WO2025124347A1 - 通信方法及装置、计算机可读存储介质 - Google Patents
通信方法及装置、计算机可读存储介质 Download PDFInfo
- Publication number
- WO2025124347A1 WO2025124347A1 PCT/CN2024/137854 CN2024137854W WO2025124347A1 WO 2025124347 A1 WO2025124347 A1 WO 2025124347A1 CN 2024137854 W CN2024137854 W CN 2024137854W WO 2025124347 A1 WO2025124347 A1 WO 2025124347A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- network element
- information
- service
- terminal device
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
Definitions
- the present application relates to the field of communication technology, and in particular to a communication method and device, and a computer-readable storage medium.
- AMF Access and Mobility Management Function
- RAN radio access network
- the technical problem that this application can solve is how to ensure business security under the service-oriented RAN architecture.
- an embodiment of the present application provides a communication method, including: receiving request information, the request information is used to request a first service; sending key information, the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
- the sending key information includes: sending first information to the network element node, where the first information includes the first key.
- the method before sending the first information to the network element node, the method further includes: selecting the network element node from a plurality of candidate network element nodes, wherein the plurality of candidate network element nodes are all associated with the first service.
- the sending of key information includes: sending second information to the terminal device, the second information includes input parameters, and the input parameters are used to generate the first key.
- the input parameter includes: an identifier of the network element node and/or an address of the network element node.
- the request information is received from the server or the terminal device.
- the network element node is selected from: a positioning management function node and a perception function node.
- an embodiment of the present application also provides a communication method, including: receiving key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service, and transmitting it to the network element node via a wireless access network.
- the receiving key information includes: receiving second information, where the second information includes input parameters, and the input parameters are used to generate the first key.
- the input parameter includes: an identifier of the network element node and/or a network interconnection protocol address of the network element node.
- the method further includes: sending request information, where the request information is used to request the first service.
- an embodiment of the present application also provides a communication method, including: receiving key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service, and transmitting it to the terminal device via a wireless access network.
- receiving key information includes: receiving first information, where the first information includes the first key.
- the network element node is selected from: a positioning management function node and a perception function node.
- an embodiment of the present application also provides a communication device, including: a receiving module, used to receive request information, wherein the request information is used to request a first service; a sending module, used to send key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
- an embodiment of the present application also provides a communication device, including: a receiving module, used to receive key information, the key information is used to indicate a first key, the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmission module, used to process the data of the first service using the first key, and transmit it to the network element node via a wireless access network.
- an embodiment of the present application also provides a communication device, including: a receiving module, used to receive key information, the key information is used to indicate a first key, the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmission module, used to process the data of the first service using the first key, and transmit it to the terminal device via a wireless access network.
- an embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored, and when the computer program is run by a processor, the steps of the above method are executed.
- an embodiment of the present application further provides a communication device, comprising a memory and a processor, wherein the memory stores a computer program that can be executed on the processor, and the processor executes the steps of the above method when running the computer program.
- an embodiment of the present application provides a communication method, including: receiving request information, the request information is used to request a first service; sending key information, the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
- the first service involved in this implementation is a service performed under the service-based RAN architecture. Since AMF does not perform the data transit function at this time, key information is sent to both parties of the communication (for example, the terminal device and the network element node) to ensure that both parties of the communication can correctly encrypt and decrypt the transmitted data. Thus, a suitable encryption mechanism is provided for the service-based RAN architecture, and security can still be guaranteed when data transmission between the core network element and the terminal device does not pass through AMF.
- an embodiment of the present application also provides a communication method, including: receiving key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service, and transmitting it to the network element node via a wireless access network.
- this implementation scheme indicates the first key configured on the AMF side to the terminal device, so that the terminal device can correctly encrypt and decrypt the transmitted data during the communication between the RAN and the network element node.
- a suitable encryption mechanism is provided for the service-oriented RAN architecture, and security can still be guaranteed when the data transmission between the core network element and the terminal device does not pass through the AMF.
- an embodiment of the present application also provides a communication method, including: receiving key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service, and transmitting it to the terminal device via a wireless access network.
- this implementation scheme indicates the first key configured on the AMF side to the network element node, so that the network element node can correctly encrypt and decrypt the transmitted data during communication with the terminal device through the RAN.
- a suitable encryption mechanism is provided for the service-oriented RAN architecture, and security can still be guaranteed when data transmission between the core network element and the terminal device does not pass through the AMF.
- FIG3 is a schematic diagram of the architecture of the third service-oriented RAN of the present application.
- the existing encryption function implemented by AMF is no longer applicable, and the service security between terminal devices and core network elements cannot be guaranteed.
- the interaction between existing terminal devices and network elements of the core network is forwarded through AMF.
- AMF the positioning management server
- the data of the positioning service (for example, including positioning requests and positioning reports) needs to be encrypted. Since the interaction between the terminal device and LMF must pass through AMF, it can be encrypted through AMF.
- an embodiment of the present application provides a communication method, including: receiving request information, the request information is used to request a first service; sending key information, the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
- the first service involved in this implementation is a service carried out under the service-oriented RAN architecture. Since the AMF does not play a data transfer function at this time, the key information is sent to both parties of the communication (for example, the terminal device and the network element node) to ensure that the communicating parties can correctly encrypt and decrypt the transmitted data. In this way, a suitable encryption mechanism is provided for the service-oriented RAN architecture, and security can still be guaranteed when the data transmission between the core network element and the terminal device does not pass through the AMF.
- Figure 1 shows an exemplary network architecture under the full service of the N2 interface, which can realize direct service calls between the access network network function (RAN Network Function, RAN NF) and the core network network function (Core Network NF, CN NF).
- the terminal device (identified by UE in the figure) can access the bus (i.e. access the core network) through AMF.
- the terminal device can also directly access the core network through RAN, thereby breaking through the existing AMF only forwarding mechanism.
- RAN includes the control plane RAN (identified by RAN-C in the figure) and the user plane RAN (identified by RAN-U in the figure).
- the application function Application Function, AF
- network storage function Network Repository Function, NRF
- policy control function Policy Control Function, PCF
- unified data management function Unified Data Management, UDM
- UPF user plane function
- DN data network
- SMF session management function
- FIG2 exemplarily shows a service-oriented network architecture for traditional RAN functions, splitting functions (also known as RAN capabilities) into services, and further realizing the integrated design of RAN and CN related functional services and processes, so as to better meet the design principles of high cohesion and loose coupling and simplify network design.
- a terminal device (indicated by UE in the figure) can access the bus through AMF. Further, the terminal device can also access RAN through a radio unit (Radio Unit, RU), and directly access the core network through RAN, wherein RU is responsible for processing digital front end (DFE) and some physical (PHY) layer functions.
- DFE digital front end
- PHY physical
- RAN is split into RAN control plane services (based on control plane services (Control Plane Service, CPS)) and RAN user plane services (based on user plane services (User Plane Service, UPS)).
