WO2025152184A1 - 密钥处理方法、通信设备及存储介质 - Google Patents

密钥处理方法、通信设备及存储介质

Info

Publication number
WO2025152184A1
WO2025152184A1 PCT/CN2024/073361 CN2024073361W WO2025152184A1 WO 2025152184 A1 WO2025152184 A1 WO 2025152184A1 CN 2024073361 W CN2024073361 W CN 2024073361W WO 2025152184 A1 WO2025152184 A1 WO 2025152184A1
Authority
WO
WIPO (PCT)
Prior art keywords
communication
sat
key
network device
user equipment
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2024/073361
Other languages
English (en)
French (fr)
Inventor
陆伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Xiaomi Mobile Software Co Ltd
Original Assignee
Beijing Xiaomi Mobile Software Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Xiaomi Mobile Software Co Ltd filed Critical Beijing Xiaomi Mobile Software Co Ltd
Priority to PCT/CN2024/073361 priority Critical patent/WO2025152184A1/zh
Publication of WO2025152184A1 publication Critical patent/WO2025152184A1/zh
Anticipated expiration legal-status Critical
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation

Definitions

  • the communication system can support user equipment to satellite to user equipment ((User Equipment, UE)-Satellite-UE, UE-SAT-UE) communication.
  • UE-SAT-UE communication means that communication between UEs is achieved through local switching under the coverage of one or more satellites instead of through the user plane (UP) on the road.
  • Embodiments of the present disclosure provide a key processing method, a communication device, and a storage medium.
  • a third network device comprising: a receiving module, configured to receive a third message of a first user equipment UE; the third message is used to request the establishment of a protocol data unit PDU session for UE-SAT-UE communication between the first UE and at least one second UE; a processing module, configured to determine whether the first UE has the authority for the UE-SAT-UE communication or has the end-to-end security authority for the UE-SAT-UE communication; the first UE has the authority for the UE-SAT-UE communication or has the end-to-end security authority for the UE-SAT-UE communication, and determines to agree to establish the PDU session for the UE-SAT-UE communication; a sending module, configured to agree to establish the PDU session for the UE-SAT-UE communication, and send a PDU session establishment request message to the second network device; the PDU session establishment request message is used by the second network device to provide a first key to the first UE; the first key
  • FIG2 is a schematic flow chart of a key processing method according to an exemplary embodiment
  • FIG3 is a schematic flow chart of a key processing method according to an exemplary embodiment
  • FIG4 is a schematic flow chart of a key processing method according to an exemplary embodiment
  • FIG5 is a schematic flow chart of a key processing method according to an exemplary embodiment
  • FIG6 is a schematic flow chart of a key processing method according to an exemplary embodiment
  • FIG7A is a schematic flow chart of a key processing method according to an exemplary embodiment
  • FIG7B is a schematic flow chart of a key processing method according to an exemplary embodiment
  • FIG8A is a schematic structural diagram of a first UE according to an exemplary embodiment
  • FIG8B is a schematic diagram showing the structure of a second network device according to an exemplary embodiment
  • FIG8C is a schematic diagram showing the structure of a first network device according to an exemplary embodiment
  • FIG9A is a schematic diagram showing the structure of a communication device according to an exemplary embodiment
  • FIG. 9B is a schematic structural diagram of a chip according to an exemplary embodiment.
  • Embodiments of the present disclosure provide a key processing method, a communication device, and a storage medium.
  • the first information also includes at least one of the following: a first indication, the first indication is used to indicate whether to activate end-to-end security of UE-SAT-UE communication; a parameter value, the parameter value and the first key are jointly used to determine the second key.
  • the above solution provides a method for the first UE to trigger the second network device to distribute the first key.
  • the method for the first UE to obtain the first key is not limited to requesting from the second network device.
  • the first message includes at least one of the following: a registration authorization request message; the registration authorization request information includes capability information of the first UE supporting UE-SAT-UE communication; and a protocol data unit PDU session establishment request message for UE-SAT-UE communication.
  • the second key comprises at least one of: an integrity key; a confidentiality key.
  • the end-to-end security protection of UE-SAT-UE communication may include integrity protection and/or confidentiality protection, thereby ensuring the end-to-end security of UE-SAT-UE communication.
  • the second aspect provides a key processing method, which is executed by a second network device and includes: determining a first key; the first key is a root key for UE-SAT-UE communication; the first key is used to generate a second key for a first user equipment UE; UE-SAT-UE communication.
  • the first message is a registration authorization request message; the registration authorization request message includes capability information of the first UE; a second message is sent to the first UE, including; the capability information of the first UE indicates whether the first UE supports UE-SAT-UE communication or whether the first UE supports end-to-end security of UE-SAT-UE communication, and the second message is sent to the first UE.
  • elements expressed in the singular form such as “a”, “an”, “the”, “above”, “the”, “the”, etc., may mean “one and only one", or “one or more”, “at least one”, etc.
  • the noun after the article may be understood as a singular expression or a plural expression.
  • plurality refers to two or more.
  • the description methods such as “at least one of A and B", “A and/or B", “A in one case, B in another case”, “A in one case, B in another case” and the like may include the following technical solutions according to the circumstances:
  • A (regardless of B)
  • A is executed independently; in some embodiments, B is executed independently of A; in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (A and B are both executed).
  • the above is also similar when there are more branches such as A, B, C, etc.
  • prefixes such as “first” and “second” in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute restrictions on the position, order, priority, quantity or content of the description objects.
  • the statement of the description object refers to the description in the context of the claims or embodiments, and should not constitute unnecessary restrictions due to the use of prefixes.
  • the description object is a "field”
  • the ordinal number before the "field” in the "first field” and the "second field” does not limit the position or order between the "fields”
  • the "first” and “second” do not limit whether the "fields” they modify are in the same message, nor do they limit the order of the "first field” and the "second field”.
  • the description object is a "level”
  • the ordinal number before the "level” in the “first level” and the “second level” does not limit the priority between the "levels”.
  • the number of description objects is not limited by the ordinal number, and can be one or more. Taking the "first device” as an example, the number of "devices” can be one or more.
  • the objects modified by different prefixes may be the same or different. For example, if the description object is "device”, then the “first device” and the “second device” may be the same device or different devices, and their types may be the same or different.
  • the description object is "information”, then the "first category of information” and the "second category of information” may be the same information or different information, and their contents may be the same or different.
  • terms such as “...”, “determine...”, “in the case of...”, “at the time of...”, “when...”, “if...”, “if...”, etc. can be used interchangeably.
  • network may be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
  • terminal In some embodiments, the terms "terminal”, “terminal device”, “user equipment (UE)”, “user terminal” “mobile station (MS)”, “mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client and the like can be used interchangeably.
  • data, information, etc. may be obtained with the user's consent.
  • the following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1A, or part of the subject, but are not limited thereto.
  • the subjects shown in FIG1A are examples, and the communication system may include all or part of the subjects in FIG1A, or may include other subjects other than FIG1A, and the number and form of the subjects are arbitrary, and the connection relationship between the subjects is an example, and the subjects may be connected or disconnected, and the connection may be in any manner, which may be a direct connection or an indirect connection, and may be a wired connection or a wireless connection.
  • the security of the user plane (UP) data flow of the Uu interface is based on the security policy provided by the core network.
  • the security policy can be set by the user data management (UDM) or by the session management function (SMF) based on the specific service requested by the UE.
  • the SMF can set the security policy according to the UP security enhancement information during the PDU session establishment process.
  • the UP security enhancement information may include but is not limited to at least one of the following:
  • the signed UP security policy which may be received from the UDM and is part of the session management contract information
  • the UP security policy is a local policy for a single data network name (DNN) and single network slice selection assistance information (S-NSSAI).
  • DNN single data network name
  • S-NSSAI single network slice selection assistance information
  • the UP security policy indicates whether UP security protection is activated on the Uu interface for this PDU session.
  • the UP security policy can be used to activate UP confidentiality and/or UP integrity for the PDU session.
  • the gNB activates UP security protection on the Uu interface for each Data Radio Bearer (DRB) through RRC signaling. If the policy is displayed as not needed (Not need), the PDU session is established without protection. If the policy is preferred (Preferred), the gNB can decide whether to activate UP security protection on the Uu interface. However, when the UP security policy indicates required (Required) or not needed (Not need), the gNB cannot veto the UP security policy received from the SMF.
  • DRB Data Radio Bearer
  • the second network device may be a policy control function (PCF).
  • PCF policy control function
  • the second network device can determine whether the capabilities and/or services supported by the UE are authorized according to the contract information of the UE.
  • UE-SAT-UE communication may also be referred to as local communication or satellite-based local communication.
  • the second network device generates a first key for UE-SAT-UE communication.
  • the second network device receives the first key from an application server providing UE-SAT-UE communications.
  • the first key is not limited to a root key, but may also be an intermediate key for generating a second key.
  • the first key is used to generate a second key for UE-SAT-UE communication.
  • the first key is a root key for UE-SAT-UE communications.
  • the second key may include at least one of the following:
  • Integrity key used for integrity protection of UE-SAT-UE communication
  • Scrambling key used for scrambling protection of UE-SAT-UE communication
  • Replay attack protection key used for replay attack protection of service data in UE-SAT-UE communication.
  • the second network device determines authority of the first UE.
  • the second network device when the second network device determines that the first UE supports UE-SAT-UE communication according to the capability information of the first UE, the second network device obtains the first key.
  • S2103 The second network device sends a second message to the first UE.
  • the first UE has the authority for UE-SAT-UE communication and sends the second message to the first UE.
  • the second message is sent to an access network device of the first UE and forwarded or transparently transmitted to the first UE by the access network device.
  • the second message is a PDU session update response message.
  • the second message may be a PDU session update success message.
  • the corresponding rejection message or failure message may be a PDU session update failure message.
  • the second network device or the third network device determines that the first key will be provided to the first UE and sends a second indication to the first network device; otherwise, the second indication may not be provided to the first network device.
  • the second network device or the third network device provides a second indication to the first network device, otherwise the second indication may not be provided to the second network device.
  • the second indication is used by the first network device to determine whether end-to-end security of UE-SAT-UE communication of the first UE needs to be activated.
  • the second indication is used by the first network device to determine whether it is necessary to activate user plane UP end-to-end security of UE-SAT-UE communication of the first UE.
  • the second indication may be a specific indication to activate the end-to-end security of the UE-SAT-UE communication of the first UE. After receiving the second indication, the second network device knows that the end-to-end security of the UE-SAT-UE communication of the first UE needs to be activated.
  • the second network device may send a second indication to the first device specifically indicating the activation of end-to-end security for the UE-SAT-UE communication of the first UE.
  • the second indication may be used to indicate whether end-to-end security of UE-SAT-UE communication of the first UE is required, and the first network device determines whether end-to-end security of UE-SAT-UE communication of the first UE needs to be activated according to the indication content of the second indication. For example, according to the operator's policy, some services based on UE-SAT-UE communication of the first UE may need to activate UP security, while some services using UE-SAT-UE communication of the first UE do not need to activate UP security. In this case, the second network device needs to determine whether it is necessary to issue the second indication or the indication content of the second indication according to the service.
  • S2104 may be an optional step.
  • the UE and the base station may determine whether UP security needs to be activated during UE-SAT-UE communication based on a pre-configuration method such as a protocol agreement. In this case, this step may be an optional step.
  • the second network device when the first UE has the authority to conduct the PDU session based on UE-SAT-UE communication, the second network device sends a second indication to the first network device.
  • the second network device receives information related to the establishment of a PDU session sent or forwarded by the third network device. For example, the third network device sends information to the second network device only after determining that the first UE has the authority to conduct a PDU session based on UE-SAT-UE communication. After receiving the information sent by the third network device, the second network device considers that the first UE has the authority to conduct a PDU session based on UE-SAT-UE communication, and sends a second indication to the first network device.
  • the first network device sends first information to the first UE.
  • the first network device sends the first information to the first UE according to the second indication.
  • the second indication is used to indicate whether to activate the user plane UP end-to-end communication of the first UE Safety.
  • the second indication indicates activation of end-to-end security for UE-SAT-UE communications of the first UE.
  • the first indication is used to indicate whether the user plane UP end-to-end security of UE-SAT-UE communication is activated.
  • the first UE determines the second key based on the first key and the parameter value.
  • the first key is a root key for UE-SAT-UE communication.
  • the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
  • the second key when the first indication is used to indicate that user plane UP end-to-end security for UE-SAT-UE communication is not activated, the second key does not need to be determined based on the first key.
  • the first key may be a root key that may be used for one or more uses of the second key.
  • one second key may be used for one PDU session.
  • a second key can be used for a business communication.
  • the second key may be set with a validity period, and the second key may be used for one or more UE-SAT-UE communications within the validity period.
  • traffic of different UE-SAT-UE communications may have different second keys.
  • one service of UE-SAT-UE communication may have one second key.
  • the second key comprises at least one of: an integrity key; a confidentiality key.
  • the first UE determines the second key according to the first key after receiving the first information.
  • sending the first information by the first network device is an optional step, for example, the first UE defaults to UE-SAT-UE UP end-to-end security activation and does not need to receive parameter values from the first network device, then the first UE directly determines the second key based on the first key.
  • the first UE determining the second key according to the first key may include at least one of the following:
  • the first key, the length of the first key, the parameter value, and the length of the parameter value are input into KDF to obtain the second key output by KDF.
  • the second key can also be generated based on the type of the second key according to the algorithm type distinguisher and the first key; or, the second key can be generated based on the algorithm type distinguisher, the first key and the parameter value corresponding to the type of the second key.
  • the algorithm type specifiers corresponding to the integrity key and/or the confidentiality key are different.
  • an embodiment of the present disclosure provides a key processing method, which is performed by a first UE.
  • the method may include:
  • S3101 Send the first message.
  • the first message is related to UE-SAT-UE communication.
  • the first message may be any NAS message.
  • the registration authorization request message includes capability information of the first UE supporting UE-SAT-UE communication.
  • the first message is a PDU session establishment request message for UE-SAT-UE communication.
  • the first message may be a PDU session update request message for UE-SAT-UE communication.
  • the first message may be used by the first UE to request a first key from the network side.
  • the optional step of S3101 may refer to S2101 of the embodiment corresponding to FIG. 2 .
  • the first key may be pre-configured in a device or a subscriber identity module (SIM) of the first UE. In this case, the first UE does not need to request the first key through the first message.
  • SIM subscriber identity module
  • S3102 Receive the second message.
  • the first UE receives a second message sent by the second network device.
  • the first UE receives a second message sent by the second network device when the first UE has authority.
  • the relevant content of the second message can be found in the embodiment of FIG. 2 , and will not be repeated here.
  • S3102 can be omitted.
  • the second network device determines that the first UE does not have the authority, the first UE also cannot receive the second message, and S3102 can also be omitted.
  • S3103 Receive first information.
  • the first information is used by the first UE to determine whether user plane UP end-to-end security of UE-SAT-UE communication is activated.
  • the relevant description of the parameter value and the first indication can refer to the embodiment corresponding to FIG. 2 .
  • S3103 may be an optional step. For example, if the first UE activates UP end-to-end security of UE-SAT-UE communication by default, there is no need to receive the first indication from the network side. For another example, if the first UE does not need to use a parameter value when generating a second key based on the first key, and does not need to obtain a parameter value from any device on the network side such as the first network device, S3103 may be omitted.
  • S3104 Determine the second key based on the first key.
  • the first key may be pre-configured on the first UE or a SIM of the first UE.
  • the first key may be a root key for all UE-SAT-UE communications, in which case the root key may be a key known to all UEs supporting UE-SAT-UE communication or UEs with UE-SAT-UE communication authority.
  • S3104 can refer to S2106 of the corresponding embodiment of FIG. 2 .
  • the first network device may be a base station.
  • the first network device may be a satellite-borne base station.
  • the first network device determines whether it is necessary to activate the UP end-to-end security of the UE-SAT-UE communication of the first UE according to the second indication.
  • the second indication is used to indicate the activation of the user plane UP end-to-end security of the UE-SAT-UE communication of the first UE, and determines to activate the UP end-to-end security of the UE-SAT-UE communication of the first UE.
  • the second indication is used to indicate the deactivation of the UP end-to-end security of the UE-SAT-UE communication of the first UE, and determines to deactivate the UP end-to-end security of the UE-SAT-UE communication of the first UE.
  • a first indication is used to indicate whether to activate user plane UP end-to-end security of UE-SAT-UE communication;
  • the parameter value and the first key are used together to determine the second key.
  • the first information may include the first indication alone.
  • the second network device receives a first message from the first UE.
  • the second network device receives a first message forwarded or transparently transmitted by the first network device and/or the third network device.
  • the first message includes at least one of the following:
  • the registration authorization request message includes capability information of the first UE supporting UE-SAT-UE communication;
  • PDU session establishment request message for UE-SAT-UE communication PDU session establishment request message for UE-SAT-UE communication.
  • the relevant description of the first message can refer to the relevant description of the embodiment corresponding to Figure 2.
  • S5102 Send a second message.
  • the first key is the root key for UE-SAT-UE communication.
  • the first key is used by the first UE to generate the second key.
  • the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
  • the second network device determines that the first UE is a legitimate terminal, for example, a UE that has signed a contract with a communication operator, and then sends a second message to the first UE.
  • determining whether the first UE has authority may include at least one of the following:
  • determining whether the first UE has the authority may include: determining whether the first UE has the authority based on capability information and/or subscription data of the first UE.
  • a second message is sent to the first UE.
  • the second message may be forwarded or transparently transmitted to the first UE by one or more network devices.
  • the second message is not sent to the first UE.
  • a rejection message or a failure message is sent to the first UE.
  • the second message can be sent directly to the first UE.
  • determining whether the first UE has the authority may be performed by a third network device.
  • the second network device may receive information or a message indicating whether the first UE has the authority from the third network device.
  • the second network device determines to send a second message to the first UE, it will also send a second indication to the first network device of the first UE.
  • the second indication is used to indicate whether to activate the end-to-end security of the UE-SAT-UE communication of the first UE.
  • the second indication is used to indicate whether to activate the UP end-to-end security of the UE-SAT-UE communication of the first UE. It is worth noting that the step of the second network device sending the second indication is an optional step.
  • the step of the second network device sending the second indication can be omitted.
  • the second indication can also be sent by the third network device to the first network device of the first UE, in which case the step of the second network device sending the second indication can also be omitted.
  • an embodiment of the present disclosure provides a key processing method, which is executed by a third network device and includes:
  • the third network device may be an SMF or the like.
  • the third message may be any message for the first UE to request the establishment of a PDU session.
  • whether the first UE has the authority is determined based on the capability information and/or subscription information of the first UE.
  • determining whether the first UE has the authority according to the capability information and/or subscription information of the first UE may include but is not limited to at least one of the following:
  • the capability information of the first UE indicates that the first UE supports UE-SAT-UE communication and determines, according to the contract information, whether the first UE has the authority to sign up for UE-SAT-UE communication;
  • the capability information of the first UE indicates that the first UE does not support UE-SAT-UE communication and according to the contract information, it is determined that the first UE does not have the authority.
  • determining whether the first UE has the authority to subscribe to UE-SAT-UE communication based on the subscription information may include but is not limited to at least one of the following:
  • the contract information it is determined whether the first UE has signed up for end-to-end security of UE-SAT-UE communication.
  • S6103 Determine whether to agree to establish a PDU session for UE-SAT-UE communication.
  • whether to agree to establish a PDU session for UE-SAT-UE communication is determined based on whether the first UE has permission.
  • the first UE does not have the authority and determines that it does not agree to establish a PDU session for UE-SAT-UE communication.
  • the first UE has signed a contract for UE-SAT-UE communication and determines to agree to establish a PDU session for UE-SAT-UE communication.
  • the first UE has not signed up for UE-SAT-UE communication and determines that it does not agree to establish a PDU session for UE-SAT-UE communication.
  • the first UE has subscribed to the end-to-end security of UE-SAT-UE communication and determines to agree to establish a PDU session for UE-SAT-UE communication.
  • the first UE has not signed up for end-to-end security of UE-SAT-UE communication and determines that it does not agree to establish a PDU session for UE-SAT-UE communication.
  • the first UE does not have the authority and determines that it does not agree to establish a PDU session for UE-SAT-UE communication.
  • S6104 Agree to establish a PDU session for UE-SAT-UE communication and send a PDU session establishment request message.
  • the third network device agrees to establish a PDU session for UE-SAT-UE communication and sends a PDU session establishment request message to the second network device.
  • the PDU session establishment request message causes the second network device to send the first key to the first UE.
  • the first key is used by the first UE to determine the second key.
  • the second network device, the first key, the second key, etc. can be referred to the relevant description of the embodiment corresponding to FIG. 2.
  • the method may further include:
  • the third network device sends a second indication to the first network device of the first UE.
  • the second indication is used to indicate whether end-to-end security of UE-SAT-UE communication of the first UE is activated.
  • the third network device agrees to establish the PDU session of the UE-SAT-UE communication and sends a second indication to the first network device; the second indication is used to indicate whether the end-to-end security of the UE-SAT-UE communication of the first UE is activated.
  • the step of the third network device sending the second indication is an optional step.
  • the second indication may be sent by the second network device, or, in a scenario where the end-to-end security of UE-SAT-UE communication is activated by default or the end-to-end security of UE-SAT-UE communication does not need to be activated, the third network device may omit the step of sending the second indication.
  • the end-to-end security of UE-SAT-UE communication can be reactivated each time the first UE establishes a PDU session, and the first UE will regenerate a second key.
  • the validity period of the second key is equivalent to the duration of the corresponding PDU session.
  • different PDU sessions of the first UE may have different second keys.
  • an embodiment of the present disclosure provides a key processing method that can improve the security of UE-SAT-UT communication.
  • UE1 and/or UE2 initiate a service authorization (Service Authorization and Provisioning) process to the core network, and the PCF sends it to UE1 and/or UE2 through AMF1/AMF2 based on the contract information of UE1 and/or UE2.
  • PCF can query the root key (K E2E ) from the UDR or AF.
  • the contract information may indicate that the UE has signed a contract with the operator for a root key (K E2E ) for end-to-end secure communication of UE-SAT-UE.
  • K E2E root key
  • the gNB When the gNB activates Uu port UP security of UE1 and UE2 respectively, it sends the first end-to-end indication of UE-SAT-UE communication to UE1 and UE2.
  • the gNB When activating Uu port UP security for UE1 and UE2 respectively, the gNB sends an end-to-end first indication of UE-SAT-UE communication to UE1 and UE2. After receiving the end-to-end first indication of UE-SAT-UE communication from the gNB, UE1 and/or UE2 derives the key for end-to-end security protection of UP traffic based on the root key (K E2E ) received from the core network in step #1.
  • K E2E root key
  • the UP traffic exchanged between UE1 and UE2 through the gNB may be protected by a key for end-to-end security protection derived by UE1 and UE2.
  • the key may be the aforementioned second key.
  • the second key may be a key for UP security protection.
  • the second key may also be a key for CP security protection.
  • the second key may include K UP_E2E_int and K UP_E2E_enc .
  • K UP_E2E_int is the integrity key of UP.
  • K UP_E2E_enc is the confidentiality key of UP.
  • L0 length of algorithm type distinguisher
  • L1 length of algorithm identity
  • the algorithm type identifier is E2E-UP-enc-alg
  • the algorithm type identifier is E2E-UP-int-alg.
  • E2E-UP-enc-alg and E2E-UP-int-alg are pending values, ranging from 0x07 to 0xf0.
  • the core network function (NF) (such as PCF) should be able to send the root key (K E2E ) for UE-SAT-UE communication to the UE.
  • the NF e.g. PCF
  • the NF should be able to send the root key (K E2E ) for UE-SAT-UE communication to the UE during PDU session establishment.
  • the NF e.g. SMF and/or PCF
  • the NF shall be able to send a first indication to the gNB during PDU session establishment to activate end-to-end security for UE-SAT-UE communication.
  • the gNB shall be able to receive an indication from the core network to activate end-to-end security for UE-SAT-UE communication.
  • the gNB When Uu security is activated for a UE, the gNB shall be able to send an indication to the UE of end-to-end security for UE-SAT-UE communications.
  • the UE should be able to receive the root key (K E2E ) for end-to-end security of UE-SAT-UE communication from the core network (such as PCF).
  • K E2E root key
  • the UE needs to be able to derive the key for end-to-end security protection of the UP from the root key (K E2E ) received from the core network.
  • an embodiment of the present disclosure provides a key processing method, which may include:
  • UE1 derives the UP key (K UP_E2E ) based on the root key (K E2E ).
  • UE2 derives the UP key (K UP_E2E ) based on the root key (K E2E ).
  • an embodiment of the present disclosure provides a key processing method, which may include:
  • K E2E root key
  • UE1 derives the UP key (K UP_E2E ) based on the root key (K E2E ).
  • UE2 derives the UP key (K UP_E2E ) based on the root key (K E2E ).
  • part or all of the steps and their optional implementations may be arbitrarily combined with part or all of the steps in other embodiments, or may be arbitrarily combined with optional implementations of other embodiments.
  • part or all of the steps and their optional implementations may be arbitrarily combined with part or all of the steps in other embodiments, or may be arbitrarily combined with optional implementations of other embodiments.
  • the embodiments of the present disclosure also provide a device for implementing any of the above methods, for example, a device is provided, the above device includes a unit or module for implementing each step performed by the terminal in any of the above methods.
  • a device for example, a device is provided, the above device includes a unit or module for implementing each step performed by the terminal in any of the above methods.
  • another device is provided, including a unit or module for implementing each step performed by a network device (for example, an access network device, or a core network device, etc.) in any of the above methods.
  • a network device for example, an access network device, or a core network device, etc.
  • the units or modules in the device may be implemented in the form of hardware circuits, and the functions of some or all of the units or modules may be implemented by designing the hardware circuits.
  • the hardware circuits may be understood as one or more processors; for example, in one implementation, the hardware circuits are application-specific integrated circuits (ASICs), and the functions of some or all of the above units or modules may be implemented by designing the logical relationship of the components in the circuits; for another example, in another implementation, the hardware circuits may be implemented by programmable logic devices (PLDs), and Field Programmable Gate Arrays (FPGAs) may be used as an example, which may include a large number of logic gate circuits, and the connection relationship between the logic gate circuits may be configured by configuring the configuration files, thereby implementing the functions of some or all of the above units or modules. All units or modules of the above devices may be implemented in the form of software called by the processor, or in the form of hardware circuits, or in the form of software called by the processor, and the remaining part may be implemented in
  • a processor is a circuit with signal processing capability.
  • the processor may be a circuit with instruction reading and execution capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which may be understood as a microprocessor), or a digital signal processor (DSP).
  • the processor may implement certain functions through the logical relationship of hardware circuits, and the logical relationship of the hardware circuits is fixed or reconfigurable.
  • the processor is an application-specific integrated circuit ((((application-specific integrated circuit). It refers to a hardware circuit implemented by an ASIC (ASIC) or a programmable logic device (PLD), such as an FPGA.
  • ASIC application-specific integrated circuit
  • PLD programmable logic device
  • the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules.
  • it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
  • NPU neural network processing unit
  • TPU tensor processing unit
  • DPU deep learning processing unit
  • the sending module is configured to send a first message to the second network device; the first message is related to UE-SAT-UE communication;
  • the registration authorization request message includes capability information of the first UE supporting UE-SAT-UE communication;
  • the processing module 7201 is configured to determine a first key; the first key is a root key for UE-SAT-UE communication; the first key is used by the first UE to generate a second key; UE-SAT-UE communication.
  • the second network device may further include a sending module and/or a receiving module.
  • the processing module may be configured to execute any steps related to information processing in the key processing method executed by the second network device.
  • the receiving module is configured to receive a first message sent by a first UE; the first message is related to UE-SAT-UE;
  • the sending module is configured to send a second message to the first UE; the second message includes the first key.
  • the sending module is configured to perform at least one of the following:
  • the sending module is configured to send a second indication to a first network device connected to the first UE, where the second indication is used to indicate whether to activate user plane UP end-to-end security of UE-SAT-UE communication of the first UE.
  • the sending module is configured to establish a PDU session for UE-SAT-UE communication for the first UE, and send a second indication to a first network device accessed by the first UE.
  • an embodiment of the present disclosure provides a first network device, including:
  • the processing module may be configured to execute any steps related to information processing in the key processing method executed by the first network device.
  • the sending module and/or the receiving module may correspond to a network interface and/or a transceiver antenna of the first network device.
  • the receiving module is configured to receive a second indication sent by a second network device or a third network device; the second indication is used to indicate whether the end-to-end security of the UE-SAT-UE communication of the first UE is activated; the sending module is configured to send first information to the first UE to determine whether the user plane UP end-to-end security protection of the UE-SAT-UE communication of the first UE needs to be activated.
  • the first information also includes at least one of the following:
  • the first indication is used to indicate whether to activate end-to-end security of the UE-SAT-UE communication
  • a parameter value wherein the parameter value and the first key are used together to determine the second key.
  • an embodiment of the present disclosure provides a third network device, which includes:
  • the processing module may be configured to execute any steps related to information processing in the key processing method executed by the third network device.
  • An embodiment of the present disclosure further provides a communication device, which may include: one or more processors; wherein the processor is used to call instructions so that the communication device executes a key processing method that can be implemented in any of the aforementioned embodiments.
  • FIG. 9B is a schematic diagram of the structure of a chip 8200 provided in an embodiment of the present disclosure.
  • the communication device 8100 may be a chip or a chip system
  • the present disclosure also provides a program product, and when the program product is executed by the communication device 8100, the communication device 8100 executes any one of the above key processing methods.
  • the program product is a computer program product.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本公开实施例提供一种密钥处理方法、通信设备、通信系统及存储介质。由第一用户设备执行的密钥处理方法包括:根据第一密钥确定第二密钥;所述第一密钥为用户设备到卫星到用户设备UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。

