Wireless communication method, terminal, and network node

WO2026200991A1PCT designated stage Publication Date: 2026-10-01VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/085968
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-26
Filing Date
2026-03-25
Publication Date
2026-10-01

Smart Images

  • Figure CN2026085968_01102026_PF_FP_ABST
    Figure CN2026085968_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the field of communications, and discloses a wireless communication method, a terminal, and a network node. The wireless communication method in embodiments of the present application comprises: a terminal executes a first operation, a second operation, or a third operation. The first operation comprises: executing a first registration process with a first network node in a first network and generating a first key, wherein the first key is used for performing security protection on interaction between the terminal and the first network. The second operation comprises: generating a second derived key on the basis of a first derived key or the first key, and executing a second registration process with the first network node in the first network on the basis of the second derived key. The third operation comprises: executing a third registration process with the first network node in the first network, and at least one of: stopping, not executing, skipping, or executing a first authentication process in the third registration process; and generating the second derived key on the basis of the first derived key.
Need to check novelty before this filing date? Find Prior Art

Description

Wireless communication methods, terminals and network nodes

[0001] Cross-reference to related applications

[0002] This application is based on and claims priority to Chinese Patent Application No. 202510367986.4, filed on March 26, 2025, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of communication technology, and more specifically, to a wireless communication method, terminal, and network node. Background Technology

[0004] Overlay networks, such as the Internet Protocol Multimedia Subsystem (IMS) network, are deployed on mobile networks. When a user equipment (UE) accesses an overlay network, it needs to complete mutual authentication with the overlay network to secure the interaction between the UE and the overlay network.

[0005] In related technologies, regardless of whether the UE and the mobile network have completed mutual authentication, the UE and the overlay network need to complete mutual authentication, which reduces the authentication flexibility between the UE and the overlay network. Summary of the Invention

[0006] This application provides a wireless communication method, terminal, and network node, which can improve the flexibility of authentication between the terminal and the first network.

[0007] In a first aspect, a wireless communication method is provided, executed by a terminal, the method comprising:

[0008] The terminal executes the first operation, the second operation, or the third operation;

[0009] The first operation includes: performing a first registration process with a first network node in a first network and generating a first key, wherein the first key is used to securely protect the interaction between the terminal and the first network;

[0010] The second operation includes: generating a second derived key based on a first derived key or a first key, and performing a second registration process with a first network node in a first network based on the second derived key;

[0011] The third operation includes: performing a third registration process with a first network node in the first network and at least one of the following:

[0012] The first authentication process may be stopped, not executed, skipped, or executed during the third registration process.

[0013] Generate a second derived key based on the first derived key;

[0014] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0015] The first derived key is generated based on the second authentication process;

[0016] The second derived key is used to securely protect the interaction between the terminal and the first network.

[0017] The second authentication process is an authentication process between the terminal and the second network; the first authentication process is an authentication process between the terminal and the first network.

[0018] The second network is the network accessed by the terminal.

[0019] Secondly, a wireless communication method is provided, executed by a first network node, the method comprising:

[0020] The first network node receives a registration request from the terminal;

[0021] The first network node sends at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node to obtain authentication status information for the second authentication process;

[0022] The first network node receives at least one of the result information and the authentication status information of the second authentication process from the second network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0023] The first network node sends a response message to the registration request;

[0024] Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network, and the first network node is a network-side node of the first network;

[0025] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0026] The third derived key is generated based on the shared key of the terminal;

[0027] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0028] The first derived key is generated based on the second authentication process;

[0029] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0030] The second authentication process is an authentication process between the terminal and the second network.

[0031] Thirdly, a wireless communication method is provided, executed by a second network node, the method comprising:

[0032] The second network node receives at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information from the first network node, and uses it to obtain authentication status information for the second authentication process.

[0033] The second network node sends at least one of the following to the first network node: result information and authentication status information of the second authentication process, based on at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information. The result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0034] Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network, and the first network node is a network-side node of the first network;

[0035] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0036] The third derived key is generated based on the shared key of the terminal;

[0037] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0038] The first derived key is generated based on the second authentication process;

[0039] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0040] The second authentication process is the authentication process between the terminal and the second network.

[0041] Fourthly, a wireless communication method is provided, executed by a fifth network node, the method comprising:

[0042] The fifth network node receives the registration request from the terminal and sends the registration request to the first network node;

[0043] The fifth network node receives a response message for the registration request from the first network node. The response message includes a second derived key and third information, wherein the third information includes at least one of the following: an indication of successful registration, at least one of the systems of the first network and the second network, an indication to stop, not execute, skip, or execute the first authentication process, and an indication that the second authentication process has been successful.

[0044] The fifth network node establishes a secure connection with the terminal based on the response message;

[0045] The first network refers to the network in which the fifth network node and the first network node are located.

[0046] Fifthly, a wireless communication device is provided, comprising:

[0047] The processing module is used to perform the first operation, the second operation, or the third operation;

[0048] The first operation includes: performing a first registration process with a first network node in the first network and generating a first key, wherein the first key is used to securely protect the interaction between the terminal and the first network;

[0049] The second operation includes: generating a second derived key based on a first derived key or a first key, and performing a second registration process with a first network node in a first network based on the second derived key;

[0050] The third operation includes: performing a third registration process with a first network node in the first network and at least one of the following:

[0051] The first authentication process may be stopped, not executed, skipped, or executed during the third registration process.

[0052] Generate a second derived key based on the first derived key;

[0053] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0054] The first derived key is generated based on the second authentication process;

[0055] The second derived key is used to securely protect the interaction between the terminal and the first network.

[0056] The second authentication process is an authentication process between the terminal and the second network; the first authentication process is an authentication process between the terminal and the first network.

[0057] The second network is the network accessed by the terminal.

[0058] Sixthly, a wireless communication device is provided, comprising:

[0059] The receiving module is used to receive registration requests from the terminal;

[0060] The sending module is used to send at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node, in order to obtain authentication status information of the second authentication process;

[0061] The receiving module is further configured to: receive at least one of result information and authentication status information of the second authentication process from the second network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0062] The sending module is also used to: send a response message for the registration request;

[0063] Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network;

[0064] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0065] The third derived key is generated based on the shared key of the terminal;

[0066] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0067] The first derived key is generated based on the second authentication process;

[0068] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0069] The second authentication process is an authentication process between the terminal and the second network.

[0070] In a seventh aspect, a wireless communication device is provided, comprising:

[0071] The receiving module is used to receive at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information from the first network node, for obtaining authentication status information of the second authentication process;

[0072] The sending module is used to send at least one of result information and authentication status information of the second authentication process to the first network node based on at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information. The result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0073] Wherein, the first network node is the network-side node of the first network;

[0074] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0075] The third derived key is generated based on the shared key of the terminal;

[0076] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0077] The first derived key is generated based on the second authentication process;

[0078] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0079] The second authentication process is the authentication process between the terminal and the second network.

[0080] Eighthly, a wireless communication device is provided, comprising:

[0081] The receiving module is used to receive registration requests from the terminal;

[0082] The sending module is used to send a registration request to the first network node;

[0083] The receiving module is further configured to receive a response message of the registration request from the first network node. The response message includes a second derived key and third information, wherein the third information includes at least one of the following: an indication of successful registration, at least one of the systems of the first network and the second network, an indication to stop, not execute, skip, or execute the first authentication process, and an indication that the second authentication process has been successful.

[0084] The processing module is used to establish a secure connection with the terminal based on the response message;

[0085] Wherein, the first network is the network where the first network node is located.

[0086] A ninth aspect provides a wireless communication device configured to perform the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect, or implement the steps of the method described in the third aspect, or implement the steps of the method described in the fourth aspect.

[0087] In a tenth aspect, a terminal is provided, the terminal including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the first aspect.

[0088] Eleventhly, a terminal is provided, including a processor and a communication interface, wherein the processor is used to perform a first operation, a second operation, or a third operation;

[0089] The first operation includes: performing a first registration process with a first network node in a first network and generating a first key, wherein the first key is used to securely protect the interaction between the terminal and the first network;

[0090] The second operation includes: generating a second derived key based on a first derived key or a first key, and performing a second registration process with a first network node in a first network based on the second derived key;

[0091] The third operation includes: performing a third registration process with a first network node in the first network and at least one of the following:

[0092] The first authentication process may be stopped, not executed, skipped, or executed during the third registration process.

[0093] Generate a second derived key based on the first derived key;

[0094] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0095] The first derived key is generated based on the second authentication process;

[0096] The second derived key is used to securely protect the interaction between the terminal and the first network.

[0097] The second authentication process is an authentication process between the terminal and the second network; the first authentication process is an authentication process between the terminal and the first network.

[0098] The second network is the network accessed by the terminal.

[0099] In a twelfth aspect, a network node is provided, the network node including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the second aspect, or implementing the steps of the method as described in the third aspect, or implementing the steps of the method as described in the fourth aspect.

[0100] In a thirteenth aspect, a network node is provided, including a processor and a communication interface, wherein the communication interface is used for:

[0101] Receive registration requests from terminals;

[0102] Send at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node to obtain authentication status information for the second authentication process;

[0103] Receive at least one of the result information and the authentication status information of the second authentication process from the second network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0104] Send a response message to the registration request;

[0105] Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network;

[0106] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0107] The third derived key is generated based on the shared key of the terminal;

[0108] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0109] The first derived key is generated based on the second authentication process;

[0110] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0111] The second authentication process is an authentication process between the terminal and the second network.

[0112] In a fourteenth aspect, a network node is provided, including a processor and a communication interface, wherein the communication interface is used for:

[0113] Receive at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information from the first network node, for the purpose of obtaining authentication status information for the second authentication process;

[0114] Based on at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information, at least one of result information and authentication status information of the second authentication process is sent to the first network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0115] Wherein, the first network node is the network-side node of the first network;

[0116] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0117] The third derived key is generated based on the shared key of the terminal;

[0118] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0119] The first derived key is generated based on the second authentication process;

[0120] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0121] The second authentication process is the authentication process between the terminal and the second network.

[0122] In a fifteenth aspect, a network node is provided, including a processor and a communication interface, wherein the communication interface is used for:

[0123] Receive registration request from the terminal;

[0124] The sending module is used to send a registration request to the first network node;

[0125] The receiving module is further configured to receive a response message of the registration request from the first network node. The response message includes a second derived key and third information, wherein the third information includes at least one of the following: an indication of successful registration, at least one of the systems of the first network and the second network, an indication to stop, not execute, skip, or execute the first authentication process, and an indication that the second authentication process has been successful.

[0126] The processor is used to establish a secure connection with the terminal based on the response message;

[0127] Wherein, the first network is the network where the first network node is located.

[0128] In a sixteenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.

[0129] In a seventeenth aspect, a wireless communication system is provided, comprising: a terminal and a network node, wherein the terminal is configured to perform the steps of the method described in the first aspect, and the network node is configured to perform the steps of the method described in the second aspect, or implement the steps of the method described in the third aspect, or implement the steps of the method described in the fourth aspect.

[0130] In an eighteenth aspect, a chip is provided, the chip including a processor and a communication interface coupled to the processor, the processor being configured to run a program or instructions to implement the steps of the method as described in the first aspect, or the steps of the method as described in the second aspect, or the steps of the method as described in the third aspect, or the steps of the method as described in the fourth aspect.

[0131] In a nineteenth aspect, a computer program / program product is provided, the computer program / program product being stored in a storage medium, the computer program / program product being executed by at least one processor to implement the steps of the wireless communication method as described in the first or second aspect, or the steps of the method as described in the third aspect, or the steps of the method as described in the fourth aspect.

[0132] In this embodiment, the terminal performs a first operation, a second operation, or a third operation, enabling the terminal to obtain a first key or a second derived key for securely protecting the interaction between the terminal and the first network through a first registration process, a second registration process, or a third registration process. This improves the flexibility of authentication between the terminal and the first network. The terminal generates a second derived key based on the first derived key or the first key, which reduces signaling overhead during the authentication process. Attached Figure Description

[0133] Figure 1 is a schematic diagram of a communication system architecture provided in an embodiment of this application.

[0134] Figures 2 to 7 are schematic flowcharts of the wireless communication method provided in the embodiments of this application.

[0135] Figures 8 to 11 are schematic block diagrams of the wireless communication device provided in the embodiments of this application.

[0136] Figure 12 is a schematic block diagram of a communication device provided in an embodiment of this application.

[0137] Figure 13 is a schematic diagram of the hardware structure of a terminal provided in an embodiment of this application.

[0138] Figure 14 is a schematic block diagram of a network node provided in an embodiment of this application. Detailed Implementation

[0139] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0140] The terms "first," "second," etc., used in this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, the first object can be one or more. Furthermore, "or" in this application indicates at least one of the connected objects. For example, the scope of protection for "A or B" covers at least three scenarios: Scenario 1: including A but not B; Scenario 2: including B but not A; Scenario 3: including both A and B. In addition, the terms "A and / or B," "at least one of A and B," and "at least one of A or B" also cover at least the above three scenarios. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0141] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as the sender explicitly informing the receiver of specific information, the required operation, or the requested result in the instruction sent. An indirect instruction can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the required operation or requested result based on the judgment result.

[0142] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. The following description describes New Radio (NR) systems for illustrative purposes, and the term NR is used in most of the following description; however, these technologies can also be applied to systems other than NR systems, such as 6th generation (6G) radio systems. th Generation 6G communication system.

[0143] Figure 1 shows a block diagram of a wireless communication system applicable to an embodiment of this application. The wireless communication system includes a terminal 11 and a network node 12. The terminal 11 can also be referred to as User Equipment (UE), and can be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipboard equipment, pedestrian user equipment (PUE), smart home (home devices with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, or self-service machine, etc. Wearable devices include: smartwatches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart chains, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among these, in-vehicle devices can also be referred to as in-vehicle terminals, in-vehicle controllers, in-vehicle modules, in-vehicle components, in-vehicle chips, or in-vehicle units, etc. It should be noted that the specific type of terminal 11 is not limited in this application embodiment. Network node 12 may include access network equipment or core network equipment, wherein access network equipment may also be referred to as Radio Access Network (RAN) equipment, radio access network function, or radio access network unit. Access network equipment may include base stations, Wireless Local Area Network (WLAN) access points (APs), or Wireless Fidelity (WiFi) nodes, etc.Among them, base stations can be referred to as Node B (NB), Evolved Node B (eNB), Next Generation Node B (gNB), New Radio Node B (NR Node B), Access Point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), Radio Base Station, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B, Transmit / Receive Point (TRP), Non-Terrestrial Network (NTN) equipment (such as satellite or high altitude platform stations). The term "base station" can be any suitable term in the field, such as "station" or any other appropriate term in the relevant field, as long as the same technical effect is achieved. The term "base station" is not limited to specific technical terms. It should be noted that the embodiments of this application only use the base station in the NR system as an example for introduction, and do not limit the specific type of base station.

