Information processing method and device

By generating keys and access credentials based on terminal access codes for verification, the problem of core network element communication security after the N2 interface upgrade was solved, and secure communication between the terminal and core network equipment was realized.

WO2026081211A1PCT designated stage Publication Date: 2026-04-23GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
Filing Date
2024-10-18
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

After the existing N2 interface is upgraded to the SBI protocol, the base station can access other core network elements on the core network side, but the lack of security policies makes it impossible to guarantee the security of communication between the terminal and other core network equipment.

Method used

By generating a first key based on the terminal access code, the messages between the terminal and the first core network device are protected, and the access credentials are used to verify the legitimacy of the access network device, thus ensuring communication security.

Benefits of technology

This technology enables the use of access codes to derive keys to protect messages when terminals access core network equipment, thus ensuring communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024125894_23042026_PF_FP_ABST
    Figure CN2024125894_23042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to an information processing method and a device. The method comprises: receiving an access code of a terminal; and generating a first key on the basis of the access code of the terminal, the first key being used for protecting a message between the terminal and a first core network device.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing methods and equipment Technical Field

[0001] This application relates to the field of communications, and more specifically, to an information processing method and apparatus. Background Technology

[0002] In existing technologies, the N2 interface exists between the base station and the AMF (Access and Mobility Management Function). The base station can only access the core network through the N2 interface and cannot directly access other core network elements on the core network side. With the N2 interface being upgraded to the SBI (Service Based Interface) protocol, the base station can access other core network elements on the core network side. However, existing registration and access service policies only include service-related policies and lack security policies. Therefore, the security of terminal communication with other core network devices cannot be guaranteed.

[0003] Summary of the Invention

[0004] This application provides an information processing method and apparatus.

[0005] This application provides an information processing method executed by a terminal, including:

[0006] The access code of the receiving terminal;

[0007] Based on the access code of the terminal, a first key is generated, wherein the first key is used to protect messages between the terminal and the first core network device.

[0008] This application provides an information processing method executed by a first core network device, including:

[0009] Obtain a first key, wherein the first key is generated based on the terminal's access code and is used to protect messages between the terminal and the first core network device.

[0010] This application provides an information processing method executed by a first access network device, including:

[0011] The terminal access code is sent, wherein the terminal access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

[0012] This application provides an information processing method executed by a second core network device, including:

[0013] The terminal access code is sent, wherein the terminal access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

[0014] This application provides an information processing method executed by a third core network device, including:

[0015] Send an access credential to the first access network device, wherein the access credential is used to verify whether the first access network device is allowed to access the first core network device.

[0016] This application provides an information processing method executed by a first access network device, including:

[0017] Receive access credentials from a third core network device, wherein the access credentials are used to verify whether the first access network device is allowed to access the first core network device.

[0018] This application provides an information processing method executed by a fourth core network device, including:

[0019] Receive a request to obtain the terminal encoding;

[0020] Send the access code of the terminal.

[0021] This application provides a terminal, including:

[0022] The first communication unit is used to receive the access code from the terminal;

[0023] The first processing unit is configured to generate a first key based on the access code of the terminal, wherein the first key is used to protect messages between the terminal and the first core network device.

[0024] This application provides a first core network device, including:

[0025] The second communication unit is used to obtain a first key, wherein the first key is generated based on the terminal's access code and is used to protect messages between the terminal and the first core network device.

[0026] This application provides a first access network device, including:

[0027] The third communication unit is used to send the terminal's access code, wherein the terminal's access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

[0028] This application provides a second core network device, including:

[0029] The fourth communication unit is used to send the terminal's access code, wherein the terminal's access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

[0030] This application provides a third core network device, including:

[0031] The fifth communication unit is used to send an access credential to the first access network device, wherein the access credential is used to verify whether the first access network device is allowed to access the first core network device.

[0032] This application provides a first access network device, including:

[0033] The third communication unit is used to receive access credentials from the third core network device, wherein the access credentials are used to verify whether the first access network device is allowed to access the first core network device.

[0034] This application provides a fourth core network device, including:

[0035] The sixth communication unit is used to receive a request to obtain the terminal code and to send the access code of the terminal.

[0036] By adopting the above scheme, a key derived from the terminal's access code is generated between the terminal and the first core network device to protect messages between them. In this way, when the terminal accesses the first core network device, the key derived from the terminal's access code can be used to protect messages between the two parties, thereby ensuring the security of their communication. Attached Figure Description

[0037] Figure 1 is a schematic diagram of an application scenario according to an embodiment of this application.

[0038] Figure 2 is a schematic flowchart of an information processing method according to an embodiment of this application.

[0039] Figure 3 is a schematic flowchart of an information processing method according to another embodiment of this application.

[0040] Figure 4 is a schematic flowchart of an information processing method according to another embodiment of this application.

[0041] Figure 5 is a schematic flowchart of an information processing method according to another embodiment of this application.

[0042] Figure 6 is a schematic flowchart of an information processing method according to another embodiment of the present application.

[0043] Figure 7 is a schematic flowchart of an information processing method according to another embodiment of the present application.

[0044] Figure 8 is a schematic flowchart of an information processing method according to another embodiment of this application.

[0045] Figure 9 is a schematic flowchart of NSP registration, allocation of access credentials to the base station, and service request of the base station according to an embodiment of this application.

[0046] Figures 10 to 12 are various schematic flowcharts of the authentication and key generation process of a UE according to an embodiment of this application.

[0047] Figure 13 is a schematic flowchart of the service request process and key generation of a base station according to an embodiment of this application.

[0048] Figure 14 is a schematic flowchart of NSP registration and base station obtaining access credentials according to an embodiment of this application.

[0049] Figure 15 is a schematic flowchart of key generation after UE authentication according to an embodiment of this application.

[0050] Figure 16 is a schematic flowchart illustrating the process of a first core network device registering with the NRF, requesting an access code for the UE from the UDM, the NRF allocating an access token to the base station, and the first core network device requesting an access code for the UE from the UDM, according to an embodiment of this application.

[0051] Figures 17 and 18 are two schematic flowcharts of a key generation process according to an embodiment of this application.

[0052] Figure 19 is a schematic block diagram of a terminal according to an embodiment of this application.

[0053] Figure 20 is a schematic block diagram of a first core network device according to an embodiment of the present application.

[0054] Figure 21 is a schematic block diagram of a first access network device according to an embodiment of the present application.

[0055] Figure 22 is a schematic block diagram of a second core network device according to an embodiment of the present application.

[0056] Figure 23 is a schematic block diagram of a third core network device according to an embodiment of the present application.

[0057] Figure 24 is a schematic block diagram of a fourth core network device according to an embodiment of the present application. Detailed Implementation

[0058] The technical solutions of this application can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.

[0059] This application describes various embodiments in conjunction with network devices and terminals. The terminal can be mobile or fixed, and may also be referred to as a mobile station, user unit, etc. The terminal can be a station in a WLAN, or a smart terminal, wireless modem, laptop, tablet, etc. In this application's embodiments, the terminal can be a VR / AR terminal, industrial control terminal, autonomous driving terminal, telemedicine terminal, smart grid terminal, transportation safety terminal, smart city terminal, or smart home wireless terminal, etc. By way of example and not limitation, in this application's embodiments, the terminal can also be a wearable device.

[0060] In this embodiment, the network device can be a device for communicating with a terminal. The network device can be an access point in a WLAN, an evolved base station in LTE, a relay station, a network device (gNB) in a vehicle-mounted device, wearable device, or NR network, or a network device in a future PLMN network, or a network device in a non-terrestrial network, etc. As an example and not a limitation, in this embodiment, the network device can have mobility characteristics; for example, the network device can be a mobile device.

[0061] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.

[0062] Figure 1 exemplarily illustrates a communication system 100. The communication system includes network devices 110 and terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and each network device 110 may include at least one terminal 120 within its coverage area; this embodiment does not limit this. In another possible implementation, the communication system 100 may also include other network entities such as mobility management entities and access and mobility management functions; this embodiment does not limit this. The communication system may also include multiple core networks for communicating with access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities; this embodiment does not limit this.

[0063] Figure 2 is a schematic flowchart of an information processing method executed by a terminal according to an embodiment of this application. The method includes at least a portion of the following.

[0064] S210, Access code of the receiving terminal;

[0065] S220. Based on the access code of the terminal, generate a first key, wherein the first key is used to protect messages between the terminal and the first core network device.

[0066] Figure 3 is a schematic flowchart of an information processing method performed by a first core network device according to an embodiment of this application. The method includes at least some of the following.

[0067] S310. Obtain a first key, wherein the first key is generated based on the terminal's access code and is used to protect messages between the terminal and the first core network device.

[0068] Figure 4 is a schematic flowchart of an information processing method performed by a first access network device according to an embodiment of this application. The method includes at least some of the following.

[0069] S410. Sending the terminal's access code, wherein the terminal's access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

[0070] Figure 5 is a schematic flowchart of an information processing method performed by a second core network device according to an embodiment of this application. The method includes at least some of the following.

[0071] S510. Sending the terminal's access code, wherein the terminal's access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

[0072] Figure 6 is a schematic flowchart of an information processing method performed by a third core network device according to an embodiment of this application. The method includes at least some of the following.

[0073] S610. Send an access credential to the first access network device, wherein the access credential is used to verify whether the first access network device is allowed to access the first core network device.

[0074] Figure 7 is a schematic flowchart of an information processing method performed by a first access network device according to an embodiment of this application. The method includes at least some of the following.

[0075] S710. Receive an access credential from a third core network device, wherein the access credential is used to verify whether the first access network device is allowed to access the first core network device.

[0076] Figure 8 is a schematic flowchart of an information processing method performed by a fourth core network device according to an embodiment of this application. The method includes at least some of the following.

[0077] S810, Receive a request to obtain the terminal code;

[0078] S820, Send the access code of the terminal.

[0079] The first core network device is any core network element capable of providing services. This first core network device can be replaced by a Network Function (NF) or a Network Service Provider (NSP).

[0080] For example, the first core network device may include at least one of the following: SMF (Session Management Function), NWDAF (Network Data Analytics Function), PCF (Policy Control Function), AIoT (Ambient Powered-enabled IoT) NF, SF (Sensing Function), etc. This is merely an illustrative example; in actual processing, the first core network device may include, but is not limited to, the above types of core network elements. This is not a limitation or an exhaustive list.

[0081] The second core network device includes at least one of the following: AUSF (Authentication Server Function), SEAF (Security Anchor Function), AMF, and key generation network element. This is only an illustrative example; in actual processing, the second core network device may include, but is not limited to, the above types of core network elements. The first core network device and the second core network device may be the same or different; this is not a limitation or an exhaustive list.

[0082] Third-party core network devices can be used for NF service registration and discovery. For example, a third-party core network device can be an NRF (Network Repository Function), etc. It should be noted that this is merely an illustrative example, and third-party core network devices may include, but are not limited to, the above types of core network elements; this is not a limitation or an exhaustive list.

[0083] The fourth core network device can be a UDM (Unified Data Management). The fourth core network device can be different from the first, second, and third core network devices; or, the fourth core network device can be co-located with the first core network device.

[0084] In some possible implementations, the processing of the first core network device may include: sending the security access policy of the first core network device to the third core network device. The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device. The processing of the third core network device may include: receiving the security access policy of the first core network device.

[0085] Security access policies can also be called security control policies, security access control policies, access control policies, or access policies, etc. This document does not limit or exhaustively list all possible names for security access policies. The method for generating security access policies for the first core network device is not limited in this embodiment.

[0086] Specifically, the first core network device sending its security access policy to the third core network device can include sending a registration request to the third core network device, wherein the registration request carries the first core network device's security access policy. The registration request can be an Nnrf_NFManagement_NFRegister Request. It should be noted that the registration request from the first core network device can carry other content besides its security access policy, such as content specified in relevant protocols, additional scope, etc., which will not be limited or exhaustively listed here.

[0087] Accordingly, the third core network device receiving the security access policy of the first core network device may include: receiving a registration request from the first core network device, and extracting the security access policy of the first core network device from the registration request. Furthermore, after extracting the security access policy of the first core network device, the third core network device may save the security access policy of the first core network device.

[0088] Optionally, the security access policy of the first core network device can be included in the configuration file or description file (e.g., profile) of the first core network device. The registration request of the first core network device can carry the profile of the first core network device, which includes the security access policy. Correspondingly, the third core network device can store the profile of the first core network device. Optionally, the security access policy of the first core network device can be sent separately. Correspondingly, the third core network device can store the security access policy of the first core network device in the profile of the first core network device.

[0089] After the third core network device stores the security access policy of the first core network device, it may further include: sending a registration response from the first core network device to the first core network device, which indicates whether the first core network device has successfully registered. Correspondingly, the processing of the first core network device may also include: receiving a registration response from the third core network device. For example, the registration response may be an Nnrf_NFManagement_NFRegister Response.

[0090] Here, if the third core network device determines that the first core network device has successfully registered, the registration response of the first core network device can include "Success" to indicate that the first core network device has successfully registered; otherwise, the registration response of the first core network device can include "Failure" to indicate that the first core network device has failed to register. This embodiment does not limit the method by which the third core network device determines whether the first core network device has successfully registered.

[0091] It should be noted that each core network element that can provide services on the core network side can perform the same processing as the first core network device. Finally, the third core network device can store the security access policy of each core network element, which will not be elaborated here.

[0092] Here, "access network side equipment" refers to all devices on the access network side in general. In the following text, when specifically referring to a particular access network device connected to the terminal (or a particular access network device of the management terminal), the access network device connected to the terminal will be referred to as the first access network device. Otherwise, if not specifically referring to the first access network device, but only describing devices on the access network side, it is used to refer to any device on the access network side or all devices on the access network side in general, and will not be explained again in the following text.

[0093] In one example, the security access policy of the first core network device is granular at the level of service or data type.

[0094] Whether to allow the access network side device to access the first core network device includes at least one of the following: whether to allow the access network side device to access at least one service of the first core network device, and whether to allow the access network side device to access one or more data types of at least one service of the first core network device.

[0095] The security access policy of the first core network device includes at least one pre-configured access code of the first core network device. In this example, the at least one pre-configured access code of the first core network device includes at least one of the following: a pre-configured access code corresponding to each of the at least one services that the first core network device allows access to devices on the access network side; and a pre-configured access code corresponding to one or more data types under each of the at least one services that the first core network device allows access to devices on the access network side. The pre-configured access code may also be called a security access code, a security code, a security access policy code, a preset access code, an optional access code, a candidate access code, etc., and not all possible names are limited or exhaustively listed here.

[0096] Optionally, the security access policy of the first core network device is at the service level. The security access policy of the first core network device may include: an indication that allows devices on the access network side to access at least one service of the first core network device, and a pre-configured access code corresponding to each of the at least one service that the first core network device allows devices on the access network side to access.

