WO2020221175A1 - 一种注册方法及装置 - Google Patents

一种注册方法及装置 Download PDF

Info

Publication number
WO2020221175A1
WO2020221175A1 PCT/CN2020/087062 CN2020087062W WO2020221175A1 WO 2020221175 A1 WO2020221175 A1 WO 2020221175A1 CN 2020087062 W CN2020087062 W CN 2020087062W WO 2020221175 A1 WO2020221175 A1 WO 2020221175A1
Authority
WO
WIPO (PCT)
Prior art keywords
amf
nas
security context
nas security
indication information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/087062
Other languages
English (en)
French (fr)
Inventor
邓娟
何承东
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to EP20799587.9A priority Critical patent/EP3952378A4/en
Publication of WO2020221175A1 publication Critical patent/WO2020221175A1/zh
Priority to US17/512,757 priority patent/US12309734B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/72Subscriber identity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W36/00Hand-off or reselection arrangements
    • H04W36/0005Control or signalling for completing the hand-off
    • H04W36/0011Control or signalling for completing the hand-off for data sessions of end-to-end connection
    • H04W36/0033Control or signalling for completing the hand-off for data sessions of end-to-end connection with transfer of context information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/20Transfer of user or subscriber data

Definitions

  • the present invention relates to the field of wireless communication technology, and in particular to a registration method and device.
  • the standard 3rd Generation Partnership Project (3rd Generation Partnership Project, 3GPP) TS 23.502 [1] defines that in the fifth generation mobile communication technology (5th-Generation, 5G) system, the User Equipment (UE) is registered In the process, a core access and mobility management function network element (Core Access and Mobility Management Function, AMF) redirection process occurs.
  • 5th-Generation 5th-Generation, 5G
  • AMF Core Access and Mobility Management Function
  • the UE During the initial registration of the UE, the UE first initiates a registration request message carrying a Subscriber Concealed Identifier (SUCI). The registration request message only carries cleartext IEs.
  • SUCI Subscriber Concealed Identifier
  • the registration request message only carries cleartext IEs.
  • Initial AMF receives the SUCI registration request , Initiate master authentication, generate the AMF key Kamf, and the corresponding key identifier ngKSI.
  • Initial AMF activates and starts Kamf generated with master authentication through the Non-Access Stratum (NAS) security mode control (Security Mode Control) process.
  • NAS Non-Access Stratum
  • Security Mode Control Security Mode Control
  • the UE Since the registration request message sent by the UE only includes cleartext IEs, the UE sends a complete registration request message in the NAS Security Mode Complete message, and the complete registration request information includes Requested S-NSSAIs.
  • Initial AMF judges whether it can serve UE according to Requested S-NSSAIs. When Initial AMF cannot serve UE, Initial AMF performs NAS reroute, that is, AMF redirection, Initial AMF sends the received registration request information to Target AMF that can serve UE. When there is no direct connection between the Initial AMF and the Target AMF, the Initial AMF sends the received registration request message carrying the SUCI to the Target AMF via the (Radio) Access Network ((R) AN).
  • R Radio Access Network
  • the NAS security context includes the AMF key Kamf, and the corresponding key identifier ngKSI, etc., so when Target AMF initiates the master authentication, it sends an authentication request (Authentication Request) without security protection to the UE.
  • Authentication Request an authentication request
  • the UE does not perceive AMF redirection, and the NAS security context has been established in the UE, when the UE receives an Authentication Request message without security protection, it will not process the Authentication Request message, causing the UE to fail to register and cannot access the network .
  • the embodiments of the present application provide a registration method and device, so as to prevent the existing UE from discarding and not processing the authentication request message sent by the target AMF, so as to avoid UE registration failure.
  • a registration method including the following processes:
  • the initial AMF sends a first non-access stratum security mode command (NAS Ssecurity Mode Command) message to the UE, or the initial AMF sends a first non-access stratum security mode command message carrying eighth indication information to the UE.
  • the eighth indication information is used to instruct the UE to save the NAS security context, if any, or to instruct the UE to save the currently used NAS security context, if any.
  • the UE should save the NAS security context, if any, or, should save the currently used NAS security context, if any .
  • the initial AMF determines to perform AMF redirection
  • the initial AMF should send indication information to the UE, the indication information is used to instruct the UE to delete or discard the NAS security context, and/or to instruct the UE to deactivate the current NAS security context of the UE, and/ Or, used to instruct the UE to process the authentication request message without security protection, and/or, used to indicate the occurrence of AMF redirection on the UE network side, and/or, used to instruct the UE to restore the NAS-free security context, and/or, Instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or, for instruct the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or, Used to instruct the UE to delete or discard the new NAS security context, and/or to instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or to indicate The UE resumes using the saved NAS security context, if any.
  • the initial AMF sends the initial AMF to the (wireless) access network ((R)AN).
  • AN Send the instruction information before sending the NAS Reroute Message (NAS Reroute Message).
  • the UE receives the indication information sent by the initial AMF
  • the UE should, discard or delete the NAS security context; and/or, deactivate the current NAS security context of the UE, and/or determine not to discard and process the received authentication request message without security protection , And/or, determine that AMF redirection occurs on the network side, and/or restore no NAS security context, and/or delete or discard the new NAS security context established by the UE and the initial AMF, and/or, Delete or discard the NAS security context established by the UE and the initial AMF, and/or delete or discard the new NAS security context, and/or, deactivate the UE and the initial AMF establishment
  • the UE receives the authentication request message sent by the target AMF, processes the authentication request message, and sends an authentication response message without security protection to the target AMF.
  • the initial AMF decides that AMF redirection will occur, the initial AMF will be used to instruct the UE to delete the indication information of the NAS security context, or to instruct the UE to deactivate the current NAS security context, or to indicate
  • the UE processes the indication information of the authentication request information without security protection, or the indication information used to indicate the occurrence of AMF redirection on the network side of the UE and sends it to the UE.
  • the UE receives the indication information, deletes the NAS security context according to the indication information, and processes the received authentication request information; or the UE deactivates the current NAS security context according to the indication information, and processes the received authentication request message; or the UE according to the indication information Process the received authentication request message; there is no security protection or the UE determines that AMF redirection occurs on the network side, and process the received authentication request message.
  • the UE sends an authentication response message without security protection to the target AMF. The UE does not discard and process the received authentication request message, thereby avoiding UE registration failure.
  • the initial AMF sending instruction information includes:
  • the initial AMF sends a first notification message to the UE, where the first notification message is used to instruct the UE to delete the NAS security context, and/or, to instruct the UE to deactivate the current NAS security context, and/or, Used to instruct the UE to process the authentication request message without security protection, and/or used to indicate the occurrence of AMF redirection on the network side of the UE, and/or used to instruct the UE to restore the NAS-free security context, and/or, used to instruct the UE Deleting or discarding the new NAS security context established by the UE and the initial AMF, and/or, for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or for Instruct the UE to delete or discard the new NAS security context, and/or to instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or to instruct the UE to resume Use the saved NAS security context, if any.
  • the indication information sent by the UE to receive the initial AMF includes:
  • the UE receives the first notification message sent by the initial AMF.
  • the initial AMF sends a first notification message to the UE, and the UE receives the first notification message.
  • the first notification message instructs the UE to delete the NAS security context, or instructs the UE to deactivate the current NAS security context, or instructs the UE to process an authentication request message without security protection, Or instruct the UE to have AMF redirection on the network side to ensure that the UE does not discard and process the received authentication request message.
  • the initial AMF sending instruction information includes:
  • the initial AMF sends a first NAS message to the UE, where the first NAS message carries first indication information, and the first indication information is used to instruct the UE to delete the NAS security context, and/or to instruct the UE to Activate the current NAS security context, and/or, instruct the UE to process an authentication request message without security protection, and/or indicate that AMF redirection occurs on the network side of the UE, and/or, be used to instruct the UE to restore no NAS security context, and/or Or, for instructing the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, And/or for instructing the UE to delete or discard the new NAS security context, and/or for instructing the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or , Used to instruct the UE to resume using the saved NAS
  • This application does not impose restrictions on the first NAS message that carries the first indication information.
  • Possible options for the NAS message include configuration update command messages, downlink NAS transport messages, and 5G system mobility management status (5G system mobility management status, 5GMM Status) and registration rejection (registration reject) messages, etc.
  • the indication information sent by the UE to receive the initial AMF includes:
  • the UE receives the first NAS message sent by the initial AMF, where the first NAS message carries first indication information.
  • the initial AMF sends the first NAS message to the UE, and the UE receives the first NAS message.
  • the first message carries the first indication information to instruct the UE to delete the NAS security context, or instruct the UE to deactivate the current NAS security context, or indicate that the UE is not safe to process
  • the protected authentication request message, or indicating the occurrence of AMF redirection on the UE network side, ensures that the UE does not discard and process the received authentication request message.
  • the first notification message or the first NAS message carries ngKSI
  • the ngKSI is used to instruct the UE to delete or deactivate the NAS security context corresponding to the ngKSI.
  • the first notification message or the first NAS message sent by the initial AMF to the UE carries the ngKSI, and the UE deletes or deactivates the NAS security context corresponding to the ngKSI, which ensures that the UE does not discard and process the received authentication request message.
  • a registration method including the following processes:
  • the target AMF receives sixth indication information, where the sixth indication information is used to instruct the UE to delete the NAS security context, and/or to instruct the UE to deactivate the current NAS security context, and/or to indicate that the UE has no security protection for processing
  • the authentication request message indicates that AMF redirection occurs on the network side of the UE, and/or, is used to instruct the UE to restore the NAS-free security context, and/or, is used to instruct the UE to delete or discard the UE and the initial A new NAS security context established by AMF, and/or used to instruct the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or used to instruct the UE to delete or discard the new NAS
  • the security context is used to instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or, to notify the target AMF that AMF redirection occurs, and/or to indicate
  • the target AMF sends an
  • the target AMF should include indication information used to instruct the UE to delete the NAS security context in the authentication request message sent to the UE, and/or include indication information used to instruct the UE to deactivate the current NAS security
  • the indication information of the context includes the indication information used to instruct the UE to process the authentication request message without security protection, and/or include the indication information used to indicate the occurrence of AMF redirection on the UE network side; and/or, include The indication information used to instruct the UE to restore the NAS-free security context, and/or include the indication information used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or include Instruction information for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or include instruction information for instructing the UE to delete or discard a new NAS security context, and/or include Indication information for instructing the UE to deactivate the current NAS security context established
  • the target AMF receives an authentication response message without security protection sent by the UE.
  • the UE receives an authentication request message sent by the target AMF.
  • the authentication request information includes indication information for instructing the UE to delete the NAS security context, or indication information for instructing the UE to deactivate the current NAS security context, or including indication information for indicating Indication information for the UE to process an authentication request message without security protection, or including indication information for indicating that AMF redirection occurs on the network side of the UE;
  • the UE according to the indication information included in the authentication request message for instructing the UE to delete the NAS security context, deletes the NAS security context, and processes the authentication request message; the UE according to the indication information included in the authentication request message for instructing the UE Indication information for deactivating the NAS security context, deactivating the current NAS security context, and processing the authentication request message; the UE according to the instructions included in the authentication request message for instructing the UE to process the authentication request message without security protection, Processing an authentication request message without security protection; the UE processes the authentication request message according to the indication information included in the authentication request message for indicating that AMF redirection has occurred on the network side of the UE.
  • the UE should, discard or delete the NAS security context; and/or, deactivate the current NAS security context of the UE, and/or determine not to discard and process the received non-security protection Authentication request message, and/or, confirm that AMF redirection occurs on the network side, and/or restore no NAS security context, and/or delete or discard the new NAS security context established by the UE and the initial AMF, And/or, delete or discard the NAS security context established by the UE and the initial AMF, and/or delete or discard the new NAS security context, and/or, deactivate the UE and all The current NAS security context established by the initial AMF; and/or, restore to use the saved NAS security context, if any.
  • the UE sends an authentication response message without security protection to the target AMF.
  • the target AMF includes indication information for instructing the UE to delete the NAS security context in the authentication request message sent to the UE, or includes indication information for instructing the UE to deactivate the current NAS security context, or It includes indication information used to instruct the UE to process the authentication request message without security protection, or includes indication information used to indicate that AMF redirection occurs on the network side of the UE.
  • the UE deletes the NAS security context according to the indication information used to instruct the UE to delete the security context included in the authentication request message.
  • the UE deactivates the current NAS security context according to the indication information used for instructing the UE to deactivate the current security context included in the authentication request message.
  • the UE processes the authentication request message without security protection according to the instruction information included in the authentication request message for instructing the UE to process the authentication request message without security protection.
  • the UE processes the authentication request message according to the instructions included in the authentication request message for indicating the occurrence of AMF redirection on the network side of the UE.
  • the UE resumes using the saved NAS security.
  • the UE processes the authentication request message. It is ensured that the UE does not discard and process the received authentication request message.
  • the initial AMF sends sixth indication information to the RAN, and the target AMF receives the sixth indication information sent by the RAN.
  • the initial AMF carries the sixth indication information in the Reroute NAS Message and sends it to the (R)AN.
  • (R) AN carries the sixth indication information in the Initial UE Message and sends it to the target AMF.
  • the target AMF receiving sixth indication information includes:
  • the target AMF receives a second notification message sent by the RAN, the second notification message carries second indication information, and the second indication information is used to instruct the UE to delete the NAS security context, and/or to instruct the UE to Activate the current NAS security context, and/or, used to instruct the UE to process authentication request information without security protection, and/or, used to indicate the occurrence of AMF redirection on the UE network side, and/or, used to instruct the UE to restore no NAS security Context, and/or, used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or, used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF NAS security context, and/or, is used to instruct the UE to delete or discard the new NAS security context, and/or, to instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF , And/or, notify the target A
  • the target AMF includes the third indication information in the authentication request message sent to the UE according to the second indication information, which is used to instruct the UE to delete the NAS security context, and/or to instruct the UE to deactivate the current NAS security
  • the context is used to instruct the UE to process authentication request information without security protection, and/or, to indicate the occurrence of AMF redirection on the UE network side, and/or, to instruct the UE to restore the NAS-free security context, and/or Or, for instructing the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, And/or for instructing the UE to delete or discard the new NAS security context, and/or for instructing the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or Notifying the target AMF that AMF redirection occurs, and/or instruct
  • the UE deletes the NAS security context, processes the authentication request message, and/or deactivates the current NAS security context, processes the authentication request message, and/or processes the authentication request message without security protection, And/or, determine that AMF redirection occurs on the network side, process the authentication request message, and/or restore the NAS-free security context, process the authentication request message, and/or delete or discard the new established by the UE and the initial AMF NAS security context, processing authentication request messages, and/or, deleting or discarding the NAS security context established by the UE and the initial AMF, processing authentication request messages, and/or, deleting or discarding the new NAS security context , Process the authentication request message, and/or, deactivate the current NAS security context established by the UE and the initial AMF, process the authentication request message, and/or, resume using the saved NAS security context, if any Then, process the authentication request message.
  • the target AMF includes the third indication information in the authentication request message sent to the UE according to the received second notification message or second indication information, and the UE deletes the NAS security context according to the third indication information, and processes the authentication request message , And/or, deactivate the current NAS security context, process the authentication request message, and/or, process the received authentication request message without security protection, and/or, determine that AMF redirection occurs on the network side, and process the authentication request message, And/or, restore no NAS security context, process the authentication request message, and/or delete or discard the new NAS security context established by the UE and the initial AMF, process the authentication request message, and/or delete or discard
  • the target AMF receiving the sixth indication information includes:
  • the target AMF receives a third notification message sent by the RAN, where the third notification message carries fourth indication information;
  • the fourth indication information may also be used to notify the target AMF that AMF redirection occurs, and/or instruct the target AMF to send an indication to the UE.
  • the target AMF includes the fourth indication information in the authentication request message sent to the UE according to the fourth indication information.
  • the indication information carried in the authentication request message for instructing the UE to delete the NAS security context, or the indication information for instructing the UE to deactivate the current NAS security context, or the indication for instructing the UE to process the authentication request information without security protection Information, or indication information used to indicate the occurrence of AMF redirection on the UE network side is the fourth indication information;
  • the UE should verify the fourth indication information, and after the verification is successful, it should delete the NAS security context, process the authentication request message, and/or deactivate the current NAS security context, process the authentication request message, and/or deal with no security Protected authentication request message, and/or, restore no NAS security context, process the authentication request message, and/or delete or discard the new NAS security context established by the UE and the initial AMF, process the authentication request message, and /Or, delete or discard the NAS security context established by the UE and the initial AMF, process the authentication request message, and/or, the UE delete or discard the new NAS security context, process the authentication request message, and/or, Deactivate the current NAS security context established by the UE and the initial AMF, process the authentication request message, and/or restore the use of the saved NAS security context, if any, process the authentication request message.
  • the fourth indication information is generated by the initial AMF according to the shared key with the UE.
  • the fourth indication information includes the first parameter and the message authentication code of the first parameter.
  • the first parameter may be a random number, or one or more of the UL NAS Count of the registration message sent by the UE to the initial AMF, or the UL NAS Count of NAS Security Complete sent by the UE to the initial AMF.
  • the first parameter message authentication code is a message authentication code calculated for the first parameter by using the initial AMF according to the shared key with the UE.
  • the shared key may be one or more of Kamf or Kseaf generated through master authentication between the UE and the initial AMF, or the NAS encryption key Knasenc, or the NAS full security key Knasint.
  • the target AMF includes fourth indication information in the authentication request message sent to the UE.
  • the UE verifies the fourth indication information, deletes the NAS security context, or deactivates the current NAS security context, or handles the failure Security-protected authentication request message, or it is determined that AMF redirection occurs on the network side.
  • the fourth instruction information is verified to prevent the attacker from sending the counterfeit The fourth instruction information improves the security of the entire registration process.
  • the target AMF receiving sixth indication information includes:
  • the target AMF receives a complete registration request message sent by the RAN;
  • the target AMF sends an authentication request message to the UE according to the complete registration request message, and includes fifth indication information in the authentication request for instructing the UE to delete the NAS security context, and/or for indicating
  • the UE deactivates the current NAS security context, and/or, is used to instruct the UE to process authentication request information without security protection, and/or, is used to indicate that AMF redirection occurs on the UE network side, and/or, is used to instruct the UE to restore NAS security context, and/or, used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or to instruct the UE to delete or discard the UE and the initial AMF
  • the established NAS security context, and/or is used to instruct the UE to delete or discard the new NAS security context, and/or, to instruct the UE to deactivate the current NAS established by the UE and the initial AMF
  • the security context, and/or, is used to instruct the UE to resume using
  • the UE should delete the NAS security context, process the authentication request message, and/or deactivate the current NAS security context, process the authentication request message, and/or process the authentication request without security protection Message, and/or, restore no NAS security context, process authentication request message, and/or, delete or discard the new NAS security context established by the UE and the initial AMF, process the authentication request message, and/or delete Or discard the NAS security context established by the UE and the initial AMF, process the authentication request message, and/or, the UE deletes or discards the new NAS security context, process the authentication request message, and/or, deactivate )
  • the target AMF includes the fifth indication information in the authentication request message sent to the UE according to the received complete registration request message, and the UE deletes the NAS security context or deactivates the current NAS security context according to the fifth indication information, or Processing the received authentication request message without security protection, or determining that AMF redirection occurs on the network side, ensures that the UE does not discard and processes the received authentication request message.
  • the target AMF sending an authentication request message to the UE to instruct the UE to delete or deactivate the NAS security context includes:
  • the target AMF carries the ngKSI in an authentication request message and sends the ngKSI to the UE according to the acquired next-generation key set identifier ngKSI.
  • the ngKSI is used to instruct the UE to delete or deactivate the NAS security corresponding to the ngKSI Context.
  • the authentication request message carries the next generation key set identifier ngKSI, and the UE deleting or deactivating the NAS security context includes:
  • the UE deletes or deactivates the NAS security context corresponding to the ngKSI, which ensures that the UE does not discard and process the received authentication request message.
  • a registration method including the following processes:
  • UE establishes NAS security context with initial AMF
  • the UE processes the authentication request message without security protection.
  • the UE sends an authentication response message without security protection.
  • the UE may not discard it, but directly process the authentication request message without security protection, which ensures that the initial registration of the UE is successful and the UE successfully accesses the network.
  • a registration method including the following processes:
  • the initial AMF sends a first non-access stratum security mode command (NAS Ssecurity Mode Command) message to the UE, or the initial AMF sends a first non-access stratum security mode command message carrying eighth indication information to the UE.
  • the eighth indication information is used to instruct the UE to save the NAS security context, if any, or to instruct the UE to save the currently used NAS security context, if any.
  • the UE should save the NAS security context, if any, or save the currently used NAS security context, if any .
  • the initial AMF decides to perform AMF redirection and determines the target AMF
  • the initial AMF sends sixth indication information to the target AMF and/or user equipment UE, which is used to instruct the UE to delete the NAS security context, or to instruct the UE to deactivate the current NAS security context, or to instruct the UE to process an authentication request without security protection Message, or indicating that AMF redirection occurs on the network side of the UE;
  • the sixth indication information can also be used to instruct the UE to delete the NAS security context, and/or to instruct the UE to deactivate the current NAS security context, and/or to Instruct the UE to process the authentication request information without security protection, and/or, to indicate the occurrence of AMF redirection on the UE network side, and/or to instruct the UE to restore the NAS-free security context, and/or to instruct the UE to delete or Discard the new NAS security context established by the UE and the initial AMF, and/or, instruct the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or,
  • the initial AMF sending the sixth indication information to the target AMF and/or UE includes:
  • the initial AMF includes the second notification message in the Reroute NAS Message sent to the (radio) access network ((R)AN), and the second notification message includes the second indication information.
  • the second indication information is used to instruct the UE to delete the NAS security context, or to instruct the UE to deactivate the current NAS security context, or to instruct the UE to process an authentication request message without security protection, or to indicate that an AMF redirection occurs on the UE network side .
  • the second indication information may also be used to instruct the UE to delete the NAS security context, and/or to instruct the UE to deactivate the current NAS security context, and/or to instruct the UE to process the authentication request information without security protection, and /Or, used to indicate the occurrence of AMF redirection on the network side of the UE, and/or used to instruct the UE to restore no NAS security context, and/or, used to instruct the UE to delete or discard the UE and the new AMF established by the initial AMF
  • the NAS security context and/or, is used to instruct the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or to instruct the UE to delete or discard the new NAS security context, and /Or, used to instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or, notify the target AMF that AMF redirection occurs, and/or, indicate the target AMF Send an indication to the UE, and/
  • the (radio) access network ((R)AN) sends the received second notification message to the target AMF in the Initial UE Message.
  • the target AMF includes third indication information in the authentication request message sent to the UE according to the second indication information, used to instruct the UE to delete the NAS security context, and/or to instruct the UE to deactivate the current NAS security context, And/or, used to instruct the UE to process the authentication request information without security protection, and/or, used to indicate the occurrence of AMF redirection on the UE network side, and/or, used to instruct the UE to restore the NAS-free security context, and/or, Used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or to instruct the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/ Or, for instructing the UE to delete or discard the new NAS security context, and/or for instructing the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or To instruct the UE to resume using the saved NAS security context, if any.
  • the initial AMF sending the sixth indication information to the target AMF and/or UE includes:
  • the initial AMF includes a third notification message in the Reroute NAS Message sent to the (radio) access network ((R)AN), and the third notification message includes fourth indication information.
