is not limited in this embodiment. It should also be noted that this is only an exemplary description of generating the access token; other methods may be used to generate the access token in actual processing, which are not limited or exhaustively described here.
[0122] In one example, the security access policy of the first core network device is granular at the service or data type level. In this example, the access token of the first core network device corresponds to the first service, or the access token of the first core network device corresponds to the first data type of the first service. The first access code corresponds to the first service; or, the first access code corresponds to the first data type of the first service.
[0123] In one scenario, the security access policy of the first core network device is based on service granularity, with the access token of the first core network device corresponding to the first service and the first access code corresponding to the first service.
[0124] The request may include the identifier of the first service; and the request may also include at least one of the following: the identification information of the first core network device and the type of the first core network device; furthermore, the request may also include at least one of the type of the first access network device and the identifier of the first access network device.
[0125] Based on the security access policy of the first core network device, determining whether to authorize the first access network device to access the first core network device may include one of the following: if the identifier of the first service matches any one of the identifiers of at least one service allowed to be accessed by the access network device in the security access policy of the first core network device, then authorize the first access network device to access the first service of the first core network device; if the identifier of the first service does not match any of the identifiers of at least one service allowed to be accessed by the access network device in the security access policy of the first core network device, then disauthorize the first access network device to access the first service of the first core network device; if the identifier of the first service matches any one of the identifiers of at least one service not allowed to be accessed by the access network device in the security access policy of the first core network device, then disauthorize the first access network device to access the first service of the first core network device.
[0126] The process of the fourth core network device generating the access token of the first core network device may include: obtaining the access code corresponding to the first service of the first core network device from the security access policy of the first core network device, using the access code corresponding to the first service as the first access code, and generating the access token of the first core network device based on the first access code.
[0127] In one scenario, the security access policy of the first core network device is granular at the data type level. The access token of the first core network device corresponds to the first data type of the first service, and the first access code corresponds to the first data type of the first service.
[0128] The acquisition request may include the identifier of the first service and the identifier of the first data type; and the acquisition request may also include at least one of the following: the identification information of the first core network device and the type of the first core network device; furthermore, the acquisition request may also include at least one of the type of the first access network device and the identifier of the first access network device.
[0129] Based on the security access policy of the first core network device, determining whether to authorize the first access network device to access the first core network device may include one of the following: if the identifier of the first service matches any one of the identifiers of at least one service allowed to be accessed by the access network device in the security access policy of the first core network device, and the identifier of the first data type matches any one of the identifiers of one or more data types under the first service allowed to be accessed by the access network device in the security access policy of the first core network device, then the first data type of the first service of the first core network device is authorized to be accessed by the first access network device; if the identifier of the first service does not match any of the identifiers of at least one service allowed to be accessed by the access network device in the security access policy of the first core network device, and / or the identifier of the first data type does not match any of the identifiers of one or more data types under the first service allowed to be accessed by the access network device in the security access policy of the first core network device, then the first data type of the first service of the first core network device is not authorized to be accessed by the first access network device.
[0130] The process of the fourth core network device generating the access token of the first core network device may include: obtaining the access code corresponding to the first data type of the first service of the first core network device from the security access policy of the first core network device, using the access code corresponding to the first data type of the first service as the first access code, and generating the access token of the first core network device based on the first access code.
[0131] Referring to Figure 8, the registration process of the first core network device and the process by which the first access network device (such as a base station) obtains the access token of the first core network device are illustrated by example:
[0132] Step 801: The first core network device sends a security access policy. This security access policy can be used to indicate whether an access network device can access the first core network device. This step is the registration process of the first core network device, that is, the first core network device sends an additional scope and its security access policy during the registration process. For example, the security access policy may include the identifier (service ID) of the services of the first core network device that the access network device is allowed to access, and the access code corresponding to the services that the access network device is allowed to access.
[0133] In this example, the first core network device can be any one of SMF, PCF, UDM, NWDAF, AIoT NF, SF, etc.
[0134] For example, assuming the first core network device is an SMF, the SMF's security access policy may include: Security Access Policy Code 1 (i.e., Access Code 1) (for example only: low security level), Service ID 1-1 (UE session management), and Service ID 1-2 (mobility management); Service ID 1-1 and Service ID 1-2 can correspond to the same Security Access Policy Code 1. Alternatively, the SMF's security access policy may include: Security Access Policy Code 1-1, Security Access Policy Code 1-2, Service ID 1-1, and Service ID 1-2; where Service ID 1-1 can correspond to Security Access Policy Code 1, and Service ID 1-2 can correspond to Security Access Policy Code 1-2.
[0135] For example, assuming the first core network device is PCF, the security access policy of PCF may include: security access policy code 2 (medium security level) and service ID2 (UE service), that is, service ID2 corresponds to security access policy code 2.
[0136] For example, assuming the first core network device is a UDM, the security access policy of the UDM may include: security access policy code 3 (high security level), service ID 3, data type 3 (for example, it may be the authentication vector (AV) under service ID 3); where the data type 3 of service ID 3 corresponds to security access policy code 3.
[0137] For example, assuming the first core network device is NWDAF, the security access policy of NWDAF may include: security access policy code 4 (high security level), service ID 4 (AI inference service), and data type 4 (such as the data inference result under the AI inference service); where the data type 4 of service ID 4 corresponds to security access policy code 4.
[0138] For example, assuming the first core network device is SF, the security access policy of SF may include: security access policy code 5 (high security level), service ID 5 (human-related sensing service, such as motion capture, heartbeat and breathing), and data type 5 (for example, it may be the sensing inference result under human-related sensing service); where the data type 5 of service ID 5 corresponds to security access policy code 5.
[0139] For example, assuming the first core network device is an AIoT NF, the security access policy of the AIoT NF may include: security access policy code 6 (high security level), service ID 6 (AIOT service), and data type 6 (for example, location information under AIoT service); where the data type 6 of service ID 6 corresponds to security access policy code 6.
[0140] It should be noted that the above is only an illustrative description of the possible contents of the security access policies under various possible types of first core network devices. In actual processing, the first core network device may include, but is not limited to, the core network elements of the above types. The security access policies that the core network elements under each type may include are not limited to the several possibilities in the above examples. For the sake of simplicity, no limitation or exhaustive list is made here.
[0141] Step 802: The NRF (i.e., the fourth core network device) stores the security access policy of the first core network device. Specifically, the NRF can save the security access policy code of the first core network device, which will be used when the NRF generates the access token (referred to as Token) of the first core network device.
[0142] Step 803: The base station (i.e., the first access network device) obtains the access credentials of the first core network device from the NRF. These credentials may include the access token and / or the first access code of the first core network device. The first access code may be one of all access codes corresponding to services that the access network device is allowed to access by the first core network device. For example, when the base station requests access to a first service of the first core network device, the first access code corresponds to the first service, and the access token corresponds to the first service. Similarly, when the base station requests access to a first data type of the first service of the first core network device, the first access code corresponds to the first data type of the first service, and the access token corresponds to the first data type of the first service.
[0143] For example, the base station may obtain the access credentials of the first core network device from the NRF during a service request procedure. During this process, the base station may initiate an acquisition request to the NRF. The NRF determines whether to authorize access based on the security policy encoding of the first core network device. If the base station is authorized to access the first service, it sends an access token (referred to as a token) and / or a first access code from the first core network device to the base station. The acquisition request may include the same content as in the aforementioned embodiments; for example, it may include the ID of the first service, etc., which is not limited or exhaustive here. The token is generated by incorporating the first access code.
[0144] In some possible implementations, during the terminal authentication process, the first access network device requests access to the first core network device and the first core network device verifies whether access to the first access network device is permitted, the terminal generates a first key, and the first core network device obtains the first key.
[0145] In some embodiments, during the terminal authentication process, the first access network device requests access to the first core network device and the first core network device verifies whether access to the first access network device is permitted.
[0146] The terminal's processing may include sending an authentication request to the first access network device. The first access network device's processing may include receiving the authentication request from the terminal. The content that the terminal's authentication request may carry is not limited in this embodiment. It should be noted that the terminal's authentication request can also be replaced by a terminal access request, or a terminal access authentication request, etc., and is not limited here.
[0147] After receiving an authentication request from a terminal, the first access network device may perform the following processing: sending a service request to a first core network device, wherein the service request carries the access credentials of the first core network device; and receiving a service response from the first core network device, wherein the service response indicates whether access to the first core network device is permitted. The processing of the first core network device may include: receiving a service request from the first access network device, wherein the service request carries the access credentials of the first core network device; and sending a service response to the first access network device, wherein the service response indicates whether access to the first core network device is permitted.
[0148] The triggering condition or prerequisite for the first access network device to send a service request to the first core network device may be that the first access network device receives an authentication request from the terminal and has already obtained the access credential from the first core network device. This service request may also be called a service request, an NF service request, or a first core network device service request, etc., and we will not limit or exhaust all possible names for this service request here.
[0149] It should be noted that, as mentioned in the foregoing embodiments, before the first access network device sends a request to the fourth core network device to obtain the access credentials of the first core network device, the first access network device receives a request message from the terminal. This request message can be a registration request, an authentication request, an access request, or an access authentication request. In one scenario, the terminal's request message is a registration request. In this case, after the first access network device obtains the access credentials of the first core network device, it will send a service request to the first core network device only after receiving the terminal's authentication request (or access request, or access authentication request). In another scenario, the terminal's request message is an authentication request (or access request, or access authentication request). In this case, after the first access network device obtains the access credentials of the first core network device, it can directly send a service request to the first core network device.
[0150] The description of the access credentials for the first core network device is the same as that in the aforementioned embodiments, and will not be repeated.
