Communication method, communication device, communication system, and storage medium
By receiving and controlling information sent by access network devices through core network devices, the flexibility and security issues of NAS protection under the service-oriented RAN architecture are resolved, enabling flexible control of NAS protection, improving security and saving resources.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2025-01-27
- Publication Date
- 2026-07-30
AI Technical Summary
In future communication networks, under the service-oriented RAN architecture, existing technologies struggle to flexibly control non-access stratum (NAS) protection, resulting in poor security protection and redundant resource consumption.
The core network equipment receives information sent by the access network equipment and controls NAS protection based on this information, including enabling or disabling NAS protection. It achieves flexible control of NAS protection through information such as identification, handover notification messages and path handover requests.
It improves the flexibility and security of NAS protection, avoids redundant protection, saves resources, and is suitable for various communication scenarios.
Smart Images

Figure CN2025075591_30072026_PF_FP_ABST
Abstract
Description
Communication methods, communication equipment, communication systems and storage media Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a communication method, communication device, communication system and storage medium. Background Technology
[0002] In future communication networks, network functions (NFs) and access network devices (such as base stations) can be directly connected through service-oriented interfaces. This architecture can be called a service-oriented radio access network (RAN) architecture. Summary of the Invention
[0003] This disclosure provides a communication method, communication device, communication system, and storage medium.
[0004] The first aspect of this disclosure provides a communication method executed by a core network device, comprising: receiving first information sent by a first access network device; and controlling non-access stratum (NAS) protection based on the first information.
[0005] A second aspect of this disclosure provides a communication method executed by a first access network device, comprising: sending first information to a core network device, wherein the first information is used by the core network device to control non-access stratum NAS protection.
[0006] A third aspect of this disclosure provides a core network device, comprising: a transceiver module for receiving first information sent by a first access network device; and a processing module for controlling non-access stratum (NAS) protection based on the first information.
[0007] The fourth aspect of this disclosure provides a first access network device, which includes a transceiver module for sending first information to a core network device, wherein the first information is used by the core network device to control non-access stratum NAS protection.
[0008] A fifth aspect of this disclosure provides a communication device comprising: one or more processors; wherein the processors are configured to perform the method as described in the first aspect above, or to perform the method as described in the second aspect above.
[0009] A sixth aspect of this disclosure provides a communication system including a core network device and a first access network device. The core network device is used to perform the method as described in the first aspect above, and the first access network device is used to perform the method as described in the second aspect above.
[0010] A seventh aspect of this disclosure provides a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect above, or to perform the method described in the second aspect above.
[0011] An eighth aspect embodiment of this disclosure provides a computer program product including a computer program that, when executed by a processor, implements the method as described in the first aspect above, or implements the method as described in the second aspect above.
[0012] In the solutions proposed in this disclosure, the core network device can receive first information sent by the first access network device and control NAS protection based on the first information. This enables flexible control of NAS protection, thereby improving security protection effectiveness. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments or background art of this disclosure, the accompanying drawings used in the embodiments or background art of this disclosure will be described below.
[0014] Figure 1A is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure;
[0015] Figure 1B is a schematic diagram of a system architecture provided in an embodiment of this disclosure;
[0016] Figure 1C is a schematic diagram of another system architecture provided in an embodiment of this disclosure;
[0017] Figure 1D is a schematic diagram of another system architecture provided in an embodiment of this disclosure;
[0018] Figure 2A is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure;
[0019] Figure 2B is an interactive schematic diagram of a communication method according to another embodiment of the present disclosure;
[0020] Figure 3 is an interactive schematic diagram of a communication method according to yet another embodiment of the present disclosure;
[0021] Figure 4 is an interactive schematic diagram of a communication method according to yet another embodiment of the present disclosure;
[0022] Figure 5 is an interactive schematic diagram of a communication method according to another embodiment of the present disclosure;
[0023] Figure 6A is a control schematic diagram according to an embodiment of this disclosure;
[0024] Figure 6B is another control diagram in an embodiment of this disclosure;
[0025] Figure 6C is another control schematic diagram in an embodiment of this disclosure;
[0026] Figure 6D is another control diagram in an embodiment of this disclosure;
[0027] Figure 6E is another control schematic diagram in an embodiment of this disclosure;
[0028] Figure 7 is a schematic diagram of the structure of the communication device proposed in an embodiment of this disclosure;
[0029] Figure 8A is a schematic diagram of the structure of the communication device proposed in an embodiment of this disclosure;
[0030] Figure 8B is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. Detailed Implementation
[0031] This disclosure provides communication methods, communication devices, communication systems, and storage media.
[0032] In a first aspect, embodiments of this disclosure propose a communication method, which is executed by a core network device, including: receiving first information sent by a first access network device; and controlling non-access stratum (NAS) protection based on the first information.
[0033] In the above embodiments, the core network device can receive first information sent by the first access network device and control the NAS protection based on the first information. This enables flexible control of NAS protection, thereby improving the security protection effect.
[0034] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0035] Send a second message to the first access network device, wherein the second message is used to indicate information related to NAS protection.
[0036] In the above embodiments, NAS protection-related information is promptly indicated to the first access network device, enabling the first access network device to effectively obtain NAS protection-related information and take appropriate follow-up measures, thus making it applicable to various communication scenarios.
[0037] In conjunction with some embodiments of the first aspect, in some embodiments, the first information includes at least one of the following:
[0038] Request information, which is used to request whether to disable or enable NAS protection;
[0039] The first identifier is used to identify the first access network device;
[0040] Toggle notification messages;
[0041] Next-Generation Application Protocol (NGAP) path switching request.
[0042] In the above embodiments, the core network device can accurately decide whether to disable NAS protection, improving the flexibility of NAS protection shutdown control. If the core network device decides to disable NAS protection, redundant NAS protection can be effectively avoided, saving resources. Alternatively, the core network device can accurately decide whether to enable NAS protection, improving the flexibility of NAS protection enable control. If the core network device decides to enable NAS protection, security protection performance can be improved.
[0043] In conjunction with some embodiments of the first aspect, in some embodiments, NAS protection is controlled based on first information, including:
[0044] NAS protection is controlled based on the first and third information, where the third information is related to the access network equipment.
[0045] In the above embodiments, the core network device can control NAS protection based on the first information and the third information related to the access network device maintained locally, thereby improving the accuracy and effectiveness of NAS protection control.
[0046] In conjunction with some embodiments of the first aspect, in some embodiments, the third information includes at least one of the following:
[0047] The second identifier is used to identify the second access network device;
[0048] The first indication information is used to indicate whether the second access network device is a service-oriented access network device;
[0049] The second indication information is used to indicate whether the second access network device is in a secure environment, and the secure environment supports disabling NAS protection.
[0050] The handover information indicates a type change between the first access network device and the third access network device, where the first access network device is the access network device after the handover and the third access network device is the access network device before the handover.
[0051] In the above embodiments, the accuracy of the decision on whether to turn off NAS protection can be effectively improved, enabling accurate control of NAS protection and ensuring the effectiveness of security protection.
[0052] In conjunction with some embodiments of the first aspect, in some embodiments, NAS protection is controlled based on first information and third information, including:
[0053] Based on the first and third information, it is determined that the first access network device meets the first condition, and NAS protection is turned off.
[0054] Based on the first and third information, it is determined that the first access network device does not meet the first condition, so NAS protection is enabled.
[0055] The first condition includes at least one of the following:
[0056] The first access network device is a service-oriented access network device;
[0057] The first access network device is located in a secure environment;
[0058] The type change between the first access network device and the third access network device is: switching from a non-service access network device to a service access network device.
[0059] In the above embodiments, accurate decision-making to disable NAS protection is achieved, enabling timely disabling of NAS protection, avoiding redundant NAS protection configurations, and conserving the resources required for NAS protection, thereby supporting improved system performance. It enables timely and effective disabling of NAS protection, ensuring security while avoiding redundant NAS protection configurations, thus effectively conserving the resources required for NAS protection. Alternatively, it enables accurate decision-making to enable NAS protection, enabling timely activation of NAS protection and improving security effectiveness.
[0060] In conjunction with some embodiments of the first aspect, in some embodiments, determining that the first access network device meets the first condition based on the first information and the third information includes at least one of the following:
[0061] The first identifier and the second identifier are the same, and the first indication information indicates that the second access network device is a service-oriented access network device, thus determining that the first access network device is a service-oriented access network device;
[0062] The first identifier and the second identifier are the same, and the second indication information indicates that the second access network device is located in a safe environment, thus determining that the first access network device is located in a safe environment;
[0063] The first information includes a handover notification message or an NGAP path handover request, and the handover information contained in the third information indicates that the type change between the first access network device and the third access network device is: a handover from a non-service access network device to a service access network device.
[0064] In the above embodiments, various methods can be selected based on the actual communication scenario requirements to determine whether the first access network device meets the first condition, thereby ensuring the correctness of NAS protection control, effectively balancing security protection performance, and avoiding redundant NAS protection configurations.
[0065] In conjunction with some embodiments of the first aspect, in some embodiments, the second information includes any one of the following:
[0066] The third instruction information is used to indicate that NAS protection has been turned off;
[0067] The first reason, where the first reason is used to indicate the reason why NAS protection was not successfully turned off.