  • the fourth indication information is used to instruct the UE to verify the fourth indication information, and after the verification succeeds, delete the NAS security context, and/or deactivate the current NAS security context, and/or process the authentication request message without security protection , And/or, instruct the UE to have AMF redirection on the network side, and/or restore no NAS security context, and/or delete or discard the new NAS security context established by the UE and the initial AMF, and/or , Delete or discard the NAS security context established by the UE and the initial AMF, and/or, the UE deletes or discards the new NAS security context, and/or, deactivate the UE and the initial AMF
  • the current NAS security context established by AMF, and/or is used to instruct the UE to resume using the saved NAS security context, if any.
  • the third notification message also includes a registration request carrying SUCI.
  • the third notification message also includes optional ngKSI.
  • the (radio) access network ((R)AN) sends the received third notification message to the target AMF in the Initial UE Message.
  • the target AMF includes the fourth indication information and optional ngKSI in the authentication request message sent to the UE according to the fourth indication information;
  • the initial AMF sending the sixth indication information to the target AMF and/or UE includes:
  • the initial AMF includes the complete initial registration request message and optional ngKSI in the Reroute NAS Message sent to the (radio) access network ((R)AN).
  • the (radio) access network ((R)AN) sends the received complete registration request message and optionally ngKSI to the target AMF in the Initial UE Message.
  • the target AMF sends an authentication request message to the UE according to the complete registration request information, and includes fifth indication information in the authentication request message for instructing the UE to delete the NAS security context, and/or for Instruct the UE to deactivate the current NAS security context, and/or, to instruct the UE to process authentication request information without security protection, and/or to instruct the UE to have AMF redirection on the network side, and/or to instruct the UE to recover No NAS security context, and/or used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or to instruct the UE to delete or discard the UE and the initial AMF
  • the NAS security context established by AMF, and/or is used to instruct the UE to delete or discard the new NAS security context, and/or, to instruct the UE to deactivate the UE and the current established by the initial AMF
  • the NAS security context, and/or is used to instruct the UE to resume using the saved NAS security
  • a registration method including the following processes:
  • the initial AMF decides to initiate AMF redirection through (R)AN or NAS Reroute through (R)AN, and decides to redirect to the target AMF.
  • the initial AMF should request the target AMF to allocate a new 5G for the UE -GUTI, or the initial AMF allocates a new 5G-GUTI to the UE, or the initial AMF should request the target AMF to allocate a special new 5G-GUTI for AMF redirection or the initial AMF allocates a new 5G-GUTI for the UE for AMF redirection
  • the initial AMF should send the new 5G-GUTI to the UE, the initial AMF should initiate a de-registration process or a registration rejection message to instruct the UE to re-register, and the initial AMF should optionally initiate an RRC link Release, the UE should perform reselection registration according to the instructions, and the UE should initiate a registration request message RR carrying a new 5G
  • the initial AMF should skip the NAS reroute step through the (R)AN, that is, skip the initial AMF and send the received registration request to the (R)AN, and the (R)AN sends the registration request to the target AMF the process of.
  • the initial AMF should send a request to the target AMF to allocate a new 5G-GUTI to the UE.
  • the target AMF should allocate a new 5G-GUTI to the UE, and the target AMF should carry the new 5G-GUTI.
  • the message is sent to the initial AMF.
  • the target AMF After the target AMF allocates a new 5G-GUTI, it marks the new 5G-GUTI, such as marking the new 5G-GUTI as the 5G-GUTI used in the AMF redirection scenario, and/or marking the new 5G-GUTI GUTI is a new 5G-GUTI allocated for UE.
  • the initial AMF requests the target AMF to allocate a new 5G-GUTI.
  • the initial AMF should send the SUCI carried in the received registration request to the target AMF.
  • the target AMF After the target AMF receives the SUCI sent by the initial AMF, it should store the SUCI and establish the corresponding relationship between the SUCI and the new 5G-GUTI.
  • the initial AMF should notify the target AMF that AMF redirection occurs.
  • the initial AMF should allocate a new 5G-GUTI for the UE.
  • the new 5G-GUTI is a new 5G-GUTI allocated to the UE.
  • the initial AMF should send a request to the target AMF to allocate a special new 5G-GUTI for the UE for AMF redirection, and the target AMF should allocate a special new 5G-GUTI for the UE for AMF redirection.
  • the target AMF should send a message carrying a special new 5G-GUTI for AMF redirection to the initial AMF.
  • the initial AMF requests the target AMF to allocate a special new 5G-GUTI for AMF redirection.
  • the initial AMF sends the SUCI carried in the received registration request to the target AMF.
  • the target AMF After the target AMF receives the SUCI sent by the initial AMF, it should store the SUCI, and establish the corresponding relationship between the SUCI and the special new 5G-GUTI used for AMF redirection.
  • the initial AMF notifies the target AMF that AMF redirection occurs.
  • the initial AMF allocates a special new 5G-GUTI for AMF redirection to the UE.
  • the target AMF receives the registration request RR and checks the 5G-GUTI carried in the RR.
  • the target AMF should initiate an identity request process to obtain the SUCI of the UE and perform the primary authentication to achieve the successful registration of the UE.
  • the target AMF should search for the corresponding relationship between SUCI and 5G-GUTI, and perform master authentication to achieve successful UE registration.
  • the target AMF determines that the 5G-GUTI is the 5G-GUTI used in the AMF redirection scenario, the target AMF should initiate an identity request process to obtain the SUCI of the UE and perform primary authentication to achieve successful registration of the UE.
  • the target AMF should look up the correspondence between SUCI and 5G-GUTI and perform master authentication to achieve successful UE registration.
  • the target AMF should initiate the master authentication to achieve the successful registration of the UE.
  • the target AMF should initiate an identity request process to obtain the SUCI of the UE, and then perform primary authentication to achieve successful registration of the UE.
  • a registration method including the following processes:
  • the UE may optionally carry an indicator 1 in the registration request message.
  • the indicator 1 is used to indicate:
  • the UE is a non-version 15 UE.
  • the UE is a version 16 or later UE; or
  • the UE supports the ability to perform NAS reroute through (R)AN; or
  • the UE supports the ability to perform AMF redirection through (R)AN; or
  • the UE supports the capability of NAS security context fallback (in NAS reroute via (RAN)/AMF redirection via (RAN)); or
  • the UE supports (in NAS reroute via (RAN) / AMF redirect via (RAN)) (recovers) the ability to use the old NAS security context; or
  • the UE supports the ability to delete a new NAS security context (in NAS reroute via (RAN)/AMF redirect via (RAN)); or
  • the UE supports (NAS reroute via (RAN) / AMF redirect via (RAN)) to support the ability to recover to no NAS security context; or
  • the UE supports the ability to perform NAS security context processing in NAS reroute (in NAS reroute via (RAN)/AMF redirect via (RAN)).
  • the initial AMF does not receive the indication 1, or the initial AMF according to the registration request message,
  • the initial AMF should perform direct NAS reroute or the initial AMF should directly register
  • the request message is forwarded to the target AMF, or the initial AMF executes all the methods in any one of the fifth aspect and the fifth aspect.
  • the initial AMF to execute the initial AMF should send to the target AMF a request to allocate a new 5G-GUTI for the UE, or the initial AMF should request the target AMF to allocate a special new 5G-GUTI for AMF redirection. Or, the initial AMF should allocate a new 5G-GUTI for the UE, or the initial AMF should allocate a special new 5G-GUTI for the UE for AMF redirection.
  • the initial AMF receives the indicator 1, or the initial AMF according to the registration request message,
  • initial AMF performs the first, second, third, fourth aspects and first, All the methods in any one of the two, three, and four aspects.
  • the initial AMF should notify the UE to send AMF redirection, or the initial AMF should instruct the UE to delete the NAS security context, or the initial AMF should return to the security when sending the registration request, or the initial AMF should instruct the UE to receive and process the unprotected authentication request News etc. Or the initial AMF should notify the target AMF that AMF redirection occurs. Or the initial AMF should send the NAS security context to the target AMF. Or the initial AMF should send the complete registration request message to the target AMF.
  • the initial AMF if the initial AMF decides to perform NAS reroute through the (R)AN (or send the registration request message to the target AMF through the (R)AN) according to the local policy and subscription information, the initial AMF performs the first, All the methods in the second, third, fourth aspect and any one of the first, second, third, and fourth aspects.
  • a registration method including the following processes:
  • the initial AMF decides to initiate AMF redirection according to the local policy during the UE registration process, and the initial AMF decides to perform direct NAS Reroute, that is, when the registration request (or NAS message) is sent directly to the target AMF, the initial AMF performs one of the following three methods A described step.
  • the initial AMF should send the current NAS security context of the UE to the target AMF.
  • the initial AMF decides whether to perform horizontal Kamf deduction according to the initial AMF local strategy. If the initial AMF decides to perform horizontal Kamf deduction, the initial AMF generates a new Kamf and sends the new Kamf to the target AMF. If the initial AMF decides not to perform horizontal Kamf deduction, the initial AMF should send the UE's current NAS security context to the target AMF.
  • the initial AMF determines whether the initial AMF performs key derivation according to whether the first AMF performs key derivation, specifically including the following possibilities:
  • the initial AMF decides whether to perform key derivation according to the local policy.
  • the key derivation instruction may Called keyAMFHDerivationInd, it is used to indicate that the first AMF has performed key derivation, and the initial AMF decides whether to perform key derivation according to the local policy. If the initial AMF decides to perform horizontal Kamf deduction, the initial AMF generates a new Kamf and sends the new Kamf to the target AMF. If the initial AMF decides not to perform horizontal Kamf deduction, the initial AMF should send the UE's current NAS security context to the target AMF.
  • the first AMF may be the initial AMF or the target AMF, or may be other AMFs except the initial AMF and the target AMF.
  • the first AMF performs key derivation, and the initial AMF sends the UE's current NAS security context to the UE.
  • the initial AMF receives the thirteenth indication information from the first AMF that indicates that a new key is generated; or the initial AMF receives the key derivation instruction sent by the first AMF, the initial AMF will change the security context of the current UE Sent to UE.
  • the initial AMF performs horizontal Kamf deduction to generate a new Kamf.
  • Initial AMF to generate a new Kamf should include one of the following:
  • the initial AMF generates a new Kamf according to the current Kamf and the value of the uplink NAS COUNT in the registration request RR; or,
  • the initial AMF generates a new Kamf based on the current Kamf and the value of the uplink NAS COUNT in the NAS Security Mode Complete message; or,
  • the initial AMF generates a new Kamf based on the current Kamf and the value of the current downlink NAS COUNT.
  • the initial AMF performs horizontal Kamf deduction to generate a new Kamf including one of the following:
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the uplink NAS COUNT in the received registration request RR.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the uplink NAS COUNT in the received NAS Security Mode Complete message.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the uplink NAS COUNT of the most recently received N1 message.
  • the N1 message includes the registration request RR and/or NAS Security Mode Complete message, that is, if the initial AMF receives the NAS Security Mode Complete message sent by the UE, the NAS Security Mode Complete message is the most recently received N1 message, the initial AMF According to the current Kamf and the value of the uplink NAS COUNT in the received NAS Security Mode Complete message, a new Kamf is generated; otherwise, the registration request RR is the most recently received N1 message, and the initial AMF is based on the current Kamf and the received registration Request the value of uplink NAS COUNT in RR to generate a new Kamf.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the current downlink NAS COUNT.
  • the initial AMF should generate a new Kamf according to the current Kamf and the value of the uplink NAS COUNT in the received registration request RR; otherwise, The initial AMF should generate a new Kamf based on the current Kamf and the value of the current downlink NAS COUNT.
  • the initial AMF receives only one NAS message, and the NAS message is a registration request RR, the initial AMF generates a new Kamf according to the current Kamf and the value of the uplink NAS COUNT in the received registration request RR; otherwise, the initial AMF is based on The current Kamf and the current downlink NAS COUNT value will generate a new Kamf.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the uplink NAS COUNT in the received registration request RR; otherwise, the initial AMF should be based on the current The value of Kamf and the current downlink NAS COUNT will generate a new Kamf.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of uplink NAS COUNT in the received registration request RR; otherwise, the initial AMF should be based on the current Kamf and The current value of downlink NAS COUNT generates a new Kamf.
  • the initial AMF should generate a new Kamf based on the current Kamf and the current downlink NAS COUNT; otherwise, the initial AMF should generate a new Kamf based on the current Kamf and received
  • other NAS messages include NAS Security Mode Complete messages.
  • the initial AMF should send the generated new Kamf to the target AMF, and the initial AMF should send an indication that a new Kamf is generated, or an indication that a horizontal Kamf has been deduced, to the target AMF. ;
  • the initial AMF should also send an instruction for AS key re-keying to the target AMF.
  • the Initial AMF should include the new Kamf generated in Namf_Communication_N1MessageNotify, indicating Indicator2, and indicating the need to perform AS key re-keying.
  • Initial AMF should send the value of the downlink NAS COUNT to the target AMF.
  • Initial AMF should include the value of the downlink NAS COUNT used to generate a new Kamf in Namf_Communication_N1MessageNotify.
  • the initial AMF should send the uplink NAS COUNT value used to generate the new Kamf to the target AMF; or if the initial AMF uses the uplink NAS COUNT of the registration request when generating the new Kamf, the initial AMF should An indicator used to indicate "use the uplink NAS COUNT value of the registration request message to generate a new Kamf" is sent to the target AMF; or if the initial AMF uses the NAS Security Mode Complete message uplink NAS COUNT when generating a new Kamf, the initial The AMF sends an indication Indicator4 to the target AMF to indicate "Generate a new Kamf using the uplink NAS COUNT value of the NAS Security Mode Complete message".
  • the initial AMF should send an indication IndicatorX to Target AMF.
  • the indication IndicatorX is used to indicate "the registration request message comes from a verified UE", or “the UE has passed authentication”, or “the registration message has passed Verification”, or “No need to verify UE”, or “No need to verify registration message”.
  • the initial AMF may optionally include IndicatorX in the Namf_Communication_N1MessageNotify message to send to the target AMF.
  • the initial AMF should send IndicatorX to the target AMF.
  • the target AMF receives Kamf
  • the target AMF decides whether to use the received Kamf according to the local policy, if it decides to use the received Kamf, and if the target AMF receives a new Kamf instruction or needs to be leveled
  • the instruction of Kamf deduction then the target AMF should send the UE an instruction to perform horizontal Kamf deduction to the UE.
  • the target AMF should set K_AMF_change_flag (the indication of UE level Kamf deduction) to 1, and send it to the UE.
  • the target AMF should initiate a re-authentication and re-establish a new NAS security context with the UE.
  • the target AMF also sends the information of the value used to generate the new Kamf to the UE, which specifically includes one of the following:
  • the target AMF should send the downlink NAS COUNT value to the UE.
  • the target AMF should include the downlink NAS COUNT value in the NAS Container including the downlink NAS COUNT value.
  • the target AMF should send the uplink NAS COUNT value to the UE.
  • the target AMF should include the uplink NAS COUNT value in the NAS Secure Mode Command message.
  • the target AMF should send an indication to the UE indicating "Generate a new Kamf using the uplink NAS COUNT value in the registration request message" Indicator5, specifically the target AMF should include the Indicator5 in the NAS
  • the Security Mode Command message is sent to the UE.
  • the target AMF should send an indication to the UE indicating "Generate a new Kamf using the uplink NAS COUNT value in the NAS security mode complete message" Indicator6, specifically the target AMF should include this Indicator6 It is sent to the UE in the NAS Security Mode Command message.
  • the target AMF if the target AMF receives IndicatorX, the target AMF does not verify the received registration request RR, or the target AMF does not verify the UE.
  • the UE receives an instruction indicating the UE level Kamf deduction, and the UE performs the level Kamf deduction to generate a new Kamf.
  • the UE when the UE receives that the value of K_AMF_change_flag is 1, it determines that it has received the information indicating the UE level Kamf deduction.
  • the UE performs horizontal Kamf deduction according to the information indicating the value used to generate the new Kamf to generate the new Kamf, which specifically includes one of the following:
  • the UE uses the downlink NAS COUNT value to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value in the registration request message to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value in NAS Security Mode Complete to generate a new Kamf.
  • the UE uses the value of uplink NAS COUNT in the most recently sent N1 message to generate a new Kamf. Specifically, if the UE recently sent a NAS Security Command message, the UE uses the value of uplink NAS COUNT in the NAS Security Command message to generate a new Kamf. Kamf, otherwise the UE uses the uplink NAS COUNT value in the sent registration request message.
  • a registration device In an eighth aspect, a registration device is provided.
  • the device provided in the present application specifically implements the functions of the AMF or UE behavior in the foregoing method, and includes means for executing the steps or functions described in the foregoing method.
  • the steps or functions can be realized by software, or by hardware (such as a circuit), or by a combination of hardware and software.
  • the foregoing device includes one or more processors and communication units.
  • the one or more processors are configured to support the apparatus to perform corresponding functions of the AMF or the UE in the foregoing method.
  • the device may further include one or more memories, where the memory is used for coupling with the processor and stores necessary program instructions and/or data for the device.
  • the one or more memories may be integrated with the processor, or may be provided separately from the processor. This application is not limited.
  • the above device includes a transceiver, a processor, and a memory.
  • the processor is used to control the transceiver or the input/output circuit to send and receive signals
  • the memory is used to store computer programs
  • the processor is used to run the computer programs in the memory so that the device executes the first, second, third, fourth, fifth,
  • the method performed by the AMF or UE in any one of the six or seven aspects or the first, second, third, fourth, fifth, sixth, and seventh aspect.
  • the foregoing device includes one or more processors and communication units.
  • the one or more processors are configured to support the apparatus to perform corresponding functions of the AMF or the UE in the foregoing method.
  • the device may further include one or more memories, where the memories are used for coupling with the processor and store program instructions and/or data necessary for the AMF or the UE.
  • the one or more memories may be integrated with the processor, or may be provided separately from the processor. This application is not limited.
  • the device may be located in AMF or UE, or may be AMF or UE.
  • the above device includes a transceiver, a processor, and a memory.
  • the processor is used to control the transceiver or the input/output circuit to send and receive signals
  • the memory is used to store computer programs
  • the processor is used to run the computer programs in the memory so that the device executes the first, second, third, fourth, fifth, and sixth AMF or UE in any one of the seven aspects or the first, second, third, fourth, fifth, sixth, and seventh aspects.
  • a computer-readable storage medium for storing a computer program.
  • the computer program includes methods for executing the first, second, third, fourth, fifth, sixth and seventh aspects or the first, second, third, Instructions for the method in any one of the four, five, six, and seven aspects.
  • a computer program product includes: computer program code, which when the computer program code runs on a computer, causes the computer to execute the first, second, third, fourth, fifth, The method in the sixth or seventh aspect or any one of the first, second, third, fourth, fifth, sixth, and seventh aspects.
  • Figure 1 is a schematic diagram of a 5G system UE registration process
  • Figure 2 is a schematic diagram of a registration method applicable in an embodiment of the application
  • Figure 3 is a schematic diagram of a registration method applicable in an embodiment of the application.
  • Fig. 4 is a schematic diagram of a registration method applicable in an embodiment of the application.
  • Fig. 5 is a schematic diagram of a registration method applicable in an embodiment of the application.
  • Fig. 6 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 7 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 8 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 9 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 10 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 11 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 12 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 13 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 14 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 15 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • FIG. 16 is a schematic diagram of a registration process applicable in an embodiment of this application.
  • Fig. 17 is a structural diagram of a registration device applicable in an embodiment of this application.
  • the technical solutions of the embodiments of the present application can be applied to various communication systems, such as the fourth generation (4th Generation, 4G), the 4G system includes the long term evolution (LTE) system, and the worldwide interconnection for microwave access (worldwide interoperability).
  • 4G fourth generation
  • WiMAX long term evolution
  • 5G future 5th Generation
  • NR new radio access technology
  • 6G future communication systems
  • the entity can be understood as a communication device in the communication system.
  • the term "exemplary” is used to indicate an example, illustration, or illustration. Any embodiment or design solution described as an "example” in this application should not be construed as being more preferable or advantageous than other embodiments or design solutions. Rather, the term example is used to present the concept in a concrete way.
  • AMF is a core access and mobility management function network element, used to manage UE access and mobility, specifically including: UE registration, UE mobility management, NAS connection, access authentication and authorization, and provision for UE and SMF Transmission and other functions.
  • UE is user equipment, including Universal Subscriber Identity Module (USIM) card and Mobile Equipment (ME) mobile equipment, sending or receiving NAS and Radio Resource Control (Radio Resource Control, RRC) requests Message, establish a user plane tunnel with the base station.
  • USIM Universal Subscriber Identity Module
  • ME Mobile Equipment
  • RRC Radio Resource Control
  • the "and/or” in this application describes the association relationship of the associated objects, indicating that there can be three relationships, for example, A and/or B, which can mean: A alone exists, A and B exist at the same time, and B exists alone. This situation.
  • the character "/" generally indicates that the associated objects are in an "or” relationship.
  • the multiple involved in this application refers to two or more.
  • the standard 3GPP TS 23.502[1] defines the process of AMF redirection in the registration process of the UE in the 5G system. Take the registration process diagram shown in Figure 1 as an example to explain in detail the application scenarios of this application in the registration process ,
  • the registration process includes:
  • Step 101 During the initial registration, the UE initiates a Registration Request (RR in abbreviation) carrying SUCI.
  • RR Registration Request
  • the UE has no NAS security context.
  • the registration request initiated by the UE in this step only carries cleartext IEs and does not include Requested S-NSSAIs.
  • AMF can determine whether it can serve the UE according to Requested S-NSSAIs.
  • the Requested S-NSSAIs is for requesting single network slice selection assistance information (Single Network Slice Selection Assistance Information, NSSAI). Allowed NSSAIs is allowed NSSAIs, which means which S-NSSAIs of the NSSAIs requested by the UE are allowed by the network.
  • the network will receive the registration message Registration Accept or the "Allowed NSSAI" IE in the Configuration Update Command and bring it to the UE.
  • the UE can send a registration request to the (Radio) Access Network ((R)AN), and after receiving the UE’s registration request, the (R)AN chooses to send the registration request Give the initial AMF (Initial AMF).
  • (R)AN Radio) Access Network
  • Step 102 After receiving the registration request carrying the SUCI, the initial AMF initiates Primary Authentication.
  • the initial AMF and the UE respectively generate an AMF key, denoted as Kamf, and the next-generation key set identifier ngKSI corresponding to the AMF key.
  • Step 103 The initial AMF initiates a NAS security mode command (NAS Security Mode Command, NAS SMC), activates and starts to use the Kamf generated by the master authentication.
  • the initial AMF includes a request complete initial NAS message flag (request complete initial NAS message flag) in the NAS SMC.
  • the UE returns the NAS Security Mode Complete message, activates and starts to use the Kamf generated by the master authentication.
  • the security mode completion message includes a complete initial NAS message, that is, a complete registration request message.
  • the complete registration request message includes Requested S-NSSAIs.
  • the NAS security context is established between the initial AMF and the UE, including the Kamf generated by the master authentication, the corresponding ngKSI, the upper and lower NAS Count, and the downlink NAS Count.
  • Step 104 The initial AMF determines whether it can serve the UE according to the Requested S-NSSAIs. If the initial AMF determines that it cannot serve the UE, the initial AMF decides to perform NAS reroute (AMF redirection).
  • AMF redirection AMF redirection
  • the initial AMF determines that the AMF is redirected to the target Target AMF, and the target AMF is an AMF that can provide services for the UE.
  • the initial AMF may obtain information about the target AMF from a network slice selection function (Network Slice Selection Function, NSSF).
  • NSSF Network Slice Selection Function
  • the UE does not perceive the process of AMF redirection.
  • Step 105 The initial AMF sends the received registration request to the (R)AN.
  • the initial AMF sends the registration request with SUCI received in step 1.1.
