Service method, network device, network system, storage medium, and program product

WO2026199131A1PCT designated stage Publication Date: 2026-10-01BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/084530
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2026-10-01

Smart Images

  • Figure CN2025084530_01102026_PF_FP_ABST
    Figure CN2025084530_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure provide a service method, a network device, a network system, a storage medium, and a program product. The method, which is performed by a first network function (NF), comprises: providing a security and privacy service, wherein the security and privacy service comprises a security service and / or a privacy service, and the security and privacy service is configured for being requested and invoked by a plurality of second NFs. The present disclosure improves security and privacy service reliability and scalability, and reduces security and privacy service redundancy.
Need to check novelty before this filing date? Find Prior Art

Description

Service methods, network equipment, network systems, storage media and software products Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a service method, network device, network system, storage medium, and program product. Background Technology

[0002] A network contains multiple Network Functions (NFs) that provide network services. For example, an NF may include an Access and Mobility Management Function (AMF) and a Network Repository Function (NRF). To ensure the proper functioning of an NF, security mechanisms can be configured. Summary of the Invention

[0003] This disclosure provides a service method, network device, network system, storage medium, and program product to improve the reliability and scalability of security and privacy services, and reduce the redundancy of security and privacy services.

[0004] According to a first aspect of the embodiments of this disclosure, a service method is proposed, executed by a first NF, the method comprising:

[0005] Provide security and privacy services;

[0006] The security and privacy services include security services and / or privacy services, which are invoked by multiple second NF requests.

[0007] In this embodiment, the security and privacy service is provided by a first network function (NF), and this service can be invoked by multiple second network functions (NFs). This eliminates the need for other network functions (primarily designed to provide non-security and privacy services) to provide the service, avoiding the exposure of additional interfaces by these functions and thus reducing the risk of attacks on them, thereby improving the reliability of the security and privacy service. The first NF is decoupled from other network functions providing non-security and privacy services; that is, the first NF can provide security and privacy services independently of specific network functions, enabling it to provide security and privacy services for various network functions, thereby improving the scalability of security and privacy protection. Furthermore, since the first NF can provide security and privacy services independently of specific network functions, it avoids defining security and privacy services for the same purpose for different network functions, thus reducing the redundancy of security and privacy protection.

[0008] According to a second aspect of the embodiments of this disclosure, a network function is provided, including:

[0009] The processing module is used to provide security and privacy services;

[0010] The security and privacy services include security services and / or privacy services, which are invoked by multiple second NF requests.

[0011] According to a third aspect of the present disclosure, a network device is provided, wherein the network device is used to perform the methods described in the first aspect and optional implementations of the first aspect.

[0012] According to a fourth aspect of the embodiments of this disclosure, a network system is proposed, including a first NF and a plurality of second NFs, wherein,

[0013] The first NF is used to provide security and privacy services, which include security services and / or privacy services;

[0014] Multiple second NFs are used to request the invocation of security and privacy services from the first NF.

[0015] According to a fifth aspect of the present disclosure, a storage medium is provided that stores instructions which, when executed on a network device, cause the network device to perform the method as described in the first aspect and optional implementations thereof.

[0016] According to a sixth aspect of the present disclosure, a program product is provided, including at least one of a program and instructions, wherein when the program and at least one of the instructions are executed by a network device, the method described in the first aspect and optional implementations of the first aspect is implemented.

[0017] According to a seventh aspect of the present disclosure, a computer program is provided that, when run on a computer, causes the computer to perform the methods described in the first aspect and optional implementations of the first aspect.

[0018] According to an eighth aspect of the embodiments of this disclosure, a chip or chip system is provided. The chip or chip system includes processing circuitry configured to perform the methods described in the first aspect and optional implementations thereof. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.

[0020] Figure 1A is a schematic diagram of a service-oriented architecture according to an embodiment of the present disclosure;

[0021] Figure 1B is a second schematic diagram of a service-oriented architecture according to an embodiment of the present disclosure;

[0022] Figure 2A is an exemplary schematic diagram of a service method according to an embodiment of the present disclosure;

[0023] Figure 2B is an exemplary schematic diagram of a service method according to an embodiment of the present disclosure;

[0024] Figure 3A is a schematic diagram of a first NF according to an embodiment of the present disclosure;

[0025] Figure 3B is a schematic diagram of the first NF according to an embodiment of the present disclosure;

[0026] Figure 3C is a schematic diagram of the first NF according to an embodiment of the present disclosure;

[0027] Figure 3D is a schematic diagram of the first NF according to an embodiment of the present disclosure;

[0028] Figure 4A is a schematic diagram of the deployment of a first NF according to an embodiment of the present disclosure;

[0029] Figure 4B is a second schematic diagram illustrating the deployment of the first NF according to an embodiment of the present disclosure;

[0030] Figure 5 is an exemplary structural diagram of the network function proposed in the embodiments of this disclosure;

[0031] Figure 6A is a schematic diagram of the structure of the network device proposed in an embodiment of this disclosure;

[0032] Figure 6B is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. Detailed Implementation

[0033] This disclosure provides a service method, network device, network system, storage medium, and program product to improve the reliability and scalability of security and privacy services, and reduce the redundancy of security and privacy services.

[0034] According to a first aspect of the embodiments of this disclosure, a service method is provided, executed by a first network function NF, the method comprising:

[0035] Provide security and privacy services;

[0036] The security and privacy services include security services and / or privacy services, which are invoked by multiple second NF requests.

[0037] In this embodiment, the security and privacy service is provided by a first network function (NF), and this service can be invoked by multiple second network functions (NFs). This eliminates the need for other network functions (primarily designed to provide non-security and privacy services) to provide such services, avoiding the exposure of additional interfaces by these functions and thus reducing the risk of attacks on them, thereby improving the reliability of the security and privacy service. The first NF is decoupled from other network functions providing non-security and privacy services; that is, the first NF can provide security and privacy services independently of specific network functions, enabling it to provide security and privacy services for various network functions, thereby improving the scalability of security and privacy protection. Furthermore, since the first NF can provide security and privacy services independently of specific network functions, it avoids defining security and privacy services for the same purpose for different network functions, thus reducing the redundancy of security and privacy protection.

[0038] In conjunction with some embodiments of the first aspect, in some embodiments, the number of the first NF is 1; or,

[0039] The first NF includes a security NF and a privacy NF. The security NF is used to provide security services, and the privacy NF is used to provide privacy services; or...

[0040] There are multiple First NFs, each of which is used to provide corresponding security and privacy services.

[0041] In this embodiment of the disclosure, when the number of first NFs is one, all security and privacy services can be provided by a single first NF. Therefore, all security and privacy services can be managed and maintained within a single NF, resulting in high convenience for managing and maintaining security and privacy services. When the first NF includes security NFs and privacy NFs, security services are provided by the security NFs and privacy services are provided by the privacy NFs. This allows for separate management of security and privacy services, resulting in high flexibility in managing security and privacy services. When the number of first NFs is multiple, different first NFs provide corresponding security and privacy services. Different security and privacy services can be managed within different NFs, resulting in high flexibility in managing security and privacy services.

[0042] In conjunction with some embodiments of the first aspect, in some embodiments, the security and privacy service includes at least one of the following:

[0043] Authentication service;

[0044] Key management service;

[0045] Non-access tier NAS security services;

[0046] Access layer AS security services;

[0047] User-side security services;

[0048] Authorized services;

[0049] User privacy protection services; or

[0050] Security context storage service.

[0051] In this embodiment, the security and privacy service may include any one or more of the aforementioned services. The specific services included in the security and privacy service can be designed according to actual needs, thus improving the flexibility of the security and privacy service. Furthermore, through the aforementioned security and privacy service, comprehensive security and privacy protection can be achieved.

[0052] In conjunction with some embodiments of the first aspect, in some embodiments, the authentication service includes at least one of the following:

[0053] Authentication services for contracted users;

[0054] Authentication services for non-contracted users;

[0055] Certification services for non-3GPP equipment access under the Third Generation Partnership Project;

[0056] The service that triggers re-authentication on the terminal device; or...

[0057] Provides credential assertion services for the authentication of service-based radio access network (RAN) devices.

[0058] In this embodiment of the disclosure, the authentication service may include any one or more of the above-mentioned services. The specific services included in the authentication service can be designed according to actual needs, thereby improving the flexibility of the authentication service.

[0059] In conjunction with some embodiments of the first aspect, in some embodiments, the key management service includes at least one of the following:

[0060] Key derivation service;

[0061] Key storage service; or,

[0062] Key distribution service.

[0063] In this embodiment of the disclosure, the key management service may include any one or more of the above-mentioned services. The specific services included in the key management service can be designed according to actual needs, thereby improving the flexibility of the key management service.

[0064] In conjunction with some embodiments of the first aspect, in some embodiments, the key provided by the key management service includes at least one of the following:

[0065] Provides a key for establishing NAS security between the terminal device and the second NF;

[0066] Provides a key for secure establishment of the access layer AS between the terminal device and the second NF;

[0067] Provides keys for secure user plane messages between the terminal device and the second NF;

[0068] Provides keys for secure data plane messages between the terminal device and the second NF;

[0069] Provides keys for secure establishment between terminal devices;

[0070] Provides keys for the mobility security of terminal devices;

[0071] Provide keys for secure application-layer messages between terminal devices and third-party servers; or,

[0072] Provides keys for authentication of uncontracted users.

[0073] In this embodiment of the disclosure, the key provided by the key management service includes any one or more of the above-mentioned keys. The key provided by the key management service can be designed according to actual needs, thereby improving the flexibility of the key management service.

[0074] In conjunction with some embodiments of the first aspect, in some embodiments, the NAS security service includes:

[0075] Establish NAS security between the terminal device and the second NF.

[0076] In this embodiment of the disclosure, the first NF can ensure NAS security between the terminal device and the second NF by providing NAS security services.

[0077] In conjunction with some embodiments of the first aspect, in some embodiments, establishing NAS security between the terminal device and the second NF includes at least one of the following:

[0078] Provide the second NF with the NAS security key between the second NF and the terminal device; or...

[0079] Provides negotiation services for secure NAS establishment between terminal devices and the second NF.

[0080] In this embodiment of the disclosure, the first NF can ensure NAS security between the terminal device and the second NF by providing the aforementioned key and / or negotiation services.

[0081] In conjunction with some embodiments of the first aspect, in some embodiments, the AS security service includes:

[0082] Establish AS security between the terminal device and the second NF.

[0083] In this embodiment of the disclosure, the first NF can ensure AS security between the terminal device and the second NF by providing AS security services.

[0084] In conjunction with some embodiments of the first aspect, in some embodiments, establishing AS security between the terminal device and the second NF includes at least one of the following:

[0085] Provide the second NF with the AS-secure key between the second NF and the terminal device; or...

[0086] Provides negotiation services for the secure establishment of the AS between the terminal device and the second NF.

[0087] In this embodiment of the disclosure, the first NF can ensure the security of the AS between the terminal device and the second NF by providing the aforementioned key and / or negotiation services.

[0088] In conjunction with some embodiments of the first aspect, in some embodiments, the user plane security service includes at least one of the following:

[0089] Provide the second NF with a key for secure user plane messages between the second NF and the terminal device;

[0090] To establish user plane security between the second NF and the terminal device, a negotiation service is provided; or,

[0091] Provide the user plane security policy for the terminal to the second NF.

[0092] In this embodiment of the disclosure, the first NF can better guarantee user plane security by providing at least one of the above-mentioned keys, user plane security policies, or negotiation services.