[0068] The fourth instruction information is used to indicate that NAS protection has been enabled;
[0069] The second reason, where the second reason is used to indicate the reason why NAS protection was not successfully enabled.
[0070] In the above embodiments, NAS protection-related information is promptly indicated to the first access network device, enabling the first access network device to effectively obtain NAS protection-related information and take appropriate follow-up measures, thus making it applicable to various communication scenarios.
[0071] In conjunction with some embodiments of the first aspect, in some embodiments, the transmission of the first information is triggered based on at least one of the following:
[0072] The first access network device completes the access layer security mode command (AS SMC) procedure.
[0073] The first access network device completes the handover based on the N2 interface;
[0074] The first access network device completes the intra-device handover.
[0075] In the above embodiments, core network devices are supported in deciding whether to disable or enable NAS protection in all the above scenarios, which can be effectively applied to personalized communication scenarios and improve the flexibility of NAS protection control.
[0076] Secondly, embodiments of this disclosure propose a communication method, which is executed by a first access network device, including: sending first information to a core network device, wherein the first information is used by the core network device to control non-access stratum NAS protection.
[0077] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0078] Receive second information sent by the core network device, wherein the second information is used to indicate information related to NAS protection.
[0079] In conjunction with some embodiments of the second aspect, in some embodiments, the first information includes at least one of the following:
[0080] Request information, which is used to request whether to disable or enable NAS protection;
[0081] The first identifier is used to identify the first access network device;
[0082] Toggle notification messages;
[0083] Next-Generation Application Protocol (NGAP) path switching request.
[0084] In conjunction with some embodiments of the second aspect, in some embodiments, the second information includes any of the following:
[0085] The third instruction information is used to indicate that NAS protection has been turned off;
[0086] The first reason, where the first reason is used to indicate the reason why NAS protection was not successfully turned off.
[0087] The fourth instruction information is used to indicate that NAS protection has been enabled;
[0088] The second reason, where the second reason is used to indicate the reason why NAS protection was not successfully enabled.
[0089] In conjunction with some embodiments of the second aspect, in some embodiments, sending first information to the core network device includes at least one of the following:
[0090] Complete the Access Layer Security Mode Command (AS SMC) procedure and send the first information to the core network equipment;
[0091] Complete the handover based on the N2 interface and send the first information to the core network equipment;
[0092] After completing the intra-device handover, the first information is sent to the core network equipment.
[0093] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0094] If the path handover confirmation message based on NGAP does not include the new security context indicator (NSCI), perform an intra-device handover and send the first information to the core network device after the intra-device handover is completed.
[0095] Thirdly, this disclosure provides a core network device, which includes: a transceiver module for receiving first information sent by a first access network device; and a processing module for controlling non-access stratum NAS protection based on the first information.
[0096] Fourthly, this disclosure provides a first access network device, which includes a transceiver module for sending first information to a core network device, wherein the first information is used by the core network device to control non-access stratum NAS protection.
[0097] Fifthly, embodiments of this disclosure provide a communication device, which includes one or more processors; wherein the communication device is used to execute the first aspect and optional implementations of the first aspect, or to execute the second aspect and optional implementations of the second aspect.
[0098] In a sixth aspect, embodiments of this disclosure provide a communication system comprising: a core network device and a first access network device; wherein the core network device is configured to perform the method described in the first aspect and its optional implementations, and the first access network device is configured to perform the method described in the second aspect and its optional implementations.
[0099] In a seventh aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect and its optional implementations, or to perform the method described in the second aspect and its optional implementations.
[0100] Eighthly, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method described in the first aspect and its optional implementations, or to perform the method described in the second aspect and its optional implementations.
[0101] In a ninth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the method as described in the first aspect and optional implementations of the first aspect, or to perform the method as described in the second aspect and optional implementations of the second aspect.
[0102] In a tenth aspect, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the method described according to the first aspect and optional implementations thereof, or configured to perform the method described according to the second aspect and optional implementations thereof.
[0103] It is understood that the aforementioned core network equipment, first access network equipment, communication equipment, communication system, storage medium, program product, computer program, chip, or chip system are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0104] This disclosure provides a communication method, a communication device, a communication system, and a storage medium. In some embodiments, the terms "communication method" and "information processing method," "communication control method," etc., can be used interchangeably; the terms "communication method apparatus" and "information processing apparatus," "communication control apparatus," etc., can be used interchangeably; and the terms "transmission system" and "information processing system," "communication system," etc., can be used interchangeably.
[0105] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0106] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0107] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0108] In this disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the aforementioned," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular or a plural expression.
[0109] In the embodiments of this disclosure, "multiple" refers to two or more.
[0110] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0111] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0112] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0113] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0114] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0115] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.
[0116] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0117] In some embodiments, the apparatus and device may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "body", etc.
[0118] In some embodiments, "network" can be interpreted as devices included in the network, such as access network devices, core network devices, etc.
[0119] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)," "base station (BS)," "radio base station," or "fixed station." In some embodiments, it may also be understood as "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," or "bandwidth part (BWP)."
[0120] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)," "user terminal," "Narrow Band-Internet of Things (NB-IoT) device," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," etc.
[0121] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.
[0122] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
[0123] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0124] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0125] Figure 1A is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure. As shown in Figure 1A, the communication system 100 may include a terminal 101, a core network device 102, and an access network device 103.
[0126] In some embodiments, terminal 101 may include, for example, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home, but is not limited thereto.
[0127] In some embodiments, the core network device 102 may be a single device, multiple devices, or a group of devices. The core network includes, for example, at least one of the Evolved Packet Core (EPC), 5G Core Network (5GCN), and Next Generation Core (NGC).
[0128] In some embodiments, the core network device 102 is, for example, an Access and Mobility Management Function (AMF) network element, but the name is not limited thereto.
[0129] In some embodiments, core network device 102 is used to provide access and mobility management functions.
[0130] In some embodiments, the terminal 101 and the core network device 102 can be connected via the access network device 103. Optionally, the access network device 103 may be, for example, a node or device that connects the terminal to the wireless network. The access network device 103 may include, in a 5G communication system, an evolved Node B (eNB), a next-generation eNB (ng-eNB), a next-generation Node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, and, in a 6G communication system, a base station.
[0131] It includes, but is not limited to, at least one of the following: Open RAN, Cloud RAN, base stations in other communication systems, and access nodes in wireless fidelity (WiFi) systems.
[0132] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.
[0133] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1A, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1A are illustrative. The communication system may include all or some of the main bodies in FIG1A, or it may include other main bodies outside of FIG1A. The number and form of each main body are arbitrary. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0134] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0135] Optionally, as shown in Figure 1B, which is a schematic diagram of a system architecture provided by an embodiment of this disclosure, Figure 1B illustrates the connection method between the UE and the Network Function (NF) in a non-serviced RAN scenario. The example uses the UE as the terminal, the base station as the access network equipment, and the AMF and the serviced NF as core network equipment. The UE (NF) sends messages to the NF (UE) through the base station and the AMF. The connection between the AMF and the NF can be based on hop-by-hop security protection. Specifically, messages between the UE and the AMF are transmitted through the base station and are protected by Non-access stratum (NAS) security. The connection between the AMF and the serviced NF is protected by Transport Layer Security (TLS), Network Domain Security (NDS), Internet Protocol (IP), or physical security.
[0136] Alternatively, one possible way to improve the efficiency of new service delivery in future communication networks is to bypass the AMF. In other words, the NF and the base station can connect directly through a service-oriented interface, which can be called a service-oriented RAN architecture. However, in a service-oriented RAN scenario, it is necessary to design a mechanism to protect the communication between the UE and the NF.
[0137] Optionally, this disclosure provides an access layer-based security mechanism for protecting the connection between the UE and the NF in a serviced RAN scenario. Furthermore, to eliminate potential NAS signaling redundancy protection, this disclosure also provides a NAS security control mechanism in a serviced RAN scenario. Based on this NAS security control mechanism, the AMF can disable redundant NAS protection when the UE connects to a serviced base station, and enable NAS protection when the UE connects to a traditional base station (e.g., a non-serviced base station).
[0138] Optionally, under the NAS security control mechanism, the serving base station can perform intra-base station handover during Xn handover and / or N2 handover procedures. Since the key used by the target serving base station is generated by the source legacy base station, the intra-base station handover performed by the serving base station can prevent the source legacy base station from using its own generated key to eavesdrop on unprotected NAS messages.
[0139] Optionally, this disclosure provides an access layer-based security mechanism to protect the connection between the UE and NF in a service-oriented RAN scenario. Additionally, a NAS security control mechanism is provided for the service-oriented RAN scenario to eliminate potentially redundant NAS signaling protection.
[0140] Optionally, as shown in Figure 1C, which is a schematic diagram of another system architecture provided by an embodiment of this disclosure, Figure 1C illustrates the secure interaction mechanism between the UE and NF in a service-oriented RAN scenario. Taking the terminal as the UE, the access network equipment includes: a non-service base station and a service base station, and the core network equipment includes a service-oriented NF for example. For instance, the non-service base station can be a DU. The service base station can be a CU. The service base station and the service-oriented NF are located in a secure environment controlled by the operator. The non-service base station (e.g., a base station deployed at the network edge) is a traditional base station.