  • the initial AMF carries the registration request message carrying the SUCI in the non-access stratum Reroute NAS Message and sends it to the (R)AN.
  • Step 106 (R) AN sends the received registration request to the target AMF.
  • the (R)AN sends the registration request message carrying the SUCI to the target AMF with the initial user equipment message in the Initial UE Message.
  • Step 107 The target AMF decides to initiate primary authentication (Initiates primary authentication).
  • the target AMF receives the registration request and initiates the main authentication process according to the SUCI in the registration request.
  • Step 108 The target AMF sends a user authentication request (Nausf_UEAuthentication_Authenticate Request) to an authentication server function network element (Authentication Server Function, AUSF), and AUSF returns a user authentication response (Nausf_UEAuthentication_Authenticate Response).
  • AUSF Authentication Server Function
  • Step 109 The target AMF sends an authentication request (Authentication Request) to the UE.
  • the authentication request sent by the target AMF to the UE is an authentication request message without security protection.
  • the authentication request message without security protection is a type of NAS message.
  • the UE rejects the authentication request message without security protection.
  • Step 110 The target AMF sends a registration rejection (Registration Reject) message.
  • the UE Since in step 102 and step 103, the UE performed NAS SMC with the initial AMF, the NAS security context has been established and started to be used in the UE. According to the definition in standard 24.501, after the UE establishes and starts to use the NAS security context, if it receives If the NAS message is not protected by security, the UE will not process the NAS message. Therefore, the UE will not process the authentication request message without security protection, resulting in registration failure and the UE unable to access the network.
  • the NAS security context is established and activated between the initial AMF and the UE, the initial AMF initiates AMF redirection and is directed to the target AMF, and the target AMF initiates the main authentication process and sends the UE there is no security Protected authentication request, but the UE has activated the NAS security context, and the UE does not perceive AMF redirection. Therefore, the UE does not process the received authentication request without security protection, resulting in AMF redirection during the initial registration process When the UE registration failed.
  • this application proposes a registration method to prevent the UE from discarding the received authentication request sent by the target AMF.
  • the initial AMF decides to initiate AMF redirection and redirect to the target AMF during the UE registration process
  • the initial AMF sends indication information to the UE to instruct the UE to delete the established NAS security context, and/or deactivate the current NAS security context, and/ Or instruct the UE to have AMF redirection on the network side, and/or instruct the UE to process the authentication request message without security protection
  • the UE processes the received authentication request message sent by the target AMF, and returns an authentication response message to ensure that the initial registration of the UE is successful.
  • the initial AMF sends the NAS security context established with the UE to the target AMF.
  • the target AMF uses the NAS security context to securely protect the authentication request message to be sent, and then sends the secured authentication request message to the UE, and the UE Determine that the received authentication request message is a security-protected authentication request message, process the authentication request message, and return an authentication response message to ensure that the initial registration of the UE is successful; or the UE directly processes the received authentication request message sent by the target AMF, Return an authentication response message to ensure that the initial registration of the UE is successful.
  • the initial AMF sends the indication information used to instruct the UE to delete the NAS security context to the target AMF through the RAN, or the indication information used to instruct the UE to deactivate the current NAS security, or the indication used to indicate the occurrence of AMF redirection on the UE network side Information, or indication information for instructing the UE to process authentication request information without security protection
  • the target AMF sends the indication information for instructing the UE to delete the NAS security context to the UE in the authentication request message according to the indication information, or for indicating
  • the UE deactivates the current NAS security indication information, or indication information used to indicate the occurrence of AMF redirection on the UE network side, or indication information used to instruct the UE to process the authentication request information without security protection.
  • the initial AMF sends a complete registration request message to the target AMF through the RAN
  • the target AMF sends the UE in the authentication request message according to the complete registration request message to the UE to instruct the UE to delete the NAS security context, or to instruct the UE to deactivate
  • the initial AMF sends indication information to the UE to instruct the UE to delete the established NAS security context, or to instruct the UE to deactivate the current NAS security context, or to Instruct the UE network side to occur AMF redirection, or instruct the UE to process the received authentication request message without security protection; the UE deletes the NAS security context according to the indication information, and processes the received authentication request message sent by the target AMF; or The UE deactivates the current NAS security according to the instruction information, and processes the received authentication request message sent by the target AMF; or the UE processes the received authentication request message sent by the target AMF according to the instruction information, the process includes:
  • Step 201 The initial AMF determines to perform AMF redirection and should send indication information to the UE to instruct the UE to delete or discard the NAS security context, and/or to instruct the UE to deactivate the current NAS security context of the UE, and /Or, used to instruct the UE to process the authentication request message without security protection, and/or, used to indicate the occurrence of AMF redirection on the UE network side, and/or, used to instruct the UE to restore the NAS-free security context, and/or, use For instructing the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or For instructing the UE to delete or discard the new NAS security context, and/or for instructing the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or for Instruct the UE to use the saved NAS security
  • the initial AMF receives the complete registration request message sent by the UE, and determines whether it can provide services for the UE according to the Requested S-NSSAIs carried in the complete registration request message. If it is determined that the UE cannot be served, the initial AMF determines that AMF redirection occurs. When the initial AMF decides that AMF redirection occurs, it sends indication information to the UE. The indication information is used to instruct the UE to delete the NAS security context, or to instruct the UE to deactivate the current NAS security context, or to indicate the occurrence of AMF redirection on the network side of the UE, or to indicate the UE Process the received authentication request message without security protection.
  • the initial AMF sends a non-access stratum NAS reconfiguration to the (wireless) access network ((R)AN).
  • NAS Reroute Message Before forwarding the message (NAS Reroute Message), send instruction information to the UE.
  • the initial AMF sends indication information to the UE, which may include two options.
  • the initial AMF may send a first notification message to the UE, the first notification message is used to instruct the UE to delete or discard the NAS security context, and/or to instruct the UE to deactivate the current NAS security context of the UE, and/or , Used to instruct the UE to process the authentication request message without security protection, and/or, used to indicate the occurrence of AMF redirection on the network side of the UE, and/or, used to instruct the UE to recover without NAS security context, and/or, used to indicate
  • the UE deletes or discards the new NAS security context established by the UE and the initial AMF, and/or is used to instruct the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or For instructing the UE to delete or discard the new NAS security context, and/or for instructing the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or for instructing the UE Use the saved NAS security context
  • the initial AMF may send a first NAS message to the UE.
  • the first NAS message carries first indication information.
  • the first indication information is used to instruct the UE to delete or discard the NAS security context, and/or to instruct the UE to deactivate ( deactivate)
  • the current NAS security context of the UE is used to instruct the UE to process an authentication request message without security protection, and/or, is used to indicate that AMF redirection occurs on the network side of the UE, and/or, is used to instruct the UE to recover No NAS security context, and/or used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or to instruct the UE to delete or discard the UE and the initial AMF
  • the NAS security context established by AMF and/or, is used to instruct the UE to delete or discard the new NAS security context, and/or, to instruct the UE to deactivate the UE and the current established by the initial AMF
  • the first NAS message may be an existing NAS message, for example, including but not limited to the following NAS messages: Configuration Update Command (Configuration Update Command), Downlink NAS Transport (DL NAS Transport) message, 5G system mobility management status (5G system mobility management status, 5GMM Status) and registration rejection (Registration Reject) messages, etc.
  • Configuration Update Command Configuration Update Command
  • DL NAS Transport Downlink NAS Transport
  • 5G system mobility management status 5G system mobility management status
  • 5GMM Status Registration rejection
  • Registration Reject Registration Reject
  • the indication information sent by the initial AMF to the UE may also carry a Next Generation Key Set Identifier (ngKSI), which is used to instruct the UE to delete the NAS security context corresponding to the ngKSI or to instruct the UE to deactivate the ngKSI
  • ngKSI Next Generation Key Set Identifier
  • the ngKSI is the ngKSI in the NAS security context established between the UE and the initial AMF.
  • the first notification message or the first NAS message carries ngKSI.
  • ngKSI may be directly carried in the first NAS message, or ngKSI may be carried in the first indication message of the first NAS message.
  • Step 202 The UE receives the indication information sent by the initial AMF, and according to the indication information, the NAS security context should be discarded or deleted, and/or the UE’s current NAS security context should be deactivated, and/or the UE’s current NAS security context should be deactivated, and/or the received information should not be discarded and processed.
  • the authentication request message without security protection, and/or, it is determined that AMF redirection occurs on the network side, and/or the NAS-free security context is restored, and/or, the new one established by the UE and the initial AMF is deleted or discarded NAS security context, and/or, delete or discard the NAS security context established by the UE and the initial AMF, and/or delete or discard the new NAS security context, and/or, deactivate all
  • the current NAS security context established by the UE and the initial AMF, and/or, is used to instruct the UE to use the saved NAS security context, if any.
  • the UE receives the first notification message sent by the initial AMF.
  • the UE receives the first NAS message sent by the initial AMF, and the first NAS message carries the first indication information.
  • the UE discards or deletes the NAS security context, and/or deactivates the current NAS security context of the UE, and/or determines not to discard and process the received authentication request message without security protection, and/or Or, determine that AMF redirection occurs on the network side, and/or restore no NAS security context, and/or delete or discard the new NAS security context established by the UE and the initial AMF, and/or delete or discard
  • the security context, and/or is used to instruct the UE to use the saved NAS security context, if any.
  • the UE deletes the NAS security context according to the received instruction, the UE deletes the NAS security context according to the received first notification message, or the UE deletes the NAS security context according to the first indication information carried in the first NAS message.
  • the UE deactivates the current NAS security context according to the received instruction, the UE deactivates the NAS security context according to the received first notification message, or the UE deactivates the NAS according to the first indication information carried in the first NAS message Security context.
  • the UE determines that AMF redirection occurs on the network side according to the received instructions, the UE determines that AMF redirection occurs on the network side according to the received first notification message, or the UE determines that AMF redirection occurs on the network side according to the first indication information carried in the first NAS message, Make sure that AMF redirection occurs on the network side.
  • the UE determines to process the received authentication request message without security protection according to the received instruction, the UE determines to process the received authentication request message without security protection according to the first notification message received, or the UE determines to process the received authentication request message without security protection according to the first notification message.
  • the first indication information carried in a NAS message determines to process the received authentication request message without security protection.
  • the indication information received by the UE may also carry ngKSI, which is used to instruct the UE to delete the NAS security context corresponding to the ngKSI or to deactivate the NAS security context corresponding to the ngKSI.
  • ngKSI is used to instruct the UE to delete the NAS security context corresponding to the ngKSI or to deactivate the NAS security context corresponding to the ngKSI.
  • the UE deletes the NAS security context the NAS security context corresponding to the ngKSI is deleted according to the ngKSI
  • the UE deactivates the NAS security context the NAS security context corresponding to the ngKSI is deactivated according to the ngKSI.
  • the first notification message or the first NAS message optionally carries ngKSI.
  • the UE deletes the NAS security context corresponding to the ngKSI or deactivates the NAS security context corresponding to the ngKSI according to the received first notification message or the ngKSI carried in the first NAS message.
  • Step 203 The target AMF sends an authentication request message to the UE.
  • the initial AMF sends a registration request message including SUCI to the (R)AN, and the (R)AN sends the registration request message to the target AMF.
  • the target AMF initiates the main authentication process according to the SUCI in the registration request message, and the target AMF sends an authentication request message without security protection to the UE.
  • Step 204 The UE receives the authentication request message sent by the target AMF, processes the authentication request message, and sends an authentication response message to the target AMF.
  • the authentication request message sent by the target AMF has no security protection.
  • the UE If the UE deletes the NAS security context or deactivates the current NAS security context according to the indication information sent by the initial AMF, the UE does not have the NAS security context, and the UE processes the authentication request message;
  • the UE determines to process the authentication request message without security protection according to the indication information sent by the initial AMF, the UE processes the authentication request message.
  • the UE sends an authentication response request without security protection to the target AMF.
  • the target AMF may send indication information to the UE, instruct the UE to delete the established NAS security context, or instruct the UE to deactivate the current NAS security context, or instruct the UE to occur on the network side of AMF redirection, or instruct the UE to process authentication request information without security protection;
  • the UE deletes the NAS security context according to the instruction information, and processes the received authentication request information sent by the target AMF; or the UE deactivates the current NAS security context according to the instruction information, and processes the received authentication request information sent by the target AMF; or
  • the UE processes the received authentication request message sent by the target AMF according to the instruction information.
  • FIG. 3 includes:
  • Step 301 The initial AMF sends sixth indication information to the target AMF.
  • the sixth indication information is used to instruct the UE to delete the NAS security context, and/or to instruct the UE to deactivate the current NAS security context, and/or to instruct the UE to process an authentication request message without security protection, and/or, Indicating the occurrence of AMF redirection on the network side of the UE, and/or, instructing the UE to restore no NAS security context, and/or, instructing the UE to delete or discard the new NAS security context established by the UE and the initial AMF, And/or for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or for instructing the UE to delete or discard the new NAS security context, and/or for Instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or notify the target AMF that AMF redirection occurs, and/or instruct the target AMF to send an
  • the initial AMF determines that it cannot provide services to the UE. If the initial AMF determines that it cannot provide services to the UE, the initial AMF determines that AMF redirection occurs. When the initial AMF performs AMF redirection, the sixth indication information is sent to the target AMF through the (R)AN.
  • the initial AMF when sending the sixth indication message to the target AMF through the (R)AN, the initial AMF sends the sixth indication information to the (R)AN, and the (R)AN sends the sixth indication information to the target AMF.
  • the initial AMF sends the sixth indication information to the target AMF, option one:
  • the initial AMF sends a second notification message to the target AMF through the (R)AN.
  • the initial AMF carries the second notification message in the Reroute NAS Message and sends it to the (R)AN
  • the (R)AN carries the second notification message in the Initial UE Message and sends it to the target AMF.
  • the second notification message carries second indication information, which is used to instruct the UE to delete the NAS security context, and/or to instruct the UE to deactivate the current NAS security context, and/or to instruct the UE to handle
  • An authentication request message without security protection indicates the occurrence of AMF redirection on the UE network side, and/or, is used to instruct the UE to restore the NAS-free security context, and/or, is used to instruct the UE to delete or discard the UE and
  • the new NAS security context established by the initial AMF, and/or is used to instruct the UE to delete or discard the UE and the NAS security context established by the initial AMF, and/or to instruct the UE to delete or discard the
  • the new NAS security context is used to instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or to notify the target AMF that AMF redirection occurs, and/or Or, instruct the target AMF to send an indication to the UE
  • the second notification message also includes a registration request message carrying SUCI.
  • the second indication information may be newly added indication information, for example, the second indication information may be named AMF_Reallocation_Ind1.
  • the second notification message may also carry ngKSI, and the ngKSI is used to instruct the UE to delete the NAS security context corresponding to the ngKSI or to instruct the UE to deactivate the NAS security context corresponding to the ngKSI.
  • the initial AMF sends the sixth indication information to the target AMF, option two:
  • the initial AMF sends the third notification message to the target AMF through the (R)AN.
  • the initial AMF carries the third notification message in the Reroute NAS Message and sends it to the (R)AN
  • the (R)AN carries the third notification message in the Initial UE Message and sends it to the target AMF.
  • the third notification message carries fourth indication information, which is used to instruct the UE to verify the fourth indication information, and after successful verification, delete the NAS security context, and/or deactivate the current NAS security context, and/or process
  • An authentication request message without security protection, and/or indicates that an AMF redirection occurs on the UE network side, and/or restores no NAS security context, and/or deletes or discards the new one established by the UE and the initial AMF NAS security context, and/or, delete or discard the NAS security context established by the UE and the initial AMF, and/or, the UE delete or discard the new NAS security context, and/or, deactivate The current NAS security context established by the UE and the initial AMF.
  • the fourth indication information may also be used to notify the target AMF that AMF redirection occurs, and/or instruct the target AMF to send an indication to the UE, and/or to instruct the UE to use the saved NAS security context, if so.
  • the third notification message also includes a registration request message carrying SUCI.
  • the fourth indication information may be generated by the initial AMF according to the shared key with the UE.
  • the fourth indication information may be named Secret.
  • the Secret includes the first parameter and the message authentication code of the first parameter.
  • the first parameter may be a random number, or one or more of the UL NAS Count of the registration message sent by the UE to the initial AMF, or the UL NAS Count of NAS Security Complete sent by the UE to the initial AMF.
  • the first parameter message authentication code is a message authentication code calculated for the first parameter by using the initial AMF according to the shared key with the UE.
  • the shared key may be one or more of Kamf or Kseaf generated through master authentication between the UE and the initial AMF, or the NAS encryption key Knasenc, or the NAS full security key Knasint.
  • the first parameter When the first parameter is the UL NAS Count of the registration message sent by the UE to the initial AMF, the first parameter may not be carried in the third notification message.
  • the third notification message may also carry ngKSI, which is used to instruct the UE to delete the NAS security context corresponding to the ngKSI or to instruct the UE to deactivate the NAS security context corresponding to the ngKSI.
  • ngKSI is used to instruct the UE to delete the NAS security context corresponding to the ngKSI or to instruct the UE to deactivate the NAS security context corresponding to the ngKSI.
  • the initial AMF sends the sixth indication information to the target AMF, option three:
  • the initial AMF can send a complete registration request message to the target AMF through the (R)AN.
  • the initial AMF carries the complete registration request message in the Reroute NAS Message and sends it to the (R)AN
  • the (R)AN carries the complete registration request message in the Initial UE Message and sends it to the target AMF.
  • the initial AMF sends the ngKSI to the target AMF through the (R)AN, and the ngKSI is used to instruct the UE to delete the NAS security context corresponding to the ngKSI or to instruct the UE to deactivate the NAS security context corresponding to the ngKSI.
  • Step 302 The target AMF receives the sixth indication information.
  • the target AMF receives a second notification message, the second notification message carries second indication information, and the second indication information is used to instruct the UE to delete the NAS security context or to indicate to deactivate the current NAS security context , Or used to indicate that AMF redirection occurs on the network side, or used to indicate that the received authentication request message without security protection is processed; or the target AMF receives the third notification message, the third notification message carries the fourth indication information , Instruct the UE to verify the fourth indication information and delete the NAS security context, or instruct the UE to verify the fourth indication information and deactivate the current NAS security context, or instruct the UE to verify the fourth indication information and determine that AMF redirection occurs on the network side, Or the UE verifies the fourth indication information and determines to process the received authentication request message without security protection; or the target AMF receives the complete registration request message.
  • Step 303 The target AMF sends the authentication request message to the UE according to the sixth indication information, including indication information for instructing the UE to delete the NAS security context, or including indication information for instructing the UE to deactivate the current NAS security context.
  • indication information for instructing the UE to process an authentication request message without security protection or include indication information for indicating that AMF redirection occurs on the network side of the UE; or include indication information for instructing the UE to restore the security context without NAS, or Include indication information for instructing the UE to delete or discard the new NAS security context established by the UE and the initial AMF, or include indication information for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF Indication information, either including indication information for instructing the UE to delete or discard a new NAS security context, or including indication information for instructing the UE to deactivate the current NAS security context established by the UE and the initial AMF, Or include indication information for instructing the UE to use the
  • the target AMF initiates the main authentication process according to the received registration request carrying the SUCI.
  • the target AMF receives the second notification message
  • the second notification message carries the second indication information
  • the target AMF includes the third indication information in the authentication request sent to the UE according to the second indication information
  • the third indication information is used for Instruct the UE to delete the NAS security context, and/or to instruct the UE to deactivate the current NAS security context, and/or to instruct the UE to process authentication request information without security protection, and/or to instruct the UE to network AMF redirection occurs on the side, and/or it is used to instruct the UE to restore no NAS security context, and/or it is used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or For instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or for instructing the UE to delete or discard the new NAS security context, and/or for instructing the UE to Deactivate the current NAS security context established by the UE and the initial A
  • the third indication information may be newly added indication information.
  • the third indication information may be named AMF_Reallocation_Ind2.
  • the third indication information and the second indication information may be the same or different.
  • the third notification message carries fourth indication information
  • the target AMF includes the fourth indication information in the authentication request sent to the UE according to the fourth indication information, which is used to instruct the UE to verify
  • the fourth instruction information after successful verification, delete the NAS security context, process the authentication request message, and/or deactivate the current NAS security context, process the authentication request message, and/or process the authentication request message without security protection, and /Or, restore the no NAS security context, process the authentication request message, and/or, delete or discard the new NAS security context established by the UE and the initial AMF, process the authentication request message, and/or delete or discard all
  • the NAS security context established by the UE and the initial AMF, processing the authentication request message, and/or, the UE deletes or discards the new NAS security context, processing the authentication request message, and/or deactivates the
  • the current NAS security context established by the UE and the initial AMF processes the authentication request message, and/or the user instructs the UE to use
  • the target AMF sends an authentication request message to the UE according to the complete registration request message, and includes fifth indication information in the authentication request message, which is used to indicate the UE Delete the NAS security context, and/or, be used to instruct the UE to deactivate the current NAS security context, and/or, be used to instruct the UE to process authentication request information without security protection, and/or, be used to instruct the UE to have an AMF reconfiguration on the network side Orientation, and/or, used to instruct the UE to restore no NAS security context, and/or, used to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or, used to indicate
  • the current indication information in the authentication request message which is used
  • the target AMF If the second notification message or the third notification message received by the target AMF carries ngKSI, or if the target AMF also receives ngKSI when receiving the complete registration request message, the target AMF carries the ngKSI in the authentication request message and sends it to UE, the ngKSI instructs the UE to delete or deactivate the NAS context corresponding to the ngKSI.
  • Step 304 According to the indication information included in the authentication request message, the UE deletes the NAS security context, processes the authentication request message, and/or deactivates the current NAS security context, processes the authentication request message, and/or processes the unsecured Authentication request message, and/or, restore no NAS security context, process authentication request message, and/or, delete or discard the new NAS security context established by the UE and the initial AMF, process the authentication request message, and/or , Delete or discard the NAS security context established by the UE and the initial AMF, process the authentication request message, and/or, the UE delete or discard the new NAS security context, process the authentication request message, and/or deactivate (deactivate)
  • the UE receives the authentication request message sent by the target AMF.
  • the UE deletes the NAS security context, processes the authentication request message according to the third indication information, and/or deactivates the current NAS security context and processes the authentication Request message, and/or, process the authentication request message without security protection, and/or, restore the security context without NAS, process the authentication request message, and/or, delete or discard the new one established by the UE and the initial AMF NAS security context, processing the authentication request message, and/or, deleting or discarding the NAS security context established by the UE and the initial AMF, processing the authentication request message, and/or, the UE deleting or discarding the new NAS security context , Process the authentication request message, and/or, deactivate the current NAS security context established by the UE and the initial AMF, process the authentication request message, and/or, the user instructs the UE to use the saved NAS security context, if If so, process the authentication request message.
  • the authentication request message sent by the target AMF received by the UE carries the fourth indication information, after successful verification, delete the NAS security context, process the authentication request message, and/or deactivate the current NAS security context, process the authentication request message, and /Or, processing the authentication request message without security protection, and/or, restoring the non-NAS security context, processing the authentication request message, and/or, deleting or discarding the new NAS security context established by the UE and the initial AMF, Process the authentication request message, and/or delete or discard the NAS security context established by the UE and the initial AMF, process the authentication request message, and/or, the UE delete or discard the new NAS security context, process the authentication request Message, and/or, deactivate the current NAS security context established by the UE and the initial AMF, process the authentication request message, and/or use the stored NAS security context, if any, process the authentication request news.
  • the UE uses the shared key with the initial AMF to generate a message authentication code for the first parameter in the fourth indication information, and the UE determines that the generated message authentication code is authenticated with the message carried in the received fourth indication information Whether the codes are consistent, if they are consistent, the fourth indication information is verified. If they are not consistent, the verification of the fourth indication information fails, and the UE discards the received authentication request message.