[0151] After the first core network device receives a service request from the first access network device and before sending a service response to the first access network device, it may further include at least one of the following: verifying the access token of the first core network device; verifying the first access code.
[0152] Optionally, if the access credentials of the first core network device only include the access token of the first core network device, then the first core network device only needs to verify the access token of the first core network device.
[0153] The verification of the access token by the first core network device is related to how the fourth core network device specifically generates the access token. For example, if the access token of the first core network device is generated based on the private key and the first access code of the fourth core network device, then the first core network device can verify the access token based on the public key and the first access code of the fourth core network device. The specific calculation or processing method for verifying the access token is not limited in this embodiment. It should also be noted that this is merely an illustrative description of generating and verifying the access token; other methods may be used to generate and verify the access token in actual processing, which are not limited or exhaustively described here.
[0154] If the first core network device successfully verifies the access token of the first core network device, a service response indicating that access to the first core network device is permitted can be generated; if the first core network device fails to verify the access token of the first core network device, a service response indicating that access to the first core network device is not permitted can be generated.
[0155] Optionally, if the access credentials of the first core network device include the access token and the first access code of the first core network device, then the first core network device needs to verify the access token and the first access code of the first core network device.
[0156] The instructions for the first core network device to verify the access token of the first core network device are the same as those in the previous example, and will not be repeated here.
[0157] The method by which the first core network device verifies the first access code may include at least one of the following: if the first access code is included in its own security access policy, the device determines that the verification of the first access code is successful; if the first access code is not included in its own security access policy, the device determines that the verification of the first access code fails.
[0158] Furthermore, if the first core network device successfully verifies the access token of the first core network device and successfully verifies the first access code, a service response indicating that access to the first core network device is permitted can be generated; if the first core network device fails to verify the access token of the first core network device and / or fails to verify the first access code, a service response indicating that access to the first core network device is not permitted can be generated.
[0159] In some embodiments, during the terminal authentication process, the terminal derives a first key, and the first core network device obtains the first key.
[0160] When the first access network device receives a service response from the first core network device, and the service response indicates that access to the first core network device is permitted, the first access network device may send an authentication request to the terminal. Correspondingly, the processing of the second core network device may include receiving the authentication request from the terminal.
[0161] Specifically, the first access network device sending the terminal's authentication request can be done by sending the terminal's authentication request to the second core network device. Correspondingly, the second core network device receiving the terminal's authentication request can be done by receiving the terminal's authentication request sent by the first access network device.
[0162] Sending a terminal authentication request from the first access network device to the second core network device may include: the first access network device sending the terminal authentication request to the second core network device through a fifth core network device. Receiving the terminal authentication request from the first access network device may include: the second core network device receiving the terminal authentication request sent by the first access network device through the fifth core network device.
[0163] The processing of the second core network device further includes sending an encoding retrieval request. The processing of the first core network device further includes receiving an encoding retrieval request. Specifically, the second core network device sending the encoding retrieval request may include sending an encoding retrieval request to the first core network device. Correspondingly, the first core network device receiving the encoding retrieval request may include receiving the encoding retrieval request from the second core network device. The timing of the second core network device sending the encoding retrieval request may be after the second core network device receives the authentication request from the terminal.
[0164] The encoding acquisition request may include at least one of the following: the identifier of the first access network device, the type of the first access network device, the identifier of the first service, the first data type, etc. Here, the possible contents of the encoding acquisition request are not limited or exhaustively listed.
[0165] The processing of the second core network device further includes: receiving the first access code. The processing of the first core network device further includes: sending the first access code. Specifically, the second core network device receiving the first access code includes: receiving the first access code from the first core network device. The first core network device sending the first access code includes: the first core network device sending the first access code to the second core network device.
[0166] For example, the second core network device can be AUSF, and the fifth core network device can be SEAF. Specifically, the first access network device first sends the terminal authentication request to SEAF; SEAF receives the terminal authentication request from the first access network device and sends the terminal authentication request to AUSF; AUSF receives the terminal authentication request from SEAF. AUSF sends an encoding acquisition request to the first core network device and receives the first access encoding from the first core network device.
[0167] In one embodiment, during the terminal authentication process, the terminal and the second core network device respectively derive a first key, and the first core network device obtains the first key sent by the second core network device.
[0168] The processing after the second core network device receives the first access code may include: generating the first key based on the first access code and the second key, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device; and sending the first key to the first core network device. The third core network device includes at least one of the following: AUSF, SEAF, or AMF. It should be noted that the second core network device and the third core network device may be the same or different.
[0169] Generating the first key based on the first access code and the second key can include: generating the first key using a key calculation method based on the first access code and the second key. The key calculation method can be configured according to actual conditions. For example, the key calculation method can include at least one of the following: KDF (Key Derivation Function), first authentication function (such as the f1 function defined in 3GPP), second authentication function (such as the f2 function defined in 3GPP), third key generation function (such as the f3 function defined in 3GPP), fourth key generation function (such as the f4 function defined in 3GPP), fifth key generation function (such as the f5 function defined in 3GPP), hash algorithm, Advanced Encryption Standard (AES), ACSON, SNOW 3G (Snow Third Generation), ZUC (ZUChongzhi), XOR calculation, and direct connection calculation. The hash algorithm can be represented as HASH(), which may include HMAC-SHA-256 (Hash based Message Authentication Code - Secure Hash Algorithm-256), or other lightweight hash algorithms (such as SPECK, SIMON, etc.). This embodiment does not exhaustively list them all. It should be understood that this is only an illustrative example, and in actual processing, this key calculation method may include many more possibilities. This embodiment does not exhaustively list all possible calculation functions (or algorithms) for the key calculation method.
[0170] In this embodiment, the second key can be any key shared by the terminal and the third core network device. For example, if the third core network device is AUSF, the second key can be K. AUSF K SEAF Any one of them. When the third core network device is SEAF, the second key can be K. SEAF .
[0171] For example, the third core network device can be the same as the second core network device, such as both being AUSF, and the second key can be K. AUSF The calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K AUSF (first access code), where K NSP This represents the first key.
[0172] For example, the second core network device is AUSF, the third core network device is different from the second core network device, or the third core network device can be the same as the fifth core network device, both being SEAF, and the second key can be K. SEAF The calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K SEAF (First access code).
[0173] The processing of the second core network device may further include: sending the first access code from the first core network device. The timing of the second core network device sending the first access code, as long as it occurs after receiving the first access code, is within the scope of protection of this embodiment. Correspondingly, the terminal's processing may further include: receiving the first access code from the second core network device.
[0174] Specifically, the second core network device sending the first access code may include: the second core network device sending the first access code to the terminal through the fifth core network device. The terminal receiving the first access code from the second core network device may include: the terminal receiving the first access code from the second core network device sent by the fifth core network device.
[0175] For example, the second core network device can be AUSSF, and the fifth core network device can be SEAF. After receiving the first access code or generating the first key, AUSF can send the terminal's authentication response to SEAF, where the terminal's authentication response carries the first access code. After receiving the terminal's authentication response, SEAF sends an authentication request to the terminal, which may carry the first access code. The terminal receives the authentication request from SEAF, where the SEAF's authentication request carries the first access code sent by AUSSF.
[0176] After receiving the first access code, the terminal generates the first key based on the first access code and the second key. The specific method by which the terminal generates or calculates the first key, and the relevant description of the second key, are the same as those for the second core network equipment, and therefore will not be repeated.
[0177] The second core network device can also send the first key to the first core network device after generating it. Correspondingly, the process by which the first core network device obtains the first key can include receiving the first key from the second core network device.
[0178] As described in the foregoing embodiments, the first access code is included in the security access policy of the first core network device, wherein the security access policy of the first core network device is used to indicate whether access to the first core network device is permitted.
[0179] When the security access policies of the first core network devices are based on service, data type, or device granularity, the granularity of the first access code and the granularity of the message protected by the first key are different, as explained below:
[0180] Optionally, the security access policy of the first core network device can be at the device level. The first key is used to protect messages between the terminal and the first core network device. That is, the first access code is a unique access code included in the security access policy of the first core network device, and this access code can correspond to all services supported by the first core network device; therefore, the first key generated based on the first access code can be used to protect messages between the terminal and the first core network device, or to protect messages (or data of all services) between the terminal and the first core network device.
[0181] Optionally, the security access policy of the first core network device can be granular at the service or data type level. The first access code corresponds to a first service, and the first key is used to protect messages of the first service between the terminal and the first core network device; or, the first access code corresponds to a first data type of the first service, and the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.
[0182] In one scenario, the security access policy of the first core network device can be at the service level. In this case, the first access code corresponds to the first service, and the first key is used to protect the messages of the first service between the terminal and the first core network device. That is, the first access code is the access code corresponding to the first service among all the access codes included in the security access policy of the first core network device; therefore, the first key generated based on the first access code can be used to protect the messages (or data) of the first service between the terminal and the first core network device.
[0183] In one scenario, the security access policy of the first core network device can be granular at the data type level. In this case, the first access code corresponds to the first data type of the first service, and the first key is used to protect messages under the first data type of the first service between the terminal and the first core network device. That is, if the security access policy of the first core network device is granular at the data type level, then the first access code is the access code corresponding to the first data type of the first service among all the access codes included in the security access policy of the first core network device; therefore, the first key generated based on the first access code can be used to protect messages (or data) under the first data type of the first service between the terminal and the first core network device.
[0184] The following, using Figures 9 and 10 as examples, with the first core network device being NSP, the fourth core network device being NRF, the first access network device being a base station (which can also be replaced by NSC (Network Service Customer)), and the terminal being UE, illustrates the following processes: 1. NSP registration process; 2. NRF authorization of the first access network device (base station) for access and allocation of access credentials to the base station; 3. Base station service request process; 4. UE authentication and key generation process.