[0141] Optionally, in some embodiments, for uplink message transmission: the UE sends NF-related messages to the serving base station via Radio Resource Control (RRC) messages. Specifically, the UE sends an RRC message to a traditional base station, which forwards the RRC message to the serving base station. The serving base station then sends NF-related messages to the serving NF.
[0142] Optionally, in some embodiments, for downlink message transmission: the serving NF sends UE-related messages to the serving base station. The serving base station sends UE-related messages to the UE via RRC messages. Specifically, the serving base station sends RRC messages to the traditional base station, which forwards the RRC messages to the UE. As shown in Figure 1C, the connection between the UE and the serving NF can be based on hop-by-hop security protection. The RRC messages are protected by access layer security. The connection between the serving base station and the serving NF is protected by TLS, NDS, IP, and physical security.
[0143] Optionally, as shown in Figure 1D, which is a schematic diagram of another system architecture provided by an embodiment of this disclosure, Figure 1D illustrates the UE and NF security interaction mechanism in a service-oriented RAN scenario. Taking the terminal as the UE, the access network equipment includes a service-oriented base station, and the core network equipment includes an AMF and a service-oriented NF as examples. In the service-oriented RAN architecture, the UE sends NAS messages to the AMF through the service-oriented RAN. The NAS messages are protected by both AS security and NAS security. However, NAS security is only introduced in base stations deployed in insecure environments. For example, even if an attacker attacks the base station in an insecure environment and decrypts the AS security, the NAS messages can still be protected by NAS security. In the service-oriented RAN architecture, it can be assumed that the service-oriented base station is deployed in a secure environment. For example, the service-oriented base station and the AMF can be deployed in the same data center. Therefore, the service-oriented base station, as the AS security endpoint, can use AS security to protect NAS messages. In this case, NAS protection is redundant. Furthermore, related technologies do not support control over NAS protection, thus affecting the security protection effect.
[0144] Optionally, in the embodiments of this disclosure, "enabled" can also be referred to as "open," "open," "activate," "activate," etc., and there is no limitation thereto.
[0145] Figure 2A is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 2A, the embodiment of the present disclosure relates to a communication method that can be used in a communication system 100. The communication system 100 may include a first access network device and a core network device. The first access network device may be a serving access network device (e.g., a serving base station) or a non-serving access network device (e.g., a non-serving base station). The core network device may be an AMF (Advanced Management Function), and there is no limitation thereto. The above method includes:
[0146] Step S2101: The first access network device sends the first information to the core network device.
[0147] Optionally, in some embodiments, the first access network device may be a serviced access network device (e.g., a serviced base station) or a non-serviced access network device (e.g., a non-serviced base station).
[0148] Alternatively, in some embodiments, the core network device may be an AMF.
[0149] Optionally, in some embodiments, the serving base station may send first information to the AMF.
[0150] Optionally, in some embodiments, the non-servicing base station may send the first information to the AMF.
[0151] Optionally, in some embodiments, the first information is used by the core network device to control NAS protection. Optionally, this embodiment uses the example of the first information being used by the core network device to disable NAS protection, while examples of the first information being used by the core network device to enable NAS protection can be found in subsequent embodiments.
[0152] Optionally, in some embodiments, the first information includes at least one of the following: request information, a first identifier, a handover notification message, and a Next Generation Application Protocol (NGAP) path handover request; wherein the request information is used to request the NAS protection to be disabled. This enables the core network device to accurately decide whether to disable NAS protection, improving the flexibility of NAS protection disabling control. If the core network device decides to disable NAS protection, redundant NAS protection can be effectively avoided, saving resources.
[0153] Optionally, this embodiment uses request information to request the disabling of NAS protection as an example, while examples of requesting the enabling of NAS protection based on request information can be found in subsequent embodiments. Optionally, in some embodiments, request information can be used to request the disabling of NAS protection. For example, the request information can be an indication field, which can be set to one value to indicate a request to disable NAS protection, or the indication field can be set to another value to indicate a request to enable NAS protection.
[0154] The aforementioned first identifier can be used to identify the first access network device. The first identifier can be the identifier (ID), name, etc., of the first access network device. The first information may include a handover notification message (or: N2 handover notification message), which can be used to trigger the shutdown or activation of NAS protection. That is, if the first information includes a handover notification message, it indicates that a device handover has occurred, such as a switch from a third access network device to a first access network device. Before and after the handover, the type of the first access network device and the third access network device may change. For example, a switch from a service-oriented access network device to a non-service-oriented access network device (in this case, the first access network device is a non-service-oriented access network device, while the third access network device is a service-oriented access network device); or a switch from a non-service-oriented access network device to a service-oriented access network device (in this case, the first access network device is a service-oriented access network device, while the third access network device is a non-service-oriented access network device). The first message may include a Next Generation Application Protocol (NGAP) path switching request. The NGAP path switching request is used to trigger the shutdown or activation of NAS protection and can also be used to initiate a path switch. If the first access network device sends a switch notification message and / or an NGAP path switching request to the core network device, the core network device can decide whether to disable NAS protection based on information stored locally.
[0155] Optionally, in some embodiments, the first access network device sends first information to the core network device, and the core network device can receive the first information sent by the first access network device and decide whether to disable NAS protection based on the first information and local policies.
[0156] Optionally, in some embodiments, the serving base station can send first information to the AMF, and the AMF can receive the first information sent by the serving base station and combine the first information with the local policy to decide whether to disable NAS protection.
[0157] Optionally, in some embodiments, the non-servicing base station can send first information to the AMF, and the AMF can receive the first information sent by the non-servicing base station and combine the first information with local policies to decide whether to disable NAS protection.
[0158] Optionally, in some embodiments, the transmission of the first information is triggered based on at least one of the following: the first access network device completes the Access Layer Security Mode Command (AS SMC) procedure; the first access network device completes a handover based on the N2 interface; or the first access network device completes an intra-device handover. Therefore, in all the aforementioned scenarios, it supports triggering the core network device to decide whether to disable NAS protection, thus effectively adapting to personalized communication scenarios and improving the flexibility of NAS protection control.
[0159] Optionally, in some embodiments, after completing the AS SMC process, the first access network device may send first information to the core network device, and the core network device may decide whether to disable NAS protection based on the first information and local policies.
[0160] Optionally, in some embodiments, after the first access network device completes the handover based on the N2 interface, it can send first information to the core network device, and the core network device can decide whether to disable NAS protection based on the first information and local policies.
[0161] Optionally, in some embodiments, after the first access network device completes the intra-device handover, it may send first information to the core network device, and the core network device may decide whether to disable NAS protection based on the first information and local policies.
[0162] Optionally, in some embodiments, the access network device can send an NGAP-based path handover confirmation message to the first access network device. The first access network device can then decide whether to perform an intra-device handover based on whether the NGAP-based path handover confirmation message contains a New Security Context Indicator (NSCI). Additionally, the NGAP-based path handover confirmation message may also contain key update parameters (e.g., a "{NH, NCC} pair"), which can assist the first access network device in performing the intra-device handover. After completing the intra-device handover, the first access network device can send first information to the core network device. Thus, after completing the intra-device handover, the first access network device can promptly and effectively indicate the first information to the core network device, enabling the core network device to decide whether to disable NAS protection based on the first information and local policies, ensuring the efficiency and effectiveness of NAS protection control.
[0163] Optionally, in some embodiments, if the first access network device determines that the "NGAP-based path handover confirmation message" does not include a new Security Context Indicator (NSCI), it can perform an intra-device handover based on the key update parameters. Conversely, if the "NGAP-based path handover confirmation message" includes the NSCI, it may not perform an intra-device handover. This improves the accuracy of the decision on whether to perform an intra-device handover. When an intra-device handover is decided upon, a new KgNB can be exported promptly to enhance security. If an intra-device handover is deemed unnecessary, handover overhead can be effectively saved, ensuring system performance.
[0164] In step S2102, the core network equipment determines the third information.
[0165] The third information refers to information stored locally by the core network device to decide whether to disable or enable NAS protection. Specifically, the third information may be information related to the access network device. Optionally, in this embodiment, the core network device may combine the first information and the third information to decide whether to disable NAS protection. For specific implementation methods of the core network device combining the first information and the third information to decide whether to enable NAS protection, please refer to subsequent embodiments.
[0166] Optionally, in some embodiments, the third information includes at least one of the following: a second identifier, first indication information, second indication information, and switching information; wherein, the second identifier is used to identify the second access network device, the first indication information is used to indicate whether the second access network device is a service-oriented access network device, the second indication information is used to indicate whether the second access network device is located in a secure environment that supports disabling NAS protection, and the switching information is used to indicate a type change between the first and third access network devices, where the first access network device is the switched-off access network device and the third access network device is the original access network device. This effectively improves the accuracy of the decision on whether to disable NAS protection, enabling accurate control of NAS protection and ensuring effective security protection.
[0167] Optionally, in some embodiments, the second identifier refers to a specific access network device (or second access network device). The number of second identifiers can be one or more. The first indication information is used to indicate whether the second access network device is a service-oriented access network device; that is, the first indication information can be used to indicate whether the second identifier stored locally on the core network device indicates whether the identified second access network device is a service-oriented access network device. The first access network device can be determined as a service-oriented access network device by comparing its first identifier and the second identifier of the second access network device, combined with the first indication information. If the first access network device is a service-oriented access network device, NAS protection can be disabled for it; for non-service-oriented access network devices, NAS protection does not need to be disabled, or it can be enabled.