  • the UE deletes the NAS security context according to the fifth indication information, and/or deactivates the current NAS security context, and/or the processing is not secure Protected authentication request information, and/or, determine that AMF redirection occurs on the network side, and/or restore no NAS security context, and/or delete or discard the new NAS security context established by the UE and the initial AMF , And/or, delete or discard the NAS security context established by the UE and the initial AMF, and/or delete or discard the new NAS security context, and/or, deactivate the UE and The current NAS security context established by the initial AMF, and/or the user instructs the UE to use the saved NAS security context, if any.
  • the UE deletes the NAS security context, it deletes the NAS security context corresponding to the ngKSI according to the ngKSI.
  • Step 305 The UE processes the authentication request message and sends an authentication response message without security protection to the target AMF.
  • Step 306 The target AMF receives the authentication response message.
  • the target AMF solves the problem that the target AMF and the NAS security context stored in the UE are inconsistent, which causes the UE to not process the authentication request message sent by the target AMF and causes the registration process to fail.
  • the initial AMF can send the NAS security context established with the UE to the target AMF.
  • the target AMF uses the NAS security context as the current NAS security context.
  • the target AMF performs security protection on the authentication request message and sends the security protected authentication request message To the UE, the UE processes the security-protected authentication request message.
  • Figure 4 includes:
  • Step 401 The initial AMF determines to perform AMF redirection, and sends the NAS security context established with the UE to the target AMF.
  • the initial AMF sends the NAS security context established with the UE to the target AMF.
  • the NAS security context may include NAS Counts, the NAS encryption key and the NAS full security key, or the security algorithm selected by the initial AMF to generate the NAS encryption key and the NAS full security key.
  • the initial AMF carries the NAS security context in the Reroute NAS Message and sends it to the (R)AN
  • the (R)AN carries the NAS security context in the Initial UE Message and sends it to the target AMF.
  • Step 402 The target AMF receives the NAS security context, and uses the NAS security context as the current NAS security context.
  • Step 403 The target AMF performs security protection on the authentication request message to be sent based on the NAS security context, and sends the security protected authentication request message to the UE.
  • the target AMF uses the key and the security algorithm selected by the initial AMF to securely protect the authentication request message to be sent.
  • the target AMF If the NAS security context received by the target AMF is the parameter used to generate the NAS encryption key and the NAS security key, the target AMF first generates the NAS encryption key and the NAS security key, and then uses the generated NAS encryption key and The NAS security key and the security algorithm selected by the initial AMF provide security protection for the authentication request message to be sent.
  • Step 404 The UE receives the security-protected authentication request message, processes the security-protected authentication request message, and sends an authentication response message to the target AMF.
  • the UE receives the security-protected authentication request message, and regardless of whether the UE can perceive the AMF redirection, it can process the security-protected authentication request message.
  • Step 405 The target AMF receives the authentication response message.
  • the initial AMF sends the NAS security context established with the UE to the target AMF.
  • the target AMF can use the NAS security context to securely protect the authentication request message. This solves the inconsistency between the target AMF and the NAS security context stored in the UE, causing the UE to discard The problem of registration process failure caused by the authentication request message sent by the target AMF is processed, and the UE registration failure is avoided.
  • the UE can also directly store the processing mechanism of the authentication request message.
  • the UE can directly process the authentication request message without security protection without the need for instructions from the network side.
  • Figure 5 refers to the registration process shown in Figure 5, which includes:
  • Step 501 The UE establishes a NAS security context with the initial AMF.
  • Step 502 The UE receives an authentication request message without security protection sent by the target AMF.
  • Step 503 The UE processes the authentication request message without security protection, and returns an authentication response message without security protection to the target AMF.
  • the initial AMF notifies the UE before performing AMF redirection.
  • the registration process includes:
  • Step 601 UE sends a registration request carrying SUCI, RegistrationRequest, abbreviated as RR.
  • the RR only includes cleartext IEs, not Requested S-NSSAIs.
  • Step 602 The initial AMF initiates master authentication.
  • the UE and the initial AMF generate an AMF key, denoted as Kamf, and the corresponding key identifier ngKSI.
  • the NAS security context includes the AMF key Kamf and the corresponding ngKS.
  • Step 603 The initial AMF initiates a security mode command, namely NAS Security Mode Command (abbreviated as NAS SMC), activates and starts to use the Kamf generated by the master authentication. Or the initial AMF sends the NAS SMC carrying the eighth indication information.
  • the eighth indication information is used to instruct the UE to save the currently used NAS security context, if any.
  • the UE saves the currently used NAS security context, if any, according to the NAS SMC or the eighth indication information carried.
  • the UE returns the NAS security mode complete message, namely NAS Security Mode Complete, activates and starts to use Kamf.
  • the UE sends a complete registration request message, including Requested S-NSSAIs.
  • Step 604 According to the Requested S-NSSAIs, the initial AMF judges whether it can serve the UE. When the initial AMF determines that it cannot serve the UE, the initial AMF decides to perform AMF redirection, namely reroute NAS.
  • Step 605 The initial AMF sends indication information (such as AMF Reallocation Notification) to the UE, the indication information is used to instruct the UE to delete or discard the NAS security context, and/or to instruct the UE to deactivate the current NAS security of the UE
  • the context and/or, is used to instruct the UE to process an authentication request message without security protection, and/or, to indicate the occurrence of AMF redirection on the UE network side, and/or, to instruct the UE to restore the NAS-free security context, and/or Or, for instructing the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, And/or for instructing the UE to delete or discard the new NAS security context, and/or for instructing the UE to deactivate the current NAS security context established by the UE and the initial AMF, and/or , Used to instruct the
  • the indication message carries the key identifier ngKSI of the key Kamf generated by the master authentication, and is used to instruct the UE to delete the NAS security context corresponding to the ngKSI.
  • the initial AMF sending instruction information includes:
  • the initial AMF sends a first notification message to the UE, where the first notification message is used to instruct the UE to delete the NAS security context, and/or, to instruct the UE to deactivate the current NAS security context, and/or, Used to instruct the UE to process the authentication request message without security protection, and/or used to indicate the occurrence of AMF redirection on the network side of the UE, and/or used to instruct the UE to restore the NAS-free security context, and/or, used to instruct the UE Deleting or discarding the new NAS security context established by the UE and the initial AMF, and/or, for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, and/or for Instruct the UE to delete or discard the new NAS security context, and/or to instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF.
  • the first notification message is a newly added NAS message, or AMF Reallocation Notification message.
  • the AMF Reallocation Notification message carries the key identifier ngKSI of the key Kamf generated by the master authentication, which is used to instruct the UE to delete the NAS security context corresponding to the ngKSI.
  • the indication information sent by the initial AMF includes:
  • the initial AMF sends a first NAS message to the UE, where the first NAS message carries first indication information, and the first indication information is used to instruct the UE to delete the NAS security context, and/or to instruct the UE to Activate the current NAS security context, and/or, instruct the UE to process an authentication request message without security protection, and/or indicate that AMF redirection occurs on the network side of the UE, and/or, be used to instruct the UE to restore no NAS security context, and/or Or, for instructing the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or for instructing the UE to delete or discard the NAS security context established by the UE and the initial AMF, And/or used to instruct the UE to delete or discard the new NAS security context, and/or to instruct the UE to deactivate the current NAS security context established by the UE and the initial AMF.
  • the first NAS message that carries the first indication information.
  • Possible options for the NAS message include configuration update command messages, downlink NAS transport messages, and 5G system mobility management status (5G system mobility management status, 5GMM Status) and registration rejection (registration reject) messages, etc.
  • the first NAS message carries the key identifier ngKSI of the key Kamf generated by the master authentication, which is used to instruct the UE to delete the NAS security context corresponding to the ngKSI.
  • the UE After the UE receives the indication information, including the first notification message or the first NAS message carrying the first indication information, it should, discard or delete the NAS security context, and/or deactivate the current NAS security context of the UE, and /Or, determine not to discard and process the received authentication request message without security protection, and/or determine that AMF redirection occurs on the network side, and/or restore the NAS-free security context, and/or delete or discard the The new NAS security context established by the UE and the initial AMF, and/or delete or discard the NAS security context established by the UE and the initial AMF, and/or delete or discard the new NAS security context, And/or, deactivate the current NAS security context established by the UE and the initial AMF.
  • the UE deletes the NAS security context corresponding to the ngKSI. Specifically, after the UE receives the first notification message, or AMF Reallocation Notification message, after that, if the first notification message (or AMF Reallocation Notification message) carries ngKSI, the UE deletes the NAS security corresponding to ngKSI. Context; or after the UE receives the first NAS message carrying the first indication information, if the first NAS message carries ngKSI, the UE deletes the NAS security context corresponding to the ngKSI.
  • Step 606 The initial AMF performs NAS reroute, that is, AMF redirection.
  • the initial AMF carries the SUCI registration request message in the Reroute NAS Message and sends it to the (R)AN.
  • Step 607 (R) AN carries the registration request message carrying the SUCI in the Initial UE Message and sends it to the target AMF.
  • Step 608 The target AMF initiates the primary authentication and sends a Nausf_UEAuthentication_Authenticate Request to AUSF, and AUSF returns Nausf_UEAuthentication_Authenticate Response.
  • Step 609 The target AMF sends an Authentication Request (also referred to as Auth. Request) message to the UE.
  • Authentication Request also referred to as Auth. Request
  • the authentication request message is an authentication request message without security protection.
  • Step 610 The UE processes (calculates) the Authentication Request message.
  • Step 611 The UE returns an Authentication Response message to the target AMF.
  • the authentication response message is an authentication response message without security protection.
  • the initial AMF notifies the target AMF that AMF redirection has occurred.
  • the target AMF adds an indication to the authentication request message to notify the UE that AMF redirection has occurred on the network side, and instruct the UE to delete the NAS security context established and activated before the AMF redirection.
  • the registration process includes:
  • step 701 to step 704 is the same as that of step 601 to step 604 shown in FIG. 6, and will not be repeated here.
  • Step 705 The initial AMF carries the second indication information, or called AMF_Reallocation_Ind1, in the Reroute NAS Message and sends it to (R)AN.
  • the second indication information, or called AMF_Reallocation_Ind1 is used to instruct the UE to delete the NAS security context, and /Or, used to instruct the UE to deactivate the current NAS security context, and/or, used to instruct the UE to process authentication request information without security protection, and/or, used to indicate the occurrence of AMF redirection on the UE network side, and/or, Used to instruct the UE to restore the NAS-free security context, and/or to instruct the UE to delete or discard the new NAS security context established by the UE and the initial AMF, and/or to instruct the UE to delete or discard the
  • the NAS security context established by the UE and the initial AMF, and/or, is used to instruct the UE to delete or discard the new NAS security context, and/or, to instruct the UE to
  • the NAS Reroute Message may carry ngKSI, and the ngKSI is used to instruct the UE to delete the NAS security context corresponding to the ngKSI.
  • Step 706 (R) AN carries the second indication information, namely AMF_Reallocation_Ind1, in the Initial UE Message and sends it to the target AMF.
  • the Initial UE Message may carry ngKSI.
  • Step 707 The target AMF initiates the primary authentication, and sends a Nausf_UEAuthentication_Authenticate Request to AUSF, and AUSF returns Nausf_UEAuthentication_Authenticate Response.
  • Step 708 The target AMF sends an Authentication Request message to the UE. If the target AMF receives the second indication information in the previous Initial UE message, or called the AMF_Reallocation_Ind1 indication, the target AMF adds an indication in the Authentication Request message, that is, the third indication information, or called the AMF_Reallocation_Ind2 indication, for notification AMF Reallocation occurs on the UE network side, and/or instructs the UE to delete the previously activated NAS security context, and/or, is used to instruct the UE to delete the NAS security context, and/or, is used to instruct the UE to deactivate the current NAS security context , And/or, used to instruct the UE to process authentication request information without security protection, and/or, used to indicate the occurrence of AMF redirection on the UE network side, and/or, used to instruct the UE to restore the NAS-free security context, and/or For instructing the UE to delete or discard the new NAS security context established by the UE
  • the target AMF if the target AMF receives the ngKSI in the previous Initial UE message, the target AMF carries the ngKSI in the Authentication Request message, and the ngKSI is used to instruct the UE to delete the ngKSI corresponding to the ngKSI.
  • Step 709 After the UE receives the Authentication Request message, if the message carries third indication information, or called AMF_Reallocation_Ind2, the UE should delete the NAS security context, process the authentication request message, or deactivate the current NAS security context, and process the authentication request Message, or process the authentication request message without security protection, or determine that AMF redirection occurs on the network side, process the authentication request message, and/or restore the security context without NAS, process the authentication request message, and/or delete or discard the The new NAS security context established by the UE and the initial AMF, processing the authentication request message, and/or, deleting or discarding the NAS security context established by the UE and the initial AMF, processing the authentication request message, and/or, deleting Or discard the new NAS security context, process the authentication request message, and/or deactivate the current NAS security context established by the UE and the initial AMF, process the authentication request message, and/or resume use The saved NAS security context, if any.
  • the UE deletes the NAS security context corresponding to the ngKSI; if there is no ngKSI in the message, the UE finds and activates the NAS security context established by the previous master authentication and deletes it.
  • the UE After the UE receives AMF_Reallocation_Ind2, the UE skips the process of performing security protection verification and decryption on the Authentication Request, and directly processes the received Authentication Request message.
  • Step 710 The UE returns an Authentication Response message to the target AMF.
  • the initial AMF notifies the target AMF that AMF redirection has occurred.
  • the target AMF adds an indication in the authentication request message to notify the UE that AMF redirection has occurred on the network side, and instruct the UE to verify the instructions, and delete the NAS security context established and activated before the AMF redirection.
  • the registration process includes:
  • step 801 to step 804 is the same as that of step 601 to step 604 shown in FIG. 6, and will not be repeated here.
  • Step 805 The initial AMF adds a new indication, the fourth indication information, or Secret, carried in the Reroute NAS Message and sent to the (R)AN.
  • the fourth indication information, or Secret is used to instruct the UE to verify According to the fourth indication information, after the verification is successful, the UE should delete the NAS security context, and/or, deactivate the current NAS security context, and/or process the authentication request message without security protection, and/or indicate the UE network side AMF redirection, and/or, restore no NAS security context, and/or, delete or discard the new NAS security context established by the UE and the initial AMF, and/or, delete or discard the UE and the The NAS security context established by the initial AMF, and/or the UE deletes or discards the new NAS security context, and/or, deactivates the UE and the current NAS security context established by the initial AMF, and/or Or, it is used to instruct the UE to resume using the saved NAS security context, if any.
  • the NAS Reroute Message also carries a registration request message carrying SUCI.
  • the parameters in Secret include:
  • Fresh parameters It can be a random number, or the UL NAS Count of the registration message sent by the UE to the initial AMF, or the UL NAS Count of the NAS Security Complete sent by the UE to the initial AMF, and one or more of the above options.
  • the purpose of the fresh parameter is to prevent replay attacks.
  • the freshness parameter is the UL NAS Count of the registration message sent by the UE to the initial AMF, the freshness parameter may not be carried in the Secret.
  • the ngKSI in the NAS security context established between the UE and the initial AMF is used to instruct the UE to delete the NAS security context corresponding to the ngKSI.
  • the ngKSI parameter may not be carried in the secret.
  • the MAC is calculated and generated by the initial AMF using the shared key between the UE and the initial AMF to the parameters in 1) and/or 2), that is, the fresh parameters and/or ngKSI parameters are calculated and generated. MAC is used to prove the authenticity of Secret and prevent attackers from spoofing messages.
  • the shared key may be Kamf, or Kseaf, or NAS encryption key Knasenc, or NAS full security key Knasint, generated through master authentication between the UE and the initial AMF.
  • Step 806 (R)AN sends an Initial UE message carrying fourth indication information (or Secret) to the target AMF.
  • the Initial UE message also carries a registration request message carrying SUCI.
  • Step 807 The target AMF initiates the primary authentication and sends a Nausf_UEAuthentication_Authenticate Request to AUSF, and AUSF returns Nausf_UEAuthentication_Authenticate Response.
  • Step 808 The target AMF sends an Authentication Request message to the UE.
  • the Authentication Request message carries the received fourth indication information, or Secret.
  • Step 809 After the UE receives the Authentication Request message, if the Authentication Request message carries the fourth indication information, or called Secret, the UE shall verify the fourth indication information, or called Secret, and after the authentication is successful, the NAS shall be deleted Security context, processing authentication request message, and/or, deactivating the current NAS security context, processing authentication request message, and/or, processing authentication request message without security protection, and/or, restoring no NAS security context, processing authentication request Message, and/or, delete or discard the new NAS security context established by the UE and the initial AMF, process the authentication request message, and/or, delete or discard the NAS security context established by the UE and the initial AMF , Processing the authentication request message, and/or, the UE deletes or discards the new NAS security context, processes the authentication request message, and/or, deactivates the current NAS security context established by the UE and the initial AMF , Process the authentication request message, and/or, restore the use of the saved NAS security context, and if any
  • the UE When the UE deletes the NAS security context, if there is ngKSI in the Secret, the UE deletes the NAS security context corresponding to the ngKSI. If there is no ngKSI in the Secret, the UE deletes the NAS context generated and activated by the primary authentication. Then the UE processes the authentication Request message; or the UE directly processes the unprotected Authentication Request message.
  • Step 810 The UE returns an Authentication Response message to the target AMF.
  • the initial AMF sends the NAS security context to the target AMF, and keeps the NAS security context between the target AMF and the UE consistent.
  • the registration process includes:
  • step 901 to step 904 is the same as that of step 601 to step 604 shown in FIG. 6, and will not be repeated here.
  • Step 9.5 Initial AMF adds NAS security context to NAS Reroute Message, including NAS Keys (including NAS encryption key Knasint and NAS full security key Knasint), and/or the parameters required to generate NAS Keys (such as Kamf and The selected security algorithm), and/or the security algorithm, and/or the NAS Counts, etc. are sent to the (R)AN.
  • NAS Keys including NAS encryption key Knasint and NAS full security key Knasint
  • the parameters required to generate NAS Keys such as Kamf and The selected security algorithm
  • the security algorithm and/or the NAS Counts, etc.
  • the initial AMF can also add NAS counts in the Reroute NAS Message.
  • NAS Counts is used to synchronize the NAS Counts of the initial AMF and the target AMF.
  • Step 906 The (R)AN sends an Initial UE message to the target AMF.
  • the message carries the NAS security context, including NAS keys or parameters for producing NAS keys, and/or security algorithms.
  • the Initial UE Message can also carry NAS Counts.
  • Step 907 The target AMF saves the received NAS security context.
  • the target AMF initiates the primary authentication and sends Nausf_UEAuthentication_Authenticate Request to AUSF, and AUSF returns Nausf_UEAuthentication_Authenticate Response.
  • the target AMF uses the received NAS counts to update the NAS counts it has saved.
  • Step 908 Before sending the Authentication Request message to the UE, the target AMF protects the Authentication Request message according to the received NAS security context (such as Knasenc and Kansint).
  • the NAS security context such as Knasenc and Kansint.
  • the Authentication Request message may also target the updated NAS count of the AMF.
  • Step 909 The target AMF sends a security-protected Authentication Request message to the UE.
  • the UE processes the security-protected Authentication Request message.
  • Step 910 The UE returns an Authentication Response message to the target AMF.
  • the initial AMF sends the complete registration request message to the target AMF.
  • the target AMF determines that AMF redirection has occurred, and instructs the UE to process the received authentication request message.
  • the registration process include:
  • step 1001 to step 1005 is the same as that of step 601 to step 604 shown in FIG. 6, and will not be repeated here.
  • Step 1006 The initial AMF carries a complete registration request message (such as complete initial NAS message) in the Reroute NAS Message, and sends it to the (R)AN.
  • a complete registration request message such as complete initial NAS message
  • the complete registration request message is obtained by the initial AMF in step 1004.
  • Step 1007 The (R)AN carries a complete registration request message in the Initial UE Message and sends it to the target AMF.
  • Step 1008 The target AMF initiates the primary authentication and sends a Nausf_UEAuthentication_Authenticate Request to AUSF, and AUSF returns Nausf_UEAuthentication_Authenticate Response.
  • the target AMF determines that AMF redirection (determines AMF reallocation has occurred) according to the complete registration request message.
  • Step 1009 The target AMF carries the indication information indicator in the Authentication Request message and sends it to the UE.
  • the indication information indicator is used to indicate that the AMF redirection has occurred on the network side of the UE, or to instruct the UE to process the received authentication request.
  • the UE processes the received authentication request message according to the indication information indicator.
  • Step 1010 The UE returns an Authentication Response message to the target AMF.
  • the initial AMF decides to initiate AMF redirection through (R)AN or NAS Reroute through (R)AN, and decides to redirect to the target AMF.
  • the initial AMF should request the target AMF to allocate a new 5G for the UE -GUTI (5G Globally Unique TemporaryUE Identity, the globally unique temporary identifier of the UE in the 5G network), or the initial AMF allocates a new 5G-GUTI to the UE, or the initial AMF should request the target AMF to allocate a special one for AMF redirection
  • the new 5G-GUTI or initial AMF allocates a special new 5G-GUTI to the UE for AMF redirection.
  • the initial AMF should send the new 5G-GUTI to the UE, and the initial AMF should initiate a de-registration process or registration rejection message , Instruct the UE to re-register, and the initial AMF should optionally initiate RRC link release, the UE should perform reselection registration according to the instructions, and the UE should initiate a registration request message RR carrying a new 5G-GUTI to the target AMF.
  • the initial AMF should skip the steps of NAS reroute through (R)AN shown in step 105 and step 106 in Figure 1, that is, skip the initial AMF and send the received registration request to (R)AN , (R) AN sends the registration request to the target AMF.
  • the registration process includes:
  • Step 1101 The initial AMF decides to initiate a redirect to the target AMF via (RAN) or reroute to the target AMF via (RAN) NAS.
  • the initial AMF should skip the NAS reroute process via (R)AN, and the initial AMF should request the target AMF Assign a new 5G-GUTI to the UE (see the description of Mode 1 below), or the initial AMF should allocate a new 5G-GUTI for the UE, (see the description of Mode 2 below), or the initial AMF should request the target AMF to allocate one A special new 5G-GUTI used for AMF redirection (see the description of Mode 3 below) or the initial AMF should allocate a special new 5G-GUTI for AMF redirection (see the description of Mode 4 below) for the UE.
  • the initial AMF should send a request to the target AMF to allocate a new 5G-GUTI to the UE, the target AMF should allocate a new 5G-GUTI to the UE, and the target AMF should send a message carrying the new 5G-GUTI to the initial AMF.
  • the initial AMF should include the initial SUCI in the information requesting the allocation of a new 5G-GUTI sent to the target AMF, where the SUCI is the SUCI carried in the registration request message received by the initial AMF.
  • the target AMF sends the message carrying the new 5G-GUTI to the initial AMF through the (R)AN, that is, the target AMF sends the message carrying the new 5G-GUTI to the (R)AN, (R)AN Send the message carrying the new 5G-GUTI to the initial AMF.
  • the target AMF After the target AMF allocates a new 5G-GUTI, it marks the new 5G-GUTI, such as marking the new 5G-GUTI as the 5G-GUTI used in the AMF redirection scenario, and/or marking the new 5G-GUTI GUTI is a new 5G-GUTI allocated for UE.
  • the initial AMF requests the target AMF to allocate a new 5G-GUTI.
  • the initial AMF sends information for requesting the allocation of a new 5G-GUTI to the target AMF.
  • the initial AMF sends the SUCI carried in the received registration request to the target AMF.