[0097] An indication allowing access network-side devices to access at least one service of the first core network device may include: an identifier for each of the at least one services that the first core network device allows access network-side devices to access. That is, if the security access policy of the first core network device includes the identifier of a certain service, it is used to indicate that access network-side devices are allowed to access that service of the first core network device; if the security access policy of the first core network device does not include the identifier of a certain service, it is used to implicitly indicate that access network-side devices are not allowed to access that service of the first core network device.

[0098] The first core network device allows access to at least one service from devices on the access network side, which may be at least a portion of all services supported by the first core network device. In the at least one service allowed access to the access network side by the first core network device, the pre-configured access code corresponding to each service may correspond to or be associated with the service identifier. The pre-configured access codes corresponding to different services in the at least one service allowed access to the access network side by the first core network device may be the same or different.

[0099] Optionally, the security access policy of the first core network device is granular at the data type level. The security access policy of the first core network device may include: an indication that allows devices on the access network side to access at least one service of the first core network device; an indication of one or more data types allowed in each service of the first core network device; and a pre-configured access code corresponding to each data type among the one or more data types allowed in each of the at least one service of the first core network device that allows devices on the access network side to access.

[0100] The indication of at least one data type allowed for access in each service may include: an identifier for each data type among the at least one data type allowed for access network devices in each service. Each service that the first core network device allows access network devices to access may include multiple data types, and the at least one data type allowed for access under a particular service of the first core network device may be at least one of all data types under that service. The identifier of the data type may also be replaced by the name of the data type, and / or the number of the data type, etc. For example, if the security access policy of the first core network device includes an identifier for a service and an identifier for a data type under that service, it indicates that access network devices are allowed to access that service of the first core network device and that data type under that service is allowed; if the security access policy of the first core network device includes an identifier for a service but does not include an identifier for a data type under that service, it implicitly indicates that access network devices are not allowed to access that data type under that service of the first core network device.

[0101] The pre-configured access code corresponding to each allowed data type under each service in at least one service that the first core network device allows access network devices to access may correspond to or be associated with the identifier of that data type. The pre-configured access codes corresponding to different allowed data types of any service may be the same or different.

[0102] In one example, the security access policy of the first core network device is implemented at the device level.

[0103] At least one pre-configured access code of the first core network device may include only one pre-configured access code of the first core network device.

[0104] The first core network device may support at least one service. A pre-configured access code for the first core network device can be the same pre-configured access code corresponding to all services supported by the first core network device. In other words, all services supported by the first core network device correspond to the same pre-configured access code.

[0105] Optionally, the security access policy of the first core network device may include only one access code of the first core network device. In this case, the security access policy of the first core network device may implicitly indicate that devices on the access network side are allowed to access the first core network device, or implicitly indicate that devices on the access network side are allowed to access various services of the first core network device.

[0106] Optionally, the security access policy of the first core network device includes an access code for the first core network device and an indication of whether to allow devices on the access network side to access the first core network device. The indication of whether to allow devices on the access network side to access the first core network device may include: first indication information for indicating that devices on the access network side are allowed to access the first core network device, or second indication information for indicating that devices on the access network side are not allowed to access the first core network device.

[0107] Specifically, the first indication information can be a first indication field. For example, if the first indication field includes any one of the following, such as "Allow," "Allow Access," or "Enable," it indicates that the device on the access network side is allowed to access the first core network device. Alternatively, the first indication information can be a first indication value, which can be configured according to actual conditions and can be 1 or 0, etc. Here, we do not limit or exhaustively list all possible first indication values. The second indication information can be a second indication field. For example, if the second indication field includes any one of the following, such as "Disallow," "Disallow Access," or "Disable," it indicates that the device on the access network side is not allowed to access the first core network device. Alternatively, the second indication information can be a second indication value, which can be configured according to actual conditions. As long as the second indication value is different from the first indication value, it is within the protection scope of this embodiment. Here, we do not limit all possible second indication values. It should be understood that this is only an illustrative example, and this embodiment does not limit or exhaustively list the content of the indication regarding whether the device on the access network side is allowed to access the first core network device.

[0108] In one scenario, the security access policy of the first core network device includes a pre-configured access code for the first core network device and first indication information for indicating whether devices on the access network side are allowed to access the first core network device.

[0109] In one scenario, the security access policy of the first core network device includes a pre-configured access code for the first core network device and a second indication message for indicating that devices on the access network side are not allowed to access the first core network device.

[0110] Optionally, the security access policy of the first core network device may only include second indication information to indicate that devices on the access network side are not allowed to access the first core network device. In this case, the security access policy of the first core network device may not include pre-configured access codes.

[0111] In some possible implementations, after the third core network device stores the security access policy of the first core network device, the first access network device can obtain access credentials from the third core network device. The first access network device may be the access network device currently accessed by the terminal.

[0112] The processing of the first access network device may include: sending a credential acquisition request to the third core network device, wherein the credential acquisition request is used to acquire an access credential. Correspondingly, the processing of the third core network device may include: receiving a credential acquisition request from the first access network device, wherein the credential acquisition request is used to acquire the access credential. For example, this credential acquisition request may be represented as Nnrf_AccessToken_Get Request.

[0113] The trigger for the first access network device to send a credential acquisition request to the third core network device can be that the first access network device receives a request message from a terminal. This request message can be any type of AS (Access Stratum) message. For example, the terminal's request message can be an RRC (Radio Resource Control) message; such as a terminal registration request, authentication request, access request, or access authentication request carried in an RRC message.

[0114] The credential acquisition request may carry at least one of the following: identification information of the first core network device, type of the first core network device, type of the first access network device, identifier of the first access network device, identifier of the first service, and identifier of the terminal. The identification information of the first core network device may include at least one of the identifier of the first core network device, name of the first core network device, etc. The identifier of the first service may include at least one of the ID of the first service, name of the first service, etc.

[0115] It should be noted that the above is merely an exemplary description of the content that a credential retrieval request may carry. In actual processing, the credential retrieval request may also carry other content, such as at least one of the following: the type of the first service, the identifier of the first data type, etc. The first data type can be any data type under the first service. The identifier of the first data type may also be replaced by the name of the first data type and / or the number of the first data type, etc., as long as it can uniquely indicate the first data type, it is within the protection scope of this embodiment.

[0116] The processing after the third core network device receives the credential acquisition request also includes: sending the access credential to the first access network device. Correspondingly, the processing of the first access network device may include: receiving the access credential from the third core network device.

[0117] The access credential includes at least one of the following: the access token, the terminal's access code, and the access code of the first core network device. The access token is generated based on the terminal's access code and / or the access code of the first core network device.

[0118] In this embodiment, the access token can be generated based on the access code of the first core network device. The access credential includes at least one of the following: the access token, and the access code of the first core network device.

[0119] The processing by the third core network device after receiving the credential acquisition request further includes: determining, based on the security access policy of the first core network device, whether to authorize the first access network device to access the first core network device. The processing by the third core network device also includes: if it determines that the first access network device is authorized to access the first core network device, generating an access token based on the access code of the first core network device and sending the access credential to the first access network device. Additionally, the processing by the third core network device may also include: if it determines that the first access network device is not authorized to access the first service of the first core network device, sending an authorization failure notification to the first access network device.

[0120] In this embodiment, the access token corresponds to a first core network device; the access code of the first core network device may correspond to the first core network device. Alternatively, the access token corresponds to a first service; the access code of the first core network device corresponds to the first service. Alternatively, the access token corresponds to a first data type of the first service; the access code of the first core network device corresponds to the first data type of the first service.

[0121] In one example, the security access policy of the first core network device is implemented at the device level.

[0122] In this example, the credential acquisition request may include at least one of the following: the identification information of the first core network device and the type of the first core network device; furthermore, the credential acquisition request may also include at least one of the type of the first access network device and the identifier of the first access network device. The credential acquisition request may or may not include the identifier of the first service, the identifier of the terminal, etc.

[0123] Based on the security access policy of the first core network device, determining whether to authorize the first access network device to access the first core network device may include one of the following: if the security access policy of the first core network device only includes a pre-configured access code of the first core network device, determine that the first access network device is authorized to access the first core network device; if the security access policy of the first core network device includes an indication that allows the access network device to access the first core network device, determine that the first access network device is authorized to access the first core network device; if the security access policy of the first core network device includes an indication that does not allow the access network device to access the first core network device, determine that the first access network device is not authorized to access the first core network device.

[0124] The method by which the third core network device determines the access code of the first core network device may include: if the security access policy of the first core network device includes a pre-configured access code of the first core network device, then using the pre-configured access code as the access code of the first core network device.

[0125] For example, the process of generating an access token based on the access code of the first core network device can be as follows: An access token is generated based on the private key of the third core network device and the access code of the first core network device. The specific calculation or processing method for generating the access token is not limited in this embodiment. It should also be noted that this is merely an illustrative description of how to generate an access token; other methods may be used in actual processing, which are not limited or exhaustively listed here.

[0126] In one example, the security access policy of the first core network device is at the service level. In this example, the access token corresponds to the first service; the access code of the first core network device corresponds to the first service.

[0127] In this example, the credential acquisition request may include the identifier of the first service; and the credential acquisition request may also include at least one of the following: the identification information of the first core network device and the type of the first core network device; furthermore, the credential acquisition request may also include at least one of the type of the first access network device and the identifier of the first access network device.

[0128] Based on the security access policy of the first core network device, determining whether to authorize the first access network device to access the first core network device may include one of the following: if the identifier of the first service matches any one of the identifiers of at least one service allowed to be accessed by the access network device in the security access policy of the first core network device, then authorize the first access network device to access the first service of the first core network device; if the identifier of the first service does not match any of the identifiers of at least one service allowed to be accessed by the access network device in the security access policy of the first core network device, then disauthorize the first access network device to access the first service of the first core network device; if the identifier of the first service matches any one of the identifiers of at least one service not allowed to be accessed by the access network device in the security access policy of the first core network device, then disauthorize the first access network device to access the first service of the first core network device.

[0129] The method by which the third core network device determines the access code of the first core network device may include: obtaining the access code corresponding to the first service of the first core network device from the security access policy of the first core network device, and using the access code corresponding to the first service as the access code of the first core network device. The relevant explanation regarding the generation of the access token based on the access code of the first core network device is the same as in the previous example and will not be repeated here.

[0130] In one example, the security access policy of the first core network device is granular at the data type level. In this example, the access token corresponds to the first data type of the first service; the access code of the first core network device corresponds to the first data type of the first service.

[0131] In this example, the credential acquisition request may include the identifier of the first service and the identifier of the first data type; furthermore, the credential acquisition request may also include at least one of the following: the identification information of the first core network device and the type of the first core network device; and even further, the credential acquisition request may also include at least one of the following: the type of the first access network device and the identifier of the first access network device.

[0132] Based on the security access policy of the first core network device, determining whether to authorize the first access network device to access the first core network device may include one of the following: if the identifier of the first service matches any one of the identifiers of at least one service allowed for access by the access network side device included in the security access policy of the first core network device, and if the identifier of the first data type matches any one of the identifiers of one or more data types under the first service allowed for access by the access network side device included in the security access policy of the first core network device, then the first data type of the first service of the first service of the first core network device is authorized to be accessed; if the identifier of the first service does not match any of the identifiers of at least one service allowed for access by the access network side device included in the security access policy of the first core network device, and / or if the identifier of the first data type does not match any of the identifiers of one or more data types under the first service allowed for access by the access network side device included in the security access policy of the first core network device, then the first data type of the first service of the first service of the first core network device is not authorized to be accessed.

[0133] The method by which the third core network device determines the access code of the first core network device may include: obtaining the pre-configured access code corresponding to the first data type of the first service of the first core network device from the security access policy of the first core network device, and using the pre-configured access code corresponding to the first data type of the first service as the access code of the first core network device. The relevant explanation regarding the generation of the access token based on the access code of the first core network device is the same as in the previous example and will not be repeated here.

[0134] In some embodiments, during the terminal authentication process, the first access network device requests access to the first core network device and the first core network device verifies whether access is allowed for the first access network device.

[0135] The terminal's processing may include sending an authentication request to the first access network device. The first access network device's processing may include receiving the authentication request from the terminal. The content that the terminal's authentication request may carry is not limited in this embodiment. The terminal's authentication request may also be replaced by a terminal access request, or a terminal access authentication request, etc., and is not limited here.

[0136] After receiving an authentication request from a terminal, the first access network device may perform the following processing: sending a service request to a first core network device, wherein the service request carries the access credential; and receiving a service response from the first core network device, wherein the service response indicates whether access to the first core network device is permitted. The processing of the first core network device may include: receiving a service request from the first access network device, wherein the service request carries an access credential; and sending a service response to the first access network device, wherein the service response indicates whether access to the first core network device is permitted.

[0137] The triggering condition or prerequisite for the first access network device to send a service request to the first core network device may be that the first access network device receives an authentication request from the terminal and obtains access credentials. This service request may also be called a service request, an NF service request, or a first core network device service request, etc., and we will not limit or exhaust all possible names for this service request here.

[0138] It should be noted that before the first access network device sends a credential acquisition request to the third core network device, the first access network device will receive a request message from the terminal. In one scenario, the terminal's request message is a registration request. In this case, after the first access network device obtains the access credentials, it sends a service request to the first core network device upon receiving the terminal's authentication request. In another scenario, the terminal's request message is an authentication request. In this case, after the first access network device obtains the access credentials, it can directly send a service request to the first core network device.

[0139] The description of this access credential is the same as that in the aforementioned embodiments, and will not be repeated.

[0140] After the first core network device receives a service request from the first access network device and before sending a service response to the first access network device, it may further include at least one of the following: verifying the access token; verifying the access code of the terminal; verifying the access code of the first core network device.

[0141] Alternatively, if the access credentials consist only of an access token, the first core network device may only verify the access token.

[0142] The verification of the access token by the first core network device is related to how the third core network device specifically generates the access token. For example, if the access token is generated based on the private key of the third core network device and the access code of the first core network device, then the first core network device can verify the access token based on the public key of the third core network device and the access code of the first core network device. The specific calculation or processing method for verifying the access token is not limited in this embodiment. This is merely an illustrative description of generating and verifying the access token; in actual processing, other methods may be used to generate and verify the access token, which are not limited or exhaustively described here.

[0143] If the access token is successfully verified by the first core network device, a service response indicating that access to the first core network device is permitted can be generated; otherwise, a service response indicating that access to the first core network device is not permitted can be generated.

[0144] Optionally, if the access credentials include an access token and an access code of the first core network device, then the first core network device verifies the access token and the access code of the first core network device.

[0145] The first core network device verifies the access token in the same way as in the previous example, and will not be described again.