[0168] Optionally, in some embodiments, the second indication information is used to indicate whether the second access network device is located in a secure environment that supports disabling NAS protection. If a secure environment supports disabling NAS protection, it generally indicates a relatively high security level. That is, the second indication information can be used to indicate whether the second access network device, identified by a second identifier stored locally on the core network device, is located in a secure environment. Whether the first access network device is located in a secure environment can be determined by comparing the first identifier of the first access network device and the second identifier of the second access network device, combined with the second indication information. If the first access network device is located in a secure environment, NAS protection can be disabled for it; if the first access network device is not located in a secure environment, NAS protection may not need to be disabled, or it may be enabled.
[0169] Optionally, in some embodiments, the switching information can be used to indicate a type change between the first access network device and the third access network device. Optionally, in some embodiments, the type change can be a switch from a non-service access network device to a service access network device, or a switch from a service access network device to a non-service access network device. The switching information can be information maintained locally by the core network device. When the core network device receives the first information sent by the first access network device, it can decide whether to disable NAS protection based on the first information and the switching information. Optionally, in some embodiments, if the core network device determines that the type change between the first access network device and the third access network device is a switch from a non-service access network device to a service access network device, it can decide to disable NAS protection. Conversely, if the core network device determines that the type change between the first access network device and the third access network device is a switch from a service access network device to a non-service access network device, it can decide not to disable NAS protection or decide to enable NAS protection.
[0170] In step S2103, the core network device determines that the first access network device meets the first condition based on the first information and the third information.
[0171] Optionally, in some embodiments, the first access network device sends first information to the core network device, the core network device can receive the first information sent by the first access network device, the core network device can also determine third information, and decide whether to disable NAS protection based on the first information and the third information.
[0172] Optionally, in some embodiments, the serving base station can send first information to the AMF, the AMF can receive the first information sent by the serving base station, the AMF can also determine third information, and decide whether to disable NAS protection based on the first information and the third information.
[0173] Optionally, in some embodiments, the non-servicing base station can send first information to the AMF, the AMF can receive the first information sent by the non-servicing base station, the AMF can also determine third information, and decide whether to disable NAS protection based on the first information and the third information.
[0174] Optionally, in some embodiments, the first condition refers to the condition under which NAS protection can be disabled. That is, if it is determined based on the first information and the third information that the first access network device meets the first condition, it can be decided to disable NAS protection; if it is determined based on the first information and the third information that the first access network device does not meet the first condition, it can be decided that NAS protection does not need to be disabled, or it can be decided to enable NAS protection.
[0175] Optionally, in some embodiments, the first condition includes at least one of the following: the first access network device is a service-oriented access network device; the first access network device is located in a secure environment; the type change between the first access network device and the third access network device is: switching from a non-service-oriented access network device to a service-oriented access network device. This enables accurate decision-making to disable NAS protection, timely disabling of NAS protection, avoidance of redundant NAS protection configurations, and conservation of resources required for NAS protection, thereby supporting improved system performance.
[0176] Optionally, in some embodiments, "determines that NAS protection does not need to be turned off" can be replaced with "determines that NAS protection is turned on"; "determines that NAS protection needs to be turned off" can be replaced with "determines that NAS protection does not need to be turned on", without limitation.
[0177] Optionally, in some embodiments, if the first access network device is a service-oriented access network device, it may be decided to disable NAS protection.
[0178] Optionally, in some embodiments, if the first access network device is located in a secure environment, it may be decided to disable NAS protection.
[0179] Optionally, in some embodiments, if the type change between the first access network device and the third access network device is from a non-service access network device to a service access network device, then it can be decided to disable NAS protection.
[0180] Optionally, in some embodiments, if the first access network device is a service-oriented access network device and the first access network device is located in a secure environment, it can be decided to disable NAS protection.
[0181] Optionally, in some embodiments, if the first access network device is a non-service access network device, and / or the first access network device is not located in a secure environment, it may be decided not to disable NAS protection.
[0182] Optionally, in some embodiments, if the first access network device is a non-service access network device, and / or the first access network device is not located in a secure environment, then it may be decided to enable NAS protection.
[0183] Optionally, in some embodiments, the core network device may decide whether the first access network device meets the first condition based on the first information and the third information. If the first access network device meets the first condition, it is decided that NAS protection needs to be turned off. If the first access network device does not meet the first condition, it is decided that NAS protection does not need to be turned off, or that NAS protection can be turned on.
[0184] Optionally, in some embodiments, if the first identifier and the second identifier are the same, and the first indication information indicates that the second access network device is a service-oriented access network device, then the first access network device is determined to be a service-oriented access network device. That is, if the first identifier of the first access network device is the same as the second identifier (identifying a specific second access network device) maintained locally by the core network device, then the first access network device and the second access network device are determined to be the same access network device. At the same time, if the first indication information indicates that the second access network device is a service-oriented access network device, then the first access network device is determined to be a service-oriented access network device. In this case, it can be determined that the first access network device meets the first condition, and a decision is made to disable NAS protection.
[0185] Optionally, in some embodiments, if the first identifier and the second identifier are the same, and the second indication information indicates that the second access network device is located in a secure environment, then the first access network device is determined to be located in a secure environment. That is, if the first identifier of the first access network device is the same as the second identifier (identifying a specific second access network device) maintained locally by the core network device, then the first access network device and the second access network device are determined to be the same access network device. At the same time, if the second indication information indicates that the second access network device is located in a secure environment, then the first access network device is determined to be located in a secure environment. In this case, it can be determined that the first access network device meets the first condition, and a decision is made to disable NAS protection.
[0186] Optionally, in some embodiments, if the first identifier and the second identifier are the same, and the second indication information indicates that the second access network device is not located in a secure environment, then it is determined that the first access network device is not located in a secure environment. That is, if the first identifier of the first access network device is the same as the second identifier (identifying a specific second access network device) maintained locally by the core network device, then it is determined that the first access network device and the second access network device are the same access network device. At the same time, if the second indication information indicates that the second access network device is not located in a secure environment, then it is determined that the first access network device is not located in a secure environment. In this case, it can be determined that the first access network device does not meet the first condition, and the decision is made whether to disable NAS protection or to enable NAS protection.
[0187] Optionally, in some embodiments, if the first information includes a handover notification message or an NGAP path handover request, and the third information maintained locally by the core network device includes handover information, and the handover information indicates that the type change between the first access network device and the third access network device is from a non-service access network device to a service access network device, then it can be determined that the first access network device meets the first condition, and the decision is made to disable NAS protection.
[0188] Optionally, in some embodiments, if the first information includes a handover notification message or an NGAP path handover request, and the third information maintained locally by the core network device includes handover information, and the handover information indicates that the type change between the first access network device and the third access network device is from a service-oriented access network device to a non-service-oriented access network device, then it can be determined that the first access network device does not meet the first condition, and the decision is made not to disable NAS protection or to enable NAS protection.
[0189] Step S2104: Disable NAS protection on the core network device.
[0190] Optionally, in some embodiments, the core network device may disable NAS protection if it determines that the first access network device meets the first condition based on the first information and the third information.
[0191] Optionally, in some embodiments, the AMF may disable NAS protection if it determines that the first information and the third information satisfy the first condition.
[0192] Optionally, in some other embodiments, steps S2103 and S2104 may be omitted, and the following steps may be performed instead: The core network device determines, based on the first information and the third information, that the first access network device does not meet the first condition; the core network device detects that NAS protection has been enabled; therefore, the core network device does not need to disable NAS protection. Alternatively, the core network device determines, based on the first information and the third information, that the first access network device does not meet the first condition; the core network device detects that NAS protection is not enabled; therefore, the core network device enables NAS protection.
[0193] In step S2105, the core network device sends the second information to the first access network device.
[0194] The second information is used to indicate information related to NAS protection. Optionally, in some embodiments, after the core network device disables NAS protection, it can send the second information to the first access network device, the second information being used to indicate information related to NAS protection.
[0195] Optionally, in some embodiments, after disabling NAS protection, the AMF may send second information to the first access network device, the second information being used to indicate information related to NAS protection.
[0196] Optionally, in some embodiments, the second information includes any one of the following: third indication information and a first reason; wherein the third indication information is used to indicate that NAS protection has been disabled; and the first reason is used to indicate the reason why NAS protection was not successfully disabled. This enables timely indication of NAS protection-related information to the first access network device, allowing the first access network device to effectively obtain NAS protection-related information and take appropriate follow-up measures, thus making it applicable to various communication scenarios.
[0197] The aforementioned third indication information can be used to indicate that NAS protection has been disabled. Reasons for unsuccessfully disabling NAS protection may include, for example, that the first access network device is a non-service access network device, and / or the first access network device is not located in a secure environment; that is, the environment in which the first access network device is located does not support disabling NAS protection, and / or the type change between the first and third access network devices is from a service access network device to a non-service access network device, without restriction.