  • the initial AMF sends SUCI to the target AMF through the (R)AN, that is, the initial AMF sends the SUCI to the (R)AN, and the (R)AN sends the SUCI to the target AMF.
  • the SUCI can be carried in the message, and the message carrying the SUCI is not limited.
  • the target AMF may store the SUCI, and establish the correspondence between the SUCI and the new 5G-GUTI.
  • the initial AMF notifies the target AMF that AMF redirection occurs.
  • the initial AMF sends the indication information or message for notifying the target AMF of the AMF redirection to the target AMF through the (R)AN, that is, the initial AMF sends the indication information or message for notifying the target AMF of the AMF redirection to (R)AN, (R)AN sends indication information for notifying the target AMF to redirect to the target AMF.
  • the indication information used to notify the target AMF of the AMF redirection can be carried in the message.
  • the initial AMF allocates a new 5G-GUTI to the UE.
  • the new 5G-GUTI is a new 5G-GUTI allocated to the UE.
  • the information of the target AMF is stored in the initial AMF.
  • the AMF should request the target AMF to allocate a special new 5G-GUTI for AMF redirection.
  • the target AMF should allocate a special new 5G-GUTI for AMF redirection to the UE.
  • the target AMF should carry information for AMF redirection.
  • the redirected special new 5G-GUTI message is sent to the initial AMF.
  • the target AMF sends a message carrying a special new 5G-GUTI for AMF redirection to the initial AMF through (R)AN, that is, the target AMF will carry a special new 5G-GUTI message for AMF redirection.
  • the GUTI is sent to the (R)AN, and the (R)AN will send a special new 5G-GUTI that carries the AMF redirection to the initial AMF.
  • the initial AMF requests the target AMF to allocate a special new 5G-GUTI for AMF redirection.
  • the initial AMF sends information for requesting the allocation of a special new 5G-GUTI for AMF redirection to the target AMF.
  • the initial AMF sends the SUCI carried in the received registration request to the target AMF.
  • the initial AMF sends SUCI to the target AMF through the (R)AN, that is, the initial AMF sends the SUCI to the (R)AN, and the (R)AN sends the SUCI to the target AMF.
  • the SUCI can be carried in the message, and the message carrying the SUCI is not limited.
  • the target AMF may store the SUCI, and establish a correspondence between the SUCI and a special new 5G-GUTI used for AMF redirection.
  • the initial AMF notifies the target AMF that AMF redirection occurs.
  • the initial AMF sends the indication information or message for notifying the target AMF of the AMF redirection to the target AMF through the (R)AN, that is, the initial AMF sends the indication information or message for notifying the target AMF of the AMF redirection to (R)AN, (R)AN sends indication information for notifying the target AMF to redirect to the target AMF.
  • the indication information used to notify the target AMF of the AMF redirection can be carried in the message.
  • the initial AMF should allocate a special new 5G-GUTI for AMF redirection to the UE.
  • the information of the target AMF is stored in the initial AMF.
  • Step 1102 The initial AMF should send a second message to the UE, and the second message should carry the new 5G-GUTI allocated for the UE.
  • the second message is a registration acceptance (Registration Accept) message or a configuration update command (Configuration Update Command).
  • Step 1103 The initial AMF initiates a de-registration process or a registration rejection message, and instructs the UE to re-register.
  • the initial AMF sends a de-registration process; if the second message is a configuration update command, the initial AMF sends a registration rejection message.
  • Step 1104 Optionally, the initial AMF initiates RRC link release.
  • Step 1105 The UE re-initiates a registration request, and the registration request message RR should carry a new 5G-GUTI.
  • the (R)AN sends the RR carrying the new 5G-GUTI to the target AMF.
  • the (R)AN sends the RR carrying the new 5G-GUTI to the initial AMF, and the initial AMF checks the 5G-GUTI carried in the RR. If the initial AMF has a label for the 5G-GUTI locally , And/or if the initial AMF determines that the 5G-GUTI is the 5G-GUTI used in the AMF redirection scenario, the initial AMF should initiate a NAS reroute process through the (R)AN, and send the RR to the target AMF through the (R)AN.
  • the (R)AN sends the RR carrying the special new 5G-GUTI for AMF redirection to the target AMF.
  • the (R)AN sends the RR carrying the special new 5G-GUTI for AMF redirection to the initial AMF, and the initial AMF checks the special RR for AMF redirection carried in the RR.
  • the initial AMF should initiate the NAS reroute process through the (R)AN, and send the RR to the target AMF through the (R)AN.
  • the initial AMF sends the SUCI carried in the RR to the target AMF.
  • Step 1106 The target AMF receives the registration request RR, and checks the 5G-GUTI carried in the RR.
  • the target AMF should initiate an identity request process to obtain the SUCI of the UE and perform primary authentication to achieve successful registration of the UE.
  • the target AMF searches for the corresponding relationship between SUCI and 5G-GUTI, and performs primary authentication to achieve successful registration of the UE.
  • step 1101 if the target AMF receives the SUCI before, the master authentication is initiated to realize the successful registration of the UE.
  • the target AMF initiates an identity request process to obtain the SUCI of the UE, and performs primary authentication to achieve successful registration of the UE.
  • the target AMF determines that the 5G-GUTI is the 5G-GUTI used in the AMF redirection scenario, the target AMF should initiate an identity request process to obtain the UE's SUCI and perform primary authentication to achieve the success of the UE registered.
  • the target AMF determines that the 5G-GUTI is the 5G-GUTI used in the AMF redirection scenario, the target AMF searches for the correspondence between SUCI and 5G-GUTI, and performs master authentication to achieve successful UE registration.
  • the initial AMF should send a request to the target AMF to allocate a new 5G-GUTI for the UE, or the initial AMF should request the target AMF to allocate a special new 5G-GUTI for AMF redirection,
  • the target AMF allocates a new 5G-GUTI to the UE, or the target AMF allocates a special new 5G-GUTI for AMF redirection to the UE.
  • the registration process includes:
  • step 1201 to step 1204 is the same as that of step 101 to step 103 shown in FIG. 1, and will not be repeated here.
  • the registration request message RR carries SUCI.
  • Step 1205 The initial AMF should determine whether it can serve the UE according to the Requested S-NSSAIs. If the initial AMF determines that it cannot serve the UE, the initial AMF decides that NAS reroute (decides to reroute NAS via (R) is needed) AN is needed), the initial AMF should skip NAS reroute (skip NAS reroute via(R)AN) of (R)AN.
  • Step 1206 The initial AMF should request a new 5G-GUTI (requesets a new 5G-GUTI from Target AMF) from the target AMF through (R)AN, or the initial AMF should request a new 5G-GUTI (requesets a new 5G-GUTI from Target AMF) from the target AMF through (R)AN. Targeted special new 5G-GUTI.
  • Step 1207 The target AMF should allocate a new 5G-GUTI (allocate a new 5G-GUTI), or the target AMF should allocate a special new 5G-GUTI for AMF redirection, and the target AMF should use the (R)AN to The initial AMF sends a message carrying a new 5G-GUTI, or the target AMF should send a message carrying a special new 5G-GUTI for AMF redirection to the initial AMF through (R)AN.
  • Step 1208 The initial AMF should carry the new 5G-GUTI in the Registration Accept message and send it to the UE, or the initial AMF should carry the special new 5G-GUTI for AMF redirection in the Registration Accept and send it to the UE.
  • the initial AMF may carry a new 5G-GUTI in the configuration update command (Configuration Update Command) and send it to the UE, or the configuration update command may carry a special new 5G-GUTI for AMF redirection and send it to the UE.
  • Configuration Update Command Configuration Update Command
  • the configuration update command may carry a special new 5G-GUTI for AMF redirection and send it to the UE.
  • Step 1209 The initial AMF should initiate a de-regiatration procedure and instruct the UE to re-register.
  • the initial AMF can send a registration rejection message to the UE and instruct the UE to re-register.
  • Step 1210 Optionally, the initial AMF initiates RRC link release (such as N2RRC Release).
  • RRC link release such as N2RRC Release
  • Step 1211 The UE should send a registration request message RR to the target AMF, and the RR carries the new 5G-GUTI.
  • Step 1212 When the target AMF receives the RR, it should check the 5G-GUTI carried in the RR.
  • the target AMF initiates an identity request process to obtain the UE’s SUCI and perform the master authentication to achieve Successful registration of the UE.
  • the target AMF looks up the correspondence between SUCI and 5G-GUTI and performs the master authentication , In order to achieve the successful registration of the UE.
  • the initial AMF should allocate a new 5G-GUTI to the UE, or the initial AMF should allocate a special new 5G-GUTI to the UE for AMF redirection, see the registration process shown in Figure 13 ,
  • the registration process includes:
  • step 1301 to step 1304 is the same as step 1201 to step 1204 shown in FIG. 12, and will not be repeated here.
  • the registration request message RR carries SUCI.
  • Step 1305 The initial AMF should determine whether it can serve the UE according to the Requested S-NSSAIs. If the initial AMF determines that it cannot serve the UE, the initial AMF decides that it needs to pass (RAN) NAS reroute (decides to reroute NAS via(R)AN) is needed), the initial AMF should skip the NAS reroute of (R)AN. The initial AMF should allocate a new 5G-GUTI and mark the UE (assign a new 5G-GUTI, and flag the UE), or the initial AMF should allocate a special new 5G-GUTI for AMF redirection.
  • Step 1306 the initial AMF should carry the new 5G-GUTI in the Registration Accept message and send it to the UE, or the initial AMF should carry the special new 5G-GUTI for the AMF redirection in the Registration Accept and send it to the UE.
  • the initial AMF may carry a new 5G-GUTI in the configuration update command (Configuration Update Command) and send it to the UE, or the configuration update command may carry a special new 5G-GUTI for AMF redirection and send it to the UE.
  • Configuration Update Command Configuration Update Command
  • the configuration update command may carry a special new 5G-GUTI for AMF redirection and send it to the UE.
  • Step 1307 The initial AMF initiates a de-registration procedure and instructs the UE to re-register.
  • the initial AMF can send a registration rejection message to the UE and instruct the UE to re-register.
  • Step 1308 Optionally, the initial AMF initiates RRC link release (such as N2RRC Release).
  • RRC link release such as N2RRC Release
  • Step 1309 The UE should send the RR carrying 5G-GUTI to the initial AMF.
  • Step 1310 The initial AMF checks the 5G-GUTI carried in the RR. If the initial AMF has an annotation on the 5G-GUTI locally, or if the initial AMF determines that the 5G-GUTI is the 5G-GUTI used in the AMF redirection scenario, the initial AMF should Initiate the NAS reroute process (perform NAS reroute) through (RAN).
  • Step 1311 The initial AMF should send the RR to the target AMF through the (R)AN.
  • the RR carries 5G-GUTI.
  • the initial AMF sends the SUCI carried in the RR to the target AMF.
  • Step 1312 When the target AMF receives the RR, it should check the 5G-GUTI carried in the RR.
  • the master authentication is initiated to achieve the successful registration of the UE.
  • the target AMF initiates an identity request process to obtain the SUCI of the UE, and performs the primary authentication to realize the successful registration of the UE.
  • the UE may optionally carry an indicator 1 in the registration request RR.
  • the initial AMF decides to perform NAS reroute, it performs different steps according to whether the RR carries the indicator 1 to achieve successful registration of the UE.
  • the UE may optionally carry an indicator 1 in the registration request RR.
  • the indicator 1 is used to indicate:
  • the UE is a non-version 15 UE.
  • the UE is a version 16 or later UE; and/or
  • UE supports version 16 and later capabilities
  • the UE supports the ability to perform NAS reroute via (R)AN; and/or
  • the UE supports the ability to perform AMF redirection through (R)AN; and/or
  • the UE supports the capability of NAS security context fallback (in NAS reroute via (RAN)/AMF redirect via (RAN)); and/or
  • the UE supports (in NAS reroute via (RAN)/AMF redirect via (RAN)) (recovers) the ability to use the old NAS security context; and/or
  • the UE supports the ability to delete a new NAS security context (in NAS reroute via (RAN)/AMF redirect via (RAN)); and/or
  • the UE supports (in NAS reroute via (RAN)/AMF redirect via (RAN)) and supports the ability to recover to no NAS security context; and/or
  • the UE supports the ability to perform NAS security context processing in NAS reroute (in NAS reroute through (RAN)/AMF redirect through (RAN)).
  • the registration process shown in Figure 14 the registration process includes:
  • Step 1401 The UE sends a registration request RR to the initial AMF, and the RR carries 5G-GUTI.
  • Indicator 1 is carried in the RR, or Indicator 1 is not carried in the RR.
  • step 1402 The implementation process of step 1402 is the same as step 102 to step 103 in FIG. 1, and will not be repeated here.
  • Step 1403 The initial AMF judges whether it can serve the UE. If the initial AMF determines that it cannot serve the UE, the initial AMF should decide to perform NAS reroute through (R)AN (or AMF redirect through (R)AN):
  • the initial AMF can perform one of the following processes:
  • the initial AMF should perform direct NAS reroute or the initial AMF should directly forward the registration request message to the target AMF, that is, the initial AMF calls the Namf_Communication_N1MessageNotify service operation provided by the Target AMF.
  • Namf_Communication_N1MessageNotify service operation should include receiving all registration request messages and UE context, if any.
  • step 7(A) defined in section 4.2.2.2.3 of TS 23.502.
  • the initial AMF should send a request to the target AMF to allocate a new 5G-GUTI for the UE, or the initial AMF should request the target AMF to allocate a special new 5G-GUTI for AMF redirection.
  • the process shown in the second embodiment (1) above which will not be repeated here.
  • the initial AMF should allocate a new 5G-GUTI for the UE, or the initial AMF should allocate a special new 5G-GUTI for the UE for AMF redirection.
  • the process shown in the second embodiment (2) above please refer to the process shown in the second embodiment (2) above, which will not be repeated here.
  • the initial AMF should decide whether to perform direct NAS reroute (that is, the initial AMF directly sends the registration request message to the target AMF) or through the NAS reroute of the (R)AN (that is, the initial AMF sends the registration request through the (R)AN) based on the local policy and subscription information.
  • the message is sent to the target AMF). If the initial AMF decides to perform direct NAS reroute based on the local policy and subscription information, or if the initial AMF decides to directly forward the registration request message to the target AMF based on the local policy and subscription information, the initial AMF calls the Namf_Communication_N1MessageNotify service operation provided by the Target AMF. Namf_Communication_N1MessageNotify service operation should include receiving all registration request messages and UE context, if any. For the detailed process, please refer to step 7(A) defined in section 4.2.2.2.3 of TS 23.502.
  • the initial AMF can perform one of the following processes:
  • the initial AMF should notify the UE to send AMF redirection, or the initial AMF should instruct the UE to delete the NAS security context, or the initial AMF should return to the security when sending the registration request, or the initial AMF should instruct the UE to receive and process unprotected authentication requests Messages, etc., that is, the process shown in the first embodiment (1) above is executed, and will not be repeated here.
  • the initial AMF should notify the target AMF that AMF redirection occurs, that is, the process shown in the first embodiment (2) above is executed, which will not be repeated here.
  • the initial AMF should notify the target AMF of the occurrence of AMF redirection, that is, the process shown in the first embodiment (3) above is executed, which will not be repeated here.
  • the initial AMF should send the NAS security context to the target AMF, that is, perform the process shown in the first embodiment (4) above, which will not be repeated here.
  • the initial AMF should send a complete registration request message to the target AMF, that is, perform the process shown in the above embodiment (5), which is not repeated here.
  • step 7(B) defined in section 4.2.2.2.3 of TS 23.502.
  • the initial AMF decides to initiate AMF redirection according to the local policy during the UE registration process, and the initial AMF decides to perform direct NAS Reroute, that is, when the registration request (or NAS message) is directly sent to the target AMF, the initial AMF should send the current NAS security context
  • the target AMF uses the NAS security context protection authentication request to be sent to the UE to realize the successful registration of the UE (see the above embodiment 1 (4) for details), or the initial AMF should decide whether to perform horizontal Kamf deduction according to the local policy, and generate The new Kamf sends the newly generated Kamf to the target AMF, and the UE generates a new Kamf, so as to ensure that the NAS security contexts on both sides of the target AMF and the UE are consistent, thereby realizing the successful registration of the UE.
  • the registration process includes:
  • Step 1501 The initial AMF decides to perform direct NAS Reroute (ie redirection) according to the local policy, or the initial AMF decides to send the registration request (or NAS message) directly to the target AMF according to the local policy, then the initial AMF should send the current NAS security context Send to the target AMF, or the initial AMF decides whether to perform horizontal Kamf deduction according to the local strategy. If it decides to perform horizontal Kamf deduction, the initial AMF generates a new Kamf and sends the newly generated Kamf to the target AMF. If it decides not to perform horizontal Kamf deduction , The initial AMF sends the current NAS security context (the NAS security context generated in step 102 in FIG. 1) to the target AMF.
  • the initial AMF sends the current NAS security context (the NAS security context generated in step 102 in FIG. 1) to the target AMF.
  • the initial AMF should carry the newly generated Kamf or the current NAS security context in the Namf_Communication_N1MessageNotify message and send it to the target AMF.
  • the initial AMF performs horizontal Kamf deduction, and the generation of a new Kamf includes one of the following:
  • the initial AMF should generate a new Kamf based on the current Kamf (the Kamf generated in step 102 in Figure 1) and the value of the uplink NAS COUNT in the received registration request RR.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the uplink NAS COUNT in the received NAS Security Mode Complete message.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the uplink NAS COUNT of the most recently received N1 message.
  • the N1 message includes the registration request RR and/or NAS Security Mode Complete message, that is, if the initial AMF receives the NAS Security Mode Complete message sent by the UE, the NAS Security Mode Complete message is the most recently received N1 message, the initial AMF According to the current Kamf and the value of the uplink NAS COUNT in the received NAS Security Mode Complete message, a new Kamf is generated; otherwise, the registration request RR is the most recently received N1 message, and the initial AMF is based on the current Kamf and the received registration Request the value of uplink NAS COUNT in RR to generate a new Kamf.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the current downlink NAS COUNT.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the uplink NAS COUNT in the received registration request RR; otherwise, The initial AMF should generate a new Kamf based on the current Kamf and the value of the current downlink NAS COUNT.
  • the initial AMF receives only one NAS message, and the NAS message is a registration request RR, the initial AMF generates a new Kamf according to the current Kamf and the value of the uplink NAS COUNT in the received registration request RR; otherwise, the initial AMF is based on The current Kamf and the current downlink NAS COUNT value will generate a new Kamf.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of the uplink NAS COUNT in the received registration request RR; otherwise, the initial AMF should be based on the current The value of Kamf and the current downlink NAS COUNT will generate a new Kamf.
  • the initial AMF should generate a new Kamf based on the current Kamf and the value of uplink NAS COUNT in the received registration request RR; otherwise, the initial AMF should be based on the current Kamf and The current value of downlink NAS COUNT generates a new Kamf.
  • the initial AMF should generate a new Kamf based on the current Kamf and the current downlink NAS COUNT; otherwise, the initial AMF should generate a new Kamf based on the current Kamf and received
  • other NAS messages include NAS Security Mode Complete messages.
  • the initial AMF should have an indication that a new Kamf has been generated, or an indication that a horizontal Kamf has been deduced should be sent to the target AMF; the initial AMF should also Send an AS key re-keying instruction to the target AMF.
  • the initial AMF should include Indicator2 in the Namf_Communication_N1MessageNotify message, or an instruction to perform horizontal Kamf deduction, and the initial AMF should include a new Kamf, a new ngKSI, and an instruction to perform AS key re-keying in the Namf_Communication_N1MessageNotify message.
  • Initial AMF should send the downlink NAS COUNT value to the target AMF. Specifically, Initial AMF should include the value of the downlink NAS COUNT used to generate a new Kamf in Namf_Communication_N1MessageNotify.
  • the initial AMF should send the uplink NAS COUNT value used to generate the new Kamf to the target AMF; or if the initial AMF uses the uplink NAS COUNT of the registration request when generating the new Kamf, the initial AMF should use one to indicate "Use the uplink NAS COUNT value of the registration request message to generate a new Kamf" indicator3 is sent to the target AMF; or if the initial AMF uses the NAS Security Mode Complete message uplink NAS COUNT when generating a new Kamf, the initial AMF will use one The indicator 4 indicating "Generate a new Kamf using the uplink NAS COUNT value of the NAS Security Mode Complete message" is sent to the target AMF.
  • the initial AMF sends an indication IndicatorX to Target AMF.
  • the indication IndicatorX is used to indicate "the registration request message comes from a verified UE", or “the UE has passed the verification", or “the registration message has been verified", or " No need to verify UE” or "No need to verify registration message”.
  • the initial AMF may optionally include IndicatorX in the Namf_Communication_N1MessageNotify message to send to the target AMF.
  • the initial AMF should send IndicatorX to the target AMF.
  • Step 1502 The target AMF receives Kamf, the target AMF decides whether to use the received Kamf according to the local policy, if it decides to use the received Kamf, and if the target AMF receives an instruction to generate a new Kamf or an instruction to perform a horizontal Kamf deduction , The target AMF should send the UE an instruction to perform horizontal Kamf deduction to the UE.
  • the target AMF can initiate re-authentication and re-establish a new NAS security context with the UE.
  • the target AMF should set K_AMF_change_flag (the UE's instruction for horizontal Kamf deduction) to 1.
  • the target AMF should carry the UE level Kamf deduction indication in the NAS Security Mode Command message and send it to the UE.
  • the target AMF also sends to the UE information about the value used to generate the new Kamf, which specifically includes one of the following:
  • the target AMF should send the downlink NAS COUNT value to the UE.
  • the target AMF should include the downlink NAS COUNT value in the NAS Container including the downlink NAS COUNT value.
  • the target AMF should send the uplink NAS COUNT value to the UE.
  • the target AMF should include the uplink NAS COUNT value in the NAS Secure Mode Command message.
  • the target AMF should send an indication to the UE indicating "Generate a new Kamf using the uplink NAS COUNT value in the registration request message" Indicator5, specifically the target AMF should include the Indicator5 in the NAS
  • the Security Mode Command message is sent to the UE.
  • the target AMF should send an indication to the UE indicating "Generate a new Kamf using the uplink NAS COUNT value in the NAS security mode complete message" Indicator6, specifically the target AMF should include this Indicator6 It is sent to the UE in the NAS Security Mode Command message.
  • the target AMF does not verify the received registration request RR, or the target AMF does not verify the UE.
  • Step 1503 The UE receives an instruction to perform horizontal Kamf deduction, performs horizontal Kamf deduction, and generates a new Kamf.
  • the process of the UE performing horizontal Kamf deduction is the same as that of the initial AMF performing horizontal Kamf deduction, so as to ensure that the NAS security context in the target AMF is consistent with the NAS security context in the UE.
  • K_AMF_change_flag If the UE receives that the value of K_AMF_change_flag is set to 1, it is determined that the information indicating the Kamf deduction of the UE level is received.
  • the UE performs horizontal Kamf deduction according to the information indicating the value used to generate the new Kamf to generate the new Kamf, which specifically includes one of the following:
  • the UE uses the downlink NAS COUNT value to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value in the registration request message to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value in NAS Security Mode Complete to generate a new Kamf.
  • the UE uses the value of uplink NAS COUNT in the most recently sent N1 message to generate a new Kamf. Specifically, if the UE recently sent a NAS Security Command message, the UE uses the value of uplink NAS COUNT in the NAS Security Command message to generate a new Kamf. Kamf, otherwise the UE uses the uplink NAS COUNT value in the sent registration request message.
  • the registration process includes:
  • step 1601 to step 1604 is the same as step 101 to step 103 shown in FIG.