[0146] The verification of the access code of the first core network device may include at least one of the following: if the access code of the first core network device is included in the security access policy, the verification of the access code of the first core network device is determined to be successful; if the access code of the first core network device is not included in the security access policy, the verification of the access code of the first core network device is determined to be unsuccessful.

[0147] If the first core network device successfully verifies the access token and successfully verifies the access code of the first core network device, the first core network device generates a service response indicating that access to the first core network device is permitted; if the first core network device fails to verify the access token and / or fails to verify the access code of the first core network device, it generates a service response indicating that access to the first core network device is not permitted.

[0148] Optionally, if the access credentials include an access token, the terminal's access code, and the access code of the first core network device, then the first core network device needs to verify the access token and the access code of the first core network device. The method by which the first core network device verifies the access token and the access code of the first core network device is the same as in the previous example and will not be repeated here.

[0149] The first core network equipment may not perform the processing of the access code for the authentication terminal.

[0150] Alternatively, the first core network device can verify the terminal's access code. For example, the first core network device can verify the terminal's access code by requesting the fourth core network device to verify it. If it receives a notification that the fourth core network device has successfully verified the terminal's access code, it determines that the terminal's access code verification was successful; if it receives a notification that the fourth core network device has failed to verify the terminal's access code, it determines that the terminal's access code verification failed. This embodiment does not limit the method by which the fourth core network device verifies the terminal's access code.

[0151] If the first core network device successfully verifies the access token and the access code of the first core network device, the first core network device may generate a service response indicating that access to the first core network device is permitted; or, if the first core network device successfully verifies the access token, the access code of the first core network device, and the access code of the terminal, the first core network device may generate a service response indicating that access to the first core network device is permitted; or, if at least one of the following occurs: the first core network device fails to verify the access token, fails to verify the access code of the first core network device, or fails to verify the access code of the terminal, the first core network device may generate a service response indicating that access to the first core network device is not permitted.

[0152] In some embodiments, during the terminal authentication process, the terminal derives a first key, and the first core network device obtains the first key.

[0153] Upon receiving a service response from a first core network device indicating permission to access the first core network device, the first access network device sends a terminal authentication request to the second core network device via the fifth core network device. The second core network device receives the terminal authentication request sent by the first access network device via the fifth core network device.

[0154] The processing of the second core network device after receiving the authentication request from the terminal also includes at least one of the following: sending an encoding acquisition request to the first core network device; sending a request to the fourth core network device to acquire the terminal encoding.

[0155] In one embodiment, the processing after the second core network device receives the authentication request from the terminal includes: sending a request to the fourth core network device to obtain the terminal code.

[0156] The processing of the fourth core network device further includes: receiving a request to obtain a terminal code, and sending the access code of the terminal. Specifically, the fourth core network device receives a request to obtain a terminal code from the second core network device and sends the access code of the terminal to the second core network device. After the second core network device sends the request to obtain the terminal code to the fourth core network device, the processing further includes: receiving the access code of the terminal. Specifically, the second core network device receives the access code of the terminal from the fourth core network device.

[0157] The access code of the terminal is determined based on the terminal's policy, which is used to verify whether the terminal can connect to the first core network device through the first access network device.

[0158] The request to obtain the terminal code may carry at least one of the following: the terminal identifier, the identifier of the first access network device, the identifier of the first service, the identifier of the first data type, etc. This embodiment does not limit the method of generating the request to obtain the terminal code. For example, the terminal authentication request may carry at least one of the following: the terminal identifier, the identifier of the first service, the identifier of the first access network device, the identifier of the first data type, etc. The second core network device may directly generate the request to obtain the terminal code based on the terminal authentication request. For example, the second core network device may determine at least one of the following based on the terminal authentication request: the terminal identifier, the identifier of the first service, the identifier of the first access network device, the first data type, etc., based on pre-configured rules or methods. Here, the method by which the second core network device generates the request to obtain the terminal code, or the possible content included in the request to obtain the terminal code, is not limited or exhaustively listed.

[0159] The processing before the fourth core network device sends the terminal's access code may include: verifying whether the terminal can connect to the first core network device through the first access network device based on the terminal's policy. Further, if it is determined that the terminal can connect to the first core network device through the first access network device, the processing of the fourth core network device further includes: obtaining the terminal's access code based on the terminal's policy. Additionally, the processing of the fourth core network device may also include: if it is determined that the terminal cannot connect to the first core network device through the first access network device, sending a notification to the second core network device that the terminal cannot connect to the first core network device through the first access network device.

[0160] The terminal's strategy can be obtained locally from the fourth core network device based on the terminal identifier carried in the request to obtain the terminal code. The specific method of obtaining the terminal is not limited in this embodiment.

[0161] The terminal's policy can refer to the terminal's access security policy or the terminal's access security control policy; the terminal's policy can be included in the terminal's subscription data and / or the terminal's user privacy policy. Furthermore, the terminal's policy can be pre-stored in the fourth core network device; this embodiment does not limit the method of generating or obtaining the terminal's policy.

[0162] Optionally, the terminal's policy can be device-level. The terminal's policy can be used to indicate whether the terminal allows, supports, or agrees to connect to core network equipment or core network elements through access network-side equipment. The core network equipment can refer to any core network-side element capable of providing services, such as including the first core network equipment.

[0163] For example, the terminal's policy includes allowing, supporting, or agreeing to connect to core network elements through access network-side devices. Based on the terminal's policy, verifying whether the terminal can connect to the first core network device through the first access network device may include: determining that the terminal can connect to the first core network device through the first access network device based on the terminal's policy including allowing, supporting, or agreeing to connect to core network elements through access network-side devices.

[0164] In one scenario, the terminal's policy may further include a pre-configured code for the terminal. The fourth core network device may directly extract the pre-configured code from the terminal's policy as the terminal's access code. In another scenario, the fourth core network device may generate the terminal's access code based on the terminal's policy using a preset method; however, this preset method is not limited in this embodiment. This is merely an illustrative example, and the fourth core network device may employ other methods to obtain the terminal's access code, which are not limited or exhaustively described here.

[0165] Optionally, the terminal's strategy can be at the service or data type granularity. The terminal's access code corresponds to a first service, or the terminal's access code corresponds to a first data type of the first service.

[0166] In one example, the terminal's policy is at the business level. The terminal's policy can include the policy corresponding to each of one or more services.

[0167] The policy corresponding to each service of the terminal may include at least one of the following: at least one identifier of a first designated service, wherein the first designated service is a service that the terminal allows, supports, or agrees to connect to the core network element through the access network side device; and at least one identifier of a second designated service, wherein the second designated service is a service that the terminal does not allow, does not support, or does not agree to connect to the core network element through the access network side device.

[0168] The fourth core network device verifies, based on the terminal's policy, whether the terminal can connect to the first core network device through the first access network device, which may include one of the following: if the identifier of the first service matches any one of the identifiers of at least one first designated service included in the terminal's policy, the terminal is determined to be able to connect to the first core network device through the first access network device; if the identifier of the first service does not match any of the identifiers of at least one first designated service included in the terminal's policy, the terminal is determined to be unable to connect to the first core network device through the first access network device; if the identifier of the first service matches any one of the identifiers of at least one second designated service included in the terminal's policy, the terminal is determined to be unable to connect to the first core network device through the first access network device; if the identifier of the first service does not match any of the identifiers of at least one second designated service included in the terminal's policy, the terminal is determined to be able to connect to the first core network device through the first access network device.

[0169] When the terminal's strategy is at the service level, the terminal's access code corresponds to the first service.

[0170] In one scenario, the terminal's policy may further include a pre-configured code corresponding to each of the first designated services, wherein the pre-configured codes corresponding to different first designated services may be the same or different. The fourth core network device may directly extract the pre-configured code corresponding to the first service from the terminal's policy as the terminal's access code.

[0171] In one scenario, the fourth core network device may generate the terminal's access code using a preset method, based on the terminal's policy, the identifier of the first service, etc. This embodiment does not limit the scope of this preset method. This is merely an illustrative example; in practice, the fourth core network device may employ other methods to obtain the terminal's access code, which are not limited or exhaustively listed here.

[0172] In one example, the terminal's strategy can be at the data type granularity. The terminal's strategy can include the strategy corresponding to each service within one or more services.

[0173] For example, the policy corresponding to each service of the terminal may include at least one of the following: at least one identifier of a first designated service, at least one first designated data type under each first designated service, each first designated data type being a data type that the terminal allows, supports, or agrees to connect to the core network element through the access network side device; at least one identifier of a second designated service, at least one second designated data type under each second designated service, each second designated data type being a data type that the terminal does not allow, does not support, or does not agree to connect to the core network element through the access network side device.

[0174] The fourth core network device verifies, based on the terminal's policy, whether the terminal can connect to the first core network device through the first access network device. This can include one of the following: if the identifier of the first service matches any one of the identifiers of at least one first specified service included in the terminal's policy, and the first data type matches any one of at least one first specified data type included in the terminal's policy, then the terminal can be determined to be able to connect to the first core network device through the first access network device; if the identifier of the first service does not match any of the identifiers of at least one first specified service included in the terminal's policy, and / or the first data type does not match any of the first specified data types included in the terminal's policy. If the identifier of the first service matches any one of the identifiers of at least one second specified service included in the terminal's policy, and / or the first data type matches any one of the at least one second specified data type included in the terminal's policy, then the terminal is determined to be unable to connect to the first core network device via the first access network device. If the identifier of the first service does not match any of the identifiers of at least one second specified service included in the terminal's policy, and the first data type does not match any of the at least one second specified data type included in the terminal's policy, then the terminal is determined to be able to connect to the first core network device via the first access network device.

[0175] When the terminal's strategy is at the data type granularity, the terminal's access encoding corresponds to the first data type of the first service.

[0176] In one scenario, the terminal's policy may further include a pre-configured code corresponding to each first specified data type under each first specified service within at least one first specified service. The pre-configured codes corresponding to different first specified data types may be the same or different. The fourth core network device can directly extract the pre-configured code corresponding to the first data type of the first service from the terminal's policy as the terminal's access code.

[0177] In one scenario, the fourth core network device may generate the terminal's access code using a preset method, based on the terminal's policy, the identifier of the first service, the identifier of the first data type, etc. This embodiment does not limit the scope of this preset method. This is merely an illustrative example; in actual processing, the fourth core network device may employ other methods to obtain the terminal's access code, which are not limited or exhaustively listed here.

[0178] The processing of the second core network device after receiving the authentication request from the terminal further includes: sending an encoding acquisition request to the first core network device. The processing of the first core network device further includes: receiving the encoding acquisition request from the second core network device.

[0179] The encoding acquisition request may include at least one of the following: the identifier of the first access network device, the type of the first access network device, the identifier of the first service, the identifier of the first data type, etc. Here, the possible contents of the encoding acquisition request are not limited or exhaustively listed.

[0180] After receiving a code acquisition request from the second core network device, the first core network device may include: sending the access code of the first core network device. Specifically, sending the access code of the first core network device includes: the first core network device sending the access code of the first core network device to the second core network device. Here, since the first core network device has already verified the access credentials sent by the first access network device, the access code of the first core network device corresponding to, used, or obtained by the first access network device can be determined based on the identifier and / or type of the first access network device.

[0181] The processing of the second core network device further includes receiving an access code from the first core network device. Specifically, the second core network device receives the access code from the first core network device. The access code of the first core network device is one of at least one pre-configured access codes of the first core network device included in the security access policy of the first core network device, and the security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device. Optionally, the access code of the first core network device corresponds to a first service. Optionally, the access code of the first core network device corresponds to a first data type of the first service. Optionally, the access code of the first core network device may correspond to the first core network device itself.

[0182] This embodiment does not limit the order in which the terminal code acquisition request is sent. For example, the second core network device may first send a code acquisition request to the first core network device, receive the access code of the first core network device, and then send a terminal code acquisition request to the fourth core network device to receive the terminal's access code. Alternatively, the second core network device may send a terminal code acquisition request to the fourth core network device, receive the terminal's access code, and then send a code acquisition request to the first core network device to receive the first core network device's access code.

[0183] In one embodiment, the processing by the second core network device after receiving the authentication request from the terminal includes: sending an encoding acquisition request to the first core network device. The processing by the first core network device further includes: receiving the encoding acquisition request from the second core network device.

[0184] The encoding acquisition request may include at least one of the following: the terminal identifier, the identifier of the first access network device, the type of the first access network device, the identifier of the first service, the first data type, etc. Here, the possible contents of the encoding acquisition request are not limited or exhaustively listed.

[0185] The processing after the first core network device receives the encoding acquisition request may also include: sending a request to the fourth core network device to acquire the terminal encoding.

[0186] The processing of the fourth core network device may include: receiving a request to obtain a terminal code, and sending the access code of the terminal. Specifically, the fourth core network device receives a request to obtain a terminal code from the first core network device, and sends the access code of the terminal to the first core network device. The processing prior to sending the terminal's access code by the fourth core network device is the same as in the aforementioned embodiments and will not be repeated.

[0187] After the first core network device sends a request to the fourth core network device to obtain the terminal code, the process further includes: receiving the access code of the terminal from the fourth core network device. The processing after the first core network device receives the terminal's access code may include: sending the terminal's access code.

[0188] Furthermore, the processing of the first core network device may also include: sending the access code of the first core network device. The processing of the second core network device further includes: receiving the access code of the terminal. The processing of the second core network device may also include: receiving the access code of the first core network device.

[0189] Optionally, the first core network device may send its access code to the second core network device after receiving the code acquisition request. The first core network device may also send the terminal's code to the second core network device after receiving the terminal's access code from the fourth core network device. Correspondingly, after sending the code acquisition request, the second core network device may first receive the access code from the first core network device, and then receive the terminal's access code from the first core network device.

[0190] Optionally, the second core network device can simultaneously receive the access code from the first core network device and the access code from the terminal. In this case, the access code from the first core network device and the access code from the terminal can be carried in the same message; this example does not limit the specific type or name of this message.

[0191] In one embodiment, during the terminal authentication process, the terminal and the second core network device respectively derive a first key, and the first core network device obtains the first key sent by the second core network device.

[0192] The processing after the second core network device receives the terminal's access code (or the terminal's access code and the first core network device's access code) may include: generating a first key based on the terminal's access code; and sending the first key to the first core network device.

[0193] The second core network device generates a first key based on the terminal's access code, which may include generating the first key based on the terminal's access code and at least one of the following: the access code of the first core network device, or a key shared between the terminal and the network device.