[0144] Core network equipment, also known as core network nodes, core network functions, or core network elements, includes, but is not limited to, at least one of the following: Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), and Binding Support. Functions include BSF, Application Function (AF), Location Management Function (LMF), Gateway Mobile Location Centre (GMLC), Network Data Analytics Function (NWDAF), and Non-Terrestrial Network (NTN) equipment (such as satellite or high altitude platform station).It should be noted that the embodiments of this application only use the core network equipment in the NR system as an example for introduction, and do not limit the specific type of core network equipment. If the name of the core network equipment mentioned in the embodiments of this application changes in subsequent protocol versions (e.g., 6G), it is also within the scope of protection of this application.

[0145] Optionally, the core network equipment can be implemented by one or more functional modules in a single device, or by multiple devices working together; this application does not specifically limit this. It is understood that the aforementioned functional modules can be network elements in hardware devices, software functional modules running on dedicated hardware, or virtualized functional modules instantiated on a platform (e.g., a cloud platform).

[0146] To facilitate a better understanding of the embodiments of this application, the related technologies are described.

[0147] (1) There is a certified IP Multimedia Subsystem (IMS) registration process.

[0148] A certified IMS registration process typically includes the following steps:

[0149] Step 1: Initial registration request.

[0150] The UE sends a Session Initiation Protocol REGISTER (SIP REGISTER) message to the Proxy-Call Session Control Function (P-CSCF) to request registration with the IMS network.

[0151] Step 2: Authentication Challenge.

[0152] The P-CSCF forwards the registration request to the Interrogating-Call Session Control Function (I-CSCF), which then interacts with the Home Subscriber Server (HSS) to retrieve the user's profile and authentication vector (AV). The HSS generates a random number (RAND) and uses key K to generate a session key Ks. It then uses key K and a sequence number (SQN) to generate an authentication token (AUTN). The HSS returns RAND, AUTN, and Ks to the P-CSCF, which in turn includes RAND and AUTN in a 401 Unauthorized response and sends it to the UE.

[0153] Step 3: Terminal authentication.

[0154] The UE extracts the Message Authentication Code (MAC) and Sequence Number (SQN) from the received AUTN and verifies them using the key K and RAND. If the verification is successful, the UE considers the network trustworthy and calculates the response RES and Ks.

[0155] Step 4: Online authentication.

[0156] The UE and P-CSCF establish a secure connection based on Ks (e.g., Internet Protocol Security (IPSec) or Transport Layer Security (TLS)) to protect signaling transmission between the UE and P-CSCF. The UE reconstructs the SIP REGISTER message and sends it to the P-CSCF (through the secure connection) carrying the RES. The P-CSCF forwards the response (RES) to the S-CSCF, which compares the RES with the expected response (XRES) obtained from the HSS. If they match, the UE is considered legitimate.

[0157] Step 5: Registration complete.

[0158] After authentication (e.g., network authentication) is successful, the S-CSCF downloads user data from the HSS, the registration process is completed, and the UE successfully registers to the IMS network.

[0159] (2) IMS re-registration process.

[0160] The certified IMS registration process is as follows:

[0161] Step 1: The UE sends a re-registration request to the P-CSCF.

[0162] The UE sends a new registration request to the P-CSCF, which includes the following key fields:

[0163] Expires header field: Setting it to a non-zero value indicates an update rather than a logout.

[0164] Security Association Identifier: Reuse existing IPsec Security Associations (SAs).

[0165] No authentication parameters: No new Authorization header or response challenge (such as RES) is included.

[0166] Step 2: P-CSCF verifies the Security Association (SA).

[0167] The P-CSCF verifies the validity of the SA, confirming its lifespan (e.g., no timeout) and integrity. If the SA is valid, the P-CSCF forwards the request to the S-CSCF without triggering Authentication and Key Agreement (AKA) authentication.

[0168] Step 3: S-CSCF processes the update.

[0169] S-CSCF accepts uncertified updates when certain conditions are met.

[0170] Step 4: UE confirms update.

[0171] The UE receives a successful registration response and maintains that existing sessions, SAs, and service flows (such as Voice over Long-Term Evolution (VoLTE) call service flows) are unaffected.

[0172] As shown above, the IMS network is the first network (e.g., an overlay network) above the second network (e.g., a mobile network). A UE needs to access the mobile network first to access the IMS network. When a UE accesses the mobile network, an authentication process is required. If authentication is successful, the UDM / HSS and the UE will derive a subkey based on a shared Long Term Key (LTK) for data security protection and processing between the UE and the mobile network. When a UE accesses the IMS network, in most cases, the UE and the IMS network also need to perform an authentication process. In most cases, the IMS network's authentication process uses the same authentication scheme as the mobile network (i.e., the AKA authentication scheme) and is based on the LTK, just like the mobile network's authentication process. That is, regardless of whether the UE and the mobile network have completed mutual authentication, the UE and the overlay network need to complete mutual authentication, unless the UE can skip the authentication process when re-registering to the IMS network through a valid secure connection. In this implementation, when a UE needs to register to the first network, the flexibility of authentication between the terminal and the first network is improved by considering the UE's registration or authentication status in the second network.

[0173] The wireless communication method provided in this application will be described in detail below with reference to the accompanying drawings and through some embodiments and application scenarios.

[0174] Figure 2 is a schematic flowchart of a wireless communication method 200 according to an embodiment of this application.

[0175] As shown in Figure 2, the wireless communication method 200 may include at least some of the following:

[0176] S201, the terminal performs the first operation, the second operation, or the third operation;

[0177] The first operation includes: performing a first registration process with a first network node in a first network and generating a first key, wherein the first key is used to securely protect the interaction between the terminal and the first network;

[0178] The second operation includes: generating a second derived key based on a first derived key or a first key, and performing a second registration process with a first network node in a first network based on the second derived key;

[0179] The third operation includes: performing a third registration process with a first network node in the first network and at least one of the following:

[0180] The first authentication process may be stopped, not executed, skipped, or executed during the third registration process.

[0181] Generate a second derived key based on the first derived key;

[0182] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0183] The first derived key is generated based on the second authentication process;

[0184] The second derived key is used to securely protect the interaction between the terminal and the first network.

[0185] The second authentication process is an authentication process between the terminal and the second network; the first authentication process is an authentication process between the terminal and the first network.

[0186] The second network is the network accessed by the terminal.

[0187] For example, the second network may be the network to which the terminal is attached or registered, or the second network may be the network to which the terminal camps in a cell.

[0188] For example, the first network is an IMS network, and the second network is a non-IMS network. Optionally, the non-IMS network includes a mobile network.

[0189] For example, the first network node may also be referred to as a first network function, a first network element, a first network device, or a first network-side device. For instance, the first network node includes a P / I / S-CSCF.

[0190] For example, when the first network and the second network adopt a unified authentication architecture, the first network node obtains the authentication vector from the second network node, and the second network node provides the first key. For instance, if the first network node is a P-CSCF and the second network node is an AUSF, and the P-CSCF obtains the authentication vector from the AUSF, and the AUSF provides the first key, then the first key is K. AUSF When the first key is provided by P-CSCF, the first key is based on K. AUSF Derived K IMS .

[0191] For example, the first derived key is a key generated based on the second authentication process if the second authentication process is successful, such as K. AUSF The first key is not generated based on the second authentication process, but rather is a key generated by the terminal during the first registration process.

[0192] For example, the identifier of the terminal in the second network includes: a permanent identifier of the terminal in the second network or a temporary identifier of the terminal in the first network. And / or, the identifier of the terminal in the first network includes: a private identifier of the terminal in the first network or a public identifier of the terminal in the first network.

[0193] For example, when the second network is a mobile network, the strings related to the system name of the second network include, but are not limited to: "eps", "eps_auth", "5GS", and "5GS_auth". The information of the second network includes, but is not limited to: network identifier or name, network domain name, network identifier or name of the home or visited network, and network domain name of the home or visited network. The identifier of the terminal in the second network includes, but is not limited to: Subscription Concealed Identifier (SUCI), Globally Unique Temporary Identifier (GUTI), and Subscription Permanent Identifier (SUPI).

[0194] For example, when the first network is an IMS network, the strings related to the system name of the first network include, but are not limited to, "ims" and "ims_auth". The information of the first network may include IMS network element information, such as the address or identifier of the P / I / S-CSCF. The identifier of the terminal in the first network includes, but is not limited to, IMS Private Identity (IMPI) and IMS Public Identity (IMPU).

[0195] For example, if the second authentication process fails or is not executed, the terminal performs the first operation.

[0196] For example, the terminal performs the second operation if the second authentication process is unsuccessful or not executed, or if the second authentication process is successful.

[0197] For example, if the second authentication process is successful, the terminal performs the third operation.

[0198] It should be understood that whether the second authentication process is executed or successful can be determined by the terminal or indicated by the network, and this application does not make specific limitations on this.

[0199] For example, when the terminal performs the first operation, the first key is used to securely protect the interaction between the terminal and the first network; when the terminal performs the second or third operation, the second derived key is used to securely protect the interaction between the terminal and the first network.

[0200] For example, if the second authentication process is successful, the first network may determine whether to execute the first authentication process. For instance, if the second authentication process is successful, the first network node determines whether to execute the first authentication process.

[0201] In this embodiment, the terminal performs a first operation, a second operation, or a third operation, enabling the terminal to obtain a first key or a second derived key for securely protecting the interaction between the terminal and the first network through a first registration process, a second registration process, or a third registration process. This improves the flexibility of authentication between the terminal and the first network. In particular, when the terminal generates a second derived key based on the first derived key or the first key, the signaling overhead in the authentication process can be reduced.

[0202] In some embodiments, S201 includes:

[0203] The terminal performs the first operation, the second operation, or the third operation based on at least one of the following:

[0204] The network type associated with the second network and the access technology used by the terminal to access the second network;

[0205] The access technology used by the terminal to access the second network includes at least one of the following: high-orbit satellite access, medium-orbit satellite access, low-orbit satellite access, and non-terrestrial network (NTN) access;

[0206] The network types associated with the second network include at least one of the following: Standalone Non-Public Network (SNPN), Public Land Mobile Network-Non-Public Network (PLMN-NPN), Non-Public Network (NPN), and Terrestrial Network (TN).

[0207] For example, when the network type associated with the second network is a specific network type, the terminal performs the first operation, the second operation, or the third operation; or, the terminal performs the operation among the first operation, the second operation, and the third operation that matches the network type associated with the second network. The specific network type may be agreed upon through a protocol, determined by the terminal, or configured through network settings.

[0208] For example, when the terminal uses a specific access technology to access the second network, the terminal performs the first operation, the second operation, or the third operation; or, the terminal performs the operation among the first operation, the second operation, and the third operation that matches the access technology used by the terminal to access the second network. The specific access technology may be agreed upon through a protocol, determined by the terminal, or configured through the network.

[0209] In this embodiment, by considering at least one of the network type associated with the second network and the access technology used by the terminal to access the second network, the terminal can select an operation that matches at least one of the network type associated with the second network and the access technology used by the terminal to access the second network, thereby registering the terminal to the first network and improving registration efficiency.

[0210] It should be noted that the access technology used by the terminal to access the second network is not limited to high-orbit satellite access, medium-orbit satellite access, or low-orbit satellite access. For example, it can be any satellite access technology, and this application embodiment does not make specific limitations in this regard.

[0211] In some embodiments, the terminal generates a second derived key based on a first derived key or a first key, including at least one of the following:

[0212] If the second authentication process is successful, the terminal generates the second derived key based on the first derived key;

[0213] If the second authentication process fails or is not executed, the terminal generates the second derived key based on the first key.

[0214] For example, if the second authentication process is successful, the terminal can obtain the first derived key, and the terminal generates the second derived key based on the first derived key; if the second authentication process is unsuccessful or not executed, the terminal cannot obtain the first derived key, and the terminal generates the second derived key based on the first key.

[0215] In this embodiment, if the second authentication process is successful, the terminal generates the second derived key based on the first derived key; if the second authentication process fails or is not executed, the terminal generates the second derived key based on the first key. This not only simplifies the authentication process between the terminal and the first network but also ensures the security of the interaction between the terminal and the first network.

[0216] In some embodiments, the terminal performs a second registration process with a first network node in a first network based on the second derived key, including at least one of the following:

[0217] The terminal generates token information based on the second derived key and sends a registration request to the first network node during the second registration process;

[0218] The terminal receives the response message of the registration request and establishes a secure connection with the first network node based on the second derived key;

[0219] The registration request includes the token information and at least one of the following: the terminal's identifier in the first network, and first indication information; the first indication information is used to indicate registration based on the second authentication process, or to indicate support for registration based on the second authentication process.

[0220] For example, the secure connection includes a TLS connection and an IPSec Security Association (SA).

[0221] For example, before sending a registration request, the terminal generates a second derived key based on the first derived key, and uses the second derived key to generate token information.

[0222] In this embodiment, the registration request includes the token information, enabling the first network node to verify the token information before authenticating the terminal and to authenticate the terminal after successful verification of the token information, thereby improving the reliability of the second registration process. Furthermore, when the registration request includes the first indication information, the first indication information can be used to assist the first network node in determining the authentication-related process. For example, the first indication information can be used to assist the first network node in determining whether to execute the first authentication process, thereby improving the flexibility of authentication between the terminal and the first network.

[0223] In some embodiments, the terminal performs a first registration process with a first network node in a first network, or the terminal performs a third registration process with a first network node in a first network, including:

[0224] The terminal sends a registration request to the first network node. The registration request includes at least one of the terminal's identifier and token information in the first network, or the registration request includes first indication information and at least one of the following: the terminal's identifier and token information in the first network.

[0225] The first indication information is used to indicate registration based on the second authentication process, or to indicate support for registration based on the second authentication process;

[0226] The token information is generated based on the shared key, the third derived key, the first derived key, or the first key on the terminal;

[0227] The third derived key is generated based on the shared key.

[0228] For example, the third derived key may be the first derived key, or the third derived key may be different from the first derived key. For instance, the third derived key may be K. AUSF The shared key can be a long-term key (LTK).

[0229] For example, when the terminal performs a third registration process with a first network node in the first network, the terminal may generate a second derived key based on a first derived key before, after, or before the registration response is sent. If the terminal generates the second derived key based on the first derived key before the registration request, the terminal can use the second derived key to generate token information. Optionally, the registration request includes the token information.

[0230] In this embodiment, the registration request includes the token information, enabling the first network node to verify the token information before authenticating the terminal and to authenticate the terminal after successful verification of the token information, thereby improving the reliability of the second registration process. Furthermore, when the registration request includes the first indication information, the first indication information can be used to assist the first network node in determining the authentication-related process. For example, the first indication information can be used to assist the first network node in determining whether to execute the first authentication process, thereby improving the flexibility of authentication between the terminal and the first network.

[0231] In some embodiments, the token information is also generated based on at least one of the following:

[0232] Some or all of the contents of the registration request;

[0233] The string related to the system name of the first network;

[0234] The string related to the system name of the second network;

[0235] Information from the first network;

[0236] Information from the second network;

[0237] The identifier of the terminal in the first network;

[0238] The identifier of the terminal in the second network;

[0239] The terminal executes the information used in the first authentication process.

