WO2023221502A1 - 数据传输方法和系统及信令安全管理网关 - Google Patents
数据传输方法和系统及信令安全管理网关 Download PDFInfo
- Publication number
- WO2023221502A1 WO2023221502A1 PCT/CN2022/140915 CN2022140915W WO2023221502A1 WO 2023221502 A1 WO2023221502 A1 WO 2023221502A1 CN 2022140915 W CN2022140915 W CN 2022140915W WO 2023221502 A1 WO2023221502 A1 WO 2023221502A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- network element
- sinking
- access network
- user
- access
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
- H04W12/033—Protecting confidentiality, e.g. by encryption of the user plane, e.g. user's traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/069—Authentication using certificates or pre-shared keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W56/00—Synchronisation arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W56/00—Synchronisation arrangements
- H04W56/001—Synchronization between nodes
Definitions
- the present disclosure relates to the technical fields of communication and network security, and in particular to a data transmission method and system and a signaling security management gateway.
- 5G fifth generation mobile communication technology
- This disclosed embodiment provides access authentication and management for downlink access network elements through a signaling security management gateway, and transmits data sent from core network elements to downlink access network elements that have passed the authentication through an encrypted channel.
- Some embodiments of the present disclosure provide a data transmission method, including:
- the signaling security management gateway receives a request from a downlink access network element to access a core network element, and authenticates the downlink access network element;
- the signaling security management gateway establishes an encrypted channel between it and the authenticated sinking access network element
- the signaling security management gateway receives the user data synchronization request sent by the sinking access network element, and sends the user data synchronization request to the core network element;
- the signaling security management gateway receives the encrypted user data sent by the core network element, and sends the encrypted user data to the sinking access network element through the encrypted channel.
- the signaling security management gateway receives a request from a sinking access network element to access a core network element, and authenticating the sinking access network element includes:
- the signaling security management gateway receives a request from a sinking access network element to access a core network element.
- the request to access a core network element carries the identifier of the sinking access network element and is embedded in the sinking access network element.
- the signaling security management gateway determines that the binding relationship between the identifier of the sinking access network element and the identifier of the user card in the request to access the core network element is incorrect or does not exist.
- the sinking access network element fails to pass the authentication; or,
- the signaling security management gateway determines that the sinking access network element is not authenticated. pass; or,
- the binding relationship between the identifier of the sinking access network element and the identifier of the user card in the request to access the core network element by the signaling security management gateway is correct and the certificate information in the user subscription data is correct. If the timeliness and legality meet the requirements, it is determined that the sinking access network element has passed the authentication.
- the user data synchronization request includes the identification and data network information of the sinking access network element; the signaling security management gateway receives the user data synchronization request sent by the sinking access network element. , and sending the user data synchronization request to the core network element, including: the signaling security management gateway receiving the user data synchronization request sent by the sinking access network element, and synchronizing the user data The request is sent to the core network element, so that the core network element obtains corresponding encrypted user data based on the identification and data network information of the sinking access network element.
- it also includes:
- the signaling security management gateway receives a request for downloading user subscription data sent by the sinking access network element, and the request for downloading the user subscription data includes the identification of the sinking access network element and the embedded number of the sinking access network element.
- the signaling security management gateway performs authentication based on the identification and certificate of the user card. After passing the authentication, it queries the user subscription data loaded in the sinking access network element. If no user is loaded in the sinking access network element, When the subscription data or the loaded user subscription data has expired, notify the sinking access network element to download new user subscription data, and establish a relationship between the identifier of the sinking access network element and the identifier of the user card. Binding information.
- the signaling security management gateway notifies the sinking access network element to download new user subscription data including:
- the signaling security management gateway notifies the sinking access network element to download new user subscription data, so that the sinking access network element downloads the new user subscription data through an encrypted channel and activates it;
- the signaling security management gateway receives the message that the new user subscription data is successfully activated sent by the sinking access network element.
- the signaling security management gateway issues user cards for each downlink access network element, and each user card includes the certificate of the user card.
- the core network elements include UDM network elements, UPF network elements, AMF network elements, and SMF network elements.
- the sinking access network elements include UDM network elements, UPF network elements, AMF network elements, and SMF network elements.
- the user card includes an embedded UICC.
- Some embodiments of the present disclosure provide a signaling security management gateway, including:
- An authentication module configured to receive a request from a downlink access network element to access a core network element, and authenticate the downlink access network element
- a channel establishment module configured to establish an encrypted channel with the sinking access network element that has passed the authentication of the authentication module
- An information agent module configured to receive a user data synchronization request sent by the sinking access network element, and send the user data synchronization request to the core network element; receive an encrypted message sent by the core network element; user data, and sends the encrypted user data to the sinking access network element through the encrypted channel.