[0185] First, referring to Figure 9, the first to third processes above will be illustrated by example, specifically including:
[0186] Steps 901 to 903 constitute the NSP registration process.
[0187] Step 901: The NSP sends a registration request (e.g., an Nnrf_NFManagement_NFRegister Request) to the NRF, which may carry the NSP's security access policy. This registration request may also carry Additional Scope Info, etc., which are not limited here. The relevant explanations regarding the security access policy are the same as in the previous embodiments and will not be repeated.
[0188] Step 902: The NRF stores the NSP's security access policy. Optionally, the NSP's security access policy may be included in the NSP Profile. In this case, the registration request sent by the NSP may contain the NSP Profile, and the NRF saves the NSP Profile accordingly.
[0189] Step 903: NRF replies to NSP with a registration response (e.g., Nnrf_NFManagement_NFRegister Response). If NSP registration is successful, the registration response can include "Success" to indicate that NSP registration was successful.
[0190] Steps 904 to 907 are the process of NRF authorizing the base station to access the NSP and allocating access credentials to the base station.
[0191] Step 904: The UE sends an RRC message to the base station (NSC). The RRC message may carry the UE's registration request or UE authentication request (or UE's access request or UE's access authentication request).
[0192] Step 905: The base station sends an acquisition request (e.g., Nnrf_AccessToken_Get Request) to the NRF. The acquisition request may carry at least one of the following: Expected NF Service name(s), NF type, NSP identification information, Consumer NF type, client id, and ID of the first service.
[0193] Step 906: The NRF, based on the NSP's secure access policy, determines whether the base station is authorized to access the NSP (or, as in NRF Check whether the NF Service Consumer is authorized). If authorization is successful, proceed to step 907. Alternatively, if authorization fails, the NRF may terminate the process and / or send an authorization failure notification to the base station.
[0194] Step 907: The NRF generates an NSP access token based on the first access code of the NSP, and then sends the NSP access credential to the base station. The NSP access credential may include the NSP access token and / or the first access code. This NSP access credential may be carried by the Nnrf_AccessToken_Get Response (NRF access token acquisition response). The generation of the token, the acquisition of the first access code, and other related processes are the same as in the previous embodiments, and therefore will not be repeated.
[0195] Steps 908 to 910 constitute the service request process for the base station.
[0196] Step 908: The base station sends a service request (NF Service request, or NF service request (or service request)) to the NSP, which carries the NSP's access credentials.
[0197] It should be noted that if the RRC message sent by the UE in step 904 carries the UE's authentication request (or the UE's access request, or the UE's access authentication request), the base station can directly execute step 908 after completing step 907. If the RRC message sent by the UE in step 904 carries the UE's registration request, the base station also needs to execute step 908 after receiving the UE's authentication request (or the UE's access request, or the UE's access authentication request). The timing of sending the UE's authentication request is not limited in this example, but the base station needs to execute step 908 after receiving the UE's authentication request and completing step 907.
[0198] Step 909: The NSP verifies its access credentials. For example, the NSP can verify the NSP's token in the access credentials and / or verify the first access code. The related processing for verifying the NSP's token in the access credentials and / or verifying the first access code is the same as in the previous embodiments and will not be described again.
[0199] Step 910: The NSP sends a service response (such as NF Service response) to the base station, indicating whether the base station is allowed to access the NSP.
[0200] Based on the process in Figure 9, and in conjunction with Figure 10, taking the first core network device as NSP, the second core network device as AUSF, the first access network device as base station, and the terminal as UE as an example, the fourth process after completing the three processes in Figure 9, namely the UE authentication and key generation process, will be explained with AUSF and UE generating the first key respectively:
[0201] Step 1011: The base station forwards the UE's authentication request to the SEAF. The SEAF can be the fifth core network device described in the previous embodiments.
[0202] It should be noted that step 1011 is executed after step 910 in Figure 9. For the sake of brevity, this example will not elaborate on the processing of steps 901 to 910.
[0203] Step 1012: SEAF forwards the UE's authentication request to AUSF.
[0204] Step 1013: AUSF sends an encoding retrieval request to NSP. The encoding retrieval request is used to request the first access code from NSP.
[0205] Step 1014: NSP sends its first access code to AUSF.
[0206] Step 1015, AUSF is based on the first access code and the second key (e.g., K). AUSF or KSEAF Generate the first key (e.g., K) NSP Here, if the second core network device is the same as the third core network device, then the second key is K. AUSF If the second core network device is different from the third core network device, and the third core network device is the same as the fifth core network device (i.e., SEAF), then the second key is K. SEAF The specific process for generating the first key is the same as in the previous embodiments and will not be repeated here.
[0207] Step 1016: AUSF sends an authentication response (or UE authentication response) to SEAF, carrying the first access code.
[0208] Step 1017: The SEAF sends an authentication request to the UE, and the authentication request sent by the SEAF carries the first access code.
[0209] Step 1018: The UE generates a first key based on the first access code and the second key. The second key used by the UE to generate the first key should be the same as that used in the AUSF, and the specific calculation method for the UE to generate the first key is also the same as that used in the AUSF, so it will not be described again.
[0210] Step 1019: AUSF sends the first key to NSP. It should be understood that the execution of step 1019 is within the scope of protection of this example as long as it occurs after step 1015. Therefore, the execution order of step 1019 and steps 1016 to 1018 is not limited here.
[0211] In another embodiment, the first core network device and the second core network device can be the same; for example, the first core network device can be located in the same entity as the second core network device. In this embodiment, during the terminal authentication process, the terminal derives a first key, and the first core network device generates a first key. Preferably, the first core network device is an AUSF.
[0212] It should be noted that in this embodiment, the first core network device and the second core network device of the aforementioned embodiment are co-located. The processes performed by the second core network device in the aforementioned embodiment, such as executing the encoding acquisition request, receiving the first access code, and sending the first key, are no longer required. In detail:
[0213] When a first access network device receives a service response from a first core network device, and the service response indicates that access to the first core network device is permitted, the first access network device may send an authentication request for the terminal to the first core network device. Correspondingly, the first core network device receives the authentication request for the terminal.
[0214] After receiving the authentication request from the terminal, the first core network device can perform the following processing: Based on the first access code and the second key, generate the first key, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device. This second key can also be any key shared between the terminal and the third core network device. For example, if the third core network device is the same as the first core network device, both being AUSF, the second key can still be K. AUSF For example, the third core network equipment differs from the first core network equipment; the third core network equipment is SEAF, and the second key is K. SEAF .
[0215] After the second core network device generates the first key or obtains the first access code, it still performs the process of sending the first access code to the terminal through the fifth core network device in the aforementioned embodiment; correspondingly, after the terminal receives the first access code, it still performs the same process as in the aforementioned embodiment to finally generate the first key, which will not be elaborated here.
[0216] Referring to Figure 11, taking AUSF as the first core network device, base station as the first access network device, and UE as the terminal as an example, the authentication and key generation process of UE is explained:
[0217] Steps 1111 to 1112 are the same as steps 1011 to 1012 shown in Figure 10, and will not be described again.
[0218] Step 1113, AUSF is based on the first access code and the second key (e.g., K). AUSF or K SEAF Generate the first key (e.g., K) NSP Here, if the second core network device is the same as the third core network device, then the second key is K. AUSF If the second core network device is different from the third core network device, and the third core network device is the same as the fifth core network device (i.e., SEAF), then the second key is K. SEAF The specific process for generating the first key is the same as in the previous embodiments and will not be repeated here.
[0219] Steps 1114 to 1116 are the same as steps 1016 to 1018 shown in Figure 10, and will not be described again. It should be understood that the execution of step 1114 is within the scope of protection of this example as long as it occurs after step 1112.
[0220] It should also be noted that before executing step 1111, the process shown in Figure 9 still needs to be executed, but the NSP shown in Figure 9 is replaced with AUSF, and the related processes executed by NSP are replaced by those executed by AUSF. This will not be explained again.
[0221] In another embodiment, during the terminal authentication process, the terminal and the first core network device respectively derive a first key.
[0222] The processing by the first core network device after receiving the access code acquisition request may include: obtaining a first key. The processing by which the first core network device obtains the first key may include: generating the first key based on the first access code. Specifically, generating the first key based on the first access code includes: generating the first key based on the first access code and a second key, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device.
[0223] The processing before the first core network device generates the first key based on the first access code may further include: receiving a second key. Receiving the second key may include: receiving a second key from a second core network device. In this example, the second key and the code acquisition request can be sent simultaneously; for example, the code acquisition request may carry the second key; or, for example, the second key and the code acquisition request may be carried in the same message.
[0224] In this embodiment, the second key can be a key shared between the terminal and the third core network device. The third core network device includes at least one of the following: AUSF, SEAF, and AMF. In this embodiment, the second core network device and the third core network device may be the same or different.
[0225] For example, the third core network device can be the same as the second core network device, both being AUSF, and the second key can be K. AUSF The calculation or generation of the first key is the same as in the previous embodiments and will not be repeated. For example, the second core network device is AUSF, and the third core network device is different from the second core network device, but can be the same as the fifth core network device, both being SEAF. The second key can be K. SEAF The calculation or generation of the first key is the same as in the previous embodiments, and will not be repeated here.
[0226] The processing by the second core network device after receiving the first access code from the first core network device may further include: sending the first access code from the first core network device. The timing of the second core network device sending the first access code, as long as it occurs after receiving the first access code, is within the scope of this embodiment. Correspondingly, the terminal's processing may further include: receiving the first access code from the second core network device. Here, the relevant processes of the second core network device sending the first access code and the terminal receiving the first access code from the second core network device are the same as in the aforementioned embodiments and will not be repeated.