- CPS Control Plane Service
- UPS User Plane Service
- a core network user plane service (based on UPS) is set up to communicate with RAN and directly access the bus.
- other core network elements such as AF, NRF, PCF and UDM directly access the bus.
- SMF can also directly access the bus.
- the DN accesses the bus through the core network user plane service.
- Figure 3 shows an exemplary service-oriented network architecture for the newly added DOICT capability, which defines artificial intelligence (AI), computing, data and other functions as services.
- DOICT simplifies field network networking through communication technology (CT); deeply collaborates with industrial protocols through operational technology (OT) to achieve high reliability; realizes intelligence through data technology (DT) technology, and closes the loop to ensure low latency experience; and enables more industrial applications through information technology (IT) technology, reduces construction costs, and realizes flexible networking.
- CT communication technology
- OT operational technology
- IT information technology
- the terminal device accesses the RAN through the RU and directly accesses the core network through the RAN.
- the RAN is split into RAN control plane services (based on the cyber physical system (CPS)), RAN user plane services (based on the user plane physical system (UPS)), and multi-dimensional capability services (including AI services, computing services and data services).
- the AMF accesses the bus and is decoupled from the terminal device.
- other core network elements such as Network Exposure Function (NEF), AF, NRF, PCF and UDM are directly connected to the bus.
- SMF can also be directly connected to the bus.
- DN is connected to the bus through UPF, and UPF communicates with RAN.
- NEF Network Exposure Function
- the network element node may be a core network element that performs a function related to the first service.
- the first service may be a service implemented based on a service-oriented RAN architecture.
- the first service may be a positioning service
- the corresponding network element node may be a positioning management function (LMF) node (SMF for short).
- LMF positioning management function
- the first service may be a synaesthesia (also known as sensing) service
- the corresponding network element node may be a sensing function (Sensing Function, SF) node (SF for short).
- AMF no longer forwards data between the terminal device and the network element node, it still plays a management function.
- FIG4 is a signaling interaction diagram of a communication method according to an embodiment of the present application.
- This implementation scheme can be applied to communication scenarios under the service-oriented RAN architecture.
- the terminal device directly interacts with the network element node via the RAN to transmit the data of the first service without transiting through the AMF.
- the steps implemented by the terminal device can be executed by a chip with communication functions in the terminal device, or by a baseband chip in the terminal device;
- the steps implemented by the AMF can be executed by a chip with communication functions in the AMF, or by a baseband chip in the AMF;
- the steps implemented by the network element node can be executed by a chip with communication functions in the network element node, or by a baseband chip in the network element node.
- the communication method described in this embodiment may include the following steps:
- Step S101 The terminal device sends a request message to the AMF.
- the AMF receives the request message, wherein the request message is used to request a first service.
- the first service may be a positioning service
- the request information may be positioning request information
- the sending of the request information may be actively triggered by the terminal device.
- the server may trigger the terminal device to send a request message to the AMF, wherein the server may be, for example, an external server for implementing the first service.
- the server may send the request information directly to the AMF.
- the requested first service may be an uplink service or a downlink service.
- the request information may include relevant information for implementing the first service, such as an identifier of the terminal device (used to uniquely identify the terminal device) and quality of service (Quality of Service, referred to as QoS).
- relevant information for implementing the first service such as an identifier of the terminal device (used to uniquely identify the terminal device) and quality of service (Quality of Service, referred to as QoS).
- the positioning request information sent in step S101 may include the terminal device identifier and the positioning QoS (such as positioning accuracy requirements, latency requirements, etc.).
- the AMF may execute step S102 to send key information to the terminal device and the network element node, respectively.
- the network element node and the terminal device each receive the key information.
- the key information is used to indicate a first key
- the first key is used to encrypt data of the first service transmitted between the network element node and the terminal device.
- step S102 may specifically include step S1021 and step S1022.
- step S1021 the AMF selects a network element node from multiple candidate network element nodes, and the multiple candidate network element nodes are all associated with the first service.
- the core network may deploy multiple network element nodes for the first service, and these network element nodes are used as candidate network element nodes.
- the AMF selects one from the multiple candidate network element nodes as the network element node that communicates with the terminal device.
- the AMF can select a nearby one from multiple candidate LMFs and determine it as the LMF that communicates with the terminal device to realize the positioning service.
- the request information may be used to request a perception service, and the AMF may select one from a plurality of candidate SFs as the SF that communicates with the terminal device to implement the perception service.
- the AMF may continue to execute step S1022 to send the first information to the network element node.
- the network element node receives the first information.
- the first information includes the first key.
- AMF directly provides the generated first key to the network element node.
- the first keys allocated to different candidate network element nodes may not be repeated.
- step S102 may specifically include step S1023, where the AMF sends the second information to the terminal device.
- the terminal device receives the second information.
- the second information includes an input parameter, and the input parameter is used to generate the first key.
- part of the input parameters can be pre-configured by the network or pre-defined by the protocol or determined by the terminal device itself, and the remaining part (for example, parameters related to the network element node) can be indicated to the terminal device by the AMF.
- the input parameters required for deriving the LMF key may include:
- Uplink/Downlink NAS COUNT which is the sequence number when the terminal device and AMF transmit signaling
- -L0 length of uplink/downlink NAS COUNT, for example 0x00 0x04;
- -L1 length of network function distinguisher, for example 0x000x01.
- the input parameter carried in the second information may include a P1 parameter. Since the P1 parameter is used to distinguish different network functions, it can also be called an identifier of a network element node (in this example, it can be understood as a type identifier) to distinguish network element nodes with different functions. For example, the P1 value corresponding to LMF is 0x01, and the P1 value corresponding to SF is 0x02.
- the AMF indicates in the second information the identifier (including type identifier and/or identity identifier) and/or address of the network element node associated with the first service, so that the terminal device generates a first key for interacting with the network element node.
- the terminal device calculates KAMF according to the K value configured in the Universal Subscriber Identity Module (USIM) and the dynamic parameters provided by the network. Further, the first key is calculated in combination with the input parameters (including the content carried in the second information (such as P1 and/or P2) and the content determined by the terminal device itself).
- USIM Universal Subscriber Identity Module
- the action of sending the second information to the terminal device can be performed before/after/simultaneously with the action of sending the first information to the network element node (corresponding to step S1021 and step S1022).
- the network element node and the terminal device may communicate directly via the RAN using the first key.
- the terminal device may execute step S103 to process data of the first service using the first key, and transmit the data to the network element node via the RAN.
- the network element node may execute step S104 to process the data of the first service using the first key, and transmit the data to the terminal device via the RAN.
- step S101 is omitted, and the AMF can actively send key information to the terminal device when the terminal device is connected. Further, the AMF can also actively send key information to the network element node corresponding to the first service that the terminal device needs to implement.
- step S102 may be omitted.
- the AMF may directly execute step S103 to send key information to the network element node.