Description

密钥处理方法、通信设备及存储介质 技术领域
本公开涉及通信技术领域,尤其涉及一种密钥处理方法、通信设备及存储介质。
背景技术
在将基站或者用户面功能(User Plane Function,UPF)集成到卫星的通信场景下,通信系统可支持用户设备到卫星到用户设备((User Equipment,UE)-Satellite-UE,UE-SAT-UE)通信。UE-SAT-UE通信是指:不经过路面的用户面(User Plane,UP)而是在一个或多个卫星覆盖下的本地交换实现UE之间的通信。
发明内容
本公开实施例提供一种密钥处理方法、通信设备及存储介质。
根据本公开实施例的第一方面,提供一种密钥处理方法,由第一用户设备UE执行,所述方法包括:根据第一密钥确定第二密钥;所述第一密钥为UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
根据本公开实施例的第二方面,提供一种密钥处理方法,其中,由第二网络设备执行,所述方法包括:确定第一密钥;所述第一密钥为UE-SAT-UE通信的根密钥;所述第一密钥用于第一用户设备UE生成第二密钥;UE-SAT-UE通信。
根据本公开实施例的第三方面,提供一种密钥处理方法,其中,由第一网络设备执行,所述方法包括:向第一用户设备UE发送第一信息;所述第一信息至少包括第一指示;所述第一指示用于指示UE-SAT-UE通信的端到端安全是否激活,使得所述第一UE根据第一密钥生成第二密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
根据本公开实施例的第四方面,提供一种密钥处理方法,其中,由第三网络设备执行,所述方法包括:接收第一用户设备UE的第三消息;所述第三消息用于请求建立所述第一UE与至少一个第二UE之间UE-SAT-UE通信的协议数据单元(Protocol Data Unit,PDU)会话;确定所述第一UE具有所述UE-SAT-UE通信的权限或具有所述UE-SAT-UE通信的端到端安全权限;所述第一UE具有所述UE-SAT-UE通信的权限或具有所述UE-SAT-UE通信的端到端安全权限,确定同意建立所述UE-SAT-UE通信的PDU会话;同意建立所述UE-SAT-UE通信的PDU会话,向第二网络设备发送PDU会话建立请求消息;所述PDU会话建立请求消息,用于所述第二网络设备向所述第一UE提供第一密钥;所述第一密钥为UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
根据本公开实施例第五方面,提供一种第一用户设备UE,其中,包括:处理模块,被配置为根据第一密钥确定第二密钥;所述第一密钥为UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
根据本公开实施例第六方面,提供一种第二网络设备,其中,包括:处理模块,被配置为确定第一密钥;所述第一密钥为UE-SAT-UE通信的根密钥;所述第一密钥用于第一用户设备UE生成第二密钥;UE-SAT-UE通信。
根据本公开实施例第七方面,提供一种第一网络设备,其中,包括:发送模块,被配置为向第一用户设备UE发送第一信息;所述第一信息至少包括第一指示;所述第一指示用于指示UE-SAT-UE通信的端到端安全是否激活,使得所述第一UE根据第一密钥生成第二密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
根据本公开实施例第八方面,提供一种第三网络设备,其中,包括:接收模块,被配置为接收第一用户设备UE的第三消息;所述第三消息用于请求建立所述第一UE与至少一个第二UE之间UE-SAT-UE通信的协议数据单元PDU会话;处理模块,被配置为确定所述第一UE具有所述UE-SAT-UE通信的权限或具有所述UE-SAT-UE通信的端到端安全权限;所述第一UE具有所述UE-SAT-UE通信的权限或具有所述UE-SAT-UE通信的端到端安全权限,确定同意建立所述UE-SAT-UE通信的PDU会话;发送模块,被配置为同意建立所述UE-SAT-UE通信的PDU会话,向第二网络设备发送PDU会话建立请求消息;所述PDU会话建立请求消息,用于所述第二网络设备向所述第一UE提供第一密钥;所述第一密钥为UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
根据本公开实施例的第九方面,提供一种通信设备,其中,通信设备包括:一个或多个处理器;其中,处理器用于调用指令以使得通信设备执行前述第一方面至第四方面任意技术方案提供的密钥 处理方法。
根据本公开实施例的第十方面,提供一种存储介质,其中,存储介质存储有指令,当指令在通信设备上运行时,使得通信设备执行第一方面至第四方面任意方面提供的密钥处理方法。
本公开实施例提供的技术方案,第一UE会根据第一密钥确定第二密钥,如此,后续第一UE和第二UE之间的UE-SAT-UE通信进行端到端的安全保护,提升了第一UE和第二UE之间UE-SAT-UE通信的安全性。
应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本公开实施例。
附图说明
此处的附图被并入说明书中并构成本说明书的一部分,示出了符合本公开实施例,并与说明书一起用于解释本公开实施例的原理。
图1A是根据一示例性实施例示出的一种通信系统的架构示意图;
图1B是根据一示例性实施例示出的一种通信系统的架构示意图;
图1C是根据一示例性实施例示出的一种通信系统的架构示意图;
图2是根据一示例性实施例示出的一种密钥处理方法的流程示意图;
图3是根据一示例性实施例示出的一种密钥处理方法的流程示意图;
图4是根据一示例性实施例示出的一种密钥处理方法的流程示意图;
图5是根据一示例性实施例示出的一种密钥处理方法的流程示意图;
图6是根据一示例性实施例示出的一种密钥处理方法的流程示意图;
图7A是根据一示例性实施例示出的一种密钥处理方法的流程示意图;
图7B是根据一示例性实施例示出的一种密钥处理方法的流程示意图;
图8A是根据一示例性实施例示出的一种第一UE的结构示意图;
图8B是根据一示例性实施例示出的一种第二网络设备的结构示意图;
图8C是根据一示例性实施例示出的一种第一网络设备的结构示意图;
图8D是根据一示例性实施例示出的一种第三网络设备的结构示意图;
图9A是根据一示例性实施例示出的一种通信设备的结构示意图;
图9B是根据一示例性实施例示出的一种芯片的结构示意图。
具体实施方式
本公开实施例提供一种密钥处理方法、通信设备及存储介质。
第一方面提供一种密钥处理方法,由第一用户设备UE执行,方法包括:
根据第一密钥确定第二密钥;第一密钥为UE-SAT-UE通信的根密钥;第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
基于上述方案,第一UE会根据第一密钥确定第二密钥,如此,后续第一UE和第二UE之间的UE-SAT-UE通信进行端到端的安全保护,提升了第一UE和第二UE之间UE-SAT-UE通信的安全性。
在第一方面的一些实施例中,方法还包括:接收第一网络设备发送的第一信息;第一信息至少用于第一UE确定是否激活UE-SAT-UE通信的用户面UP端到端安全;根据第一密钥确定第二密钥,包括:在UE-SAT-UE通信的端到端安全激活的情况下,根据第一密钥确定第二密钥。
基于上述方案,第一UE可以根据第一信息确定是否需要激活UE-SAT-UE通信的端到端安全的情况下,根据第一密钥确定第二密钥,从而减少了无需进行UE-SAT-UE通信的端到端安全时的不必要的密钥生成。
在第一方面的一些实施例中,第一信息还包括以下至少之一:第一指示,第一指示用于指示是否激活UE-SAT-UE通信的端到端安全;参数值,参数值和第一密钥共同用于确定第二密钥。
基于上述方案限定了第一信息的具体内容,第一信息可仅包括第一指示、第一信息可仅包括参数值,第一信息可同时包括第一指示和参数值。在一些情况下第一信息还可以包括其他内容。总之,上述仅仅是第一信息的距离,具体实现时刻根据需要灵活设置。
在第一方面的一些实施例中,在UE-SAT-UE通信的端到端安全激活的情况下,根据第一密钥确定第二密钥,包括以下至少之一:根据第一密钥和参数值生成第二密钥;根据第一密钥生成第二密钥。基于上述方案限定了在UE-SAT-UE通信端到端安全激活的情况下生成第二密钥的两种可选方式,具有实现简单的优点。
在第一方面的一些实施例中,方法包括:向第二网络设备发送第一消息;第一消息与UE-SAT-UE通信相关;接收第二网络设备发送的第二消息;第二消息包括第一密钥。
上述方案,提供了第一UE触发第二网络设备分发第一密钥的方式,具体实现时第一UE获取第一密钥的方式不局限于从第二网络设备请求。
在第一方面的一些实施例中,第一消息包括以下至少之一:注册授权请求消息;注册授权请求信息包括第一UE支持UE-SAT-UE通信的能力信息;UE-SAT-UE通信的协议数据单元PDU会话建立请求消息。
基于上述方案提供了第一消息的两种可选消息,都是复用了具有其他功能的消息,从而与相关技术的兼容性强,且无须设置新的消息也可以触发第二网络设备向第一UE提供第一密钥。
在第一方面的一些实施例中,第二密钥包括以下至少之一:完整性密钥;机密性密钥。
基于上述方案,此处的UE-SAT-UE通信的端到端安全保护可包括完整性保护和/或机密性保护,从而确保了UE-SAT-UE通信的端到端安全性。
第二方面提供一种密钥处理方法,其中,由第二网络设备执行,方法包括:确定第一密钥;第一密钥为UE-SAT-UE通信的根密钥;第一密钥用于第一用户设备UE生成第二密钥;UE-SAT-UE通信。
在第二方面的一些实施例中,方法还包括:接收第一UE发送的第一消息;第一消息与UE-SAT-UE相关;向第一UE发送第二消息;第二消息包括第一密钥。
在第二方面的一些实施例中,第一消息为注册授权请求消息;注册授权请求消息包括第一UE的能力信息;向第一UE发送第二消息,包括;第一UE的能力信息指示第一UE是否支持UE-SAT-UE通信或第一UE是否支持UE-SAT-UE通信的端到端安全,向第一UE发送包括第二消息。
在第二方面的一些实施例中,向第一UE发送第二消息,包括以下至少之一;第一消息为UE-SAT-UE通信的协议数据单元PDU会话建立请求消息且第二网络设备确定第一UE具有UE-SAT-UE通信的权限,向第一UE发送第二消息;第一消息为UE-SAT-UE通信的协议数据单元PDU会话建立请求消息且第二网络设备确定第一UE具有UE-SAT-UE通信的端到端安全权限,向第一UE发送第二消息;第一消息为UE-SAT-UE通信的协议数据单元PDU会话建立请求消息且第三网络设备同意为第一UE建立UE-SAT-UE通信的PDU会话,向第一UE发送第二消息。
在第二方面的一些实施例中,方法还包括:根据第一UE的签约信息,确定第一UE是否签约UE-SAT-UE通信;第一UE有签约UE-SAT-UE通信,确定向第一UE发送第二消息。
在第二方面的一些实施例中,方法还包括:根据第一UE的签约信息,确定第一UE是否签约UE-SAT-UE通信的端到端安全;第一UE签约UE-SAT-UE通信的端到端安全,确定向第一UE发送第二消息。
在第二方面的一些实施例中,方法还包括:向第一UE连接的第一网络设备发送第二指示,第二指示用于指示是否激活第一UE的UE-SAT-UE通信的用户面UP端到端安全。
在第二方面的一些实施例中,向第一UE连接的第一网络设备发送第二指示,包括:为第一UE建立UE-SAT-UE通信的PDU会话,向第一UE接入的第一网络设备发送第二指示。
第三方面提供一种密钥处理方法,其中,由第一网络设备执行,方法包括:向第一用户设备UE发送第一信息;所述第一信息至少用于指示用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全是否激活,以使得第一UE根据第一密钥生成第二密钥;第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
在第三方面的一些实施例中,方法包括:接收第二网络设备或第三网络设备发送的第二指示;第二指示用于指示是否激活第一UE的UE-SAT-UE通信的端到端安全;向第一用户设备UE发送第一指示,包括:是否需要激活第一UE的UE-SAT-UE通信的端到端安全保护,向第一UE发送第一信息。
在第三方面的一些实施例中,所述第一信息还包括以下至少之一:第一指示,所述第一指示用于指示是否激活所述UE-SAT-UE通信的端到端安全;参数值,所述参数值和所述第一密钥共同用于确定所述第二密钥。
第四方面提供一种密钥处理方法,其中,由第三网络设备执行,方法包括:
接收第一用户设备UE的第三消息;第三消息用于请求建立第一UE与至少一个第二UE之间UE-SAT-UE通信的协议数据单元PDU会话;确定第一UE具有UE-SAT-UE通信的权限或具有UE-SAT-UE通信的端到端安全权限;第一UE具有UE-SAT-UE通信的权限或具有UE-SAT-UE通信的端到端安全权限,确定同意建立UE-SAT-UE通信的PDU会话;同意建立UE-SAT-UE通信的PDU会话,向第二网络设备发送PDU会话建立请求消息;PDU会话建立请求消息,用于第二网络设备向第一UE提供第一密钥;第一密钥为UE-SAT-UE通信的根密钥;第二密钥用于第一UE与至少一 个第二UE之间UE-SAT-UE通信的端到端安全保护。
在第四方面的一些实施例中,该方法还可包括:
同意建立所述UE-SAT-UE通信的PDU会话,向第一网络设备发送第二指示;所述第二指示用于指示所述第一UE的UE-SAT-UE通信的端到端安全是否激活。
第五方面提供一种第一用户设备UE,其中,包括:处理模块,被配置为根据第一密钥确定第二密钥;第一密钥为UE-SAT-UE通信的根密钥;第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
第六方面提供一种第二网络设备,其中,包括:处理模块,被配置为确定第一密钥;第一密钥为UE-SAT-UE通信的根密钥;第一密钥用于第一用户设备UE生成第二密钥;UE-SAT-UE通信。
第七方面提供一种第一网络设备,其中,包括:发送模块,被配置为向第一用户设备UE发送第一信息;第一信息至少包括第一指示;第一指示用于指示UE-SAT-UE通信的端到端安全是否激活,使得第一UE根据第一密钥生成第二密钥;第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
第八方面提供一种第三网络设备,其中,包括:接收模块,被配置为接收第一用户设备UE的第三消息;第三消息用于请求建立第一UE与至少一个第二UE之间UE-SAT-UE通信的协议数据单元PDU会话;处理模块,被配置为确定第一UE具有UE-SAT-UE通信的权限或具有UE-SAT-UE通信的端到端安全权限;第一UE具有UE-SAT-UE通信的权限或具有UE-SAT-UE通信的端到端安全权限,确定同意建立UE-SAT-UE通信的PDU会话;发送模块,被配置为同意建立UE-SAT-UE通信的PDU会话,向第二网络设备发送PDU会话建立请求消息;PDU会话建立请求消息,用于第二网络设备向第一UE提供第一密钥;第一密钥为UE-SAT-UE通信的根密钥;第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
第九方面提供一种通信设备,通信设备包括:一个或多个处理器;
其中,处理器用于调用指令以使得通信设备执行第一方面至第四方面的可选实现方式所描述的密钥处理方法。
第十方面,本公开实施例提供了一种存储介质,其中,存储介质存储有指令,当指令在通信设备上运行时,使得通信设备执行第一方面至第四方面的可选实现方式所描述的密钥处理方法。
第十一方面,本公开实施例提供了一种程序产品,程序产品被通信设备执行时,使得通设备执行第一方面至第四方面的可选实现方式所描述的密钥处理方法。
第十二方面,本公开实施例提供了一种计算机程序,当其在计算机上运行时,使得计算机执行第一方面至第四方面的可选实现方式所描述的密钥处理方法。
可以理解地,上述终端、网络设备以及通信系统、程序产品、计算机程序均用于执行本公开实施例所提供的方法。因此,其所能达到的有益效果可以参考对应方法中的有益效果,此处不再赘述。
本公开实施例提出了一种密钥处理方法、通信设备、通信系统及存储介质。本公开实施例并非穷举,仅为部分实施例的示意,不作为对本公开保护范围的具体限制。在不矛盾的情况下,某一实施例中的每个步骤均可以作为独立实施例来实施,且各步骤之间可以任意组合,例如,在某一实施例中去除部分步骤后的方案也可以作为独立实施例来实施,且在某一实施例中各步骤的顺序可以任意交换,另外,某一实施例中的可选实现方式可以任意组合;此外,各实施例之间可以任意组合,例如,不同实施例的部分或全部步骤可以任意组合,某一实施例可以与其他实施例的可选实现方式任意组合。