[0240] For example, when the token information is generated based on part or all of the content in the registration request, it can be generated based on part or all of the content in the registration request other than the token information. For instance, the token information can be based on the MAC used for integrity protection of the registration request in the registration request.

[0241] For example, the first derived key is a key generated based on the second authentication process if the second authentication process is successful, such as K. AUSF The first key is not generated based on the second authentication process, but rather is a key generated by the terminal during the first registration process.

[0242] For example, the identifier of the terminal in the second network includes: a permanent identifier of the terminal in the second network or a temporary identifier of the terminal in the first network. And / or, the identifier of the terminal in the first network includes: a private identifier of the terminal in the first network or a public identifier of the terminal in the first network.

[0243] For example, when the second network is a mobile network, the strings related to the system name of the second network include, but are not limited to: "eps", "eps_auth", "5GS", and "5GS_auth". The information of the second network includes, but is not limited to: network identifier or name, network domain name, network identifier or name of the home or visited network, and network domain name of the home or visited network. The identifier of the terminal in the second network includes, but is not limited to: Subscription Concealed Identifier (SUCI), Globally Unique Temporary Identifier (GUTI), and Subscription Permanent Identifier (SUPI).

[0244] For example, when the first network is an IMS network, the strings related to the system name of the first network include, but are not limited to, "ims" and "ims_auth". The information of the first network may include IMS network element information, such as the address or identifier of the P / I / S-CSCF. The identifier of the terminal in the first network includes, but is not limited to, IMS Private Identity (IMPI) and IMS Public Identity (IMPU).

[0245] For example, the information used by the terminal during the first authentication process may include information used most recently or multiple times during the first authentication process. For example, information used in the most recent mutual authentication with the second network (such as RAND, SQN, RES, service network name, etc.).

[0246] In this embodiment, the token information is generated from information from multiple dimensions, allowing the terminal to select appropriate information to generate the token information according to actual needs or scenarios, thereby improving the flexibility of the terminal in generating the token information. It should be noted that this application does not limit the specific method of generating the token information; for example, the token information can be obtained through hash operations or other processing.

[0247] In some embodiments, the method 200 further includes:

[0248] The terminal receives a response message to the registration request; wherein the response message includes at least one of the following:

[0249] Indicator of registration success or failure;

[0250] At least one of the information used to indicate the system of the first network and the information used to indicate the system of the second network;

[0251] Instructions to stop, not execute, skip, or execute the first authentication process;

[0252] Instructions indicating whether the second authentication process was successful, unsuccessful, or not executed;

[0253] Wherein, stopping, not executing, skipping, or executing the first authentication process during the third registration process includes any one of the following:

[0254] Based on the response message, the terminal stops, skips, or does not perform the first authentication process;

[0255] The terminal performs a first authentication process based on the response message;

[0256] Wherein, the terminal generates a second derived key based on the first derived key, and performs a second registration process with the first network node in the first network based on the second derived key, including any one of the following:

[0257] Based on the response message, the terminal may stop, skip, or not perform the first authentication process during the second registration process;

[0258] The terminal performs a first authentication process based on the response message.

[0259] For example, the terminal generates a second derived key based on a first derived key or a first key, and if the response message includes an instruction to stop, not perform, or skip the first authentication process, the terminal stops, skips, or does not perform the first authentication process; if the response message includes an instruction to perform the first authentication process, the terminal performs the first authentication process.

[0260] For example, the terminal performs a third registration process with a first network node in the first network. Further, if the response message includes an instruction to stop, not perform, or skip the first authentication process, the terminal stops, skips, or does not perform the first authentication process; if the response message includes an instruction to perform the first authentication process, the terminal performs the first authentication process.

[0261] In this embodiment, the terminal can determine whether to execute the first authentication process based on the indications included in the response message to stop, not execute, skip, or execute the first authentication process, thereby enabling the authentication process executed by the terminal and the first network node to be consistent, and thus improving the reliability of authentication between the terminal and the first network node.

[0262] In some embodiments, the second derived key is also generated based on at least one of the following:

[0263] The string related to the system name of the first network;

[0264] The string related to the system name of the second network;

[0265] Information from the first network;

[0266] Information from the second network;

[0267] The identifier of the terminal in the first network;

[0268] The identifier of the terminal in the second network;

[0269] The information used by the terminal during the second authentication process.

[0270] For example, the identifier of the terminal in the second network includes: a permanent identifier of the terminal in the second network or a temporary identifier of the terminal in the first network. And / or, the identifier of the terminal in the first network includes: a private identifier of the terminal in the first network or a public identifier of the terminal in the first network.

[0271] For example, when the second network is a mobile network, the strings related to the system name of the second network include, but are not limited to: "eps", "eps_auth", "5GS", and "5GS_auth". The information of the second network includes, but is not limited to: network identifier or name, network domain name, network identifier or name of the home or visited network, and network domain name of the home or visited network. The identifier of the terminal in the second network includes, but is not limited to: Subscription Concealed Identifier (SUCI), Globally Unique Temporary Identifier (GUTI), and Subscription Permanent Identifier (SUPI).

[0272] For example, when the first network is an IMS network, the strings related to the system name of the first network include, but are not limited to, "ims" and "ims_auth". The information of the first network may include IMS network element information, such as the address or identifier of the P / I / S-CSCF. The identifier of the terminal in the first network includes, but is not limited to, IMS Private Identity (IMPI) and IMS Public Identity (IMPU).

[0273] For example, the information used by the terminal during the first authentication process may include information used most recently or multiple times during the first authentication process. For instance, information used in the most recent mutual authentication with the second network (such as RAND, SQN, RES, service network name, etc.).

[0274] In this embodiment, the second derived key is generated from information from multiple dimensions, enabling the terminal to select appropriate information to generate the second derived key according to actual needs or scenarios, thereby improving the flexibility of the terminal in generating the second derived key. It should be noted that this application does not limit the specific method of generating the second derived key; for example, the second derived key can be obtained through hash operations or other processing.

[0275] In some embodiments, the method 200 further includes at least one of the following:

[0276] When performing the second registration process or the third registration process, the terminal establishes a secure connection with the first network based on the second derived key;

[0277] When the first registration process is executed, the terminal establishes a secure connection with the first network based on the first key.

[0278] For example, the terminal may establish a secure connection with the first network during or after the registration process.

[0279] For example, the secure connection includes a TLS connection and an IPSec Security Association (SA).

[0280] In this embodiment, when the second registration process or the third registration process is executed, the terminal establishes a secure connection with the first network based on the second derived key; when the first registration process is executed, the terminal establishes a secure connection with the first network based on the first key, which can ensure the communication security between the terminal and the first network.

[0281] In some embodiments, the system of the second network is a non-IMS system, and the system of the first network is an IMS system.

[0282] For example, the non-IMS system includes a mobile network system. For instance, the mobile network system may include an Evolved Packet System (EPS), a 5GS system, a 6GS system, etc.

[0283] In this embodiment, the terminal performs a first operation, a second operation, or a third operation, enabling the terminal to obtain a first key or a second derived key for securely protecting the interaction between the terminal and the IMS network through a first registration process, a second registration process, or a third registration process, thereby improving the flexibility of authentication between the terminal and the IMS network. In some embodiments, the terminal generates a second derived key based on the first derived key or the first key, which can reduce the signaling overhead of the authentication process between the terminal and the IMS network.

[0284] Figure 3 is a schematic flowchart of a wireless communication method 300 according to an embodiment of this application.

[0285] The method 300 can be executed interactively by a terminal, a first network node, and a second network node. The first network node can also be referred to as a first network function, a first network element, a first network device, or a first network-side device. For example, the first network node includes a P / I / S-CSCF. The second network node can also be referred to as a second network function, a second network element, a second network device, or a second network-side device. For example, the second network node includes an AUSF / HSS. Furthermore, the method 300 may also involve interaction with a third, fourth, or fifth network node. The third network node can also be referred to as a third network function, a third network element, a third network device, or a third network-side device. For example, the third network node includes a PCF / PCRF. The fourth network node can also be referred to as a fourth network function, a fourth network element, a fourth network device, or a fourth network-side device. For example, the fourth network node includes a UDM / HSS. The fifth network node can also be referred to as a fifth network function, a fifth network element, a fifth network device, or a fifth network-side device. For example, when the first network node is an I / S-CSCF, the fifth network node includes a P-CSCF.

[0286] As shown in Figure 3, the wireless communication method 300 may include at least some of the following:

[0287] S301, the terminal sends a registration request to the first network node;

[0288] S302, the first network node sends at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node to obtain authentication status information for the second authentication process;

[0289] S303, the first network node receives at least one of result information and authentication status information of the second authentication process from the second network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0290] S304, the first network node sends a response message to the registration request;

[0291] Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network, and the first network node is a network-side node of the first network;

[0292] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0293] The third derived key is generated based on the shared key of the terminal;

[0294] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0295] The first derived key is generated based on the second authentication process;

[0296] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0297] The second authentication process is an authentication process between the terminal and the second network.

[0298] For example, the terminal sends a registration request to a first network node. Upon receiving the registration request, the first network node sends at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to a second network node to obtain authentication status information for the second authentication process. After receiving at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information from the first network node, the second network node, based on the terminal's identifier in the first network, the terminal's identifier in the second network, and token information, sends at least one of the result information and authentication status information for the second authentication process to the first network node. The result information indicates whether the authentication status information for the second authentication process was successfully obtained or not. Upon receiving at least one of the result information and authentication status information for the second authentication process, the first network node sends a response message for the registration request to the terminal.

[0299] It should be noted that network nodes (such as the first network node or the second network node) can query or obtain the shared key of the terminal from the database, and this application does not specifically limit this.

[0300] In some embodiments, S302 includes:

[0301] The first network node sends to the second network node at least one of the following based on the registration request: the terminal's identifier in the first network, the terminal's identifier in the second network, and the token information:

[0302] The network type associated with the second network and the access technology used by the terminal to access the second network;

[0303] The access technology includes at least one of the following: high-orbit satellite access, medium-orbit satellite access, low-orbit satellite access, and non-terrestrial network NTN access;

[0304] The network type includes at least one of the following: Standalone Non-Public Network (SNPN), Non-Standalone Non-Public Network (PLMN-NPN), Non-Public Network (NPN), and Terrestrial Network (TN).

[0305] In some embodiments, the registration request includes at least one of the terminal's identifier in the first network and the token information, or

[0306] The registration request includes first indication information and at least one of the following: the terminal's identifier in the first network, and token information;

[0307] Wherein, the first indication information is used to indicate registration based on the second authentication, or the first indication information is used to indicate support for registration based on the second authentication.

[0308] In some embodiments, prior to S302, method 300 further includes at least one of the following:

[0309] The first network node obtains the identifier of the terminal in the second network from the third network node based on at least one of the terminal's identifier in the first network and the token information;

[0310] The first network node verifies the token information.

[0311] In some embodiments, S303 includes at least one of the following:

[0312] If at least one of the terminal's identification acquisition failure in the second network and the token information verification failure occurs, the first network node shall stop receiving at least one of the result information and the authentication status information from the second network node.

[0313] If at least one of the terminal's identifier being successfully acquired in the second network and the token information being successfully verified is met, the first network node receives at least one of the result information and the authentication status information from the second network node.

[0314] For example, if the first network node needs to obtain the identifier of the terminal in the second network (e.g., the first network node needs to obtain the identifier of the terminal in the second network from a third network node), if the acquisition of the identifier of the terminal in the second network fails, the first network node stops receiving at least one of the result information and the authentication status information from the second network node; if the acquisition of the identifier of the terminal in the second network is successful, the first network node receives at least one of the result information and the authentication status information from the second network node.

[0315] For example, if the registration request includes the token information, in the event of at least one of the token information verification failures, the first network node stops receiving at least one of the result information and the authentication status information from the second network node; in the event of at least one of the token information verification successes, the first network node receives at least one of the result information and the authentication status information from the second network node.

[0316] For example, if the first network node needs to obtain the identifier of the terminal in the second network (e.g., the first network node needs to obtain the identifier of the terminal in the second network from a third network node) and the registration request includes the token information, in the case that the acquisition of the identifier of the terminal in the second network fails and the verification of the token information fails, the first network node stops receiving at least one of the result information and the authentication status information from the second network node; in the case that the acquisition of the identifier of the terminal in the second network succeeds and the verification of the token information succeeds, the first network node receives at least one of the result information and the authentication status information from the second network node.

[0317] In some embodiments, S302 includes:

[0318] The first network node sends the token information and at least one of the following to the second network node: the identifier of the terminal in the first network, and the identifier of the terminal in the second network;

[0319] The result information includes the verification result of the token information.

[0320] For example, the first network node sends the token information to the second network node. After receiving the token information, the second network node verifies the token information and obtains the verification result of the token information; wherein, the result information includes the verification result of the token information.

[0321] In some embodiments, the token information is also generated based on at least one of the following:

[0322] Some or all of the contents of the registration request;

[0323] The string related to the system name of the first network;

[0324] The string related to the system name of the second network;

[0325] Information from the first network;

[0326] Information from the second network;

[0327] The identifier of the terminal in the first network;

[0328] The identifier of the terminal in the second network;

[0329] The information used by the terminal during the second authentication process.

[0330] In some embodiments, if the terminal successfully authenticates in the second network, the authentication information includes at least one of the following:

[0331] The second authentication process has been successfully completed;

[0332] Instructions to stop, not perform, or skip the first authentication process;

[0333] The second derived key or the first derived key.

[0334] For example, successful authentication of the terminal in the second network can mean that the authentication process between the terminal and the second network has been executed and the authentication was successful.

[0335] In some embodiments, if the terminal fails to authenticate in the second network, the authentication status information includes a random number, response information generated based on the random number, and a third derived key;

[0336] The third derived key is generated based on the shared key of the terminal.

[0337] For example, the terminal's failure to authenticate in the second network may mean that the authentication process between the terminal and the second network was not executed, or was executed but failed to authenticate.

[0338] In some embodiments, the method 300 further includes:

[0339] The first network node generates the second derived key based on the first derived key or the first key.

[0340] In some embodiments, the response message to the registration request includes at least one of the following:

[0341] The second derived key;

[0342] Indicator of registration success or failure;

[0343] At least one of the information used to indicate the system of the first network and the information used to indicate the system of the second network;

[0344] Instructions to stop, not execute, skip, or execute the first authentication process;

[0345] Instructions indicating whether the second authentication process was successful, unsuccessful, or not executed.

[0346] In some embodiments, the second derived key is also generated based on at least one of the following:

[0347] The string related to the system name of the first network;

[0348] The string related to the system name of the second network;

[0349] Information from the first network;

[0350] Information from the second network;

[0351] The identifier of the terminal in the first network;

[0352] The identifier of the terminal in the second network;

[0353] The information used by the terminal during the second authentication process.