[0194] The key calculation method used to generate the first key can be configured according to actual conditions. For example, the key calculation method may include at least one of the following: KDF (Key Derivation Function), first authentication function (such as the f1 function defined in 3GPP), second authentication function (such as the f2 function defined in 3GPP), third key generation function (such as the f3 function defined in 3GPP), fourth key generation function (such as the f4 function defined in 3GPP), fifth key generation function (such as the f5 function defined in 3GPP), hash algorithm, Advanced Encryption Standard (AES), ACSON, SNOW 3G (Snow Third Generation), ZUC (ZUChongzhi), XOR calculation, direct connection calculation. The hash algorithm can be represented as HASH(), which may include HMAC-SHA-256 (Hash based Message Authentication Code - Secure Hash Algorithm-256), or other lightweight hash algorithms (such as SPECK, SIMON, etc.). This embodiment does not exhaustively list them all. It should be understood that this is only an illustrative example, and in actual processing, this key calculation method may include many more possibilities. This embodiment does not exhaustively list all possible calculation functions (or algorithms) for the key calculation method.

[0195] Here, the network device may include one of the following: AUSF, SEAF, AMF, or a first access network device. It should be noted that the network device generally refers to any network element or device that shares a key with the terminal on the network side (core network and / or access network side). The network device may be the same as or different from the second core network device, and the network device may be the same as or different from the first access network device, all of which are within the scope of protection of this embodiment.

[0196] For example, the network device and the second core network device are both AUSF, and the key shared between the terminal and the network device can be K. AUSF The first key can be calculated on the AUSF side using the following formula: K NSP =KDF(K AUSF The terminal's access code, the access code of the first core network device), where K NSP This represents the first key. For example, the second core network device is AUSF, the network device can be SEAF, and the key shared between the terminal and the network device can be K. SEAF The first key can be calculated on the AUSF side using the following formula: K NSP =KDF(K SEAF (Access code of the terminal, access code of the first core network device).

[0197] In this embodiment, the first core network device obtaining the first key includes receiving the first key. Specifically, the first core network device receives the first key from the second core network device.

[0198] In one embodiment, the processing of the second core network device may further include: transmitting the access code of the terminal. Additionally, the processing of the second core network device may further include: transmitting the access code of the first core network device.

[0199] Accordingly, the processing of the terminal receiving the access code may include: receiving the access code from the second core network device. The terminal's processing may also include: receiving the access code from the first core network device. Specifically, the terminal receives the access code from the first core network device via the second core network device.

[0200] Specifically, the second core network device sends the terminal's access code to the terminal through the fifth core network device; the second core network device also sends the access code of the first core network device to the terminal through the fifth core network device. The terminal receives the terminal's access code from the second core network device sent by the fifth core network device; the terminal also receives the access code from the first core network device sent by the second core network device sent by the fifth core network device.

[0201] The second core network device can send the terminal's access code and the first core network device's access code simultaneously. For example, the second core network device can send the terminal's authentication response to the fifth core network device, which carries the terminal's access code and the first core network device's access code. After receiving the terminal's authentication response, the fifth core network device can send an authentication request to the terminal, which can carry both the terminal's access code and the first core network device's access code.

[0202] After the terminal receives the access code of the terminal and the access code of the first core network device, it generates a first key based on the terminal's access code. Specifically, the terminal's generation of the first key based on the terminal's access code may include: generating the first key based on the terminal's access code and at least one of the following: the access code of the first core network device, or a key shared between the terminal and the network device. The specific descriptions regarding the generation or calculation of the first key by the terminal are the same as those regarding the second core network device, and therefore will not be repeated.

[0203] The first key is used to protect messages of the first service between the terminal and the first core network device. Alternatively, the first key is used to protect messages of the first service under a first data type between the terminal and the first core network device, or the first key is used to protect messages between the terminal and the first core network device (or messages under all data types of all services). The granularity of the messages protected by the first key is related to whether the terminal's access code corresponds to the first service or the first data type, and whether the first core network device's access code corresponds to the first service or the first data type.

[0204] Optionally, the terminal's policy can be at the service granularity, and the terminal's access code can correspond to the first service; and / or, the security access policy of the first core network device is at the service granularity, and the access code of the first core network device corresponds to the first service. The first key is used to protect the messages of the first service between the terminal and the first core network device.

[0205] Optionally, the terminal's policy can be data type granular, and the terminal's access code can correspond to the first data type of the first service; and / or, the security access policy of the first core network device is data type granular, and the access code of the first core network device corresponds to the first data type of the first service. The first key is used to protect messages (or data) under the first data type of the first service between the terminal and the first core network device.

[0206] Optionally, if the access code of the terminal and the access code of the first core network device are both device-level, then the first key is used to protect the messages (or all service messages) between the terminal and the first core network device.

[0207] In some possible embodiments, the second core network device may not perform any of the processes such as sending an encoding acquisition request to the first core network device or sending a request to the fourth core network device to acquire the terminal encoding. Instead, the fifth core network device may perform any of these processes. In this embodiment, the second core network device may be SEAF, and the fifth core network device may be AUSF. After receiving the access code from the first core network device and the terminal's access code, the second core network device calculates the first key and performs related processing, similar to the aforementioned embodiments, and therefore will not be described in detail.

[0208] The following example, using Figure 9 as a reference, illustrates the following: the first core network device is NSP, the third core network device is NRF, the first access network device is a base station (which can also be alternatively referred to as NSC (Network Service Customer)), and the terminal is UE.

[0209] Steps 901 to 903 constitute the NSP registration process.

[0210] Step 901: The NSP sends a registration request (e.g., an Nnrf_NFManagement_NFRegister Request) to the NRF, which may carry the NSP's security access policy. This registration request may also carry Additional Scope Info, etc., which are not limited here. The relevant explanations regarding the security access policy are the same as in the previous embodiments and will not be repeated.

[0211] Step 902: The NRF stores the NSP's security access policy. Optionally, the NSP's security access policy may be included in the NSP Profile. In this case, the registration request sent by the NSP may contain the NSP Profile, and the NRF saves the NSP Profile accordingly.

[0212] Step 903: NRF replies to NSP with a registration response (e.g., Nnrf_NFManagement_NFRegister Response). If NSP registration is successful, the registration response can include "Success" to indicate that NSP registration was successful.

[0213] Steps 904 to 907 are the process of NRF authorizing the base station to access the NSP and allocating access credentials to the base station.

[0214] Step 904: The UE sends an RRC message to the base station (NSC). The RRC message may carry the UE's registration request or UE authentication request (or UE's access request or UE's access authentication request).

[0215] Step 905: The base station sends a credential acquisition request (e.g., Nnrf_AccessToken_Get Request) to the NRF. This credential acquisition request may carry at least one of the following: Expected NF Service name(s), NF type, NSP identification information, Consumer NF type, client id, and ID of the first service.

[0216] Step 906: The NRF, based on the NSP's secure access policy, determines whether the base station is authorized to access the NSP (or, as in NRF Check whether the NF Service Consumer is authorized). If authorization is successful, proceed to step 907. Alternatively, if authorization fails, the NRF may terminate the process and / or send an authorization failure notification to the base station.

[0217] Step 907: The NRF generates an access token based on the NSP's access code, and then sends access credentials to the base station. These access credentials may include the access token and / or the NSP's access code. This access credential may be carried by the Nnrf_AccessToken_Get Response (NRF access token acquisition response). The generation of the token and the acquisition of the NSP's access code are the same as in the previous embodiments, and therefore will not be repeated.

[0218] Steps 908 to 910 constitute the service request process for the base station.

[0219] Step 908: The base station sends a service request (i.e., NF Service request, NF service request (or service request)) to the NSP, which carries access credentials.

[0220] It should be noted that if the RRC message sent by the UE in step 904 carries the UE's authentication request (or the UE's access request, or the UE's access authentication request), the base station can directly execute step 908 after completing step 907. If the RRC message sent by the UE in step 904 carries the UE's registration request, the base station also needs to execute step 908 after receiving the UE's authentication request (or the UE's access request, or the UE's access authentication request). The timing of sending the UE's authentication request is not limited in this example, but the base station needs to execute step 908 after receiving the UE's authentication request and completing step 907.

[0221] Step 909: NSP verifies access credentials. For example, NSP can verify the Token in the access credentials and / or verify the NSP's access code. The related processing for verifying the Token in the access credentials and / or verifying the NSP's access code is the same as in the previous embodiments and will not be described again.

[0222] Step 910: The NSP sends a service response (such as NF Service response) to the base station, indicating whether the base station is allowed to access the NSP.

[0223] Based on the process in Figure 9, and in conjunction with Figure 10, taking the first core network device as NSP, the second core network device as AUSF, the fourth core network device as UDM, the first access network device as base station, and the terminal as UE as an example, the authentication and key generation process of UE is explained, with AUSF and UE generating the first key respectively:

[0224] Step 1011: The base station forwards the UE's authentication request to the SEAF. The SEAF can be the fifth core network device described in the previous embodiments.

[0225] It should be noted that step 1011 is executed after step 910 in Figure 9. For the sake of brevity, this example will not elaborate on the processing of steps 901 to 910.

[0226] Step 1012: SEAF forwards the UE's authentication request to AUSF.

[0227] Step 1013: AUSF sends a request to UDM to obtain the UE code. The request to obtain the UE code is used to request the UE's access code.

[0228] Step 1014: UDM sends the UE's access code to AUSF.

[0229] Before the UDM sends the UE's terminal access code to the AUSF, the UDM's processing may also include: the UDM checking the UE's policy (such as a user privacy policy) to determine whether the UE can or is capable of connecting to the NSP through the base station. The explanation regarding the UDM's determination of whether the UE can or is capable of connecting to the NSP through the base station is the same as in the aforementioned embodiments and will not be repeated.

[0230] Furthermore, if the UDM determines, based on the UE's policy, that the UE can connect to the core network element NSP (NF service provider) via the base station, then step 1014 is executed to send the UE's access code to the AUSF. Additionally, the process may also include: if the UDM determines, based on the UE's policy, that the UE cannot or is unable to connect to the NSP via the base station, then the processing may end and / or a notification may be sent to the AUSF that the UE cannot connect to the NSP via the base station.

[0231] It should be noted that in step 1013, while the AUSF sends the UE's encoding acquisition request to the UDM, it can also request the AV from the UDM; correspondingly, in step 1014, while the UDM sends the UE's terminal access code to the AUSF, it can also return the UE's AV to the AUSF. This embodiment does not limit the generation or acquisition of the UE's AV and related explanations.

[0232] Step 1015: AUSF sends an encoding retrieval request to NSP. The encoding retrieval request is used to request the access encoding from NSP.

[0233] Step 1016: NSP sends its access code to AUSF.

[0234] The order of steps 1013-1014 and steps 1015-1016 is not limited. For example, you can execute them in the order shown in the example above, or you can execute steps 1015-1016 first, and then execute steps 1013-1014.

[0235] Step 1017, AUSF is based on the UE's access code, the NSP's access code, and the key shared between the UE and the network device (e.g., K). AUSF or K SEAF Generate the first key (e.g., K) NSP Here, if the second core network device is the same as the network device, then the key shared between the UE and the network device is K. AUSF If the second core network device is different from the network device, for example, the network device is SEAF, then the key shared between the UE and the network device is K. SEAF The specific process for generating the first key is the same as in the previous embodiments and will not be repeated here.

[0236] In step 1018, the AUSF sends an authentication response (or UE authentication response) to the SEAF, carrying the UE's access code and the NSP's access code. It should be noted that the authentication response sent by the AUSF to the SEAF may also carry AUTH (authentication information) as specified in the relevant protocol; however, this does not limit or exhaustively list all the possible contents that the authentication response may carry.

[0237] Step 1019: The SEAF sends an authentication request to the UE. This authentication request carries the UE's access code and the NSP's access code. It should be noted that the authentication request sent by the SEAF may also carry the AUTH specified in the relevant protocol. This document does not limit or exhaustively list all the possible contents that the authentication request sent by the SEAF may carry.

[0238] Step 1020: The UE generates a first key based on its access code, the NSP's access code, and the key shared between the UE and the network device. The specific calculation method for the UE to generate the first key is the same as that of AUSF, so it will not be repeated.

[0239] Step 1021: AUSF sends the first key to NSP. It should be understood that the execution of step 1021 is within the scope of this example as long as it occurs after step 1017. Therefore, the execution order of step 1021 and steps 1018 to 1020 is not limited here.

[0240] An alternative example of Figure 10 above: SEAF can act as the second core network device, and AUSF can act as the fifth core network device in the aforementioned embodiments. In this alternative example, steps 1011 to 1016 in Figure 10 remain unchanged, step 1017 is replaced by AUSF sending an authentication response to SEAF, the authentication response carrying the UE's access code and NSP's access code; step 1018 is replaced by SEAF based on the UE's access code, NSP's access code, and a key shared between the UE and the network device (e.g., K). SEAF Generate the first key. Steps 1019 to 1020 remain unchanged. Step 1021 is replaced by SEAF sending the first key to NSP.

[0241] Based on the process in Figure 9, and in conjunction with Figure 11, taking the first core network device as NSP, the second core network device as AUSF, the fourth core network device as UDM, the first access network device as base station, and the terminal as UE as an example, the authentication and key generation process of UE is explained, with AUSF and UE generating the first key respectively:

[0242] The processing steps 1111 to 1112 are the same as those shown in Figure 10, and will not be described again.

[0243] Step 1113: AUSF sends an encoding retrieval request to NSP.

[0244] Step 1114: NSP sends its access code to AUSF.

[0245] Step 1115: NSP sends a request to UDM to obtain the UE code.

[0246] Step 1116: UDM sends the UE's access code to NSP.

[0247] Here, before the UDM sends the UE's access code to the AUSF, the UDM's processing may further include: the UDM checking the UE's policy to determine whether the UE can or is capable of connecting to the NSP through the base station. The explanation regarding the UDM's determination of whether the UE can or is capable of connecting to the NSP through the base station is the same as in the previous embodiments and will not be repeated. Further, if the UDM determines, based on the UE's policy, that the UE can connect to the core network element NSP (NF service provider) through the base station, then step 1116 is executed to send the UE's terminal access code to the NSP. Additionally, it may also include: if the UDM determines, based on the UE's policy, that the UE cannot or is not capable of connecting to the NSP through the base station, then the processing may end and / or a notification may be sent to the NSP that the UE cannot connect to the NSP through the base station.

[0248] Step 1117: The NSP sends the UE's access code to the AUSF. It should be noted that in some possible examples, the NSP may not perform step 1114. In such examples, step 1117 is replaced by the NSP sending the UE's access code and the NSP's access code to the AUSF.

[0249] The processing of steps 1118 to 1122 is the same as that of steps 1017 to 1021 in the example corresponding to Figure 10 above, and will not be repeated.