在各本公开实施例中,如果没有特殊说明以及逻辑冲突,各实施例之间的术语和/或描述具有一致性,且可以互相引用,不同实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
本公开实施例中所使用的术语只是为了描述特定实施例的目的,而并非作为对本公开的限制。
在本公开实施例中,除非另有说明,以单数形式表示的元素,如“一个”、“一种”、“该”、“上述”、、“前述”、“这一”等,可以表示“一个且只有一个”,也可以表示“一个或多个”、“至少一个”等。例如,在翻译中使用如英语中的“a”、“an”、“the”等冠词(article)的情况下,冠词之后的名词可以理解为单数表达形式,也可以理解为复数表达形式。
在本公开实施例中,“多个”是指两个或两个以上。
在一些实施例中,“至少一者(至少之一、至少一项、至少一个)(at least one of)”、“一个或多个(one or more)”、“多个(a plurality of)”、“多个(multiple)等术语可以相互替换。
在一些实施例中,“A、B中的至少一者”、“A和/或B”、“在一情况下A,在另一情况下B”、“一情况A,另一情况B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关 地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行);在一些实施例中A和B(A和B都被执行)。当有A、B、C等更多分支时也类似上述。
在一些实施例中,“A或B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行)。当有A、B、C等更多分支时也类似上述。
本公开实施例中的“第一”、“第二”等前缀词,仅仅为了区分不同的描述对象,不对描述对象的位置、顺序、优先级、数量或内容等构成限制,对描述对象的陈述参见权利要求或实施例中上下文的描述,不应因为使用前缀词而构成多余的限制。例如,描述对象为“字段”,则“第一字段”和“第二字段”中“字段”之前的序数词并不限制“字段”之间的位置或顺序,“第一”和“第二”并不限制其修饰的“字段”是否在同一个消息中,也不限制“第一字段”和“第二字段”的先后顺序。再如,描述对象为“等级”,则“第一等级”和“第二等级”中“等级”之前的序数词并不限制“等级”之间的优先级。再如,描述对象的数量并不受序数词的限制,可以是一个或者多个,以“第一装置”为例,其中“装置”的数量可以是一个或者多个。此外,不同前缀词修饰的对象可以相同或不同,例如,描述对象为“装置”,则“第一装置”和“第二装置”可以是相同的装置或者不同的装置,其类型可以相同或不同;再如,描述对象为“信息”,则“第一类信息”和“第二类信息”可以是相同的信息或者不同的信息,其内容可以相同或不同。
在一些实施例中,“包括A”、“包含A”、“用于指示A”、“携带A”,可以解释为直接携带A,也可以解释为间接指示A。
在一些实施例中,“……”、“确定……”、“在……的情况下”、“在……时”、“当……时”、“若……”、“如果……”等术语可以相互替换。
在一些实施例中,“大于”、“大于或等于”、“不小于”、“多于”、“多于或等于”、“不少于”、“高于”、“高于或等于”、“不低于”、“以上”等术语可以相互替换,“小于”、“小于或等于”、“不大于”、“少于”、“少于或等于”、“不多于”、“低于”、“低于或等于”、“不高于”、“以下”等术语可以相互替换。
在一些实施例中,装置等可以解释为实体的、也可以解释为虚拟的,其名称不限定于实施例中所记载的名称,“装置”、“设备(equipment)”、“设备(device)”、“电路”、“网元”、“节点”、“功能”、“单元”、“部件(section)”、“系统”、“网络”、“芯片”、“芯片系统”、“实体”、“主体”等术语可以相互替换。
在一些实施例中,“网络”可以解释为网络中包含的装置(例如,接入网设备、核心网设备等)。
在一些实施例中,“接入网设备(access network device,AN device)”、“无线接入网设备(radio access network device,RAN device)”、“基站(base station,BS)”、“无线基站(radio base station)”、“固定台(fixed station)”、“节点(node)”、“接入点(access point)”、“发送点(transmission point,TP)”、“接收点(reception point,RP)”、“发送接收点(transmission/reception point,TRP)”、“面板(panel)”、“天线面板(antenna panel)”、“天线阵列(antenna array)”、“小区(cell)”、“宏小区(macro cell)”、“小型小区(small cell)”、“毫微微小区(femto cell)”、“微微小区(pico cell)”、“扇区(sector)”、“小区组(cell group)”、“服务小区”、“小区(carrier)”、“分量小区(component carrier)”、“带宽部分(bandwidth part,BWP)”等术语可以相互替换。
在一些实施例中,“终端(terminal)”、“终端设备(terminal device)”、“用户设备(user equipment,UE)”、“用户终端(user terminal)”、“移动台(mobile station,MS)”、“移动终端(mobile terminal,MT)”、订户站(subscriber station)、移动单元(mobile unit)、订户单元(subscriber unit)、无线单元(wireless unit)、远程单元(remote unit)、移动设备(mobile device)、无线设备(wireless device)、无线通信设备(wireless communication device)、远程设备(remote device)、移动订户站(mobile subscriber station)、接入终端(access terminal)、移动终端(mobile terminal)、无线终端(wireless terminal)、远程终端(remote terminal)、手持设备(handset)、用户代理(user agent)、移动客户端(mobile client)、客户端(client)等术语可以相互替换。
在一些实施例中,接入网设备、核心网设备、或网络设备可以被替换为终端。例如,针对将接入网设备、核心网设备、或网络设备以及终端间的通信置换为多个终端间的通信(例如,设备对设备(device-to-device,D2D)、车联网(vehicle-to-everything,V2X)等)的结构,也可以应用本公开的各实施例。在该情况下,也可以设为终端具有接入网设备所具有的全部或部分功能的结构。此外,“上行”、“下行”等术语也可以被替换为与终端间通信对应的术语(例如,“侧行(side)”)。例如,上行信道、下行信道等可以被替换为侧行信道,上行链路、下行链路等可以被替换为侧行链路。
在一些实施例中,终端可以被替换为接入网设备、核心网设备、或网络设备。在该情况下,也可以设为接入网设备、核心网设备、或网络设备具有终端所具有的全部或部分功能的结构。
在一些实施例中,获取数据、信息等可以遵照所在地国家的法律法规。
在一些实施例中,可以在得到用户同意后获取数据、信息等。
此外,本公开实施例的表格中的每一元素、每一行、或每一列均可以作为独立实施例来实施,任意元素、任意行、任意列的组合也可以作为独立实施例来实施。
图1A是根据本公开实施例示出的通信系统的架构示意图。
如图1A所示,通信系统100包括终端(terminal)101以及网络设备102。网络设备102可包括接入网设备和/或核心网设备。
在一些实施例中,终端101例如包括手机(mobile phone)、可穿戴设备、物联网设备、具备通信功能的汽车、智能汽车、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、工业控制(industrial control)中的无线终端设备、无人驾驶(self-driving)中的无线终端设备、远程手术(remote medical surgery)中的无线终端设备、智能电网(smart grid)中的无线终端设备、运输安全(transportation safety)中的无线终端设备、智慧城市(smart city)中的无线终端设备、智慧家庭(smart home)中的无线终端设备中的至少一者,但不限于此。
在一些实施例中,终端又称为用户设备(User Equipment,UE)。
在一些实施例中,接入网设备例如可以是将终端接入到无线网络的节点或设备,接入网设备可以包括5G通信系统中的演进节点B(evolved NodeB,eNB)、下一代演进节点B(next generation eNB,ng-eNB)、下一代节点B(next generation NodeB,gNB)、节点B(node B,NB)、家庭节点B(home node B,HNB)、家庭演进节点B(home evolved nodeB,HeNB)、无线回传设备、无线网络控制器(radio network controller,RNC)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、基带单元(base band unit,BBU)、移动交换中心、6G通信系统中的基站、开放型基站(Open RAN)、云基站(Cloud RAN)、其他通信系统中的基站、Wi-Fi系统中的接入节点中的至少一者,但不限于此。
在一些实施例中,本公开的技术方案可适用于Open RAN架构,此时,本公开实施例所涉及的接入网设备间或者接入网设备内的接口可变为Open RAN的内部接口,这些内部接口之间的流程和信息交互可以通过软件或者程序实现。
在一些实施例中,接入网设备可以由集中单元(central unit,CU)与分布式单元(distributed unit,DU)组成的,其中,CU也可以称为控制单元(control unit),采用CU-DU的结构可以将接入网设备的协议层拆分开,部分协议层的功能放在CU集中控制,剩下部分或全部协议层的功能分布在DU中,由CU集中控制DU,但不限于此。
在一些实施例中,核心网设备可以是一个设备,包括第一网元等,也可以是多个设备或设备群,分别包括第一网元。网元可以是虚拟的,也可以是实体的。核心网例如包括演进分组核心(Evolved Packet Core,EPC)、5G核心网络(5G Core Network,5GCN)、下一代核心(Next Generation Core,NGC)中的至少一者。
可以理解的是,本公开实施例描述的通信系统是为了更加清楚的说明本公开实施例的技术方案,并不构成对于本公开实施例提供的技术方案的限定,本领域普通技术人员可知,随着系统架构的演变和新业务场景的出现,本公开实施例提供的技术方案对于类似的技术问题同样适用。
下述本公开实施例可以应用于图1A所示的通信系统100、或部分主体,但不限于此。图1A所示的各主体是例示,通信系统可以包括图1A中的全部或部分主体,也可以包括图1A以外的其他主体,各主体数量和形态为任意,各主体之间的连接关系是例示,各主体之间可以不连接也可以连接,其连接可以是任意方式,可以是直接连接也可以是间接连接,可以是有线连接也可以是无线连接。
本公开各实施例可以应用于长期演进(Long Term Evolution,LTE)、LTE-Advanced(LTE-A)、LTE-Beyond(LTE-B)、SUPER 3G、IMT-Advanced、第四代移动通信系统(4th generation mobile communication system,4G)、)、第五代移动通信系统(5th generation mobile communication system,5G)、5G新空口(new radio,NR)、未来无线接入(Future Radio Access,FRA)、新无线接入技术(New-Radio Access Technology,RAT)、新无线(New Radio,NR)、新无线接入(New radio access,NX)、未来一代无线接入(Future generation radio access,FX)、Global System for Mobile communications(GSM(注册商标))、CDMA2000、超移动宽带(Ultra Mobile Broadband,UMB)、IEEE 802.11(Wi-Fi(注册商标))、IEEE 802.16(WiMAX(注册商标))、IEEE 802.20、超宽带 (Ultra-WideBand,UWB)、蓝牙(Bluetooth(注册商标))、陆上公用移动通信网(Public Land Mobile Network,PLMN)网络、设备到设备(Device-to-Device,D2D)系统、机器到机器(Machine to Machine,M2M)系统、物联网(Internet of Things,IoT)系统、车联网(Vehicle-to-Everything,V2X)、利用其他资源的配置方法的系统、基于它们而扩展的下一代系统等。此外,也可以将多个系统组合(例如,LTE和NR的组合)。
图1B所示为一个支持UE-SAT-UE的网络系统,可包括:UE1、UE2、搭载在卫星X上的gNB。卫星X上的gNB与地面之间具有反馈链路(feeder link)。该反馈链路可用于卫星X上的gNB连接到核心网,例如,连接到核心网的接入管理功能(Access Management Function,AMF)等。卫星X上的gNB有形成卫星小区A,小区A可以与地面小区相邻。地面小区可由地面基站形成。卫星X上的gNB和UE1和UE2之间的Uu口之间的连接是卫星链路。如此,UE1和UE2之间,可以基于卫星X上的基站进行用户面数据的传输。但值得注意的是:图1B中使用两个UE代表UE-SAT-UE之间的通信,但是这种通信可以涉及两一个以上的UE之间。UE-SAT-UE通信的多个UE可以位于一个小区,也可以位于不同的小区。UE-SAT-UE通信涉及的卫星个数可以是一个,也可以是多个。在图1B中AMF仅仅是核心网的网络功能的代表,实际上核心网的网络功能不局限于AMF,具体核心网的网络功能还可包括会话管理功能(Session Management Function,SMF)。如图1B所示,搭载在卫星(Satellite,SAT)x上的gNB与地面之间的连接可用于控制面(Control Plane,CP)面信令交互。
图1C所示的为两个进行UE-SAT-UE通信的UE位于不同的小区内,且不同小区对应了不同基站和/或用户面功能(User Plane Function,UPF),此时需要卫星之间的建立连接(或说链路)。卫星之间具有跨卫星链路(Inter Satellite Link(s),ISL)。ISL可以使得卫星可以通过ISL连接到其他卫星,并通过其他卫星连接到地面,如此,相当于ISL可以使得卫星与地面之间的连接随时可用。在本地交换能力涉及到多个卫星时,UE-SAT-UE通信可以扩展到一个或多个卫星的覆盖范围,
Uu口的用户面(User Plane,UP)数据流的安全是基于核心网提供的安全策略的,该安全策略可由用户数据管理(User Data Management,UDM)设置,也可由会话管理功能(Session Management Function,SMF)基于UE请求的特定业务设置。例如,SMF在PDU会话建立的过程可根据UP安全增强信息设置安全策略。该UP安全增强信息可包括但不限于以下至少之一:
签约的UP安全策略,该签约的UP安全策略可是从UDM接收的且属于会话管理签约信息的一部分;
UP安全策略可是针对单个数据网络名字(Date Network Name,DNN)和单网片选择辅助信息(Single Network Slice Selection Assistance Information,S-NSSAI)的本地策略。该本地的UP安全策略可以是在UDM未提供签约的UP安全策略时使用。
UP安全策略表示该PDU会话在Uu口上是否激活UP安全保护。UP安全策略可用于激活PDU会话的UP机密性和/或UP完整性。根据SMF提供的UP安全策略,如果该UP安全策略为需要(Required),则gNB通过RRC信令对每个数据无线承载(Data Radio Bearer,DRB)激活Uu口的UP安全保护。如果策略显示为不需要(Not need),则在不受保护的情况下继续建立PDU会话。如果策略为优选(Preferred),则gNB可以决定是否激活Uu口的UP安全保护。但是当UP安全策略指示为需要(Required)或不需要(Not need)时,gNB不能否决从SMF接收到的UP安全策略。
对于使用现有机制通过第五移动通信(5th Generation,5G)网络进行的传统UE到UE通信,UE通过可能单独的gNB分别与核心网建立单独的PDU会话。然后,gNB在各终端的PDU会话中应用不同的UP安全策略。