[0093] In conjunction with some embodiments of the first aspect, in some embodiments, the authorized service includes at least one of the following:

[0094] Provide access token services;

[0095] Provides certificate assertion services;

[0096] Services that grant authorization at the granularity of the request message information;

[0097] Provide token verification services;

[0098] To provide network services with the ability to authorize third-party application functions; or,

[0099] This service provides authorization information or tokens to authorized application programming interface (API) callers.

[0100] In this embodiment of the disclosure, the authorized service may include any one or more of the above-mentioned services. The specific services included in the authorized service can be designed according to actual needs, thereby improving the flexibility of the authorized service.

[0101] In conjunction with some embodiments of the first aspect, in some embodiments, the user privacy protection service includes at least one of the following:

[0102] Hiding sensitive user information;

[0103] Provide user consent information to the second NF that implements user consent; or,

[0104] Process user consent information.

[0105] In this embodiment of the disclosure, the first NF can effectively protect user privacy by providing one or more of the aforementioned services. Furthermore, by hiding sensitive user information, the first NF can reduce the risk of user privacy being violated when the service network is untrusted.

[0106] In conjunction with some embodiments of the first aspect, in some embodiments, the security context storage service includes at least one of the following:

[0107] NAS security context storage;

[0108] AS security context storage;

[0109] User plane security context storage;

[0110] Data plane security context storage;

[0111] Security context storage between terminal devices; or,

[0112] Authentication or authorization result storage service.

[0113] In this embodiment of the disclosure, the security context storage service may include one or more of the above-mentioned services. The specific services included in the security context storage service can be designed according to actual needs, thereby improving the flexibility of the security context storage service.

[0114] In conjunction with some embodiments of the first aspect, in some embodiments, the first NF is deployed in the home network.

[0115] In conjunction with some embodiments of the first aspect, in some embodiments, the authentication service includes at least one of the following:

[0116] Authentication services for contracted users;

[0117] Authentication service for non-contracted users; or,

[0118] Authentication service for non-3GPP devices accessing the network.

[0119] In this embodiment of the disclosure, the authentication service may include any one or more of the above-mentioned services. The specific services included in the authentication service can be designed according to actual needs, thereby improving the flexibility of the authentication service.

[0120] In conjunction with some embodiments of the first aspect, in some embodiments, the key management service includes at least one of the following:

[0121] Key derivation service;

[0122] Key storage service; or,

[0123] Key distribution service.

[0124] In this embodiment of the disclosure, the key management service may include any one or more of the above-mentioned services. The specific services included in the key management service can be designed according to actual needs, thereby improving the flexibility of the key management service.

[0125] In conjunction with some embodiments of the first aspect, in some embodiments, the key provided by the key management service includes at least one of the following:

[0126] Provides a key for establishing NAS security between the terminal device and the second NF in the home network;

[0127] Provides keys for secure user plane messages between terminal devices and the second NF in the home network;

[0128] Provides keys for secure data plane messages between terminal devices and the second NF in the home network;

[0129] Provide keys for secure application-layer messages between terminal devices and third-party servers; or,

[0130] Provides keys for authentication of uncontracted users.

[0131] In this embodiment of the disclosure, the key provided by the key management service includes any one or more of the above-mentioned keys. The key provided by the key management service can be designed according to actual needs, thereby improving the flexibility of the key management service.

[0132] In conjunction with some embodiments of the first aspect, in some embodiments, the NAS security service includes: establishing NAS security between the terminal device and a second NF in the home network.

[0133] In this embodiment of the disclosure, the first NF can guarantee NAS security between the terminal device and the second NF in the home network through the NAS security service it provides.

[0134] In conjunction with some embodiments of the first aspect, in some embodiments, establishing NAS security between the terminal device and the second NF in the home network includes at least one of the following:

[0135] Provides the NAS security key between the second NF and the terminal device to the second NF in the home network;

[0136] Provide the NAS security key between the second NF and the terminal device to the second NF in the service network; or...

[0137] Provides negotiation services for NAS connections between terminal devices and the second NF in the home network.

[0138] In this embodiment of the disclosure, the first NF can ensure NAS security between the terminal device and the second NF in the home network by providing the aforementioned key and / or negotiation services.

[0139] In conjunction with some embodiments of the first aspect, in some embodiments, the user plane security service includes at least one of the following:

[0140] Provides the second NF in the home network with a key for secure user plane messages between the second NF and the terminal device;

[0141] To provide negotiation services for establishing user plane security between the second NF in the home network and the terminal device; or,

[0142] Provide the user plane security policy of the terminal device to the second NF in the home network.

[0143] In this embodiment of the disclosure, the first NF can better guarantee user plane security by providing at least one of the above-mentioned keys, user plane security policies, or negotiation services.

[0144] In conjunction with some embodiments of the first aspect, in some embodiments, the authorized service includes at least one of the following:

[0145] The service of providing access tokens to the second NF in the home network;

[0146] Provide authorization services for credential assertion to the second NF in the home network;

[0147] Services that grant authorization at the granularity of the request message information;

[0148] Provide token verification services for the second NF that does not support token verification in the home network;

[0149] To provide network services with the ability to authorize third-party application functions; or,

[0150] A service that provides authorization information or tokens to authorized API callers.

[0151] In this embodiment of the disclosure, the authorized service may include any one or more of the above-mentioned services. The specific services included in the authorized service can be designed according to actual needs, thereby improving the flexibility of the authorized service.

[0152] In conjunction with some embodiments of the first aspect, in some embodiments, the user privacy protection service includes at least one of the following:

[0153] Hiding sensitive user information;

[0154] Provide user consent information to the second NF that executes the user consent information; or,

[0155] Process user consent information.

[0156] In this embodiment of the disclosure, the first NF can effectively protect user privacy by providing one or more of the aforementioned services. Furthermore, by hiding sensitive user information, the first NF can reduce the risk of user privacy being violated when the service network is untrusted.

[0157] In conjunction with some embodiments of the first aspect, in some embodiments, the security context storage service includes at least one of the following:

[0158] NAS security context storage for terminal devices and the second NF in the home network;

[0159] The terminal device stores the user plane security context of the second NF in the home network;

[0160] The terminal device stores the data plane security context of the second NF in the home network; or...

[0161] Authentication or authorization result storage service.

[0162] In this embodiment of the disclosure, the security context storage service may include one or more of the above-mentioned services. The specific services included in the security context storage service can be designed according to actual needs, thereby improving the flexibility of the security context storage service.

[0163] In conjunction with some embodiments of the first aspect, in some embodiments, the first NF is deployed in the service network.

[0164] In conjunction with some embodiments of the first aspect, in some embodiments, the authentication service includes at least one of the following:

[0165] The Security Anchoring (SEAF) function provides services during the authentication process;

[0166] The service that triggers re-authentication on the terminal device; or...

[0167] Provides credential assertion services for authentication of service-based RAN devices.

[0168] In this embodiment of the disclosure, the authentication service may include any one or more of the above-mentioned services. The specific services included in the authentication service can be designed according to actual needs, thereby improving the flexibility of the authentication service.

[0169] In conjunction with some embodiments of the first aspect, in some embodiments, the key management service includes at least one of the following:

[0170] Key derivation service;

[0171] Key storage service; or,

[0172] Key distribution service.

[0173] In this embodiment of the disclosure, the key management service may include any one or more of the above-mentioned services. The specific services included in the key management service can be designed according to actual needs, thereby improving the flexibility of the key management service.

[0174] In conjunction with some embodiments of the first aspect, in some embodiments, the key provided by the key management service includes at least one of the following:

[0175] Provides keys for secure NAS establishment between terminal devices and the second NF in the service network;

[0176] Provides keys for secure establishment of the access layer AS between terminal devices and the second NF in the service network;

[0177] Provides keys for secure user plane messages between terminal devices and the second NF in the serving network;

[0178] Provides keys for secure data plane messages between terminal devices and the second NF in the serving network;

[0179] Provides keys for secure establishment between terminal devices; or,

[0180] Provides keys for the mobility security of terminal devices.

[0181] In this embodiment of the disclosure, the key provided by the key management service includes any one or more of the above-mentioned keys. The key provided by the key management service can be designed according to actual needs, thereby improving the flexibility of the key management service.

[0182] In conjunction with some embodiments of the first aspect, in some embodiments, the NAS security service includes:

[0183] Establish NAS security between terminal devices and the second NF in the service network.

[0184] In this embodiment of the disclosure, the first NF can guarantee NAS security between the terminal device and the second NF in the service network through the NAS security service it provides.

[0185] In conjunction with some embodiments of the first aspect, in some embodiments, establishing NAS security between the terminal device and the second NF in the service network includes at least one of the following:

[0186] Provide the NAS-secure key between the terminal device and the second NF in the service network; or...

[0187] Provides negotiation services for establishing NAS security between terminal devices and the second NF in the service network.

[0188] In this embodiment of the disclosure, the first NF can ensure NAS security between the terminal device and the second NF in the service network by providing the aforementioned key and / or negotiation services.

[0189] In conjunction with some embodiments of the first aspect, in some embodiments, the AS security service includes:

[0190] Establish AS security between terminal devices and the second NF in the service network.

[0191] In this embodiment of the disclosure, the first NF can guarantee AS security between the terminal device and the second NF in the service network by providing AS security services.

[0192] In conjunction with some embodiments of the first aspect, in some embodiments, establishing AS security between the terminal device and the second NF in the serving network includes at least one of the following:

[0193] Provides the AS-secure key between the terminal device and the second NF in the service network;

[0194] It provides negotiation services for the secure establishment of an AS between a terminal device and a second NF in the service network.

[0195] In this embodiment of the disclosure, the first NF can ensure the security of the AS between the terminal device and the second NF in the service network by providing the aforementioned key and / or negotiation services.

[0196] In conjunction with some embodiments of the first aspect, in some embodiments, the user plane security service includes at least one of the following:

[0197] Provides a secure key for user plane messages between the terminal device and the second NF in the service network;

[0198] To provide negotiation services for establishing user plane security between the second NF and the terminal device in the service network; or,

[0199] Provide end-user plane security policies to the second NF in the service network.

[0200] In this embodiment of the disclosure, the first NF can better guarantee user plane security by providing at least one of the above-mentioned keys, user plane security policies, or negotiation services.

[0201] In conjunction with some embodiments of the first aspect, in some embodiments, the authorized service includes at least one of the following:

[0202] The service of providing access tokens to the second NF in the service network;

[0203] Provide credential assertion services to the second NF in the service network;

[0204] Provide token verification services for second NFs that do not support token verification in the service network;

[0205] Services that grant authorization at the granularity of the request message; or...

[0206] A service that provides authorization information or tokens to authorized API callers.

[0207] In this embodiment of the disclosure, the authorized service may include any one or more of the above-mentioned services. The specific services included in the authorized service can be designed according to actual needs, thereby improving the flexibility of the authorized service.

[0208] In conjunction with some embodiments of the first aspect, in some embodiments, the user privacy protection service includes at least one of the following:

[0209] Provide user consent information to the second NF that executes the user consent information; or,

[0210] Process user consent information.

[0211] In this embodiment of the disclosure, the first NF can effectively protect user privacy by providing one or more of the aforementioned services. Furthermore, by hiding sensitive user information, the first NF can reduce the risk of user privacy being violated when the service network is untrusted.

[0212] In conjunction with some embodiments of the first aspect, in some embodiments, the security context storage service includes at least one of the following:

[0213] NAS security context storage for the second NF in the terminal device and service network;

[0214] AS security context storage of the second NF in the terminal device and service network;

[0215] User plane security context storage in the second NF of the terminal device and service network;

[0216] The data plane security context storage of the second NF in the terminal device and service network; or...

[0217] Security context storage between terminal devices.