[0198] The communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2105. For example, steps S2101, S2102, S2103, S2104, and S2105 can each be implemented as an independent embodiment; steps S2101+S2102 can be implemented as an independent embodiment; steps S2101+S2103 can be implemented as an independent embodiment; steps S2101+S2104 can be implemented as an independent embodiment; steps S2101+S2105 can be implemented as an independent embodiment; steps S2102+S2103 can be implemented as an independent embodiment; steps S2102+S2104 can be implemented as an independent embodiment; steps S2103+S2105 can be implemented as an independent embodiment; and steps S2104+S2105 can be implemented as an independent embodiment. Steps S2105, S2101, S2102, S2103, S2104, S2101, S2102, S2105, S2101, S2103, S2104, S2101, S2103, S2105, S2101, S2103, S2104, S2101, S2103, S2105, S2102, S2103, S2104, S2102, S2103, S2105, S2102, S2103, S2104, S2105, etc., can be implemented as independent embodiments, but are not limited thereto.
[0199] In the embodiments of this disclosure, some or all of the steps, and their optional implementations, can be arbitrarily combined with some or all of the steps in other embodiments, or arbitrarily combined with the optional implementations in other embodiments. In the embodiments of this disclosure, each step and its optional implementation can also be implemented independently.
[0200] In this embodiment, the first access network device sends first information to the core network device. This first information is used by the core network device to control NAS protection. The core network device determines third information and, based on the first and third information, determines that the first access network device meets a first condition, disables NAS protection, and then sends second information to the first access network device. This second information indicates information related to NAS protection. Therefore, NAS protection can be disabled promptly and effectively. While ensuring security protection, redundant NAS protection configurations can be avoided, thus effectively saving the resources required for NAS protection.
[0201] It should be noted that in the following embodiments, the descriptions of the same or corresponding terms and method steps as in the above embodiments can be found in the above embodiments, and will not be repeated here.
[0202] Figure 2B is an interactive schematic diagram of a communication method according to another embodiment of the present disclosure. As shown in Figure 2B, the embodiments of the present disclosure relate to a communication method that can be used in a communication system 100. The communication system 100 may include a first access network device and a core network device. The first access network device may be a serving access network device (e.g., a serving base station) or a non-serving access network device (e.g., a non-serving base station). The core network device may be an AMF (Advanced Management Function), and there is no limitation thereto. The above method includes:
[0203] Step S2201: The first access network device sends the first information to the core network device.
[0204] Optionally, in some embodiments, the first access network device may be a serviced access network device (e.g., a serviced base station) or a non-serviced access network device (e.g., a non-serviced base station).
[0205] Alternatively, in some embodiments, the core network device may be an AMF.
[0206] Optionally, in some embodiments, the serving base station may send first information to the AMF.
[0207] Optionally, in some embodiments, the non-servicing base station may send the first information to the AMF.
[0208] Optionally, in this embodiment, the first information is used by the core network device to determine whether to enable NAS protection.
[0209] Optionally, in some embodiments, the first information can be used by the AMF to determine whether to enable NAS protection.
[0210] Optionally, in some embodiments, the first information includes at least one of the following: request information, a first identifier, a handover notification message, and an NGAP path handover request; wherein the request information is used to request the activation of NAS protection. This enables the core network device to accurately determine whether to enable NAS protection, improving the flexibility of NAS protection activation control. If the core network device decides to enable NAS protection, it can improve security protection performance.
[0211] Optionally, in some embodiments, the first access network device sends first information to the core network device, and the core network device can receive the first information sent by the first access network device and combine the first information with local policies to decide whether to enable NAS protection.
[0212] Optionally, in some embodiments, the serving base station can send first information to the AMF, and the AMF can receive the first information sent by the serving base station and combine the first information with local policies to determine whether to enable NAS protection.
[0213] Optionally, in some embodiments, enabling NAS protection may include: enabling NAS confidentiality activation and / or enabling NAS integrity protection activation.
[0214] Optionally, in some embodiments, the non-servicing base station can send first information to the AMF, and the AMF can receive the first information sent by the non-servicing base station and combine the first information with local policies to decide whether to activate (deactivate) NAS protection.
[0215] Optionally, in some embodiments, the transmission of the first information is triggered based on at least one of the following: the first access network device completes the Access Layer Security Mode Command (AS SMC) procedure; the first access network device completes a handover based on the N2 interface; or the first access network device completes an intra-device handover. Therefore, in all the aforementioned scenarios, it supports triggering the core network device to decide whether to enable NAS protection, thus effectively adapting to personalized communication scenarios and improving the flexibility of NAS protection control.
[0216] Optionally, in some embodiments, after completing the AS SMC process, the first access network device may send first information to the core network device, and the core network device may decide whether to enable NAS protection based on the first information and local policies.
[0217] Optionally, in some embodiments, after the first access network device completes the handover based on the N2 interface, it can send first information to the core network device, and the core network device can decide whether to enable NAS protection based on the first information and local policies.
[0218] Optionally, in some embodiments, the first access network device sends a handover notification message to the core network device, and the core network device can decide whether to enable NAS protection based on the handover notification message and local policies.
[0219] Optionally, in some embodiments, after the first access network device completes the intra-device handover, it may send first information to the core network device, and the core network device may decide whether to enable NAS protection based on the first information and local policies.
[0220] In step S2202, the core network equipment determines the third information.
[0221] Optionally, in this embodiment, the core network device can combine the first information and the third information to decide whether to enable NAS protection.
[0222] In step S2203, the core network device determines, based on the first information and the third information, that the first access network device does not meet the first condition.
[0223] Optionally, in some embodiments, the first access network device sends first information to the core network device, the core network device can receive the first information sent by the first access network device, the core network device can also determine third information, and decide whether to enable NAS protection based on the first information and the third information.
[0224] Optionally, in some embodiments, the serving base station can send first information to the AMF, the AMF can receive the first information sent by the serving base station, the AMF can also determine third information, and decide whether to enable NAS protection based on the first information and the third information.
[0225] Optionally, in some embodiments, the non-servicing base station can send first information to the AMF, the AMF can receive the first information sent by the non-servicing base station, the AMF can also determine third information, and decide whether to enable NAS protection based on the first information and the third information.
[0226] Optionally, in some embodiments, the first condition includes at least one of the following: the first access network device is a service-oriented access network device; the first access network device is located in a secure environment; the type change between the first access network device and the third access network device is: switching from a non-service-oriented access network device to a service-oriented access network device. This enables accurate decision-making on whether to enable NAS protection, supports timely activation of NAS protection, and thereby improves security performance.
[0227] Optionally, in some embodiments, if the first access network device is a non-service access network device, it may be decided that NAS protection needs to be enabled.
[0228] Optionally, in some embodiments, if the first access network device is not located in a secure environment, it may be decided to enable NAS protection.
[0229] Optionally, in some embodiments, if the type change between the first access network device and the third access network device is from a service-oriented access network device to a non-service-oriented access network device, then it can be determined that NAS protection needs to be enabled.
[0230] Optionally, in some embodiments, the core network device may decide whether the first access network device meets the first condition based on the first information and the third information. If the first access network device meets the first condition, the decision is made that NAS protection does not need to be enabled. If the first access network device does not meet the first condition, the decision is made that NAS protection needs to be enabled.
[0231] Step S2204: Enable NAS protection for core network devices.
[0232] Optionally, in some embodiments, the core network device may enable NAS protection if it determines, based on the first information and the third information, that the first access network device does not meet the first condition.
[0233] Optionally, in some embodiments, the AMF may enable NAS protection if it determines that the first information and the third information do not meet the first condition.
[0234] In step S2205, the core network device sends the second information to the first access network device.
[0235] The second information is used to indicate information related to NAS protection. Optionally, in some embodiments, after enabling NAS protection, the core network device can send the second information to the first access network device, the second information being used to indicate information related to NAS protection.
[0236] Optionally, in some embodiments, after enabling NAS protection, the AMF may send second information to the first access network device, the second information being used to indicate information related to NAS protection.
[0237] Optionally, in some embodiments, the second information includes any one of the following: a fourth indication information and a second reason; wherein the fourth indication information is used to indicate that NAS protection has been enabled; and the second reason is used to indicate the reason why NAS protection was not successfully enabled. This enables timely indication of NAS protection-related information to the first access network device, allowing the first access network device to effectively obtain NAS protection-related information and take appropriate follow-up measures, thus making it applicable to various communication scenarios.
[0238] The aforementioned fourth indication information can be used to indicate that NAS protection has been enabled. Reasons for unsuccessfully enabling NAS protection may include, for example, that the first access network device is a service-oriented access network device, and / or that the first access network device is located in a secure environment, meaning the environment in which the first access network device is located supports disabling NAS protection, and / or that the type change between the first and third access network devices is a switch from a non-service-oriented access network device to a service-oriented access network device, without restriction.
[0239] The communication method involved in the embodiments of this disclosure may include at least one of steps S2201 to S2205. For example, steps S2201, S2202, S2203, S2204, and S2205 can each be implemented as an independent embodiment. Steps S2201+S2202, S2203, S2204, and S2205 can be implemented as independent embodiments. Steps S2202+S2203, S2202+S2204, S2202+S2205, S2203+S2204, and S2205 can be implemented as independent embodiments. Step S2202+S2205 can be implemented as an independent embodiment. Steps S2201+S2202+S2203, S2204, S2201+S2202+S2205, S2201+S2203+S2204, S2201+S2203+S2205, S2201+S2203+S2204, S2201+S2203+S2205, S2202+S2203+S2204, S2202+S2203+S2205, S2202+S2203+S2204+S2205, etc., can be implemented as independent embodiments, but are not limited thereto.