对于在本地交换UP流量而不让其通过核心网络功能(例如SMF)所在的地面网络的UE-SAT-UE通信,可以重用现有机制来为UE-SAT-UE通信建立两个单独的PDU会话。但是,如果通信终端具有不同的UP安全策略,则可能导致对单个UE-SAT-UE通信会话的两个Uu口应用不同的安全保护。在这种情况下,两个Uu口上的安全保护可能不一致,一个Uu口上的高安全保护(例如完整性和机密性保护)可能被另一个Uu口上的低安全保护(例如只有完整性保护或只有机密性保护或没有保护)所掩盖。
对Uu口的安全保护终止于gNB,即需要发送终端的gNB将上行UP流量进行解码,需要接收终端的gNB对发送终端的下行UP流量进行编码。当UP业务需要在发送终端的gNB和接收终端的gNB之间通过卫星间链路传输时,对ISL上UP业务的保护只能依赖于ISL上应用的安全性,而ISL可能不受运营商的控制。因此,两个Uu口上携带的UP流量在传输链路上可能无法得到一致的保护。在这种情况下,UP流量可能有被恶意/行为不端的实体(例如卫星间链路之间的实体)篡改的。
如果在两个通信终端之间进行端到端保护,则可以实现对两个Uu口携带的UP流量和在UE-SAT-UE通信传输链路上的一致保护。然而,对于UE-SAT-UE通信的UP业务,目前还没有端到端保护的解决方案,需要进一步研究。
确保两个通信终端之间应用端到端保护,使两个Uu口承载的UP流量保护在UE-SAT-UE通信传输链路上保持一致。
如图2所示,本公开实施例提供一种密钥处理方法,由通信系统执行。该方法可包括:
S2101:第一UE向第二网络设备发送第一消息。
在一些实施例中,第二网络设备可为包括但不限于核心网设备,例如,第二网络设备可为部署在核心网内的网络功能(Network Function,NF)。
在一些实施例中,第二网络设备可为策略控制功能(Policy Control Function,PCF)。
在一些实施例中,第一UE通过如1B和图1C所示的服务链路、卫星上的基站向第二网络设备发送第一消息。卫星上的gNB转发或透传第一消息至第二网络设备。
在一些实施例中,第一消息可为第一UE在注册授权认证过程发送的任何消息。
在一些实施例中,第一消息可为授权请求消息。
在一些实施例中,第一消息可为UE-SAT-UE通信的授权请求消息。
在一些实施例中,第一消息可为PDU会话建立请求消息。
在一些实施例中,第一消息可为PDU会话修改请求消息。
在一些实施例中,第一消息至少包括:
第一UE的标识信息;
第一UE的能力信息。
UE-SAT-UE通信的业务标识;
UE-SAT-UE通信使用的数据网络的网络信息;
UE-SAT-UE通信使用的网络切片的切片信息。
在一些实施例中,第一UE的标识信息可包括但不限于第一UE的应用层标识(例如,用户信息标识(User Info)、用户永久标识符(SUbscription Permanent Identifier,SUPI)等。
在一些实施例中,能力信息可指示以下至少之一:
第一UE支持的通信类型;
第一UE支持的业务。
在一些实施例中,如此,第二网络设备收到能力信息之后,可以根据UE的签约信息确定UE支持的能力和/或业务是否有签约授权。
在一些实施例中,能力信息可用于指示第一UE是否支持UE-SAT-UE通信或第一UE是否支持UE-SAT-UE通信的端到端安全。
在一些实施例中,UE-SAT-UE通信可配置有一个或多个业务,这些业务的业务流量可基于UE-SAT-UE通信传输。
在一些实施例中,UE-SAT-UE通信也可以称之为本地通信或者基于卫星的本地通信。
S2102:第二网络设备获取第一密钥。
在一些实施例中,第二网络设备生成UE-SAT-UE通信的第一密钥。
在一些实施例中,第二网络设备从提供UE-SAT-UE通信的应用服务器接收第一密钥。
在一些实施例中,第二网络设备从用户数据管理(User Data Management,UDM)或者用户数据统一仓储(Unified Data Repository,UDR)接收第一密钥。
在一些实施例中,第一密钥为UE-SAT-UE通信的根密钥。
在一些实施例中,第一密钥用于生成第二密钥。
在一些实施例中,第一密钥不限于根密钥,还可以是生成第二密钥的中间密钥。
在一些实施例中,第一密钥用于生成用于UE-SAT-UE通信的第二密钥。
在一些实施例中,第一密钥为UE-SAT-UE通信的根密钥。
在一些实施例中,第二密钥可包括以下至少之一:
完整性密钥,用于UE-SAT-UE通信的完整性保护;
机密性密钥,用于UE-SAT-UE通信的机密性保护;
加扰密钥,用于UE-SAT-UE通信的加扰保护;
重放攻击保护密钥,用于UE-SAT-UE通信的业务数据的重放攻击保护。
在一些实施例中,第二网络设备确定第一UE的权限。
在一些实施例中,第二网络设备在确定第一UE具有权限的情况下,获取第一密钥。
在一些实施例中,该第一UE的权限可包括:第一UE的UE-SAT-UE通信的权限,例如,第一UE有签约UE-SAT-UE通信的权限。
在一些实施例中,该第一UE的权限可包括:第一UE参与UE-SAT-UE通信的端到端安全权限,例如,第一UE有签约UE-SAT-UE通信的端到端安全权限。
在一些实施例中,第二网络设备根据第一UE的能力信息和/或签约信息,确定第一UE是否有UE-SAT-UE通信的权限。
在一些实施例中,第二网络设备根据第一UE的能力信息确定出第一UE支持UE-SAT-UE通信时,获取第一密钥。
在一些实施例中,第二网络设备根据第一UE的能力信息确定出第一UE不支持UE-SAT-UE通信时,无需获取第一密钥。
在一些实施例中,根据第一UE的签约信息确定第一UE是否有签约UE-SAT-UE通信的权限。
在一些实施例中,根据第一UE的签约信息确定第一UE是否有签约UE-SAT-UE通信的端到端安全的权限。
在一些实施例中,根据第一UE的签约信息确定第一UE是否有签约UE-SAT-UE通信的权限且在有签约UE-SAT-UE通信的权限的情况下是否有签约UE-SAT-UE通信的端到端安全的权限。
在一些实施例中,根据第一UE的能力信息确定第一UE支持UE-SAT-UE的通信下,根据第一UE的签约信息确定第一UE是否签约UE-SAT-UE通信的权限。
在一些实施例中,若第一UE不具有UE-SAT-UE通信的权限或者不具有UE-SAT-UE的端到端安全的权限时,则第二网络设备可以在跳过获取第一密钥的情况下,向第一UE发送拒绝消息或失败消息。该拒绝消息可用于指示网络侧拒绝PDU会话建立、PDU会话更新或者注册授权。该失败消息可用于指示PDU会话建立失败、PDU会话更新失败或者注册授权失败。
S2103:第二网络设备向第一UE发送第二消息。
在一些实施例中,第二消息包括第一密钥。
在一些实施例中,第二网络设备可先获取第一密钥,在收到第一UE的第一消息的情况下,再对第一UE是否具有权限进行确定。
在一些实施例中,第一UE具有UE-SAT-UE通信的权限,向第一UE发送第二消息。示例性地,将第二消息发送给第一UE的接入网设备,且由接入网设备转发或透传至第一UE。
在一些实施例中,第一UE不具有UE-SAT-UE通信的权限,向第一UE发送拒绝消息或失败消息。该拒绝消息或失败消息,指示第一UE不具有UE-SAT-UE通信的权限。
在一些实施例中,若第二网络设备先确定第一UE是否具有权限且在第一UE没有权限的情况下,则S2103可为可选步骤。此时第二网络设备可向第一UE发送前述拒绝消息或失败消息。在一些实施例中,第二网络设备还可不向第一UE发送任何消息。在一些实施例中,第二网络设备还可向第一UE发送不带第一密钥的请求接受消息。
在一些实施例中,若拒绝消息或失败消息还可携带有失败原因。该失败原因指示鉴权失败等。即在一些实施例中,S2103可为可选步骤。
在一些实施例中,若第一消息为PDU会话建立请求消息,则第二消息为PDU会话建立响应消息。示例性地,该第二消息具体可为PDU会话建立成功消息。对应的拒绝消息或失败消息可为PDU会话建立失败消息。
在一些实施例中,若第一消息为PDU会话更新请求消息,则第二消息为PDU会话更新响应消息。示例性地,该第二消息具体可为PDU会话更新成功消息。对应的拒绝消息或失败消息可为PDU会话更新失败消息。
在一些实施例中,若第一消息为注册授权请求消息,则第二消息可为注册授权响应消息。示例性地,该第二消息具体可为注册授权成功消息。对应的拒绝消息或失败消息可为注册授权失败消息。
在一些实施例中,第一UE是否有权限可由第三网络设备执行。示例性地,第三网络设备可为会话管理功能(Session Management Funciton,SMF)。若由第三网络设备进行第一UE是否有权限确定的情况下,则第三网络设备会通知第二网络设备第一UE具有权限,例如,第三网络设备通知第二网络设备具有UE-SAT-UE通信的权限。
在一些实施例中,若第三网络设备确定第一UE具有UE-SAT-UE通信的权限或者第一UE具有UE-SAT-UE通信的端到端安全的权限,则第三网络设备将第一消息透传或转发至第二网络设备。此时,第二网络设备在接收到第一消息,就认为第一UE具有对应的权限。
例如,第一消息为PDU会话建立请求消息或者PDU会话更新消息,则第一消息会经过基站达到第三网络设备,第三网络设备收到该第一消息之后会根据第一UE的能力信息和/或签约信息确定第一UE是否具有对应的权限。在具有对应的权限时,才将第一消息转发或者透传至第二网络设备。
S2104:第二网络设备向第一UE的第一网络设备发送第二指示。
在一些实施例中,第二指示可由第三网络设备发送给第一UE。例如,在PDU会话建立的过程中,第三网络设备根据是否激活第一UE的UE-SAT-UE通信的端到端安全向第一UE的第一网络设备发送第二指示。示例性地,第一UE的第一网络设备可为第一UE的服务基站或者锚基站。在一些实施例中,第一UE的第三网络设备可为第一UE的SMF等。
若第一消息是注册授权请求消息时,则后续第一UE在通信时会发起PUD会话请求。例如,该PDU会话请求可包括UE-SAT-UE通信涉及的业务标识。该PDU会话请求可用于请求基于UE-SAT-UE通信进行业务标识对应的业务数据传输。
PDU会话请求用于第一UE请求PDU会话。
在一些实施例中,第二网络设备或第三网络设备在第一UE请求PDU会话时,向第一网络设备发送第二指示。
在一些实施例中,第二网络设备或第三网络设备在第一UE请求PDU会话时确定已将向第一UE提供第一密钥,则向第一网络设备发送第二指示,否则可不向第一网络设备提供第二指示。
在一些实施例中,若第一消息是PDU会话建立请求或PDU会话更新请求,则第二网络设备向第一网络设备提供第二指示。
在一些实施例中,若第一消息是PDU会话建立请求或PDU会话更新请求且确定向第一UE提供第一密钥,则第二网络设备或第三网络设备向第一网络设备提供第二指示,否则可不向第二网络设备提供第二指示。
在一些实施例中,第二指示用于第一网络设备确定是否需要激活第一UE的UE-SAT-UE通信的端到端安全。
在一些实施例中,端到端安全可包括:UP端到端安全和/或控制面(Control Plane,CP)端到端安全。
在一些实施例中,第二指示用于第一网络设备确定是否需要激活第一UE的UE-SAT-UE通信的用户面UP端到端安全。
在一些实施例中,第二指示可为专门指示激活第一UE的UE-SAT-UE通信的端到端安全,则第二网络设备收到该第二指示之后就知道需要激活第一UE的UE-SAT-UE通信的端到端安全。
在一些实施例中,若使用第一UE的UE-SAT-UE通信的PDU会话都需要激活UP安全,则第二网络设备可向第一设备发送专门指示激活第一UE的UE-SAT-UE通信的端到端安全的第二指示。
在一些实施例中,第二指示可用于指示是否需要第一UE的UE-SAT-UE通信的端到端安全,此第一网络设备根据第二指示的指示内容,确定是否需要激活第一UE的UE-SAT-UE通信的端到端安全。例如,根据运营商策略,某些基于第一UE的UE-SAT-UE通信的业务可能需要激活UP安全,而有些使用第一UE的UE-SAT-UE通信的业务不需要激活UP安全,则此时第二网络设备需要根据业务判断是否需要下发第二指示或第二指示的指示内容。
在一些实施例中,该S2104可为可选步骤,例如,UE和基站可以基于协议约定等预配置方式确定在进行UE-SAT-UE通信是否需要激活UP安全,此时该步骤即可选步骤。
在一些实施例中,在第一UE具有基于UE-SAT-UE通信进行PDU会话的权限时,第二网络设备向第一网络设备发送第二指示。
在一些实施例中,第二网络设备会接收到第三网络设备发送或转发的与PDU会话建立相关的信息。例如,第三网络设备在确定出第一UE具有基于UE-SAT-UE通信进行PDU会话的权限才向第二网络设备发送信息,则第二网络设备在收到第三网络设备发送的信息之后,就认为第一UE具有基于UE-SAT-UE通信进行PDU会话的权限,并向第一网络设备发送第二指示。
在一些实施例中,第二网络设备会接收到第三网络设备发送或转发的与PDU会话建立相关的信息。例如,第三网络设备在确定出第一UE具有基于UE-SAT-UE通信进行PDU会话的权限才向第二网络设备发送信息,则第二网络设备在收到第三网络设备发送的信息之后,就认为第一UE具有基于UE-SAT-UE通信进行PDU会话的权限,并向第一网络设备发送第二指示。
S2105:第一网络设备向第一UE发送第一信息。
在一些实施例中,第一网络设备根据第二指示,向第一UE发送第一信息。
在一些实施例中,第二指示用于指示是否激活第一UE的UE-SAT-UE通信的用户面UP端到端 安全。
在一些实施例中,在第二指示表明激活第一UE的UE-SAT-UE通信的端到端安全。
在一些实施例中,在第二指示表明激活第一UE的UE-SAT-UE通信的UE端到端安全。
在一些实施例中,在第二指示表明激活第一UE的UE-SAT-UE通信的UP端到端安全,第一网络设备向第一UE发送第一信息。
在一些实施例中,在第二指示表明不激活第一UE的UE-SAT-UE通信的UP端到端安全,第一网络设备不向第一UE发送第一信息。
在一些实施例中,在第二指示表明激活第一UE的UE-SAT-UE通信的UP端到端安全,第一网络设备向第一UE发送指示激活UE-SAT-UE通信的UP端到端安全的第一信息。
在一些实施例中,在第二指示表明不激活第一UE的UE-SAT-UE通信的UP端到端安全,第一网络设备向第一UE发送指示不激活UE-SAT-UE通信的UP端到端安全的第一信息。
在一些实施例中,第一信息包括以下至少之一:
第一指示,第一指示用于指示UE-SAT-UE通信的用户面UP端到端安全是否激活。
参数值,该参数值和第一密钥共同用于确定第二密钥。
若参数值和第一密钥共同用于生成第二密钥,则参数值和第一密钥共同作为密钥推导功能(Key Derivation Function,KDF)的输入,得到KDF输出的第二密钥。
在一些实施例中,第一指示可为可选内容,例如,第一信息包括参数值,相当于第一网络设备通过参数值隐含指示激活UE-SAT-UE通信的用户面UP端到端安全。
在一些实施例中,参数值可为可选内容。例如,第一UE根据第一密钥确定(生成)第二密钥时可以不用使用参数值。
示例性地,该参数值可为第一网络设备的特定计数器的计数值、特定定时器的定时值、随机数或者第一网络设备维护的新鲜值。
S2106:第一UE根据第一密钥确定第二密钥。
在一些实施例中,第一UE根据第一密钥和参数值确定第二密钥。
在一些实施例中,第一密钥为UE-SAT-UE通信的根密钥。
在一些实施例中,第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
在一些实施例中,在第一指示用于指示激活UE-SAT-UE通信的用户面UP端到端安全时,根据第一密钥确定第二密钥。
在一些实施例中,在第一指示用于指示不激活UE-SAT-UE通信的用户面UP端到端安全时,无需根据第一密钥确定第二密钥。
在一些实施例中,第一密钥可为根密钥,可以用于一次或多次第二密钥的使用。
例如,一个第二密钥可用于一次PDU会话。
又例如,一个第二密钥可用于一次业务通信。
当然在一些实施例中,第二密钥可设置有有效期,第二密钥可在有效期内用于一次或多次UE-SAT-UE通信。
在一些实施例中,不同UE-SAT-UE通信的业务可具有不同的第二密钥。
在一些实施例中,UE-SAT-UE通信的一种业务可具有一个第二密钥。
在一些实施例中,第二密钥包括以下至少之一:完整性密钥;机密性密钥。
在一些实施例中,若第一网络设备会向第一UE发送第一信息的情况下,第一UE在接收到第一信息之后,根据第一密钥确定第二密钥。
在一些实施例中,若第一网络设备发送第一信息是可选步骤,例如,第一UE默认UE-SAT-UE的UP端到端安全激活也无需从第一网络设备接收参数值,则第一UE直接根据第一密钥确定第二密钥。
在一些实施例中,第一UE根据第一密钥确定第二密钥可包括以下至少之一:
将第一密钥输入到KDF得到KDF输出的第二密钥;
将第一密钥、第一密钥的长度输入到KDF得到KDF输出的第二密钥;