[0354] In some embodiments, the method 300 further includes:

[0355] The first network node obtains from the third network node or the registration request at least one of the access technology used by the terminal to access the second network and the network type related to the second network.

[0356] The third network node is a network-side node of the second network.

[0357] In some embodiments, the system of the second network is a non-IMS system, and the system of the first network is an IMS system.

[0358] In some embodiments, the method 300 further includes:

[0359] The first network node indicates the registration status of the terminal or the authentication status between the terminal and the first network to the fourth network node;

[0360] In cases where the first authentication process has been stopped, not executed, or skipped, the authentication status between the terminal and the first network is considered authenticated.

[0361] For example, the second network node is HSS, which indicates the registration status of the terminal or the authentication status between the terminal and the first network to the fourth network node (e.g., UDM).

[0362] In some embodiments, the method 300 further includes:

[0363] The first network node receives a failure indication information from the fifth network node, the failure indication information indicating that the establishment of a secure channel or secure connection between the fifth network node and the terminal has failed.

[0364] The first network node sends an update indication message to the fourth network node. The update indication message is used to indicate the invalidation or deletion of the terminal's registration status or the authentication status between the terminal and the first network.

[0365] In some embodiments, the method 300 further includes:

[0366] The second network node obtains the terminal's identifier in the second network from the fourth network node based on the terminal's identifier in the first network.

[0367] In some embodiments, the method 300 further includes:

[0368] The second network node verifies the token information;

[0369] The result information includes the verification result of the token information.

[0370] In some embodiments, the method 300 further includes:

[0371] The second network node sends the token information to the fourth network node;

[0372] The second network node receives the result information from the fourth network node.

[0373] For example, the second network node is AUSF, which sends the token information to the fourth network node (e.g., UDM) and receives the result information from the fourth network node.

[0374] It should be understood that the wireless communication method 300 includes the interaction process between the terminal, the first network node, and the second network node. The terminology involved is similar to that of method 200. Therefore, the specific content can be referred to the relevant description in method 200. To avoid repetition, it will not be repeated here.

[0375] Figure 4 is a schematic flowchart of a wireless communication method 400 according to an embodiment of this application.

[0376] As shown in Figure 4, the wireless communication method 400 may include at least some of the following:

[0377] S401, the fifth network node receives a registration request from the terminal;

[0378] S402, Send a registration request to the first network node;

[0379] S403, the fifth network node receives a response message for the registration request from the first network node. The response message includes a second derived key and third information, wherein the third information includes at least one of the following: an indication of successful registration, at least one of the systems of the first network and the second network, an indication to stop, not execute, skip, or execute the first authentication process, and an indication that the second authentication process has been successful.

[0380] S404, the fifth network node establishes a secure connection with the terminal based on the response message;

[0381] The first network refers to the network in which the fifth network node and the first network node are located.

[0382] In some embodiments, the method 400 further includes:

[0383] In the event that the secure connection establishment fails, the fifth network node sends a failure indication message to the first network node, the failure indication message indicating that the secure connection establishment between the fifth network node and the terminal has failed.

[0384] In some embodiments, S404 includes at least one of the following:

[0385] The fifth network node establishes a secure connection with the terminal based on the second derived key;

[0386] The fifth network node establishes a secure connection with the terminal based on the third information.

[0387] In some embodiments, S404 includes:

[0388] If the third information indicates that the first authentication process should be stopped, not executed, or skipped, the fifth network node establishes a secure connection with the terminal.

[0389] It should be understood that the wireless communication method 400 includes the interaction process between the terminal, the first network node, and the second network node. The terminology involved is similar to that of method 200. Therefore, the specific content can be referred to the relevant description in method 200. To avoid repetition, it will not be repeated here.

[0390] The solution provided in this application will be described below with reference to specific embodiments.

[0391] Example 1:

[0392] In this embodiment, the UE registers to the IMS network by considering its registration or authentication status in the 5G mobile network.

[0393] Figure 5 is a schematic flowchart of the wireless communication method 500 provided in an embodiment of this application.

[0394] As shown in Figure 5, the method 500 includes:

[0395] S501, the UE sends a registration request to the AMF, including SUCI / GUTI.

[0396] The UE sends a registration request to the AMF to request access to the 5G mobile network. This can be a Non-Access Stratum (NAS) Registration Request message. The registration request carries a user identifier, such as SUCI or GUTI.

[0397] S502, AMF sends an authentication request to AUSF, including SUCI / SUPI.

[0398] If the AMF determines that the UE needs to be authenticated, it will trigger the AUSF to initiate the authentication process, such as by sending an Authentication Request message to the AUSF or calling the AUSF's Nausf_UEAuthentication_Authenticate operation, carrying SUCI or SUPI and the Serving Network Name (SNN).

[0399] S503, AUSF sends an AV request to UDM, including SUCI / SUPI.

[0400] AUSF requests the Authentication Vector (AV) for the UE from the UDM, for example by sending an AV request or calling the UDM's Nudm_UEAuthentication_Get operation, carrying SUCI or SUPI.

[0401] S504, UDM returns an AV response to AUSF, including RAND, AUTN, RES, and K. AUSF .

[0402] The UDM decrypts the SUCI to obtain the SUPI. The UDM then returns the authentication vector to the AUSF, such as RAND, AUTN, RES, and K generated based on the UE's LTK. AUSF .

[0403] S505, UE and AUSF complete mutual authentication through AMF based on RAND, AUTN and RES.

[0404] UE and AUSF perform certification processes based on RAND, AUTN, and RES through AMF, such as 5G AKA or EAP-AKA' certification.

[0405] S506, AUSF returns an authentication response to AMF, including K SEAF .

[0406] After successful AUSF certification, an certification response is returned to AMF, including AUSF's K-based authentication information. AUSF Derived session key K SEAF .

[0407] S507, AMF sends a registration and reception response to UE.

[0408] The AMF sends a NAS registration acceptance message to the UE. After successful authentication, the UE also generates a K based on its locally configured LTK in the same way as the UDM. AUSF Based on K AUSF K is generated in the same way as AUSF. SEAF From this point on, the UE and the 5G mobile network can communicate based on K SEAF Implement secure protection and secure processing of NAS messages and user plane data.

[0409] S508, establish a PDU session for IMS.

[0410] The UE, AMF, SMF, UPF, and UDM interact to complete the PDU session establishment process related to IMS services. This process is based on the key generated in S507 and is protected and processed securely.

[0411] S509, the UE sends a SIP registration request to the P-CSCF via the UPF, including IMPI / IMPU, [token information], and [first indication information].

[0412] The UE sends a SIP registration request message to the P-CSCF through an IMS service-related PDU session. This SIP registration request message is routed through the UPF and carries the IMPU and IMPI. Optionally, the SIP registration request message carries token information, which is generated based on LTK or a session / sub / derived key generated by LTK (generated during or after S508 authentication) (e.g., a K derived from LTK). AUSF Or by K AUSF Derived K SEAF Or by K SEAF Derived K AMF Or by K AUSF Derived K IMS (Generated). The shared key on the terminal can be LTK, the third derived key or the first derived key mentioned above can be a session key / subkey / derived key generated based on LTK, and the second derived key or the first key mentioned above can be K. IMS The UE can generate this information when performing IMS registration. Optionally, the SIP registration request message carries first indication information, indicating that the UE supports the enhanced functions required by S509-S516 (in short, implicit IMS authentication function, new key derivation function), i.e., function indication, which can be indicated by capability information or function tags, etc.

[0413] Token information can also be generated based on at least one of the following:

[0414] Part or all of the IMS registration request message content (such as the MAC generated based on the above key for integrity protection of the IMS registration request message), the string "IMS" (uppercase or lowercase) or strings related to "IMS" (such as "ims_authentication", "imsapplication", etc.), information about the IMS network (such as network identifier or name, network domain name, network identifier or name of the home or visited IMS network, network domain name of the home or visited IMS network), the UE's IMS identification information (such as IMPI, IMPU), and the information used for the most recent mutual authentication with the mobile network (such as RAND, SQN, etc.).

[0415] The P-CSCF forwards the SIP registration request message to the I-CSCF, and the I-CSCF forwards it to the S-CSCF.

[0416] S510, I / S-CSCF sends an ID mapping request to UDM, including IMPI / IMPU.

[0417] The I-CSCF or S-CSCF (or P-CSCF) requests the UE's mobile network identifier (SUPI or GPSI) from the UDM. This can be done by sending an ID mapping request message to the UDM or calling the UDM's Nudm_ImsSDM_Get operation, carrying the UE's IMS identifier information, such as IMPI / IMPU. The UDM then returns the UE's mobile network identifier (e.g., 4G or 5G network), i.e., SUPI / GPSI. Optionally, the P / I / S-CSCF can request the UE's SUPI / GPSI from the UDM based on the first indication information sent by the UE.

[0418] S511, UDM sends an ID mapping response, including SUPI / GPSI, to I / S-CSCF.

[0419] Optionally, the UDM checks whether the UE has been successfully authenticated before returning the ID mapping response (if the S505 authentication is successful, AUSF will update the UE's authentication status in the UDM). If authentication is incomplete or fails, the SUPI / GPSI response will be refused, or if authentication is successful, the SUPI / GPSI response will be returned.

[0420] S512, I / S-CSCF sends an authentication request to AUSF, including IMPI / SUPI, [IMS Instruction].

[0421] The P / I / S-CSCF triggers the AUSF to initiate the authentication process, such as by sending an Authentication Request message or invoking the AUSF's Nausf_UEAuthentication_Authenticate operation. This message carries the UE's Mobile Network Identifier (SUPI) or IMS Network Identifier (IMPI or IMPU), and may also carry an IMS indication to indicate that the authentication process is for the IMS network. The IMS indication can be indicated by the serving network name, including the IMS network name or network domain name, or IMS network element information (such as the address or identifier of the P / I / S-CSCF), or by the carried token information. Optionally, the P / I / S-CSCF can trigger the AUSF to initiate the authentication process based on the first indication information sent by the UE.

[0422] Optionally, if the IMS instruction includes token information, AUSF verifies the token information based on the following method:

[0423] Method 1: AUSF generates a key for calculating token information (e.g., K). IMSAUSF uses this key to verify token information.

[0424] Method 2: AUSF uses the key generated during the authentication process (e.g., K). AUSF Directly verify token information.

[0425] If the token information is verified, AUSF will proceed with the next steps if the verification is successful; otherwise, it will stop proceeding with the next steps.

[0426] S513, AUSF sends an ID mapping request to UDM, including IMPI / IMPU.

[0427] Optionally, the AUSF requests the UE's SUPI / GPSI from the UDM / UDR / HSS based on the UE's IMS identification information. This can be done by sending an ID mapping request message to the UDM or calling the UDM's Nudm_ImsSDM_Get operation, carrying the UE's IMS identification information, such as IMPI or IMPU. The UDM then returns the UE's mobile network (e.g., 4G or 5G network) identifier, i.e., the SUPI or GPSI identifier. Furthermore, the AUSF can also request the UE's SUPI / GPSI from the UDM based on the IMS indication and the UE's IMS identification information.

[0428] S514, UDM returns an ID mapping response to AUSF, including SUPI / GPSI.

[0429] Optionally, the UDM can check whether the UE has been successfully authenticated before returning SUPI (if the S505 authentication is successful, AUSF will update the UE's authentication status in the UDM). If authentication is incomplete or fails, the SUPI will be refused, or if authentication is successful, the SUPI will be returned.

[0430] Optionally, if the UE's IMPU is mapped from the GPSI, or if the UE's IMPU is the GPSI, then steps S510-S511 and S513-S514 are not executed. The AUSF can obtain the GPSI through the IMPU, and then obtain the UE's mobile network authentication status through the GPSI.

[0431] S515, AUSF returns an authentication response to I / S-CSCF, including K IMS .

[0432] AUSF determines that the UE has already completed authentication on the mobile network and does not need to perform the authentication process on the IMS network based on the UE's mobile network identifier. AUSF can optionally be based on K... AUSF Generate K IMS Return the authentication result to P / I / S-CSCF, including K AUSF Or the key K used in IMS networksIMS Furthermore, AUSF can also determine, based on IMS indication and the UE's mobile network identifier, whether the UE has completed authentication in the mobile network and does not need to perform the authentication process in the IMS network. Optional AUSF is based on K... AUSF Generate K IMS Return the authentication result to P / I / S-CSCF, including K AUSF Or the key K used in IMS networks IMS .

[0433] In one embodiment, S509 includes token information while S512 does not; optionally, AUSF uses K. AUSF or K IMS The expected token information is calculated in the same way as the UE's calculation method in S509, and then sent to the P / I / S-CSCF. The P / I / S-CSCF verifies the token information based on the following method:

[0434] Method 1: If the expected token information is not received from AUSF, based on K IMS Verify token information, such as based on K. IMS The expected token information is calculated in the same way as the UE's calculation method in S509, and then the token information is compared with the expected token information to see if they are the same.

[0435] Method 2: If the expected token information is received from AUSF, compare whether the token information is the same as the expected token information.

[0436] If the verification is successful (e.g., the comparison results are the same), the P / I / S-CSCF will proceed with the next steps; otherwise, it will stop proceeding with the next steps.

[0437] S516a, the I / S-CSCF sends a registration success response to the P-CSCF, including K IMS .

[0438] I / S-CSCF is based on the authentication result returned by AUSF (including information indicating success / failure and / or K). AUSF / K IMS ), optional K-based AUSF Generate K IMS The system sends an IMS registration success response to the UE, such as a SIP 200 OK response message. Optionally, the IMS registration success response carries authentication success indication information to indicate that IMS implicit authentication was successful. If the I / S-CSCF and AUSF are performing S512-S515, the SIP 200 OK message is forwarded to the UE via the P-CSCF. In this case, the SIP 200 OK message sent by the I / S-CSCF needs to carry K. IMS .

[0439] In S516b, the P-CSCF sends a registration success response to the UE via the UPF.

[0440] P-CSCF is based on K IMS Establish an IPSec Security Alliance / TLS secure connection with the UE for secure protection and processing of IMS signaling between the UE and the P-CSCF. The P-CSCF forwards data without carrying K. IMS The SIP 200 OK message is sent to the UE. The UE did not perform authentication on the IMS network; it can use the same method as AUSF based on K after S505 and before S516. AUSF Generate K IMS (Can be used to calculate token information). Furthermore, if the UE does not perform authentication on the IMS network but receives an IMS registration success response message or an IMS authentication success indication message (i.e., after S516), a K is generated. IMS .

[0441] K IMS Except for K AUSF Generation can also be based on K AUSF Generate with at least one of the following:

[0442] The string “IMS” (uppercase or lowercase) or a string related to “IMS” (such as “ims_authentication”, “ims application”, etc.), information about the IMS network (such as network identifier or name, network domain name, network identifier or name of the home or visited IMS network, network domain name of the home or visited IMS network), UE’s IMS identification information (such as IMPI, IMPU), IMS network element information (such as P / I / S-CSCF address or identifier), and information about the most recent mutual authentication with the mobile network (such as RAND, SQN, etc.).