[0218] In this embodiment of the disclosure, the security context storage service may include one or more of the above-mentioned services. The specific services included in the security context storage service can be designed according to actual needs, thereby improving the flexibility of the security context storage service.

[0219] In conjunction with some embodiments of the first aspect, in some embodiments, the method includes:

[0220] Request network services from the third NF.

[0221] In this embodiment of the disclosure, the first NF requests network services from the third NF, enabling the first NF to provide security and privacy services based on the network services obtained from the request.

[0222] In conjunction with some embodiments of the first aspect, in some embodiments, the third NF is used to provide at least one piece of information to the first NF, and the at least one piece of information is used by the first NF to provide security and privacy services.

[0223] In this embodiment of the disclosure, the third NF can provide at least one piece of information to the first NF, enabling the first NF to provide security and privacy services based on the at least one piece of information.

[0224] In conjunction with some embodiments of the first aspect, in some embodiments, the first NF includes at least one of the following:

[0225] An authentication NF (Authentication NF) is used to provide authentication services.

[0226] Key Management NF is used to provide key management services.

[0227] Authorization NF, the authorization NF is used to provide authorization services;

[0228] Securely establishes an NF (Network Instance), which is used to provide secure establishment services.

[0229] Privacy Protection NF, used to provide user privacy protection services; or,

[0230] Security Context Store (NF) is used to provide security context storage services.

[0231] In this embodiment of the disclosure, when the first NF cannot provide all security and privacy services, but can provide a specific set of security and privacy services, the first NF can be designed according to this implementation method, which makes the design of the first NF more flexible.

[0232] According to a second aspect of the embodiments of this disclosure, a network function is provided, including:

[0233] The processing module is used to provide security and privacy services;

[0234] The security and privacy services include security services and / or privacy services, which are invoked by multiple second NF requests.

[0235] According to a third aspect of the present disclosure, a network device is provided, wherein the network device is used to perform the methods described in the first aspect and optional implementations of the first aspect.

[0236] According to a fourth aspect of the embodiments of this disclosure, a network system is proposed, including a first NF and a plurality of second NFs, wherein,

[0237] The first NF is used to provide security and privacy services, which include security services and / or privacy services;

[0238] Multiple second NFs are used to request the invocation of security and privacy services from the first NF.

[0239] According to a fifth aspect of the present disclosure, a storage medium is provided that stores instructions which, when executed on a network device, cause the network device to perform the method as described in the first aspect and optional implementations thereof.

[0240] According to a sixth aspect of the present disclosure, a program product is provided, including at least one of a program and instructions, wherein when the program and at least one of the instructions are executed by a network device, the method described in the first aspect and optional implementations of the first aspect is implemented.

[0241] According to a seventh aspect of the present disclosure, a computer program is provided that, when run on a computer, causes the computer to perform the methods described in the first aspect and optional implementations of the first aspect.

[0242] According to an eighth aspect of the embodiments of this disclosure, a chip or chip system is provided. The chip or chip system includes processing circuitry configured to perform the methods described in the first aspect and optional implementations thereof.

[0243] It is understood that the aforementioned network functions, network devices, storage media, program products, etc., are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0244] This disclosure provides service methods, network devices, communication systems, storage media, and program products. In some embodiments, the terms service method, service provision method, service invocation method, etc., may be used interchangeably.

[0245] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments. In all embodiments of this disclosure, unless otherwise specified or logically conflicting, the terminology and / or descriptions between the embodiments are consistent and can be mutually referenced. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0246] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0247] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.

[0248] In the embodiments disclosed herein, "multiple" refers to two or more.

[0249] In some embodiments, the terms “at least one of A or B, at least one of A and B”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0250] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, both A and B are executed. The same applies when there are more branches such as A, B, C, etc.

[0251] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.

[0252] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0253] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0254] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.

[0255] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.

[0256] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0257] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “network function,” “network device,” “function,” “node,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.

[0258] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).

[0259] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.

[0260] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.

[0261] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.

[0262] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.

[0263] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0264] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0265] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0266] In some embodiments, the terminal includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.

[0267] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system, but is not limited thereto.

[0268] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.

[0269] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.

[0270] In some embodiments, the core network equipment may be a single device, including a first network element, a second network element, etc., or it may be multiple devices or a group of devices, each including all or part of the first network element, the second network element, etc. Network elements may be virtual or physical. The core network may include, for example, at least one of the Evolved Packet Core (EPC), 5G Core Network (5GCN), and Next Generation Core (NGC).

[0271] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).

[0272] Figure 1A is a schematic diagram of a service-oriented architecture according to an embodiment of the present disclosure. As shown in Figure 1A, the service-oriented architecture includes multiple NFs, including: Network Slice Selection Function (NSSF), Network Exposure Function (NEF), Network Repository Function (NRF), Policy Control Function (PCF), Unified Data Management (UDM), Application Function (AF), Edge Application Server Discovery Function (EASDF), Network Slice Specific Authentication and Authorization Function (NSSAAF), Authentication Server Function (AUSF), AMF, Session Management Function (SMF), Service Communication Proxy (SCP), Network Slice Admission Control Function (NSACF), UE, (R)AN, User Plane Function (UPF), and Data Network (DN).

[0273] Each NF has its corresponding communication interface. For example, the communication interface corresponding to NSSF is Nnssf, NEF is Nnef, NRF is Nnrf, PCF is Npcf, UDM is Nudm, AF is Naf, EASDF is Neasdf, NSSAAF is Nnssaaf, AUSF is Nausf, AMF is Naamf, SMF is Nsmf, SCP is Nscp, NSACF is Nnsacf, the communication interface between UE and AMF is N1, (R)AN and AMF is N2, (R)AN and UPF is N3, UPF and SMF is N4, UPF and DN is N6, and UPF also has a corresponding communication interface N9.

[0274] The aforementioned multiple network nodes (NFs) can achieve various functions, such as Ultra-Reliable Low Latency Communications (URLLC), Enhanced Mobile Broadband (eMBB), Enhanced Wireless Wideband Communication (eWWC), Internet of Things (IoT) (e.g., Cellular Internet of Things (CIoT), Industrial Internet of Things (IIoT), Environmental Internet of Things), Network Slicing, Edge Computing, Enhanced Location Service (eLCS), Integrated Access and Backhaul (IAB), Non-Public Network (NPN), Device-to-Device Communication (e.g., Vehicle-to-Everything (V2X), Proximity Services (ProSe), Ranging, Unmanned Aerial Vehicle (UAV)), Satellite Communication, and Artificial Intelligence-based Communication. These multiple functions can be protected through various security mechanisms, such as authentication, authorization, transport security (e.g., Non-Access Stratum Security (NAS Security), Access Stratum Security (AS Security), User Plane Security (UP Security)), Service-Based Architecture Security (SBA Security), privacy protection of exposed services, user consent, Authentication and Key Management for Applications (AKMA), and stronger security algorithms.

[0275] The security and privacy protection of these multiple functions relies to some extent on various security mechanisms; for example, different security mechanisms can be used for different functions. Security and privacy services for these multiple functions can be provided by a portion of the Network Functions (NFs), which are primarily designed to provide non-security and privacy services. For example, this portion of the NFs may include base stations (gNBs), AMFs, NRFs, DDNMFs, GMLCs, and NEFs. This, however, will at least lead to the following problems:

[0276] 1. Security and privacy protection is highly complex and carries a high risk of attack. If security and privacy services are provided through only a portion of the Functional Network (NF), that portion of the NF needs to provide more interfaces, thus exposing more interfaces and increasing the risk of attack. This approach may result in more security context sets in the terminal device, for example, these security context sets may be used to implement enhanced functions or different protection purposes.

[0277] 2. Poor scalability of security and privacy protection. Specifically, security and privacy protection for one function cannot be applied to other functions. For example, because NRF and NEF lack information about the terminal device, they cannot provide privacy protection for the terminal device.

[0278] 3. High redundancy in security and privacy protection. For example, regarding privacy protection for terminal devices, there are Location Service (LCS) privacy profiles, user consent frameworks, and Resource Owner-aware Northbound API Access (RNAA) based on the Common API Framework for Northbound APIs (CAPIF), all of which are redundant. For the protection of northbound API exposure, there are the Service Enabler Architecture Layer (SEAL) and the Common API Framework for Northbound APIs (CAPIF), both of which are redundant.

[0279] 4. Unconditional trust in services or access networks. For example, exposing a user's Subscription Permanent Identifier (SUPI) to services or access networks.

[0280] As mobile networks evolve, more features will be introduced, which may exacerbate the aforementioned problems.

[0281] Figure 1A illustrates a Service Based Architecture (SBA), where services can register themselves and subscribe to other services. SBA provides a modular framework, allowing for greater flexibility in new service development by enabling connections to other components without introducing specific new interfaces. It allows for the building, configuration, connection, and deployment of various functionalities to meet current needs and achieve the required scale. SBA offers scalability, flexibility, and independence. For example, network functions (NFs) are loosely coupled, and different NFs can connect via APIs. Each network function can evolve and be deployed independently, resulting in good scalability for network systems (e.g., 5G systems). If an instance or physical node fails, the monitoring system can detect the failure and launch multiple instances. Multiple logical networks can run on a single physical network. In the service-based architecture shown in Figure 1A, network functions are exposed by defining service-based interfaces (SBIs), and new network functions can be introduced without affecting existing functionalities.

[0282] As shown in Figure 1A, AUSF is mainly used to provide authentication services, and authentication services are only a part of security and privacy services. Other security and privacy services cannot benefit from the advantages of the service architecture (scalability, flexibility, and independence, etc.).

[0283] To address the aforementioned issues, one or more dedicated network functions for providing security and privacy services can be added to the above service architecture. This service architecture will be described below with reference to Figure 1B.

[0284] Figure 1B is a second schematic diagram of a service-oriented architecture according to an embodiment of this disclosure. Based on Figure 1A, referring to Figure 1B, the service-oriented architecture may further include a Security & Privacy Service Function (SECF). The SECF is configured to provide security and privacy services. Security and privacy services may include security services and / or privacy services. Security services refer to services related to security, and privacy services refer to services related to privacy.

[0285] In some embodiments, the SECF may be used exclusively to provide security and privacy services; that is, the SECF may not be used to provide non-security and privacy services. For example, the SECF may be used exclusively to provide security services, or the SECF may be used exclusively to provide privacy services, or the SECF may be used exclusively to provide both security and privacy services.

[0286] SECF can provide security and privacy services independent of any specific function. That is, the network can provide predefined security and privacy services in a function-agnostic manner to support multiple functions or use cases without designing different security and privacy services for specific functions. For example, an authentication service can be used for both NF authentication in the core network and RAN node authentication in the access network. A privacy protection service can be used for Integrated Sensing Communication (ISAC), Artificial Intelligence (AI), and Non-Terrestrial Networks (NTN) communication, etc.

[0287] Figure 2A is an exemplary schematic diagram illustrating a service method according to an embodiment of the present disclosure. As shown in Figure 2A, this disclosure relates to a service method, which includes:

[0288] Step S2101: The first NF provides security and privacy services.

[0289] The first NF can be the SECF in Figure 1B.

[0290] The first NF can be deployed in network devices.

[0291] In some embodiments, the first NF may be dedicated to providing security and privacy services, that is, the first NF does not provide any other services besides security and privacy services, and other services besides security and privacy services may also be referred to as non-security and privacy services.

[0292] The security and privacy services provided by the first normalized network (NF) can be invoked by multiple second normalized networks (NFs). A second normalized network (NF) can be any NF other than the first normalized network (NF). A second normalized network (NF) can also be another first normalized network (NF). In other words, a first normalized network (NF) can provide security and privacy services to NFs primarily designed to provide non-security and privacy services, and it can also provide security and privacy services to NFs primarily designed to provide security and privacy services.