将第一密钥和参数值输入到KDF得到KDF输出的第二密钥;
将第一密钥、第一密钥的长度、参数值以及参数值的长度输入到KDF得到KDF输出的第二密钥。
在一些实施例中,根据第二密钥的类型还可以根据算法类型区分符(Algorithm type distinguisher)和第一密钥共同生成第二密钥;或者,根据第二密钥的类型对应的算法类型区分符、第一密钥和参数值共同生成第二密钥。
例如,完整性密钥和/或机密性密钥对应的算法类型区分符不同。
如图3所示,本公开实施例提供一种密钥处理方法,由第一UE执行。该方法可包括:
S3101:发送第一消息。
在一些实施例中,第一消息与UE-SAT-UE通信相关。
在一些实施例中,第一消息可为任意NAS消息。
在一些实施例中,注册授权请求消息;注册授权请求信息包括第一UE支持UE-SAT-UE通信的能力信息。
在一些实施例中,第一消息为UE-SAT-UE通信的PDU会话建立请求消息。
在一些实施例中,第一消息可为UE-SAT-UE通信的PDU会话更新请求消息。
在一些实施例中,第一消息可用于第一UE向网络侧请求第一密钥。
在一些实施例中,该S3101的可选步骤可参见图2对应的实施例的S2101。
在一些实施例中,第一密钥可为预先配置在第一UE的设备或者用户识别模块(subscriber identity module,SIM),则此时第一UE无需通过第一消息来请求第一密钥。
S3102:接收第二消息。
在一些实施例中,第一UE接收第二网络设备发送的第二消息。
在一些实施例中,第一UE接收第二网络设备在第一UE具有权限时发送的第二消息。
在一些实施例中,第二消息的相关内容可参见图2实施例,此处就不再重复了。
值得注意的是:例如,第一UE不发送请求第一密钥的第一消息时,则该S3102可省略。又例如,第二网络设备确定第一UE没有权限时,则第一UE同样也接收不到第二消息,则该S3102也可省略。
S3103:接收第一信息。
在一些实施例中,第一信息用于第一UE确定UE-SAT-UE通信的用户面UP端到端安全是否激活。
在一些实施例中,第一信息包括第一指示和/或参数值。
第一指示,用于指示是否激活UE-SAT-UE通信的用户面UP端到端安全。
在一些实施例中,第一指示用于指示UE-SAT-UE通信的用户面UP端到端安全是否激活。在一些实施例中,第一UE接收第一网络设备发送的第一指示。
在一些实施例中,该参数值和第一指示的相关描述可以参见图2对应的实施例。
在一些实施例中,该S3103可为可选步骤,例如,第一UE默认激活UE-SAT-UE通信的UP端到端安全,则无需从网络侧接收第一指示。又例如,第一UE根据第一密钥生成第二密钥时无需使用参数值的情况下,也无需从第一网络设备等网络侧任意设备的参数值,则该S3103可省略。
S3104:根据第一密钥确定第二密钥。
在一些实施例中,第一密钥可预先配置在第一UE或者第一UE的SIM上。
在一些实施例中,第一密钥还可以预先由协议约定。
在一些实施例中,第一密钥可以是所有UE-SAT-UE通信的根密钥,此时该根密钥可为所有支持UE-SAT-UE通信的UE或者具有UE-SAT-UE通信权限的UE都知晓的密钥。
在一些实施例中,第一密钥可以是UE-SAT-UE通信某个业务的根密钥。此时该根密钥可为所有支持UE-SAT-UE通信对应业务UE或者具有UE-SAT-UE通信对应业务权限的UE都知晓的密钥。
在一些实施例中,第一密钥还可以PDU会话粒度的密钥或者UE组粒度的密钥。例如,该UE组可为一次UE-SAT-UE通信的所有UE。PDU会话粒度的密钥,则说明第一密钥可用于针对单个PDU会话。
在一些实施例中,S3104的具体操作可参见图2对应实施例的S2106。
值得注意的是:在一些实施例中,S3104可单独执行,例如,第一UE预先被配置有第一密钥,则可以单独执行S3104,则S3101至S3102都是可选步骤。若第一UE默认UE-SAT-UE通信的UP端到端安全激活且无需网络侧提供参数值,则S3103可省略。
一些实施例包括:S3101、S3102以及S3104可组合执行,即S3103为可选步骤。
一些实施例包括:S3103以及S3104可组合执行。
如图4所示,本公开实施例提供一种密钥处理方法,由第一网络设备执行。该方法可包括:
S4101:接收第二指示。
在一些实施例中,第一网络设备可基站。
在一些实施例中,第一网络设备可为星载基站。
在一些实施例中,第一网络设备接收第二网络设备发送的第二指示。
在一些实施例中,第二网络设备可为核心网设备。
在一些实施例中,第二网络设备可为PCF等。
在一些实施例中,第二指示用于指示是否激活第一UE的UE-SAT-UE通信的用户面UP端到端安全。
在一些实施例中,第一网络设备接收第二网络设备或第三网络设备发送的第二指示。
在一些实施例中,在第一UE的网络注册、第一UE的PDU会话建立过程中、第一UE的PDU会话更新过程中,从第二网络设备或第三网络设备接收第二指示。
S4102:发送第一信息。
在一些实施例中,第一网络设备向第一UE发送第一信息。
在一些实施例中,第一网络设备确定需要激活第一UE的UE-SAT-UE的UP端到端安全,向第一UE发送第一信息。
在一些实施例中,第一网络设备确定不需要激活第一UE的UE-SAT-UE通信的UP端到端安全,向第一UE发送第一信息。
在一些实施例中,第一网络设备根据第二指示确定是否需要激活第一UE的UE-SAT-UE通信的UP端到端安全。例如,第二指示用于指示激活第一UE的UE-SAT-UE通信的用户面UP端到端安全,确定激活第一UE的UE-SAT-UE通信的UP端到端安全。又例如,第二指示用于指示不激活第一UE的UE-SAT-UE通信的UP端到端安全,确定不激活第一UE的UE-SAT-UE通信的UP端到端安全。
在一些实施例中,第一网络设备还可以根据本地配置,结合第一UE的UE类型和/或请求的UE-SAT-UE通信涉及的业务等一个或多个参数,确定是否需要激活第一UE的UE-SAT-UE通信的UP端到端安全。
在一些实施例中,第一网络设备未收到第二指示的情况下,可根据本地配置确定是否激活第一UE的UE-SAT-UE通信的UP端到端安全。第一网络设备接收到第二指示的情况下,第一网络设备根据第二指示确定是否激活第一UE的UE-SAT-UE通信的UP端到端安全。即第二指示的优先级高于第一网络设备的本地配置的优先级。
在一些实施例中,第一网络设备根据第二指示,确定是否发送第一信息。
在一些实施例中,第一信息包括以下至少之一:
第一指示,第一指示用于指示是否激活UE-SAT-UE通信的用户面UP端到端安全;
参数值,参数值和第一密钥共同用于确定第二密钥。
在一些实施例中,第一信息可单独包括第一指示。
在一些实施例中,第一信息可单独包括参数值。
在一些实施例中,第一信息可包括第一指示和参数值。
值得注意的是:该第一信息可参见图2对应的实施例的相关描述。
在一些实施例中,S4101可为可选步骤。例如,第一网络设备可根据本地配置确定是否需要激活第一UE的UE-SAT-UE通信的UP端到端安全。即S4102可单独组合实施。
如图5所示,本公开实施例提供一种密钥处理方法,其中,由第二网络设备执行,方法包括:
S5101:接收第一消息。
在一些实施例中,第二网络设备接收第一UE的第一消息。
在一些实施例中,第二网络设备接收第一网络设备和/或第三网络设备转发或透传的第一消息。
在一些实施例中,第一消息与UE-SAT-UE通信相关。
在一些实施例中,第一消息包括以下至少之一:
注册授权请求消息;注册授权请求信息包括第一UE支持UE-SAT-UE通信的能力信息;
UE-SAT-UE通信的PDU会话建立请求消息。
在一些实施例中,第一消息的相关描述可参见图2对应实施例的相关描述。
S5102:发送第二消息。
在一些实施例中,第二消息包括第一密钥。
第一密钥为UE-SAT-UE通信的根密钥。
在一些实施例中,第一密钥用于第一UE生成第二密钥。
在一些实施例中,第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
在一些实施例中,第二网络设备确定第一UE是合法终端,例如,有签约到通信运营商的UE,则向第一UE发送第二消息。
在另一些实施例中,确定第一UE是否具有权限,且确定第一UE具有权限则向第一UE发送第二消息。
在一些实施例中,确定第一UE是否具有权限,可包括以下至少之一:
确定第一UE是否具有UE-SAT-UE通信的权限;
确定第一UE是否具有UE-SAT-UE通信的UP端到端安全的权限。
在一些实施例中,确定第一UE是否具有权限可包括:根据第一UE的能力信息和/或签约数据确定第一UE是否具有权限。
在第一UE具有权限时,向第一UE发送第二消息。该第二消息可由一个或多个网络设备转发或透传至第一UE。
在第一UE不具有权限时,不向第一UE发送第二消息。
在一些实施例中,在第一UE不具有权限,向第一UE发送拒绝消息或失败消息。
在一些实施例中,无需验证第一UE是否有权限,则在接收到第一消息之后,可直接向第一UE发送第二消息。
在一些实施例中,确定第一UE是否具有权限可以由第三网络设备执行,如此,第二网络设备从第三网络设备接收指示第一UE是否具有权限的信息或消息即可。
值得注意的是:S5102的具体实现可参见S2103。
在一些实施例中,第二网络设备确定向第一UE发送第二消息,则还会向第一UE的第一网络设备发送第二指示。第二指示,用于指示是否激活第一UE的UE-SAT-UE通信的端到端安全。示例性地,第二指示,用于指示是否激活第一UE的UE-SAT-UE通信的UP端到端安全。值得注意的是:第二网络设备发送第二指示的步骤是可选步骤。例如,默认激活UE-SAT-UE通信的端到端安全,或者UE-SAT-UE通信的端到端安全不需要激活时,则第二网络设备发送第二指示的步骤可以省略。在一些实施例中,第二指示还可是由第三网络设备发送给第一UE的第一网络设备,则此时第二网络设备发送第二指示的步骤也可以省略。
如图6所示,本公开实施例提供一种密钥处理方法,其中,由第三网络设备执行,方法包括:
S6101:接收第三消息。
在一些实施例中,第三网络设备可为SMF等。
在一些实施例中,第三消息用于请求建立第一UE与至少一个第二UE之间UE-SAT-UE通信的PDU会话。
在一些实施例中,第三消息可为第一UE请求建立PDU会话的任意消息。
S6102:确定第一UE是否具有权限。
在一些实施例中,在收到第三消息之后,确定第一UE是否具有权限。
在一些实施例中,确定第一UE是否具有UE-SAT-UE通信的权限。
在一些实施例中,确定第一UE是否具有UE-SAT-UE通信的端到端安全权限。
在一些实施例中,根据第一UE的能力信息和/或签约信息,确定第一UE是否具有权限。
在一些实施例中,根据第一UE的能力信息和/或签约信息,确定第一UE是否具有权限,可包括但不限于以下至少之一:
第一UE的能力信息指示第一UE支持UE-SAT-UE通信且根据签约信息,确定第一UE是否有签约UE-SAT-UE通信的权限;
第一UE的能力信息指示第一UE不支持UE-SAT-UE通信且根据签约信息,确定第一UE不具有权限。
在一些实施例中,根据签约信息,确定第一UE是否有签约UE-SAT-UE通信的权限,可包括但不限于以下至少之一:
根据签约信息,确定第一UE是否有签约UE-SAT-UE通信的权限;
根据签约信息,确定第一UE是否有签约UE-SAT-UE通信的端到端安全。
S6103:确定是否同意建立UE-SAT-UE通信的PDU会话。
在一些实施例中,根据第一UE是否有权限,确定是否同意建立UE-SAT-UE通信的PDU会话。
在一些实施例中,第一UE具有权限,确定同意建立UE-SAT-UE通信的PDU会话。
在一些实施例中,第一UE不具有权限,确定不同意建立UE-SAT-UE通信的PDU会话。
在一些实施例中,第一UE有签约UE-SAT-UE通信,确定同意建立UE-SAT-UE通信的PDU会话。
在一些实施例中,第一UE未签约UE-SAT-UE通信,确定不同意建立UE-SAT-UE通信的PDU会话。
在一些实施例中,第一UE有签约UE-SAT-UE通信的端到端安全,确定同意建立UE-SAT-UE通信的PDU会话。
在一些实施例中,第一UE未签约UE-SAT-UE通信的端到端安全,确定不同意建立UE-SAT-UE通信的PDU会话。
在一些实施例中,第一UE不具有权限,确定不同意建立UE-SAT-UE通信的PDU会话。
S6104:同意建立UE-SAT-UE通信的PDU会话,发送PDU会话建立请求消息。
在一些实施例中,第三网络设备同意建立UE-SAT-UE通信的PDU会话,向第二网络设备发送PDU会话建立请求消息。
在一些实施例中,该PDU会话建立请求消息会使得第二网络设备向第一UE发送第一密钥。第一密钥用于第一UE确定第二密钥。在本公开实施例中,第二网络设备、第一密钥、第二密钥等相关描述均可参见图2对应实施例的相关描述。
在一些实施例中,不同意建立UE-SAT-UE通信的PDU会话,则不向第二网络设备发送PDU会话建立请求消息,此时PDU会话建立失败。
在一些实施例中,该方法还可包括:
发送第二指示。
在一些实施例中,第三网络设备向第一UE的第一网络设备发送第二指示。
在一些实施例中,所述第二指示用于指示所述第一UE的UE-SAT-UE通信的端到端安全是否激活。
在一些实施例中,第三网络设备同意建立所述UE-SAT-UE通信的PDU会话,向第一网络设备发送第二指示;所述第二指示用于指示所述第一UE的UE-SAT-UE通信的端到端安全是否激活。
在一些实施例中,第三网络设备发送第二指示的步骤是可选步骤。例如,第二指示可由第二网络设备发送,或者,默认激活UE-SAT-UE通信的端到端安全,或者UE-SAT-UE通信的端到端安全不需要激活的场景下,则第三网络设备都可以省略发送第二指示的步骤。
值得注意的是:若第二指示由第三网络设备发送,则可以使得第一UE每建立一个PDU会话则会被重新激活UE-SAT-UE通信的端到端安全,则第一UE会重新生成一个第二密钥。此时,第二密钥的有效期相当于是对应PDU会话的存续期。如此,第一UE不同的PDU会话可具有不同的第二密钥。有鉴于此,本公开实施例提供一种密钥处理方法,可以提升UE-SAT-UT通信的安全性。示例性地,UE1和/或UE2向核心网发起业务授权(Service Authorization and Provisioning)过程,PCF根据UE1和/或UE2的签约信息,通过AMF1/AMF2发送给UE1和/或UE2。PCF可以从UDR或AF查询根密钥(KE2E)。
示例性地,该签约信息可指示UE与运营商签约了UE-SAT-UE的端到端安全通信的根密钥(KE2E)。
UE1和/或UE2向核心网发起PDU会话建立过程。在此过程中,核心网向gNB发送UE-SAT-UE通信的端到端第一指示,例如SMF1/SMF2根据会话管理签约信息或会话管理信息确定UE-SAT-UE通信的端到端安全保护。
gNB在分别激活UE1和UE2的Uu口UP安全时,向UE1和UE2发送UE-SAT-UE通信的端到端第一指示。
gNB在分别激活UE1和UE2的Uu口UP安全时,向UE1和UE2发送UE-SAT-UE通信的端到端第一指示。在从gNB接收到UE-SAT-UE通信的端到端第一指示后,UE1和/或UE2根据步骤#1从核心网接收到的根密钥(KE2E)派生UP流量的端到端安全保护的密钥。
UE1和UE2之间通过gNB交换的UP流量,该UP流量可由由UE1和UE2使用派生的端到端安全保护的密钥对UP流量进行保护。该密钥可为前述的第二密钥。示例性地,第二密钥可为UP安全保护的密钥。在一些实施例中,第二密钥也可以用于CP安全保护的密钥。示例性地,第二密钥可包括KUP_E2E_int和KUP_E2E_enc。KUP_E2E_int是UP的完整性密钥。KUP_E2E_enc是UP的机密性密钥。
当从UE的KE2E导出UE-SAT-UE通信UP业务的端到端安全保护的密钥时,需要使用以下参数组成字符串S:
FC=待定(To Be determined,TBD);
P0=算法类型区分符(algorithm type distinguisher);
L0=算法类型区分值的长度(length of algorithm type distinguisher);
P1=算法标识(algorithm identity);
L1=算法标识的长度(length of algorithm identity);
对于E2E-UP加密算法,算法类型标识符为E2E-UP-enc-alg;
对于E2E-UP完整性保护算法,算法类型标识符为E2E-UP-int-alg。
在设置算法类型区分符的取值时,0x07到0xf0是保留给将来使用的,0xf1到0xff是保留给私人使用的。因此,E2E-UP-enc-alg和E2E-UP-int-alg的值为待定值,取值范围为0x07到0xf0。
对于UE1和UE2之间使用的完整性密钥(KUP_E2E_int)和加密密钥(KUP_E2E_enc)的生成(也即派生),输入密钥应为核心网(如PCF)提供的256位的KE2E。或者,根密钥(KE2E)可以在PDU会话建立过程中由PCF通过SMF提供给UE1和/或UE2。该输入密钥即为前述第一密钥。