[0250] An alternative example of Figure 11 above: SEAF can act as a second core network device, and AUSF can be replaced by the fifth core network device in the aforementioned embodiment. In this alternative example, steps 1111 to 1117 in Figure 11 remain unchanged, step 1118 is replaced by AUSF sending an authentication response to SEAF, the authentication response carrying the UE's access code and NSP's access code; step 1119 is replaced by SEAF based on the UE's access code, NSP's access code, and a key shared between the UE and the network device (e.g., K). SEAF Generate the first key. Steps 1120 and 1121 remain unchanged. Step 1122 is replaced by SEAF sending the first key to NSP.

[0251] In another embodiment, during the terminal authentication process, the terminal and the first core network device respectively derive a first key.

[0252] The processing of the second core network device after receiving the authentication request from the terminal includes: sending an encoding acquisition request to the first core network device. The processing of the first core network device further includes: receiving the encoding acquisition request from the second core network device. The relevant description of this encoding acquisition request is the same as in the aforementioned embodiments and will not be repeated.

[0253] Unlike the previous embodiments, the processing of the second core network device after receiving the authentication request from the terminal further includes: sending the key shared between the terminal and the network device to the first core network device. The processing of the first core network device may further include: receiving the key shared between the terminal and the network device. Specifically, the first core network device receives the key shared between the terminal and the network device from the second core network device.

[0254] In this process, the second core network device can send the key shared between the terminal and the network device and send an encoding acquisition request simultaneously. For example, the encoding acquisition request can carry the key shared between the terminal and the network device, or the encoding acquisition request and the key shared between the terminal and the network device can be carried in the same message, etc. The methods by which the second core network device sends the key shared between the terminal and the network device and the encoding acquisition request are not limited or exhaustively listed here.

[0255] The processing by the first core network device after receiving the encoding acquisition request and the key shared between the terminal and the network device may also include: sending a request to the fourth core network device to acquire the terminal encoding.

[0256] The processing of the fourth core network device may include: receiving a request to obtain a terminal code, and sending the access code of the terminal. Specifically, the fourth core network device receives a request to obtain a terminal code from the first core network device, and sends the access code of the terminal to the first core network device. The processing of the fourth core network device before sending the terminal's access code to the first core network device is the same as in the previous embodiments, and therefore will not be repeated.

[0257] After the first core network device sends a request to the fourth core network device to obtain the terminal code, it also includes: receiving the access code of the terminal from the fourth core network device.

[0258] Obtaining the first key on the first core network device side includes: generating the first key based on the access code of the terminal.

[0259] Specifically, the process by which the first core network device generates the first key based on the terminal's access code may include: generating the first key based on the terminal's access code and at least one of the following: the access code of the first core network device, or a key shared between the terminal and the network device. The specific method by which the first core network device generates the first key is similar to the method by which the second core network device generates the first key in the aforementioned embodiments, and will not be elaborated upon further.

[0260] The processing after the first core network device receives the access code from the terminal may include: sending the terminal's access code. Furthermore, the processing of the first core network device may also include: sending the access code of the first core network device. The processing of the second core network device further includes: receiving the access code of the terminal. The processing of the second core network device may also include: receiving the access code of the first core network device. The method by which the first core network device sends its access code and the terminal's access code is the same as in the aforementioned embodiments and will not be repeated here.

[0261] The processing of the second core network device receiving the access code from the terminal of the first core network device, and the processing of the access code from the first core network device, may further include: sending the terminal's access code; and sending the access code from the first core network device. Correspondingly, the processing of the terminal receiving the terminal's access code may include: receiving the terminal's access code from the second core network device. The terminal's processing may further include: receiving the access code from the first core network device. Specifically, the terminal receives the access code from the first core network device from the second core network device.

[0262] The descriptions of the access codes for the second core network device's transmitting terminal and the access codes for the first core network device are the same as those in the aforementioned embodiments and will not be repeated here.

[0263] After the terminal receives the access code of the terminal and the access code of the first core network device, it generates a first key based on the terminal's access code. The specific method by which the terminal generates or calculates the first key should be the same as that of the first core network device, and therefore will not be repeated. In addition, the description of the granularity of the messages protected by the first key under different circumstances is also the same as in the previous embodiments, and will not be elaborated further.

[0264] Based on the process in Figure 9, and in conjunction with Figure 12, taking the first core network device as NSP, the second core network device as AUSF, the fourth core network device as UDM, the first access network device as base station, and the terminal as UE as an example, the authentication and key generation process of UE is explained, with AUSF and UE generating the first key respectively:

[0265] The processing of steps 1211 to 1212 is the same as that of steps 1011 to 1012 shown in Figure 10, and will not be described again.

[0266] Step 1213: The AUSF sends an encoding retrieval request to the NSP. The encoding retrieval request may carry a key shared between the UE and the network device (e.g., K). AUSF or K SEAF ).

[0267] Steps 1214 to 1216 are the same as steps 1114 to 1116 shown in Figure 11, and will not be described again.

[0268] Step 1217: The NSP is based on the UE's access code, the NSP's access code, and the key shared between the UE and the network device (e.g., K). AUSF or K SEAF Generate the first key (e.g., K) NSP The specific process for generating the first key is the same as in the aforementioned embodiments and will not be repeated here.

[0269] Step 1218: NSP sends the UE's access code to AUSF.

[0270] It should be noted that the execution order of steps 1213-1218 may differ from this example. For instance, after executing step 1213, steps 1215 and 1216 can be executed, and then the NSP can execute step 1217 to generate the first key. After completing step 1217, steps 1214 and 1218 can be executed. Alternatively, steps 1213-1216 can be executed in the above order, followed by step 1218, and then the NSP can execute step 1217 to generate the first key.

[0271] It should also be noted that in some possible examples, the NSP may omit step 1214. In such examples, step 1218 is replaced by the NSP sending the UE's access code and the NSP's access code to the AUSF. In such alternative examples, step 1218 may be performed before or after step 1217; this example does not impose any limitations.

[0272] The processing of steps 1219 to 1221 is the same as that of steps 1018 to 1020 in the example corresponding to Figure 10 above, and will not be repeated.

[0273] In an alternative example of Figure 12 above, the first core network device and the second core network device are the same, both being AUSF. All processes involving NSP execution in Figure 12 can be merged into AUSF. The NSP access code is replaced with the AUSF access code. Steps 1213 and 1214 can be omitted. Step 1217 is replaced with: AUSF based on the UE's access code, the AUSF access code, and a key shared between the UE and the network device (e.g., K).AUSF or K SEAF The first key is generated, and the remaining steps are the same as the example in Figure 12 above, so they will not be repeated here.

[0274] In some embodiments, after terminal authentication, the first access network device requests access to the first core network device, and the first core network device verifies whether access is allowed for the first access network device.

[0275] The first access network device, after the terminal completes authentication, may include: sending a service request to the first core network device, wherein the service request carries the access credential; and receiving a service response from the first core network device, wherein the service response indicates whether access to the first core network device is permitted. The processing of the first core network device may include: receiving a service request from the first access network device, wherein the service request carries the access credential; and sending a service response to the first access network device, wherein the service response indicates whether access to the first core network device is permitted. The relevant description of the access credential is the same as in the aforementioned embodiments and will not be repeated.

[0276] After the first core network device receives a service request from the first access network device and before sending a service response to the first access network device, it may further include at least one of the following: verifying the access token; verifying the terminal's access code; and verifying the access code of the first core network device. The relevant explanations regarding the first core network device's verification of the access credential's contents, and the relevant processing for the first core network device to generate a service response, are the same as in the aforementioned embodiments and will not be repeated.

[0277] In one embodiment, after the terminal completes authentication, the terminal and the second core network device respectively derive a first key, and the first core network device receives the first key from the second core network device.

[0278] If the first core network device determines that the first access network device is allowed to access the first core network device, it may send the access code of the first core network device. Specifically, the first core network device sends the access code of the first core network device to the second core network device.

[0279] The processing of the second core network device may include: receiving the access code from the first core network device.

[0280] The processing after the second core network device receives the access code from the first core network device may further include: sending a request to the fourth core network device to obtain a terminal code. Correspondingly, the fourth core network device may receive the request to obtain a terminal code and send the access code of the terminal. Specifically, the fourth core network device receives the request to obtain a terminal code from the second core network device and sends the terminal's access code to the second core network device. The processing before the fourth core network device sends the terminal's access code is the same as in the aforementioned embodiments and will not be described again.

[0281] The processing by the second core network device after receiving the access code from the terminal may include: generating the first key based on the terminal's access code, and sending the first key to the first core network device. The first core network device may receive the first key from the first core network device. The related processing for generating the first key is the same as in the aforementioned embodiments.

[0282] In this embodiment, the second core network device can be an AMF.

[0283] For example, if the network device and the second core network device are both AMF, the key shared between the terminal and the network device can be one of the following: K AMF K NASint K NASenc Wait. Let K be the key shared between the terminal and the network device. AMF For example, the generation of the first key can be represented as: K NSP =KDF(K AMF The terminal's access code and the access code of the first core network device. The key shared between the terminal and the network device is K. NASint For example, the generation of the first key can be represented as: K NSP =KDF(K NASint (Access code of the terminal, access code of the first core network device).

[0284] For example, the network device is the first access network device, the second core network device can be the AMF, and the key shared between the terminal and the first access network device that can be obtained on the AMF side can be K. gNB The generation of the first key can be represented as: K NSP =KDF(K gNB (Access code of the terminal, access code of the first core network device).

[0285] The processing by the second core network device after receiving the access code from the terminal may further include: sending the terminal's access code. Furthermore, the processing by the second core network device may also include: sending the access code from the first core network device. Specifically, the second core network device sends the terminal's access code to the terminal, and the second core network device also sends the access code from the first core network device to the terminal.

[0286] Accordingly, on the terminal side, receiving the terminal's access code may include: receiving the terminal's access code from the second core network device. The terminal's processing may further include: receiving the access code from the first core network device. Specifically, the terminal receives the terminal's access code from the second core network device, and the terminal also receives the access code from the first core network device, which is also from the second core network device.

[0287] The access codes sent by the second core network device to the terminal and the access codes sent by the first core network device can be executed simultaneously. In this embodiment, the terminal access codes sent by the second core network device to the terminal and the access codes sent by the first core network device can be carried by a NAS Security Mode Command (SMC).

[0288] After the terminal receives the access code from the terminal, the method for generating the first key based on the access code should be the same as that of the second core network device, and therefore will not be repeated.

[0289] In this embodiment, after generating the first key, the terminal can also send a NAS security mode complete message to the second core network device.

[0290] The description of the granularity of the messages protected by the first key is the same as that in the previous embodiments, and will not be repeated.

[0291] Referring to Figure 13, taking the first core network device as NSP, the second core network device as AMF, the fourth core network device as UDM, the first access network device as base station, and the terminal as UE as an example, the service request process of the base station and the key generation after UE authentication are explained:

[0292] Steps 1301 to 1302 constitute the UE's access authentication process.

[0293] Step 1301: The UE sends an RRC message to the base station (NSC), which carries the UE's authentication request.

[0294] Step 1302: At least one of the network elements on the base station and the core network side, such as SEAF, AUSF, and UDM, performs the authentication process. The details of the authentication process are not specified here.

[0295] Steps 1303 to 1306 constitute the service request process for the base station.

[0296] Step 1303: The base station sends a service request (i.e., NF Service request, NF service request (or service request)) to the NSP, which carries access credentials.

[0297] It should be noted that before executing step 1303, the processing of steps 901 to 907 as shown in Figure 9 may have been completed. This example does not limit the specific timing of the execution of steps 901 to 907 in this example. As long as the processing of steps 901 to 907 is completed before step 1303, it is within the protection scope of this embodiment.

[0298] The processing of steps 1304 to 1305 is the same as that of steps 909 to 910 shown in Figure 9 above, and will not be described again.

[0299] Step 1306: NSP sends its access code to AMF.

[0300] Steps 1307 to 1313 are the process of deriving keys in the NAS SMC process.

[0301] Step 1307: AMF sends a request to UEM to obtain the UE code.

[0302] Step 1308: The UDM sends the UE's access code to the AMF. The related processes for the UDM to verify whether the UE can access the NSP through the base station and to obtain the UE's access code are the same as in the previous embodiments and will not be repeated here.

[0303] Step 1309: The AMF uses the UE's access code, the NSP's access code, and the key shared between the UE and the network device (e.g., K). AMF or K gNB Generate the first key (e.g., K) NSP It should be understood that AMF can also receive K from SEAF before performing step 1309. AMF Due to the specific derivation of K AMF The method is not limited in this embodiment, so it is not illustrated in Figure 13 for the sake of simplicity.

[0304] Step 1310: The AMF sends a NAS SMC to the UE, which carries the UE's access code and the NSP's access code.

[0305] Step 1311: The UE uses its access code, the NSP's access code, and the key shared between the UE and the network device (e.g., K). AMF or KgNB Generate the first key (e.g., K) NSP The UE generates the first key in the same way as the AMF, so it will not be explained again.

[0306] Step 1312: The UE sends the NAS security mode completion message to the AMF.

[0307] In step 1313, the AMF sends the first key to the NSP. It should be understood that the execution of step 1313 is within the scope of protection of this example as long as it occurs after step 1309. Therefore, the execution order of step 1313 and steps 1310 to 1312 is not limited here.

[0308] In some possible examples, the first core network device can be an AUSF (the NSP shown in Figure 13 is the same as or co-located in the same entity as the AUSF). In this example, all the processes performed by the NSP shown in Figure 13 can be replaced by the AUSF, and the access code of the NSP is replaced by the access code of the AUSF, which will not be described again.

[0309] In some embodiments, when the first core network device determines that it is allowed to access the first access network device, it may not send its access code to the second core network device. Instead, it may send a notification to the second core network device indicating that the authentication of the first access network device has been completed and / or a request to generate a key. Accordingly, the processing of the second core network device may include receiving the notification and / or the request to generate a key.

[0310] After receiving the notification of completion of authentication of the first access network device and / or the request to generate a key, the second core network device may further include sending a request to the fourth core network device to obtain a terminal code. Correspondingly, the fourth core network device may receive the request to obtain a terminal code from the second core network device and send the terminal's access code to the second core network device. The processing of the second core network device may include receiving the terminal's access code from the fourth core network device. Here, the content that the request to obtain the terminal code may carry, and the processing before the fourth core network device sends the request for the terminal code, are the same as in the aforementioned embodiments, and therefore will not be repeated.

[0311] The processing by the second core network device after receiving the access code from the terminal may include: generating the first key based on the access code of the terminal; and sending the first key to the first core network device. The first core network device may receive the first key from the first core network device.

[0312] This embodiment differs from the previous embodiments in that the second core network device may only receive the terminal's access code. Therefore, generating the first key based on the terminal's access code may include generating the first key based on the terminal's access code and a key shared between the terminal and the network device. The related processing for generating the first key is the same as in the previous embodiments and will not be repeated.