[0293] The first NF can provide security and privacy services upon request from the second NF; the first NF can also provide security and privacy services under specific triggering conditions.

[0294] Security and privacy services may include security services and / or privacy services.

[0295] The first NF can be designed in a variety of possible ways, and these possible ways can include at least one of the following:

[0296] One possible implementation: The number of the first NF is 1.

[0297] The implementation method will now be explained with reference to Figure 3A.

[0298] Figure 3A is a schematic diagram of a first NF according to an embodiment of the present disclosure. As shown in Figure 3A, the first NF can provide all security and privacy services. That is, all security and privacy services are provided through one NF, and all security services and / or all privacy services are provided through this one NF.

[0299] In this implementation, since all security and privacy services are provided through a single NF, all security and privacy services can be managed and maintained within a single NF, making the management and maintenance of security and privacy services highly convenient.

[0300] Another possible implementation: The first NF includes a security NF and a privacy NF.

[0301] The implementation method will now be explained with reference to Figure 3B.

[0302] Figure 3B is a second schematic diagram of a first NF according to an embodiment of the present disclosure. As shown in Figure 3B, the first NF includes a security NF and a privacy NF. The security NF is used to provide security services, and the privacy NF is used to provide privacy services. For example, the security NF can provide all security services, and the privacy NF can provide all privacy services.

[0303] In this implementation, by setting up security NF and privacy NF, security services and privacy services can be managed separately, which makes the management of security and privacy services more flexible.

[0304] Another possible implementation: the number of first NFs is multiple.

[0305] Each first NF is used to provide corresponding security and privacy services.

[0306] The following explanation of this implementation method is based on Figure 3C.

[0307] Figure 3C is a schematic diagram of a first NF according to an embodiment of the present disclosure. As shown in Figure 3C, there are multiple first NFs, each providing a portion of security and privacy services. Each portion of security and privacy services may include a portion of security services and / or a portion of privacy services. For example, the first first NF provides a first portion of security and privacy services, the second first NF provides a second portion of security and privacy services, and so on, with the Nth first NF providing an Nth portion of security and privacy services. N is an integer greater than 1.

[0308] In this implementation, multiple first NFs can be set up, with different first NFs providing different security and privacy services. This allows for the management of different security and privacy services in different NFs, resulting in greater flexibility in the management of security and privacy services.

[0309] Another possible implementation: The first NF includes at least one of the following: authentication NF, key management NF, authorization NF, security establishment NF, privacy protection NF, and security context storage NF.

[0310] Among them, the Authentication NF is used to provide authentication services; the Key Management NF is used to provide key management services; the Authorization NF is used to provide authorization services; the Secure Establishment NF is used to provide secure establishment services; the Privacy Protection NF is used to provide user privacy protection services; and the Security Context Storage NF is used to provide security context storage services.

[0311] Optionally, if the first NF cannot provide all security and privacy services, but can provide a specific set of security and privacy services, the first NF can be designed in this manner, which makes the design of the first NF more flexible.

[0312] The implementation method will be explained below with reference to Figure 3D.

[0313] Figure 3D is a schematic diagram of the first NF according to an embodiment of the present disclosure. As shown in Figure 3D, the first NF includes at least one of an authentication NF, a key management NF, an authorization NF, a security establishment NF, a privacy protection NF, and a security context storage NF. In practical applications, any of the above NFs can be deployed independently.

[0314] In some embodiments, the multiple security and privacy services provided by the first NF include at least one of the following: authentication service, key management service, NAS security service, access layer AS security service, user plane security service, authorization service, user privacy protection service, or security context storage service.

[0315] In some embodiments, the authentication service may include at least one of the following: 1.1 to 1.5

[0316] 1.1 Authentication service for contracted users.

[0317] The authentication service for contracted users refers to the authentication service provided to contracted users. Contracted users can be users who have signed a service agreement with the operator (e.g., individuals or enterprises).

[0318] For example, authentication services for contracted users may include: 3GPP access authentication, terminal device identity authentication, etc.

[0319] The authentication service for contracted users can be the same as the authentication service provided by AUSF. For example, if the first NF can replace AUSF, then the first NF can provide the authentication service for contracted users.

[0320] 1.2 Authentication services for non-contracted users.

[0321] Authentication services for non-contracted users can refer to authentication services provided to non-contracted users. Non-contracted users can be users who have not signed a service agreement with the operator (e.g., individuals or enterprises), such as roaming users or temporary users.

[0322] Authentication services for uncontracted users can be performed by triggering multiple Functional Levels (NFs). These NFs can include Security Anchor Functions (SEAFs), AMFs, etc.

[0323] 1.3 Authentication service for non-3rd Generation Partnership Project (3GPP) equipment access.

[0324] In the absence of a Non-3GPP Interworking Function (N3IWF), the first NF can provide authentication services for non-3GPP access devices.

[0325] 1.4. Trigger the service of terminal device re-authentication.

[0326] This terminal device can be a roaming terminal device.

[0327] The first NF can trigger a re-authentication service for terminal devices to the home network.

[0328] For example, when a terminal device roams to a serving network, and re-authentication of the terminal device is required, the terminal device's home network can be triggered to provide a re-authentication service.

[0329] 1.5 Provide credential assertion services for authentication of service-based RAN devices.

[0330] RAN equipment can be used by RAN consumers or RAN service providers.

[0331] For example, the first NF can provide credential assertions to service-based RAN devices to enable authentication of RAN devices.

[0332] In some embodiments, the key management service may include any one of the following 2.1 to 2.3:

[0333] 2.1 Key Derivation Service.

[0334] Key derivation service can refer to deriving key materials based on the root key of a terminal device.

[0335] For example, the key derivation service can be: based on the K of the terminal device AUSF , derived AKMA key material. K AUSF This can be the root key generated by AUSF for the terminal device. AKMA key materials may include the AKMA Key Identifier (A-KID) and K... AKMA K AKMA According to K AUSF The derived key.

[0336] For example, the key derivation service can be: based on the K of the terminal device AUSF This derives uncontracted User Identity Authentication (UIA) key material. UIA key material may include K... UIA K UIA According to K AUSF The derived key.

[0337] 2.2 Key storage service.

[0338] Key storage services can refer to services that store keys.

[0339] The stored keys may include the root key of the terminal device, derived keys, etc.

[0340] 2.3 Key distribution service.

[0341] Key distribution service can refer to the service of distributing keys to other NFs.

[0342] For example, a key distribution service can send AKMA key materials to the Authentication and Authorization Function (AAnF) to implement AKMA functionality.

[0343] In some embodiments, the key management service may provide a key, which may include at least one of the following: 3.1 to 3.8

[0344] 3.1 Provide a key for establishing NAS security between the terminal device and the second NF.

[0345] For example, the first NF can provide a key to the second NF so that the second NF can establish NAS security with the terminal device based on the key.

[0346] The second NF can be PCF, UDM, or SMF, etc.

[0347] The key can be the NAS root key.

[0348] 3.2 Provide a key for establishing AS security between the terminal device and the second NF.

[0349] For example, the first NF can provide a key to the second NF so that the second NF can establish AS security with the terminal device based on the key.

[0350] The key can be the AS root key.

[0351] 3.3 Provide keys for secure user plane messages between the terminal device and the second NF.

[0352] For example, the first NF can provide a key to the second NF to ensure the security of user plane messages between the terminal device and the second NF.

[0353] 3.4 Provide keys for secure data plane messages between the terminal device and the second NF.

[0354] For example, the first NF can provide a key to the second NF to ensure the security of data plane messages between the terminal device and the second NF.

[0355] 3.5. Provide keys for secure establishment between terminal devices (D2D).

[0356] For example, the first NF can provide a key to the terminal device to ensure that a secure connection is established between the terminal devices.

[0357] 3.6 Provide keys for the mobility security of terminal devices.

[0358] 3.7 Provide keys for application layer message security between terminal devices and third-party servers.

[0359] 3.8 Provide keys for authentication of non-contracted users.

[0360] In some embodiments, the NAS security service may include: establishing NAS security between the terminal device and the second NF.

[0361] In some embodiments, establishing NAS security between the terminal device and the second NF includes at least one of the following 4.1 and 4.2:

[0362] 4.1 Provide the second NF with the NAS security key between the second NF and the terminal device.

[0363] For example, the first NF can provide a key to the second NF so that the second NF can establish NAS security with the end device based on the key.

[0364] 4.2 Provide negotiation services for the secure establishment of the NAS between the terminal device and the second NF.

[0365] For example, the first NF can provide negotiation services to the terminal device and the second NF, so that the terminal device and the second NF can establish NAS security based on the negotiation service.

[0366] In some embodiments, the AS security service may include: establishing AS security between the terminal device and the second NF.

[0367] In some embodiments, establishing AS security between the terminal device and the second NF includes at least one of the following 5.1 and 5.2:

[0368] 5.1 Provide the second NF with the AS security key between the second NF and the terminal device.

[0369] For example, the first NF can provide a key to the second NF so that the second NF can establish AS security with the terminal device based on the key.

[0370] 5.2 Provide negotiation services for the secure establishment of the AS between the terminal device and the second NF.

[0371] For example, the first NF can provide negotiation services to the terminal device and the second NF, so that the terminal device and the second NF can establish AS security based on the negotiation service.

[0372] In some embodiments, the user plane security service may include at least one of the following 6.1 to 6.3:

[0373] 6.1 Provide the second NF with a key for secure user plane messages between the second NF and the terminal device.

[0374] For example, the first NF can provide a key to the second NF so that the second NF can secure user plane messages between the second NF and the terminal device based on the key.

[0375] 6.2. Provide negotiation services for establishing user plane security between the second NF and the terminal device.

[0376] For example, the first NF can provide negotiation services to the second NF and the terminal device to enable the establishment of user plane security between the second NF and the terminal device.

[0377] 6.3 Provide the user plane security policy for the terminal to the second NF.

[0378] For example, user plane security policies may include encryption policies, integrity protection policies, and algorithm selection policies.

[0379] In some embodiments, the licensing service may include at least one of the following 7.1 to 7.6:

[0380] 7.1 Provide access token services.

[0381] For example, the first NF can provide an access token to an NF consumer to enable the provision of authorization services to the NF consumer. The NF consumer is the NF that requests security and privacy services from the first NF.

[0382] 7.2 Provide credential assertion services.

[0383] For example, the first NF can provide credential assertions to an NF consumer to enable the provision of authorization services to the NF consumer. The NF consumer is the NF that requests security and privacy services from the first NF.

[0384] 7.3 Services authorized at the granularity of request message information.

[0385] The granularity of a request message can refer to the granularity of the information requested by the request message. In other words, if a request message requests authorization for first information, then the granularity of the request message can be the granularity corresponding to that first information.

[0386] For example, if a request message is used to request authorization for a resource, the granularity of the request message information is the resource granularity. If a request message is used to request authorization for an operation, the granularity of the request message information is the operation granularity.

[0387] For example, suppose the request message is used to request authorization for a resource, then the first NF can provide resource-level authorization services to authorize that resource. Suppose the request message is used to request authorization for an operation, then the first NF can provide operation-level authorization services to authorize that operation.

[0388] 7.4 Provide token verification services.

[0389] For example, the first NF can provide token verification services to NFs that do not support token verification, in order to enable authorization to NFs that do not support token verification.

[0390] Token verification can be used for Open Authorization (OAuth) token verification.

[0391] 7.5. Provide network services with the ability to authorize third-party application functions.

[0392] For example, the first NF can provide authorization services for third-party application functions (AFs) to enable network service openness.

[0393] 7.6. Provide authorization information or tokens to authorized API callers.