- the signaling security management gateway further includes: a download management module configured to receive a request to download user subscription data sent by the sinking access network element, where the request to download user subscription data includes the The identification of the sinking access network element and the identification and certificate of the user card embedded in the sinking access network element; perform authentication based on the identification and certificate of the user card, and after passing the authentication, query the sinking access network If the user subscription data loaded by the user element is not loaded in the sinking access network element or the loaded user subscription data has expired, the sinking access network element is notified to download new user subscription data, and Establish binding information between the identifier of the downlink access network element and the identifier of the user card.
- a download management module configured to receive a request to download user subscription data sent by the sinking access network element, where the request to download user subscription data includes the The identification of the sinking access network element and the identification and certificate of the user card embedded in the sinking access network element; perform authentication based on the identification and certificate of the user card, and after passing the authentication, query the
- the authentication module is configured as:
- the request to access a core network element carries the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access network element. And the certificate information in the user’s contract data;
- the binding relationship between the identifier of the sinking access network element and the identifier of the user card is correct and the timeliness and legality of the certificate information in the user subscription data meet the requirements.
- Some embodiments of the present disclosure provide a signaling security management gateway, including: a memory; and a processor coupled to the memory, the processor being configured to execute various embodiments based on instructions stored in the memory. data transmission method.
- Some embodiments of the present disclosure provide a data transmission system, including: a signaling security management gateway of each embodiment, a core network element, configured to respond to a user data synchronization request and send encrypted user data to the signaling security management gateway , and the sinking access network element is configured to send a request to access the core network element to the signaling security management gateway, establish an encrypted channel with the signaling security management gateway, and send a request to the signaling security management gateway.
- User data synchronization request receiving encrypted user data sent by the signaling security management gateway through an encrypted channel.
- Some embodiments of the present disclosure provide a non-transitory computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps of the data transmission method of each embodiment are implemented.
- Figure 1 shows a schematic diagram of a secure data transmission system according to some embodiments of the present disclosure.
- Figure 2 shows a schematic diagram of a secure data transmission method according to some embodiments of the present disclosure.
- Figure 3 shows a schematic diagram of a secure data transmission method according to other embodiments of the present disclosure.
- Figure 4 shows a schematic structural diagram of a signaling security management gateway according to some embodiments of the present disclosure.
- Figure 5 shows a schematic structural diagram of a signaling security management gateway according to other embodiments of the present disclosure.
- This disclosed embodiment provides access authentication and management for downlink access network elements through the signaling security management gateway, and transmits data from the core network element to the downlink access network element that has passed the authentication through an encrypted channel, thereby improving The security of data transmitted between core network elements and sinking access network elements reduces the risk of information leakage.
- Figure 1 shows a schematic diagram of a secure data transmission system according to some embodiments of the present disclosure.
- the secure data transmission system of this embodiment includes: a core network element 110, a signaling security management gateway 120, and a downlink access network element 130.
- the core network element 110 is a variety of network elements deployed in the core network, which may include, for example, Universal Data Management (Unified Data Management, UDM) network elements, User Plane Function (UPF, User Plane Function) network elements, AMF (Access and Mobility) Management Function, access and mobility management function) network element, SMF (Session Management Function, session management function) network element, etc.
- the core network provides network services such as terminal access and mobility management, authentication and authorization management, session management, and policy control through various core network elements.
- the 5G SA Tin Alone, independent networking
- core network provides 5G network services such as 5G terminal access and mobility management, authentication management, session management, and policy control.
- the signaling security management gateway 120 may include functions such as network element authentication and authentication, embedded user card remote management, and information agency.
- the remote management function of the embedded user card may include, for example: performing data interaction with the embedded user card and establishing an encrypted channel; implementing the management and downloading of the embedded user card data, interacting with the embedded user card, and downloading the user contract data to On the embedded user card, remote configuration of user data is realized to meet the needs of users to configure and manage embedded user cards safely and flexibly.
- the user card may include, for example, an embedded universal integrated circuit card (eUICC, embedded Universal Integrated Circuit Card), etc.
- the user subscription data may include, for example, but is not limited to: user authentication related subscription data, access management subscription data, session management subscription data, etc.
- user authentication-related subscription data may include, for example, but is not limited to: International Mobile Subscriber Identity (IMSI, International Mobile Subscriber Identity), mobile subscriber number, etc.