[0313] The second core network device can be an AMF (Advanced Feature Provider). For example, the network device can be the same as the second core network device, both being AMFs, with the key shared between the terminal and the network device being K. AMF For example, the generation of the first key can be represented by the following formula: K NSP =KDF(K AMF (The terminal's access code). For example, the network device is a first access network device, the second core network device can be an AMF, and the key shared between the terminal and the first access network device that can be obtained on the AMF side can be K. gNB The calculation or generation of the first key can be represented by the following formula: K NSP =KDF(K gNB (Terminal access code).

[0314] In this embodiment, the content sent by the second core network device to the terminal may only include the terminal's access code, which may also be carried in the NAS SMC. Correspondingly, the process of the terminal generating the first key should be the same as that of the second core network device and will not be described again. After generating the first key, the terminal can also send a NAS security mode completion message to the second core network device. The description regarding the granularity of the messages protected by the first key is similar to that in the aforementioned embodiments and will not be repeated.

[0315] In some embodiments, when the first core network device determines that it is allowed to access the first access network device, the first core network device may not send the access code of the first core network device to the second core network device, but instead send a request to the fourth core network device to obtain the terminal code.

[0316] The processing of the fourth core network device may include: receiving a request from the first core network device to obtain a terminal code, and sending the terminal's access code to the second core network device. Correspondingly, the second core network device receives the terminal's access code from the fourth core network device. Here, the content that the request to obtain the terminal code may carry, and the processing performed by the fourth core network device before sending the request for the terminal code, are the same as in the aforementioned embodiments, and therefore will not be repeated.

[0317] The processing by the second core network device after receiving the access code from the terminal may include: generating the first key based on the terminal's access code; and sending the first key to the first core network device. The first core network device may receive the first key from the first core network device. This embodiment differs from the previous embodiments in that the second core network device may only receive the terminal's access code. Therefore, the second core network device may generate the first key based on the terminal's access code and a key shared between the terminal and the network device. The related processing for generating the first key is similar to the previous embodiments and will not be described in detail.

[0318] In this embodiment, the content sent by the second core network device to the terminal may only include the terminal's access code, which may also be carried in the NAS SMC. Correspondingly, the process of the terminal generating the first key should be the same as that of the second core network device and will not be described in detail. After generating the first key, the terminal can also send a NAS security mode completion message to the second core network device.

[0319] The description of the granularity of the messages protected by the first key is similar to that in the previous embodiments and will not be repeated.

[0320] It should be noted that in the above embodiment where the second core network device is AMF as an example, the second core network device may also be replaced with other network elements. For example, the second core network device may be SEAF, and the corresponding network device may be SEAF; or the second core network device may be a key generation network element, and the corresponding network device may be AMF or SEAF, etc. For the sake of simplicity, this will not be repeated here.

[0321] In some possible embodiments, the first key is generated by the first access network device or the first core network device.

[0322] The processing by the first access network device may include sending a credential acquisition request to the third core network device. Correspondingly, the processing by the third core network device may include receiving a credential acquisition request from the first access network device. For example, this credential acquisition request may be represented as an Nnrf_AccessToken_Get Request. The content that the credential acquisition request may carry, and the reason for the first access network device sending the credential acquisition request, are the same as in the previous embodiments and will not be repeated.

[0323] The processing performed by the first access network device after sending a credential acquisition request to the third core network device may include at least one of the following: receiving the access code from the first core network device; or receiving the access code from the terminal. Specifically, the first access network device may receive the access code from the third core network device; and / or, the first access network device may receive the access code from the terminal of the third core network device.

[0324] Preferably, the first access network device can receive the access code from the third core network device; and the first access network device can receive the access code from the terminal of the third core network device. The terminal's access code and the first core network device's access code can be carried or contained in the same message or information. For example, the terminal's access code and the first core network device's access code can be included in the access credentials sent by the third core network device to the first access network device.

[0325] Accordingly, the processing after the third core network device receives the credential acquisition request also includes: sending the access credential to the first access network device. Correspondingly, the processing of the first access network device may include: receiving the access credential from the third core network device.

[0326] In this embodiment, the access credential includes at least one of the following: the access token, the terminal's access code, and the access code of the first core network device. The access token can be generated based on the access code of the first core network device and / or the terminal's access code. Preferably, the access credential may include the access token, the terminal's access code, and the access code of the first core network device.

[0327] The processing after the third core network device receives the credential acquisition request further includes: sending a request to the fourth core network device to acquire a terminal code; and receiving the access code of the terminal from the fourth core network device. The fourth core network device receives the request to acquire the terminal code from the third core network device and sends the access code of the terminal to the third core network device. The content that the request to acquire the terminal code may carry, the method of generating the request, and the processing performed by the fourth core network device before sending the terminal's access code can be the same as in the previous embodiments, and therefore will not be repeated.

[0328] After the third core network device receives the access code from the terminal of the fourth core network device, it may include: determining, based on the security access policy of the first core network device, whether to authorize the first access network device to access the first core network device. The specific processing of the third core network device determining whether to authorize the first access network device to access the first core network device based on the security access policy of the first core network device, and determining the access code of the first core network device, is the same as in the previous embodiments and will not be repeated. The access code of the first core network device is one of at least one pre-configured access codes of the first core network device included in the security access policy of the first core network device. The security access policy of the first core network device is used to indicate whether to allow the access network-side device to access the first core network device.

[0329] The processing by the third core network device further includes: when it is determined that the first access network device is authorized to access the first core network device, the third core network device generates an access token based on the access code of the terminal and / or the access code of the first core network device, and sends the access credential to the first access network device. Correspondingly, the processing by the first access network device may include: receiving the access credential from the third core network device. Preferably, the third core network device generates the access token based on the access code of the terminal and the access code of the first core network device. The specific processing method for the third core network device to generate the access token is similar to the aforementioned example and will not be described in detail.

[0330] In one scenario, the access token corresponds to a first service; the terminal's access code corresponds to the first service; and / or the access code of the first core network device corresponds to the first service. Specifically, the security access policy of the first core network device is at the service granularity, and the access code of the first core network device corresponds to the first service; and / or, the terminal's policy is at the service granularity, and the terminal's access code corresponds to the first service. In this case, the access token corresponds to the first service.

[0331] In one scenario, the access token corresponds to a first data type of the first service; the terminal's access code corresponds to the first data type of the first service; and / or the access code of the first core network device corresponds to the first data type of the first service. Specifically, the security access policy of the first core network device is granular at the data type level, and the access code of the first core network device corresponds to the first data type of the first service; and / or, the terminal's policy is granular at the data type level, and the terminal's access code corresponds to the first data type of the first service. In this case, the access token corresponds to the first data type of the first service.

[0332] In one scenario, both the terminal's access code and the first core network device's access code correspond to the device. In this case, the access token corresponds to the device (the terminal and the first core network device).

[0333] The processing by the third core network device may further include: sending an authorization failure notification to the first access network device when it determines that the first access network device is not authorized to access the first service of the first core network device and / or receiving a notification from the fourth core network device that the terminal cannot connect to the first core network device through the first access network device. Correspondingly, the processing by the first access network device may include: receiving the authorization failure notification from the third core network device, and then the first access network device may terminate the processing and / or send an access denial notification to the terminal.

[0334] The processing by the first access network device may further include: generating the first key based on the access code of the terminal; and sending the first key to the first core network device. It should be noted that before the first access network device generates the first key based on the terminal's access code, the following processes may also be performed: the first access network device sends access credentials, which are then verified by the first core network device (e.g., verifying an access token, verifying the access code of the first core network device, or verifying at least one of the terminal's access code); and / or the terminal completes authentication; and / or the first access network device obtains a key shared with the terminal, etc. For the sake of brevity, all possible processes before the first access network device generates the first key will not be elaborated here.

[0335] On the first access network device side, generating the first key based on the terminal's access code includes: generating the first key based on the terminal's access code and at least one of the following: the access code of the first core network device, and a key shared between the terminal and the first access network device.

[0336] Specifically, the first access network device can generate the first key based on the terminal's access code, the first core network device's access code, and a key shared between the terminal and the first access network device. For example, the key shared between the terminal and the first access network device can be any one of the following: K gNB NH (next-hop key), K RRCint K RRCenc K UPint K UPenc Wait. Let K be the key shared between the terminal and the first access network device. RRCenc For example, the calculation or generation of the first key can be represented by the following formula: K NSP =KDF( RRCenc(The terminal's access code, the access code of the first core network device). Since the process of generating the first key is similar to that in the aforementioned embodiments, it will not be described again.

[0337] The processing by the first access network device may further include: sending the terminal's access code. Specifically, the first access network device sends the terminal's access code to the terminal. Correspondingly, the terminal receives the terminal's access code from the first access network device.

[0338] After generating the first key, the first access network device may further include: sending the access code of the first core network device. Specifically, the first access network device sends the access code of the first core network device to the terminal. Correspondingly, the terminal receives the access code of the first core network device from the first access network device.

[0339] The terminal's access code and the first core network device's access code can be sent simultaneously. For example, the terminal's access code and the first core network device's access code can be carried by the AS SMC.

[0340] After receiving the access code from the terminal, the terminal generates a first key based on the access code. The specific method by which the terminal generates the first key should be the same as that of the first access network device, and therefore will not be repeated. After generating the first key, the terminal can also send an AS security mode message to the second core network device to complete the process.

[0341] Furthermore, the first access network device may send the first key to the first core network device after the first key is generated or after the AS security mode is received. Correspondingly, the first core network device receives the first key from the first access network device.

[0342] The description of the granularity of the messages protected by the first key is the same as that in the previous embodiments, and will not be repeated.

[0343] Referring to Figure 14, taking the first core network device as NSP, the second core network device as AMF, the third core network device as NRF, the fourth core network device as UDM, the first access network device as base station, and the terminal as UE as an example, the registration of NSP and the acquisition of token by base station are explained:

[0344] Steps 1401 to 1403 constitute the NSP registration process. The processing of steps 1401 to 1403 is the same as steps 901 to 903 in the previous example, and will not be described again.

[0345] Steps 1404 to 1407 are the process of NRF authorizing the base station to access the NSP and allocating access credentials to the base station.

[0346] The processing of steps 1404 to 1405 is the same as that of steps 904 to 905 in the previous example, and will not be described again.

[0347] Step 1406: The NRF sends a request to the UDM to obtain the UE code.

[0348] Step 1407: The UDM sends the UE's access code to the NRF. The related processing of UDM verification and obtaining the UE's access code is the same as in the previous embodiment and will not be described again.

[0349] Step 1408: The NRF determines whether to authorize the base station to access the NSP based on the NSP's security access policy. If authorization is successful, proceed to step 1409. Alternatively, if authorization fails, the NRF may terminate the process and / or send an authorization failure notification to the base station.

[0350] Step 1409: The NRF generates an access token based on the UE's access code and the NSP's access code, and then sends access credentials to the base station. These access credentials may include the access token, the UE's access code, and the NSP's access code. The token generation and related processing are the same as in the previous embodiments, and therefore will not be repeated.

[0351] Based on Figure 14 and in conjunction with Figure 15, taking the first core network device as NSP, the second core network device as AMF, the fourth core network device as UDM, the first access network device as base station, and the terminal as UE as an example, the key generation after UE authentication is explained:

[0352] Step 1501: The base station uses the UE's access code, the NSP's access code, and the key shared between the UE and the base station (e.g., K) as a basis. gNB Generate the first key (e.g., K) NSP ).

[0353] It should be noted that before step 1501, the base station may have already completed the NSP verification of access credentials, the UE completion of the authentication process, and the base station receiving K from the AMF. gNB For the sake of simplicity, this example will not elaborate on the above processes.

[0354] Step 1502: The base station sends the first key to the NSP.

[0355] Step 1503: The base station sends an AS SMC to the UE, which carries the UE's access code and the NSP's access code.

[0356] Step 1504: The UE uses its access code, NSP access code, and the key shared between the UE and the base station (e.g., K). gNBGenerate the first key (e.g., K) NSP The UE generates its first key in the same way as the base station, so it will not be explained again.

[0357] Step 1505: The UE sends the AS security mode completion message to the AMF.

[0358] It should be understood that as long as step 1502 is executed after step 1501, it is within the protection scope of this example. Here, the execution order between step 1502 and steps 1503 to 1505 is not limited.

[0359] Referring to Figure 16, the following exemplifies the process of the first core network device (e.g., NSF) registering with the NRF and requesting the UE's access code from the UDM; the NRF allocating an access token to the base station; and the first core network device requesting the UE's access code from the UDM:

[0360] Step 1601: The first core network device sends a security access policy. This security access policy can be used to indicate whether access network devices can access the first core network device. This step is the registration process of the first core network device, that is, the first core network device sends an additional scope and its own security access policy during the registration process.

[0361] In this example, the first core network device can be any one of SMF, PCF, UDM, NWDAF, AIoT NF, SF, etc.

[0362] For example, assuming the first core network device is an SMF, the SMF's security access policy may include: Security Access Policy Code 1 (i.e., Access Code 1) (for example only: low security level), Service ID 1-1 (UE session management), and Service ID 1-2 (mobility management); Service ID 1-1 and Service ID 1-2 can correspond to the same Security Access Policy Code 1. Alternatively, the SMF's security access policy may include: Security Access Policy Code 1-1, Security Access Policy Code 1-2, Service ID 1-1, and Service ID 1-2; where Service ID 1-1 can correspond to Security Access Policy Code 1, and Service ID 1-2 can correspond to Security Access Policy Code 1-2.

[0363] For example, assuming the first core network device is PCF, the security access policy of PCF may include: security access policy code 2 (medium security level) and service ID2 (UE service), that is, service ID2 corresponds to security access policy code 2.

[0364] For example, assuming the first core network device is a UDM, the security access policy of the UDM may include: security access policy code 3 (high security level), service ID 3, data type 3 (for example, it may be authentication vector (AV) under service ID 3); where data type 3 of service ID 3 corresponds to security access policy code 3.

[0365] For example, assuming the first core network device is NWDAF, the security access policy of NWDAF may include: security access policy code 4 (high security level), service ID 4 (AI inference service), and data type 4 (such as the data inference result under the AI ​​inference service); where the data type 4 of service ID 4 corresponds to security access policy code 4.

[0366] For example, assuming the first core network device is SF, the security access policy of SF may include: security access policy code 5 (high security level), service ID 5 (human-related sensing services, such as motion capture, heartbeat and breathing), and data type 5 (for example, the sensing inference result under human-related sensing services); where the data type 5 of service ID 5 corresponds to security access policy code 5.

[0367] For example, assuming the first core network device is an AIoT NF, the security access policy of the AIoT NF may include: security access policy code 6 (high security level), service ID 6 (AIOT service), and data type 6 (for example, location information under AIoT service); where the data type 6 of service ID 6 corresponds to security access policy code 6.