- AMF ensures that the communicating parties can correctly encrypt and decrypt the transmitted data by sending key information to the communicating parties (for example, the terminal device and the network element node).
- the terminal device In response to receiving the key information (for example, the second information), the terminal device can correctly encrypt and decrypt the transmitted data during the communication between the RAN and the network element node.
- the network element node In response to receiving the key information (for example, the first information), the network element node can correctly encrypt and decrypt the transmitted data during the communication between the RAN and the terminal device.
- a suitable encryption mechanism is provided for the service-oriented RAN architecture, and the security of the data transmission between the core network network element and the terminal device can still be guaranteed without passing through the AMF.
- Fig. 5 is a schematic diagram of the structure of a communication device 2 according to an embodiment of the present application. Those skilled in the art will appreciate that the communication device 2 according to this embodiment can be used to implement the method and technical solutions described in the embodiments described in Figs. 1 to 4 above.
- the communication device 2 described in this embodiment may include: a receiving module 21, used to receive request information, the request information is used to request a first service; a sending module 22, used to send key information, the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
- the above-mentioned communication device 2 may correspond to a chip with a communication function in a network device, or to a chip with a data processing function, such as a system-on-a-chip (SOC), a baseband chip, etc.; or to a chip module including a chip with a communication function in a network device; or to a chip module with a chip with a data processing function, or to a network device.
- the network device may be, for example, an AMF.
- Fig. 6 is a schematic diagram of the structure of another communication device 3 according to an embodiment of the present application.
- the communication device 3 described in this embodiment can be used to implement the method and technical solutions described in the embodiments described in Figs. 1 to 4 above.
- the communication device 3 described in this embodiment may include: a receiving module 31, used to receive key information, the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmission module 32, used to use the first key to process the data of the first service and transmit it to the network element node via a wireless access network.
- the above-mentioned communication device 3 may correspond to a chip with communication function in a terminal device, or to a chip with data processing function, such as a system-on-a-chip (SOC for short), a baseband chip, etc.; or to a chip module in a terminal device that includes a chip with communication function; or to a chip module with a chip with data processing function, or to a terminal device.
- a chip with communication function such as a system-on-a-chip (SOC for short), a baseband chip, etc.
- SOC system-on-a-chip
- Fig. 7 is a schematic diagram of the structure of another communication device 4 according to an embodiment of the present application.
- the communication device 4 described in this embodiment can be used to implement the method and technical solutions described in the embodiments described in Figs. 1 to 4 above.
- the communication device 4 described in this embodiment may include: a receiving module 41, used to receive key information, the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmission module 42, used to use the first key to process the data of the first service and transmit it to the terminal device via a wireless access network.
- the above-mentioned communication device 4 may correspond to a chip with a communication function in a network device, or to a chip with a data processing function, such as a system-on-a-chip (SOC), a baseband chip, etc.; or to a chip module including a chip with a communication function in a network device; or to a chip module with a data processing function chip, or to a network device.
- the network device may be, for example, a core network element (i.e., a network element node).
- each module/unit included in each device or product described in the above embodiments may be a software module/unit or a hardware module/unit, or may be partly a software module/unit and partly a hardware module/unit.
- each module/unit contained therein may be implemented in the form of hardware such as circuits, or at least some of the modules/units may be implemented in the form of software programs, which run on a processor integrated inside the chip, and the remaining (if any) modules/units may be implemented in the form of hardware such as circuits; for each device or product applied to or integrated in a chip module, each module/unit contained therein may be implemented in the form of hardware such as circuits, and different modules/units may be located in the same component (such as a chip, circuit module, etc.) or different components of the chip module, or at least some of the modules/units may be implemented in the form of software programs.
- the element can be implemented in the form of a software program, which runs on a processor integrated inside the chip module, and the remaining (if any) modules/units can be implemented in the form of hardware such as circuits; for various devices and products applied to or integrated in the terminal, the various modules/units contained therein can be implemented in the form of hardware such as circuits, and different modules/units can be located in the same component (for example, chip, circuit module, etc.) or in different components in the terminal, or, at least some modules/units can be implemented in the form of a software program, which runs on a processor integrated inside the terminal, and the remaining (if any) modules/units can be implemented in the form of hardware such as circuits.
- the embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transitory storage medium, on which a computer program is stored, and when the computer program is executed by the processor, the steps of the communication method provided in any of the above embodiments are executed.
- the storage medium may include a computer-readable storage medium such as a non-volatile memory or a non-transitory memory.
- the storage medium may include a ROM, a RAM, a magnetic disk or an optical disk, etc.
- the embodiment of the present application also provides another communication device, including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor runs the computer program, the steps of the communication method provided in the embodiment corresponding to FIG. 4 are executed.
- the communication device can be integrated into a terminal/network device, or the communication device can be, for example, a terminal/network device.
- the technical solution of the present application can be applied to the fifth generation (5th Generation, 5G) communication system, as well as the fourth generation (4th Generation, 4G), third generation (3rd Generation, 3G) communication system, and various new communication systems in the future, such as the sixth generation (6th Generation, 6G), seventh generation (7th Generation, 7G), etc., but the embodiments of the present application are not limited to this.
- the technical solution of the present application is also applicable to different network architectures, including but not limited to relay network architecture, dual-link architecture, vehicle-to-everything (V2X) architecture, device-to-device (D2D) architecture, and other architectures.
- relay network architecture dual-link architecture
- V2X vehicle-to-everything
- D2D device-to-device
- other architectures including but not limited to relay network architecture, dual-link architecture, vehicle-to-everything (V2X) architecture, device-to-device (D2D) architecture, and other architectures.
- V2X vehicle-to-everything
- D2D device-to-device
- the devices in the embodiments of the present application include network devices and terminal devices.
- the network equipment in the embodiment of the present application includes a base station and a base station controller of the access network, and may also include a terminal device.
- the base station (BS) in the embodiment of the present application is a device deployed in a radio access network (RAN) to provide wireless communication functions.
- the equipment providing base station functions in 2G networks includes base transceiver stations (Base Transceiver Station, BTS), the equipment providing base station functions in 3G networks includes NodeB, the equipment providing base station functions in 4G networks includes evolved NodeB (eNB), in wireless local area networks (Wireless Local Area Networks, WLAN), the equipment providing base station functions is access point (Access Point, AP), the equipment providing base station functions in 5G new radio (New Radio, NR) is gNB, and the evolving NodeB (ng-eNB), wherein the gNB and the terminal equipment use NR technology for communication, and the ng-eNB and the terminal equipment use Evolved Universal Terrestrial Radio Access (E-UTRA) technology for communication, and both gNB and ng-eNB can be connected to the 5G core network.
- the base station controller in the embodiment of the present application may also be referred to as a base station controller device, which is a device for managing base stations, such as a base station controller (BSC) in a 2G network, a radio network controller (RNC) in a 3G network, and may also refer to a device for controlling and managing base stations in future new communication systems.