- IMSI International Mobile Subscriber Identity
- the mobile subscriber number may be, for example, MSISDN (Mobile Subscriber International ISDN number, Mobile Subscriber International Integrated Services Digital Network (ISDN) number).
- Access management subscription data includes but is not limited to: UE (User Equipment, user equipment) level uplink and downlink bandwidth, prohibited area data, business area restriction data, RFSP (RAT/Frequency Selection Priority, wireless access type/frequency selection priority) ; RAT: Radio Access Technology, wireless access technology), authentication methods, etc.
- session management contract data include but are not limited to: S-NSSAI (Single Network Slice Selection Assistance Information, single network slice selection assistance information), DNN (Data Network Name, data network name), quality of service, whether to default to DNN, etc.
- the sinking access network element 130 refers to the network elements with some functions sinking from the core network to the edge access network.
- the sinking access network element 130 may include, for example, a UDM network element, a UPF network element, an AMF network element, an SMF network element, etc.
- sinking UDM network elements can be network elements formed by sinking some functions of the UDM network elements of the core network to the edge access network.
- the downlink access network element 130 can interact with the core network element 110 for data exchange such as user authentication.
- the sinking access network element 130 can be equipped with an embedded user card.
- the embedded user card can store card files, data and applications, and can remotely download user contract data.
- User subscription data may include, for example, but is not limited to: user identification information, business information, etc.
- the embedded user card may include, for example, an embedded UICC or the like.
- the interface between the core network element 110 and the signaling security management gateway 120 may include, for example, N4/N8/N10/N12/N14, etc.
- the interface between the signaling security management gateway 120 and the downlink access network element 130 may, for example, Including N4/N8/N10/N12/N14, etc.
- the signaling security management gateway 120 can be configured to receive the request of the sinking access network element to access the core network element, and authenticate the sinking access network element; and authenticate Establish an encrypted channel through the sinking access network element; receive the user data synchronization request sent by the sinking access network element, and send the user data synchronization request to the corresponding core network element; receive the encrypted user data sent by the core network element , sending the encrypted user data to the sinking access network element through the encrypted channel; the core network element 110 can be configured to respond to the user data synchronization request and send the encrypted user data to the signaling security management gateway; and the sinking access network Element 130 can be configured to send a request to access the core network element to the signaling security management gateway, establish an encrypted channel with the signaling security management gateway, send a user data synchronization request to the signaling security management gateway, and receive signaling through the encrypted channel. Secure management of encrypted user data sent by the gateway.
- the signaling security management gateway 120 can be configured to receive a request for downloading user subscription data sent by the sinking access network element.
- the request may include a request from the sinking access network element.
- the identification and the identification and certificate of the user card embedded in the sinking access network element; authentication is performed based on the identification and certificate of the user card.
- the user subscription data loaded in the sinking access network element is queried, and the user's contract data loaded in the sinking access network element is If the user subscription data is not loaded into the user element or the loaded user subscription data has expired, notify the downlink access network element to download new user subscription data, establish the identification of the downlink access network element and embed the downlink access network element's Binding information of user card identification.
- Figure 2 shows a schematic diagram of a secure data transmission method according to some embodiments of the present disclosure.
- the secure data transmission method of this embodiment may include the following steps.
- the signaling security management gateway issues user cards for each downlink access network element, and each user card includes the certificate of the issued user card.
- the signaling security management gateway receives a request to download user subscription data sent by the sinking access network element.
- the request includes the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access network element. Certificate.
- the signaling security management gateway performs authentication based on the identity and certificate of the user card. After passing the authentication, it queries the user subscription data loaded in the downlink access network element. If the downlink access network element does not load the user subscription data or loads the user subscription data, When the user subscription data has expired, the downlink access network element is notified to download new user subscription data, and the binding information between the downlink access network element's identifier and the identifier of the user card embedded in the downlink access network element is established. When the user subscription data loaded by the downlink access network element has not expired, the downlink access network element is notified that it does not need to download or stops downloading the user subscription data.
- authentication based on the identity and certificate of the user card includes: if the issuer of the certificate of the user card is the signaling security management gateway, and the certificate of the user card is within the validity period, and the certificate of the user card matches the identity of the user card , the authentication passes, otherwise, the authentication fails.
- step 230 the signaling security management gateway notifies the underlying access network element to download new user subscription data.
- step 240 the downlink access network element downloads the new user subscription data through the encrypted channel and activates it, and the old user subscription data can be deleted.
- step 250 the signaling security management gateway receives the new user subscription data activation success message sent by the sinking access network element.