[0368] It should be noted that the above is only an illustrative description of the possible contents of the security access policies under various possible types of first core network devices. In actual processing, the first core network device may include, but is not limited to, the core network elements of the above types. The security access policies that the core network elements under each type may include are not limited to the several possibilities in the above examples. For the sake of simplicity, no limitation or exhaustive list is made here.

[0369] Step 1602: The NRF stores the security access policy of the first core network device. Specifically, the NRF can save the security access policy code of the first core network device, which will be used when the NRF generates an access token.

[0370] Step 1603: The base station obtains access credentials from the NRF, which may include an access token and / or the access code of the first core network device.

[0371] For example, the base station may obtain the access credentials of the first core network device from the NRF during the Service Request Procedure. During the process of the base station obtaining the access credentials of the first core network device, it may initiate a credential acquisition request to the NRF. The NRF determines whether to authorize based on the security policy code of the first core network device. If the base station is authorized to access the first service, it sends an access token and / or the access code of the first core network device to the base station.

[0372] Step 1604: The first core network device requests the UE's access code from the UDM.

[0373] Step 1605: UDM sends the UE's access code to the first core network device.

[0374] Referring to Figure 17, the key generation process is illustrated by example:

[0375] Step 1700: The base station receives an access request (or authentication request) from the UE.

[0376] Step 1701: The base station sends access credentials to the NSP, including the access token and the NSP's access code.

[0377] Step 1702: The NSP obtains the UE's access code from the UDM. This step is optional. If the NSP does not have the UE's access code, it requests it from the UDM. The NSP can send the UE ID and service ID to request the access code. The UDM can determine whether the UE can connect to the NSP via the base station based on the UE's policy and then send the UE's access code accordingly. If the NSP already has the UE's access code, it can skip this step and directly obtain the UE's access code.

[0378] Step 1703: The NSP sends the UE's access code and the NSP's access code to the key generation network element (such as AUSF, AMF, etc.).

[0379] Optionally, in step 1704, the key generation network element uses the UE's access code and the NSP's access code to generate the first key.

[0380] Step 1705: The key generation network element sends the UE's access code and the NSP's access code to the UE.

[0381] Step 1706: The UE uses its access code and the NSP's access code to generate the first key.

[0382] Optionally, in step 1704', the NSP generates a first key using the UE's access code and the NSP's access code. In this case, step 1704 is not required, and steps 1705 to 1706 are executed directly.

[0383] Referring to Figure 18, the key generation process is illustrated by example:

[0384] Steps 1800 to 1801 are the same as steps 1700 to 1701, and will not be described again.

[0385] Step 1802: The NSP uses the UE's access code and the NSP's access code to generate the first key.

[0386] This step may also include: if the NSP does not have the UE's access code, the NSP requests the UE's access code from the UDM; the NSP may send the UE ID and service ID to request the UE's access code. The UDM can determine whether the UE can connect to the NSP through the base station based on the UE's policy, and then send the UE's access code. If the NSP already has the UE's access code, the NSP can skip this step and directly obtain the UE's access code.

[0387] Steps 1803 to 1804 are the same as steps 1703 to 1704, and will not be described again.

[0388] In step 1805, if the NSP successfully verifies the connection with the base station, it can send an access success response to the base station. This access success response may include the UE's access code and the NSP's access code.

[0389] Step 1806: The base station sends the UE's access code and the NSP's access code to the UE.

[0390] Step 1807 is the same as step 1706, and will not be described again.

[0391] In the above examples, if the NSP does not execute step 1802, then steps 1803 to 1804 are executed; or, if the NSP executes step 1802, steps 1803 to 1804 can be omitted; or, if the NSP executes step 1802, step 1803 can be executed, but steps 1804 to 1806 are omitted, and step 1804 is replaced by the key generation network element sending the UE's access code and the NSP's access code to the UE, and then directly executing step 1807. It should be noted that this is only an illustrative example, and the actual processing may include, but is not limited to, the above exemplary processes; however, it is not limited or exhaustive here.

[0392] In terms of relevant technologies, the existing N2 interface exists between the base station and the AMF (Advanced Management Function), preventing the base station from directly accessing other core network elements. After upgrading the N2 interface to the SBI (Security Provider Interface) protocol, the base station can access other core network elements. However, the current SBA registration and access service policy lacks a security policy, thus failing to guarantee the security of messages transmitted between the terminal and other core network devices. Furthermore, the lack of a security policy in the SBA registration and access service policy creates security vulnerabilities, allowing attackers to target high-security core network elements. For example, malicious attackers could directly access core network elements through the base station to steal or tamper with high-security data or information stored in these core network elements, leading to security risks.

[0393] This application provides an embodiment that, by adopting the above scheme, can derive a key between the terminal and the first core network device based on the terminal's access code to protect messages between the two parties. Thus, when the terminal accesses the first core network device, the key derived from the terminal's access code can be used to protect messages between the two parties, thereby ensuring the security of communication.

[0394] Furthermore, the above scheme can also allow the third core network device to allocate access credentials to the first access network device for verification. In this way, when the first access network device needs to access the first core network device, the first core network device can verify the access credentials to determine whether the first access network device is allowed to access the first core network device, thereby protecting the security of the first core network device.

[0395] In addition, by registering its security access policy with the third core network device, the first core network device in the above scheme can authorize whether the first access network device is allowed to access the first core network device according to the security access policy, and send access credentials to the first access network device. That is, the first access network device will only be authorized to access the first core network device if the first access network device meets the requirements of the first core network device's security access policy and is allowed to access the first core network device, thus further ensuring the security of the first core network device.

[0396] Furthermore, the above scheme allows the fourth core network device to verify whether the terminal can access the first core network device through the first access network device and send the terminal's access code. Thus, in addition to verifying whether the first access network device can access the first core network device, the core network side also verifies whether the terminal can connect to the first core network device through the access network side device. That is, the terminal will only be allowed to connect to the first core network device through the first access network device if both the first access network device and the terminal can access the first core network device through the access network side device. This further ensures the security of the first core network device.

[0397] Figure 19 is a schematic diagram of the composition structure of a terminal according to an embodiment of this application, including:

[0398] The first communication unit 1901 is used to receive the access code of the terminal;

[0399] The first processing unit 1902 is used to generate a first key based on the access code of the terminal, wherein the first key is used to protect messages between the terminal and the first core network device.

[0400] The first processing unit is configured to generate the first key based on the access code of the terminal and at least one of the following: the access code of the first core network device, and a key shared between the terminal and the network device.

[0401] The network equipment includes one of the following: AUSF, SEAF, AMF, or first access network equipment.

[0402] The first communication unit is used to receive the access code of the first core network device.

[0403] The access code of the first core network device is one of at least one pre-configured access codes of the first core network device included in the security access policy of the first core network device. The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device.

[0404] The access code of the first core network device corresponds to the first service, or the access code of the first core network device corresponds to the first data type of the first service.

[0405] The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

[0406] The first key is used to protect messages of the first service between the terminal and the first core network device, or the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.

[0407] The access code of the terminal is determined based on the terminal's policy, which is used to verify whether the terminal can connect to the first core network device through the first access network device.

[0408] Figure 20 is a schematic diagram of the composition structure of a first core network device according to an embodiment of this application, including:

[0409] The second communication unit 2001 is used to obtain a first key, wherein the first key is generated based on the terminal's access code and is used to protect messages between the terminal and the first core network device.

[0410] The second communication unit is used to receive the first key.

[0411] As shown in Figure 20, the first core network device further includes a second processing unit 2002, used to generate the first key based on the access code of the terminal.

[0412] The second processing unit is configured to generate the first key based on the access code of the terminal and at least one of the following: the access code of the first core network device, and a key shared between the terminal and the network device.

[0413] The network equipment includes one of the following: AUSF, SEAF, AMF, or first access network equipment.

[0414] The second communication unit is used to receive the key shared between the terminal and the network device.

[0415] The second communication unit is used to send the access code of the first core network device.

[0416] The access code of the first core network device corresponds to the first service, or the access code of the first core network device corresponds to the first data type of the first service.

[0417] The second communication unit is used to send a request to the fourth core network device to obtain the terminal code.

[0418] The second communication unit is used to receive the access code from the terminal of the fourth core network device.

[0419] The second communication unit is used to send the access code of the terminal.

[0420] The second communication unit is used to receive encoding acquisition requests from the second core network device.

[0421] The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

[0422] The first key is used to protect messages of the first service between the terminal and the first core network device, or the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.

[0423] The access code of the terminal is determined based on the terminal's policy, which is used to verify whether the terminal can connect to the first core network device through the first access network device.

[0424] The second communication unit is configured to receive a service request from a first access network device, wherein the service request carries an access credential; and to send a service response to the first access network device, wherein the service response is used to indicate whether access to the first core network device is permitted.

[0425] The access credentials include at least one of the following: the access token, the access code of the terminal, and the access code of the first core network device.

[0426] The second processing unit is configured to perform at least one of the following: verifying the access token; verifying the access code of the terminal; and verifying the access code of the first core network device.

[0427] The second communication unit is used to send the security access policy of the first core network device to the third core network device, wherein the security access policy of the first core network device is used to indicate whether to allow the device on the access network side to access the first core network device.

[0428] Whether to allow the access network side device to access the first core network device includes at least one of the following: whether to allow the access network side device to access at least one service of the first core network device, and whether to allow the access network side device to access one or more data types of at least one service of the first core network device.

[0429] The security access policy of the first core network device includes at least one pre-configured access code of the first core network device.

[0430] The first core network device has at least one of the following pre-configured access codes: a pre-configured access code corresponding to each service in at least one service that the first core network device allows access network-side devices to access; and a pre-configured access code corresponding to one or more data types under each service in at least one service that the first core network device allows access network-side devices to access.

[0431] Figure 21 is a schematic diagram of the composition structure of a first access network device according to an embodiment of this application, including:

[0432] The third communication unit 2101 is used to send the terminal's access code, wherein the terminal's access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

[0433] As shown in Figure 21, the first access network device further includes:

[0434] The third processing unit 2102 is used to generate the first key based on the access code of the terminal;

[0435] The third communication unit is used to send the first key to the first core network device.

[0436] The third processing unit is configured to generate the first key based on the terminal's access code and at least one of the following: the access code of the first core network device, and a key shared between the terminal and the first access network device.

[0437] The access code of the first core network device is one of at least one pre-configured access codes of the first core network device included in the security access policy of the first core network device. The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device.

[0438] The access code of the first core network device corresponds to the first service, or the access code of the first core network device corresponds to the first data type of the first service.

[0439] The third communication unit is configured to perform at least one of the following: receive the access code of the first core network device; receive the access code of the terminal.

[0440] The third communication unit is used to send the access code of the first core network device.

[0441] The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

[0442] The first key is used to protect messages of the first service between the terminal and the first core network device, or the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.

[0443] Figure 22 is a schematic diagram of the composition structure of a second core network device according to an embodiment of this application, including:

[0444] The fourth communication unit 2201 is used to send the terminal's access code, wherein the terminal's access code is used to generate a first key, and the first key is used to protect the messages between the terminal and the first core network device.

[0445] As shown in Figure 22, the second core network device also includes:

[0446] The fourth processing unit 2202 is used to generate the first key based on the access code of the terminal;

[0447] The fourth communication unit is used to send the first key to the first core network device.

[0448] The fourth processing unit is configured to generate the first key based on the access code of the terminal and at least one of the following: the access code of the first core network device, and a key shared between the terminal and the network device.

[0449] The fourth communication unit is used to receive the access code of the first core network device.

[0450] The fourth communication unit is used to send the access code of the first core network device.

[0451] The access code of the first core network device is one of at least one pre-configured access codes of the first core network device included in the security access policy of the first core network device. The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device.

[0452] The access code of the first core network device corresponds to the first service, or the access code of the first core network device corresponds to the first data type of the first service.

[0453] The fourth communication unit is used to send the key shared between the terminal and the network device to the first core network device.

[0454] The network equipment includes one of the following: AUSF, SEAF, AMF, or first access network equipment.

[0455] The fourth communication unit is used to receive the access code of the terminal.

[0456] The fourth communication unit is configured to perform at least one of the following: send an encoding acquisition request to the first core network device; send a request to the fourth core network device to acquire the terminal encoding.

[0457] The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

[0458] The first key is used to protect messages of the first service between the terminal and the first core network device, or the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.

[0459] The access code of the terminal is determined based on the terminal's policy, which is used to verify whether the terminal can connect to the first core network device through the first access network device.

[0460] Figure 23 is a schematic diagram of the composition structure of a third core network device according to an embodiment of this application, including:

[0461] The fifth communication unit 2301 is used to send an access credential to the first access network device, wherein the access credential is used to verify whether the first access network device is allowed to access the first core network device.

[0462] The fifth communication unit is configured to receive a credential acquisition request from the first access network device, wherein the credential acquisition request is used to acquire the access credential.

[0463] The credential acquisition request carries at least one of the following: identification information of the first core network device, type of the first core network device, type of the first access network device, identifier of the first access network device, identifier of the first service, and identifier of the terminal.

[0464] The access credentials include at least one of the following: an access token, the access code of the terminal, and the access code of the first core network device, wherein the access token is generated based on the access code of the terminal and / or the access code of the first core network device.

[0465] The fifth communication unit is used to send a request to the fourth core network device to obtain the terminal code; and to receive the access code of the terminal from the fourth core network device.

[0466] The access token corresponds to the first service; the terminal's access code corresponds to the first service, and / or the access code of the first core network device corresponds to the first service.

[0467] The access token corresponds to the first data type of the first service; the access code of the terminal corresponds to the first data type of the first service, and / or the access code of the first core network device corresponds to the first data type of the first service.

[0468] As shown in Figure 23, the third core network device also includes:

[0469] The fifth processing unit 2302 is used to determine whether to authorize the first access network device to access the first core network device based on the security access policy of the first core network device.

[0470] The fifth communication unit is used to receive the security access policy of the first core network device.

[0471] The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device.

[0472] Whether to allow the access network side device to access the first core network device includes at least one of the following: whether to allow the access network side device to access at least one service of the first core network device, and whether to allow the access network side device to access one or more data types of at least one service of the first core network device.

[0473] The security access policy of the first core network device includes at least one pre-configured access code of the first core network device.

[0474] The first core network device has at least one of the following pre-configured access codes: a pre-configured access code corresponding to each service in at least one service that the first core network device allows access network-side devices to access; and a pre-configured access code corresponding to one or more data types under each service in at least one service that the first core network device allows access network-side devices to access.

[0475] In one embodiment, a first access network device includes:

[0476] The third communication unit is used to receive access credentials from the third core network device, wherein the access credentials are used to verify whether the first access network device is allowed to access the first core network device.