- BSC base station controller
- RNC radio network controller
- the terminal device in the embodiments of the present application may also be referred to as a terminal, and may refer to various forms of user equipment (UE), access terminal equipment, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal equipment, mobile equipment, user terminal equipment, wireless communication equipment, user agent or user device.
- UE user equipment
- MS mobile station
- remote station remote terminal equipment
- mobile equipment user terminal equipment
- wireless communication equipment user agent or user device.
- the terminal device may also be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device with wireless communication function, a computing device or other processing equipment connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a future 5G network or a terminal device in a future evolved Public Land Mobile Network (PLMN), etc., and the embodiments of the present application are not limited to this.
- SIP Session Initiation Protocol
- WLL Wireless Local Loop
- PDA Personal Digital Assistant
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
一种通信方法及装置、计算机可读存储介质,涉及通信技术领域,该方法包括:接收请求信息,该请求信息用于请求第一业务;发送密钥信息,该密钥信息用于指示第一密钥,该第一密钥用于加密在网元节点和终端设备之间传输的所述第一业务的数据。通过本公开方案能够为服务化RAN架构提供合适的加密机制,在核心网网元和终端设备之间的数据传输不经过AMF的情况下仍能保证安全性。
Description
本申请要求于2023年12月14日提交中国专利局、申请号为202311731505.0、申请名称为“通信方法及装置、计算机可读存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及通信技术领域,具体地涉及一种通信方法及装置、计算机可读存储介质。
当前,终端设备和核心网的网元之间的交互需要通过访问和移动性管理功能(Access and Mobility Management Function,AMF)转发,安全性由AMF的加密机制来保护。
未来有极大可能引入服务化无线接入网(Radio access network,RAN),核心网网元和AMF之间的嵌套关系会被突破,终端设备可以和核心网网元直接交互而无需经过AMF中转。此时,AMF无法再实现加密功能,终端设备和核心网网元之间的业务安全性无法得到保障。
本申请可以解决的技术问题是如何确保服务化RAN架构下的业务安全性。
为解决上述技术问题,本申请实施例提供一种通信方法,包括:接收请求信息,所述请求信息用于请求第一业务;发送密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的所述第一业务的数据。
可选的,所述发送密钥信息包括:向所述网元节点发送第一信息,所述第一信息包括所述第一密钥。
可选的,在向网元节点发送第一信息之前,所述方法还包括:从多个候选网元节点中选择得到所述网元节点,所述多个候选网元节点均与所述第一业务相关联。
可选的,所述发送密钥信息包括:向所述终端设备发送第二信息,所述第二信息包括输入参数,所述输入参数用于生成所述第一密钥。
可选的,所述输入参数包括:所述网元节点的标识和/或所述网元节点的地址。
可选的,所述请求信息接收自服务器或者所述终端设备。
可选的,所述网元节点选自:定位管理功能节点以及感知功能节点。
为解决上述技术问题,本申请实施例还提供一种通信方法,包括:接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述网元节点。
可选的,所述接收密钥信息包括:接收第二信息,所述第二信息包括输入参数,所述输入参数用于生成所述第一密钥。
可选的,所述输入参数包括:所述网元节点的标识和/或所述网元节点的网络互连协议地址。
可选的,所述方法还包括:发送请求信息,所述请求信息用于请求第一业务。
为解决上述技术问题,本申请实施例还提供一种通信方法,包括:接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述终端设备。
可选的,所述接收密钥信息包括:接收第一信息,所述第一信息包括所述第一密钥。
可选的,所述网元节点选自:定位管理功能节点以及感知功能节点。
为解决上述技术问题,本申请实施例还提供一种通信装置,包括:接收模块,用于接收请求信息,所述请求信息用于请求第一业务;发送模块,用于发送密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的所述第一业务的数据。
为解决上述技术问题,本申请实施例还提供一种通信装置,包括:接收模块,用于接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;传输模块,用于使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述网元节点。
为解决上述技术问题,本申请实施例还提供一种通信装置,包括:接收模块,用于接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;传输模块,用于使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述终端设备。
为解决上述技术问题,本申请实施例还提供一种计算机可读存储介质,所述计算机可读存储介质为非易失性存储介质或非瞬态存储介质,其上存储有计算机程序,所述计算机程序被处理器运行时执行上述方法的步骤。
为解决上述技术问题,本申请实施例还提供一种通信装置,包括存储器和处理器,所述存储器上存储有可在所述处理器上运行的计算机程序,所述处理器运行所述计算机程序时执行上述方法的步骤。
与现有技术相比,本申请实施例的技术方案具有以下有益效果:
在AMF侧,本申请实施例提供一种通信方法,包括:接收请求信息,所述请求信息用于请求第一业务;发送密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的所述第一业务的数据。
相较于现有技术中AMF作为中转节点在为终端设备和核心网网元转发消息/数据时完成加密,本实施方案涉及的第一业务为服务化RAN架构下进行的业务,由于此时AMF不起到数据中转功能,因而通过将密钥信息发送给通信的双方(例如,终端设备和网元节点),确保通信各方能够正确加解密传输的数据。由此,为服务化RAN架构提供合适的加密机制,在核心网网元和终端设备之间的数据传输不经过AMF的情况下仍能保证安全性。
在终端设备侧,本申请实施例还提供一种通信方法,包括:接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述网元节点。
相较于现有技术中终端设备只需收发由AMF解加密的数据,本实施方案通过将AMF侧配置的第一密钥指示给终端设备,使得终端设备在通过RAN和网元节点通信期间,能够正确加解密传输的数据。由此,为服务化RAN架构提供合适的加密机制,在核心网网元和终端设备之间的数据传输不经过AMF的情况下仍能保证安全性。