[0227] After receiving the first access code, the terminal generates the first key based on the first access code and the second key. The specific method by which the terminal generates or calculates the first key, and the relevant description of the second key, are the same as those for the first core network equipment, and therefore will not be repeated.
[0228] The security access policy of the first core network device can be based on the granularity of service, device, or data type. Regarding the above situations, the descriptions related to the granularity of the first access code and the granularity of the message protected by the first key are the same as those in the previous embodiments, and will not be repeated.
[0229] Based on the process in Figure 9, and in conjunction with Figure 12, taking the first core network device as NSP, the second core network device as AUSF, the first access network device as base station, and the terminal as UE as an example, the fourth process after completing the three processes in Figure 9, namely the UE authentication and key generation process, will be explained with NSP and UE generating the first key respectively:
[0230] The explanations for steps 1211 to 1212 are the same as those for steps 1011 to 1012 shown in Figure 10 above, and will not be repeated.
[0231] Step 1213: AUSF sends an encoding retrieval request to NSP. This encoding retrieval request is used to request the first access code from NSP, and may carry a second key (e.g., K). AUSF or K SEAF ).
[0232] Step 1214, NSP generates a first key (e.g., K) based on the first access code and the second key. NSP The specific process for generating the first key is the same as in the aforementioned embodiments and will not be repeated here.
[0233] In step 1215, the NSP sends the first access code to the AUSF. It should be noted that the execution order of steps 1214 and 1215 is not critical.
[0234] Steps 1216 to 1218 are the same as steps 1016 to 1018 shown in Figure 10 above, so they will not be described again.
[0235] In another embodiment, during the terminal authentication process, the terminal and the second core network device respectively derive a first key, and the first core network device receives the first key sent by the second core network device.
[0236] The first access network device sends a terminal authentication request to the second core network device, and correspondingly, the second core network device receives the terminal authentication request sent by the first access network device. After receiving the terminal authentication request from the first access network device, the second core network device may send the terminal authentication request to the fifth core network device. After receiving the terminal authentication request, the fifth core network device may send an encoding acquisition request to the first core network device. The processing of the first core network device may include receiving the encoding acquisition request from the fifth core network device.
[0237] Furthermore, the processing by the first core network device after receiving the encoding acquisition request from the fifth core network device may further include: sending a first access code. The content that may be included in this encoding acquisition request is similar to that in the aforementioned embodiments and will not be described in detail here.
[0238] Specifically, the first core network device sending the first access code can be done by sending the first access code to the fifth core network device.
[0239] The processing by the fifth core network device after receiving the first access code may include: sending an authentication response from the terminal to the second core network device, wherein the authentication response carries the first access code. Correspondingly, the processing by the second core network device after receiving the first access code may include: receiving an authentication response from the terminal, wherein the authentication response carries the first access code.
[0240] For example, the second core network device can be SEAF, and the fifth core network device can be AUSSF. Specifically, the first access network device sends a terminal authentication request to SEAF; SEAF receives the terminal authentication request from the first access network device and then sends the terminal authentication request to AUSSF. After receiving the terminal authentication request, AUSF sends an encoding acquisition request to the first core network device and receives the first access code. SEAF receives the terminal authentication response from AUSSF, which carries the first access code.
[0241] After receiving the first access code, the second core network device can generate the first key based on the first access code and the second key. The specific processing method for generating or calculating the first key is the same as in the previous embodiments and will not be repeated here.
[0242] In this embodiment, the second key can be a key shared between the terminal and the third core network device. For example, the third core network device can be the same as the second core network device, both being SEAF, and the second key can be K. SEAF The calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K SEAF (First access code).
[0243] The processing of the second core network device may further include: sending the first access code from the first core network device. The timing of the second core network device sending the first access code, as long as it occurs after receiving the first access code, is within the scope of protection of this embodiment. Correspondingly, the terminal's processing may further include: receiving the first access code from the second core network device. For example, the second core network device may be an SEAF. The SEAF may send an authentication request to the terminal after receiving the first access code or after generating the first key. This authentication request from the SEAF may carry the first access code. The terminal receives the authentication request from the SEAF, wherein the SEAF's authentication request carries the first access code issued by the AUSF.
[0244] After receiving the first access code from the first core network device, the terminal generates the first key based on the first access code and the second key. The specific method by which the terminal generates or calculates the first key, and the relevant description of the second key, are the same as those for the second core network device, and therefore will not be repeated.
[0245] The security access policy of the first core network device can be based on the granularity of service, device, or data type. Regarding the above situations, the descriptions related to the granularity of the first access code and the granularity of the message protected by the first key are the same as those in the previous embodiments, and will not be repeated.
[0246] It should be noted that in some other possible examples, the first core network device can be an AUSF (i.e., the first core network device and the fifth core network device (AUSF) are the same or co-located in the same entity). In this example, the AUSF may not need to send an encoding acquisition request to the first core network device or receive the first access code from the first core network device. It only needs to obtain the first access code directly from its local machine after receiving the authentication request from the second core network device (SEAF) and send the first access code to the second core network device in the authentication response. Other processes are the same as in the aforementioned embodiments, so they will not be described again.
[0247] Based on the process in Figure 9, and in conjunction with Figure 13, taking the first core network device as NSP, the second core network device as SEAF, the first access network device as base station, and the terminal as UE as an example, the fourth process after completing the three processes in Figure 9, namely the UE authentication and key generation process, will be explained with the example of SEAF and UE generating the first key respectively:
[0248] Step 1311: The base station forwards the UE's authentication request to the SEAF. It should be noted that step 1311 is performed after step 910 in Figure 9.
[0249] Step 1312: SEAF forwards the UE's authentication request to AUSF. AUSF can be a fifth core network device.
[0250] Step 1313: AUSF sends an encoding retrieval request to NSP. The encoding retrieval request is used to request the first access code from NSP.
[0251] Step 1314: NSP sends the first access code to AUSF.
[0252] Step 1315: AUSF sends an authentication response to SEAF, carrying the first access code.
[0253] Step 1316, SEAF is based on the first access code and the second key (e.g., K). SEAF Generate the first key (e.g., K) NSP In this example, the second core network device and the third core network device are the same, both being SEAF.
[0254] Step 1317: The SEAF sends an authentication request to the UE, and the authentication request sent by the SEAF carries the first access code.
[0255] Step 1318: The UE generates a first key based on the first access code and the second key. The second key used by the UE to generate the first key should be the same as the SEAF (i.e., K). SEAF The specific calculation method for the UE to generate the first key is the same as that for SEAF, so it will not be repeated here.
[0256] Step 1319: SEAF sends the first key to NSP. It should be understood that the execution of step 1319 is within the scope of this example as long as it occurs after step 1316. Therefore, the execution order of step 1319 and steps 1317-1318 is not limited here.
[0257] Based on the process shown in Figure 9 (replacing NSP with AUSF in Figure 9), and in conjunction with Figure 14, taking AUSF as the first core network device, SEAF as the second core network device, base station as the first access network device, and UE as the terminal as an example, the fourth process after completing the three processes in Figure 9, namely the UE authentication and key generation process, will be explained with examples of SEAF and UE generating the first key respectively:
[0258] Steps 1411 to 1412 are the same as steps 1311 to 1312 in Figure 13, and will not be described again. Steps 1413 to 1416 are the same as steps 1315 to 1318 shown in Figure 13, and will not be described again.
[0259] In step 1417, SEAF sends the first key to AUSF. It should be understood that the execution of step 1417 is within the scope of protection of this example as long as it occurs after step 1414.
[0260] In some possible implementations, after terminal authentication, the first access network device requests access to the first core network device, and the first core network device verifies whether access is allowed for the first access network device, the terminal generates a first key, and the first core network device obtains the first key.
[0261] In some embodiments, after terminal authentication, the first access network device requests access to the first core network device, and the first core network device verifies whether access is allowed for the first access network device.
[0262] The first access network device may, after the terminal completes authentication, send a service request to the first core network device, wherein the service request carries the access credentials of the first core network device; and receive a service response from the first core network device, wherein the service response is used to indicate whether access to the first core network device is permitted. The processing of the first core network device may include: receiving the service request from the first access network device, wherein the service request carries the access credentials of the first core network device; and sending a service response to the first access network device, wherein the service response is used to indicate whether access to the first core network device is permitted.
[0263] The description of the access credentials for the first core network device is the same as that in the aforementioned embodiments, and will not be repeated.
[0264] After the first core network device receives a service request from the first access network device and before sending a service response to the first access network device, it may further include at least one of the following: verifying the access token of the first core network device; verifying the first access code of the first core network device (hereinafter referred to as verifying the first access code).
[0265] The explanations regarding the verification of the access token of the first core network device, the verification of the first access code, and the related processing of the first core network device generating a service response based on whether the verification is successful are all the same as those in the aforementioned embodiments and will not be repeated.
[0266] In this embodiment, after authentication, the terminal can receive a first access code. Receiving the first access code from the first core network device includes one of the following: receiving the first access code from a second core network device; or receiving the first access code from a first access network device. Furthermore, the first key can be derived by the terminal and the second core network device respectively, or by the terminal and the first access network device respectively. The process by which the first core network device obtains the first key can include one of the following: receiving the first key from the second core network device; or receiving the first key from the first access network device. The following describes these two scenarios using different embodiments.
[0267] In one embodiment, after the terminal completes authentication, the terminal and the second core network device respectively derive a first key, and the first core network device receives the first key from the second core network device.
[0268] Upon determining that access to the first core network device is permitted, the first core network device may send a first access code. The processing by the second core network device may include receiving the first access code.
[0269] Specifically, the first core network device sending the first access code may include: sending the first access code to the second core network device. Correspondingly, the second core network device receiving the first access code specifically includes: the second core network device receiving the first access code from the first core network device.