[0443] S516c, P-CSCF sends a failure indication message to I / S-CSCF.

[0444] Optionally, if S509 of the embodiment does not carry token information, the fake UE can impersonate the real UE to send an IMS registration request message (the message sent by the real UE is a plaintext message and is not protected by security). Although AUSF / UDM cannot determine the authenticity of the UE, the fake UE does not have the real UE's LTK and cannot generate K. IMSTherefore, it cannot establish a secure connection / security association with the P-CSCF. The P-CSCF will detect that the secure connection with the UE has failed to be established. At this time, after receiving the IMS registration response message, the optional P-CSCF, based on the result of the interaction with the UE, and further based on the fact that the authentication process between the UE and the I / S-CSCF has not been executed, may send UE registration result information to the S-CSCF (which can be through the I-CSCF). For example, it may send a SIP message (INFO) carrying UE registration result information. The UE registration result information includes a success or failure indication, and may also include a failure reason value (such as indicating a fake UE, security failure, etc.). Optionally, when the S-CSCF receives the UE registration result information including a failure indication, it may delete or invalidate the UE's IMS registration-related information in the UDM, such as deleting or invalidating the associated S-CSCF and P-CSCF, setting the UE's IMS registration status to "unregistered", etc.

[0445] Example 2:

[0446] In this embodiment, the UE registers to the IMS network by considering its registration or authentication status in the 4G mobile network.

[0447] Figure 6 is a schematic flowchart of the wireless communication method 600 provided in an embodiment of this application.

[0448] As shown in Figure 6, the method 600 includes:

[0449] S601, the UE sends a registration request to the MME, including SUCI / GUTI.

[0450] The UE sends a registration request to the MME to request access to the 4G mobile network. This can be a Non-Access Stratum (NAS) Registration Request message. The registration request carries a user identifier, such as SUCI or GUTI.

[0451] S602, the MME sends an authentication request, including SUPI, to the HSS.

[0452] The MME determines that the UE needs to be authenticated and requests an authentication vector from the HSS, such as by sending an Authentication Request message to the HSS, carrying the SUPI and the Serving Network Name (SNN).

[0453] S603, HSS returns an authentication response to MME, including RAND, AUTN, RES, and K. ASME .

[0454] K ASME LTK generation based on UE.

[0455] S604, UE and MME complete mutual authentication based on RAND, AUTN and RES.

[0456] UE and MME perform certification processes based on RAND, AUTN, and RES, such as EPS AKA or EAP-AKA certification.

[0457] S605, the MME returns a registration acceptance response to the UE.

[0458] After successful authentication, the MME sends a NAS registration acceptance message to the UE. Following successful authentication, the UE also generates a KASME based on its locally configured LTK in the same manner as the HSS. From this point onward, the UE and the 4G mobile network can achieve secure protection and processing of NAS messages and user plane data based on the KASME.

[0459] S606, Establish a PDN connection for IMS.

[0460] The UE, MME, SGW, PGW, and HSS interact to complete the PDN session establishment process related to IMS services. This process is based on the key generated in S605 and is protected and processed securely.

[0461] S607, the UE sends a SIP registration request to the P-CSCF via the PGW, including IMPI / IMPU, token information, and first indication information.

[0462] The UE sends a SIP registration request message to the P-CSCF via the IMS service-related PDN connection. This SIP registration request message is routed through the PGW, carrying the IMPU and IMPI. Optionally, the PGW also carries token information, which is generated based on the session / sub / derived key generated during LTK generation or authentication (e.g., based on the K derived from LTK). ASME Or by K ASME (Derived key generation). The shared key on the terminal can be an LTK, and the third or first derived key mentioned above can be a session key / subkey / derived key generated based on the LTK. The UE can generate this key when performing IMS registration. Optionally, the SIP registration request message carries first indication information, indicating that the UE supports the enhanced functions required by S607-S610 (in short, implicit IMS authentication function, new key derivation function), i.e., function indication, which can be indicated through capability information or function tags, etc.

[0463] Token information can also be generated based on at least one of the following:

[0464] Part or all of the IMS registration request message content (such as the MAC generated based on the above key for integrity protection of the IMS registration request message), the string "IMS" (uppercase or lowercase) or strings related to "IMS" (such as "ims_authentication", "imsapplication", etc.), information about the IMS network (such as network identifier or name, network domain name, network identifier or name of the home or visited IMS network, network domain name of the home or visited IMS network), the UE's IMS identification information (such as IMPI, IMPU), and the information used for the most recent mutual authentication with the mobile network (such as RAND, SQN, etc.).

[0465] The P-CSCF forwards the SIP registration request message to the I-CSCF, and the I-CSCF forwards it to the S-CSCF.

[0466] S608, I / S-CSCF sends an authentication request to HSS, including IMPI / SUPI and token information.

[0467] The P-CSCF / I-CSCF / S-CSCF triggers the HSS to initiate the authentication process, such as by sending an Authentication Request message carrying the UE's IMS network identifier (i.e., IMPI or IMPU), and may also carry an IMS indication to indicate that the authentication process is for the IMS network. The IMS indication can be indicated by the serving network name, including the IMS network name or network domain name, or IMS network element information (such as the address or identifier of the P / I / S-CSCF), or by carrying token information. The P / I / S-CSCF can optionally trigger the HSS to initiate the authentication process based on the function indication sent by the UE.

[0468] Optionally, if the IMS indication includes token information, the HSS verifies the token information based on the following method:

[0469] Method 1: HSS generates a key for calculating token information (e.g., K). IMS HSS uses this key to verify token information.

[0470] Method 2: HSS uses the key generated during the authentication process (e.g., K). ASME Directly verify token information.

[0471] If the HSS verifies the token information and the verification is successful, it will proceed with the next steps; otherwise, it will stop proceeding with the next steps.

[0472] S609, HSS returns an authentication response to I / S-CSCF, including K IMS .

[0473] HSS associates the UE's IMS network identifier with the UE's mobile network identifier to determine if the UE has already completed authentication on the mobile network and does not need to perform the authentication process on the IMS network. HSS can optionally be based on K... ASME Generate K IMS Return the authentication result to P / I / S-CSCF, including K ASME Or the key K used in IMS networks IMS Furthermore, the HSS can also determine the associated UE's mobile network identifier from the UE's IMS network identifier based on the IMS indication, and determine whether the UE has already completed authentication in the mobile network and does not need to perform the authentication process in the IMS network based on the IMS indication and the UE's mobile network identifier. The HSS can optionally be based on K... ASME Generate K IMS Return the authentication result to P / I / S-CSCF, including K ASME Or the key K used in IMS networks IMS .

[0474] In one embodiment, S607 includes token information while S608 does not; optionally, HSS uses K. ASME or K IMS The expected token information is calculated in the same way as the UE's calculation method in S607, and then sent to the P / I / S-CSCF. The P / I / S-CSCF verifies the token information based on the following method:

[0475] Method 1: If the expected token information is not received from the HSS, based on K IMS Verify token information, such as based on K. IMS The expected token information is calculated in the same way as the UE's calculation method in S607, and then the token information is compared with the expected token information to see if they are the same.

[0476] Method 2: If the expected token information is received from the HSS, compare whether the token information is the same as the expected token information.

[0477] If the verification is successful (e.g., the comparison results are the same), the P / I / S-CSCF will proceed with the next steps; otherwise, it will stop proceeding with the next steps.

[0478] S610a, the I / S-CSCF sends a registration success response to the P-CSCF, including K IMS .

[0479] P / I / S-CSCF is based on the authentication results returned by HSS (including information indicating success / failure and / or K). ASME / K IMS ), optional K-based ASME Generate K IMS The system sends an IMS registration success response to the UE, such as a SIP 200 OK response message. Optionally, the IMS registration success response includes authentication success indication information, indicating successful implicit IMS authentication. If the I / S-CSCF and AUSF are executing S608-S609, the SIP 200 OK message is forwarded to the UE via the P-CSCF. In this case, the SIP 200 OK message sent by the I / S-CSCF needs to include the K... IMS .

[0480] In S610b, the P-CSCF sends a registration success response to the UE via the PGW.

[0481] P-CSCF is based on K IMS Establish an IPSec Security Alliance / TLS secure connection with the UE for secure protection and processing of IMS signaling between the UE and the P-CSCF. The P-CSCF forwards data without carrying K. IMS The SIP 200 OK message is sent to the UE. The UE did not perform authentication on the IMS network; it can use the same method as HSS based on K after S605 and before S616. ASME Generate K IMS (Can be used to calculate token information). Furthermore, if the UE does not perform authentication on the IMS network but receives an IMS registration success response message or an IMS authentication success indication message (i.e., after S616), it generates a K. IMS .

[0482] K IMS Except for K ASME Generation can also be based on K ASME Generate with at least one of the following:

[0483] The string “IMS” (uppercase or lowercase) or a string related to “IMS” (such as “ims_authentication”, “ims application”, etc.), information about the IMS network (such as network identifier or name, network domain name, network identifier or name of the home or visited IMS network, network domain name of the home or visited IMS network), UE’s IMS identification information (such as IMPI, IMPU), IMS network element information (such as P / I / S-CSCF address or identifier), and information about the most recent mutual authentication with the mobile network (such as RAND, SQN, etc.).

[0484] S610c, P-CSCF sends a failure indication message to I / S-CSCF.

[0485] Optionally, if S607 of the embodiment does not carry token information, the fake UE can impersonate the real UE to send an IMS registration request message (the message sent by the real UE is a plaintext message and is not protected by security). Although the HSS cannot determine the authenticity of the UE, the fake UE does not have the real UE's LTK and cannot generate K. IMS Therefore, it cannot establish a secure connection / security association with the P-CSCF. The P-CSCF will detect that the secure connection with the UE has failed to be established. At this time, after receiving the IMS registration response message, the optional P-CSCF, based on the result of the interaction with the UE, and further based on the fact that the authentication process between the UE and the I / S-CSCF has not been executed, sends UE registration result information to the S-CSCF (which can be through the I-CSCF). For example, the SIP INFO message carries UE registration result information. The UE registration result information includes a success or failure indication, and may also include a failure reason value (such as indicating a fake UE, security failure, etc.). Optionally, when the S-CSCF receives the UE registration result information including a failure indication, it can delete or invalidate the UE's IMS registration-related information in the HSS, such as deleting or invalidating the associated S-CSCF and P-CSCF, setting the UE's IMS registration status to "unregistered", etc.

[0486] It should be noted that this embodiment can also be used in 5G networks, that is, MME is replaced with AMF, HSS is replaced with AUSF and UDM, and S608-S609 is P / I / S-CSCF and UDM interaction.

[0487] Example 3:

[0488] In this embodiment, when the UE is not authenticated in the 5G mobile network, the UE generates a key during the registration process of registering to the IMS network.

[0489] Figure 7 is a schematic flowchart of a wireless communication method 700 provided in an embodiment of this application.

[0490] As shown in Figure 7, the method 700 includes:

[0491] S701~S703.

[0492] S701 to S703 are similar to S501 to S503, except that the registration request sent by the terminal UE to the AMF does not carry the GUTI. To avoid repetition, this will not be elaborated further here.

[0493] S704, UDM returns an AV response to AUSF.

[0494] If the UDM determines that no authentication is required, it will not return an authentication vector to the AUSF.

[0495] S705, AUSF sends an authentication response to AMF.

[0496] AUSF returns an authentication response to AMF, which does not include authentication-related information such as keys.

[0497] S706, AMF sends a registration and reception response to UE.

[0498] AMF sends a NAS registration accept message to the UE. No authentication is performed, therefore the UE will not derive a key based on the LTK.

[0499] S707, establish a PDU session for IMS.

[0500] The UE, AMF, SMF, UPF, and UDM interact to complete the PDU session establishment process related to IMS services, but this process is not protected or processed with security.

[0501] S708, the UE sends a SIP registration request to the P-CSCF via the UPF, including IMPI / IMPU, [first indication information].

[0502] The UE sends a SIP registration request message to the P-CSCF through the IMS service-related PDU session. The SIP registration request message is routed through the UPF and carries IMPU and IMPI. Optionally, the SIP registration request message carries first indication information, indicating that the UE supports the functions required by S509-S516 to enhance the UE (in short, implicit IMS authentication function, new key derivation function), i.e., function indication, which can be indicated by capability information or function tags, etc.

[0503] The P-CSCF forwards the SIP registration request message to the I-CSCF, and the I-CSCF forwards it to the S-CSCF.

[0504] S709, I / S-CSCF sends an ID mapping request to UDM, including IMPI / IMPU.

[0505] Optionally, the P-CSCF, I-CSCF, or S-CSCF requests the UE's SUPI from the UDM, for example, by sending an ID mapping request message to the UDM or calling the UDM's Nudm_ImsSDM_Get operation, carrying the UE's IMS identification information, such as IMPI or IMPU. The UDM returns the UE's mobile network (e.g., 4G or 5G network) identifier, i.e., the SUPI. The P / I / S-CSCF may optionally request the UE's SUPI from the UDM based on the function indication sent by the UE.

[0506] S710, UDM sends ID mapping response, including SUPI, to I / S-CSCF.

[0507] Optionally, the UDM can check whether the UE has been successfully authenticated before returning SUPI (if the S705 authentication is successful, AUSF will update the UE's authentication status in the UDM). If authentication is incomplete or fails, the SUPI will be refused, or if authentication is successful, the SUPI will be returned.

[0508] S711, I / S-CSCF sends an authentication request to AUSF, including IMPI / SUPI, [IMS Instruction].

[0509] The P-CSCF / I-CSCF / S-CSCF triggers the AUSF to initiate the authentication process, such as by sending an Authentication Request message or invoking the AUSF's Nausf_UEAuthentication_Authenticate operation. This message carries the UE's Mobile Network Identifier (SUPI) or IMS Network Identifier (IMPI or IMPU), and may also carry an IMS indication to indicate that the authentication process is for the IMS network. The IMS indication can be indicated by the serving network name, including the IMS network name or network domain name, or IMS network element information (such as the address or identifier of the P / I / S-CSCF). Optionally, the P / I / S-CSCF can trigger the AUSF to initiate the authentication process based on the first indication information sent by the UE.

[0510] S712, AUSF sends an ID mapping request to UDM, including IMPI / IMPU.

[0511] Optionally, the AUSF requests the UE's SUPI from the UDM / UDR / HSS based on the UE's IMS identification information. This can be done by sending an ID mapping request message to the UDM or calling the UDM's Nudm_ImsSDM_Get operation, carrying the UE's IMS identification information, such as IMPI or IMPU. The UDM then returns the UE's mobile network (e.g., 4G or 5G network) identifier, i.e., the SUPI. Furthermore, the AUSF can also request the UE's SUPI from the UDM based on the IMS indication and the UE's IMS identification information.

[0512] S713, UDM returns an ID mapping response to AUSF, including SUPI / GPSI.