在核心网侧,本申请实施例还提供一种通信方法,包括:接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述终端设备。
相较于现有技术中网元节点只需收发由AMF解加密的数据,本实施方案通过将AMF侧配置的第一密钥指示给网元节点,使得网元节点在通过RAN和终端设备通信期间,能够正确加解密传输的数据。由此,为服务化RAN架构提供合适的加密机制,在核心网网元和终端设备之间的数据传输不经过AMF的情况下仍能保证安全性。
图1是本申请第一种服务化RAN的架构示意图;
图2是本申请第二种服务化RAN的架构示意图;
图3是本申请第三种服务化RAN的架构示意图;
图4是本申请实施例一种通信方法的信令交互图;
图5是本申请实施例一种通信装置的结构示意图;
图6是本申请实施例另一种通信装置的结构示意图;
图7是本申请实施例又一种通信装置的结构示意图。
如背景技术所言,在服务化RAN架构下,现有通过AMF实现的加密功能不再适用,终端设备和核心网网元之间的业务安全性无法得到保障。
具体而言,现有终端设备和核心网的网元之间的交互,通过AMF转发。以定位业务举例,定位管理服务器(也称,位置管理功能Location management function,LMF)和终端设备之间没有直接接口。出于业务安全性考虑,定位业务的数据(例如,包括定位请求和定位报告)需要被加密,由于终端设备和LMF之间的交互必然经过AMF,因此可以通过AMF加密。
考虑到6G会引入服务化架构,其中一种选项是RAN直接接入核心网,不再通过AMF转发。因而,需要为服务化RAN的架构设计新的加密机制。
为解决上述技术问题,本申请实施例提供一种通信方法,包括:接收请求信息,所述请求信息用于请求第一业务;发送密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的所述第一业务的数据。
本实施方案涉及的第一业务为服务化RAN架构下进行的业务,由于此时AMF不起到数据中转功能,因而通过将密钥信息发送给通信的双方(例如,终端设备和网元节点),确保通信各方能够正确加解密传输的数据。由此,为服务化RAN架构提供合适的加密机制,在核心网网元和终端设备之间的数据传输不经过AMF的情况下仍能保证安全性。
本申请实施例中服务化RAN架构可以如图1至图3中的任一种所示。
图1示例性的展示N2接口全服务化下的网络架构,可以实现接入网网络功能(RAN Network Function,RAN NF)和核心网网络功能(Core Network NF,CN NF)之间的直接服务调用。具体而言,终端设备(图中以UE标识)可以通过AMF接入总线(即访问核心网)。进一步,终端设备还可以通过RAN直接访问核心网,从而突破现有AMF唯一转发的机制。RAN包括控制面RAN(图中以RAN-C标识)以及用户面RAN(图中以RAN-U标识)。进一步,图1所示架构中,核心网侧的应用功能(Application Function,AF)、网络存储功能(Network Repository Function,NRF)、策略控制功能(Policy Control Function,PCF)以及统一数据管理功能(Unified Data Management,UDM)也直接接入总线。进一步,用户面功能(User Plane Function,简称UPF)以及数据网络(Data Network,DN)可以通过会话管理功能(Session Management Function,简称SMF)接入总线。
图2示例性的展示针对传统RAN功能的服务化的网络架构,将功能(也称,RAN能力)拆分为服务,并进一步实现RAN和CN相关功能服务与流程的融合设计,以更好满足高内聚、松耦合的设计原则,精简网络设计。具体而言,终端设备(图中以UE标识)可以通过AMF接入总线。进一步,终端设备还可以通过无线电单元(Radio Unit,RU)访问RAN,并经由RAN直接访问核心网,其中,RU负责处理数字前端(DFE)和部分物理(PHY)层功能。进一步,RAN拆分为RAN控制面服务(基于控制面服务(Control Plane Service,CPS)实现)和RAN用户面服务(基于用户面服务(User Plane Service,UPS)实现)。进一步,设置核心网用户面服务(基于UPS实现),与RAN相通信并直接接入总线。进一步,其他诸如AF、NRF、PCF和UDM之类的核心网网元直接接入总线。进一步,SMF也可直接接入总线。进一步,DN通过核心网用户面服务接入总线。
图3示例性的展示针对新增DOICT能力的服务化的网络架构,该架构将人工智能(Artificial Intelligence,简称AI)、计算、数据等功能定义为服务。其中,DOICT通过通信技术(Communication Technology,CT)技术来简化现场网组网;通过运营技术(Operational Technology,OT)技术,与工业协议深度协同实现高可靠性;通过数据技术(Data technology,DT)技术实现智能化,闭环保障低时延体验;通过信息技术(Information Technology,IT)技术使能更多工业应用,降低建设成本,实现灵活组网。具体而言,终端设备通过RU访问RAN,并经由RAN直接访问核心网。进一步,RAN拆分为RAN控制面服务(基于网络物理系统(Cyber Physical System,CPS)实现)、RAN用户面服务(基于用户面物理系统(User Physical System,UPS)实现),以及多维能力服务化(包括AI服务、计算服务和数据服务)。进一步,AMF接入总线并与终端设备解耦。进一步,其他诸如网络开放功能(Network Exposure Function,NEF)、AF、NRF、PCF和UDM之类的核心网网元直接接入总线。进一步,SMF也可直接接入总线。进一步,DN通过UPF接入总线,UPF与RAN相通信。
本申请实施例中,网元节点可以是执行第一业务相关功能的核心网网元。第一业务可以是基于服务化RAN架构实现的业务。例如,第一业务可以为定位业务,相应的网元节点可以为定位管理功能(LMF)节点(简称SMF)。又如,第一业务可以为通感(也称感知,sensing)业务,相应的网元节点可以为感知功能(Sensing Function,SF)节点(简称SF)。
本申请实施例中,AMF虽然不再在终端设备和网元节点之间转发数据,但还是起到管理功能。
为使本申请的上述目的、特征和有益效果能够更为明显易懂,下面结合附图对本申请的具体实施例做详细的说明。
图4是本申请实施例一种通信方法的信令交互图。
本实施方案可以应用于服务化RAN架构下的通信场景,终端设备直接经由RAN和网元节点交互以传输第一业务的数据,无需经过AMF中转。
在具体实施中,下述步骤S101~步骤S102所提供的通信方法中,由终端设备实现的步骤,可以由终端设备中的具有通信功能的芯片执行,也可以由终端设备中的基带芯片执行;由AMF实现的步骤,可以由AMF中的具有通信功能的芯片执行,也可以由AMF中的基带芯片执行;由网元节点实现的步骤,可以由网元节点中的具有通信功能的芯片执行,也可以由网元节点中的基带芯片执行。
具体地,参考图4,本实施方案所述通信方法可以包括如下步骤:
步骤S101,终端设备向AMF发送请求信息。相应的,AMF接收请求信息。其中,请求信息用于请求第一业务。
例如,第一业务可以为定位业务,相应的,请求信息可以为定位请求信息。
在一些实施例中,可以由终端设备主动触发请求信息的发送。
在一些实施例中,可以由服务器触发终端设备向AMF发送请求信息。其中,服务器可以例如是外部服务器,用于实现第一业务。
在一些实施例中,可以由服务器直接向AMF发送请求信息。
在一些实施例中,请求的第一业务可以是上行业务,也可以是下行业务。
在一些实施例中,请求信息可以包括实现第一业务的相关信息,如终端设备的标识(用于唯一识别终端设备)、服务质量(Quality of Service,简称Qos)。
仍以终端设备请求定位业务为例,步骤S101中发送的定位请求信息可以包括终端设备的标识、定位的QoS(如定位的精度要求、时延要求等)。
在一个具体实施中,继续参考图4,响应于接收到请求信息,AMF可以执行步骤S102,分别向终端设备和网元节点发送密钥信息。相应的,网元节点和终端设备各自接收密钥信息。其中,密钥信息用于指示第一密钥,第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据。
在一些实施例中,对于网元节点和AMF之间的交互,步骤S102具体可以包括步骤S1021和步骤S1022。