[0270] The processing by the second core network device after receiving the first access code may include: generating the first key based on the first access code and the second key, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device; and sending the first key to the first core network device. The processing of generating the first key based on the first access code and the second key is similar to that in the previous embodiments and will not be described again.
[0271] Optionally, the second key can be any key shared between the terminal and the third core network device. For example, the second core network device can be an AMF (Advanced Management Function), and the third core network device can be the same as the second core network device, also an AMF. The second key can be a key shared between the terminal and the AMF. AMF Or any NAS (Non-Access Stratum) key, which may include at least one of the following: K NASint K NASenc Wait, this doesn't limit or exhaustively list all possible types of NAS keys, nor does it limit or exhaustively list which NAS key the second key could be. Let the second key be K. AMFFor example, the calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K AMF (First access code). Using the second key as K. NASint For example, the calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K NASint (First access code). Using the second key as K. NASenc For example, the calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K NASenc (First access code).
[0272] Optionally, the second key can be any key shared between the terminal and the first access network device. For example, the second core network device can be the AMF, and the key shared between the terminal and the first access network device that can be obtained on the AMF side can be K. gNB With the second key as K gNB For example, the calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K gNB (First access code).
[0273] The processing by the second core network device after receiving the first access code may further include: sending the first access code from the first core network device. Specifically, sending the first access code by the second core network device may include: the second core network device sending the first access code to the terminal. Correspondingly, on the terminal side, receiving the first access code from the first core network device may include: receiving the first access code from the second core network device.
[0274] In this embodiment, the first access code sent by the second core network device to the terminal can be carried by the NAS Security Mode Command (SMC).
[0275] After the terminal receives the first access code, the method for generating the first key based on the first access code should be the same as that of the second core network device, so it will not be repeated.
[0276] In this embodiment, after generating the first key, the terminal can also send a NAS security mode complete message to the second core network device.
[0277] The security access policy of the first core network device can be based on the granularity of service, device, or data type. Regarding the above situations, the descriptions related to the granularity of the first access code and the granularity of the message protected by the first key are the same as those in the previous embodiments, and will not be repeated.
[0278] Referring to Figure 15, taking the first core network device as NSP, the second core network device as AMF, the first access network device as base station, and the terminal as UE as an example, the service request process of the base station and the key generation after UE authentication are explained:
[0279] Steps 1501 to 1505 constitute the UE's access authentication process.
[0280] Step 1501: The UE sends an RRC message to the base station (NSC), which carries the UE's authentication request.
[0281] Step 1502: The base station sends the UE's authentication request to the SEAF.
[0282] Step 1503: SEAF sends the UE's authentication request to AUSF.
[0283] Step 1504: AFSU sends the UE's authentication response to SEAF.
[0284] Step 1505: SEAF sends an authentication request to the UE.
[0285] It should be noted that steps 1501 to 1505 above are only a brief description of the UE's access authentication process, and do not limit the messages that may be transmitted between various devices and all the contents that may be carried during the UE's access authentication process.
[0286] Steps 1506 to 1508 constitute the service request process for the base station.
[0287] Step 1506: The base station sends a service request (NF Service request, or NF service request (or service request)) to the NSP, which carries the NSP's access credentials.
[0288] It should be noted that before executing step 1506, the processing of steps 901 to 907 as shown in Figure 9 may have been completed. This example does not limit the specific timing of the execution of steps 901 to 907 in this example. As long as the processing of steps 901 to 907 is completed before step 1507, it is within the protection scope of this embodiment.
[0289] The processing of steps 1507 to 1508 is the same as that of steps 909 to 910 shown in Figure 9 above, and will not be described again.
[0290] Steps 1509 to 1514 are the process of deriving keys in the NAS SMC process.
[0291] Step 1509: NSP sends its first access code to AMF.
[0292] Step 1510, AMF is based on the first access code and the second key (e.g., K). AMF or K gNB Generate the first key (e.g., K) NSP It should be understood that AMF can also receive K from SEAF before performing step 1510. AMF Since the specific way of deriving KAMF is not limited in this embodiment, it is not illustrated in Figure 15 for the sake of simplicity.
[0293] Step 1511: The AMF sends a NAS SMC to the UE, which carries the first access code.
[0294] Step 1512: The UE generates a first key based on the first access code and the second key. The second key used by the UE to generate the first key should be the same as the AMF, and the specific calculation method for the UE to generate the first key is also the same as that for the AMF, so it will not be described again.
[0295] Step 1513: The UE sends the NAS security mode completion message to the AMF.
[0296] Step 1514: AMF sends the first key to NSP. It should be understood that the execution of step 1514 is within the scope of protection of this example as long as it occurs after step 1510. Therefore, the execution order of step 1514 and steps 1511 to 1513 is not limited here.
[0297] In some possible examples, the first core network device can be an AUSF (i.e., the NSP shown in Figure 15 is the same as or co-located with the AUSF in the same entity). In this example, all the processes performed by the NSP shown in Figure 15 can be replaced by the AUSF. Specifically: step 1506 is replaced by the base station sending a service request (carrying the AUSF's access credentials) to the AUSF; step 1507 is replaced by the AUSF verifying the AUSF's access credentials; step 1508 is replaced by the AUSF sending a service response to the base station; step 1509 is replaced by the AUSF sending the first access code to the AMF; and step 1514 is replaced by the AMF sending the first key to the AUSF.
[0298] In some embodiments, after the terminal completes authentication, the terminal and the first access network device respectively derive the first key, and the first core network device receives the first key from the first access network device.
[0299] Optionally, if the first core network device determines that access to the first core network device is permitted, it may send the first access code of the first core network device to the second core network device. Correspondingly, the second core network device receiving the first access code of the first core network device specifically includes: the second core network device receiving the first access code of the first core network device from the first core network device.
[0300] The processing by the second core network device after receiving the first access code may further include: sending the first access code from the first core network device. The processing by the first access network device may include: receiving the first access code. Specifically, the second core network device sending the first access code may include: the second core network device sending the first access code to the first access network device. On the first access network device side, receiving the first access code may include: receiving the first access code from the second core network device.
[0301] Optionally, if the first core network device determines that access to the first core network device is permitted, it may send the first access code to the first access network device. Correspondingly, on the first access network device side, receiving the first access code may include: receiving the first access code from the first core network device.
[0302] After receiving the first access code, the first access network device further includes: generating the first key based on the first access code and the key shared between the terminal and the first access network device; and sending the first key to the first core network device.
[0303] The key shared between the terminal and the first access network device refers to the key shared between the terminal and the first access network device used to calculate the first key. In this embodiment, the key shared between the terminal and the first access network device used to calculate the first key can be any type of AS key. Specifically, the AS key can include at least one of the following: K gNB NH (next-hop key), K RRCint K RRCenc K UPint K UPenc Wait, the key shared between the terminal used to calculate the first key and the first access network device can be any one of the AS keys mentioned above. This does not limit or exhaustively list all possible types of AS keys, nor does it limit or exhaustively list which AS key the key shared between the terminal used to calculate the first key and the first access network device might be. For example, let's say the key shared between the terminal used to calculate the first key and the first access network device is K. gNB For example, the calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K gNB(First access code). The key shared between the terminal used to calculate the first key and the first access network device is K. RRCenc For example, the calculation or generation of the first key can be represented by the following formula: K NSP =KDF( RRCenc (First access code). Since the process of generating the first key is similar to that in the previous embodiments, it will not be described again.
[0304] It should be understood that the first access network device may receive K from the second core network device simultaneously with or before receiving the first access code, or before generating the first key. gNB .
[0305] Optionally, the first access network device can obtain the first access code upon receiving the access credential from the first core network device. In this case, the first access network device can also obtain the first access code upon receiving a service response indicating permission to access the first core network device and receiving a K from the second core network device. gNB Subsequently, the first key is generated based on the first access code and the key shared between the terminal and the first access network device. The explanation regarding the generation of the first key is the same as in the previous example and will not be repeated here.
[0306] After receiving the first access code from the first core network device, or after receiving a service response indicating permission to access the first core network device, the first access network device may further include: sending the first access code from the first core network device. Specifically, sending the first access code by the first access network device includes: the first access network device sending the first access code to the terminal. Correspondingly, on the terminal side, the first access code is received from the first access network device.
[0307] In this embodiment, the first access code sent by the first access network device to the terminal can be carried by the AS SMC.
[0308] After the terminal receives the first access code, the method for generating the first key based on the first access code should be the same as that of the first access network device, so it will not be described again.
[0309] In this embodiment, after generating the first key, the terminal can also send the AS security mode completion message to the second core network device.
[0310] Additionally, the first access network device can send the first key to the first core network device after generating it. Correspondingly, the first core network device receives the first key from the first access network device.
[0311] The description of the granularity of the messages protected by the first key is the same as that in the previous embodiments, and will not be repeated.
[0312] Referring to Figure 16, taking the first core network device as NSP, the second core network device as AMF, the first access network device as base station, and the terminal as UE as an example, the service request process of the base station and the key generation after UE authentication are explained:
[0313] Steps 1601 to 1605 constitute the UE's access authentication process. The processing of steps 1601 to 1605 is the same as that of steps 1501 to 1505 in Figure 15, and will not be described in detail.
[0314] Steps 1606 to 1608 constitute the service request process of the base station. The processing of steps 1606 to 1608 is the same as that of steps 1506 to 1508 in Figure 15, and will not be described in detail.
[0315] Steps 1609 to 1614 are the process of deriving the key in the AS SMC procedure.
[0316] Step 1609: NSP sends its first access code to AMF.
[0317] Step 1610: The AMF sends the first access code to the base station. In this step, the AMF may also send K to the base station. gNB For the sake of simplicity, it is not shown in the diagram.