[0513] Optionally, the UDM can check whether the UE has been successfully authenticated before returning SUPI (if the S705 authentication is successful, AUSF will update the UE's authentication status in the UDM). If authentication is incomplete or fails, the SUPI will be refused, or if authentication is successful, the SUPI will be returned.

[0514] In one embodiment, the UE's IMPU is mapped from the GPSI, or the UE's IMPU is the GPSI. In this case, steps S709-S710 and S712-S713 are not executed. The AUSF can obtain the GPSI through the IMPU and then obtain the UE's mobile network authentication status through the GPSI.

[0515] S714, AUSF sends an AV request to UDM, including SUPI.

[0516] Based on the UE's mobile network identifier, the AUSF determines that the UE has not completed authentication on the mobile network and needs to perform the authentication process on the IMS network. The AUSF then requests an authentication vector for the UE from the UDM, for example, by sending an AV request or calling the UDM's Nudm_UEAuthentication_Get operation, carrying SUCI or SUPI. Furthermore, the AUSF can also determine that the UE has not completed authentication on the mobile network and needs to perform the authentication process on the IMS network based on the IMS indication and the UE's mobile network identifier, and in this case, the AUSF requests an authentication vector for the UE from the UDM.

[0517] S715, UDM returns an AV response to AUSF, including RAND, AUTN, RES, and K. AUSF .

[0518] The UDM decrypts the SUCI to obtain the SUPI. The UDM then returns the authentication vector to the AUSF, such as RAND, AUTN, RES, and K generated based on the UE's LTK. AUSF .

[0519] S716, AUSF returns an authentication response to I / S-CSCF, including RAND, AUTN, RES, and K. AUSF / K IMS .

[0520] AUSF optional K-based AUSF Generate K IMS Send authentication vectors, including RAND, AUTN, RES, and K, to the P / I / S-CSCF. AUSF / K IMS .

[0521] S717, UE and P / I / S-CSCF complete mutual authentication based on RAND, AUTN and RES.

[0522] S518, the I / S-CSCF sends a registration success response to the P-CSCF, including K IMS .

[0523] P / I / S-CSCF is based on the S717 authentication result. If authentication is successful, an optional K-based authentication method can be used. AUSF Generate K IMS The system sends a successful IMS registration response to the UE, such as a SIP 200 OK response message. If the I / S-CSCF and AUSF are performing S711-S716, the SIP 200 OK message is forwarded to the UE via the P-CSCF.

[0524] The UE adopts the same approach as AUSF or P / I / S-CSCF based on K. AUSF Generate K IMS .

[0525] K IMS Except for K AUSF Generation can also be based on K AUSF Generate with at least one of the following:

[0526] The string “IMS” (uppercase or lowercase) or a string related to “IMS” (such as “ims_authentication”, “ims application”, etc.), information about the IMS network (such as network identifier or name, network domain name, network identifier or name of the home or visited IMS network, network domain name of the home or visited IMS network), UE’s IMS identification information (such as IMPI, IMPU), and IMS network element information (such as P / I / S-CSCF address or identifier).

[0527] It should be noted that the solution provided in this application can be applied to 6G IMS security, or to IMS signaling optimization in 5G-enhanced Geostationary Earth Orbit (GEO) voice scenarios, thereby accelerating the UE access to IMS in such scenarios.

[0528] It should be noted that the information in [Information B] included in Information A in the above embodiments indicates that Information B is optional information in Information A. The related functions performed by AUSF or HSS in the above embodiments can also be performed by other nodes, such as AMF and UDM in 5G networks, MME in EPS networks, or SEAF and other nodes in 6G networks.

[0529] The wireless communication method provided in this application can be executed by a wireless communication device. This application uses an example of a wireless communication device executing a wireless communication method to illustrate the wireless communication device provided in this application.

[0530] This application provides a wireless communication device. As an example, the wireless communication device may be a communication equipment or a component within a communication equipment, such as a chip. The communication equipment may be a terminal, a network node, or a server, etc. Exemplarily, the terminal may include, but is not limited to, the type of terminal 11 listed above, and the network node may include, but is not limited to, the type of network node 12 listed above. This application does not impose specific limitations.

[0531] The wireless communication device includes a receiving module, a transmitting module, and a processing module. These modules can be implemented in software or hardware. When implemented in hardware, the processing module can be implemented by a processor. For example, the processor can include general-purpose processors, special-purpose processors, etc., such as central processing units (CPUs), microprocessors, digital signal processors (DSPs), artificial intelligence (AI) processors, graphics processing units (GPUs), application-specific integrated circuits (ASICs), network processors (NPs), field-programmable gate arrays (FPGAs), or other programmable logic devices, gate circuits, transistors, discrete hardware components, etc. The receiving and transmitting modules can be implemented by a communication interface, which can include one or more of the following: transceivers, pins, circuits, buses, radio frequency units, etc.

[0532] Specifically, referring to Figure 8, when the wireless communication device is a terminal or a component within a terminal, the wireless communication device 810 includes:

[0533] Processing module 811 is used to perform the first operation, the second operation, or the third operation;

[0534] The first operation includes: performing a first registration process with a first network node in a first network and generating a first key, wherein the first key is used to securely protect the interaction between the terminal and the first network;

[0535] The second operation includes: generating a second derived key based on a first derived key or a first key, and performing a second registration process with a first network node in a first network based on the second derived key;

[0536] The third operation includes: performing a third registration process with a first network node in the first network and at least one of the following:

[0537] The first authentication process may be stopped, not executed, skipped, or executed during the third registration process.

[0538] Generate a second derived key based on the first derived key;

[0539] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0540] The first derived key is generated based on the second authentication process;

[0541] The second derived key is used to securely protect the interaction between the terminal and the first network.

[0542] The second authentication process is an authentication process between the terminal and the second network; the first authentication process is an authentication process between the terminal and the first network.

[0543] The second network is the network accessed by the terminal.

[0544] In this embodiment, the terminal performs a first operation, a second operation, or a third operation, enabling the terminal to obtain a first key or a second derived key for securely protecting the interaction between the terminal and the first network through a first registration process, a second registration process, or a third registration process. This improves the flexibility of authentication between the terminal and the first network. In particular, when the terminal generates a second derived key based on the first derived key or the first key, the signaling overhead in the authentication process can be reduced.

[0545] In some embodiments, the processing module 811 is specifically used for:

[0546] The first operation, the second operation, or the third operation is performed based on at least one of the following:

[0547] The network type associated with the second network and the access technology used by the terminal to access the second network;

[0548] The access technology used by the terminal to access the second network includes at least one of the following: high-orbit satellite access, medium-orbit satellite access, low-orbit satellite access, and non-terrestrial network NTN access;

[0549] The network types associated with the second network include at least one of the following: Independent Non-Public Network (SNPN), Non-Independent Non-Public Network (PLMN-NPN), Non-Public Network (NPN), and Terrestrial Network (TN).

[0550] In some embodiments, generating the second derived key based on the first derived key or the first key includes at least one of the following:

[0551] If the second authentication process is successful, the second derived key is generated based on the first derived key;

[0552] If the second authentication process fails or is not executed, the second derived key is generated based on the first key.

[0553] In some embodiments, performing the second registration process with the first network node in the first network based on the second derived key includes at least one of the following:

[0554] Token information is generated based on the second derived key, and a registration request is sent to the first network node during the second registration process;

[0555] Upon receiving the response message of the registration request, a secure connection is established with the first network node based on the second derived key;

[0556] The registration request includes the token information and at least one of the following: the terminal's identifier in the first network, and first indication information; the first indication information is used to indicate registration based on the second authentication process, or to indicate support for registration based on the second authentication process.

[0557] In some embodiments, performing a first registration process with a first network node in a first network, or performing a third registration process with a first network node in a first network, includes:

[0558] Send a registration request to the first network node, the registration request including at least one of the terminal's identifier and token information in the first network, or the registration request including first indication information and at least one of the following: the terminal's identifier and token information in the first network;

[0559] The first indication information is used to indicate registration based on the second authentication process, or to indicate support for registration based on the second authentication process;

[0560] The token information is generated based on the shared key, the third derived key, the first derived key, or the first key on the terminal;

[0561] The third derived key is generated based on the shared key.

[0562] In some embodiments, the token information is also generated based on at least one of the following:

[0563] Some or all of the contents of the registration request;

[0564] The string related to the system name of the first network;

[0565] The string related to the system name of the second network;

[0566] Information from the first network;

[0567] Information from the second network;

[0568] The identifier of the terminal in the first network;

[0569] The identifier of the terminal in the second network;

[0570] The terminal executes the information used in the first authentication process.

[0571] In some embodiments, the device 810 includes a first receiving module for:

[0572] A response message to the registration request is received; wherein the response message includes at least one of the following:

[0573] Indicator of registration success or failure;

[0574] At least one of the information used to indicate the system of the first network and the information used to indicate the system of the second network;

[0575] Instructions to stop, not execute, skip, or execute the first authentication process;

[0576] Instructions indicating whether the second authentication process was successful, unsuccessful, or not executed;

[0577] Wherein, stopping, not executing, skipping, or executing the first authentication process during the third registration process includes any one of the following:

[0578] Based on the response message, the first authentication process may be stopped, skipped, or not executed.

[0579] Based on the response message, the first authentication process is executed;

[0580] The step of generating a second derived key based on a first derived key and performing a second registration process with a first network node in the first network based on the second derived key includes any one of the following:

[0581] Based on the response message, the first authentication process may be stopped, skipped, or not executed during the second registration process;

[0582] Based on the response message, the first authentication process is performed.

[0583] In some embodiments, the second derived key is also generated based on at least one of the following:

[0584] The string related to the system name of the first network;

[0585] The string related to the system name of the second network;

[0586] Information from the first network;

[0587] Information from the second network;

[0588] The identifier of the terminal in the first network;

[0589] The identifier of the terminal in the second network;

[0590] The information used by the terminal during the second authentication process.

[0591] In some embodiments, the processing module 811 is further configured to perform at least one of the following:

[0592] In the event of executing the second registration process or the third registration process, a secure connection is established with the first network based on the second derived key;

[0593] When the first registration process is performed, a secure connection is established with the first network based on the first key.

[0594] In some embodiments, the system of the second network is a non-IMS system, and the system of the first network is an IMS system.

[0595] Referring to Figure 9, when the wireless communication device is a first network node or a component within a first network node, the wireless communication device 820 includes:

[0596] The receiving module 821 is used to receive registration requests from the terminal;

[0597] The sending module 822 is used to send at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node, in order to obtain authentication status information of the second authentication process;

[0598] The receiving module 821 is further configured to: receive at least one of result information and authentication status information of the second authentication process from the second network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0599] The sending module 822 is further configured to: send a response message to the registration request;

[0600] Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network;

[0601] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0602] The third derived key is generated based on the shared key of the terminal;

[0603] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0604] The first derived key is generated based on the second authentication process;

[0605] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0606] The second authentication process is an authentication process between the terminal and the second network.

[0607] In some embodiments, sending at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node includes:

[0608] Based on the registration request and at least one of the following, the terminal's identifier in the first network, the terminal's identifier in the second network, and at least one of the token information are sent to the second network node:

[0609] The network type associated with the second network and the access technology used by the terminal to access the second network;

[0610] The access technology includes at least one of the following: high-orbit satellite access, medium-orbit satellite access, low-orbit satellite access, and non-terrestrial network NTN access;

[0611] The network type includes at least one of the following: Standalone Non-Public Network (SNPN), Non-Standalone Non-Public Network (PLMN-NPN), Non-Public Network (NPN), and Terrestrial Network (TN).

[0612] In some embodiments, the registration request includes at least one of the terminal's identifier in the first network and the token information, or

[0613] The registration request includes first indication information and at least one of the following: the terminal's identifier in the first network, and token information;

[0614] Wherein, the first indication information is used to indicate registration based on the second authentication, or the first indication information is used to indicate support for registration based on the second authentication.

[0615] In some embodiments, the apparatus 820 further includes a first processing module, wherein before the sending module 822 sends at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node, the receiving module 821 is further configured to:

[0616] The identifier of the terminal in the second network is obtained from a third network node based on at least one of the terminal's identifier in the first network and the token information;

[0617] The first processing module is used to verify the token information.

[0618] In some embodiments, receiving at least one of the result information from the second network node and the authentication status information of the second authentication process includes at least one of the following:

[0619] If at least one of the terminal's identification acquisition failure in the second network and the token information verification failure occurs, stop receiving at least one of the result information and the authentication status information from the second network node;

[0620] If at least one of the terminal's identifier being successfully acquired in the second network and the token information being successfully verified is met, at least one of the result information and the authentication status information is received from the second network node.

[0621] In some embodiments, sending at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node includes:

[0622] Send the token information and at least one of the following to the second network node: the identifier of the terminal in the first network, and the identifier of the terminal in the second network;

[0623] The result information includes the verification result of the token information.

[0624] In some embodiments, the token information is also generated based on at least one of the following:

[0625] Some or all of the contents of the registration request;

[0626] The string related to the system name of the first network;

[0627] The string related to the system name of the second network;

[0628] Information from the first network;

[0629] Information from the second network;

[0630] The identifier of the terminal in the first network;

[0631] The identifier of the terminal in the second network;

[0632] The information used by the terminal during the second authentication process.

[0633] In some embodiments, if the terminal successfully authenticates in the second network, the authentication information includes at least one of the following:

[0634] The second authentication process has been successfully completed;

[0635] Instructions to stop, not perform, or skip the first authentication process;

[0636] The second derived key or the first derived key.

[0637] In some embodiments, if the terminal fails to authenticate in the second network, the authentication status information includes a random number, response information generated based on the random number, and a third derived key;

[0638] The third derived key is generated based on the shared key of the terminal.

[0639] In some embodiments, the device 820 further includes a second processing module for:

[0640] The second derived key is generated based on the first derived key or the first key.

[0641] In some embodiments, the response message to the registration request includes at least one of the following:

[0642] The second derived key;

[0643] Indicator of registration success or failure;

[0644] At least one of the information used to indicate the system of the first network and the information used to indicate the system of the second network;

[0645] Instructions to stop, not execute, skip, or execute the first authentication process;

[0646] Instructions indicating whether the second authentication process was successful, unsuccessful, or not executed.

[0647] In some embodiments, the second derived key is also generated based on at least one of the following:

[0648] The string related to the system name of the first network;

[0649] The string related to the system name of the second network;

[0650] Information from the first network;

[0651] Information from the second network;

[0652] The identifier of the terminal in the first network;

[0653] The identifier of the terminal in the second network;

[0654] The information used by the terminal during the second authentication process.

[0655] In some embodiments, the device 820 further includes a third processing module for:

[0656] From the third network node or the registration request, obtain at least one of the access technologies used by the terminal to access the second network and the network type related to the second network;

[0657] The third network node is a network-side node of the second network.

[0658] In some embodiments, the system of the second network is a non-IMS system, and the system of the first network is an IMS system.