- the signaling security management gateway receives a request from the sinking access network element to access the core network element, which carries the identifier of the sinking access network element, the identifier of the user card embedded in the sinking access network element, and the user's contract. Certificate information in the data.
- the signaling security management gateway authenticates the downlink access network element, which may include, for example:
- the sinking access network element in the access request When the binding relationship between the identifier of the sinking access network element in the access request and the identifier of the user card is correct and the timeliness and legality of the certificate information in the user subscription data meet the requirements, it is determined that the sinking access network is Meta-certification passed.
- steps 290 to 2150 are allowed to be executed.
- step 280 the signaling security management gateway sends the authentication result to the downlink access network element.
- the authentication result includes, for example, authentication passed or authentication failed.
- step 290 the signaling security management gateway establishes an encrypted channel with the authenticated sinking access network element.
- the establishment method of the encrypted channel can refer to the existing technology.
- the encrypted channel includes, for example, encryption key information negotiated by the communicating parties. After the encrypted channel is established, the communicating parties can use the negotiated encryption key to transmit information. Since the third party does not know the encryption key, even if the encrypted information is intercepted, there is no way to know the transmitted information.
- the signaling security management gateway receives a user data synchronization request sent by the downlink access network element.
- the user data synchronization request may include the identification of the downlink access network element and data network information.
- the data network information includes, but is not limited to, data network name (Data Network name, DNN).
- step 2110 the signaling security management gateway sends the user data synchronization request to the corresponding core network element.
- the signaling security management gateway forwards user data synchronization requests from UDM network elements to core network UDM network elements.
- the core network elements are hidden from the sinking access network elements.
- the sinking access network elements send the request to the signaling security management gateway. There is no need to send the core network element.
- the signaling security management gateway can send the request to Core network elements.
- the core network element searches for the user data corresponding to the identification of the sinking access network element and the data network information and encrypts the user data to obtain the encrypted user data.
- the core network element can encrypt the user data according to the key negotiated in advance with the downlink access network element to obtain encrypted user data.
- the user data is, for example, user card and authentication data, such as IMSI, KI (Key identifier), etc.
- step 2130 the signaling security management gateway receives the encrypted user data sent by the core network element.
- step 2140 the signaling security management gateway sends the encrypted user data to the downlink access network element through the encrypted channel.
- the sinking access network element receives the encrypted user data, decrypts it to obtain the user data, and uses the user data according to business needs to ensure service, for example, to ensure that the service is not interrupted.
- the downlink access network element can decrypt the encrypted user data to obtain the user data according to the key negotiated in advance with the core network element.
- the above embodiment provides access authentication and management for downlink access network elements through the signaling security management gateway, and transmits data from core network elements to downlink access network elements that have passed the authentication through encrypted channels, thereby improving the core
- the security of data transmitted between network elements and sinking access network elements reduces the risk of information leakage.
- Figure 3 shows a schematic diagram of a secure data transmission method according to other embodiments of the present disclosure.
- the secure data transmission method of this embodiment may include the following steps.
- the downlink UDM network element has an embedded UICC, and the UICC is issued by the signaling security management gateway.
- the sinking UDM network element requests access to the 5G SA network on time or on demand, actively connects to the signaling security management gateway through the embedded UICC, and requests to download the user subscription data (set as Profile).
- the request carries the embedded UICC EID (Electronic Identity, electronic identity identification) and the device ID of the UDM network element.
- the network element access management gateway performs security authentication based on the EID and the certificate information in the UICC. After passing the authentication, it queries whether the sinking UDM network element corresponding to the device ID has loaded the Profile; if it has not been loaded or the Profile has expired, notify the sinking UDM network element to prepare to download the user subscription data, and bind the EID and device ID; if the Profile has been loaded and the Profile has not expired, notify the sinking UDM network element to stop downloading.
- security authentication based on the EID and the certificate information in the UICC includes: If the issuer of the certificate in the UICC is the signaling security management gateway, and the certificate in the UICC is within the validity period, and the certificate in the UICC matches the EID, the authentication passes, otherwise , the authentication fails.
- step 330 the signaling security management gateway sends a request to the sinking UDM network element, requesting to establish an encrypted channel, download and enable the Profile.
- step 340 an encrypted channel is established between the sinking UDM network element and the signaling security management gateway, and a new Profile is downloaded through the encrypted channel. If an expired Profile has been loaded before, the old Profile is deleted and the new Profile is enabled.
- step 350 the sinking UDM network element returns a profile activation success message to the signaling security management gateway.