[0394] For example, the first NF can provide authorization information or tokens to authorized API callers to enable the provision of authorization services to API callers.

[0395] In some embodiments, the user privacy protection service may include at least one of the following 8.1 to 8.3:

[0396] 8.1 Hide sensitive user information.

[0397] Sensitive user information may include a user's permanent identifier.

[0398] Hiding sensitive user information can mean not disclosing sensitive user information to other network nodes (NFs) on the network.

[0399] 8.2 Provide user consent information to the second NF that implements user consent.

[0400] For example, the second NF that implements user consent can be the Network Data Analytics Function (NWDAF) in the home network, the Location Management Function (LMF) in the serving network, or the RAN in the serving network.

[0401] User consent information may include the information the user agrees to, the permission granted, etc.

[0402] 8.3 Processing user consent information.

[0403] For example, processing user consent information may include: collecting user consent information, updating user consent information, withdrawing user consent information, and ensuring the non-repudiation of user consent.

[0404] In some embodiments, the security context storage service includes at least one of the following: 9.1 to 9.6

[0405] 9.1 NAS Security Context Storage.

[0406] For example, NAS security context can refer to the context used to protect NAS security.

[0407] 9.2 AS Security Context Storage.

[0408] For example, an AS security context can refer to the context in which a user protects the security of the AS.

[0409] 9.3 User plane security context storage.

[0410] For example, a user plane security context can refer to a context used to protect user plane security.

[0411] 9.4 Data plane security context storage.

[0412] For example, a data plane security context can refer to a context used to protect the security of the data plane.

[0413] 9.5 Security context storage between terminal devices.

[0414] 9.6. Authentication or authorization result storage service.

[0415] In step S2102, the first NF requests network services from the third NF.

[0416] In some embodiments, the first NF may also request necessary network services from other NFs to enable the first NF to provide security and privacy services. That is, the first NF, as an NF consumer, requests necessary network services from other NF producers.

[0417] In some embodiments, a first NF requesting network services from a third NF may mean that the first NF requests at least one piece of information from the third NF so that the first NF can provide security and privacy services based on the at least one piece of information.

[0418] Optionally, the third NF is used to provide at least one piece of information to the first NF, and the at least one piece of information is used by the first NF to provide security and privacy services.

[0419] At least one type of information may include at least one of the following: authentication method, security parameters, security policy, user consent information, or privacy configuration information.

[0420] The third NF may include at least one of the following: UDM, AUSF, NRF, or other NF used to provide security and privacy services.

[0421] For example, the first NF can request authentication methods, user consent information, LCS privacy profiles, and user plane security policies from the UDM; the first NF can also request K from the ASUF. AUSF Or KAKMA The first NF can request NF profile information from the NRF to generate access tokens; the first NF can request NAS keys from other NFs used to provide security and privacy services.

[0422] In some embodiments, the first NF can also interact with the terminal device to obtain relevant information. For example, the first NF can request consent from the user (the user using the terminal device) or request the configuration of key materials in the terminal device.

[0423] In some embodiments, security between the first NF and other NFs can be guaranteed based on certain security mechanisms. For example, mutual authentication between the first NF and other NFs (e.g., the second NF) can be achieved through the SBA security mechanism. Transmission security between the first NF and other NFs (e.g., the second NF) can also be ensured through the SBA security mechanism.

[0424] When the first NF acts as an NF producer, it needs to register with the NRF. To authorize NF consumers to access the security and privacy services provided by the first NF, the first NF can provide access tokens to the NF consumers through the NRF, or authorize the NF consumers based on local authorization information in the SECF. To authorize NF consumers to access network services provided by NF producers other than the first NF, the NF producers can authorize the NF consumers using access tokens provided by the first NF.

[0425] When the first NF acts as an NF consumer, an access token can be generated by the NRF in order to authorize the first NF to access network services provided by other NF producers.

[0426] Security between the first NF and the end device can be ensured by a non-access stratum (NAS) security mechanism.

[0427] The signal transmission method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2102. For example, step S2101 may be implemented as a separate embodiment, and step S2102 may be implemented as a separate embodiment, but is not limited thereto.

[0428] In some embodiments, steps S2101 and S2102 may be performed in an alternate order or simultaneously.

[0429] In some embodiments, step S2102 is optional, and in different embodiments, this step may be omitted or replaced.

[0430] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0431] In one embodiment, SECF can be deployed in both the home network and the service network (also referred to as the visited network). The home network is the network to which the terminal device is registered and belongs; it performs authentication, billing management, and core data storage for the terminal device. The service network is the network the terminal device is currently connected to; it provides services such as data transmission and resource allocation. When the terminal device is not roaming, its home network and service network can be the same. When the terminal device is roaming, its home network and service network can be different.

[0432] For most networks, this network can function as both a home network and a service network. In other words, this network can serve as the home network for some terminal devices and the service network for others. To enable this network to provide security and privacy services both as a home network and as a service network, the first NF can be deployed in this network in any of the following ways:

[0433] One possible implementation:

[0434] Two types of first-level network elements (NFs) are deployed in the network. When the network is a home network, one type of NF provides security and privacy services for functions within that home network; this can also be understood as the NF being deployed within the home network. When the network is a serving network, the other type of NF provides security and privacy services for functions within that serving network; this can also be understood as the NF being deployed within the serving network. These two types of NFs can be deployed on the same network element or on different network elements.

[0435] The implementation method will be explained below with reference to Figure 4A.

[0436] Figure 4A is a schematic diagram illustrating the deployment of a first NF according to an embodiment of the present disclosure. As shown in Figure 4A, a first NF-1 and a first NF-2 are deployed in the network system. The first NF-1 is used to provide security and privacy services for functions in the home network, and the first NF-2 is used to provide security and privacy services for functions in the serving network.

[0437] When the network is the home network of the terminal device, the first NF-1 can provide security and privacy services. For example, during the interaction between the terminal device and a network element (e.g., a UDM network element) in the home network, the first NF-1 can provide security and privacy services.

[0438] When the network serves as a service network for terminal devices, the first NF-2 can provide security and privacy services. For example, during interactions between the terminal device and network elements (e.g., AMF network elements) in the service network, the first NF-2 can provide security and privacy services.

[0439] When the network serves as both the home network and the service network for the terminal device, privacy services can be provided by the first NF-1 and the first NF-2. For example, during the interaction between the terminal device and network elements in the home network (e.g., UDM network elements), the first NF-1 provides security and privacy services; during the interaction between the terminal device and network elements in the service network (e.g., AMF network elements, SMF network elements), the first NF-2 provides security and privacy services.

[0440] In this implementation, by deploying two types of first NFs separately, the two types of first NFs can be managed and maintained separately, which makes the management and maintenance of the first NFs more flexible.

[0441] Another possible implementation:

[0442] Deploy a unified first NF in the network. This first NF can provide two types of security and privacy services: one type is security and privacy services for the home network, and the other type is security and privacy services for the serving network.

[0443] The implementation method will now be explained with reference to Figure 4B.

[0444] Figure 4B is a second schematic diagram illustrating the deployment of a first NF according to an embodiment of the present disclosure. As shown in Figure 4B, a first NF is deployed in the network system, and the first NF can provide security and privacy service 1 for the home network and security and privacy service 2 for the home network.

[0445] When the network is the home network of the terminal device, the first NF can provide security and privacy service 1. For example, during the interaction between the terminal device and a network element (e.g., a UDM network element) in the home network, the first NF can provide the corresponding security and privacy service in security and privacy service 1.

[0446] When the network serves as the service network for the terminal device, the first NF can provide security and privacy service 2. For example, during the interaction between the terminal device and a network element (e.g., an AMF network element) in the service network, the first NF can provide the corresponding security and privacy service in security and privacy service 2.

[0447] When the network serves as both the home network and the serving network for the terminal device, the first NF can provide security and privacy service 1 and security and privacy service 2. During interactions between the terminal device and network elements in the home network (e.g., UDM network elements), the first NF can provide the corresponding security and privacy service in security and privacy service 1. During interactions between the terminal device and network elements in the serving network (e.g., AMF network elements), the first NF can provide the corresponding security and privacy service in security and privacy service 2.

[0448] In this implementation method, the various security and privacy services provided by the first NF can be managed and maintained in a unified manner, making the management and maintenance of the first NF more convenient.

[0449] The security and privacy services provided by the first NF deployed in the home network may differ from those provided by the first NF deployed in the service network. The following sections will describe the security and privacy services provided by the first NF deployed in the home network and the first NF deployed in the service network, respectively.

[0450] For the first NF deployed in the home network:

[0451] In some embodiments, the multiple security and privacy services provided by the first NF include at least one of the following: authentication service, key management service, NAS security service, user plane security service, authorization service, user privacy protection service, or security context storage service.

[0452] In some embodiments, the authentication service includes at least one of the following:

[0453] Authentication services for contracted users;

[0454] Authentication service for non-contracted users; or,

[0455] Authentication service for non-3GPP devices accessing the network.

[0456] It should be noted that the relevant descriptions of the authentication service can be found in sections 1.1 to 1.3 above, and will not be repeated here.

[0457] In some embodiments, the key management service may include at least one of the following:

[0458] Key derivation service;

[0459] Key storage service; or,

[0460] Key distribution service.

[0461] It should be noted that the relevant descriptions of the key management service can be found in sections 2.1 to 2.3 above, and will not be repeated here.

[0462] In some embodiments, the key provided by the key management service includes at least one of the following: 10.1 to 10.5

[0463] 10.1 Provides a key for establishing NAS security between the terminal device and the second NF in the home network.

[0464] For example, the first NF can provide a key to the second NF in the home network so that the second NF can establish NAS security with the end device based on the key.

[0465] The second NF can be a PCF, UDM, or SMF in the home network, etc.

[0466] The key can be the NAS root key.

[0467] 10.2 Provide keys for secure user plane messages between terminal devices and the second NF in the home network.

[0468] For example, the first NF can provide a key to the second NF in the home network to ensure the security of user plane messages between the terminal device and the second NF in the home network.

[0469] 10.3 Provide keys for secure data plane messages between terminal devices and the second NF in the home network.

[0470] For example, the first NF can provide a key to the second NF in the home network to ensure the security of data plane messages between the terminal device and the second NF in the home network.

[0471] 10.4 Provide keys for application layer message security between terminal devices and third-party servers.

[0472] 10.5 Provide keys for authentication of non-contracted users.

[0473] In some embodiments, the NAS security service includes: establishing NAS security between the terminal device and a second NF in the home network.

[0474] In some embodiments, establishing NAS security between the terminal device and a second NF in the home network may include at least one of the following 11.1 to 11.3:

[0475] 11.1 Provide the second NF in the home network with the NAS security key between the second NF and the terminal device.

[0476] For example, the first NF can provide a key to the second NF in the home network so that the second NF can establish NAS security with the end device based on the key.

[0477] 11.2 Provide the second NF in the service network with the NAS security key between the second NF and the terminal device.

[0478] For example, the first NF can provide a key to the second NF in the service network so that the second NF can establish NAS security with the end device based on the key.

[0479] 11.3 Provide negotiation services for NAS connections between terminal devices and the second NF in the home network.

[0480] For example, the first NF can provide negotiation services to the terminal device and the second NF in the home network, so that the terminal device and the second NF in the home network can establish NAS security based on the negotiation service.

[0481] In some embodiments, the user plane security service may include at least one of the following 12.1 to 12.3:

[0482] 12.1 Provide the second NF in the home network with the key for secure user plane messages between the second NF and the terminal device.

[0483] For example, a first NF can provide a key to a second NF in its home network so that the second NF can secure user plane messages between the second NF and the terminal device based on the key.