[0240] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.
[0241] In the embodiments disclosed herein, each step and its optional implementation can also be carried out independently.
[0242] In this embodiment, the first access network device sends first information to the core network device. This first information is used by the core network device to control NAS protection. The core network device determines third information and, based on the first and third information, determines that the first access network device does not meet the first condition, activates NAS protection, and then sends second information to the first access network device. This second information is used to indicate information related to NAS protection. Therefore, NAS protection can be activated promptly and effectively, improving security protection.
[0243] Figure 3 is an interactive schematic diagram illustrating a communication method according to yet another embodiment of the present disclosure. As shown in Figure 3, the embodiments of the present disclosure relate to a communication method that can be used in core network equipment. The method includes:
[0244] Step S3101: Receive the first information sent by the first access network device.
[0245] Step S3102: Control the non-access stratum NAS protection according to the first information.
[0246] The communication method involved in the embodiments of this disclosure may include at least one of steps S3101 to S3102. For example, steps S3101, S3102, etc., may be implemented as independent embodiments, and steps S3101+S3102 may be implemented as independent embodiments, but are not limited thereto.
[0247] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.
[0248] In the embodiments disclosed herein, each step and its optional implementation can also be carried out independently.
[0249] Optionally, in some embodiments of this disclosure, the method further includes:
[0250] Send a second message to the first access network device, wherein the second message is used to indicate information related to NAS protection.
[0251] Optionally, in some embodiments of this disclosure, the first information includes at least one of the following:
[0252] Request information, which is used to request whether to disable or enable NAS protection;
[0253] The first identifier is used to identify the first access network device;
[0254] Toggle notification messages;
[0255] Next-Generation Application Protocol (NGAP) path switching request.
[0256] Optionally, in some embodiments of this disclosure, NAS protection is controlled based on first information, including:
[0257] NAS protection is controlled based on the first and third information, where the third information is related to the access network equipment.
[0258] Optionally, in some embodiments of this disclosure, the third information includes at least one of the following:
[0259] The second identifier is used to identify the second access network device;
[0260] The first indication information is used to indicate whether the second access network device is a service-oriented access network device;
[0261] The second indication information is used to indicate whether the second access network device is in a secure environment, and the secure environment supports disabling NAS protection.
[0262] The handover information indicates a type change between the first access network device and the third access network device, where the first access network device is the access network device after the handover and the third access network device is the access network device before the handover.
[0263] Optionally, in some embodiments of this disclosure, NAS protection is controlled based on first information and third information, including:
[0264] Based on the first and third information, it is determined that the first access network device meets the first condition, and NAS protection is turned off.
[0265] Based on the first and third information, it is determined that the first access network device does not meet the first condition, so NAS protection is enabled.
[0266] The first condition includes at least one of the following:
[0267] The first access network device is a service-oriented access network device;
[0268] The first access network device is located in a secure environment;
[0269] The type change between the first access network device and the third access network device is: switching from a non-service access network device to a service access network device.
[0270] Optionally, in some embodiments of this disclosure, determining that the first access network device meets the first condition based on the first information and the third information includes at least one of the following:
[0271] The first identifier and the second identifier are the same, and the first indication information indicates that the second access network device is a service-oriented access network device, thus determining that the first access network device is a service-oriented access network device;
[0272] The first identifier and the second identifier are the same, and the second indication information indicates that the second access network device is located in a safe environment, thus determining that the first access network device is located in a safe environment;
[0273] The first information includes a handover notification message or an NGAP path handover request, and the handover information contained in the third information indicates that the type change between the first access network device and the third access network device is: a handover from a non-service access network device to a service access network device.
[0274] Optionally, in some embodiments of this disclosure, the second information includes any of the following:
[0275] The third instruction information is used to indicate that NAS protection has been turned off;
[0276] The first reason, where the first reason is used to indicate the reason why NAS protection was not successfully turned off.
[0277] The fourth instruction information is used to indicate that NAS protection has been enabled;
[0278] The second reason, where the second reason is used to indicate the reason why NAS protection was not successfully enabled.
[0279] Optionally, in some embodiments of this disclosure, the transmission of the first information is triggered based on at least one of the following:
[0280] The first access network device completes the access layer security mode command (AS SMC) procedure.
[0281] The first access network device completes the handover based on the N2 interface;
[0282] The first access network device completes the intra-device handover.
[0283] Figure 4 is an interactive schematic diagram illustrating a communication method according to yet another embodiment of the present disclosure. As shown in Figure 4, the embodiments of the present disclosure relate to a communication method that can be used in a first access network device. The method includes:
[0284] Step S4101: Send first information to the core network device, wherein the first information is used by the core network device to control the non-access stratum NAS protection.
[0285] The communication method involved in the embodiments of this disclosure may include step S4101. For example, step S4101 may be implemented as a standalone embodiment, but is not limited thereto.
[0286] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.
[0287] In the embodiments disclosed herein, each step and its optional implementation can also be carried out independently.
[0288] Optionally, in some embodiments of this disclosure, the method further includes:
[0289] Receive second information sent by the core network device, wherein the second information is used to indicate information related to NAS protection.
[0290] Optionally, in some embodiments of this disclosure, the first information includes at least one of the following:
[0291] Request information, which is used to request whether to disable or enable NAS protection;
[0292] The first identifier is used to identify the first access network device;
[0293] Toggle notification messages;
[0294] Next-Generation Application Protocol (NGAP) path switching request.
[0295] Optionally, in some embodiments of this disclosure, the second information includes any of the following:
[0296] The third instruction information is used to indicate that NAS protection has been turned off;
[0297] The first reason, where the first reason is used to indicate the reason why NAS protection was not successfully turned off.
[0298] The fourth instruction information is used to indicate that NAS protection has been enabled;
[0299] The second reason, where the second reason is used to indicate the reason why NAS protection was not successfully enabled.
[0300] Optionally, in some embodiments of this disclosure, sending first information to the core network device includes at least one of the following:
[0301] Complete the Access Layer Security Mode Command (AS SMC) procedure and send the first information to the core network equipment;
[0302] Complete the handover based on the N2 interface and send the first information to the core network equipment;
[0303] After completing the intra-device handover, the first information is sent to the core network equipment.
[0304] Optionally, in some embodiments of this disclosure, the method further includes:
[0305] If the path handover confirmation message based on NGAP does not include the new security context indicator (NSCI), perform an intra-device handover and send the first information to the core network device after the intra-device handover is completed.
[0306] Figure 5 is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure. As shown in Figure 5, the embodiments of the present disclosure relate to a communication method that can be used in a communication system, which may include: a core network device and a first access network device. The above method includes:
[0307] Step S5101: The first access network device sends first information to the core network device, wherein the first information is used by the core network device to control the non-access stratum NAS protection.
[0308] In step S5102, the core network device controls the non-access layer NAS protection based on the first information.
[0309] The communication method involved in the embodiments of this disclosure may include at least one of steps S5101 to S5102. For example, steps S5101, S5102, etc. may be implemented as independent embodiments, and steps S5101+S5102 may be implemented as independent embodiments, but are not limited thereto.
[0310] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.
[0311] In the embodiments disclosed herein, each step and its optional implementation can also be carried out independently.
[0312] The following is an exemplary description of the above method.
[0313] Optionally, the following embodiments are available:
[0314] As shown in Figure 6A, which is a control schematic diagram of an embodiment of this disclosure, NAS protection can be disabled after the AS SMC process is completed. An example is provided using the terminal as the UE, the first access network device as the serving base station, and the core network device as the AMF.
[0315] 1a. Execute the NAS Security Mode Command (SMC) procedure between the UE and AMF.
[0316] 2a. Perform the Access Stratum (AS) SMC procedure between the UE and the servicing base station.
[0317] 3a. Service-oriented base stations can send a request message to AMF to disable NAS protection.
[0318] Optionally, in some embodiments, if the AS SMC procedure is executed by the serving base station, and the AS SMC procedure is successful, the serving base station may send a request message to the AMF to disable NAS protection.
[0319] 4a. The AMF triggers the NAS SMC process to activate the NULL integrity protection algorithm and the NULL ciphering algorithm.
[0320] Optionally, in some embodiments, it is assumed that the AMF locally stores information about whether a particular base station is a serving base station and whether the serving base station is located in a secure environment. If the serving base station sends a request to disable NAS protection and the base station is in a secure environment, the AMF can trigger the NAS SMC procedure to activate the null integrity protection algorithm and the null encryption algorithm.
[0321] 5a. The AMF sends a NAS protection shutdown response message to the service base station.
[0322] Optionally, in some embodiments, the AMF sends a NAS protection shutdown response message to the serving base station. This response can indicate that NAS protection has been successfully disabled.
[0323] Optionally, in some other embodiments, if the NAS protection shutdown request message is sent by a non-servicing base station (another optional example of the first access network device), the NAS protection shutdown response message may include failure information. The failure information may indicate the reason for the failure to shut down NAS protection, for example, that only serving base stations are supported in triggering the NAS protection shutdown request message.