[0659] In some embodiments, the sending module 822 is further configured to:

[0660] Indicate the registration status of the terminal or the authentication status between the terminal and the first network to the fourth network node;

[0661] In cases where the first authentication process has been stopped, not executed, or skipped, the authentication status between the terminal and the first network is considered authenticated.

[0662] In some embodiments, the receiving module 821 is further configured to:

[0663] The sending module 822 is further configured to: receive failure indication information from the fifth network node, the failure indication information indicating that the establishment of a secure channel or secure connection between the fifth network node and the terminal has failed; the sending module 822 is also configured to:

[0664] An update indication message is sent to the fourth network node. The update indication message is used to indicate the invalidation or deletion of the terminal's registration status or the authentication status between the terminal and the first network.

[0665] Referring to Figure 10, when the wireless communication device is a second network node or a component within a second network node, the wireless communication device 830 includes:

[0666] The receiving module 831 is used to receive at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information from the first network node, for obtaining authentication status information of the second authentication process;

[0667] The sending module 832 is used to send at least one of result information and authentication status information of the second authentication process to the first network node based on at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information. The result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0668] Wherein, the first network node is the network-side node of the first network;

[0669] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0670] The third derived key is generated based on the shared key of the terminal;

[0671] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0672] The first derived key is generated based on the second authentication process;

[0673] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0674] The second authentication process is the authentication process between the terminal and the second network.

[0675] In some embodiments, the receiving module 831 is further configured to:

[0676] Based on the terminal's identifier in the first network, the terminal's identifier in the second network is obtained from the fourth network node.

[0677] In some embodiments, the device 830 further includes a first processing module for:

[0678] Verify the token information;

[0679] The result information includes the verification result of the token information.

[0680] In some embodiments, the token information is also generated based on at least one of the following:

[0681] Part or all of the content in the registration request;

[0682] The string related to the system name of the first network;

[0683] The string related to the system name of the second network;

[0684] Information from the first network;

[0685] Information from the second network;

[0686] The identifier of the terminal in the first network;

[0687] The identifier of the terminal in the second network;

[0688] The information used by the terminal during the second authentication process.

[0689] In some embodiments, if the terminal successfully authenticates in the second network, the authentication information includes at least one of the following:

[0690] The second authentication process has been successfully completed;

[0691] Instructions to stop, not perform, or skip the first authentication process;

[0692] The second derived key or the first derived key.

[0693] In some embodiments, if the terminal fails to authenticate in the second network, the authentication status information includes a random number, response information generated based on the random number, and the third derived key.

[0694] In some embodiments, the sending module 832 is further configured to:

[0695] The second network node sends the token information to the fourth network node; the receiving module 831 is further configured to:

[0696] The second network node receives the result information from the fourth network node.

[0697] In some embodiments, if the terminal fails to authenticate in the second network, the sending module 832 is further configured to:

[0698] Sending at least one of the terminal's identifier in the first network and the terminal's identifier in the second network to the fourth network node; the receiving module 831 is further configured to:

[0699] Receive the authentication information from the fourth network node;

[0700] The authentication information includes the third derived key, a random number, and response information generated based on the random number.

[0701] In some embodiments, the system of the second network is a non-IMS system, and the system of the first network is an IMS system.

[0702] Referring to Figure 11, when the wireless communication device is a fifth network node or a component within a fifth network node, the wireless communication device 840 includes:

[0703] Receiver module 841 is used to receive registration requests from the terminal;

[0704] Sending module 842 is used to send a registration request to the first network node;

[0705] The receiving module is further configured to receive a response message of the registration request from the first network node. The response message includes a second derived key and third information, wherein the third information includes at least one of the following: an indication of successful registration, at least one of the systems of the first network and the second network, an indication to stop, not execute, skip, or execute the first authentication process, and an indication that the second authentication process has been successful.

[0706] Processing module 843 is used to establish a secure connection with the terminal based on the response message;

[0707] Wherein, the first network is the network where the first network node is located.

[0708] In some embodiments, the sending module 842 is further configured to:

[0709] In the event that the secure connection fails to be established, a failure indication message is sent to the first network node, indicating that the secure connection between the fifth network node and the terminal has failed to be established.

[0710] In some embodiments, establishing a secure connection with the terminal based on the response message includes at least one of the following:

[0711] A secure connection is established with the terminal based on the second derived key;

[0712] A secure connection is established with the terminal based on the third information.

[0713] In some embodiments, establishing a secure connection with the terminal based on the third information includes:

[0714] If the third information indicates that the first authentication process should be stopped, not executed, or skipped, a secure connection is established with the terminal.

[0715] The apparatus provided in this application embodiment can implement the various processes implemented in the method embodiments of Figures 2 to 7 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0716] As shown in Figure 12, this application embodiment also provides a communication device 900, including a processor 901 and a memory 902. The memory 902 stores a program or instructions that can run on the processor 901. For example, when the communication device 900 is a terminal, the program or instructions executed by the processor 901 implement the various steps of the above-described wireless communication method embodiment and achieve the same technical effect. When the communication device 900 is a first network node, a second network node, or a fifth network node, the program or instructions executed by the processor 901 implement the various steps of the above-described wireless communication method embodiment and achieve the same technical effect. To avoid repetition, further details are omitted here.

[0717] This application also provides a terminal, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps in the method embodiments shown in Figures 2 to 7. This terminal embodiment corresponds to the above-described terminal-side method embodiments, and all implementation processes and methods of the above-described method embodiments can be applied to this terminal embodiment and achieve the same technical effect. The terminal may be the wireless communication device shown in Figure 8. Specifically, Figure 13 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of this application.

[0718] The terminal 1000 includes, but is not limited to, at least some of the following components: radio frequency unit 1001, network module 1002, audio output unit 1003, input unit 1004, sensor 1005, display unit 1006, user input unit 1007, interface unit 1008, memory 1009, and processor 1010.

[0719] Those skilled in the art will understand that the terminal 1000 may also include a power supply (such as a battery) for powering various components. The power supply can be logically connected to the processor 1010 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The terminal structure shown in Figure 13 does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0720] It should be understood that, in this embodiment, the input unit 1004 may include a graphics processor 10041 and a microphone 10042. The graphics processor 10041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 1006 may include a display panel 10061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1007 includes a touch panel 10071 and at least one of other input devices 10072. The touch panel 10071 is also called a touch screen. The touch panel 10071 may include a touch detection device and a touch controller. Other input devices 10072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.

[0721] In this embodiment, after receiving downlink data from a network node, the radio frequency unit 1001 can transmit it to the processor 1010 for processing; in addition, the radio frequency unit 1001 can send uplink data to the network node. Typically, the radio frequency unit 1001 includes, but is not limited to, antennas, amplifiers, transceivers, couplers, low-noise amplifiers, duplexers, etc.

[0722] The memory 1009 can be used to store software programs or instructions, as well as various data. The memory 1009 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 1009 may include volatile memory or non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 1009 in this embodiment includes, but is not limited to, these and any other suitable types of memory.

[0723] The processor 1010 may include one or more processing units; optionally, the processor 1010 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into the processor 1010.

[0724] Processor 1010 is used to perform a first operation, a second operation, or a third operation;

[0725] The first operation includes: performing a first registration process with a first network node in a first network and generating a first key, wherein the first key is used to securely protect the interaction between the terminal and the first network;

[0726] The second operation includes: generating a second derived key based on a first derived key or a first key, and performing a second registration process with a first network node in a first network based on the second derived key;

[0727] The third operation includes: performing a third registration process with a first network node in the first network and at least one of the following:

[0728] The first authentication process may be stopped, not executed, skipped, or executed during the third registration process.

[0729] Generate a second derived key based on the first derived key;

[0730] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0731] The first derived key is generated based on the second authentication process;

[0732] The second derived key is used to securely protect the interaction between the terminal and the first network.

[0733] The second authentication process is an authentication process between the terminal and the second network; the first authentication process is an authentication process between the terminal and the first network.

[0734] The second network is the network accessed by the terminal.

[0735] In the embodiments of this application, the terminal performs a first operation, a second operation, or a third operation. The first operation enhances the flexibility of authentication between the terminal and the first network. In particular, when the terminal generates a second derived key based on a first derived key or a first key, the signaling overhead during the authentication process can be reduced.

[0736] It is understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant descriptions of method embodiments 200 to 700 and achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.

[0737] This application also provides a network node, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method embodiments shown in Figures 3 to 7. This network node embodiment corresponds to the above-described network node method embodiments, and all implementation processes and methods of the above-described method embodiments can be applied to this network node embodiment and achieve the same technical effects.

[0738] Specifically, this application embodiment also provides a network node. As shown in FIG14, the network node 1100 includes: a processor 1101, a network interface 1102, and a memory 1103. The network node may be the wireless communication device shown in FIG9, FIG10, or FIG11. The network interface 1102 is, for example, a common public radio interface (CPRI).

[0739] In one implementation, the network node 1100 may be a first network node, and the network interface 1102 is used for:

[0740] Receive registration requests from terminals;

[0741] Send at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node to obtain authentication status information for the second authentication process;

[0742] Receive at least one of the result information and the authentication status information of the second authentication process from the second network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0743] Send a response message to the registration request;

[0744] Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network;

[0745] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0746] The third derived key is generated based on the shared key of the terminal;

[0747] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0748] The first derived key is generated based on the second authentication process;

[0749] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0750] The second authentication process is an authentication process between the terminal and the second network.

[0751] In one implementation, the network node 1100 can be a second network node, and the network interface 1102 is used for:

[0752] Receive at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information from the first network node, for the purpose of obtaining authentication status information for the second authentication process;

[0753] Based on at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information, at least one of result information and authentication status information of the second authentication process is sent to the first network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed.

[0754] Wherein, the first network node is the network-side node of the first network;

[0755] The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key;

[0756] The third derived key is generated based on the shared key of the terminal;

[0757] The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key.

[0758] The first derived key is generated based on the second authentication process;

[0759] The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network;

[0760] The second authentication process is the authentication process between the terminal and the second network.

[0761] In one implementation, network node 1100 can be a fifth network node, and network interface 1102 is used for:

[0762] Receive registration request from the terminal;

[0763] The sending module is used to send a registration request to the first network node;

[0764] The receiving module is further configured to receive a response message of the registration request from the first network node. The response message includes a second derived key and third information, wherein the third information includes at least one of the following: an indication of successful registration, at least one of the systems of the first network and the second network, an indication to stop, not execute, skip, or execute the first authentication process, and an indication that the second authentication process has been successful.

[0765] Processor 1101 is used to establish a secure connection with the terminal based on the response message;

[0766] Wherein, the first network is the network where the first network node is located.

[0767] In addition, the network node 1100 in this embodiment of the application also includes: a program or instructions stored in the memory 1103 and executable on the processor 1101. The processor 1101 calls the program or instructions in the memory 1103 to execute the methods executed by the modules shown in FIG9, FIG10 or FIG11 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.

[0768] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described wireless communication method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.

[0769] The processor mentioned above is either the processor in the terminal or the processor in the network node described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk. In some examples, the readable storage medium may be a non-transient readable storage medium.

[0770] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described wireless communication method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0771] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0772] This application also provides a computer program / program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the above-described wireless communication method embodiments, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0773] This application also provides a wireless communication system, including a terminal and a network node. The terminal can be used to execute the steps of the wireless communication method described above, and the network node can be used to execute the steps of the wireless communication method described above.

[0774] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0775] From the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of a computer software product plus the necessary general-purpose hardware platform, and of course, they can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.), and the computer software product includes several instructions to cause a terminal or network node to execute the methods described in the various embodiments of this application.

[0776] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other implementations under the guidance of this application without departing from the spirit and scope of the claims. All of these implementations are within the protection scope of this application.

Claims

1. A wireless communication method, comprising: The terminal executes the first operation, the second operation, or the third operation; The first operation includes: performing a first registration process with a first network node in a first network and generating a first key, wherein the first key is used to securely protect the interaction between the terminal and the first network; The second operation includes: generating a second derived key based on a first derived key or a first key, and performing a second registration process with a first network node in a first network based on the second derived key; The third operation includes: performing a third registration process with a first network node in the first network and at least one of the following: The first authentication process may be stopped, not executed, skipped, or executed during the third registration process. Generate a second derived key based on the first derived key; The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network; The first derived key is generated based on the second authentication process; The second derived key is used to securely protect the interaction between the terminal and the first network. The second authentication process is an authentication process between the terminal and the second network; the first authentication process is an authentication process between the terminal and the first network. The second network is the network accessed by the terminal.

2. The method according to claim 1, wherein, The terminal performs a first operation, a second operation, or a third operation, including: The terminal performs the first operation, the second operation, or the third operation based on at least one of the following: The network type associated with the second network and the access technology used by the terminal to access the second network; The access technology used by the terminal to access the second network includes at least one of the following: high-orbit satellite access, medium-orbit satellite access, low-orbit satellite access, and non-terrestrial network NTN access; The network types associated with the second network include at least one of the following: Independent Non-Public Network (SNPN), Non-Independent Non-Public Network (PLMN-NPN), Non-Public Network (NPN), and Terrestrial Network (TN).

3. The method according to claim 1 or 2, wherein, The terminal generates a second derived key based on a first derived key or a first key, including at least one of the following: If the second authentication process is successful, the terminal generates the second derived key based on the first derived key; If the second authentication process fails or is not executed, the terminal generates the second derived key based on the first key.

4. The method according to any one of claims 1 to 3, wherein, The terminal performs a second registration process with a first network node in the first network based on the second derived key, including at least one of the following: The terminal generates token information based on the second derived key and sends a registration request to the first network node during the second registration process; The terminal receives the response message of the registration request and establishes a secure connection with the first network node based on the second derived key; The registration request includes the token information and at least one of the following: the terminal's identifier in the first network, and first indication information; the first indication information is used to indicate registration based on the second authentication process, or to indicate support for registration based on the second authentication process.

5. The method according to any one of claims 1 to 3, wherein, The terminal performs a first registration process with a first network node in the first network, or the terminal performs a third registration process with a first network node in the first network, including: The terminal sends a registration request to the first network node. The registration request includes at least one of the terminal's identifier and token information in the first network, or the registration request includes first indication information and at least one of the following: the terminal's identifier and token information in the first network. The first indication information is used to indicate registration based on the second authentication process, or to indicate support for registration based on the second authentication process; The token information is generated based on the shared key, the third derived key, the first derived key, or the first key on the terminal; The third derived key is generated based on the shared key.

6. The method according to claim 4 or 5, wherein, The token information is also generated based on at least one of the following: Some or all of the contents of the registration request; The string related to the system name of the first network; The string related to the system name of the second network; Information from the first network; Information from the second network; The identifier of the terminal in the first network; The identifier of the terminal in the second network; The terminal executes the information used in the first authentication process.