- step 360 the sinking UDM network element initiates a request to access the core network UDM network element in the 5G SA network to the signaling security management gateway, carrying the EID of the embedded UICC, the device ID and the certificate information in the Profile.
- the signaling security management gateway checks whether the binding relationship between the EID and the device ID is correct based on the request information of the sinking UDM network element. If it is incorrect or does not exist, the sinking UDM network element is not allowed to access; if it is correct, , then the validity and legality of the certificate in the Profile are verified. After the certification is passed, access to the sinking UDM network element is allowed.
- step 380 after the authentication is passed, the signaling security management gateway sends an authentication pass notification to the downlink UDM network element.
- the sinking UDM network element uses the embedded UICC-related security information, such as EID, to establish an encrypted channel with the signaling security management gateway.
- EID embedded UICC-related security information
- step 3100 the sinking UDM network element sends a user data synchronization request to the signaling security management gateway, carrying information such as DNN and device ID.
- the signaling security management gateway hides the core network UDM topology information and forwards the user data synchronization request to the corresponding core network UDM network element to request synchronization of user data.
- the UDM network element of the core network finds relevant user card data, authentication data and other user data, such as IMSI, KI and other data, based on the device ID and DNN information, and then The data is encrypted, and the encryption key is pre-negotiated or pre-set by the core network UDM network element and the sinking UDM network element.
- step 3130 the core network UDM network element transmits the encrypted user data to the signaling security management gateway.
- step 3140 the signaling security management gateway transmits the encrypted user data to the sinking UDM network element through the encrypted channel.
- the sinking UDM network element decrypts the encrypted user data to obtain user data.
- user data such as user card data and authentication data are used as needed to ensure 5G services. No interruption.
- the above embodiment does not change the existing 5G architecture and business implementation process, and uses embedded UICC remote configuration technology and security encryption technology to perform security authentication and security authentication for untrusted access network element devices such as 5G sinking UDM to access the 5G core network. management, effectively reducing the security interaction risk of sinking network elements to the 5G core network.
- data encryption and channel encryption are performed on the requested sensitive data (such as user card data and authentication data) in the UDM of the 5G core network, effectively reducing Information leakage security risks, thereby improving 5G network security and data security.
- Figure 4 shows a schematic structural diagram of a signaling security management gateway according to some embodiments of the present disclosure.
- the signaling security management gateway 120 of this embodiment may include:
- the authentication module 410 is configured to receive a request from a downlink access network element to access a core network element, and authenticate the downlink access network element;
- the channel establishment module 420 is configured to establish an encrypted channel with the authenticated sinking access network element
- the information agent module 430 is configured to receive the user data synchronization request sent by the sinking access network element, and send the user data synchronization request to the corresponding core network network element; receive the encrypted user data sent by the core network network element, and send the encrypted user data to the corresponding core network element.
- the data is sent to the downlink access network element through an encrypted channel.
- the signaling security management gateway 120 also includes: a download management module 440, configured to receive a request to download user subscription data sent by the sinking access network element, where the request includes the identification of the sinking access network element. and the identity and certificate of the user card embedded in the sinking access network element; authentication is performed based on the user card's identity and certificate. After the authentication is passed, the user contract data loaded in the sinking access network element is queried. When the user subscription data is loaded or the loaded user subscription data has expired, the downlink access network element is notified to download new user subscription data, and the identification of the downlink access network element is established and the user card embedded in the downlink access network element is The binding information of the identifier.
- a download management module 440 configured to receive a request to download user subscription data sent by the sinking access network element, where the request includes the identification of the sinking access network element. and the identity and certificate of the user card embedded in the sinking access network element; authentication is performed based on the user card's identity and certificate. After the authentication is passed
- the authentication module 410 is also configured to:
- Figure 5 shows a schematic structural diagram of a signaling security management gateway according to other embodiments of the present disclosure.
- the signaling security management gateway 120 of this embodiment includes: a memory 510 and a processor 520 coupled to the memory 510.
- the processor 520 is configured to perform any of the foregoing based on instructions stored in the memory 510. Secure data transmission methods in some embodiments.
- the memory 510 may include, for example, system memory, fixed non-volatile storage media, etc.
- System memory stores, for example, operating systems, applications, boot loaders, and other programs.
- the processor 520 can be a general-purpose processor, a digital signal processor (Digital Signal Processor, DSP), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or It can be implemented by other discrete hardware components such as programmable logic devices, discrete gates or transistors.