[0318] Step 1611: The base station generates a first key based on the first access code and the key shared between the UE and the base station. The detailed explanation of how the base station derives the first key is the same as in the previous embodiments and will not be repeated.
[0319] In step 1612, the base station sends an AS SMC to the UE, which carries the first access code. The execution of steps 1611 and 1612 can be in any order.
[0320] Step 1613: The UE generates a first key based on the first access code and the key shared between the UE and the base station. The specific calculation method for the UE to generate the first key is the same as that of the base station.
[0321] Step 1614: The UE sends the AS security mode completion message to the base station.
[0322] Step 1615: The base station sends the first key to the NSP. It should be understood that the execution of step 1615 is within the scope of this example as long as it occurs after step 1611. The execution order of step 1615 and steps 1612 to 1614 is not limited here.
[0323] In some possible examples, the first core network device can be an AUSF (i.e., the NSP shown in Figure 16 is the same as or co-located with the AUSF in the same entity). In this example, all the processes performed by the NSP shown in Figure 16 can be replaced by the AUSF. Specifically: step 1606 is replaced by the base station sending a service request (carrying the AUSF's access credentials) to the AUSF; step 1607 is replaced by the AUSF verifying the AUSF's access credentials; step 1608 is replaced by the AUSF sending a service response to the base station; step 1609 is replaced by the AUSF sending the first access code to the AMF; and step 1615 is replaced by the base station sending the first key to the AUSF.
[0324] In some embodiments, after the terminal completes authentication, the terminal and the first core network device respectively generate a first key.
[0325] On the first core network device side, if it determines that access to the first core network device is permitted, it may send the first access code of the first core network device. The processing of the second core network device may include: receiving the first access code of the first core network device.
[0326] Sending a first access code from a first core network device may include sending the first access code to a second core network device. Correspondingly, receiving the first access code from the first core network device may include receiving the first access code from the first core network device.
[0327] The processing by the first core network device after determining that access is permitted may further include: sending a key request message to the second core network device to obtain a second key. Correspondingly, the second core network device may also receive a key request message from the first core network device to obtain a second key. In this example, the key request message and the first access code may be sent simultaneously; for example, the key request message may carry the first access code; or, for example, the key request message and the first access code may be carried in the same message.
[0328] Furthermore, the first core network device can also receive a second key. Receiving the second key by the first core network device can include: the first core network device receiving a second key from the second core network device. Correspondingly, the processing after the second core network device receives the first access code and key request message can further include: sending the second key to the first core network device, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device.
[0329] The processing by the first core network device after receiving the second key may include: obtaining the first key. The processing by which the first core network device obtains the first key may include: generating the first key based on the first access code and the second key. For example, the second core network device may be an AMF (Access Default Function). The second key may be a key shared between the terminal and the third core network device, which may be the same as the second core network device and also be an AMF. The second key may be any NAS key, such as K. AMF Alternatively, the second key can be a key shared between the terminal and the first access network device; for example, the second key could be K. gNB The process for generating the first key is similar to that in the previous embodiments and will not be repeated here.
[0330] The processing of the second core network device after receiving the first access code and key request message may further include: sending the first access code of the first core network device.
[0331] The second core network device sending the first access code from the first core network device can include: the second core network device sending the first access code to the terminal. Correspondingly, on the terminal side, receiving the first access code from the first core network device can include: receiving the first access code from the second core network device. The first access code sent by the second core network device to the terminal can be carried by the NAS SMC.
[0332] After the terminal receives the first access code from the second core network device, it generates a first key based on the first access code. The method for generating the first key on the terminal side should be the same as that of the first core network device, and therefore will not be described again.
[0333] In this embodiment, after generating the first key, the terminal can also send a NAS security mode completion message to the second core network device.
[0334] It should be noted that the description of the granularity of the messages protected by the first key is the same as that in the aforementioned embodiments, and will not be repeated.
[0335] Referring to Figure 17, taking the first core network device as NSP, the second core network device as AMF, the first access network device as base station, and the terminal as UE as an example, the service request process of the base station and the key generation after UE authentication are explained:
[0336] Steps 1701 to 1708 are the same as steps 1501 to 1508 in the example corresponding to Figure 15 above, and will not be described again.
[0337] Step 1709: NSP sends a first access code and key acquisition request to AMF. This key acquisition request is used to request the acquisition of a second key.
[0338] Step 1710, AMF sends a second key (e.g., K) to NSP. AMF or K gNB ).
[0339] Step 1711: NSP generates a first key based on the first access code and the second key.
[0340] In step 1712, the AMF sends a NAS SMC to the UE, which carries the first access code. It should be understood that the AMF can also receive a K from the SEAF before performing step 1712. AMF and derived K gNB It is then sent to the base station, which is not illustrated in Figure 17 for simplicity.
[0341] Step 1713: The UE generates a first key based on the first access code and the second key. The second key used by the UE to generate the first key should be the same as the NSP, and the specific calculation method for the UE to generate the first key is also the same as that for the NSP, so it will not be described again.
[0342] Step 1714: The UE sends the NAS security mode completion message to the AMF.
[0343] It should be understood that the execution of step 1711 is within the scope of protection of this example as long as it is performed after step 1710. The execution order between step 1711 and steps 1712 to 1714 is not limited here.
[0344] In some possible examples, the first core network device can be an AUSF (i.e., the NSP shown in Figure 17 is the same as or co-located with the AUSF in the same entity). In this example, all the processes performed by the NSP shown in Figure 17 can be replaced by the AUSF. Specifically: step 1706 is replaced by the base station sending a service request (carrying the AUSF's access credentials) to the AUSF; step 1707 is replaced by the AUSF verifying the AUSF's access credentials; step 1708 is replaced by the AUSF sending a service response to the base station; step 1709 is replaced by the AUSF sending a first access code and key acquisition request to the AMF; step 1710 is replaced by the AMF sending a second key to the AUSF; and step 1711 is replaced by the AUSF generating a first key based on the first access code and the second key.
[0345] In some embodiments, after the terminal completes authentication, the terminal and the first core network device respectively generate a first key.
[0346] When the first core network device determines that access is permitted, it may send a first access code to the first core network device. The processing by the first access network device may include receiving the first access code from the first core network device.
[0347] Sending a first access code from the first core network device may include sending the first access code to the first access network device. Correspondingly, receiving the first access code from the first core network device may include receiving the first access code from the first core network device.
[0348] The processing by the first core network device after determining that access is permitted may further include: sending a key request message to the first access network device. Correspondingly, the first access network device may also receive a key request message from the first core network device. In this example, the key request message and the first access code may be sent simultaneously; for example, the key request message may carry the first access code; or, for example, the key request message and the first access code may be carried in the same message.
[0349] Furthermore, after the first core network device sends the key request message, it may include: the first core network device receiving the key shared between the terminal and the first access network device from the first access network device. Correspondingly, the processing after the first access network device receives the first access code and key request message may further include: sending the key shared between the terminal and the first access network device to the first core network device. The key shared between the terminal and the first access network device refers to the key shared between the terminal and the first access network device used to calculate the first key. The relevant descriptions regarding the key shared between the terminal and the first access network device used to calculate the first key are the same as in the previous embodiments and will not be repeated here.
[0350] The processing by the first core network device after receiving the key shared between the terminal and the first access network device may include: generating the first key based on the first access code and the key shared between the terminal and the first access network device. The related processing for generating the first key based on the first access code and the key shared between the terminal and the first access network device is the same as in the previous embodiments and will not be repeated here.
[0351] After receiving the first access code, the first access network device may further include: sending the first access code from the first core network device. Specifically, the first access network device sending the first access code from the first core network device includes: the first access network device sending the first access code to the terminal. Correspondingly, on the terminal side, receiving the first access code from the first core network device may include: receiving the first access code from the first core network device.
[0352] In this embodiment, the first access code sent by the first access network device to the terminal can be carried by the AS SMC.
[0353] After the terminal receives the first access code from the first access network device, the method for generating the first key based on the first access code should be the same as that of the first core network device, and will not be described again.
[0354] In this embodiment, after generating the first key, the terminal can also send the AS security mode completion message to the first access network device.
[0355] Referring to Figure 18, taking the first access network device as the base station, the second core network device as the key generation network element, and the terminal as the UE as an example, the following exemplarily describes the process of the first access network device requesting access to the services of the first core network device, the first core network device verifying whether access is allowed, the terminal generating the first key, and the first core network device obtaining the first key:
[0356] In step 1800, the UE sends an access request to the base station. This access request can be an authentication request from the UE.
[0357] In step 1801, in order to establish a connection with the first core network device, the base station sends a service request (also referred to as a service request) to the first core network device. The service request contains the access token and / or the first access code of the first core network device.
[0358] Step 1802: The first core network device determines whether to allow the base station to access (or whether to authorize the base station's service request) based on the access token and / or the first access code.
[0359] Step 1803: If the first core network device determines that the base station is allowed to access, the first core network device sends the first access code of the first core network device to the key generation network element.
[0360] Step 1804: The key generation network element generates a first key based on the first access code. The first key is the key (or security key) between the first core network device and the UE.
[0361] Step 1805: The key generation network element sends the first access code to the UE.
[0362] Step 1806: The UE generates a first key based on the first access code.
[0363] Step 1807: The key generation network element sends the first key to the first core network device. Step 1807 can be executed at any stage after step 1804.
[0364] It should be noted that in some possible examples, the first core network device may also send the first access code to the base station, and step 1805 is replaced by the base station sending the first access code to the UE. This situation is not illustrated in Figure 18 for the sake of simplicity.