[0484] 12.2 Provide negotiation services for establishing user plane security between the second NF in the home network and the terminal device.

[0485] For example, the first NF can provide negotiation services to the terminal device and the second NF in the home network so that user plane security can be established between the second NF and the terminal device.

[0486] 12.3 Provide the user plane security policy of the terminal device to the second NF in the home network.

[0487] In some embodiments, the licensing service may include at least one of the following 13.1 to 13.6:

[0488] 13.1 Providing access token services to the second NF in the home network.

[0489] For example, a first NF can provide an access token to a second NF in its home network to enable the provision of authorization services to the second NF in its home network.

[0490] 13.2 Provide authorization services for credential assertion to the second NF in the home network.

[0491] For example, the first NF can provide credential assertions to the second NF in the home network to enable the provision of authorization services to the second NF in the home network.

[0492] 13.3. Services that authorize at the granularity of the request message information.

[0493] It should be noted that the relevant description in 13.3 can be found in the description in 7.3 above, and will not be repeated here.

[0494] 13.4 Provide token verification services for the second NF in the home network that does not support token verification.

[0495] For example, the first NF can provide token verification services to NFs in the home network that do not support token verification, so as to enable authorization for NFs that do not support token verification.

[0496] 13.5. Provide network services with the ability to authorize third-party application functions.

[0497] It should be noted that the relevant description in 13.5 can be found in the description in 7.5 above, and will not be repeated here.

[0498] 13.6. Provide authorization information or tokens to authorized API callers.

[0499] It should be noted that the relevant descriptions in 13.6 can be found in the description in 7.6 above, and will not be repeated here.

[0500] In some embodiments, the user privacy protection service includes at least one of the following:

[0501] Hiding sensitive user information;

[0502] Provide user consent information to the second NF that executes the user consent information; or,

[0503] Process user consent information.

[0504] It should be noted that the relevant descriptions of the user privacy protection service can be found in sections 8.1 to 8.3 above, and will not be repeated here.

[0505] In some embodiments, the security context storage service may include at least one of the following 14.1 to 14.4:

[0506] 14.1 NAS security context storage for terminal devices and the second NF in the home network.

[0507] For example, a NAS security context can refer to a context used to protect NAS security between an end device and a second NF in the home network.

[0508] 14.2. Terminal equipment and the second NF in the home network user plane security context storage.

[0509] For example, a user plane security context can refer to a context used to protect user plane security between a terminal device and a second NF in the home network.

[0510] 14.3 Data plane security context storage between terminal equipment and the second NF in the home network.

[0511] For example, a data plane security context can refer to a context used to protect the data plane security between an end device and a second NF in the home network.

[0512] 14.4 Authentication or authorization result storage service.

[0513] For the first NF deployed in the service network:

[0514] In some embodiments, the multiple security and privacy services provided by the first NF include at least one of the following: authentication service, key management service, NAS security service, access layer AS security service, user plane security service, authorization service, user privacy protection service, or security context storage service.

[0515] In some embodiments, the authentication service may include at least one of the following: 15.1 to 15.3

[0516] 15.1 Services provided by SEAF during the certification process.

[0517] Optionally, if the first NF can replace the SEAF, the first NF can provide the services provided by the SEAF during the authentication process.

[0518] 15.2. Trigger terminal device re-authentication service.

[0519] It should be noted that the relevant description in 15.2 can be found in the description in 1.4 above, and will not be repeated here.

[0520] 15.3 Provide credential assertion services for authentication of service-based RAN devices.

[0521] It should be noted that the relevant description in 15.3 can be found in the description in 1.5 above, and will not be repeated here.

[0522] In some embodiments, the key management service may include at least one of the following:

[0523] Key derivation service;

[0524] Key storage service; or,

[0525] Key distribution service.

[0526] It should be noted that the relevant descriptions of the key management service can be found in sections 2.1 to 2.3 above, and will not be repeated here.

[0527] In some embodiments, the key provided by the key management service may include at least one of the following: 16.1 to 16.6

[0528] 16.1 Provide a key for establishing NAS security between the terminal device and the second NF in the service network.

[0529] For example, the first NF can provide a key to the second NF in the service network so that the second NF can establish NAS security with the end device based on the key.

[0530] The second NF can be an AMF, SMF, or LMF in the serving network, etc.

[0531] The key can be the NAS root key.

[0532] 16.2 Provide a key for establishing AS security between the terminal device and the second NF in the service network.

[0533] For example, the first NF can provide a key to the second NF in the serving network so that the second NF can establish AS security with the terminal device based on the key.

[0534] 16.3 Provide keys for secure user plane messages between terminal devices and the second NF in the service network.

[0535] For example, the first NF can provide a key to the second NF in the serving network to ensure the security of user plane messages between the terminal device and the second NF in the serving network.

[0536] 16.4 Provide keys for secure data plane messages between terminal devices and the second NF in the service network.

[0537] For example, the first NF can provide a key to the second NF in the serving network to ensure the security of data plane messages between the terminal device and the second NF in the serving network.

[0538] 16.5. Provide keys for secure establishment between terminal devices.

[0539] 16.6 Provide keys for the mobility security of terminal devices.

[0540] In some embodiments, the NAS security service may include: establishing NAS security between the terminal device and a second NF in the service network.

[0541] In some embodiments, establishing NAS security between the terminal device and a second NF in the serving network may include at least one of the following 17.1 to 17.2:

[0542] 17.1 Provide the NAS security key between the terminal device and the second NF in the service network.

[0543] For example, the first NF can provide a key to the second NF in the service network so that the second NF can establish NAS security with the end device based on the key.

[0544] 17.2. Provide negotiation services for establishing NAS security between terminal devices and the second NF in the service network.

[0545] For example, the first NF can provide negotiation services to the second NF in the terminal device and service network, so that the second NF in the terminal device and service network can establish NAS security based on the negotiation service.

[0546] In some embodiments, the AS security service may include: establishing AS security between the terminal device and a second NF in the service network.

[0547] In some embodiments, establishing AS security between the terminal device and a second NF in the serving network may include at least one of the following 18.1 to 18.2:

[0548] 18.1 Provide the second NF in the serving network with the AS secure key between the terminal device and the terminal device.

[0549] For example, the first NF can provide a key to the second NF in the serving network so that the second NF can establish AS security with the terminal device based on the key.

[0550] 18.2 Provide negotiation services for the secure establishment of the AS between the terminal device and the second NF in the service network.

[0551] For example, the first NF can provide negotiation services for the second NF in the terminal device and service network, so that the second NF in the terminal device and service network can establish AS security based on the negotiation service.

[0552] In some embodiments, the user plane security service may include at least one of the following: 19.1 to 19.3

[0553] 19.1 Provide the second NF in the serving network with a key for secure user plane messages between the terminal device and the terminal device.

[0554] For example, a first NF can provide a key to a second NF in the serving network so that the second NF can secure user plane messages between the second NF and the terminal device based on the key.

[0555] 19.2. Provide negotiation services for establishing user plane security between the second NF in the service network and the terminal device.

[0556] For example, the first NF can provide negotiation services to the terminal device and the second NF in the service network so that user plane security can be established between the second NF and the terminal device.

[0557] 19.3 Provide end-user plane security policies to the second NF in the serving network.

[0558] In some embodiments, the licensing service may include at least one of the following: 20.1 to 20.5

[0559] 20.1. Provide access token services to the second NF in the service network.

[0560] For example, the first NF can provide an access token to the second NF in the service network to enable the provision of authorized services to the second NF in the service network.

[0561] 20.2 Provide credential assertion services to the second NF in the service network.

[0562] For example, the first NF can provide credential assertions to the second NF in the service network to enable the provision of authorization services to the second NF in the service network.

[0563] 20.3 Provide token verification services for second NFs in the service network that do not support token verification.

[0564] For example, the first NF can provide token verification services to NFs in the service network that do not support token verification, so as to enable authorization for NFs that do not support token verification.

[0565] 20.4. Services authorized at the granularity of the request message information.

[0566] It should be noted that the relevant description of 20.4 can be found in the description in 7.3 above, and will not be repeated here.

[0567] 20.5. Provide authorization information or tokens for authorized API callers.

[0568] It should be noted that the relevant description of 20.5 can be found in the description in 7.6 above, and will not be repeated here.

[0569] In some embodiments, a user privacy protection service may include at least one of the following:

[0570] Provide user consent information to the second NF that executes the user consent information; or,

[0571] Process user consent information.

[0572] It should be noted that the relevant descriptions of the user privacy protection service can be found in sections 8.2 to 8.3 above, and will not be repeated here.

[0573] In some embodiments, the security context storage service may include at least one of the following 21.1 to 21.5:

[0574] 21.1 NAS security context storage for the second NF in the terminal equipment and service network.

[0575] For example, a NAS security context can refer to a context used to protect NAS security between an end device and a second NF in the service network.

[0576] 21.2. AS security context storage of the second NF in the terminal equipment and service network.

[0577] For example, an AS security context can refer to a context used to protect AS security between an end device and a second NF in the serving network.

[0578] 21.3 User plane security context storage in the second NF of the terminal equipment and service network.

[0579] For example, a user plane security context can refer to a context used to protect user plane security between a terminal device and a second NF in the serving network.

[0580] 21.4 Data plane security context storage in the second NF of terminal equipment and service network.

[0581] For example, a data plane security context can refer to a context used to protect the data plane security between an end device and a second NF in the serving network.

[0582] 21.5 Security context storage between terminal devices.

[0583] Figure 2B is an exemplary schematic diagram of a service method according to an embodiment of the present disclosure. As shown in Figure 2B, this disclosure relates to a service method, which includes:

[0584] Step S2201: The first NF provides security and privacy services.

[0585] Among them, the privacy service includes security service and / or privacy service, and the security and privacy service is used to be invoked by multiple second NF requests.

[0586] It should be noted that the relevant content in step S2201 can be found in the description in step S2101, and will not be repeated here.

[0587] This disclosure also proposes an apparatus (also referred to as a network function, network device, communication device, etc.) for implementing any of the above methods. For example, an apparatus is proposed, which includes units or modules for implementing the steps performed by the first NF in any of the above methods.

[0588] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0589] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0590] Figure 5 is an exemplary structural diagram of a network function proposed in an embodiment of this disclosure. The first NF is used to execute any of the methods described above. In some embodiments, as shown in Figure 5, the first NF 5100 may include a processing module 5101, wherein...

[0591] Processing module 5101 is used to provide security and privacy services;

[0592] The security and privacy services include security services and / or privacy services, which are invoked by multiple second NF requests.

[0593] In some embodiments, the number of the first NF is 1; or,

[0594] The first NF includes a security NF and a privacy NF. The security NF is used to provide security services, and the privacy NF is used to provide privacy services; or...

[0595] There are multiple First NFs, each of which is used to provide corresponding security and privacy services.

[0596] In some embodiments, the security and privacy service includes at least one of the following:

[0597] Authentication service;

[0598] Key management service;

[0599] Non-access tier NAS security services;

[0600] Access layer AS security services;

[0601] User-side security services;

[0602] Authorized services;

[0603] User privacy protection services; or

[0604] Security context storage service.

[0605] In some embodiments, the authentication service includes at least one of the following:

[0606] Authentication services for contracted users;

[0607] Authentication services for non-contracted users;

[0608] Certification services for non-3GPP equipment access under the Third Generation Partnership Project;

[0609] The service that triggers re-authentication on the terminal device; or...

[0610] Provides credential assertion services for the authentication of service-based radio access network (RAN) devices.

[0611] In some embodiments, the key management service includes at least one of the following:

[0612] Key derivation service;

[0613] Key storage service; or,

[0614] Key distribution service.