[0324] As shown in Figure 6B, which is another control schematic diagram in an embodiment of this disclosure, NAS protection can be disabled after the Xn handover is completed. Taking the terminal as the UE, the access network equipment includes a source traditional base station (an optional example of a third access network equipment) and a target serving base station (an optional example of a first access network equipment), and the core network equipment is exemplified as an AMF.
[0325] 1b. Signaling handover is completed between the UE and the source traditional base station and the target service base station.
[0326] Optionally, in some embodiments, handover signaling with the UE can be completed in order to switch from the source traditional base station to the target serving base station.
[0327] 2b. The target service base station sends an NGAP path handover request message to the AMF.
[0328] 3b. The AMF sends an NGAP path handover confirmation message to the target serving base station.
[0329] Optionally, in some embodiments, the NGAP path switching confirmation message may include a key update parameter pair "{NH, NCC}".
[0330] 4b. The target service base station performs intra-base station handover.
[0331] Optionally, in some embodiments, since the source legacy base station knows the key of the target serving base station, if the NGAP path handover confirmation message does not contain a New Security Context Indicator (NSCI), the target serving base station uses the newly received "{NH, NCC} pair" to perform an intra-base station handover to derive a new KgNB, thereby achieving forward security against the source legacy base station.
[0332] 5b. The target service base station can send a request message to AMF to disable NAS protection.
[0333] Optionally, in some embodiments, after completing the intra-base station handover, the target serving base station sends a request message to the AMF to disable NAS protection.
[0334] 6b. AMF triggers the NAS SMC process to activate the null integrity protection algorithm and the null encryption algorithm.
[0335] Optionally, in some embodiments, upon receiving a request to disable NAS protection, the AMF determines whether to disable NAS protection in the same manner as step 4a in Figure 6A above.
[0336] 7b. The AMF sends a NAS protection shutdown response message to the target service base station.
[0337] Optionally, in some embodiments, this step is the same as step 5a in FIG6A above.
[0338] As shown in Figure 6C, which is another control schematic diagram in an embodiment of this disclosure, NAS protection can be disabled after the N2 handover is completed. Taking the terminal as the UE, the first access network device can be, for example, the target serving base station, and the core network device as the target AMF, as an example.
[0339] 1c. The target serving base station sends a handover notification message to the target AMF.
[0340] 2c. The target AMF triggers the NAS SMC process to activate the null integrity protection algorithm and the null encryption algorithm.
[0341] Optionally, in some embodiments, when the target AMF receives a handover notification message, the target AMF checks the conditions for disabling NAS protection. If it is a handover from a source legacy base station to a target serving base station, the target AMF determines whether to disable NAS protection, or determines whether to disable NAS protection in the same manner as step 4a in Figure 6A above. The target AMF may trigger the NAS SMC procedure to activate the null integrity protection algorithm and the null encryption algorithm.
[0342] As shown in Figure 6D, which is another control schematic diagram in an embodiment of this disclosure, NAS protection can be enabled after the Xn handover process is completed. Taking the terminal as the UE, the access network equipment includes a source serving base station (an optional example of a third access network equipment) and a target traditional base station (an optional example of a first access network equipment), and the core network equipment is exemplified as an AMF.
[0343] 1d. Complete the handover signaling interaction with the UE.
[0344] Optionally, in some embodiments, handover signaling with the UE is completed in order to switch from the source serving base station to the target legacy base station.
[0345] 2d. The target traditional base station sends an NGAP path switching request message to the AMF.
[0346] Option 1 can be executed:
[0347] 3d(a) The AMF check meets the conditions for enabling NAS protection.
[0348] Optionally, in some embodiments, before the AMF sends the NGAP path handover confirmation message, the AMF checks the conditions for enabling NAS protection. If it is a case of a source serving base station switching to a target legacy base station, the AMF determines to enable NAS protection.
[0349] 4d(a) AMF triggers the NAS SMC process to activate the non-empty integrity protection algorithm and the non-empty encryption algorithm.
[0350] 5d(a) The AMF sends an NGAP path handover confirmation message to the target traditional base station.
[0351] Option 2 can be executed:
[0352] 5d(b) The AMF sends an NGAP path handover confirmation message to the target traditional base station.
[0353] 6d(b) The AMF check meets the conditions for enabling NAS protection.
[0354] Optionally, in some embodiments, after the AMF sends the NGAP path handover confirmation message, the AMF checks the conditions for enabling NAS protection. If it is a handover from a source serving base station to a target legacy base station, the AMF determines to enable NAS protection.
[0355] 7d(b) AMF triggers the NAS SMC process to activate the non-empty integrity protection algorithm and the non-empty encryption algorithm.
[0356] As shown in Figure 6E, which is another control schematic diagram in an embodiment of this disclosure, NAS protection can be enabled after the N2 handover process is completed. An example is provided with the terminal as the UE, the first access network device as such (e.g., the target traditional base station), and the core network device as the target AMF.
[0357] 1e. The target traditional base station sends a handover notification message to the target AMF.
[0358] 2e. AMF triggers the NAS SMC process to activate the non-empty integrity protection algorithm and the non-empty encryption algorithm.
[0359] Optionally, in some embodiments, when a handover notification message is received, the AMF checks the conditions for enabling NAS protection. If it is a case of a source serving base station handing over to a target legacy base station, the AMF determines whether to enable NAS protection or disable NAS protection in the same manner as step 4a in Figure 6A above. The AMF triggers the NAS SMC procedure to activate the non-empty integrity protection algorithm and the non-empty encryption algorithm.
[0360] The method provided in this disclosure offers an access layer-based security mechanism that can protect the connection between a terminal (e.g., UE) and network functions (e.g., NF) in a service-oriented RAN scenario. Furthermore, to avoid redundant protection of NAS signaling, a NAS security control mechanism for service-oriented RAN scenarios is also provided.
[0361] This disclosure also provides embodiments of an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Furthermore, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., a RAN) in any of the above methods.
[0362] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0363] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).
[0364] Figure 7 is a schematic diagram of the structure of a communication device proposed in an embodiment of this disclosure. As shown in Figure 7, the communication device 7100 may include at least one of a transceiver module 7101, a processing module 7102, etc.
[0365] In some embodiments, the communication device 7100 is a core network device, wherein...
[0366] The transceiver module 7101 is used to receive the first information sent by the first access network device.
[0367] The processing module 7102 is used to control the non-access stratum NAS protection based on the first information.
[0368] Optionally, in some embodiments of this disclosure, the transceiver module 7101 is used to send second information to the first access network device, wherein the second information is used to indicate information related to NAS protection.
[0369] Optionally, in some embodiments of this disclosure, the first information includes at least one of the following:
[0370] Request information, which is used to request whether to disable or enable NAS protection;
[0371] The first identifier is used to identify the first access network device;
[0372] Toggle notification messages;
[0373] Next-Generation Application Protocol (NGAP) path switching request.
[0374] Optionally, in some embodiments of this disclosure, the processing module 7102 is configured to:
[0375] NAS protection is controlled based on the first and third information, where the third information is related to the access network equipment.
[0376] Optionally, in some embodiments of this disclosure, the third information includes at least one of the following:
[0377] The second identifier is used to identify the second access network device;
[0378] The first indication information is used to indicate whether the second access network device is a service-oriented access network device;
[0379] The second indication information is used to indicate whether the second access network device is in a secure environment, and the secure environment supports disabling NAS protection.
[0380] The handover information indicates a type change between the first access network device and the third access network device, where the first access network device is the access network device after the handover and the third access network device is the access network device before the handover.
[0381] Optionally, in some embodiments of this disclosure, the processing module 7102 is configured to:
[0382] Based on the first and third information, it is determined that the first access network device meets the first condition, and NAS protection is turned off.
[0383] Based on the first and third information, it is determined that the first access network device does not meet the first condition, so NAS protection is enabled.
[0384] The first condition includes at least one of the following:
[0385] The first access network device is a service-oriented access network device;
[0386] The first access network device is located in a secure environment;
[0387] The type change between the first access network device and the third access network device is: switching from a non-service access network device to a service access network device.
[0388] Optionally, in some embodiments of this disclosure, the processing module 7102 is configured to perform at least one of the following:
[0389] The first identifier and the second identifier are the same, and the first indication information indicates that the second access network device is a service-oriented access network device, thus determining that the first access network device is a service-oriented access network device;
[0390] The first identifier and the second identifier are the same, and the second indication information indicates that the second access network device is located in a safe environment, thus determining that the first access network device is located in a safe environment;
[0391] The first information includes a handover notification message or an NGAP path handover request, and the handover information contained in the third information indicates that the type change between the first access network device and the third access network device is: a handover from a non-service access network device to a service access network device.
[0392] Optionally, in some embodiments of this disclosure, the second information includes any of the following:
[0393] The third instruction information is used to indicate that NAS protection has been turned off;
[0394] The first reason, where the first reason is used to indicate the reason why NAS protection was not successfully turned off.
[0395] The fourth instruction information is used to indicate that NAS protection has been enabled;
[0396] The second reason, where the second reason is used to indicate the reason why NAS protection was not successfully enabled.
[0397] Optionally, in some embodiments of this disclosure, the transmission of the first information is triggered based on at least one of the following:
[0398] The first access network device completes the access layer security mode command (AS SMC) procedure.