[0365] In terms of relevant technologies, the existing N2 interface exists between the base station and the AMF (Application Function), preventing the base station from directly accessing other core network elements. After upgrading the N2 interface to the SBI (Service Based Interface) protocol, the base station can access other core network elements, such as SMF, NWDAF, UDM, and PCF. This increases the probability of high-security core network elements being accessed by the base station. However, the current SBA registration and access service policy only includes service-related policies, lacking security policies. This makes it impossible to guarantee the security of messages transmitted between the terminal and other core network devices. Furthermore, the current SBA registration and access service policy, due to the absence of security policies, may also pose security risks, including attackers being able to target high-security core network elements. For example, malicious attackers could directly access various core network elements through the base station to steal or tamper with high-security data or information stored in these core network elements, thus introducing security risks to these core network elements.
[0366] This application provides an embodiment that, by adopting the above scheme, can derive a key between the terminal and the first core network device based on the access code of the first core network device to protect messages between the two parties. In this way, when the terminal accesses the first core network device, the key derived from the access code of the first core network device can be used to protect messages between the two parties, thereby ensuring the security of communication between them.
[0367] Furthermore, the solution provided in this application can also allow the fourth core network device to assign access credentials to the first access network device for verifying whether access to the first core network device is permitted. In this way, when the first access network device needs to access the first core network device, the first core network device can verify the access credentials to determine whether access to the first core network device is permitted, thereby protecting the security of the first core network device.
[0368] In addition, in the solution provided in this application, the first core network device can register its security access policy with the fourth core network device, which enables the fourth core network device to authorize whether to allow the first access network device to access the first core network device according to the security access policy, and send the access certificate of the first core network device to the first access network device. That is, the first access network device will only be authorized to access the first core network device when it meets the requirements of the security access policy of the first core network device, thereby further ensuring the security of the first core network device.
[0369] Figure 19 is a schematic diagram of the composition structure of a terminal according to an embodiment of this application, including:
[0370] The first communication unit 1901 is used to receive the first access code of the first core network device;
[0371] The first processing unit 1902 is configured to generate a first key based on the first access code, wherein the first key is used to protect messages between the terminal and the first core network device.
[0372] The first access code corresponds to a first service, and the first key is used to protect messages of the first service between the terminal and the first core network device; or, the first access code corresponds to a first data type of the first service, and the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.
[0373] The first communication unit is configured to perform one of the following: receive the first access code from the second core network device; or receive the first access code from the first access network device.
[0374] The second core network equipment includes at least one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), Access and Mobility Management Function (AMF), and Key Generation Network Element.
[0375] The first processing unit is configured to generate the first key based on the first access code and the second key, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device.
[0376] The third core network equipment includes at least one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), and Access and Mobility Management Function (AMF).
[0377] The first access code of the first core network device is included in the security access policy of the first core network device, wherein the security access policy of the first core network device is used to indicate whether access to the first core network device is allowed.
[0378] Figure 20 is a schematic diagram of the composition structure of a first core network device according to an embodiment of this application, including:
[0379] The second communication unit 2001 is used to obtain a first key, wherein the first key is generated based on the first access code of the first core network device, and the first key is used to protect messages between the terminal and the first core network device.
[0380] The first access code corresponds to a first service, and the first key is used to protect messages of the first service between the terminal and the first core network device; or, the first access code corresponds to a first data type of the first service, and the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.
[0381] The second communication unit is configured to perform one of the following: receive the first key from the second core network device; or receive the first key from the first access network device.
[0382] The second core network equipment includes at least one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), Access and Mobility Management Function (AMF), and Key Generation Network Element.
[0383] As shown in Figure 20, the first core network device further includes a second processing unit 2002, used to generate the first key based on the first access code.
[0384] The second processing unit is configured to generate the first key based on the first access code and the second key, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device.
[0385] The second communication unit is used to receive the second key.
[0386] The second communication unit is used to send the first access code.
[0387] The second communication unit is used to receive encoding acquisition requests.
[0388] The second communication unit is configured to receive a service request from a first access network device, wherein the service request carries the access credentials of the first core network device; and to send a service response to the first access network device, wherein the service response is used to indicate whether access to the first core network device is permitted.
[0389] The access credentials of the first core network device include at least one of the following: the access token of the first core network device, and the first access code.
[0390] The second processing unit is configured to perform at least one of the following: verify the access token of the first core network device; verify the first access code.
[0391] The second communication unit is used to send the security access policy of the first core network device to the fourth core network device.
[0392] The security access policy of the first core network device is used to indicate whether access to the first core network device is permitted.
[0393] Whether to allow access to the first core network device includes at least one of the following: whether to allow the access network device to access at least one service of the first core network device, and whether to allow the access network device to access at least one data type of at least one service of the first core network device.
[0394] The security access policy of the first core network device includes at least one access code of the first core network device.
[0395] The first core network device includes at least one of the following: the access code corresponding to each service in at least one service that the first core network device allows access network devices to access; and the access code corresponding to at least one data type of each service in at least one service that the first core network device allows access network devices to access.
[0396] Figure 21 is a schematic diagram of the composition structure of a first access network device according to an embodiment of this application, including:
[0397] The third communication unit 2101 is used to send a first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
[0398] As shown in Figure 21, the first access network device further includes: a third processing unit 2102, used to generate the first key based on the first access code and the key shared between the terminal and the first access network device;
[0399] The third communication unit is used to send the first key to the first core network device.
[0400] The third communication unit is used to receive the first access code.
[0401] The first access code corresponds to a first service, and the first key is used to protect messages of the first service between the terminal and the first core network device; or, the first access code corresponds to a first data type of the first service, and the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.
[0402] Figure 22 is a schematic diagram of the composition structure of a second core network device according to an embodiment of this application, including:
[0403] The fourth communication unit 2201 is used to send a first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
[0404] As shown in Figure 22, the second core network device further includes: a fourth processing unit 2202, used to generate the first key based on the first access code and the second key, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, and a key shared between the terminal and the first access network device;
[0405] The fourth communication unit is used to send the first key to the first core network device.
[0406] The fourth communication unit is used to send a second key to the first core network device, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device.
[0407] The third core network equipment includes at least one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), and Access and Mobility Management Function (AMF).
[0408] The fourth communication unit is used to receive the first access code.
[0409] The fourth communication unit is used to send an encoding acquisition request.
[0410] The first access code corresponds to a first service, and the first key is used to protect messages of the first service between the terminal and the first core network device; or, the first access code corresponds to a first data type of the first service, and the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.
[0411] Figure 23 is a schematic diagram of the composition structure of a fourth core network device according to an embodiment of this application, including...
[0412] The fifth communication unit 2301 is used to send the access credential of the first core network device to the first access network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
[0413] The fifth communication unit is configured to receive an acquisition request from the first access network device, wherein the acquisition request is used to acquire the access credentials of the first core network device.
[0414] The acquisition request carries at least one of the following: identification information of the first core network device, identifier of the first service, type of the first core network device, type of the first access network device, identifier of the first access network device, and identifier of the first data type.
[0415] The access credentials of the first core network device include at least one of the following: the access token of the first core network device, and the first access code of the first core network device, wherein the access token of the first core network device is generated based on the first access code.
[0416] The access token of the first core network device corresponds to the first service, and the first access code corresponds to the first service; or, the access token of the first core network device corresponds to the first data type of the first service, and the first access code corresponds to the first data type of the first service.
[0417] As shown in Figure 23, the fourth core network device further includes a fifth processing unit 2302, which is used to determine whether to authorize the first access network device to access the first core network device based on the security access policy of the first core network device.
[0418] The fifth communication unit is used to receive the security access policy of the first core network device.
[0419] The security access policy of the first core network device is used to indicate whether access to the first core network device is permitted.
[0420] Whether to allow access to the first core network device includes at least one of the following: whether to allow the access network device to access at least one service of the first core network device, and whether to allow the access network device to access at least one data type of at least one service of the first core network device.
[0421] The security access policy of the first core network device includes at least one access code of the first core network device.
[0422] The first core network device includes at least one of the following: the access code corresponding to each service in at least one service that the first core network device allows access network devices to access; and the access code corresponding to at least one data type under each service in at least one service that the first core network device allows access network devices to access.
[0423] In one embodiment, the first access network device includes:
[0424] The third communication unit is used to receive the access credential of the first core network device from the fourth core network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
[0425] The third communication unit is used to send an acquisition request to the fourth core network device, wherein the acquisition request is used to acquire the access credential of the first core network device.
[0426] The acquisition request carries at least one of the following: identification information of the first core network device, identifier of the first service, type of the first core network device, type of the first access network device, identifier of the first access network device, and identifier of the first data type.
[0427] The access credentials of the first core network device include at least one of the following: the access token of the first core network device, and the first access code of the first core network device.
[0428] The access token of the first core network device corresponds to the first service, or the access token of the first core network device corresponds to the first data type of the first service.
[0429] The third communication unit is configured to send a service request to the first core network device, wherein the service request carries the access credentials of the first core network device; and to receive a service response from the first core network device, wherein the service response is used to indicate whether access to the first core network device is permitted.
[0430] The third communication unit is used to send the first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
[0431] The third processing unit is used to generate the first key based on the first access code and the key shared between the terminal and the first access network device;
[0432] The third communication unit is used to send the first key to the first core network device.
[0433] The first access code corresponds to a first service, and the first key is used to protect messages of the first service between the terminal and the first core network device; or, the first access code corresponds to a first data type of the first service, and the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.
[0434] The device in this application embodiment can realize the corresponding functions of the devices in the foregoing information processing method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in this device can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the device of this application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).