[0615] In some embodiments, the keys provided by the key management service include at least one of the following:

[0616] Provides a key for establishing NAS security between the terminal device and the second NF;

[0617] Provides a key for secure establishment of the access layer AS between the terminal device and the second NF;

[0618] Provides keys for secure user plane messages between the terminal device and the second NF;

[0619] Provides keys for secure data plane messages between the terminal device and the second NF;

[0620] Provides keys for secure establishment between terminal devices;

[0621] Provides keys for the mobility security of terminal devices;

[0622] Provide keys for secure application-layer messages between terminal devices and third-party servers; or,

[0623] Provides keys for authentication of uncontracted users.

[0624] In some embodiments, the NAS security service includes:

[0625] Establish NAS security between the terminal device and the second NF.

[0626] In some embodiments, establishing NAS security between the terminal device and the second NF includes at least one of the following:

[0627] Provide the second NF with the NAS security key between the second NF and the terminal device; or...

[0628] Provides negotiation services for secure NAS establishment between terminal devices and the second NF.

[0629] In some embodiments, the AS security service includes:

[0630] Establish AS security between the terminal device and the second NF.

[0631] In some embodiments, establishing AS security between the terminal device and the second NF includes at least one of the following:

[0632] Provide the second NF with the AS-secure key between the second NF and the terminal device; or...

[0633] Provides negotiation services for the secure establishment of the AS between the terminal device and the second NF.

[0634] In some embodiments, the user plane security service includes at least one of the following:

[0635] Provide the second NF with a key for secure user plane messages between the second NF and the terminal device;

[0636] To establish user plane security between the second NF and the terminal device, a negotiation service is provided; or,

[0637] Provide the user plane security policy for the terminal to the second NF.

[0638] In some embodiments, the licensed service includes at least one of the following:

[0639] Provide access token services;

[0640] Provides certificate assertion services;

[0641] Services that grant authorization at the granularity of the request message information;

[0642] Provide token verification services;

[0643] To provide network services with the ability to authorize third-party application functions; or,

[0644] This service provides authorization information or tokens to authorized application programming interface (API) callers.

[0645] In some embodiments, the user privacy protection service includes at least one of the following:

[0646] Hiding sensitive user information;

[0647] Provide user consent information to the second NF that implements user consent; or,

[0648] Process user consent information.

[0649] In some embodiments, the security context storage service includes at least one of the following:

[0650] NAS security context storage;

[0651] AS security context storage;

[0652] User plane security context storage;

[0653] Data plane security context storage;

[0654] Security context storage between terminal devices; or,

[0655] Authentication or authorization result storage service.

[0656] In some embodiments, the first NF is deployed in the home network.

[0657] In some embodiments, the authentication service includes at least one of the following:

[0658] Authentication services for contracted users;

[0659] Authentication service for non-contracted users; or,

[0660] Authentication service for non-3GPP devices accessing the network.

[0661] In some embodiments, the key management service includes at least one of the following:

[0662] Key derivation service;

[0663] Key storage service; or,

[0664] Key distribution service.

[0665] In some embodiments, the keys provided by the key management service include at least one of the following:

[0666] Provides a key for establishing NAS security between the terminal device and the second NF in the home network;

[0667] Provides keys for secure user plane messages between terminal devices and the second NF in the home network;

[0668] Provides keys for secure data plane messages between terminal devices and the second NF in the home network;

[0669] Provide keys for secure application-layer messages between terminal devices and third-party servers; or,

[0670] Provides keys for authentication of uncontracted users.

[0671] In some embodiments, the NAS security service includes: establishing NAS security between the terminal device and a second NF in the home network.

[0672] In some embodiments, establishing NAS security between the terminal device and a second NF in the home network includes at least one of the following:

[0673] Provides the NAS security key between the second NF and the terminal device to the second NF in the home network;

[0674] Provide the NAS security key between the second NF and the terminal device to the second NF in the service network; or...

[0675] Provides negotiation services for NAS connections between terminal devices and the second NF in the home network.

[0676] In some embodiments, the user plane security service includes at least one of the following:

[0677] Provides the second NF in the home network with a key for secure user plane messages between the second NF and the terminal device;

[0678] To provide negotiation services for establishing user plane security between the second NF in the home network and the terminal device; or,

[0679] Provide the user plane security policy of the terminal device to the second NF in the home network.

[0680] In some embodiments, the licensed service includes at least one of the following:

[0681] The service of providing access tokens to the second NF in the home network;

[0682] Provide authorization services for credential assertion to the second NF in the home network;

[0683] Services that grant authorization at the granularity of the request message information;

[0684] Provide token verification services for the second NF that does not support token verification in the home network;

[0685] To provide network services with the ability to authorize third-party application functions; or,

[0686] A service that provides authorization information or tokens to authorized API callers.

[0687] In some embodiments, the user privacy protection service includes at least one of the following:

[0688] Hiding sensitive user information;

[0689] Provide user consent information to the second NF that executes the user consent information; or,

[0690] Process user consent information.

[0691] In some embodiments, the security context storage service includes at least one of the following:

[0692] NAS security context storage for terminal devices and the second NF in the home network;

[0693] The terminal device stores the user plane security context of the second NF in the home network;

[0694] The terminal device stores the data plane security context of the second NF in the home network; or...

[0695] Authentication or authorization result storage service.

[0696] In some embodiments, the first NF is deployed in the service network.

[0697] In some embodiments, the authentication service includes at least one of the following:

[0698] The Security Anchoring (SEAF) function provides services during the authentication process;

[0699] The service that triggers re-authentication on the terminal device; or...

[0700] Provides credential assertion services for authentication of service-based RAN devices.

[0701] In some embodiments, the key management service includes at least one of the following:

[0702] Key derivation service;

[0703] Key storage service; or,

[0704] Key distribution service.

[0705] In some embodiments, the keys provided by the key management service include at least one of the following:

[0706] Provides keys for secure NAS establishment between terminal devices and the second NF in the service network;

[0707] Provides keys for secure establishment of the access layer AS between terminal devices and the second NF in the service network;

[0708] Provides keys for secure user plane messages between terminal devices and the second NF in the serving network;

[0709] Provides keys for secure data plane messages between terminal devices and the second NF in the serving network;

[0710] Provides keys for secure establishment between terminal devices; or,

[0711] Provides keys for the mobility security of terminal devices.

[0712] In some embodiments, the NAS security service includes:

[0713] Establish NAS security between terminal devices and the second NF in the service network.

[0714] In some embodiments, establishing NAS security between the terminal device and a second NF in the service network includes at least one of the following:

[0715] Provide the NAS-secure key between the terminal device and the second NF in the service network; or...

[0716] Provides negotiation services for establishing NAS security between terminal devices and the second NF in the service network.

[0717] In some embodiments, the AS security service includes:

[0718] Establish AS security between terminal devices and the second NF in the service network.

[0719] In some embodiments, establishing AS security between a terminal device and a second NF in the serving network includes at least one of the following:

[0720] Provides the AS-secure key between the terminal device and the second NF in the service network;

[0721] It provides negotiation services for the secure establishment of an AS between a terminal device and a second NF in the service network.

[0722] In some embodiments, the user plane security service includes at least one of the following:

[0723] Provides a secure key for user plane messages between the terminal device and the second NF in the service network;

[0724] To provide negotiation services for establishing user plane security between the second NF and the terminal device in the service network; or,

[0725] Provide end-user plane security policies to the second NF in the service network.

[0726] In some embodiments, the licensed service includes at least one of the following:

[0727] The service of providing access tokens to the second NF in the service network;

[0728] Provide credential assertion services to the second NF in the service network;

[0729] Provide token verification services for second NFs that do not support token verification in the service network;

[0730] Services that grant authorization at the granularity of the request message; or...

[0731] A service that provides authorization information or tokens to authorized API callers.

[0732] In some embodiments, the user privacy protection service includes at least one of the following:

[0733] Provide user consent information to the second NF that executes the user consent information; or,

[0734] Process user consent information.

[0735] In some embodiments, the security context storage service includes at least one of the following:

[0736] NAS security context storage for the second NF in the terminal device and service network;

[0737] AS security context storage of the second NF in the terminal device and service network;

[0738] User plane security context storage in the second NF of the terminal device and service network;

[0739] The data plane security context storage of the second NF in the terminal device and service network; or...

[0740] Security context storage between terminal devices.

[0741] In some embodiments, the processing module is further configured to request network services from a third NF.

[0742] In some embodiments, the third NF is used to provide at least one piece of information to the first NF, and the at least one piece of information is used by the first NF to provide security and privacy services.

[0743] In some embodiments, the first NF includes at least one of the following:

[0744] An authentication NF (Authentication NF) is used to provide authentication services.

[0745] Key Management NF is used to provide key management services.

[0746] Authorization NF, the authorization NF is used to provide authorization services;

[0747] Securely establishes an NF (Network Instance), which is used to provide secure establishment services.

[0748] Privacy Protection NF, used to provide user privacy protection services; or,

[0749] Security Context Store (NF) is used to provide security context storage services.

[0750] Optionally, the processing module 5101 described above is used to execute at least one of the steps executed by the first NF in any of the above methods (e.g., step S2101, step S2102, step S2201, but not limited thereto), which will not be elaborated here.

[0751] Figure 6A is a schematic diagram of the network device proposed in an embodiment of this disclosure. This network device can be an access network device, a core network device, a chip, a chip system, or a processor that supports the network device in implementing any of the above methods. Network device 6100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0752] As shown in Figure 6A, the network device 6100 is used to execute any of the above methods. In some embodiments, the network device 6100 includes one or more processors 6101. The processor 6101 may be a general-purpose processor or a special-purpose processor, such as a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, and the central processing unit may be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the network device 6100 is used to execute any of the above methods. Optionally, one or more processors 6101 are used to invoke instructions to cause the network device 6100 to execute any of the above methods.

[0753] In some embodiments, the network device 6100 further includes one or more transceivers 6102. When the network device 6100 includes one or more transceivers 6102, the transceiver 6102 performs at least one of the communication steps such as sending and / or receiving in the above-described method, and the processor 6101 performs at least one of the processing steps in the above-described method (e.g., steps S2101, S2102, and S2201, but not limited thereto). In optional embodiments, the transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, interface, etc., can be used interchangeably; the terms transmitter, sending unit, transmitter, sending circuit, etc., can be used interchangeably; the terms receiver, receiving unit, receiver, receiving circuit, etc., can be used interchangeably.

[0754] In some embodiments, the network device 6100 further includes one or more memories 6103 for storing data and / or instructions. Optionally, one or more processors 6101 are used to invoke instructions stored in the memory 6103 to cause the network device 6100 to perform any of the above methods. Optionally, all or part of the memory 6103 may also be located outside the network device 6100. In optional embodiments, the network device 6100 may include one or more interface circuits 6104. Optionally, the interface circuit 6104 is connected to the memory 6103 and can be used to receive data and / or instructions from the memory 6103 or other devices, and can be used to send data and / or instructions to the memory 6103 or other devices. For example, the interface circuit 6104 can read data and / or instructions stored in the memory 6103 and send the data and / or instructions to the processor 6101.

[0755] The structure of network device 6100 is not limited to that shown in Figure 6A. Network device can be a standalone device or part of a larger device. For example, network device can be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally including storage components for storing data, programs and / or instructions; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0756] Figure 6B is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. For cases where the network device 6100 can be a chip or a chip system, please refer to the schematic diagram of the chip 6200 shown in Figure 6B, but it is not limited thereto.

[0757] Chip 6200 includes one or more processors 6201. Chip 6200 is used to perform any of the methods described above.