- DSP Digital Signal Processor
- ASIC Application Specific Integrated Circuit
- FPGA Field Programmable Gate Array
- FPGA Field Programmable Gate Array
- the signaling security management gateway 120 may also include an input and output interface 530, a network interface 540, a storage interface 550, and so on. These interfaces 530, 540, 550, the memory 510 and the processor 520 may be connected through a bus 560, for example.
- the input and output interface 530 provides a connection interface for input and output devices such as a monitor, mouse, keyboard, and touch screen.
- Network interface 540 provides a connection interface for various networked devices.
- the storage interface 550 provides a connection interface for external storage devices such as SD cards and USB disks.
- Bus 560 may use any of a variety of bus structures. For example, bus structures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, and Peripheral Component Interconnect (PCI) bus.
- ISA Industry Standard Architecture
- MCA Micro Channel Architecture
- PCI Peripheral Component Interconnect
- embodiments of the present disclosure may be provided as methods, systems, or computer program products. Accordingly, the present disclosure may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment that combines software and hardware aspects. Furthermore, the present disclosure may take the form of a computer program product embodied on one or more non-transitory computer-readable storage media (including, but not limited to, disk memory, CD-ROM, optical storage, etc.) embodying computer program code therein. .
- These computer program instructions may also be stored in a computer-readable memory that causes a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including the instruction means, the instructions
- the device implements the functions specified in a process or processes of the flowchart and/or a block or blocks of the block diagram.
- These computer program instructions may also be loaded onto a computer or other programmable data processing device, causing a series of operating steps to be performed on the computer or other programmable device to produce computer-implemented processing, thereby executing on the computer or other programmable device.
- Instructions provide steps for implementing the functions specified in a process or processes of a flowchart diagram and/or a block or blocks of a block diagram.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (14)
- 一种数据传输方法,其中,包括:信令安全管理网关接收下沉接入网元访问核心网网元的请求,对所述下沉接入网元进行认证;所述信令安全管理网关在其与认证通过的所述下沉接入网元之间建立加密通道;所述信令安全管理网关接收所述下沉接入网元发送的用户数据同步请求,并将所述用户数据同步请求发送到所述核心网网元;所述信令安全管理网关接收所述核心网网元发送的加密用户数据,并将所述加密用户数据通过所述加密通道发送给所述下沉接入网元。
- 根据权利要求1所述的方法,其中,信令安全管理网关接收下沉接入网元访问核心网网元的请求,对所述下沉接入网元进行认证包括:信令安全管理网关接收下沉接入网元访问核心网网元的请求,所述访问核心网网元的请求携带所述下沉接入网元的标识、嵌入所述下沉接入网元的用户卡的标识以及用户签约数据中的证书信息;所述信令安全管理网关在所述访问核心网网元的请求中的所述下沉接入网元的标识与所述用户卡的标识的绑定关系不正确或不存在的情况下,判定所述下沉接入网元认证不通过;或者,所述信令安全管理网关在所述访问核心网网元的请求中的用户签约数据中的证书信息的时效性和合法性不满足要求的情况下,判定所述下沉接入网元认证不通过;或者,所述信令安全管理网关在所述访问核心网网元的请求中的所述下沉接入网元的标识与所述用户卡的标识的绑定关系正确且用户签约数据中的证书信息的时效性和合法性满足要求的情况下,判定所述下沉接入网元认证通过。