步骤S1021中,AMF从多个候选网元节点中选择得到网元节点,多个候选网元节点均与第一业务相关联。
具体而言,核心网针对第一业务可以部署多个网元节点,这些网元节点作为候选网元节点。AMF在接收到请求信息后,从多个候选网元节点中择一确定为与终端设备相通信的网元节点。
仍以定位请求信息为例,AMF可以从多个候选LMF中就近选择一个,确定为与终端设备相通信以实现定位业务的LMF。
又例如,请求信息可以用于请求感知业务,AMF可以从多个候选SF中择一确定为与终端设备相通信以实现感知业务的SF。
进一步,在确定网元节点后,AMF可以继续执行步骤S1022,向网元节点发送第一信息。相应的,网元节点接收第一信息。其中,第一信息包括第一密钥。
由此,AMF直接向网元节点提供生成好的第一密钥。
在一些实施例中,分配给不同候选网元节点的第一密钥可以互不重复。
在一个具体实施中,对于终端设备和AMF之间的交互,步骤S102具体可以包括步骤S1023,AMF向终端设备发送第二信息。相应的,终端设备接收第二信息。其中,第二信息包括输入(input)参数,所述输入参数用于生成所述第一密钥。
具体而言,输入参数中的一部分可以由网络预配置或协议预定义或由终端设备自行确定,剩余部分(例如,与网元节点相关的参数)可以由AMF指示给终端设备。
仍以第一业务为定位业务为例,LMF的密钥(KLMF)的派生需要用到的输入参数可以包括:
-FC=0x6E,用于区分不同的派生算法;
-P0=上/下行非接入层(Non-Access Stratum,NAS)计数(Uplink/Downlink NAS COUNT),为终端设备和AMF传递信令时的序列号;
-L0=上/下行NAS计数的长度(length of uplink/downlink NAS COUNT),例如0x00 0x04;
-P1=网络功能标识(Network function distinguisher),用于区分不同的网络功能;
-L1=网络功能标识的长度(length of Network function distinguisher),例如0x000x01。
在一些实施例中,第二信息中携带的输入参数可以包括P1参数。由于P1参数用于区分不同的网络功能,因而也可称为网元节点的标识(本示例中,可以理解为类型标识),以区分不同功能的网元节点。例如,LMF对应的P1值为0x01,SF对应的P1值为0x02。
在一个变化例中,P1参数的内容可以为网元节点的身份标识(Identification,ID),用于唯一标识候选网元节点。例如,核心网侧包括多个候选LMF,其中每一候选LMF分配有各自唯一的ID。AMF从多个候选LMF中选定一个后,将选定的LMF的ID通过第二信息指示给终端设备。
在一个变化例中,P1参数的内容可以替换为网络功能地址(Network function address),相应的,L1参数的内容可以替换为网络功能地址的长度(length of Network function address)。
网元节点的地址可以例如是网络互连协议(Internet Protocol,简称IP)地址,还可以例如是媒体访问控制(Medium Access Control,MAC)地址。
在另一个变化例中,除了P1参数外,LMF的密钥(KLMF)的派生需要用到的输入参数还可以包括P2=网络功能地址,以及L2=网络功能地址的长度。进一步,第二信息可以包括P1参数以及P2参数。
在一个具体实施中,AMF通过在第二信息中指示第一业务关联的网元节点的标识(包括类型标识和/或身份标识)和/或地址,供终端设备生成用于与该网元节点交互的第一密钥。
例如,响应于接收到第二信息,终端设备根据全球用户识别卡(Universal Subscriber Identity Module,USIM)里配置的K值和网络提供的动态参数,计算KAMF。进一步,结合输入参数(包括第二信息中携带的内容(如P1和/或P2)以及终端设备自行确定的内容)计算得到第一密钥。
在一些实施例中,向终端设备发送第二信息(对应步骤S1023)的动作,可以在向网元节点发送第一信息(对应步骤S1021和步骤S1022)的动作之前/之后/同时执行。
在一个具体实施中,响应于分别接收到第一信息和第二信息,网元节点和终端设备可以使用第一密钥经由RAN进行直接通信。
具体而言,响应于接收到第二信息,终端设备可以执行步骤S103,以使用第一密钥处理第一业务的数据,并经由RAN传输至网元节点。
类似的,响应于接收到第一信息,网元节点可以执行步骤S104,以使用第一密钥处理第一业务的数据,并经由RAN传输至终端设备。
在一个变化例中,步骤S101以被省略,AMF可以在终端设备接入时即主动向其发送密钥信息。进一步,AMF还可以向终端设备需要实现的第一业务对应的网元节点也主动发送密钥信息。
在一个变化例中,步骤S102可以被省略。例如,只有一个与第一业务相关联的网元节点,则AMF可以直接执行步骤S103,以向该网元节点发送密钥信息。
由上,AMF通过将密钥信息发送给通信的双方(例如,终端设备和网元节点),确保通信各方能够正确加解密传输的数据。响应于接收到密钥信息(例如,第二信息),终端设备在通过RAN和网元节点通信期间,能够正确加解密传输的数据。响应于接收到密钥信息(例如,第一信息),网元节点在通过RAN和终端设备通信期间,能够正确加解密传输的数据。由此,为服务化RAN架构提供合适的加密机制,在核心网网元和终端设备之间的数据传输不经过AMF的情况下仍能保证安全性。
图5是本申请实施例一种通信装置2的结构示意图。本领域技术人员理解,本实施例所述通信装置2可以用于实施上述图1至图4所述实施例中所述的方法技术方案。
具体而言,本实施例所述通信装置2可以包括:接收模块21,用于接收请求信息,所述请求信息用于请求第一业务;发送模块22,用于发送密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的所述第一业务的数据。
关于所述通信装置2的工作原理、工作方式的更多内容,可以参照上述图1至图4中的相关描述,这里不再赘述。
在具体实施中,上述的通信装置2可以对应于网络设备中具有通信功能的芯片,或者对应于具有数据处理功能的芯片,例如片上系统(System-On-a-Chip,简称SOC)、基带芯片等;或者对应于网络设备中包括具有通信功能芯片的芯片模组;或者对应于具有数据处理功能芯片的芯片模组,或者对应于网络设备。本示例中,网络设备可以例如是AMF。
图6是本申请实施例另一种通信装置3的结构示意图。本领域技术人员理解,本实施例所述通信装置3可以用于实施上述图1至图4所述实施例中所述的方法技术方案。
具体地,参考图6,本实施例所述通信装置3可以包括:接收模块31,用于接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;传输模块32,用于使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述网元节点。
关于所述通信装置3的工作原理、工作方式的更多内容,可以参照上述图1至图4中的相关描述,这里不再赘述。
在具体实施中,上述的通信装置3可以对应于终端设备中具有通信功能的芯片,或者对应于具有数据处理功能的芯片,例如片上系统(System-On-a-Chip,简称SOC)、基带芯片等;或者对应于终端设备中包括具有通信功能芯片的芯片模组;或者对应于具有数据处理功能芯片的芯片模组,或者对应于终端设备。
图7是本申请实施例又一种通信装置4的结构示意图。本领域技术人员理解,本实施例所述通信装置4可以用于实施上述图1至图4所述实施例中所述的方法技术方案。
具体地,参考图7,本实施例所述通信装置4可以包括:接收模块41,用于接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;传输模块42,用于使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述终端设备。
关于所述通信装置4的工作原理、工作方式的更多内容,可以参照上述图1至图4中的相关描述,这里不再赘述。
在具体实施中,上述的通信装置4可以对应于网络设备中具有通信功能的芯片,或者对应于具有数据处理功能的芯片,例如片上系统(System-On-a-Chip,简称SOC)、基带芯片等;或者对应于网络设备中包括具有通信功能芯片的芯片模组;或者对应于具有数据处理功能芯片的芯片模组,或者对应于网络设备。本示例中,网络设备可以例如是核心网网元(也即,网元节点)。
在具体实施中,关于上述实施例中描述的各个装置、产品包含的各个模块/单元,其可以是软件模块/单元,也可以是硬件模块/单元,或者也可以部分是软件模块/单元,部分是硬件模块/单元。