[0758] In some embodiments, chip 6200 further includes one or more interface circuits 6202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 6200 further includes one or more memories 6203 for storing data and / or instructions. Optionally, all or part of the memories 6203 may be located outside of chip 6200. Optionally, interface circuit 6202 is connected to memory 6203, and interface circuit 6202 can be used to receive data and / or instructions from memory 6203 or other devices, and interface circuit 6202 can be used to send data and / or instructions to memory 6203 or other devices. For example, interface circuit 6202 can read data and / or instructions stored in memory 6203 and send the data and / or instructions to processor 6201.

[0759] In some embodiments, the interface circuit 6202 performs at least one of the communication steps, such as sending and / or receiving, in the above-described method. For example, the interface circuit 6202 performing the communication steps, such as sending and / or receiving, in the above-described method means that the interface circuit 6202 performs data and / or instruction interaction between the processor 6201, the chip 6200, the memory 6203, or the transceiver device. In some embodiments, the processor 6201 performs at least one of other steps (e.g., steps S2101, S2102, and S2201, but not limited thereto).

[0760] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0761] This disclosure also proposes a storage medium storing instructions that, when executed on a network device, cause the network device to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0762] This disclosure also proposes a program product, including a program and / or instructions, which, when executed by a network device, cause the network device to perform any of the above methods. Optionally, the program product is a computer program product. Optionally, the program product is stored on the storage medium.

[0763] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

[0764] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0765] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0766] The above are merely specific embodiments of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.

Claims

1. A service method, characterized in that, Performed by a first network function NF, the method includes: Provide security and privacy services; The security and privacy service includes a security service and / or a privacy service, which is used to be invoked by multiple second NF requests.

2. The method according to claim 1, characterized in that, The number of the first NF is 1; or, The first NF includes a security NF and a privacy NF, wherein the security NF is used to provide the security service, and the privacy NF is used to provide the privacy service; or, There are multiple first NFs, and each first NF is used to provide corresponding security and privacy services.

3. The method according to claim 1 or 2, characterized in that, The security and privacy services include at least one of the following: Authentication service; Key management service; Non-access tier NAS security services; Access layer AS security services; User-side security services; Authorized services; User privacy protection services; or Security context storage service.

4. The method according to claim 3, characterized in that, The authentication service includes at least one of the following: Authentication services for contracted users; Authentication services for non-contracted users; Certification services for non-3GPP equipment access under the Third Generation Partnership Project; The service that triggers re-authentication on the terminal device; or, Provides credential assertion services for the authentication of service-based radio access network (RAN) devices.

5. The method according to claim 3 or 4, characterized in that, The key management service includes at least one of the following: Key derivation service; Key storage service; or, Key distribution service.

6. The method according to any one of claims 3-5, characterized in that, The keys provided by the key management service include at least one of the following: Provides a key for establishing NAS security between the terminal device and the second NF; Provides a key for secure establishment of the access layer AS between the terminal device and the second NF; Provides keys for secure user plane messages between the terminal device and the second NF; Provides keys for secure data plane messages between the terminal device and the second NF; Provides keys for secure establishment between terminal devices; Provides keys for the mobility security of terminal devices; Provides keys for secure application-layer messages between terminal devices and third-party servers; or, Provides keys for authentication of uncontracted users.

7. The method according to any one of claims 3-6, characterized in that, The NAS security services include: Establish NAS security between the terminal device and the second NF.

8. The method according to claim 7, characterized in that, Establishing NAS security between the terminal device and the second NF includes at least one of the following: Provide the second NF with the NAS security key between the second NF and the terminal device; or... It provides negotiation services for the secure establishment of NAS between the terminal device and the second NF.

9. The method according to any one of claims 3-8, characterized in that, The AS security services include: Establish AS security between the terminal device and the second NF.

10. The method according to claim 9, characterized in that, Establishing AS security between the terminal device and the second NF includes at least one of the following: Provide the second NF with the AS-secure key between the second NF and the terminal device; or... It provides negotiation services for the secure establishment of the AS between the terminal device and the second NF.

11. The method according to any one of claims 3-10, characterized in that, The user plane security service includes at least one of the following: Provide the second NF with a key for secure user plane messages between the second NF and the terminal device; To provide negotiation services for establishing user plane security between the second NF and the terminal device; or, Provide the user plane security policy of the terminal to the second NF.

12. The method according to any one of claims 3-11, characterized in that, The authorized services include at least one of the following: Provide access token services; Provides certificate assertion services; Services that grant authorization at the granularity of the request message information; Provide token verification services; To provide network services with the ability to authorize third-party application functions; or, This service provides authorization information or tokens to authorized application programming interface (API) callers.

13. The method according to any one of claims 3-12, characterized in that, The user privacy protection service includes at least one of the following: Hiding sensitive user information; Provide user consent information to the second NF that implements user consent; or, Process user consent information.

14. The method according to any one of claims 3-13, characterized in that, The security context storage service includes at least one of the following: NAS security context storage; AS security context storage; User plane security context storage; Data plane security context storage; Security context storage between terminal devices; or, Authentication or authorization result storage service.

15. The method according to claim 3, characterized in that, The first NF is deployed in the home network.

16. The method according to claim 15, characterized in that, The authentication service includes at least one of the following: Authentication services for contracted users; Authentication service for non-contracted users; or, Authentication service for non-3GPP devices accessing the network.

17. The method according to claim 15 or 16, characterized in that, The key management service includes at least one of the following: Key derivation service; Key storage service; or, Key distribution service.

18. The method according to any one of claims 15-17, characterized in that, The keys provided by the key management service include at least one of the following: Provides a key for establishing NAS security between the terminal device and the second NF in the home network; Provides keys for secure user plane messages between the terminal device and the second NF in the home network; Provide a key for secure data plane messages between the terminal device and the second NF in the home network; Provides keys for secure application-layer messages between terminal devices and third-party servers; or, Provides keys for authentication of uncontracted users.

19. The method according to any one of claims 15-18, characterized in that, The NAS security service includes: establishing NAS security between the terminal device and the second NF in the home network.

20. The method according to claim 19, characterized in that, Establishing NAS security between the terminal device and the second NF in the home network includes at least one of the following: Provide the second NF in the home network with a NAS-secure key between the second NF and the terminal device; Provide the second NF in the service network with the NAS security key between the second NF and the terminal device; or... Provide negotiation services for NAS connections between terminal devices and the second NF in the home network.

21. The method according to any one of claims 15-19, characterized in that, The user plane security service includes at least one of the following: Provide the second NF in the home network with a key for user plane message security between the second NF and the terminal device; To provide negotiation services for establishing user plane security between the second NF in the home network and the terminal device; or, Provide the user plane security policy of the terminal device to the second NF in the home network.

22. The method according to any one of claims 15-21, characterized in that, The authorized services include at least one of the following: The service of providing access tokens to the second NF in the home network; Provide authorization services for credential assertion to the second NF in the home network; Services that grant authorization at the granularity of the request message information; Provide token verification services for the second NF in the home network that does not support token verification; To provide network services with the ability to authorize third-party application functions; or, A service that provides authorization information or tokens to authorized API callers.

23. The method according to any one of claims 15-22, characterized in that, The user privacy protection service includes at least one of the following: Hiding sensitive user information; Provide user consent information to the second NF that executes the user consent information; or, Process user consent information.

24. The method according to any one of claims 15-23, characterized in that, The security context storage service includes at least one of the following: The terminal device stores the NAS security context of the second NF in the home network; The terminal device stores the user plane security context of the second NF in the home network; The terminal device stores the data plane security context of the second NF in the home network; or, Authentication or authorization result storage service.

25. The method according to claim 3, characterized in that, The first NF is deployed in the service network.

26. The method according to claim 25, characterized in that, The authentication service includes at least one of the following: The Security Anchoring (SEAF) function provides services during the authentication process; The service that triggers re-authentication on the terminal device; or... Provides credential assertion services for authentication of service-based RAN devices.

27. The method according to claim 25 or 26, characterized in that, The key management service includes at least one of the following: Key derivation service; Key storage service; or, Key distribution service.

28. The method according to any one of claims 25-27, characterized in that, The keys provided by the key management service include at least one of the following: Provides a key for establishing NAS security between the terminal device and the second NF in the service network; Provides a key for secure establishment of the access layer AS between the terminal device and the second NF in the service network; Provides a key for secure user plane messages between the terminal device and the second NF in the service network; Provides a key for secure data plane messages between the terminal device and the second NF in the service network; Provides keys for secure establishment between terminal devices; or, Provides keys for the mobility security of terminal devices.

29. The method according to any one of claims 25-28, characterized in that, The NAS security services include: Establish NAS security between the terminal device and the second NF in the service network.

30. The method according to claim 29, characterized in that, Establishing NAS security between the terminal device and the second NF in the service network includes at least one of the following: Provide the second NF in the service network with a NAS-secure key for communication with the terminal device; or... Negotiation services are provided for establishing NAS security between the terminal device and the second NF in the service network.

31. The method according to any one of claims 25-30, characterized in that, The AS security services include: Establish AS security between the terminal device and the second NF in the service network.

32. The method according to claim 31, characterized in that, Establishing AS security between the terminal device and the second NF in the service network includes at least one of the following: Provides the second NF in the service network with an AS-secure key between the terminal device; Provide negotiation services for the secure establishment of the AS between the terminal device and the second NF in the service network.

33. The method according to any one of claims 25-32, characterized in that, The user plane security service includes at least one of the following: Provide the second NF in the service network with a key for secure user plane messages between the terminal device; To provide negotiation services for establishing user plane security between the second NF and the terminal device in the service network; or, Provide end-user plane security policies to the second NF in the service network.

34. The method according to any one of claims 25-33, characterized in that, The authorized services include at least one of the following: The service of providing access tokens to the second NF in the service network; Provide credential assertion services to the second NF in the service network; Provide token verification services for the second NF in the service network that does not support token verification; Services that grant authorization at the granularity of the request message; or... A service that provides authorization information or tokens to authorized API callers.

35. The method according to any one of claims 25-34, characterized in that, The user privacy protection service includes at least one of the following: Provide user consent information to the second NF that executes the user consent information; or, Process user consent information.

36. The method according to any one of claims 25-35, characterized in that, The security context storage service includes at least one of the following: The NAS security context storage of the terminal device and the second NF in the service network; The terminal device stores the AS security context of the second NF in the service network; The terminal device stores the user plane security context of the second NF in the service network. The terminal device stores the data plane security context of the second NF in the service network. or, Security context storage between terminal devices.

37. The method according to any one of claims 1-36, characterized in that, The method includes: Request network services from the third NF.

38. The method according to claim 37, characterized in that, The third NF is used to provide at least one piece of information to the first NF, and the at least one piece of information is used by the first NF to provide the security and privacy service.

39. The method according to any one of claims 1-38, characterized in that, The first NF includes at least one of the following: An authentication NF, which is used to provide authentication services; A key management NF, wherein the key management NF is used to provide key management services; An authorization NF, which is used to provide authorization services; A secure establishment NF is used to provide secure establishment services. A privacy protection NF, wherein the privacy protection NF is used to provide user privacy protection services; or, A security context storage NF is used to provide security context storage services.

40. A network device, characterized in that, The network device is used to perform the service method according to any one of claims 1-39.

41. A network system, characterized in that, Includes the first NF and multiple second NFs, among which, The first NF is used to provide security and privacy services, which include security services and / or privacy services; The plurality of second NFs are used to request the invocation of the security and privacy service from the first NF.

42. A storage medium storing instructions, characterized in that, When the instruction is executed on a network device, the network device performs the service method as described in any one of claims 1-39.

43. A program product comprising at least one of a program and instructions, characterized in that, When at least one of the program or instructions is executed by the network device, it implements the steps of the method according to any one of claims 1-39.