[0399] The first access network device completes the handover based on the N2 interface;
[0400] The first access network device completes the intra-device handover.
[0401] Optionally, the transceiver module described above is used to perform at least one of the communication steps such as sending and / or receiving performed by the core network device in any of the above methods, which will not be elaborated here.
[0402] Optionally, the above processing module is used to perform at least one of the other steps performed by the core network device in any of the above methods, which will not be elaborated here.
[0403] In some embodiments, the communication device 7100 is a first access network device, wherein...
[0404] The transceiver module 7101 is used to send first information to the core network device, wherein the first information is used by the core network device to control the non-access stratum NAS protection.
[0405] Optionally, in some embodiments of this disclosure, the transceiver module 7101 is configured to receive second information sent by the core network device, wherein the second information is used to indicate information related to NAS protection.
[0406] Optionally, in some embodiments of this disclosure, the first information includes at least one of the following:
[0407] Request information, which is used to request whether to disable or enable NAS protection;
[0408] The first identifier is used to identify the first access network device;
[0409] Toggle notification messages;
[0410] Next-Generation Application Protocol (NGAP) path switching request.
[0411] Optionally, in some embodiments of this disclosure, the second information includes any of the following:
[0412] The third instruction information is used to indicate that NAS protection has been turned off;
[0413] The first reason, where the first reason is used to indicate the reason why NAS protection was not successfully turned off.
[0414] The fourth instruction information is used to indicate that NAS protection has been enabled;
[0415] The second reason, where the second reason is used to indicate the reason why NAS protection was not successfully enabled.
[0416] Optionally, in some embodiments of this disclosure, the transceiver module 7101 is configured to perform at least one of the following:
[0417] Complete the Access Layer Security Mode Command (AS SMC) procedure and send the first information to the core network equipment;
[0418] Complete the handover based on the N2 interface and send the first information to the core network equipment;
[0419] After completing the intra-device handover, the first information is sent to the core network equipment.
[0420] Optionally, in some embodiments of this disclosure, the processing module 7102 is used to determine that the path handover confirmation message based on NGAP does not include a new security context indicator (NSCI) and to perform an intra-device handover; the transceiver module 7101 is used to send first information to the core network device after the intra-device handover is completed.
[0421] Optionally, the transceiver module is used to perform at least one of the communication steps such as sending and / or receiving performed by the first access network device in any of the above methods, which will not be elaborated here.
[0422] Optionally, the above processing module is used to perform at least one of the other steps performed by the first access network device in any of the above methods, which will not be elaborated here.
[0423] Figure 8A is a schematic diagram of the structure of the communication device proposed in an embodiment of this disclosure. The communication device 8100 can be an access network device, a core network device, etc., or it can be a chip, chip system, or processor that supports the access network device in implementing any of the above methods, or it can be a chip, chip system, or processor that supports the core network device in implementing any of the above methods. The communication device 8100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0424] As shown in Figure 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. The communication device 8100 is used to execute any of the above methods.
[0425] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may also be located outside the communication device 8100.
[0426] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceivers 8103 perform at least one of the communication steps such as sending and / or receiving in the above method, and the processor 8101 performs other steps.
[0427] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.
[0428] In some embodiments, the communication device 8100 may include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected to the memory 8102, and the interface circuit 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0429] The communication device 8100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 8100 described in this disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG8A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0430] Figure 8B is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. For cases where the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of the chip 8200 shown in Figure 8B, but it is not limited thereto.
[0431] Chip 8200 includes one or more processors 8201, which are used to perform any of the above methods.
[0432] In some embodiments, chip 8200 further includes one or more interface circuits 8202. Optionally, the interface circuit 8202 is connected to memory 8203, and the interface circuit 8202 can be used to receive signals from memory 8203 or other devices, and the interface circuit 8202 can be used to send signals to memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in memory 8203 and send the instructions to processor 8201.
[0433] In some embodiments, the interface circuit 8202 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processor 8201 performs at least one of the other steps.
[0434] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.
[0435] In some embodiments, chip 8200 further includes one or more memories 8203 for storing instructions. Optionally, all or part of the memories 8203 may be located outside of chip 8200.
[0436] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device 8100, cause the communication device 8100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0437] This disclosure also provides a program product that, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0438] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
[0439] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).
[0440] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0441] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0442] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. A communication method characterized by comprising: The method is executed by a core network device, and the method includes: Receive the first information sent by the first access network device; Based on the first information, control is applied to the protection of the non-access stratum NAS.
2. The method of claim 1, wherein, The method further includes: Send a second message to the first access network device, wherein the second message is used to indicate information related to the NAS protection.
3. The method according to any one of claims 1 to 2, wherein, The first information includes at least one of the following: Request information, wherein the request information is used to request to disable or enable NAS protection; A first identifier, wherein the first identifier is used to identify the first access network device; Toggle notification messages; Next-Generation Application Protocol (NGAP) path switching request.
4. The method according to any one of claims 1 to 3, characterized in that, The step of controlling NAS protection based on the first information includes: Determine the third piece of information; The NAS protection is controlled based on the first information and the third information, wherein the third information is related to the access network device.
5. The method of claim 4, wherein, The third information includes at least one of the following: The second identifier is used to identify the second access network device; First indication information, wherein the first indication information is used to indicate whether the second access network device is a service-oriented access network device; The second indication information is used to indicate whether the second access network device is located in a secure environment, wherein the secure environment supports disabling NAS protection; The handover information indicates a type change between the first access network device and the third access network device, wherein the first access network device is the access network device after the handover, and the third access network device is the access network device before the handover.
6. The method according to any one of claims 4-5, wherein, The step of controlling the NAS protection based on the first information and the third information includes: Based on the first information and the third information, it is determined that the first access network device meets the first condition, and the NAS protection is turned off. Based on the first information and the third information, it is determined that the first access network device does not meet the first condition, and the NAS protection is enabled. The first condition includes at least one of the following: The first access network device is the service-oriented access network device; The first access network device is located in a secure environment; The type change between the first access network device and the third access network device is: switching from a non-service access network device to a service access network device.
7. The method of claim 6, wherein, The step of determining that the first access network device meets the first condition based on the first information and the third information includes at least one of the following: The first identifier and the second identifier are the same, and the first indication information indicates that the second access network device is a service-oriented access network device, thus determining that the first access network device is the service-oriented access network device; The first identifier and the second identifier are the same, and the second indication information indicates that the second access network device is located in a secure environment, thus determining that the first access network device is located in a secure environment; The first information includes a handover notification message or an NGAP path handover request, and the handover information included in the third information indicates that the type change between the first access network device and the third access network device is: a handover from a non-service access network device to a service access network device.
8. The method according to any one of claims 2 to 7, wherein, The second information includes any one of the following: The third indication information is used to indicate that the NAS protection has been turned off; The first reason, wherein the first reason is used to indicate the reason why the NAS protection was not successfully turned off. The fourth indication information is used to indicate that the NAS protection has been enabled; The second reason, wherein the second reason is used to indicate the reason why the NAS protection was not successfully enabled.
9. The method according to any one of claims 1 to 8, wherein, The sending of the first information is triggered based on at least one of the following: The first access network device completes the access layer security mode command (AS SMC) process; The first access network device completes the handover based on the N2 interface; The first access network device completes the intra-device handover.
10. A communication method characterized by comprising: The method is performed by a first access network device, and the method includes: Send first information to the core network device, wherein the first information is used by the core network device to control the protection of the non-access stratum NAS.
11. The method of claim 10, wherein, The method further includes: The system receives second information sent by the core network device, wherein the second information is used to indicate information related to NAS protection.
12. The method according to any one of claims 10-11, wherein, The first information includes at least one of the following: Request information, wherein the request information is used to request to disable or enable NAS protection; A first identifier, wherein the first identifier is used to identify the first access network device; Toggle notification messages; Next-Generation Application Protocol (NGAP) path switching request.
13. The method according to any one of claims 11-12, characterized in that, The second information includes any of the following: The third indication information is used to indicate that the NAS protection has been turned off; The first reason, wherein the first reason is used to indicate the reason why the NAS protection was not successfully turned off. The fourth indication information is used to indicate that the NAS protection has been enabled; The second reason, wherein the second reason is used to indicate the reason why the NAS protection was not successfully enabled.
14. The method according to any one of claims 10-13, characterized in that, Sending the first information to the core network equipment includes at least one of the following: Complete the Access Layer Security Mode Command (AS SMC) procedure and send the first information to the core network device; Complete the handover based on the N2 interface and send the first information to the core network device; After completing the intra-device handover, the first information is sent to the core network device.
15. The method according to any one of claims 10-14, characterized in that, The method further includes: If the path handover confirmation message based on NGAP does not include the New Security Context Indicator (NSCI), perform an intra-device handover, and after completing the intra-device handover, send the first information to the core network device.
16. A communication device, characterized in that, The communication device is used to perform the method as described in any one of claims 1-9 or 10-15.
17. A communication system, characterized in that, It includes a core network device and a first access network device, wherein the core network device is used to perform the method as described in any one of claims 1-9, and the first access network device is used to perform the method as described in any one of claims 10-15.
18. A storage medium storing instructions, characterized in that, When the instructions are executed on the communication device, the communication device performs the method as described in any one of claims 1-15.
19. A computer program product, characterised in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-15.