- 根据权利要求1所述的方法,其中,所述用户数据同步请求包括所述下沉接入网元的标识和数据网络信息;所述信令安全管理网关接收所述下沉接入网元发送的用户数据同步 请求,并将所述用户数据同步请求发送到所述核心网网元,包括:所述信令安全管理网关接收所述下沉接入网元发送的用户数据同步请求,并将所述用户数据同步请求发送到所述核心网网元,以使所述核心网网元根据所述下沉接入网元的标识和数据网络信息获得相应的加密用户数据。
- 根据权利要求1所述的方法,其中,还包括:所述信令安全管理网关接收所述下沉接入网元发送的下载用户签约数据的请求,所述下载用户签约数据的请求包括所述下沉接入网元的标识和嵌入所述下沉接入网元的用户卡的标识和证书;所述信令安全管理网关根据所述用户卡的标识和证书进行认证,认证通过后,查询所述下沉接入网元加载的用户签约数据,在所述下沉接入网元未加载用户签约数据或者加载的用户签约数据已过期的情况下,通知所述下沉接入网元下载新的用户签约数据,并建立所述下沉接入网元的标识与所述用户卡的标识的绑定信息。
- 根据权利要求4所述的方法,其中,所述信令安全管理网关通知所述下沉接入网元下载新的用户签约数据包括:所述信令安全管理网关通知所述下沉接入网元下载新的用户签约数据,以使所述下沉接入网元通过加密通道下载新的用户签约数据并启用;所述信令安全管理网关接收所述下沉接入网元发送的新的用户签约数据启用成功的消息。
- 根据权利要求1所述的方法,其中,所述信令安全管理网关为各个下沉接入网元签发用户卡,每个用户卡内包括所述用户卡的证书。
- 根据权利要求2-6任一项所述的方法,其中,所述核心网网元包括UDM网元、UPF网元、AMF网元、SMF网 元;所述下沉接入网元包括UDM网元、UPF网元、AMF网元、SMF网元;所述用户卡包括嵌入式UICC。
- 一种信令安全管理网关,其中,包括:认证模块,被配置为接收下沉接入网元访问核心网网元的请求,对所述下沉接入网元进行认证;通道建立模块,被配置为在与所述认证模块认证通过的所述下沉接入网元之间建立加密通道;信息代理模块,被配置为接收所述下沉接入网元发送的用户数据同步请求,并将所述用户数据同步请求发送到所述核心网网元;接收所述核心网网元发送的加密用户数据,并将所述加密用户数据通过所述加密通道发送给所述下沉接入网元。
- 根据权利要求8所述的信令安全管理网关,其中,还包括:下载管理模块,被配置为接收所述下沉接入网元发送的下载用户签约数据的请求,所述下载用户签约数据的请求包括所述下沉接入网元的标识和嵌入所述下沉接入网元的用户卡的标识和证书;根据所述用户卡的标识和证书进行认证,认证通过后,查询所述下沉接入网元加载的用户签约数据,在所述下沉接入网元未加载用户签约数据或者加载的用户签约数据已过期的情况下,通知所述下沉接入网元下载新的用户签约数据,并建立所述下沉接入网元的标识与所述用户卡的标识的绑定信息。
- 根据权利要求8所述的信令安全管理网关,其中,所述认证模块,被配置为:接收下沉接入网元访问核心网网元的请求,所述访问核心网网元的请求携带所述下沉接入网元的标识、嵌入所述下沉接入网元的用户卡的标识以及用户签约数据中的证书信息;在所述访问核心网网元的请求中的所述下沉接入网元的标识与所述 用户卡的标识的绑定关系不正确或不存在的情况下,判定所述下沉接入网元认证不通过;或者,在所述访问核心网网元的请求中的用户签约数据中的证书信息的时效性和合法性不满足要求的情况下,判定所述下沉接入网元认证不通过;或者,在所述访问核心网网元的请求中的所述下沉接入网元的标识与所述用户卡的标识的绑定关系正确且用户签约数据中的证书信息的时效性和合法性满足要求的情况下,判定所述下沉接入网元认证通过。
- 一种信令安全管理网关,包括:存储器;以及耦接至所述存储器的处理器,所述处理器被配置为基于存储在所述存储器中的指令,执行权利要求1-7中任一项所述的数据传输方法。
- 一种数据传输系统,包括:权利要求8-11任一项所述的信令安全管理网关,核心网网元,被配置为响应用户数据同步请求,发送加密用户数据给所述信令安全管理网关,以及下沉接入网元,被配置为向所述信令安全管理网关发送访问核心网网元的请求,与所述信令安全管理网关建立加密通道,向所述信令安全管理网关发送用户数据同步请求,通过加密通道接收所述信令安全管理网关发送的加密用户数据。
- 根据权利要求12所述的数据传输系统,其中,所述核心网网元包括UDM网元、UPF网元、AMF网元、SMF网元;所述下沉接入网元包括UDM网元、UPF网元、AMF网元、SMF网元。
- 一种非瞬时性计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时实现权利要求1-7中任一项所述的数据传输方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202210550259.8 | 2022-05-20 | ||
| CN202210550259.8A CN117135625B (zh) | 2022-05-20 | 2022-05-20 | 数据传输方法和系统及信令安全管理网关 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023221502A1 true WO2023221502A1 (zh) | 2023-11-23 |
Family
ID=88834496
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/140915 Ceased WO2023221502A1 (zh) | 2022-05-20 | 2022-12-22 | 数据传输方法和系统及信令安全管理网关 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN117135625B (zh) |
| WO (1) | WO2023221502A1 (zh) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111147426A (zh) * | 2018-11-05 | 2020-05-12 | 中兴通讯股份有限公司 | 一种承载侧网络系统、移固共存融合系统及其部署方法 |
| CN112422679A (zh) * | 2020-11-17 | 2021-02-26 | 中国联合网络通信集团有限公司 | 一种通信方法及装置 |
| CN113068175A (zh) * | 2019-12-12 | 2021-07-02 | 中国电信股份有限公司 | 用户数据分流的方法、下沉用户面功能网元和系统 |
| CN113747515A (zh) * | 2020-05-27 | 2021-12-03 | 华为技术有限公司 | 一种通信方法及装置 |