  • Step 1605 The initial AMF determines whether it can serve the UE. If the initial AMF determines that it cannot serve the UE, the initial AMF determines that direct NAS reroute is required or the initial AMF determines that it needs to send the registration request message (or NAS message) directly to the target AMF, The initial AMF sends the current security context to the target AMF, or the initial AMF decides whether to perform horizontal Kamf derivation according to local policies. If it decides to perform horizontal key derivation, the initial AMF generates a new Kamf, and the newly generated Kamf Send to the target AMF. If it decides not to perform horizontal Kamf deduction, the initial AMF sends the current NAS security context to the target AMF.
  • Step 1606 The initial AMF sends a Namf_Communication_N1MessageNotify message to the target AMF.
  • the Namf_Communication_N1MessageNotify message includes the new Kamf and the indication Indicator 1.
  • the Namf_Communication_N1MessageNotify message includes the indication IndicatorX.
  • Initial AMF should send the downlink NAS COUNT value to the target AMF. Specifically, Initial AMF should include the value of the downlink NAS COUNT used to generate a new Kamf in Namf_Communication_N1MessageNotify.
  • Initial AMF sends the uplink NAS COUNT value used to generate the new Kamf to Target AMF; or if Initial AMF uses the uplink NAS COUNT of the registration request when generating the new Kamf, Initial AMF will use one to indicate "Use The registration request message’s uplink NAS COUNT value generates a new Kamf indication, Indicator3 is sent to Target AMF; or if Initial AMF uses NAS Security Mode Complete message’s uplink NAS COUNT when generating a new Kamf, Initial AMF will be used to indicate The indication "Use the uplink NAS COUNT value of the NAS Security Mode Complete message to generate a new Kamf" indicator 4 is sent to the Target AMF.
  • Step 1607 The target AMF receives the new Kamf and the indicator 1, and decides to use the received new Kamf according to the local policy; if not, the target AMF can initiate re-authentication and establish a new NAS security context with the UE. If the target AMF decides to use the received Kamf according to the local policy, if the target AMF should set K_AMF_change_flag to 1.
  • Step 1608 The target AMF includes the K_AMF_change_flag as 1 in the security mode command Security Mode Command message and sends it to the UE, and the Security Mode Command message should indicate information about the value used to generate the new Kamf.
  • the target AMF should send the downlink NAS COUNT value to the UE.
  • the target AMF should include the downlink NAS COUNT value in the NAS Container including the downlink NAS COUNT value.
  • the target AMF should send the uplink NAS COUNT value to the UE.
  • the target AMF should include the uplink NAS COUNT value in the NAS Secure Mode Command message.
  • the target AMF should send an indication to the UE indicating “use the uplink NAS COUNT value in the registration request message to generate a new Kamf” indication Indicator5, specifically the target AMF should include the Indicator5 in the NAS
  • the Security Mode Command message is sent to the UE.
  • the target AMF should send an indication to the UE indicating "Generate a new Kamf using the uplink NAS COUNT value in the NAS security mode complete message" Indicator6, specifically the target AMF should include this Indicator6 It is sent to the UE in the NAS Security Mode Command message.
  • Step 1609 The UE receives that the value of K_AMF_change_flag is 1 to determine to perform horizontal Kamf deduction, and generates a new Kamf according to the received value used for generating a new Kamf.
  • the UE uses the downlink NAS COUNT value to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value in the registration request message to generate a new Kamf.
  • the UE uses the uplink NAS COUNT value in NAS Security Mode Complete to generate a new Kamf.
  • the UE uses the value of uplink NAS COUNT in the most recently sent N1 message to generate a new Kamf. Specifically, if the UE recently sent a NAS Security Command message, the UE uses the value of uplink NAS COUNT in the NAS Security Command message to generate a new Kamf. Kamf, otherwise the UE uses the uplink NAS COUNT value in the sent registration request message.
  • an embodiment of the present application also provides a schematic structural diagram of a registration apparatus 1700.
  • the apparatus 1700 may be used to implement the method described in the foregoing method embodiment applied to AMF or UE, and reference may be made to the description in the foregoing method embodiment.
  • the device 1700 includes one or more processors 1701.
  • the processor 1701 may be a general-purpose processor or a special-purpose processor. For example, it can be a baseband processor or a central processing unit.
  • the baseband processor can be used to process communication protocols and communication data
  • the central processor can be used to control communication devices (such as base stations, terminals, or chips), execute software programs, and process data in the software programs.
  • the communication device may include a transceiving unit to implement signal input (reception) and output (transmission).
  • the transceiver unit may be a transceiver, a radio frequency chip, or the like.
  • the apparatus 1700 includes one or more processors 1701, and the one or more processors 1701 can implement the AMF or UE method in the above-mentioned embodiment.
  • the processor 1701 may implement other functions in addition to implementing the methods in the above-mentioned embodiments.
  • the processor 1701 may execute instructions to cause the apparatus 1700 to execute the method described in the foregoing method embodiment.
  • the instructions may be stored in the processor in whole or in part, such as the instruction 1703, or in the memory 1702 coupled to the processor, in whole or in part, such as the instruction 1704, or the instructions 1703 and 1704 can be used together to make
  • the apparatus 1700 executes the method described in the foregoing method embodiment.
  • the communication device 1700 may also include a circuit, and the circuit may implement the function of the AMF or UE in the foregoing method embodiment.
  • the device 1700 may include one or more memories 1702, on which instructions 1704 are stored, and the instructions may be executed on the processor, so that the device 1700 executes the foregoing method The method described in the examples.
  • data may also be stored in the memory.
  • the optional processor may also store instructions and/or data.
  • the one or more memories 1702 may store the corresponding relationship described in the foregoing embodiment, or related parameters or tables involved in the foregoing embodiment.
  • the processor and memory can be provided separately or integrated together.
  • the device 1700 may further include a transceiver unit 1705 and an antenna 1706.
  • the processor 1701 may be referred to as a processing unit, which controls a device (terminal or base station).
  • the transceiver unit 1705 may be called a transceiver, a transceiver circuit, or a transceiver, etc., and is used to implement the transceiver function of the device through the antenna 1706.
  • the processor in the embodiment of the present application may be an integrated circuit chip with signal processing capability.
  • the steps of the foregoing method embodiments can be completed by hardware integrated logic circuits in the processor or instructions in the form of software.
  • the aforementioned processor may be a general-purpose processor, a digital signal processor (Digital Signal Processor, DSP), an application specific integrated circuit (ASIC), a ready-made programmable gate array (Field Programmable Gate Array, FPGA) or other Programming logic devices, discrete gates or transistor logic devices, discrete hardware components.
  • DSP Digital Signal Processor
  • ASIC application specific integrated circuit
  • FPGA ready-made programmable gate array
  • the methods, steps, and logical block diagrams disclosed in the embodiments of the present application can be implemented or executed.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
  • the steps of the method disclosed in the embodiments of the present application may be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor.
  • the software module can be located in a mature storage medium in the field such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, registers.
  • the storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
  • the memory in the embodiments of the present application may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory.
  • the non-volatile memory can be read-only memory (Read-Only Memory, ROM), programmable read-only memory (Programmable ROM, PROM), erasable programmable read-only memory (Erasable PROM, EPROM), and electrically available Erase programmable read-only memory (Electrically EPROM, EEPROM) or flash memory.
  • the volatile memory may be random access memory (Random Access Memory, RAM), which is used as an external cache.
  • RAM random access memory
  • SRAM static random access memory
  • DRAM dynamic random access memory
  • DRAM synchronous dynamic random access memory
  • SDRAM double data rate synchronous dynamic random access memory
  • Double Data Rate SDRAM DDR SDRAM
  • ESDRAM enhanced synchronous dynamic random access memory
  • Synchlink DRAM SLDRAM
  • DR RAM Direct Rambus RAM
  • the embodiment of the present application also provides a computer-readable medium on which a computer program is stored, and when the computer program is executed by a computer, the registration method described in any method embodiment applied to the AMF or UE is implemented.
  • the embodiment of the present application also provides a computer program product that, when executed by a computer, implements the registration method described in any method embodiment applied to the AMF or UE.
  • the computer program product includes one or more computer instructions.
  • the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
  • the computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website, computer, server, or data center.
  • the computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center integrated with one or more available media.
  • the usable medium may be a magnetic medium (for example, a floppy disk, a hard disk, and a magnetic tape), an optical medium (for example, a high-density digital video disc (Digital Video Disc, DVD)), or a semiconductor medium (for example, a solid state disk (Solid State Disk, SSD)) etc.
  • An embodiment of the present application also provides a processing device, including a processor and an interface; the processor is configured to execute the registration method described in any method embodiment applied to AMF or UE.
  • the foregoing processing device may be a chip, and the processor may be implemented by hardware or software.
  • the processor When implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc.; when implemented by software, At this time, the processor may be a general-purpose processor, which is implemented by reading the software code stored in the memory, and the memory may be integrated in the processor, may be located outside the processor, and exist independently.
  • the disclosed system, device, and method may be implemented in other ways.
  • the device embodiments described above are merely illustrative, for example, the division of units is only a logical function division, and there may be other divisions in actual implementation, for example, multiple units or components can be combined or integrated. To another system, or some features can be ignored, or not implemented.
  • the displayed or discussed mutual coupling or direct coupling or communication connection may be indirect coupling or communication connection through some interfaces, devices or units, and may also be electrical, mechanical or other forms of connection.
  • the units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the solutions of the embodiments of the present application.
  • the functional units in the various embodiments of the present application may be integrated into one processing unit, or each unit may exist alone physically, or two or more units may be integrated into one unit.
  • the above-mentioned integrated unit can be implemented in the form of hardware or software functional unit.
  • the computer-readable medium includes a computer storage medium and a communication medium, where the communication medium includes any medium that facilitates the transfer of a computer program from one place to another.
  • the storage medium may be any available medium that can be accessed by a computer.
  • computer readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or can be used to carry or store instructions or data structures
  • Any connection can suitably become a computer-readable medium.
  • the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave
  • coaxial cable , Fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, wireless and microwave are included in the fixing of the media.
  • Disk and disc include compact discs (CD), laser discs, optical discs, digital versatile discs (DVD), floppy discs and Blu-ray discs. Disks usually copy data magnetically, while discs The laser is used to optically copy data. The above combination should also be included in the protection scope of the computer-readable medium.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请实施例涉及一种注册方法及装置,用以保证UE不丢弃并处理接收到的目标AMF发送的认证请求消息,该注册方法为初始AMF向UE发送指示信息,或者是目标AMF向UE发送包括指示信息的认证请求消息,指示信息用于指示UE删除NAS安全上下文,UE删除NAS安全上下文,处理接收到的认证请求消息,向目标AMF发送认证响应消息,或者是UE直接处理接收到的没有安全保护的认证请求消息,向目标AMF发送认证响应消息。

Description

一种注册方法及装置
相关申请的交叉引用
本申请要求在2019年04月29日提交中国专利局、申请号为201910357072.4、申请名称为“一种注册方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中;本申请要求在2019年06月17日提交中国专利局、申请号为201910521938.0、申请名称为“一种注册方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中;本申请要求在2019年08月19日提交中国专利局、申请号为201910765736.0、申请名称为“一种注册方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及无线通信技术领域,尤其涉及一种注册方法及装置。
背景技术
标准第三代合作伙伴项目(3rd Generation Partnership Project,3GPP)TS 23.502[1]中定义了在第五代移动通信技术(5th-Generation,5G)系统中,用户设备(User Equipment,UE)在注册过程中发生核心接入与移动管理功能网元(Core Access and Mobility Management Function,AMF)重定向的流程。
UE在初始注册时,UE首先发起携带了用户隐藏标识符(Subscriber Concealed Identifier,SUCI)的注册请求信息,该注册请求信息中只携带明文cleartext IEs,初始Initial AMF接收到携带有SUCI的注册请求之后,发起主认证,生成AMF密钥Kamf,以及对应的密钥标识符ngKSI。Initial AMF通过非接入层(Non-Access Stratum,NAS)安全模式控制(Security Mode Control)流程,激活并开始用主认证生成的Kamf。UE也激活并使用Kamf。由于UE发送的注册请求消息中只包括cleartext IEs,UE在NAS Security Mode Complete消息中,发送完整注册请求消息,该完整注册请求信息中包括Requested S-NSSAIs。Initial AMF根据Requested S-NSSAIs,判断自己是否能服务UE。当Initial AMF不能服务UE时,Initial AMF进行NAS reroute,即AMF重定向,Initial AMF将接收到的注册请求信息发送给可以服务UE的目标Target AMF。当Initial AMF和Target AMF之间没有直接连接时,Initial AMF将接收到的携带SUCI的注册请求消息通过(无线)接入网络((Radio)Access Network,(R)AN)发给Target AMF。