在业务授权和信息发放过程中,核心网络功能(Network Function,NF)(如PCF)应能够向UE发送用于UE-SAT-UE通信的根密钥(KE2E)。
NF(例如PCF)应该能够在PDU会话建立期间向UE发送用于UE-SAT-UE通信的根密钥(KE2E)。
NF(例如SMF和/或PCF)应能够在PDU会话建立期间向gNB发送激活UE-SAT-UE通信的端到端安全的第一指示。
gNB应能接收到来自核心网激活UE-SAT-UE通信的端到端安全的指示。
在为UE激活Uu安全时,gNB应能够向UE发送用于UE-SAT-UE通信的端到端安全的指示。
UE应能从核心网(如PCF)接收UE-SAT-UE通信的端到端安全的根密钥(KE2E)。
UE需要能够从从核心网接收到的根密钥(KE2E)中推导UP的端到端安全保护的密钥。
如图7A所示,本公开实施例提供一种密钥处理方法,可包括:
1a.UE1的授权和认证,在该过程中网络设备下发UE-SAT-UE通信的根密钥。
1b.UE2的授权和认证,在该过程中网络设备下发UE-SAT-UE通信的根密钥。
2a.建立UE1的PDU会话,向基站发送UE-SAT-UE通信的端到端安全指示。
2a.建立UE2的PDU会话,向基站发送UE-SAT-UE通信的端到端安全指示。
3a.针对UE1的UP安全激活。
3b.针对UE2的UP安全激活。
4a.UE1基于根密钥(KE2E)推导UP密钥(KUP_E2E)。
4b.UE2基于根密钥(KE2E)推导UP密钥(KUP_E2E)。
5.使用KUP_E2E保护UP流量。
如图7B所示,本公开实施例提供一种密钥处理方法,可包括:
1.建立UE1的PDU会话,向基站发送UE-SAT-UE通信的端到端安全指示,向UE1发送根密钥(KE2E)。
2.建立UE2的PDU会话,向基站发送UE-SAT-UE通信的端到端安全指示,向UE2发送根密钥(KE2E)。
3a.针对UE1的UP安全激活。
3b.针对UE2的UP安全激活。
4a.UE1基于根密钥(KE2E)推导UP密钥(KUP_E2E)。
4b.UE2基于根密钥(KE2E)推导UP密钥(KUP_E2E)。
5.使用KUP_E2E保护UP流量。
在本公开实施例中,部分或全部步骤、其可选实现方式可以与其他实施例中的部分或全部步骤任意组合,也可以与其他实施例的可选实现方式任意组合。
在本公开实施例中,部分或全部步骤、其可选实现方式可以与其他实施例中的部分或全部步骤任意组合,也可以与其他实施例的可选实现方式任意组合。
本公开实施例还提供用于实现以上任一方法的装置,例如,提供一种装置,上述装置包括用以实现以上任一种方法中终端所执行的各步骤的单元或模块。再如,还提供另一种装置,包括用以实现以上任一种方法中网络设备(例如,接入网设备、或者核心网设备等)所执行的各步骤的单元或模块。
应理解以上装置中各单元或模块的划分仅是一种逻辑功能的划分,在实际实现时可以全部或部分集成到一个物理实体上,也可以物理上分开。此外,装置中的单元或模块可以以处理器调用软件的形式实现:例如装置包括处理器,处理器与存储器连接,存储器中存储有指令,处理器调用存储器中存储的指令,以实现以上任一种方法或实现上述装置各单元或模块的功能,其中处理器例如为通用处理器,例如中央处理单元(Central Processing Unit,CPU)或微处理器,存储器为装置内的存储器或装置外的存储器。或者,装置中的单元或模块可以以硬件电路的形式实现,可以通过对硬件电路的设计实现部分或全部单元或模块的功能,上述硬件电路可以理解为一个或多个处理器;例如,在一种实现中,上述硬件电路为专用集成电路(application-specific integrated circuit,ASIC),通过对电路内元件逻辑关系的设计,实现以上部分或全部单元或模块的功能;再如,在另一种实现中,上述硬件电路为可以通过可编程逻辑器件(programmable logic device,PLD)实现,以现场可编程门阵列(Field Programmable Gate Array,FPGA)为例,其可以包括大量逻辑门电路,通过配置文件来配置逻辑门电路之间的连接关系,从而实现以上部分或全部单元或模块的功能。以上装置的所有单元或模块可以全部通过处理器调用软件的形式实现,或全部通过硬件电路的形式实现,或部分通过处理器调用软件的形式实现,剩余部分通过硬件电路的形式实现。
在本公开实施例中,处理器是一种具有信号处理能力的电路,在一种实现中,处理器可以是具有指令读取与运行能力的电路,例如中央处理单元(Central Processing Unit,CPU)、微处理器、图形处理器(graphics processing unit,GPU)(可以理解为一种微处理器)、或数字信号处理器(digital signal processor,DSP)等;在另一种实现中,处理器可以通过硬件电路的逻辑关系实现一定功能,上述硬件电路的逻辑关系是固定的或可以重构的,例如处理器为专用集成电路((((application-specific integrated circuit,ASIC)或可编程逻辑器件((((programmable logic device,PLD)实现的硬件电路,例如FPGA。在可重构的硬件电路中,处理器加载配置文档,实现硬件电路配置的过程,可以理解为处理器加载指令,以实现以上部分或全部单元或模块的功能的过程。此外,还可以是针对人工智能设计的硬件电路,其可以理解为一种ASIC,例如神经网络处理单元(Neural Network Processing Unit,NPU)、张量处理单元(Tensor Processing Unit,TPU)、深度学习处理单元(Deep learning Processing Unit,DPU)等。
如图8A所示,本公开实施例提供一种第一UE,包括:
处理模块7101,被配置为根据第一密钥确定第二密钥;第一密钥为UE-SAT-UE通信的根密钥;第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
在一些实施例中,该处理模块可用于第一UE执行任意一个密钥处理方法中的信息处理相关的步骤。
在一些实施例中,该第一UE还可包括:发送模块和/或接收模块。
在一些实施例中,该发送模块和/或接收模块可对应于第一UE的网络接口和/或收发天线。
在一些实施例中,该发送模块可用于第一UE执行任意一个密钥处理方法中的信息发送相关的步骤。
在一些实施例中,该接收模块可用于第一UE执行任意一个密钥处理方法中的信息发送相关的步骤。
接收模块,被配置为接收第一网络设备发送的第一信息;第一信息用于第一UE确定是否激活UE-SAT-UE通信的用户面UP端到端安全;
根据第一密钥确定第二密钥,包括:在UP端到端安全激活的情况下,根据第一密钥确定第二密钥。
在一些实施例中,第一信息还包括以下至少之一:
第一指示,第一指示用于指示是否激活UE-SAT-UE通信的用户面UP端到端安全;
参数值,参数值和第一密钥共同用于确定第二密钥。
在一些实施例中,处理模块,被配置为执行以下至少之一:
根据第一密钥和参数值生成第二密钥;
根据第一密钥生成第二密钥。
在一些实施例中,发送模块被配置为向第二网络设备发送第一消息;第一消息与UE-SAT-UE通信相关;
接收模块,被配置为接收第二网络设备发送的第二消息;第二消息包括第一密钥。
在一些实施例中,第一消息包括以下至少之一:
注册授权请求消息;注册授权请求信息包括第一UE支持UE-SAT-UE通信的能力信息;
UE-SAT-UE通信的PDU会话建立请求消息。
在一些实施例中,第二密钥包括以下至少之一:
完整性密钥;
机密性密钥。
图8B是本公开实施例提供的一种第二网络设备,包括:
处理模块7201,被配置为确定第一密钥;第一密钥为UE-SAT-UE通信的根密钥;第一密钥用于第一UE生成第二密钥;UE-SAT-UE通信。
在一些实施例中,该第二网络设备还可包括发送模块和/或接收模块。
在一些实施例中,该处理模块可被配置为执行第二网络设备执行的密钥处理方法中信息处理相关的任意步骤。
在一些实施例中,该发送模块和/或接收模块可对应于第二网络设备的网络接口和/或收发天线。
在一些实施例中,接收模块,被配置为接收第一UE发送的第一消息;第一消息与UE-SAT-UE相关;
发送模块,被配置为向第一UE发送第二消息;第二消息包括第一密钥。
第一消息为注册授权请求消息;注册授权请求消息包括第一UE的能力信息;发送模块,还被配置为第一UE的能力信息指示第一UE是否支持UE-SAT-UE通信或第一UE是否支持UE-SAT-UE通信的端到端安全,向第一UE发送包括第二消息。
在一些实施例中,发送模块,被配置为执行以下至少之一:
第一消息为UE-SAT-UE通信的PDU会话建立请求消息且第二网络设备确定第一UE具有UE-SAT-UE通信的权限,向第一UE发送第二消息;
第一消息为UE-SAT-UE通信的PDU会话建立请求消息且第二网络设备确定具有UE-SAT-UE通信的端到端安全权限,向第一UE发送第二消息;
第一消息为UE-SAT-UE通信的PDU会话建立请求消息且第三网络设备同意为第一UE建立UE-SAT-UE通信的PDU会话,向第一UE发送第二消息。
在一些实施例中,处理模块,被配置为根据第一UE的签约信息,确定第一UE是否签约UE-SAT-UE通信;第一UE有签约UE-SAT-UE通信,确定向第一UE发送第二消息。
在一些实施例中,处理模块,被配置为根据第一UE的签约信息,确定第一UE是否签约UE-SAT-UE通信的端到端安全;
第一UE签约UE-SAT-UE通信的端到端安全,确定向第一UE发送第二消息。
在一些实施例中,发送模块,被配置为向第一UE连接的第一网络设备发送第二指示,第二指示用于指示是否激活第一UE的UE-SAT-UE通信的用户面UP端到端安全。
在一些实施例中,发送模块,被配置为为第一UE建立UE-SAT-UE通信的PDU会话,向第一UE接入的第一网络设备发送第二指示。
如图8C所示,本公开实施例提供一种第一网络设备,包括:
发送模块7301,被配置为向第一用户设备UE发送第一信息;所述第一信息至少包括第一信息;所述第一信息至少用于指示用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全是否激活,以使得所述第一UE根据第一密钥生成第二密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
在一些实施例中,该第一网络设备还可包括接收模块和/或处理模块。
在一些实施例中,该处理模块可被配置为执行第一网络设备执行的密钥处理方法中信息处理相关的任意步骤。
在一些实施例中,该发送模块和/或接收模块可对应于第一网络设备的网络接口和/或收发天线。
在一些实施例中,接收模块,被配置为接收第二网络设备或第三网络设备发送的第二指示;所述第二指示用于指示所述第一UE的UE-SAT-UE通信的端到端安全是否激活;发送模块,被配置为是否需要激活第一UE的UE-SAT-UE通信的用户面UP端到端安全保护,向第一UE发送第一信息。在一些实施例中,所述第一信息还包括以下至少之一:
第一指示,所述第一指示用于指示是否激活所述UE-SAT-UE通信的端到端安全;
参数值,所述参数值和所述第一密钥共同用于确定所述第二密钥。
如图8D所示,本公开实施例提供一种第三网络设备,其中,包括:
接收模块7401,被配置为接收第一UE的第三消息;第三消息用于请求建立第一UE与至少一个第二UE之间UE-SAT-UE通信的PDU会话;
处理模块7402,被配置为确定第一UE具有UE-SAT-UE通信的权限或具有UE-SAT-UE通信的端到端安全权限;第一UE具有UE-SAT-UE通信的权限或具有UE-SAT-UE通信的端到端安全权限,确定同意建立UE-SAT-UE通信的PDU会话;
发送模块7403,被配置为同意建立UE-SAT-UE通信的PDU会话,向第二网络设备发送PDU会话建立请求消息;PDU会话建立请求消息,用于第二网络设备向第一UE提供第一密钥;第一密钥为UE-SAT-UE通信的根密钥;第二密钥用于第一UE与至少一个第二UE之间UE-SAT-UE通信的端到端安全保护。
在一些实施例中,该第三网络设备还可包括接收模块和/或处理模块。
在一些实施例中,该处理模块可被配置为执行第三网络设备执行的密钥处理方法中信息处理相关的任意步骤。
在一些实施例中,该发送模块和/或接收模块可对应于第三网络设备的网络接口和/或收发天线。
在一些实施例中,发送模块,还被配置为同意建立所述UE-SAT-UE通信的PDU会话,向第一网络设备发送第二指示;所述第二指示用于指示所述第一UE的UE-SAT-UE通信的端到端安全是否激活。
本公开实施例还提供一种通信设备,该通信设备可包括:一个或多个处理器;其中,处理器用于调用指令以使得通信设备执行前述任何一个实施例可实现的密钥处理方法。
在一些实施例中,如图9A和/或图9B所示,通信设备8100还包括用于存储指令的一个或多个存储器8102。可选地,全部或部分存储器8102也可以处于通信设备8100之外。
该通信设备可为前述的终端以及网络设备。在一些实施例中,该网络设备可为主节点和/或辅助节点。
在一些实施例中,通信设备8100还包括一个或多个收发器8103。在通信设备8100包括一个或多个收发器8103时,上述方法中的发送接收等通信步骤由收发器8103执行,其他步骤由处理器8101执行。
在一些实施例中,收发器可以包括接收器和发送器,接收器和发送器可以是分离的,也可以集成在一起。可选地,收发器、收发单元、收发机、收发电路等术语可以相互替换,发送器、发送单元、发送机、发送电路等术语可以相互替换,接收器、接收单元、接收机、接收电路等术语可以相互替换。
可选地,通信设备8100还包括一个或多个接口电路8104,接口电路8104与存储器8102连接,接口电路8104可用于从存储器8102或其他装置接收信号,可用于向存储器8102或其他装置发送信号。例如,接口电路8104可读取存储器8102中存储的指令,并将该指令发送给处理器8101。
以上实施例描述中的通信设备8100可以是网络设备或者终端,但本公开中描述的通信设备8100的范围并不限于此,通信设备8100的结构可以不受图9A的限制。通信设备可以是独立的设备或者可以是较大设备的一部分。例如通信设备可以是:(1)独立的集成电路IC,或芯片,或,芯片系统或子系统;(2)具有一个或多个IC的集合,可选地,上述IC集合也可以包括用于存储数据,程序的存储部件;(3)ASIC,例如调制解调器(Modem);(4)可嵌入在其他设备内的模块;(5)接收机、终端设备、智能终端设备、蜂窝电话、无线设备、手持机、移动单元、车载设备、网络设备、云设备、人工智能设备等等;(6)其他等等。
图9B是本公开实施例提供的芯片8200的结构示意图。对于通信设备8100可以是芯片或芯片系统的情况,可以参见图9B所示的芯片8200的结构示意图,但不限于此。
芯片8200包括一个或多个处理器8201,处理器8201用于调用指令以使得芯片8200执行以上任一种密钥处理方法。
在一些实施例中,芯片8200还包括一个或多个接口电路8202,接口电路8202与存储器8203连接,接口电路8202可以用于从存储器8203或其他装置接收信号,接口电路8202可用于向存储器8203或其他装置发送信号。例如,接口电路8202可读取存储器8203中存储的指令,并将该指令发送给处理器8201。可选地,接口电路、接口、收发管脚、收发器等术语可以相互替换。
在一些实施例中,芯片8200还包括用于存储指令的一个或多个存储器8203。可选地,全部或部分存储器8203可以处于芯片8200之外。
本公开还提供一种存储介质,上述存储介质上存储有指令,当上述指令在通信设备8100上运行时,使得通信设备8100执行以上任一种方法。可选地,上述存储介质是电子存储介质。可选地,上述存储介质是计算机可读存储介质,但也可以是其他装置可读的存储介质。可选地,上述存储介质可以是非暂时性(non-transitory)存储介质,但也可以是暂时性存储介质。
本公开还提供一种程序产品,上述程序产品被通信设备8100执行时,使得通信设备8100执行以上任一种密钥处理方法。可选地,上述程序产品是计算机程序产品。
本公开还提供一种计算机程序,当其在计算机上运行时,使得计算机执行以上任一种密钥处理方法。
本领域技术人员在考虑说明书及实践这里公开的发明后,将容易想到本公开实施例的其它实施方案。本公开旨在涵盖本公开实施例的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本公开实施例的一般性原理并包括本公开未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本公开实施例的真正范围和精神由下面的权利要求指出。
应当理解的是,本公开实施例并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本公开实施例的范围仅由所附的权利要求来限制。