[0435] It should be understood that the sequence number of each process in the various embodiments of this application does not imply the order of execution; the execution order of each process should be determined by its function and internal logic. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. The above descriptions are merely specific embodiments of this application, and the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An information processing method executed by a terminal, comprising: Receive the first access code from the first core network device; Based on the first access code, a first key is generated, wherein the first key is used to protect messages between the terminal and the first core network device.
2. The method according to claim 1, wherein, The first access code corresponds to the first service, and the first key is used to protect the messages of the first service between the terminal and the first core network device; Alternatively, the first access code corresponds to the first data type of the first service, and the first key is used to protect messages under the first data type of the first service between the terminal and the first core network device.
3. The method according to claim 1 or 2, wherein, The first access code received from the first core network device includes one of the following: Receive the first access code from the second core network device; Receive the first access code from the first access network device.
4. The method according to claim 3, wherein, The second core network equipment includes at least one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), Access and Mobility Management Function (AMF), and Key Generation Network Element.
5. The method according to any one of claims 1-4, wherein, The step of generating the first key based on the first access code includes: Based on the first access code and the second key, the first key is generated, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device.
6. The method according to claim 5, wherein, The third core network equipment includes at least one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), and Access and Mobility Management Function (AMF).
7. The method according to any one of claims 1-6, wherein, The first access code is included in the security access policy of the first core network device, wherein the security access policy of the first core network device is used to indicate whether access to the first core network device is allowed.
8. An information processing method executed by a first core network device, comprising: Obtain a first key, wherein the first key is generated based on a first access code of the first core network device, and the first key is used to protect messages between the terminal and the first core network device.
9. The method according to claim 8, wherein, The first access code corresponds to the first service, and the first key is used to protect the messages of the first service between the terminal and the first core network device; Alternatively, the first access code corresponds to the first data type of the first service, and the first key is used to protect messages under the first data type of the first service between the terminal and the first core network device.
10. The method according to claim 8 or 9, wherein, The acquisition of the first key includes one of the following: Receive the first key from the second core network device; Receive the first key from the first access network device.
11. The method according to claim 10, wherein, The second core network equipment includes at least one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), Access and Mobility Management Function (AMF), and Key Generation Network Element.
12. The method according to claim 8 or 9, wherein, Obtaining the first key includes: The first key is generated based on the first access code.
13. The method according to claim 12, wherein, The step of generating the first key based on the first access code includes: Based on the first access code and the second key, the first key is generated, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device.
14. The method of claim 13, further comprising: Receive the second key.
15. The method according to any one of claims 8-14, further comprising: Send the first access code.
16. The method of claim 15, further comprising: Receive encoding retrieval request.
17. The method according to any one of claims 8-16, further comprising: Receive a service request from a first access network device, wherein the service request carries the access credentials of the first core network device; Send a service response to the first access network device, wherein the service response is used to indicate whether access to the first core network device is permitted.
18. The method according to claim 17, wherein, The access credentials of the first core network device include at least one of the following: the access token of the first core network device, and the first access code.
19. The method of claim 18, further comprising at least one of the following: Verify the access token of the first core network device; Verify the first access code.
20. The method according to any one of claims 8-19, further comprising: Send the security access policy of the first core network device to the fourth core network device.
21. The method according to claim 20, wherein, The security access policy of the first core network device is used to indicate whether access to the first core network device is permitted.
22. The method according to claim 21, wherein, Whether to allow access to the first core network device includes at least one of the following: whether to allow the access network device to access at least one service of the first core network device, and whether to allow the access network device to access at least one data type of at least one service of the first core network device.
23. The method according to claim 21 or 22, wherein, The security access policy of the first core network device includes at least one access code of the first core network device.
24. The method according to claim 23, wherein, The first core network device includes at least one of the following: the access code corresponding to each service in at least one service that the first core network device allows access network devices to access; and the access code corresponding to at least one data type of each service in at least one service that the first core network device allows access network devices to access.
25. An information processing method executed by a first access network device, comprising: Send a first access code from the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.
26. The method of claim 25, further comprising: The first key is generated based on the first access code and the key shared between the terminal and the first access network device; Send the first key to the first core network device.
27. The method according to claim 25 or 26, further comprising: Receive the first access code.
28. The method according to any one of claims 25-27, wherein, The first access code corresponds to the first service, and the first key is used to protect the messages of the first service between the terminal and the first core network device; Alternatively, the first access code corresponds to the first data type of the first service, and the first key is used to protect messages under the first data type of the first service between the terminal and the first core network device.
29. An information processing method executed by a second core network device, comprising: Send a first access code from the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.
30. The method of claim 29, further comprising: Based on the first access code and the second key, the first key is generated, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device; Send the first key to the first core network device.
31. The method of claim 29, further comprising: Send a second key to the first core network device, wherein the second key includes one of the following: a key shared between the terminal and the third core network device, or a key shared between the terminal and the first access network device.
32. The method according to claim 30 or 31, wherein, The third core network equipment includes at least one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), and Access and Mobility Management Function (AMF).
33. The method according to any one of claims 29-32, further comprising: Receive the first access code.
34. The method of claim 33, further comprising: Send an encoding retrieval request.
35. The method according to any one of claims 29-34, wherein, The first access code corresponds to the first service, and the first key is used to protect the messages of the first service between the terminal and the first core network device; Alternatively, the first access code corresponds to the first data type of the first service, and the first key is used to protect messages under the first data type of the first service between the terminal and the first core network device.
36. An information processing method executed by a fourth core network device, comprising: Send the access credential of the first core network device to the first access network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
37. The method of claim 36, further comprising: Receive an acquisition request from the first access network device, wherein the acquisition request is used to acquire the access credentials of the first core network device.
38. The method according to claim 37, wherein, The acquisition request carries at least one of the following: identification information of the first core network device, identifier of the first service, type of the first core network device, type of the first access network device, identifier of the first access network device, and identifier of the first data type.
39. The method according to claim 37 or 38, wherein, The access credentials of the first core network device include at least one of the following: the access token of the first core network device, and the first access code of the first core network device, wherein the access token of the first core network device is generated based on the first access code.
40. The method according to claim 39, wherein, The access token of the first core network device corresponds to the first service, and the first access code corresponds to the first service; or, the access token of the first core network device corresponds to the first data type of the first service, and the first access code corresponds to the first data type of the first service.
41. The method according to any one of claims 36-40, further comprising: Based on the security access policy of the first core network device, determine whether to authorize the first access network device to access the first core network device.
42. The method according to any one of claims 36-41, further comprising: Receive the security access policy of the first core network device.
43. The method according to claim 41 or 42, wherein, The security access policy of the first core network device is used to indicate whether access to the first core network device is permitted.
44. The method according to claim 43, wherein, Whether to allow access to the first core network device includes at least one of the following: whether to allow the access network device to access at least one service of the first core network device, and whether to allow the access network device to access at least one data type of at least one service of the first core network device.
45. The method according to claim 43 or 44, wherein, The security access policy of the first core network device includes at least one access code of the first core network device.
46. The method according to claim 45, wherein, The first core network device includes at least one of the following: the access code corresponding to each service in at least one service that the first core network device allows access network devices to access; and the access code corresponding to at least one data type under each service in at least one service that the first core network device allows access network devices to access.
47. An information processing method executed by a first access network device, comprising: The system receives access credentials from the first core network device, which are used to verify whether the first access network device is allowed to access the first core network device.
48. The method of claim 47, further comprising: Send an acquisition request to the fourth core network device, wherein the acquisition request is used to acquire the access credentials of the first core network device.
49. The method according to claim 48, wherein, The acquisition request carries at least one of the following: identification information of the first core network device, identifier of the first service, type of the first core network device, type of the first access network device, identifier of the first access network device, and identifier of the first data type.
50. The method according to any one of claims 47-49, wherein, The access credentials of the first core network device include at least one of the following: the access token of the first core network device, and the first access code of the first core network device.
51. The method according to claim 50, wherein, The access token of the first core network device corresponds to the first service, or the access token of the first core network device corresponds to the first data type of the first service.
52. The method according to any one of claims 47-51, further comprising: Send a service request to the first core network device, wherein the service request carries the access credentials of the first core network device; Receive a service response from the first core network device, wherein the service response is used to indicate whether access to the first core network device is permitted.
53. The method according to any one of claims 47-52, further comprising: Send the first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
54. The method of claim 53, further comprising: The first key is generated based on the first access code and the key shared between the terminal and the first access network device; Send the first key to the first core network device.
55. The method according to claim 53 or 54, wherein, The first access code corresponds to the first service, and the first key is used to protect the messages of the first service between the terminal and the first core network device; Alternatively, the first access code corresponds to the first data type of the first service, and the first key is used to protect messages under the first data type of the first service between the terminal and the first core network device.
56. A terminal, comprising: The first communication unit is used to receive the first access code from the first core network device; The first processing unit is configured to generate a first key based on the first access code, wherein the first key is used to protect messages between the terminal and the first core network device.
57. A first core network device, comprising: The second communication unit is used to obtain a first key, wherein the first key is generated based on a first access code of the first core network device, and the first key is used to protect messages between the terminal and the first core network device.
58. A first access network device, comprising: The third communication unit is used to send a first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
59. A second core network device, comprising: The fourth communication unit is used to send a first access code of the first core network device, wherein the first access code is used by the terminal to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.
60. A fourth core network device, comprising: The fifth communication unit is used to send the access credential of the first core network device to the first access network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
61. A first access network device, comprising: The third communication unit is used to receive the access credential of the first core network device from the fourth core network device, wherein the access credential of the first core network device is used to verify whether the first access network device is allowed to access the first core network device.
Citation Information
Patent Citations
Security negotiation method, security functional entity, core network element, and user equipment
CN109314860A
Method and apparatus for protecting privacy issue for authentication and key management for applications
US20240244427A1
Communication method and equipment
WO2017128306A1