例如,对于应用于或集成于芯片的各个装置、产品,其包含的各个模块/单元可以都采用电路等硬件的方式实现,或者,至少部分模块/单元可以采用软件程序的方式实现,该软件程序运行于芯片内部集成的处理器,剩余的(如果有)部分模块/单元可以采用电路等硬件方式实现;对于应用于或集成于芯片模组的各个装置、产品,其包含的各个模块/单元可以都采用电路等硬件的方式实现,不同的模块/单元可以位于芯片模组的同一组件(例如芯片、电路模块等)或者不同组件中,或者,至少部分模块/单元可以采用软件程序的方式实现,该软件程序运行于芯片模组内部集成的处理器,剩余的(如果有)部分模块/单元可以采用电路等硬件方式实现;对于应用于或集成于终端的各个装置、产品,其包含的各个模块/单元可以都采用电路等硬件的方式实现,不同的模块/单元可以位于终端内同一组件(例如,芯片、电路模块等)或者不同组件中,或者,至少部分模块/单元可以采用软件程序的方式实现,该软件程序运行于终端内部集成的处理器,剩余的(如果有)部分模块/单元可以采用电路等硬件方式实现。
本申请实施例还提供了一种计算机可读存储介质,所述计算机可读存储介质为非易失性存储介质或非瞬态存储介质,其上存储有计算机程序,所述计算机程序被处理器运行时执行上述任一实施例提供的通信方法的步骤。优选地,所述存储介质可以包括诸如非挥发性(non-volatile)存储器或者非瞬态(non-transitory)存储器等计算机可读存储介质。所述存储介质可以包括ROM、RAM、磁盘或光盘等。
本申请实施例还提供了另一种通信装置,包括存储器和处理器,所述存储器上存储有可在所述处理器上运行的计算机程序,所述处理器运行所述计算机程序时执行上述图4对应实施例所提供的通信方法的步骤。通信装置可以集成于终端/网络设备,或者,通信装置可以例如是终端/网络设备。
本申请技术方案可适用于第五代(5th Generation,5G)通信系统,还可适用于第四代(4th Generation,4G)、第三代(3rd Generation,3G)通信系统,还可适用于未来新的各种通信系统,例如第六代(6th Generation,6G)、第七代(7th Generation,7G)等,本申请实施例对此并不限定。
本申请技术方案也适用于不同的网络架构,包括但不限于中继网络架构、双链接架构、车辆到任何物体的通信(Vehicle-to-Everything,V2X)架构、设备到设备的通信(Device-to-Device,D2D)等架构。
本申请实施例中的设备包含网络设备和终端设备。
本申请实施例中的网络设备包括接入网的基站和基站控制器,还可以包含终端设备。-
本申请实施例中的基站(base station,BS),也可称为基站设备,是一种部署在无线接入网(RAN)用以提供无线通信功能的装置。例如在2G网络中提供基站功能的设备包括基地无线收发站(Base Transceiver Station,BTS),3G网络中提供基站功能的设备包括节点B(NodeB),在4G网络中提供基站功能的设备包括演进的节点B(evolved NodeB,eNB),在无线局域网络(Wireless Local Area Networks,WLAN)中,提供基站功能的设备为接入点(Access Point,AP),5G新无线(New Radio,NR)中的提供基站功能的设备gNB,以及继续演进的节点B(ng-eNB),其中gNB和终端设备之间采用NR技术进行通信,ng-eNB和终端设备之间采用演进的通用地面无线接入(Evolved Universal Terrestrial Radio Access,E-UTRA)技术进行通信,gNB和ng-eNB均可连接到5G核心网。本申请实施例中的基站还包含在未来新的通信系统中提供基站功能的设备等。
本申请实施例中的基站控制器,也可以称为基站控制器设备,是一种管理基站的装置,例如2G网络中的基站控制器(Base Station Controller,BSC)、3G网络中的无线网络控制器(Radio Network Controller,RNC)、还可指未来新的通信系统中控制管理基站的装置。
本申请实施例中的终端设备,也可以称为终端,可以指各种形式的用户设备(User Equipment,简称UE)、接入终端设备、用户单元、用户站、移动站、移动台(Mobile Station,MS)、远方站、远程终端设备、移动设备、用户终端设备、无线通信设备、用户代理或用户装置。终端设备还可以是蜂窝电话、无绳电话、会话启动协议(Session Initiation Protocol,简称SIP)电话、无线本地环路(Wireless Local Loop,WLL)站、个人数字处理(Personal Digital Assistant,PDA)、具有无线通信功能的手持设备、计算设备或连接到无线调制解调器的其它处理设备、车载设备、可穿戴设备,未来5G网络中的终端设备或者未来演进的公用陆地移动通信网络(Public Land Mobile Network,PLMN)中的终端设备等,本申请实施例对此并不限定。
虽然本申请披露如上,但本申请并非限定于此。任何本领域技术人员,在不脱离本申请的精神和范围内,均可作各种更动与修改,因此本申请的保护范围应当以权利要求所限定的范围为准。
Claims (19)
- 一种通信方法,其特征在于,包括:接收请求信息,所述请求信息用于请求第一业务;发送密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的所述第一业务的数据。
- 根据权利要求1所述的方法,其特征在于,所述发送密钥信息包括:向所述网元节点发送第一信息,所述第一信息包括所述第一密钥。
- 根据权利要求2所述的方法,其特征在于,在向网元节点发送第一信息之前,还包括:从多个候选网元节点中选择得到所述网元节点,所述多个候选网元节点均与所述第一业务相关联。
- 根据权利要求1至3中任一项所述的方法,其特征在于,所述发送密钥信息包括:向所述终端设备发送第二信息,所述第二信息包括输入参数,所述输入参数用于生成所述第一密钥。
- 根据权利要求4所述的方法,其特征在于,所述输入参数包括:所述网元节点的标识和/或所述网元节点的地址。
- 根据权利要求1至5中任一项所述的方法,其特征在于,所述请求信息接收自服务器或者所述终端设备。
- 根据权利要求1至5中任一项所述的方法,其特征在于,所述网元节点选自:定位管理功能节点以及感知功能节点。
- 一种通信方法,其特征在于,包括:接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述网元节点。
- 根据权利要求8所述的方法,其特征在于,所述接收密钥信息包括:接收第二信息,所述第二信息包括输入参数,所述输入参数用于生成所述第一密钥。
- 根据权利要求9所述的方法,其特征在于,所述输入参数包括:所述网元节点的标识和/或所述网元节点的网络互连协议地址。
- 根据权利要求8至10中任一项所述的方法,其特征在于,还包括:发送请求信息,所述请求信息用于请求第一业务。
- 一种通信方法,其特征在于,包括:接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述终端设备。
- 根据权利要求12所述的方法,其特征在于,所述接收密钥信息包括:接收第一信息,所述第一信息包括所述第一密钥。
- 根据权利要求12或13所述的方法,其特征在于,所述网元节点选自:定位管理功能节点以及感知功能节点。
- 一种通信装置,其特征在于,包括:接收模块,用于接收请求信息,所述请求信息用于请求第一业务;发送模块,用于发送密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的所述第一业务的数据。
- 一种通信装置,其特征在于,包括:接收模块,用于接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;传输模块,用于使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述网元节点。
- 一种通信装置,其特征在于,包括:接收模块,用于接收密钥信息,所述密钥信息用于指示第一密钥,所述第一密钥用于加密在网元节点和终端设备之间传输的第一业务的数据;传输模块,用于使用所述第一密钥处理所述第一业务的数据,并经由无线接入网传输至所述终端设备。
- 一种计算机可读存储介质,所述计算机可读存储介质为非易失性存储介质或非瞬态存储介质,其上存储有计算机程序,其特征在于,所述计算机程序被处理器运行时执行权利要求1至14中任一项所述方法的步骤。