| WO2021244509A1 (zh) * | 2020-06-03 | 2021-12-09 | 中兴通讯股份有限公司 | 数据传输方法和系统、电子设备及计算机可读存储介质 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2009155812A1 (zh) * | 2008-06-23 | 2009-12-30 | 华为技术有限公司 | 终端接入方法、接入管理方法网络设备以及通信系统 |
| KR20160091625A (ko) * | 2015-01-26 | 2016-08-03 | 한국전자통신연구원 | 계층적 네트워크 제어 시스템 및 방법 |
| CN106937351B (zh) * | 2015-12-29 | 2020-04-17 | 中国移动通信集团公司 | 一种会话实现方法及核心网元 |
| CN112512045B (zh) * | 2019-08-27 | 2023-04-18 | 华为技术有限公司 | 一种通信系统、方法及装置 |
-
2022
- 2022-05-20 CN CN202210550259.8A patent/CN117135625B/zh active Active
- 2022-12-22 WO PCT/CN2022/140915 patent/WO2023221502A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111147426A (zh) * | 2018-11-05 | 2020-05-12 | 中兴通讯股份有限公司 | 一种承载侧网络系统、移固共存融合系统及其部署方法 |
| CN113068175A (zh) * | 2019-12-12 | 2021-07-02 | 中国电信股份有限公司 | 用户数据分流的方法、下沉用户面功能网元和系统 |
| CN113747515A (zh) * | 2020-05-27 | 2021-12-03 | 华为技术有限公司 | 一种通信方法及装置 |
| WO2021244509A1 (zh) * | 2020-06-03 | 2021-12-09 | 中兴通讯股份有限公司 | 数据传输方法和系统、电子设备及计算机可读存储介质 |
| CN112422679A (zh) * | 2020-11-17 | 2021-02-26 | 中国联合网络通信集团有限公司 | 一种通信方法及装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN117135625A (zh) | 2023-11-28 |
| CN117135625B (zh) | 2026-04-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12041452B2 (en) | Non-3GPP device access to core network | |
| US10554420B2 (en) | Wireless connections to a wireless access point | |
| CN109756447B (zh) | 一种安全认证方法及相关设备 | |
| CN109905350B (zh) | 一种数据传输方法及系统 | |
| US8320880B2 (en) | Apparatus and methods for secure architectures in wireless networks | |
| WO2019041802A1 (zh) | 基于服务化架构的发现方法及装置 | |
| CN113556227B (zh) | 网络连接管理方法、装置、计算机可读介质及电子设备 | |
| US12267683B2 (en) | Non-3GPP device access to core network | |
| CN110519753B (zh) | 访问方法、装置、终端和可读存储介质 | |
| JP2017050875A (ja) | 複数のアクセス制御クライアントをサポートするモバイル装置、及び対応する方法 | |
| JP2016167835A (ja) | アクセス制御クライアントの記憶及び演算に関する方法及び装置 | |
| CN106230838A (zh) | 一种第三方应用访问资源的方法和装置 | |
| CN108809907A (zh) | 一种证书请求消息发送方法、接收方法和装置 | |
| CN114223233A (zh) | 用于网络切片管理的数据安全性 | |
| US20250203372A1 (en) | Method For Authenticating To A Remote Server Using Service-Specific Credentials Stored In The eUICC | |
| WO2023221502A1 (zh) | 数据传输方法和系统及信令安全管理网关 | |
| US11171786B1 (en) | Chained trusted platform modules (TPMs) as a secure bus for pre-placement of device capabilities | |
| WO2023240587A1 (zh) | 一种设备权限配置方法及装置、终端设备 | |
| JP2023509806A (ja) | モバイルネットワークアクセスシステム、方法、記憶媒体及び電子機器 | |
| US20260074893A1 (en) | Trusted third party assisted public key distribution | |
| US20260129435A1 (en) | Shared Secret Key Architecture and Distribution | |
| CN120358493A (zh) | 通信方法和通信装置 | |
| CN118900413A (zh) | 一种wifi组网方法、鸿蒙化设备、智能终端和介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22942522 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22942522 Country of ref document: EP Kind code of ref document: A1 |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 09/07/2025) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22942522 Country of ref document: EP Kind code of ref document: A1 |