Claims (26)

  1. 一种密钥处理方法,其中,由第一用户设备UE执行,所述方法包括:
    根据第一密钥确定第二密钥;所述第一密钥为用户设备到卫星到用户设备UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
  2. 根据权利要求1所述的方法,其中,所述方法还包括:
    接收第一网络设备发送的第一信息;所述第一信息至少用于所述第一UE确定是否激活所述UE-SAT-UE通信的端到端安全;
    所述根据第一密钥确定第二密钥,包括:在所述UE-SAT-UE通信的端到端安全激活的情况下,根据所述第一密钥确定所述第二密钥。
  3. 根据权利要求2所述的方法,其中,所述第一信息还包括以下至少之一:
    第一指示,所述第一指示用于指示是否激活所述UE-SAT-UE通信的端到端安全;
    参数值,所述参数值和所述第一密钥共同用于确定所述第二密钥。
  4. 根据权利要求3所述的方法,其中,所述在所述UE-SAT-UE通信的端到端安全激活的情况下,根据所述第一密钥确定所述第二密钥,包括以下至少之一:
    根据所述第一密钥和所述参数值生成所述第二密钥;
    根据所述第一密钥生成所述第二密钥。
  5. 根据权利要求1至4任一项所述的方法,其中,所述方法包括:
    向第二网络设备发送第一消息;所述第一消息与所述UE-SAT-UE通信相关;
    接收所述第二网络设备发送的第二消息;所述第二消息包括所述第一密钥。
  6. 根据权利要求5所述的方法,其中,所述第一消息包括以下至少之一:
    注册授权请求消息;所述注册授权请求信息包括所述第一UE支持UE-SAT-UE通信的能力信息;
    所述UE-SAT-UE通信的协议数据单元PDU会话建立请求消息。
  7. 根据权利要求1至6任一项所述的方法,其中,所述第二密钥包括以下至少之一:
    完整性密钥;
    机密性密钥。
  8. 一种密钥处理方法,其中,由第二网络设备执行,所述方法包括:
    确定第一密钥;所述第一密钥为用户设备到卫星到用户设备UE-SAT-UE通信的根密钥;所述第一密钥用于第一用户设备UE生成第二密钥;用户设备到卫星到用户设备UE-SAT-UE通信。
  9. 根据权利要求8所述的方法,其中,所述方法还包括:
    接收所述第一UE发送的第一消息;所述第一消息与所述UE-SAT-UE相关;
    向所述第一UE发送第二消息;所述第二消息包括所述第一密钥。
  10. 根据权利要求9所述的方法,其中,所述第一消息为注册授权请求消息;所述注册授权请求消息包括所述第一UE的能力信息;所述向所述第一UE发送第二消息,包括;
    所述第一UE的能力信息指示所述第一UE是否支持所述UE-SAT-UE通信或所述第一UE是否支持所述UE-SAT-UE通信的端到端安全,向所述第一UE发送包括第二消息。
  11. 根据权利要求9所述的方法,其中,所述向所述第一UE发送第二消息,包括以下至少之一;
    所述第一消息为所述UE-SAT-UE通信的协议数据单元PDU会话建立请求消息且所述第二网络设备确定所述第一UE具有所述UE-SAT-UE通信的权限,向所述第一UE发送所述第二消息;
    所述第一消息为所述UE-SAT-UE通信的协议数据单元PDU会话建立请求消息且所述第二网络设备确定所述第一UE具有所述UE-SAT-UE通信的端到端安全权限,向所述第一UE发送所述第二消息;
    所述第一消息为所述UE-SAT-UE通信的协议数据单元PDU会话建立请求消息且第三网络设备同意为所述第一UE建立所述UE-SAT-UE通信的PDU会话,向所述第一UE发送所述第二消息。
  12. 根据权利要求9或10所述的方法,其中,所述方法还包括:
    根据所述第一UE的签约信息,确定所述第一UE是否签约所述UE-SAT-UE通信;
    所述第一UE有签约所述UE-SAT-UE通信,确定向所述第一UE发送所述第二消息。
  13. 根据权利要求9或10所述的方法,其中,所述方法还包括:
    根据所述第一UE的签约信息,确定所述第一UE是否签约所述UE-SAT-UE通信的端到端安全;
    所述第一UE签约所述UE-SAT-UE通信的端到端安全,确定向所述第一UE发送所述第二消息。
  14. 根据权利要求7至13任一项所述的方法,其中,所述方法还包括:
    向所述第一UE连接的第一网络设备发送第二指示,所述第二指示用于指示是否激活所述第一UE的UE-SAT-UE通信的用户面UP端到端安全。
  15. 根据权利要求12所述的方法,其中,所述向所述第一UE连接的第一网络设备发送第二指示,包括:
    为所述第一UE建立所述UE-SAT-UE通信的PDU会话,向所述第一UE接入的第一网络设备发送第二指示。
  16. 一种密钥处理方法,其中,由第一网络设备执行,所述方法包括:
    向第一用户设备UE发送第一信息;所述第一信息至少包括第一信息;所述第一信息至少用于指示用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全是否激活,以使得所述第一UE根据第一密钥生成第二密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
  17. 根据权利要求16所述的方法,其中,所述方法包括:
    接收第二网络设备或第三网络设备发送的第二指示;所述第二指示用于指示所述第一UE的UE-SAT-UE通信的端到端安全是否激活;
    所述向第一用户设备UE发送第一信息,包括:
    是否需要激活所述第一UE的UE-SAT-UE通信的端到端安全保护,向所述第一UE发送所述第一信息。
  18. 根据权利要求16或17所述的方法,其中,所述第一信息还包括以下至少之一:
    第一指示,所述第一指示用于指示是否激活所述UE-SAT-UE通信的端到端安全;
    参数值,所述参数值和所述第一密钥共同用于确定所述第二密钥。
  19. 一种密钥处理方法,其中,由第三网络设备执行,所述方法包括:
    接收第一用户设备UE的第三消息;所述第三消息用于请求建立所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的协议数据单元PDU会话;
    确定所述第一UE具有所述UE-SAT-UE通信的权限或具有所述UE-SAT-UE通信的端到端安全权限;
    所述第一UE具有所述UE-SAT-UE通信的权限或具有所述UE-SAT-UE通信的端到端安全权限,确定同意建立所述UE-SAT-UE通信的PDU会话;
    同意建立所述UE-SAT-UE通信的PDU会话,向第二网络设备发送PDU会话建立请求消息;所述PDU会话建立请求消息,用于所述第二网络设备向所述第一UE提供第一密钥;所述第一密钥为用户设备到卫星到用户设备UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
  20. 根据权利要求19所述的方法,其中,所述方法还包括:
    同意建立所述UE-SAT-UE通信的PDU会话,向第一网络设备发送第二指示;所述第二指示用于指示所述第一UE的UE-SAT-UE通信的端到端安全是否激活。
  21. 一种第一用户设备UE,其中,包括:
    处理模块,被配置为根据第一密钥确定第二密钥;所述第一密钥为用户设备到卫星到用户设备UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
  22. 一种第二网络设备,其中,包括:
    处理模块,被配置为确定第一密钥;所述第一密钥为用户设备到卫星到用户设备UE-SAT-UE通信的根密钥;所述第一密钥用于第一用户设备UE生成第二密钥;用户设备到卫星到用户设备UE-SAT-UE通信。
  23. 一种第一网络设备,其中,包括:
    发送模块,被配置为向第一用户设备UE发送第一信息;所述第一信息至少包括第一指示;所述第一指示用于指示用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全是否激活,使得所述第一UE根据第一密钥生成第二密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
  24. 一种第三网络设备,其中,包括:
    接收模块,被配置为接收第一用户设备UE的第三消息;所述第三消息用于请求建立所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的协议数据单元PDU会话;
    处理模块,被配置为确定所述第一UE具有所述UE-SAT-UE通信的权限或具有所述UE-SAT-UE通信的端到端安全权限;所述第一UE具有所述UE-SAT-UE通信的权限或具有所述UE-SAT-UE通信的端到端安全权限,确定同意建立所述UE-SAT-UE通信的PDU会话;
    发送模块,被配置为同意建立所述UE-SAT-UE通信的PDU会话,向第二网络设备发送PDU会话建立请求消息;所述PDU会话建立请求消息,用于所述第二网络设备向所述第一UE提供第一密钥;所述第一密钥为用户设备到卫星到用户设备UE-SAT-UE通信的根密钥;所述第二密钥用于所述第一UE与至少一个第二UE之间用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
  25. 一种通信设备,其中,所述通信设备包括:
    一个或多个处理器;
    其中,所述处理器用于调用指令以使得所述通信设备执行权利要求1至7、8至15、16至18和/或权利要求19至20中任一项所述的下行控制信息DCI的传输方法。
  26. 一种存储介质,其中,所述存储介质存储有指令,当所述指令在通信设备上运行时,使得所述通信设备执行权利要求1至7、8至15、16至18和/或权利要求19至20中任一项所述的下行控制信息DCI的传输方法。
PCT/CN2024/073361 2024-01-19 2024-01-19 密钥处理方法、通信设备及存储介质 Pending WO2025152184A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CN2024/073361 WO2025152184A1 (zh) 2024-01-19 2024-01-19 密钥处理方法、通信设备及存储介质