7. The method according to any one of claims 4 to 6, wherein, The method further includes: The terminal receives a response message to the registration request; wherein the response message includes at least one of the following: Indicator of registration success or failure; At least one of the information used to indicate the system of the first network and the information used to indicate the system of the second network; Instructions to stop, not execute, skip, or execute the first authentication process; Instructions indicating whether the second authentication process was successful, unsuccessful, or not executed; Wherein, stopping, not executing, skipping, or executing the first authentication process during the third registration process includes any one of the following: Based on the response message, the terminal stops, skips, or does not perform the first authentication process; The terminal performs a first authentication process based on the response message; Wherein, the terminal generates a second derived key based on the first derived key, and performs a second registration process with the first network node in the first network based on the second derived key, including any one of the following: Based on the response message, the terminal may stop, skip, or not perform the first authentication process during the second registration process; The terminal performs a first authentication process based on the response message.

8. The method according to any one of claims 1 to 7, wherein, The second derived key is also generated based on at least one of the following: The string related to the system name of the first network; The string related to the system name of the second network; Information from the first network; Information from the second network; The identifier of the terminal in the first network; The identifier of the terminal in the second network; The information used by the terminal during the second authentication process.

9. The method according to any one of claims 1 to 8, wherein, The method further includes at least one of the following: When performing the second registration process or the third registration process, the terminal establishes a secure connection with the first network based on the second derived key; When the first registration process is executed, the terminal establishes a secure connection with the first network based on the first key.

10. The method according to any one of claims 1 to 9, wherein, The second network uses a non-IMS system, while the first network uses an IMS system.

11. A wireless communication method, comprising: The first network node receives a registration request from the terminal; The first network node sends at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node to obtain authentication status information for the second authentication process; The first network node receives at least one of the result information and the authentication status information of the second authentication process from the second network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed. The first network node sends a response message to the registration request; Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network, and the first network node is a network-side node of the first network; The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key; The third derived key is generated based on the shared key of the terminal; The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key. The first derived key is generated based on the second authentication process; The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network; The second authentication process is an authentication process between the terminal and the second network.

12. The method according to claim 11, wherein, The first network node sends at least one of the following to the second network node: the terminal's identifier in the first network, the terminal's identifier in the second network, and token information: The first network node sends to the second network node at least one of the following based on the registration request: the terminal's identifier in the first network, the terminal's identifier in the second network, and the token information: The network type associated with the second network and the access technology used by the terminal to access the second network; The access technology includes at least one of the following: high-orbit satellite access, medium-orbit satellite access, low-orbit satellite access, and non-terrestrial network NTN access; The network type includes at least one of the following: Standalone Non-Public Network (SNPN), Non-Standalone Non-Public Network (PLMN-NPN), Non-Public Network (NPN), and Terrestrial Network (TN).

13. The method according to claim 11 or 12, wherein, The registration request includes at least one of the terminal's identifier in the first network and the token information, or The registration request includes first indication information and at least one of the following: the terminal's identifier in the first network, and token information; Wherein, the first indication information is used to indicate registration based on the second authentication, or the first indication information is used to indicate support for registration based on the second authentication.

14. The method according to claim 13, wherein, Before the first network node sends at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node, the method further includes at least one of the following: The first network node obtains the identifier of the terminal in the second network from the third network node based on at least one of the terminal's identifier in the first network and the token information; The first network node verifies the token information.

15. The method according to claim 14, wherein, The first network node receives at least one of the following: result information and authentication status information of the second authentication process from the second network node: If at least one of the terminal's identification acquisition failure in the second network and the token information verification failure occurs, the first network node shall stop receiving at least one of the result information and the authentication status information from the second network node. If at least one of the terminal's identifier being successfully acquired in the second network and the token information being successfully verified is met, the first network node receives at least one of the result information and the authentication status information from the second network node.

16. The method according to any one of claims 13 to 15, wherein, The first network node sends at least one of the following to the second network node: the terminal's identifier in the first network, the terminal's identifier in the second network, and token information: The first network node sends the token information and at least one of the following to the second network node: the identifier of the terminal in the first network, and the identifier of the terminal in the second network; The result information includes the verification result of the token information.

17. The method according to any one of claims 13 to 16, wherein, The token information is also generated based on at least one of the following: Some or all of the contents of the registration request; The string related to the system name of the first network; The string related to the system name of the second network; Information from the first network; Information from the second network; The identifier of the terminal in the first network; The identifier of the terminal in the second network; The information used by the terminal during the second authentication process.

18. The method according to any one of claims 11 to 17, wherein, If the terminal successfully authenticates in the second network, the authentication information includes at least one of the following: The second authentication process has been successfully completed; Instructions to stop, not perform, or skip the first authentication process; The second derived key or the first derived key.

19. The method according to any one of claims 11 to 17, wherein, If the terminal fails to authenticate in the second network, the authentication status information includes a random number, response information generated based on the random number, and a third derived key; The third derived key is generated based on the shared key of the terminal.

20. The method according to any one of claims 11 to 19, wherein, The method further includes: The first network node generates the second derived key based on the first derived key or the first key.

21. The method according to any one of claims 11 to 20, wherein, The response message to the registration request includes at least one of the following: The second derived key; Indicator of registration success or failure; At least one of the information used to indicate the system of the first network and the information used to indicate the system of the second network; Instructions to stop, not execute, skip, or execute the first authentication process; Instructions indicating whether the second authentication process was successful, unsuccessful, or not executed.

22. The method according to claim 18, 20 or 21, wherein, The second derived key is also generated based on at least one of the following: The string related to the system name of the first network; The string related to the system name of the second network; Information from the first network; Information from the second network; The identifier of the terminal in the first network; The identifier of the terminal in the second network; The information used by the terminal during the second authentication process.

23. The method according to any one of claims 12 to 22, wherein, The method further includes: The first network node obtains from the third network node or the registration request at least one of the access technology used by the terminal to access the second network and the network type related to the second network. The third network node is a network-side node of the second network.

24. The method according to any one of claims 11 to 23, wherein, The second network uses a non-IMS system, while the first network uses an IMS system.

25. The method according to any one of claims 11 to 24, wherein, The method further includes: The first network node indicates the registration status of the terminal or the authentication status between the terminal and the first network to the fourth network node; In cases where the first authentication process has been stopped, not executed, or skipped, the authentication status between the terminal and the first network is considered authenticated.

26. The method of claim 25, wherein, The method further includes: The first network node receives a failure indication information from the fifth network node, the failure indication information indicating that the establishment of a secure channel or secure connection between the fifth network node and the terminal has failed. The first network node sends an update indication message to the fourth network node. The update indication message is used to indicate the invalidation or deletion of the terminal's registration status or the authentication status between the terminal and the first network.

27. A wireless communication method, comprising: The second network node receives at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information from the first network node, and uses it to obtain authentication status information for the second authentication process. The second network node sends at least one of the following to the first network node: result information and authentication status information of the second authentication process, based on at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information. The result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed. Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network, and the first network node is a network-side node of the first network; The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key; The third derived key is generated based on the shared key of the terminal; The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key. The first derived key is generated based on the second authentication process; The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network; The second authentication process is the authentication process between the terminal and the second network.

28. The method according to claim 27, wherein, The method further includes: The second network node obtains the terminal's identifier in the second network from the fourth network node based on the terminal's identifier in the first network.

29. The method according to claim 27 or 28, wherein, The method includes: The second network node verifies the token information; The result information includes the verification result of the token information.

30. The method according to any one of claims 27 to 29, wherein, The token information is also generated based on at least one of the following: Part or all of the content in the registration request; The string related to the system name of the first network; The string related to the system name of the second network; Information from the first network; Information from the second network; The identifier of the terminal in the first network; The identifier of the terminal in the second network; The information used by the terminal during the second authentication process.

31. The method according to any one of claims 27 to 30, wherein, If the terminal successfully authenticates in the second network, the authentication information includes at least one of the following: The second authentication process has been successfully completed; Instructions to stop, not perform, or skip the first authentication process; The second derived key or the first derived key.

32. The method according to any one of claims 27 to 31, wherein, If the terminal fails to authenticate in the second network, the authentication status information includes a random number, response information generated based on the random number, and the third derived key.

33. The method according to any one of claims 27 to 32, wherein, The method further includes: The second network node sends the token information to the fourth network node; The second network node receives the result information from the fourth network node.

34. The method according to any one of claims 27 to 33, wherein, If the terminal fails to authenticate in the second network, the method further includes: The second network node sends at least one of the terminal's identifier in the first network and the terminal's identifier in the second network to the fourth network node; The second network node receives the authentication information from the fourth network node; The authentication information includes the third derived key, a random number, and response information generated based on the random number.

35. The method according to any one of claims 27 to 34, wherein, The second network uses a non-IMS system, while the first network uses an IMS system.

36. A wireless communication method, comprising: The fifth network node receives the registration request from the terminal and sends the registration request to the first network node; The fifth network node receives a response message for the registration request from the first network node. The response message includes a second derived key and third information, wherein the third information includes at least one of the following: an indication of successful registration, at least one of the systems of the first network and the second network, an indication to stop, not execute, skip, or execute the first authentication process, and an indication that the second authentication process has been successful. The fifth network node establishes a secure connection with the terminal based on the response message; The first network refers to the network in which the fifth network node and the first network node are located.

37. The method of claim 36, wherein, The method further includes: In the event that the secure connection establishment fails, the fifth network node sends a failure indication message to the first network node, the failure indication message indicating that the secure connection establishment between the fifth network node and the terminal has failed.

38. The method according to claim 36 or 37, wherein, The fifth network node establishes a secure connection with the terminal based on the response message, including at least one of the following: The fifth network node establishes a secure connection with the terminal based on the second derived key; The fifth network node establishes a secure connection with the terminal based on the third information.

39. The method according to claim 38, wherein, The fifth network node establishes a secure connection with the terminal based on the third information, including: If the third information indicates that the first authentication process should be stopped, not executed, or skipped, the fifth network node establishes a secure connection with the terminal.

40. A wireless communication device, comprising: The processing module is used to perform the first operation, the second operation, or the third operation; The first operation includes: performing a first registration process with a first network node in the first network and generating a first key, wherein the first key is used to securely protect the interaction between the terminal and the first network; The second operation includes: generating a second derived key based on a first derived key or a first key, and performing a second registration process with a first network node in a first network based on the second derived key; The third operation includes: performing a third registration process with a first network node in the first network and at least one of the following: The first authentication process may be stopped, not executed, skipped, or executed during the third registration process. Generate a second derived key based on the first derived key; The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network; The first derived key is generated based on the second authentication process; The second derived key is used to securely protect the interaction between the terminal and the first network. The second authentication process is an authentication process between the terminal and the second network; the first authentication process is an authentication process between the terminal and the first network. The second network is the network accessed by the terminal.

41. The apparatus according to claim 40, wherein, The processing module is specifically used for: The first operation, the second operation, or the third operation is performed based on at least one of the following: The network type associated with the second network and the access technology used by the terminal to access the second network; The access technology used by the terminal to access the second network includes at least one of the following: high-orbit satellite access, medium-orbit satellite access, low-orbit satellite access, and non-terrestrial network NTN access; The network types associated with the second network include at least one of the following: Independent Non-Public Network (SNPN), Non-Independent Non-Public Network (PLMN-NPN), Non-Public Network (NPN), and Terrestrial Network (TN).

42. A wireless communication device, comprising: The receiving module is used to receive registration requests from the terminal; The sending module is used to send at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information to the second network node, in order to obtain authentication status information of the second authentication process; The receiving module is further configured to: receive at least one of result information and authentication status information of the second authentication process from the second network node, wherein the result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed. The sending module is also used to: send a response message for the registration request; Wherein, the second network node is a network-side node of the second network, or the second network node is a network-side node shared by the second network and the first network; The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key; The third derived key is generated based on the shared key of the terminal; The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key. The first derived key is generated based on the second authentication process; The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network; The second authentication process is an authentication process between the terminal and the second network.

43. The apparatus according to claim 42, wherein, The sending module is specifically used for: Based on the registration request and at least one of the following, the terminal's identifier in the first network, the terminal's identifier in the second network, and at least one of the token information are sent to the second network node: The network type associated with the second network and the access technology used by the terminal to access the second network; The access technology includes at least one of the following: high-orbit satellite access, medium-orbit satellite access, low-orbit satellite access, and non-terrestrial network NTN access; The network type includes at least one of the following: Standalone Non-Public Network (SNPN), Non-Standalone Non-Public Network (PLMN-NPN), Non-Public Network (NPN), and Terrestrial Network (TN).

44. A wireless communication device, comprising: The receiving module is used to receive at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information from the first network node, for obtaining authentication status information of the second authentication process; The sending module is used to send at least one of result information and authentication status information of the second authentication process to the first network node based on at least one of the terminal's identifier in the first network, the terminal's identifier in the second network, and token information. The result information is used to indicate whether the authentication status information of the second authentication process was successfully obtained or failed. Wherein, the first network node is the network-side node of the first network; The token information is generated based on at least one of the following: the terminal's shared key, third derived key, first derived key, second derived key, and first key; The third derived key is generated based on the shared key of the terminal; The second derived key is used to securely protect the interaction between the terminal and the first network, and the second derived key is generated based on the first derived key or the first key. The first derived key is generated based on the second authentication process; The first key is generated based on at least one of first information and second information; the first information includes at least one of the following: a string related to the system name of the second network, information about the second network, and the identifier of the terminal in the second network; the second information includes at least one of the following: a string related to the system name of the first network, information about the first network, and the identifier of the terminal in the first network; The second authentication process is the authentication process between the terminal and the second network.

45. The apparatus according to claim 44, wherein, The receiving module is also used for: Based on the terminal's identifier in the first network, the terminal's identifier in the second network is obtained from the fourth network node.

46. ​​A wireless communication device, comprising: The receiving module is used to receive registration requests from the terminal; The sending module is used to send a registration request to the first network node; The receiving module is further configured to receive a response message of the registration request from the first network node. The response message includes a second derived key and third information, wherein the third information includes at least one of the following: an indication of successful registration, at least one of the systems of the first network and the second network, an indication to stop, not execute, skip, or execute the first authentication process, and an indication that the second authentication process has been successful. The processing module is used to establish a secure connection with the terminal based on the response message; Wherein, the first network is the network where the first network node is located.

47. The apparatus according to claim 46, wherein, The sending module is also used for: In the event that the secure connection fails to be established, a failure indication message is sent to the first network node, indicating that the secure connection between the fifth network node and the terminal has failed to be established.

48. A terminal comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the wireless communication method as claimed in any one of claims 1 to 10.

49. A network node comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the wireless communication method as claimed in any one of claims 11 to 26, or implementing the steps of the wireless communication method as claimed in any one of claims 27 to 35, or implementing the steps of the wireless communication method as claimed in any one of claims 36 to 39.

50. A readable storage medium storing a program or instructions that, when executed by a processor, implement the steps of the wireless communication method as claimed in any one of claims 1 to 10, or the steps of the wireless communication method as claimed in any one of claims 11 to 26, or the steps of the wireless communication method as claimed in any one of claims 27 to 35, or the steps of the wireless communication method as claimed in any one of claims 36 to 39.