由于Target AMF中没有NAS安全上下文,其中NAS安全上下文包括AMF密钥Kamf,以及对应的密钥标识符ngKSI等,所以Target AMF发起主认证时,发送给UE没有安全保护的认证请求(Authentication Request)消息,由于UE不感知AMF重定向,并且UE中已经建立了NAS安全上下文,因此UE接收到没有安全保护的Authentication Request消息时,不会处理该Authentication Request消息,导致UE注册失败,无法接入网络。
发明内容
本申请实施例提供了注册方法及装置,从而避免现有UE丢弃不处理目标AMF发送的认证请求消息,以避免UE注册失败。
第一方面,提供了一种注册方法,包括以下过程:
初始AMF向UE发送第一非接入层安全模式命令(NAS Ssecurity Mode Command)消息,或初始AMF向UE发送携带第八指示信息的第一非接入层安全模式命令消息。所述第八指示信息用于指示UE保存NAS安全上下文,如果有的话,或者,用于指示UE保存当前使用NAS安全上下文,如果有的话。
所述UE,根据第一非接入层安全模式命令消息,或者所述第八指示信息,应保存NAS安全上下文,如果有的话,或者,应保存当前使用的NAS安全上下文,如果有的话。
所述初始AMF确定进行AMF重定向;
所述初始AMF应向所述UE发送指示信息,所述指示信息用于指示UE删除或丢弃NAS安全上下文,和/或,用于指示UE去激活(deactivate)UE的当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。
应理解,所述初始AMF在所述初始AMF决定进行通过(无线)接入网络((R)AN)进行AMF重定向之后,在所述初始AMF向所述(无线)接入网络((R)AN)发送非接入层NAS重转消息(NAS Reroute Message)之前发送所述指示信息。
UE接收初始AMF发送的指示信息;
所述UE根据所述指示信息,应,丢弃或删除NAS安全上下文;和/或,去激活UE的当前NAS安全上下文,和/或,确定不丢弃并处理接收到的没有安全保护的认证请求消息,和/或,确定网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,恢复使用保存的NAS安全上下文,如果有的话;
所述UE如果接收目标AMF发送的认证请求消息,处理所述认证请求消息,向所述目标AMF发送没有安全保护的认证响应消息。
在初始注册过程中,如果初始AMF决定要发生AMF重定向,初始AMF将用于指示UE删除NAS安全上下文的指示信息,或者用于指示UE去激活当前NAS安全上下文的指示信息,或者用于指示UE处理没有安全保护的认证请求信息的指示信息,或者用于指示UE网络侧发生AMF重定向的指示信息发送给UE。UE接收该指示信息,根据该指示信息删除NAS安全上下文,处理接收到的认证请求信息;或者UE根据该指示信息去激活当前NAS安全上下文,处理接收到的认证请求消息;或者UE根据该指示信息处理接收到的认证请求信息;没有安全保护或者UE确定网络侧发生AMF重定向,处理接收到的认证请 求消息。UE向目标AMF发送没有安全保护的认证响应消息。UE不丢弃并处理接收到的认证请求消息,避免了UE注册失败。
在一种可能的实现中,初始AMF发送指示信息包括:
所述初始AMF向所述UE发送第一通知消息,所述第一通知消息用于指示所述UE删除NAS安全上下文,和/或者,用于指示UE去激活当前NAS安全上下文,和/或者,用于指示UE处理没有安全保护的认证请求消息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。
UE接收初始AMF发送的指示信息包括:
UE接收初始AMF发送的第一通知消息。
初始AMF向UE发送第一通知消息,UE接收第一通知消息,第一通知消息指示UE删除NAS安全上下文,或者指示UE去激活当前NAS安全上下文,或者指示UE处理没有安全保护的认证请求消息,或者指示UE网络侧发生AMF重定向,保证了UE不丢弃并处理接收到的认证请求消息。
在一种可能的实现中,所述初始AMF发送指示信息包括:
所述初始AMF向UE发送第一NAS消息,其中所述第一NAS消息中携带第一指示信息,所述第一指示信息用于指示所述UE删除NAS安全上下文,和/或,指示UE去激活当前NAS安全上下文,和/或,指示UE处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。本申请中不对携带所述第一指示信息的第一NAS消息做限制,NAS消息可能的选项有配置更新命令(configuration update command)消息、下行NAS传输(downlink NAS transport)消息、5G系统移动管理状态(5G system mobility management status,5GMM Status)和注册拒绝(registration reject)消息等。
UE接收初始AMF发送的指示信息包括:
UE接收初始AMF发送的第一NAS消息,所述第一NAS消息中携带有第一指示信息。
初始AMF向UE发送第一NAS消息,UE接收第一NAS消息,第一消息中携带第一指示信息来指示UE删除NAS安全上下文,或者指示UE去激活当前NAS安全上下文,或者指示UE处理没有安全保护的认证请求消息,或者指示UE网络侧发生AMF重定向,保证了UE不丢弃并处理接收到的认证请求消息。
在一种可能的实现中,所述第一通知消息或所述第一NAS消息中携带有ngKSI,所述ngKSI用于指示所述UE删除或者去激活所述ngKSI对应的NAS安全上下文。
初始AMF向UE发送的第一通知消息或第一NAS消息中携带ngKSI,UE删除或者去 激活该ngKSI对应的NAS安全上下文,保证了UE不丢弃并处理接收到的认证请求消息。
第二方面,提供了一种注册方法,包括如下过程:
目标AMF接收第六指示信息,所述第六指示信息用于指示UE删除NAS安全上下文、和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话;
所述目标AMF根据所述第六指示信息,应在向UE发送认证请求消息中包括用于指示所述UE删除NAS安全上下文的指示信息,和/或,包括用于指示UE去激活当前NAS安全上下文的指示信息,和/或,包括用于指示UE处理没有安全保护的认证请求消息的指示信息,和/或,包括用于指示UE网络侧发生AMF重定向的指示信息;和/或,包括用于指示UE恢复无NAS安全上下文的指示信息,和/或,包括用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文的指示信息,和/或,包括用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文的指示信息,和/或,包括用于指示UE删除或丢弃新的NAS安全上下文的指示信息,和/或,包括用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文的指示信息,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。
所述目标AMF接收所述UE发送的没有安全保护的认证响应消息。
UE接收目标AMF发送的认证请求消息,所述认证请求信息中包括用于指示UE删除NAS安全上下文的指示信息,或者包括用于指示UE去激活当前NAS安全上下文的指示信息,或者包括用于指示UE处理没有安全保护的认证请求消息的指示信息,或者包括用于指示UE网络侧发生AMF重定向的指示信息;
所述UE根据所述认证请求消息中包括的用于指示UE删除NAS安全上下文的指示信息,删除NAS安全上下文,处理认证请求消息;所述UE根据所述认证请求消息中包括的用于指示UE去激活NAS安全上下文的指示信息,去激活当前NAS安全上下文,处理所述认证请求消息;所述UE根据所述认证请求消息中包括的用于指示UE处理没有安全保护的认证请求消息的指示,处理没有安全保护的认证请求消息;所述UE根据所述认证请求消息中包括的用于指示UE网络侧发生了AMF重定向的指示信息,处理所述认证请求消息。
所述UE根据目标AMF发送的所述指示信息,应,丢弃或删除NAS安全上下文;和/或,去激活UE的当前NAS安全上下文,和/或,确定不丢弃并处理接收到的没有安全保护的认证请求消息,和/或,确定网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文;和/或,恢复使用保存的NAS安全上下文,如果有的话。
所述UE向所述目标AMF发送没有安全保护的认证响应消息。
目标AMF根据接收到的第六指示信息,在向UE发送的认证请求消息中包括用于指示UE删除NAS安全上下文的指示信息,或者包括用于指示UE去激活当前NAS安全上下文的指示信息,或者包括用于指示UE处理没有安全保护的认证请求消息的指示信息,或者包括用于指示UE网络侧发生AMF重定向的指示信息。UE根据认证请求消息中包括的用于指示UE删除安全上下文的指示信息,删除NAS安全上下文。或者UE根据认证请求消息中包括的用于指示UE去激活当前安全上下文的指示信息,去激活当前NAS安全上下文。或者UE根据认证请求消息中包括的用于指示UE处理没有安全保护的认证请求消息的指示信息,处理没有安全保护的认证请求消息。或者UE根据认证请求消息中包括的用于指示UE网络侧发生AMF重定向,处理所述认证请求消息。或者UE根据认证请求消息中包括的用于指示UE恢复使用保存的NAS安全上下文的指示信息,UE恢复使用保存的NAS安全下文,如果有的话,UE处理所述认证请求消息。保证了UE不丢弃并处理接收到的认证请求消息。
在一种可能的实现中,所述初始AMF将第六指示信息发送给RAN,所述目标AMF接收RAN发送的第六指示信息。
在一种可能的实现中,所述初始AMF将第六指示信息携带在Reroute NAS Message中发送给(R)AN。(R)AN将第六指示信息携带在Initial UE Message中发送给目标AMF。
在一种可能的实现中,所述目标AMF接收第六指示信息包括:
所述目标AMF接收RAN发送的第二通知消息,所述第二通知消息中携带第二指示信息,所述第二指示信息用于指示UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,指示所述UE恢复使用保存的NAS安全上下文,如果有的话。
所述目标AMF根据第二指示信息,在向UE发送认证请求消息中包括所述第三指示信息,用于指示所述UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,指示所述UE恢复使用保存的NAS安全上下文,如果有的话。
所述UE根据所述第三指示信息,删除NAS安全上下文,处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理没有安全保护的认证请求 消息,和/或,确定网络侧发生AMF重定向,处理认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,恢复使用保存的NAS安全上下文,如果有的话,处理认证请求消息。
目标AMF根据接收到的第二通知消息或者第二指示信息,在向UE发送的认证请求消息中包括所述第三指示信息,UE根据该第三指示信息,删除NAS安全上下文,处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理接收到的没有安全保护的认证请求消息,和/或,确定网络侧发生AMF重定向,处理认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,恢复使用保存的NAS安全上下文,如果有的话,保证了UE不丢弃并处理接收到的认证请求消息。
在一种可能的实现中,所述目标AMF接收第六指示信息,包括:
所述目标AMF接收RAN发送的第三通知消息,所述第三通知消息中携带第四指示信息;
用于指示UE验证所述第四指示信息,验证成功后,删除NAS安全上下文、和/或,去激活当前NAS安全上下文,和/或,处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,UE删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,恢复使用保存的NAS安全上下文,如果有的话。
所述第四指示信息,还可用于,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示。
所述目标AMF根据所述第四指示信息,在向UE发送认证请求消息中包括所述第四指示信息。
所述认证请求消息中携带的用于指示UE删除NAS安全上下文的指示信息,或者用于指示UE去激活当前NAS安全上下文的指示信息,或者用于指示UE处理没有安全保护的认证请求信息的指示信息,或者用于指示UE网络侧发生AMF重定向的指示信息为第四指示信息;
所述UE应验证所述第四指示信息,验证成功之后,应删除NAS安全上下文、处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理没有安全保护的认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息, 和/或,UE删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,恢复使用保存的NAS安全上下文,如果有的话,处理认证请求信息。
第四指示信息是初始AMF根据与UE之间的共享密钥生成的。该第四指示信息包括第一参数以及第一参数的消息认证码。该第一参数可以为一个随机数,或者为UE发送给初始AMF的注册消息的UL NAS Count,或者是UE发送给初始AMF的NAS Security Complete的UL NAS Count中的一种或多种。该第一参数消息认证码是利用初始AMF根据与UE之间的共享密钥,对该第一参数计算的消息认证码。该共享密钥可以是UE和初始AMF之间通过主认证生成的Kamf,或者Kseaf,或者NAS加密密钥Knasenc,或者NAS完保密钥Knasint等中的一项或多项。
目标AMF根据接收到的第三通知消息,在向UE发送的认证请求消息中包括第四指示信息,UE验证该第四指示信息,删除NAS安全上下文,或者去激活当前NAS安全上下文,或者处理没有安全保护的认证请求消息,或者确定网络侧发生AMF重定向,在保证UE处理接收到的没有安全保护的认证请求消息的基础上,通过验证该第四指示信息,防止了攻击者发送仿冒的该第四指示信息,提高了整个注册过程中的安全性。
在一种可能的实现中,所述目标AMF接收第六指示信息包括:
所述目标AMF接收所述RAN发送的完整注册请求消息;
所述目标AMF根据所述完整注册请求消息,向UE发送认证请求消息,并在所述认证请求中包括第五指示信息,用于指示所述UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。
所述UE根据所述第五指示信息,应,删除NAS安全上下文,处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理没有安全保护的认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,UE删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,恢复使用保存的NAS安全上下文,如果有的话,处理认证请求消息。
目标AMF根据接收到的完整注册请求消息,在向UE发送的认证请求消息中包括所述第五指示信息,UE根据该第五指示信息,删除NAS安全上下文,或者去激活当前NAS安全上下文,或者处理接收到没有安全保护的认证请求消息,或者确定网络侧发生AMF重定向,保证了UE不丢弃并处理接收到的认证请求消息。
在一种可能的实现中,所述目标AMF向UE发送认证请求消息,指示所述UE删除或者去激活NAS安全上下文包括:
所述目标AMF根据获取到的下一代密钥集标识ngKSI,将所述ngKSI携带在认证请求消息中发送给UE,所述ngKSI用于指示所述UE删除或者去激活所述ngKSI对应的NAS安全上下文。
所述认证请求消息中携带有下一代密钥集标识符ngKSI,UE删除或者去激活NAS安全上下文包括:
根据所述ngKSI,删除所述ngKSI对应的NAS安全上下文。
UE删除或去激活该ngKSI对应的NAS安全上下文,保证了UE不丢弃并处理接收到的认证请求消息。
第三方面,提供了一种注册方法,包括如下过程:
UE与初始AMF建立NAS安全上下文;
所述UE接收目标AMF发送的没有安全保护的认证请求消息;
所述UE处理所述没有安全保护的认证请求消息。
所述UE发送没有安全保护的认证响应消息。
UE可以不丢弃,而是直接处理没有安全保护的认证请求消息,保证了UE初始注册成功,UE成功接入网络。
第四方面,提供了一种注册方法,包括如下过程:
初始AMF向UE发送第一非接入层安全模式命令(NAS Ssecurity Mode Command)消息,或初始AMF向UE发送携带第八指示信息的第一非接入层安全模式命令消息。所述第八指示信息用于指示UE保存NAS安全上下文,如果有的话,或者,用于指示UE保存当前使用NAS安全上下文,如果有的话。
所述UE,根据第一非接入层安全模式命令消息,或者所述第八指示信息,应,保存NAS安全上下文,如果有的话,或者,保存当前使用的NAS安全上下文,如果有的话。
初始AMF决定进行AMF重定向,并确定目标AMF;
初始AMF向目标AMF和/或用户设备UE发送第六指示信息,用于指示UE删除NAS安全上下文,或者用于指示UE去激活当前NAS安全上下文,或者用于指示UE处理没有安全保护的认证请求消息,或者指示UE网络侧发生AMF重定向;所述第六指示信息还可以用于指示UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。
一种可能的实现中,初始AMF向目标AMF和/或UE发送第六指示信息包括:
初始AMF在向(无线)接入网络((R)AN)发送的Reroute NAS Message中包括第二通知消息,所述第二通知消息包括第二指示信息。所述第二指示信息用于指示UE删除NAS安全上下文,或者用于指示UE去激活当前NAS安全上下文,或者用于指示UE处理没有安全保护的认证请求消息,或者指示UE网络侧发生AMF重定向。所述第二指示信息还 可以用于指示UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。所述第二通知消息还包括携带SUCI的注册请求。所述第二通知消息还包括可选的ngKSI。
所述(无线)接入网络((R)AN)的将接收到的第二通知消息在Initial UE Message中发送给目标AMF。
所述目标AMF根据所述第二指示信息,在向UE发送认证请求消息中包括第三指示信息,用于指示UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。所述AMF在所述认证请求消息中包括可选的ngKSI。
一种可能的实现中,初始AMF向目标AMF和/或UE发送第六指示信息包括:
初始AMF在向(无线)接入网络((R)AN)发送的Reroute NAS Message中包括第三通知消息,所述第三通知消息包括第四指示信息。所述第四指示信息用于指示UE验证所述第四指示信息,验证成功后,删除NAS安全上下文,和/或,去激活当前NAS安全上下文,和/或,处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,UE删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。所述第四指示信息,还可用于,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示。
所述第三通知消息还包括携带SUCI的注册请求。所述第三通知消息还包括可选的ngKSI。
所述(无线)接入网络((R)AN)的将接收到的第三通知消息在Initial UE Message中发送给目标AMF。
所述目标AMF根据所述第四指示信息,在向UE发送认证请求消息中包括所述第四指示信息和可选的ngKSI;
一种可能的实现中,初始AMF向目标AMF和/或UE发送第六指示信息包括:
初始AMF在向(无线)接入网络((R)AN)发送的Reroute NAS Message中包括完整 初始注册请求消息和可选的ngKSI。
所述(无线)接入网络((R)AN)的将接收到的完整注册请求消息和可选地ngKSI在Initial UE Message中发送给目标AMF。
所述目标AMF根据所述完整注册请求信息,向UE发送认证请求消息,并在所述认证请求消息中包括第五指示信息,用于指示所述UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE恢复使用保存的NAS安全上下文,如果有的话。所述AMF在所述认证请求消息中包括可选的ngKSI。
第五方面,提供了一种注册方法,包括如下过程:
初始AMF在UE的注册过程中决定发起通过(R)AN的AMF重定向或通过(R)AN的NAS Reroute,并决定重定向到目标AMF,初始AMF应请求目标AMF为UE分配一个新的5G-GUTI,或初始AMF给UE分配一个新的5G-GUTI,或者初始AMF应请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI或者初始AMF为UE分配一个用于AMF重定向的特殊的新的5G-GUTI,初始AMF应将新的5G-GUTI发送给UE,初始AMF应发起去注册流程或者注册拒绝消息,指示UE进行重注册,以及初始AMF应可选地发起RRC链接释放,UE应根据指示,进行重选注册,UE应向目标AMF发起携带有新的5G-GUTI的注册请求消息RR。
在该方法中初始AMF应跳过通过(R)AN的NAS reroute的步骤,即跳过了初始AMF将接收到的注册请求发送给(R)AN,(R)AN将注册请求发送给目标AMF的过程。
一种可能的实现中,初始AMF应向目标AMF发送请求为UE分配新的5G-GUTI的信息,目标AMF应为UE分配一个新的5G-GUTI,目标AMF应将携带有新的5G-GUTI的消息发送给初始AMF。
目标AMF分配一个新的5G-GUTI后,对该新的5G-GUTI做标记,如标记该新的5G-GUTI为AMF重定向场景中使用的5G-GUTI,和/或标记该新的5G-GUTI是为UE分配的新的5G-GUTI。
可选地,初始AMF请求目标AMF分配一个新的5G-GUTI。
可选地,初始AMF应将接收到的注册请求中携带的SUCI发送给目标AMF。
目标AMF在接收到初始AMF发送的SUCI后,应存储该SUCI,建立该SUCI与新的5G-GUTI的对应关系。
可选地,初始AMF应通知目标AMF发生AMF重定向。
一种可能的实现中,初始AMF应为UE分配一个新的5G-GUTI。
初始AMF分配一个新的5G-GUTI后,对UE进行标记或者对该新的5G-GUTI做标记,如标记该新的5G-GUTI为AMF重定向场景中使用的5G-GUTI,和/或标记该新的5G-GUTI是为UE分配的新的5G-GUTI。
一种可能的实现中,初始AMF应向目标AMF发送请求为UE分配用于AMF重定向 的特殊的新的5G-GUTI的信息,目标AMF应为UE分配一个用于AMF重定向的特殊的新的5G-GUTI,目标AMF应将携带有用于AMF重定向的特殊的新的5G-GUTI的消息发送给初始AMF。
可选地,初始AMF请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI。
可选地,初始AMF将接收到的注册请求中携带的SUCI发送给目标AMF。
目标AMF在接收到初始AMF发送的SUCI后,应存储该SUCI,建立该SUCI与用于AMF重定向的特殊的新的5G-GUTI的对应关系。
可选地,初始AMF通知目标AMF发生AMF重定向。
一种可能的实现中,初始AMF为UE分配一个用于AMF重定向的特殊的新的5G-GUTI。
一种可能的实现中,目标AMF接收注册请求RR,检查RR中携带的5G-GUTI。
如果目标AMF在本地对5G-GUTI有标注,目标AMF应发起身份请求流程获取UE的SUCI,进行主认证,以实现UE的成功注册。
或者,如果目标AMF在本地对5G-GUTI有标注,目标AMF应查找SUCI与5G-GUTI的对应关系,进行主认证,以实现UE的成功注册。
如果目标AMF确定该5G-GUTI为AMF重定向场景中使用的5G-GUTI,目标AMF应发起身份请求流程获取UE的SUCI,进行主认证,以实现UE的成功注册。
或者,如果目标AMF确定该5G-GUTI为AMF重定向场景中使用的5G-GUTI,目标AMF应查找SUCI与5G-GUTI的对应关系,进行主认证,以实现UE的成功注册。
如果目标AMF之前接收到SUCI,则目标AMF应发起主认证,以实现UE的成功注册。
或者,如果目标AMF未接收到SCUI,则目标AMF应发起身份请求流程获取UE的SUCI,然后进行主认证,以实现UE的成功注册。
第六方面,提供了一种注册方法,包括如下过程:
UE在注册请求消息中可选地携带指示Indicator 1。
在一种可能的实现中,该指示Indicator 1用于指示:
UE为非15版本的UE;或
UE为16版本或16版本之后的UE;或
UE支持16版本及以后的能力;或
UE支持通过(R)AN进行NAS reroute的能力;或
UE支持通过(R)AN进行AMF重定向的能力;或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)NAS安全上下文回退的能力;或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)(恢复)使用老的NAS安全上下文的能力;或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)删除新的NAS安全上下文的能力;或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)持恢复到无NAS安全上下文的能力;或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)进行 NAS reroute中NAS安全上下文处理的能力。
在一种可能的实现中,如果初始AMF没有接收到指示Indicator 1,或者初始AMF根据注册请求消息,
判断UE为版本15的UE;或
判断UE为非16版本或16版本之后的UE;或
判断UE不支持16版本及以后的能力;或
判断UE不支持通过(R)AN进行NAS reroute的能力;或
判断UE不支持通过(R)AN进行AMF重定向的能力;或
判断不UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)NAS安全上下文回退的能力;或
判断UE不支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)(恢复)使用老的NAS安全上下文的能力;或
判断UE不支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)删除新的NAS安全上下文的能力;或
判断UE不支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)持恢复到无NAS安全上下文的能力;或
判断UE不支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)进行NAS reroute中NAS安全上下文处理的能力;则初始AMF应进行直接NAS reroute或初始AMF应直接将注册请求消息转发目标AMF,或者初始AMF执行第五方面及第五方面中的任一种可能实现方式中所有的方法。
即初始AMF执行初始AMF应向目标AMF发送请求为UE分配一个新的5G-GUTI的信息,或者初始AMF应请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI。或者,初始AMF应为UE分配一个新的5G-GUTI,或者初始AMF应为UE分配一个用于AMF重定向的特殊的新的5G-GUTI。
在一种可能的实现中,初始AMF接收到指示Indicator 1,或初始AMF根据注册请求消息,
判断UE为非版本15的UE;或
判断UE为16版本或16版本之后的UE;或
判断UE支持16版本及以后的能力;或
判断UE支持通过(R)AN进行NAS reroute的能力;或
判断UE支持通过(R)AN进行AMF重定向的能力;或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)NAS安全上下文回退的能力;或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)(恢复)使用老的NAS安全上下文的能力;或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)删除新的NAS安全上下文的能力;或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)持恢复到无NAS安全上下文的能力;或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中) 进行NAS reroute中NAS安全上下文处理的能力;初始AMF执行第一、二、三、四方面及第一、二、三、四方面中的任一种可能实现方式中所有的方法。
即,初始AMF应通知UE发送AMF重定向,或初始AMF应指示UE删除NAS安全上下文,或初始AMF应返回到发送注册请求时的安全,或初始AMF应指示UE接收并处理没有保护的认证请求消息等。或者初始AMF应通知目标AMF发生AMF重定向。或者初始AMF应将NAS安全上下文发送给目标AMF。或者初始AMF应将完整的注册请求消息发送给目标AMF。
在一种可能的实现中,初始AMF如果根据本地策略和订阅信息决定进行通过(R)AN的NAS reroute(或通过(R)AN将注册请求消息发送给目标AMF),初始AMF执行第一、二、三、四方面及第一、二、三、四方面中的任一种可能实现方式中所有的方法。
第七方面,提供了一种注册方法,包括如下过程:
初始AMF在UE的注册过程中根据本地策略决定发起AMF重定向,初始AMF决定进行直接NAS Reroute,即将注册请求(或NAS消息)直接发送到目标AMF时,则初始AMF执行以下三种方式中其中的一种描述的步骤。
方式一:
初始AMF应将UE当前的NAS安全上下文发送给目标AMF。
方式二:
初始AMF根据初始AMF本地策略决定是否进行水平Kamf推演。如果初始AMF决定进行水平Kamf推演,则初始AMF生成新的Kamf,并将新的Kamf发送给目标AMF。如果初始AMF决定不进行水平Kamf推演,则初始AMF应将UE当前的NAS安全上下文发送给目标AMF。
方式三:
初始AMF根据第一AMF是否进行密钥推演决定初始AMF是否进行密钥推演,具体地包括以下几种可能:
可能一:
如果第一AMF没有进行密钥推演,则初始AMF根据本地策略决定是否进行密钥推演。
例如,如果初始AMF没有接收到来自第一AMF的用于指示生成了新密钥的第十三指示信息;或者初始AMF没有接收到第一AMF发送的密钥推演指示,该密钥推演指示可以称为keyAMFHDerivationInd,用于指示第一AMF进行了密钥推演,则初始AMF根据本地策略决定是否进行密钥推演。如果初始AMF决定进行水平Kamf推演,则初始AMF生成新的Kamf,并将新的Kamf发送给目标AMF。如果初始AMF决定不进行水平Kamf推演,则初始AMF应将UE当前的NAS安全上下文发送给目标AMF。
其中,第一AMF可以为初始AMF或目标AMF,也可以为除初始AMF及目标AMF外的其他AMF。
可能二:
第一AMF进行了密钥推演,则初始AMF将UE当前的NAS安全上下文发送给UE。
例如,初始AMF接收来自第一AMF的用于指示生成了新密钥的第十三指示信息;或者初始AMF接收到第一AMF发送的密钥推演指示,则初始AMF将当前的UE的安全上下文发送给UE。
在一种可能的实现中,初始AMF进行水平Kamf推演,生成一个新的Kamf。初始AMF 生成一个新的Kamf应包括以下中的一种:
初始AMF根据当前的Kamf以及注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;或者,
初始AMF根据当前的Kamf以及NAS Security Mode Complete消息中的uplink NAS COUNT的值,生成新的Kamf;或者,
初始AMF根据当前的Kamf以及当前的downlink NAS COUNT的值,生成新的Kamf。
具体的,初始AMF进行水平Kamf推演,生成一个新的Kamf包括以下中的一种:
初始AMF应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf。
初始AMF应根据当前的Kamf和接收到的NAS Security Mode Complete消息中的uplink NAS COUNT的值,生成新的Kamf。
初始AMF应根据当前的Kamf和最近接收到的N1消息的uplink NAS COUNT的值,生成新的Kamf。具体的,N1消息包括注册请求RR和/或NAS Security Mode Complete消息,即如果初始AMF接收到了UE发送的NAS Security Mode Complete消息,则该NAS Security Mode Complete消息为最近接收到的N1消息,初始AMF根据当前的Kamf和接收到的NAS Security Mode Complete消息中的uplink NAS COUNT的值,生成新的Kamf;否则,注册请求RR为最近接收到的N1消息,初始AMF根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf。