- 一种通信装置,包括存储器和处理器,所述存储器上存储有可在所述处理器上运行的计算机程序,其特征在于,所述处理器运行所述计算机程序时执行权利要求1至14中任一项所述方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202311731505.0A CN120201421A (zh) | 2023-12-14 | 2023-12-14 | 通信方法及装置、计算机可读存储介质 |
| CN202311731505.0 | 2023-12-14 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025124347A1 true WO2025124347A1 (zh) | 2025-06-19 |
Family
ID=96056496
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/137854 Pending WO2025124347A1 (zh) | 2023-12-14 | 2024-12-09 | 通信方法及装置、计算机可读存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN120201421A (zh) |
| WO (1) | WO2025124347A1 (zh) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110830991A (zh) * | 2018-08-10 | 2020-02-21 | 华为技术有限公司 | 安全会话方法和装置 |
| CN114867004A (zh) * | 2021-02-03 | 2022-08-05 | 维沃移动通信有限公司 | 核心网系统 |
| US20230018399A1 (en) * | 2021-07-16 | 2023-01-19 | Cisco Technology, Inc. | DIRECT SMF CONTROL PLANE WITH gNB |
| WO2023224915A1 (en) * | 2022-05-16 | 2023-11-23 | Intel Corporation | Security for distributed non-access stratum protocol in a mobile system |
| WO2023229316A1 (en) * | 2022-05-23 | 2023-11-30 | Samsung Electronics Co., Ltd. | Method and system for designing security protocol for 6g network architecture |
-
2023
- 2023-12-14 CN CN202311731505.0A patent/CN120201421A/zh active Pending
-
2024
- 2024-12-09 WO PCT/CN2024/137854 patent/WO2025124347A1/zh active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110830991A (zh) * | 2018-08-10 | 2020-02-21 | 华为技术有限公司 | 安全会话方法和装置 |
| CN114867004A (zh) * | 2021-02-03 | 2022-08-05 | 维沃移动通信有限公司 | 核心网系统 |
| US20230018399A1 (en) * | 2021-07-16 | 2023-01-19 | Cisco Technology, Inc. | DIRECT SMF CONTROL PLANE WITH gNB |
| WO2023224915A1 (en) * | 2022-05-16 | 2023-11-23 | Intel Corporation | Security for distributed non-access stratum protocol in a mobile system |
| WO2023229316A1 (en) * | 2022-05-23 | 2023-11-30 | Samsung Electronics Co., Ltd. | Method and system for designing security protocol for 6g network architecture |
Also Published As
| Publication number | Publication date |
|---|---|
| CN120201421A (zh) | 2025-06-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11778459B2 (en) | Secure session method and apparatus | |
| US11533610B2 (en) | Key generation method and related apparatus | |
| CN110830993B (zh) | 一种数据处理的方法、装置和计算机可读存储介质 | |
| JP6936393B2 (ja) | パラメータ保護方法及びデバイス、並びに、システム | |
| EP3820198A1 (en) | Security protection method, device, and system | |
| EP3820182A1 (en) | Method and apparatus for acquiring security context | |
| US11956715B2 (en) | Communications method and apparatus | |
| US20250365578A1 (en) | Communication method and communication apparatus | |
| WO2020052414A1 (zh) | 一种数据保护方法、设备及系统 | |
| CN109246696B (zh) | 密钥处理方法以及相关装置 | |
| US12388792B2 (en) | Secure communication method, related apparatus, and system | |
| US20220141664A1 (en) | Data transmission method and apparatus in network slice architecture | |
| WO2022027476A1 (zh) | 密钥管理方法及通信装置 | |
| WO2018176187A1 (zh) | 数据传输方法、用户设备和控制面节点 | |
| WO2022134089A1 (zh) | 一种安全上下文生成方法、装置及计算机可读存储介质 | |
| US20210168614A1 (en) | Data Transmission Method and Device | |
| CN109788577A (zh) | 双连接通信方法、装置、基站以及用户面节点 | |
| US20250338123A1 (en) | Communication method and communication apparatus | |
| US20250227797A1 (en) | Communication method and apparatus | |
| US20250126476A1 (en) | Security decision negotiation method and network element | |
| WO2025124347A1 (zh) | 通信方法及装置、计算机可读存储介质 | |
| WO2020142884A1 (zh) | 切换传输路径的方法及装置 | |
| US20260052595A1 (en) | Communication method and corresponding apparatus | |
| CN108391252B (zh) | 一种数据包处理方法和装置 | |
| WO2025031156A1 (zh) | 通信方法和通信装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24902768 Country of ref document: EP Kind code of ref document: A1 |