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2024/073361 WO2025152184A1 (zh) 2024-01-19 2024-01-19 密钥处理方法、通信设备及存储介质

Publications (1)

Publication Number Publication Date
WO2025152184A1 true WO2025152184A1 (zh) 2025-07-24

Family

ID=96470672

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/073361 Pending WO2025152184A1 (zh) 2024-01-19 2024-01-19 密钥处理方法、通信设备及存储介质

Country Status (1)

Country Link
WO (1) WO2025152184A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20180372878A1 (en) * 2017-06-27 2018-12-27 Here Global B.V. Authentication of satellite navigation system receiver
CN115776673A (zh) * 2021-09-08 2023-03-10 大唐移动通信设备有限公司 卫星通信系统、认证方法及装置
CN117098123A (zh) * 2023-10-17 2023-11-21 西北大学 一种基于量子密钥的北斗短报文加密通信系统
CN117310755A (zh) * 2023-11-30 2023-12-29 中国人民解放军国防科技大学 卫星导航信号可信认证协议及终端可信定位的方法与装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20180372878A1 (en) * 2017-06-27 2018-12-27 Here Global B.V. Authentication of satellite navigation system receiver
CN115776673A (zh) * 2021-09-08 2023-03-10 大唐移动通信设备有限公司 卫星通信系统、认证方法及装置
CN117098123A (zh) * 2023-10-17 2023-11-21 西北大学 一种基于量子密钥的北斗短报文加密通信系统
CN117310755A (zh) * 2023-11-30 2023-12-29 中国人民解放军国防科技大学 卫星导航信号可信认证协议及终端可信定位的方法与装置

Similar Documents

Publication Publication Date Title
WO2025010737A1 (zh) 通信方法及装置、通信设备、通信系统及存储介质
CN116321489B (zh) 中继发现方法和终端
CN116965102A (zh) 无线通信方法、终端设备和网络设备
WO2024234313A1 (zh) 信息处理方法及装置、通信设备、通信系统、存储介质
CN116114315B (zh) 无线通信的方法、终端设备和网络设备
CN117322027A (zh) 信息处理方法、装置及存储介质
CN115152255A (zh) 中继方法和通信设备
CN115348627B (zh) 切片信息配置方法和设备
WO2025166774A1 (zh) Pdcch监听方法、装置
WO2025152184A1 (zh) 密钥处理方法、通信设备及存储介质
WO2025015513A1 (zh) 信息处理方法、终端、通信系统及存储介质
WO2025030300A1 (zh) 信息指示方法、第一api调用者、第一网络功能和存储介质
WO2025065695A1 (zh) 信息指示方法、终端
CN116250290B (zh) 无线通信方法、终端设备、第一接入网设备以及网元
CN116325832B (zh) 会话管理方法、终端设备和网络设备
KR20230049646A (ko) 중계 통신 방법 및 디바이스
WO2025091186A1 (zh) 密钥处理方法、通信设备、及存储介质
CN116349325B (zh) 寻呼方法和网络节点
WO2025065348A1 (zh) 通信安全防护方法、通信设备及存储介质
WO2025152183A1 (zh) 数据安全处理方法及通信设备、通信系统及存储介质
WO2025213393A1 (zh) 用户认证方法、通信设备及存储介质
WO2025213399A1 (zh) 用户认证方法、通信设备及存储介质
WO2025213347A1 (zh) 通信方法、网络设备、终端及通信系统
WO2026036328A1 (zh) 信息处理方法、通信设备及存储介质
WO2025010573A1 (zh) 基于ntn的通信方法和装置、通信设备、通信系统及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24917807

Country of ref document: EP

Kind code of ref document: A1