[0477] The third communication unit is used to send a credential acquisition request to the third core network device, wherein the credential acquisition request is used to acquire the access credential.

[0478] The credential acquisition request carries at least one of the following: identification information of the first core network device, type of the first core network device, type of the first access network device, identifier of the first access network device, identifier of the first service, and identifier of the terminal.

[0479] The access credentials include at least one of the following: an access token, the access code of the terminal, and the access code of the first core network device, wherein the access token is generated based on the access code of the terminal and / or the access code of the first core network device.

[0480] The access token corresponds to the first service; the terminal's access code corresponds to the first service, and / or the access code of the first core network device corresponds to the first service.

[0481] The access token corresponds to the first data type of the first service; the access code of the terminal corresponds to the first data type of the first service, and / or the access code of the first core network device corresponds to the first data type of the first service.

[0482] The third communication unit is configured to send a service request to the first core network device, wherein the service request carries the access credential; and to receive a service response from the first core network device, wherein the service response is used to indicate whether access to the first core network device is permitted.

[0483] Figure 24 is a schematic diagram of the composition structure of a fourth core network device according to an embodiment of this application, including:

[0484] The sixth communication unit 2401 is used to receive a request to obtain the terminal code and to send the access code of the terminal.

[0485] As shown in Figure 24, the fourth core network device also includes:

[0486] The sixth processing unit 2402 is used to verify, based on the terminal's policy, whether the terminal can connect to the first core network device through the first access network device.

[0487] The sixth processing unit is used to obtain the access code of the terminal based on the terminal's strategy.

[0488] The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

[0489] The device in this application embodiment can realize the corresponding functions of the devices in the foregoing information processing method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in this device can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the device of this application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0490] It should be understood that the sequence number of each process in the various embodiments of this application does not imply the order of execution; the execution order of each process should be determined by its function and internal logic. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. The above descriptions are merely specific embodiments of this application, and the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An information processing method executed by a terminal, comprising: The access code of the receiving terminal; Based on the access code of the terminal, a first key is generated, wherein the first key is used to protect messages between the terminal and the first core network device.

2. The method according to claim 1, wherein, The process of generating the first key based on the access code of the terminal includes: The first key is generated based on the terminal's access code and at least one of the following: the access code of the first core network device, or a key shared between the terminal and the network device.

3. The method according to claim 2, wherein, The network equipment includes one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), Access and Mobility Management Function (AMF), and a first access network device.

4. The method according to claim 2 or 3, further comprising: Receive the access code from the first core network device.

5. The method according to any one of claims 2-4, wherein, The access code of the first core network device is one of at least one pre-configured access codes of the first core network device included in the security access policy of the first core network device. The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device.

6. The method according to any one of claims 2-5, wherein, The access code of the first core network device corresponds to the first service, or the access code of the first core network device corresponds to the first data type of the first service.

7. The method according to any one of claims 1-6, wherein, The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

8. The method according to claim 6 or 7, wherein, The first key is used to protect messages of the first service between the terminal and the first core network device, or the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.

9. The method according to any one of claims 1-8, wherein, The access code of the terminal is determined based on the terminal's policy, which is used to verify whether the terminal can connect to the first core network device through the first access network device.

10. An information processing method executed by a first core network device, comprising: Obtain a first key, wherein the first key is generated based on the terminal's access code and is used to protect messages between the terminal and the first core network device.

11. The method according to claim 10, wherein, Obtaining the first key includes: Receive the first key.

12. The method according to claim 10, wherein, Obtaining the first key includes: The first key is generated based on the access code of the terminal.

13. The method according to claim 12, wherein, The process of generating the first key based on the access code of the terminal includes: The first key is generated based on the terminal's access code and at least one of the following: the access code of the first core network device, or a key shared between the terminal and the network device.

14. The method according to claim 13, wherein, The network equipment includes one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), Access and Mobility Management Function (AMF), and a first access network device.

15. The method according to claim 13 or 14, further comprising: Receive the key shared between the terminal and the network device.

16. The method according to any one of claims 13-15, further comprising: Send the access code of the first core network device.

17. The method according to any one of claims 13-16, wherein, The access code of the first core network device corresponds to the first service, or the access code of the first core network device corresponds to the first data type of the first service.

18. The method according to any one of claims 10-17, further comprising: Send a request to the fourth core network device to obtain the terminal code.

19. The method of claim 18, further comprising: The terminal receives the access code from the fourth core network device.

20. The method of claim 19, further comprising: Send the access code of the terminal.

21. The method according to any one of claims 16-20, further comprising: Receive encoding retrieval requests from the second core network device.

22. The method according to any one of claims 10-21, wherein, The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

23. The method according to claim 17 or 22, wherein, The first key is used to protect messages of the first service between the terminal and the first core network device, or the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.

24. The method according to any one of claims 10-22, wherein, The access code of the terminal is determined based on the terminal's policy, which is used to verify whether the terminal can connect to the first core network device through the first access network device.

25. The method according to any one of claims 10-24, further comprising: Receive a service request from a first access network device, wherein the service request carries an access credential; Send a service response to the first access network device, wherein the service response is used to indicate whether access to the first core network device is permitted.

26. The method of claim 25, wherein, The access credentials include at least one of the following: an access token, the access code of the terminal, and the access code of the first core network device.

27. The method of claim 26, further comprising at least one of the following: Verify the access token; Verify the access code of the terminal; Verify the access code of the first core network device.

28. The method according to any one of claims 10-27, further comprising: Send the security access policy of the first core network device to the third core network device, wherein the security access policy of the first core network device is used to indicate whether to allow the device on the access network side to access the first core network device.

29. The method according to claim 28, wherein, Whether to allow the access network side device to access the first core network device includes at least one of the following: whether to allow the access network side device to access at least one service of the first core network device, and whether to allow the access network side device to access one or more data types of at least one service of the first core network device.

30. The method according to claim 28 or 29, wherein, The security access policy of the first core network device includes at least one pre-configured access code of the first core network device.

31. The method according to claim 30, wherein, The first core network device has at least one of the following pre-configured access codes: a pre-configured access code corresponding to each service in at least one service that the first core network device allows access network-side devices to access; and a pre-configured access code corresponding to one or more data types under each service in at least one service that the first core network device allows access network-side devices to access.

32. An information processing method executed by a first access network device, comprising: The terminal access code is sent, wherein the terminal access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

33. The method of claim 32, further comprising: The first key is generated based on the access code of the terminal; Send the first key to the first core network device.

34. The method according to claim 33, wherein, The process of generating the first key based on the access code of the terminal includes: The first key is generated based on the terminal's access code and at least one of the following: the access code of the first core network device, and a key shared between the terminal and the first access network device.

35. The method according to claim 34, wherein, The access code of the first core network device is one of at least one pre-configured access codes of the first core network device included in the security access policy of the first core network device. The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device.

36. The method according to claim 34 or 35, wherein, The access code of the first core network device corresponds to the first service, or the access code of the first core network device corresponds to the first data type of the first service.

37. The method according to any one of claims 34-36, further comprising at least one of the following: Receive the access code from the first core network device; Receive the access code from the terminal.

38. The method of claim 37, further comprising: Send the access code of the first core network device.

39. The method according to any one of claims 32-38, wherein, The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

40. The method according to claim 36 or 39, wherein, The first key is used to protect messages of the first service between the terminal and the first core network device, or the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.

41. An information processing method executed by a second core network device, comprising: The terminal access code is sent, wherein the terminal access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

42. The method of claim 41, further comprising: The first key is generated based on the access code of the terminal; Send the first key to the first core network device.

43. The method according to claim 42, wherein, The process of generating the first key based on the access code of the terminal includes: The first key is generated based on the terminal's access code and at least one of the following: the access code of the first core network device, or a key shared between the terminal and the network device.

44. The method of claim 43, further comprising: Receive the access code from the first core network device.

45. The method of claim 44, further comprising: Send the access code of the first core network device.

46. ​​The method according to any one of claims 43-45, wherein, The access code of the first core network device is one of at least one pre-configured access codes of the first core network device included in the security access policy of the first core network device. The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device.

47. The method according to any one of claims 43-45, wherein, The access code of the first core network device corresponds to the first service, or the access code of the first core network device corresponds to the first data type of the first service.

48. The method of claim 41, further comprising: Send the key shared between the terminal and the network device to the first core network device.

49. The method according to any one of claims 43-48, wherein, The network equipment includes one of the following: Authentication Service Function (AUSF), Security Anchor Function (SEAF), Access and Mobility Management Function (AMF), and a first access network device.

50. The method according to any one of claims 41-49, further comprising: Receive the access code from the terminal.

51. The method according to any one of claims 41-50, further comprising at least one of the following: Send an encoding acquisition request to the first core network device; Send a request to the fourth core network device to obtain the terminal code.

52. The method according to any one of claims 41-51, wherein, The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

53. The method according to claim 47 or 52, wherein, The first key is used to protect messages of the first service between the terminal and the first core network device, or the first key is used to protect messages of the first data type of the first service between the terminal and the first core network device.

54. The method according to any one of claims 41-53, wherein, The access code of the terminal is determined based on the terminal's policy, which is used to verify whether the terminal can connect to the first core network device through the first access network device.

55. An information processing method executed by a third core network device, comprising: Send an access credential to the first access network device, wherein the access credential is used to verify whether the first access network device is allowed to access the first core network device.

56. The method of claim 55, further comprising: A credential acquisition request is received from the first access network device, wherein the credential acquisition request is used to acquire the access credential.

57. The method according to claim 56, wherein, The credential acquisition request carries at least one of the following: identification information of the first core network device, type of the first core network device, type of the first access network device, identifier of the first access network device, identifier of the first service, and identifier of the terminal.

58. The method according to any one of claims 55-57, wherein, The access credentials include at least one of the following: an access token, an access code of the terminal, and an access code of the first core network device, wherein the access token is generated based on the access code of the terminal and / or the access code of the first core network device.

59. The method of claim 58, further comprising: Send a request to the fourth core network device to obtain the terminal code; The terminal receives the access code from the fourth core network device.

60. The method according to claim 58, wherein, The access token corresponds to the first service; the terminal's access code corresponds to the first service, and / or the access code of the first core network device corresponds to the first service.

61. The method according to claim 58, wherein, The access token corresponds to the first data type of the first service; the access code of the terminal corresponds to the first data type of the first service, and / or the access code of the first core network device corresponds to the first data type of the first service.

62. The method according to any one of claims 55-61, further comprising: Based on the security access policy of the first core network device, determine whether to authorize the first access network device to access the first core network device.

63. The method according to any one of claims 55-62, further comprising: Receive the security access policy of the first core network device.

64. The method according to claim 62 or 63, wherein, The security access policy of the first core network device is used to indicate whether to allow devices on the access network side to access the first core network device.

65. The method according to claim 64, wherein, Whether to allow the access network side device to access the first core network device includes at least one of the following: whether to allow the access network side device to access at least one service of the first core network device, and whether to allow the access network side device to access one or more data types of at least one service of the first core network device.

66. The method according to claim 64 or 65, wherein, The security access policy of the first core network device includes at least one pre-configured access code of the first core network device.

67. The method according to claim 66, wherein, The first core network device has at least one of the following pre-configured access codes: a pre-configured access code corresponding to each service in at least one service that the first core network device allows access network-side devices to access; and a pre-configured access code corresponding to one or more data types under each service in at least one service that the first core network device allows access network-side devices to access.

68. An information processing method executed by a first access network device, comprising: Receive access credentials from a third core network device, wherein the access credentials are used to verify whether the first access network device is allowed to access the first core network device.

69. The method of claim 68, further comprising: A credential acquisition request is sent to the third core network device, wherein the credential acquisition request is used to acquire the access credential.

70. The method according to claim 69, wherein, The credential acquisition request carries at least one of the following: identification information of the first core network device, type of the first core network device, type of the first access network device, identifier of the first access network device, identifier of the first service, and identifier of the terminal.

71. The method according to claim 68 or 69, wherein, The access credentials include at least one of the following: an access token, an access code of the terminal, and an access code of the first core network device, wherein the access token is generated based on the access code of the terminal and / or the access code of the first core network device.

72. The method according to claim 71, wherein, The access token corresponds to the first service; the terminal's access code corresponds to the first service, and / or the access code of the first core network device corresponds to the first service.

73. The method according to claim 71, wherein, The access token corresponds to the first data type of the first service; the access code of the terminal corresponds to the first data type of the first service, and / or the access code of the first core network device corresponds to the first data type of the first service.

74. The method according to any one of claims 68-73, further comprising: Send a service request to the first core network device, wherein the service request carries the access credential; Receive a service response from the first core network device, wherein the service response is used to indicate whether access to the first core network device is permitted.

75. An information processing method executed by a fourth core network device, comprising: Receive a request to obtain the terminal encoding; Send the access code of the terminal.

76. The method of claim 75, further comprising: Based on the terminal's policy, verify whether the terminal can connect to the first core network device through the first access network device.

77. The method according to claim 75 or 76, further comprising: Based on the terminal's strategy, the terminal's access code is obtained.

78. The method according to any one of claims 75-77, wherein, The access code of the terminal corresponds to the first service, or the access code of the terminal corresponds to the first data type of the first service.

79. A terminal, comprising: The first communication unit is used to receive the access code from the terminal; The first processing unit is configured to generate a first key based on the access code of the terminal, wherein the first key is used to protect messages between the terminal and the first core network device.

80. A first core network device, comprising: The second communication unit is used to obtain a first key, wherein the first key is generated based on the terminal's access code and is used to protect messages between the terminal and the first core network device.

81. A first access network device, comprising: The third communication unit is used to send the terminal's access code, wherein the terminal's access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

82. A second core network device, comprising: The fourth communication unit is used to send the terminal's access code, wherein the terminal's access code is used to generate a first key, and the first key is used to protect messages between the terminal and the first core network device.

83. A third core network device, comprising: The fifth communication unit is used to send an access credential to the first access network device, wherein the access credential is used to verify whether the first access network device is allowed to access the first core network device.

84. A first access network device, comprising: The third communication unit is used to receive access credentials from the third core network device, wherein the access credentials are used to verify whether the first access network device is allowed to access the first core network device.

85. A fourth core network device, comprising: The sixth communication unit is used to receive requests to obtain terminal codes; Send the access code of the terminal.

Citation Information

Patent Citations

  • Key acquisition method and device

    CN113225176A

  • Equipment authentication, voucher and identifier distribution method, relay equipment and network side equipment

    CN117459932A

  • Communication method and communication device

    CN118265032A

  • Access Network Authentication Token Broker (ANATB) Gateway

    US20200145402A1

  • Non-public network authentication in 5g

    US20220159460A1