初始AMF应根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF和UE之间没有激活/使用/生成/建立新的NAS安全上下文,初始AMF应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;否则,初始AMF应根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF仅接收到了一个NAS消息,并且该NAS消息为注册请求RR,初始AMF根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;否则,初始AMF根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF与UE之间没有进行NAS security mode command/control流程,初始AMF应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;否则,初始AMF根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF接收到的NAS消息只有注册请求消息RR,初始AMF应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;否则,初始AMF根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF接收到除注册请求RR外还接收到了其他NAS消息,初始AMF应根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf;否则,初始AMF应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf。其中,其他NAS消息包括NAS Security Mode Complete消息。
在一种可能的实现中,初始AMF应将生成的新的Kamf发送给目标AMF,并且初始AMF应将一个生成了新的Kamf的指示Indicator2,或一个进行了水平Kamf推演的指示发送给目标AMF;初始AMF还应将一个用于指示需要做AS key re-keying的指示发送给目 标AMF。具体地,具体地,Initial AMF在Namf_Communication_N1MessageNotify中应包括生成的新的Kamf,指示Indicator2,和用于指示需要做AS key re-keying的指示。
在一种可能的实现中,如果Initial AMF生成新的Kamf使用了当前的downlink NAS COUNT,则Initial AMF应将该downlink NAS COUNT值发送给目标AMF。具体地,Initial AMF在Namf_Communication_N1MessageNotify中应包括生成新的Kamf所使用的downlink NAS COUNT值。
在一种可能的实现中,初始AMF应将生成新的Kamf所用的uplink NAS COUNT值发送给目标AMF;或者如果初始AMF在生成新的Kamf时使用了注册请求的uplink NAS COUNT,初始AMF应将一个用于指示“使用注册请求消息的uplink NAS COUNT值生成新的Kamf”的指示Indicator3发送给目标AMF;或者如果初始AMF在生成新的Kamf时使用了NAS Security Mode Complete消息的uplink NAS COUNT,初始AMF将一个用于指示“使用NAS Security Mode Complete消息的uplink NAS COUNT值生成新的Kamf”的指示Indicator4发送给目标AMF。
在一种可能的实现中,初始AMF应发送一个指示IndicatorX给Target AMF,该指示IndicatorX用于指示“注册请求消息来自验证过的UE”,或者“UE已经通过验证”,或者“注册消息已通过验证”,或者“不需要验证UE”,或者“不需要验证注册消息”。具体地,初始AMF在Namf_Communication_N1MessageNotify消息中可选地包括IndicatorX发给目标AMF。
可选的,如果初始AMF跟UE之间建立的新的NAS安全上下文,则初始AMF应将IndicatorX发送给目标AMF。
在一种可能的实现中,目标AMF接收Kamf,目标AMF根据本地策略决定是否使用接收到的Kamf,如果决定使用接收到的Kamf,并且如果目标AMF接收到生成了新的Kamf指示或需要进行水平Kamf推演的指示,则目标AMF应将UE进行水平Kamf推演的指示发送给UE。具体的,目标AMF应设置K_AMF_change_flag(UE水平Kamf推演的指示)为1,并将其发送给UE。
可选的,如果目标AMF决定不使用接收到的新生成的Kamf,目标AMF应发起重新认证,与UE重新建立新的NAS安全上下文。
在一种可能的实现中,目标AMF还将生成新Kamf所使用的值的信息发送给UE,具体的包括以下中的一种:
如果目标AMF接收到downlink NAS COUNT值,则目标AMF应将downlink NAS COUNT值发送给UE,具体地,目标AMF应将downlink NAS COUNT值包括在NAS Container中包括downlink NAS COUNT值。
或者如果目标AMF接收到uplink NAS COUNT值,则目标AMF应将uplink NAS COUNT值发送给UE,具体地,目标AMF应将uplink NAS COUNT值包括在NAS Securtiy Mode Command消息中。
或者如果目标AMF接收到Indicator3,则目标AMF应向UE发送一个用于指示“采用注册请求消息中的uplink NAS COUNT值生成新的Kamf”的指示Indicator5,具体地目标AMF应将该Indicator5包括在NAS Security Mode Command消息中发给UE。
或者如果目标AMF接收到Indicator4,则目标AMF应向UE发送一个用于指示“采用NAS security mode complete消息中的uplink NAS COUNT值生成新的Kamf”的指示 Indicator6,具体地目标AMF应将该Indicator6包括在NAS Security Mode Command消息中发给UE。
在一种可能的实现中,如果目标AMF接收到IndicatorX,目标AMF对接收到注册请求RR不做验证,或者目标AMF不对UE做验证。
在一种可能的实现中,UE接收指示UE水平Kamf推演的指示,UE进行水平Kamf推演,生成新的Kamf。
具体的,UE接收到将K_AMF_change_flag的值为1时,确定接收到指示UE水平Kamf推演的信息。
在一种可能的实现中,UE根据指示生成新Kamf所使用的值的信息,进行水平Kamf推演,生成新的Kamf,具体的包括以下中的一种:
如果UE接收到downlink NAS COUNT值,则UE使用该downlink NAS COUNT值生成新的Kamf。
或者如果UE接收到uplink NAS COUNT值,则UE使用该uplink NAS COUNT值生成新的Kamf。
或者如果UE接收到Indicator4,则UE使用注册请求消息中的uplink NAS COUNT值生成新的Kamf。
或者如果UE接收到Indicator5,则UE使用NAS Security Mode Complete中的uplink NAS COUNT值生成新的Kamf。
否则,UE使用最近发送的N1消息中的uplink NAS COUNT的值生成新的Kamf,具体地,如果UE最近发送了NAS Security Command消息,则UE使用NAS Security Command消息中的uplink NAS COUNT值生成新的Kamf,否则UE使用发送了的注册请求消息中的uplink NAS COUNT值。
第八方面,提供了一种注册装置。本申请提供的装置具体实现上述方法方面AMF或UE行为的功能,其包括用于执行上述方法方面所描述的步骤或功能相对应的部件(means)。所述步骤或功能可以通过软件实现,或硬件(如电路)实现,或者通过硬件和软件结合来实现。
在一种可能的设计中,上述装置包括一个或多个处理器和通信单元。所述一个或多个处理器被配置为支持所述装置执行上述方法中AMF或UE相应的功能。
可选的,所述装置还可以包括一个或多个存储器,所述存储器用于与处理器耦合,其保存装置必要的程序指令和/或数据。所述一个或多个存储器可以和处理器集成在一起,也可以与处理器分离设置。本申请并不限定。
另一个可能的设计中,上述装置,包括收发器、处理器和存储器。该处理器用于控制收发器或输入/输出电路收发信号,该存储器用于存储计算机程序,该处理器用于运行该存储器中的计算机程序,使得该装置执行第一、二、三、四、五、六、七方面或第一、二、三、四、五、六、七方面中任一种可能实现方式中AMF或UE完成的方法。
在一种可能的设计中,上述装置包括一个或多个处理器和通信单元。所述一个或多个处理器被配置为支持所述装置执行上述方法中AMF或UE相应的功能。
可选的,所述装置还可以包括一个或多个存储器,所述存储器用于与处理器耦合,其保存AMF或UE必要的程序指令和/或数据。所述一个或多个存储器可以和处理器集成在一起,也可以与处理器分离设置。本申请并不限定。
所述装置可以位于AMF或UE中,或者为AMF或UE。
另一个可能的设计中,上述装置,包括收发器、处理器和存储器。该处理器用于控制收发器或输入/输出电路收发信号,该存储器用于存储计算机程序,该处理器用于运行存储器中的计算机程序,使得该装置执行第一、二、三、四、五、六、七方面或第一、二、三、四、五、六、七方面中任一种可能实现方式中AMF或UE完成的方法。
第九方面,提供了一种计算机可读存储介质,用于存储计算机程序,该计算机程序包括用于执行第一、二、三、四、五、六、七方面或第一、二、三、四、五、六、七方面中任一种可能实现方式中的方法的指令。
第十方面,提供了一种计算机程序产品,所述计算机程序产品包括:计算机程序代码,当所述计算机程序代码在计算机上运行时,使得计算机执行上述第一、二、三、四、五、六、七方面或第一、二、三、四、五、六、七方面中任一种可能实现方式中的方法。
附图说明
图1为一种5G系统UE在注册流程示意图;
图2为本申请实施例中适用的一种注册方法示意图;
图3为本申请实施例中适用的一种注册方法示意图;
图4为本申请实施例中适用的一种注册方法示意图;
图5为本申请实施例中适用的一种注册方法示意图;
图6为本申请实施例中适用的一种注册流程示意图;
图7为本申请实施例中适用的一种注册流程示意图;
图8为本申请实施例中适用的一种注册流程示意图;
图9为本申请实施例中适用的一种注册流程示意图;
图10为本申请实施例中适用的一种注册流程示意图;
图11为本申请实施例中适用的一种注册流程示意图;
图12为本申请实施例中适用的一种注册流程示意图;
图13为本申请实施例中适用的一种注册流程示意图;
图14为本申请实施例中适用的一种注册流程示意图;
图15为本申请实施例中适用的一种注册流程示意图;
图16为本申请实施例中适用的一种注册流程示意图;
图17为本申请实施例中适用的一种注册装置结构图。
具体实施方式
下面将结合附图对本发明作进一步地详细描述。
本申请实施例的技术方案可以应用于各种通信系统,例如:第四代(4th Generation,4G),4G系统包括系统长期演进(long term evolution,LTE)系统,全球互联微波接入(worldwide interoperability for microwave access,WiMAX)通信系统,未来的第五代(5th Generation,5G)系统,如新一代无线接入技术(new radio access technology,NR),及未来的通信系统,如6G系统等,只要该通信系统中存在一个实体需要发送信号,另一个实体需要接收该信号,实体可以理解为通信系统中的通信设备。
本申请将围绕可包括多个设备、组件、模块等的系统来呈现各个方面、实施例或特征。应当理解和明白的是,各个系统可以包括另外的设备、组件、模块等,并且/或者可以并不包括结合附图讨论的所有设备、组件、模块等。此外,还可以使用这些方案的组合。
另外,在本申请实施例中,“示例的”一词用于表示作例子、例证或说明。本申请中被描述为“示例”的任何实施例或设计方案不应被解释为比其它实施例或设计方案更优选或更具优势。确切而言,使用示例的一词旨在以具体方式呈现概念。
本申请实施例描述的网络架构以及业务场景是为了更加清楚的说明本申请实施例的技术方案,并不构成对于本申请实施例提供的技术方案的限定,本领域普通技术人员可知,随着网络架构的演变和新业务场景的出现,本申请实施例提供的技术方案对于类似的技术问题,同样适用。
以下对本申请实施例的部分用语进行解释说明,以便于本领域技术人员理解。
1)、AMF为核心接入与移动管理功能网元,用于管理UE的接入和移动,具体地包括:UE注册、UE移动管理、NAS连接、接入认证和授权、为UE和SMF提供传输等功能。
2)、UE为用户设备,包括全球用户识别卡(Universal Subscriber Identity Module,USIM)卡和移动设备(Mobile Equipment,ME)移动设备,发送或接收NAS和无线资源控制(Radio Resource Control,RRC)请求消息,与基站之间建立用户面隧道。
本申请中的“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。字符“/”一般表示前后关联对象是一种“或”的关系。
本申请中所涉及的多个,是指两个或两个以上。
另外,需要理解的是,在本申请的描述中,“第一”、“第二”等词汇,仅用于区分描述的目的,而不能理解为指示或暗示相对重要性,也不能理解为指示或暗示顺序。
为了便于理解本申请实施例,首先对本申请使用的应用场景进行说明。
标准3GPP TS 23.502[1]中定义了,在5G系统中UE在注册过程中发生AMF重定向的流程,以图1所示的注册流程示意图为例,详细说明本申请在注册过程中的应用场景,该注册过程包括:
步骤101:在初始注册时,UE发起携带有SUCI的注册请求Registration Request(简写为RR)。
在该步骤中UE没有NAS安全上下文,根据标准33.501[2]定义,该步骤UE发起的注册请求中只携带明文信元cleartext IEs,不包括Requested S-NSSAIs。
AMF可以根据Requested S-NSSAIs确定自身是否能够服务UE。
该Requested S-NSSAIs为请求单网片切片选择辅助信息(Single Network Slice Selection Assistance Information,NSSAI)。Allowed NSSAIs为允许NSSAIs,表示UE请求的NSSAIs中,哪些S-NSSAIs被网络允许了,网络会在注册接收消息Registration Accept或者配置更新命令Configuration Update Command中的"Allowed NSSAI"IE带给UE。
在该步骤中,UE可以将注册请求发送给(无线)接入网络((Radio)Access Network,(R)AN),(R)AN在接收到UE的注册请求之后,选择将该注册请求发送给初始AMF(Initial AMF)。
步骤102:初始AMF在接收到携带SUCI的注册请求之后,发起Primary Authentication主认证。
在该步骤中,初始AMF和UE各自生成AMF密钥,记为Kamf,以及AMF密钥对应的下一代密钥集标识符ngKSI等。
步骤103:初始AMF发起NAS安全模式命令(NAS Security Mode Command,NAS SMC),激活并开始使用主认证生成的Kamf。初始AMF在该NAS SMC中包括请求完整初始NAS消息标志位(request complete initial NAS message flag)。
UE返回NAS安全模式完成消息(NAS Security Mode Complete),激活并开始使用主认证生成的Kamf。在安全模式完成消息中包括完整初始NAS消息,即完整注册请求消息。该完整注册请求消息中包括Requested S-NSSAIs。
初始AMF和UE之间建立了NAS安全上下文,包括主认证生成的Kamf,对应的ngKSI,以及上下NAS Count,下行NAS Count等。
步骤104:初始AMF根据Requested S-NSSAIs,判断是否能够为UE服务,如果初始AMF确定不能为UE服务,初始AMF决定进行NAS reroute(AMF重定向)。
在该步骤中,初始AMF确定AMF重定向到目标Target AMF,该目标AMF为能够为UE提供服务的AMF。具体地,初始AMF可以从网络切片选择功能网元(Network Slice Selection Function,NSSF)中获取目标AMF的信息。
UE不感知AMF重定向的过程。
步骤105:初始AMF将接收到的注册请求发送给(R)AN。
在该步骤中,初始AMF发送的是在步骤1.1中接收到的携带有SUCI的注册请求。
具体地,初始AMF将携带有SUCI的注册请求消息携带在非接入层重转消息Reroute NAS Message中发送给(R)AN。
步骤106:(R)AN将接收到的注册请求发送给目标AMF。
具体地,(R)AN将携带有SUCI的注册请求消息携带初始用户设备消息在Initial UE Message中发送给目标AMF。
步骤107:目标AMF决定发起主认证(Initiates primary authentication)。
在该步骤中,目标AMF接收到注册请求中,根据该注册请求中的SUCI,发起主认证流程。
步骤108:目标AMF向鉴权服务器功能网元(Authentication Server Function,AUSF)发送用户鉴权请求(Nausf_UEAuthentication_Authenticate Request),AUSF返回用户鉴权响应(Nausf_UEAuthentication_Authenticate Response)。
步骤109:目标AMF发送认证请求(Authentication Request)给UE。
在该步骤中,由于目标AMF中没有NAS安全上下文,目标AMF给UE发送的认证请求是没有安全保护的认证请求消息。
该没有安全保护的认证请求消息为NAS消息的一种。
UE丢弃(reject)该没有安全保护的认证请求消息。
步骤110:目标AMF发送注册拒绝(Registration Reject)消息。
由于之前在步骤102和步骤103中,UE与初始AMF进行了NAS SMC,UE中已经建立并开始使用NAS安全上下文,根据标准24.501中定义,UE在建立并开始使用NAS安全上下文之后,如果接收到的NAS消息没有安全保护,则UE不会处理该NAS消息,因此UE不会处理该没有安全保护的认证请求消息,导致注册失败,UE无法接入网络。
基于上述对现有技术注册流程的描述,初始AMF与UE之间建立并激活了NAS安全 上下文,初始AMF发起了AMF重定向,定向到目标AMF,目标AMF发起主认证流程,向UE发送没有安全保护的认证请求,但是UE已经激活了NAS安全上下文,并且UE不感知AMF重定向,因此UE在对接收到的没有安全保护的认证请求不进行处理,导致在初始注册过程中当发生AMF重定向时出现UE注册失败的问题。鉴于此,为了防止初始注册过程中发生AMF重定向时UE注册失败,本申请提出了一种注册方法来避免UE丢弃接收到的目标AMF发送的认证请求。
具体地,初始AMF在UE注册过程中决定发起AMF重定向并重定向到目标AMF,初始AMF向UE发送指示信息,指示UE删除建立的NAS安全上下文,和/或去激活当前NAS安全上下文,和/或指示UE网络侧发生AMF重定向,和/或指示UE处理没有安全保护的认证请求消息,UE处理接收到的目标AMF发送的认证请求消息,返回认证响应消息,保证UE初始注册成功。或者是初始AMF将与UE之间建立的NAS安全上下文发送给目标AMF,目标AMF采用该NAS安全上下文对待发送的认证请求消息进行安全保护,然后将经过安全保护的认证请求消息发送给UE,UE确定接收到的认证请求消息为经过安全保护的认证请求消息,处理该认证请求消息,返回认证响应消息,保证UE初始注册成功;或者UE直接对接收到的目标AMF发送的认证请求消息进行处理,返回认证响应消息,保证UE初始注册成功。或者初始AMF通过RAN向目标AMF发送用于指示UE删除NAS安全上下文的指示信息、或者用于指示UE去激活当前NAS安全上文的指示信息、或者用于指示UE网络侧发生AMF重定向的指示信息、或者用于指示UE处理没有安全保护的认证请求信息的指示信息,目标AMF根据该指示信息,在认证请求消息中向UE发送用于指示UE删除NAS安全上下文的指示信息、或者用于指示UE去激活当前NAS安全上文的指示信息、或者用于指示UE网络侧发生AMF重定向的指示信息、或者用于指示UE处理没有安全保护的认证请求信息的指示信息。或者初始AMF通过RAN向目标AMF发送完整注册请求消息,目标AMF根据该完整注册请求消息,在认证请求消息中向UE发送用于指示UE删除NAS安全上下文的指示信息、或者用于指示UE去激活当前NAS安全上文的指示信息、或者用于指示UE网络侧发生AMF重定向的指示信息、或者用于指示UE处理没有安全保护的认证请求信息的指示信息。
以下述实施例详细说明UE注册的具体过程。
实施例一
首先参见图2所示的注册过程,该过程中主要是由初始AMF向UE发送指示信息,用于指示UE删除建立的NAS安全上下文、或者用于指示UE去激活当前NAS安全上下文、或者用于指示UE网络侧发生AMF重定向、或者用于指示UE处理接收到的没有安全保护的认证请求消息;UE根据该指示信息,删除NAS安全上下文,处理接收到的目标AMF发送的认证请求消息;或者UE根据该指示信息,去激活当前NAS安全上文,处理接收到的目标AMF发送的认证请求消息;或者UE根据该指示信息,处理接收到的目标AMF发送的认证请求消息,该过程包括:
步骤201:初始AMF确定进行AMF重定向,应向UE发送指示信息,用于指示UE删除或丢弃NAS安全上下文,和/或,用于指示UE去激活(deactivate)UE的当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于 指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。
初始AMF接收到UE发送的完整注册请求消息,根据该完整注册请求消息中携带的Requested S-NSSAIs,判断是否能够为UE提供服务,如果确定不能为UE提供服务,初始AMF决定发生AMF重定向。初始AMF决定发生AMF重定向时,向UE发送指示信息,该指示信息用于指示UE删除NAS安全上下文、或者指示UE去激活当前NAS安全上下文、或者指示UE网络侧发生AMF重定向、或者指示UE处理接收到的没有安全保护的认证请求消息。
具体地,初始AMF在决定进行通过(无线)接入网络((R)AN)进行AMF重定向之后,在初始AMF向(无线)接入网络((R)AN)发送非接入层NAS重转消息(NAS Reroute Message)之前,向UE发送指示信息。
初始AMF向UE发送指示信息,可包括两种选项。
选项一:
初始AMF可以向UE发送第一通知消息,该第一通知消息用于指示UE删除或丢弃NAS安全上下文,和/或,用于指示UE去激活(deactivate)UE的当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。该第一通知消息可以为新增的通知消息,例如可以为新增的NAS消息,该新增的NAS消息可以命名为AMF Reallocation Notification。
选项二:
初始AMF可以向UE发送第一NAS消息,该第一NAS消息中携带第一指示信息,该第一指示信息用于指示UE删除或丢弃NAS安全上下文,和/或,用于指示UE去激活(deactivate)UE的当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。该第一指示消息可以为新增的指示信息,例如,该第一指示信息可以命名为AMF_Reallocation_Ind。
示例的,该第一NAS消息可以为现在已有的NAS消息,例如包括但不限于以下NAS消息:配置更新命令(Configuration Update Command)、下行NAS传输(DL NAS Transport)消息、5G系统移动管理状态(5G system mobility management status,5GMM Status)和注册拒绝(Registration Reject)消息等。
可选地,初始AMF向UE发送的指示信息中还可以携带有下一代密钥集标识符(ngKSI),该ngKSI用于指示UE删除ngKSI对应的NAS安全上下文、或者用于指示UE去激活ngKSI对应的NAS安全上下文,该ngKSI为UE和初始AMF之间建立的NAS安全上下文中的ngKSI。
具体地,第一通知消息或第一NAS消息中携带有ngKSI。可选地,如果第一NAS消息中携带有ngKSI,则可以是在第一NAS消息中直接携带ngKSI,可以是在第一NAS消息的第一指示消息中携带ngKSI。
步骤202:UE接收初始AMF发送的指示信息,根据所述指示信息,应丢弃或删除NAS安全上下文,和/或,去激活UE的当前NAS安全上下文,和/或,确定不丢弃并处理接收到的没有安全保护的认证请求消息,和/或,确定网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。
与初始AMF发送指示信息对应的,如果初始AMF向UE发送第一通知消息,UE接收初始AMF发送的第一通知消息。
或者如果初始AMF向UE发送携带有第一指示信息的第一NAS消息,UE接收初始AMF发送的第一NAS消息,该第一NAS消息中携带有第一指示信息。
UE根据接收到的指示信息,丢弃或删除NAS安全上下文,和/或,去激活UE的当前NAS安全上下文,和/或,确定不丢弃并处理接收到的没有安全保护的认证请求消息,和/或,确定网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。
示例的,如果UE根据接收到的指示删除NAS安全上下文,UE根据接收到的第一通知消息,删除NAS安全上下文,或者UE根据第一NAS消息携带的第一指示信息,删除NAS安全上下文。
示例的,如果UE根据接收到的指示去激活当前NAS安全上下文,UE根据接收到的第一通知消息,去激活NAS安全上下文,或者UE根据第一NAS消息携带的第一指示信息,去激活NAS安全上下文。
示例的,如果UE根据接收到的指示确定网络侧发生AMF重定向,UE根据接收到的第一通知消息,确定网络侧发生AMF重定向,或者UE根据第一NAS消息携带的第一指示信息,确定网络侧发生AMF重定向。
示例的,如果UE根据接收到的指示确定处理接收到的没有安全保护的认证请求消息,UE根据接收到的第一通知消息,确定处理接收到的没有安全保护的认证请求消息,或者UE根据第一NAS消息携带的第一指示信息,确定处理接收到的没有安全保护的认证请求消息。
可选地,UE接收到的指示信息中还可以携带有ngKSI,该ngKSI用于指示UE删除 ngKSI对应的NAS安全上下文、或者去激活ngKSI对应的NAS安全上下文。UE删除NAS安全上下文时,根据该ngKSI,删除该ngKSI对应的NAS安全上下文,UE去激活NAS安全上下文时,根据该ngKSI,去激活该ngKSI对应的NAS安全上下文。
具体地,第一通知消息或第一NAS消息中可选地携带有ngKSI。UE根据接收到的第一通知消息或第一NAS消息中携带的ngKSI,删除该ngKSI对应的NAS安全上下文,或者去激活该ngKSI对应的NAS安全上下文。
步骤203:目标AMF向UE发送认证请求消息。
初始AMF将包括SUCI的注册请求消息发送给(R)AN,(R)AN将注册请求消息发送给目标AMF。
目标AMF根据注册请求消息中的SUCI,发起主认证流程,目标AMF向UE发送没有安全保护的认证请求消息。
步骤204:UE接收目标AMF发送的认证请求消息,处理该认证请求消息,向目标AMF发送认证响应消息。
目标AMF发送的认证请求消息是没有安全保护的。
如果UE根据初始AMF发送的指示信息,删除了NAS安全上下文或去激活了当前NAS安全上下文,则UE没有NAS安全上下文,UE处理该认证请求消息;
如果UE根据初始AMF发送的指示信息,确定处理没有安全保护的认证请求消息,则UE处理该认证请求消息。
UE向目标AMF发送没有安全保护的认证响应请求。
目标AMF可以向UE发送指示信息,指示UE删除建立的NAS安全上下文、或者指示UE去激活当前NAS安全上下文、或者指示UE网络侧发生AMF重定向、或者指示UE处理没有安全保护的认证请求信息;UE根据该指示信息,删除NAS安全上下文,处理接收到的目标AMF发送的认证请求信息;或者UE根据该指示信息,去激活当前NAS安全上下文,处理接收到的目标AMF发送的认证请求信息;或者UE根据该指示信息,处理接收到的目标AMF发送的认证请求消息,具体参见图3所示的注册流程,该过程包括:
步骤301:初始AMF向目标AMF发送第六指示信息。该第六指示信息用于指示UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。
初始AMF如果确定不能为UE提供服务,初始AMF决定发生AMF重定向。初始AMF进行AMF重定向时,通过(R)AN向目标AMF发送第六指示信息。
具体地,通过(R)AN向目标AMF发送第六指示消息时,初始AMF将第六指示信息发送给(R)AN,(R)AN将第六指示信息发送给目标AMF。
初始AMF向目标AMF发送第六指示信息,选项一:
初始AMF通过(R)AN向目标AMF发送第二通知消息。
示例的,初始AMF将该第二通知消息携带在Reroute NAS Message中发送给(R)AN,(R)AN将该第二通知消息携带在Initial UE Message发送给目标AMF。
该第二通知消息中携带第二指示信息,该第二指示信息用于指示UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。
该第二通知消息还包括携带有SUCI的注册请求消息。
该第二指示信息可以为新增的指示信息,例如该第二指示信息可以命名为AMF_Reallocation_Ind1。
可选地,该第二通知消息中还可以携带有ngKSI,该ngKSI用于指示UE删除该ngKSI对应的NAS安全上下文、或者指示UE去激活ngKSI对应的NAS安全上下文。
初始AMF向目标AMF发送第六指示信息,选项二:
初始AMF通过(R)AN将第三通知消息发送给目标AMF。
示例的,初始AMF将该第三通知消息携带在Reroute NAS Message中发送给(R)AN,(R)AN将该第三通知消息携带在Initial UE Message发送给目标AMF。
该第三通知消息中携带第四指示信息,用于指示UE验证所述第四指示信息,在验证成功后,删除NAS安全上下文,和/或,去激活当前NAS安全上下文,和/或,处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,UE删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文。所述第四指示信息,还可用于,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。
该第三通知消息还包括携带SUCI的注册请求消息。
该第四指示信息可以是初始AMF根据与UE之间的共享密钥生成的,例如该第四指示信息可以命名为Secret。示例的,该Secret包括第一参数以及第一参数的消息认证码。该第一参数可以为一个随机数,或者为UE发送给初始AMF的注册消息的UL NAS Count,或者是UE发送给初始AMF的NAS Security Complete的UL NAS Count中的一种或多种。该第一参数消息认证码是利用初始AMF根据与UE之间的共享密钥,对该第一参数计算的消息认证码。该共享密钥可以是UE和初始AMF之间通过主认证生成的Kamf,或者Kseaf,或者NAS加密密钥Knasenc,或者NAS完保密钥Knasint等中的一项或多项。
该第一参数为UE发送给初始AMF的注册消息的UL NAS Count时,该第一参数可以不携带在第三通知消息中。
可选地,该第三通知消息中还可以携带有ngKSI,该ngKSI用于指示UE删除该ngKSI 对应的NAS安全上下文、或者指示UE去激活ngKSI对应的NAS安全上下文。
初始AMF向目标AMF发送第六指示信息,选项三:
初始AMF可以通过(R)AN将完整注册请求消息发送给目标AMF。
示例的,初始AMF将该完整注册请求消息携带在Reroute NAS Message中发送给(R)AN,(R)AN将该完整注册请求消息携带在Initial UE Message发送给目标AMF。
可选地,初始AMF通过(R)AN发送ngKSI给目标AMF,该ngKSI用于指示UE删除该ngKSI对应的NAS安全上下文、或者指示UE去激活ngKSI对应的NAS安全上下文。
步骤302:目标AMF接收第六指示信息。
与初始AMF对应的,目标AMF接收第二通知消息,该第二通知消息中携带第二指示信息,该第二指示信息用于指示UE删除NAS安全上下文、或者用于指示去激活当前NAS安全上下文、或者用于指示确定网络侧发生AMF重定向、或者用于指示确定处理接收到的没有安全保护的认证请求消息;或者目标AMF接收第三通知消息,该第三通知消息中携带第四指示信息,指示UE验证该第四指示信息并删除NAS安全上下文、或者指示UE验证该第四指示信息并去激活当前NAS安全上下文、或者指示UE验证该第四指示信息并确定网络侧发生AMF重定向、或者UE验证该第四指示信息并确定处理接收到的没有安全保护的认证请求消息;或者目标AMF接收完整的注册请求消息。
步骤303:目标AMF根据第六指示信息,在向UE发送认证请求消息中包括用于指示所述UE删除NAS安全上下文的指示信息,或者包括用于指示UE去激活当前NAS安全上下文的指示信息,或者包括用于指示UE处理没有安全保护的认证请求消息的指示信息,或者包括用于指示UE网络侧发生AMF重定向的指示信息;或者包括用于指示UE恢复无NAS安全上下文的指示信息,或者包括用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文的指示信息,或者包括用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文的指示信息,或者包括用于指示UE删除或丢弃新的NAS安全上下文的指示信息,或者包括用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文的指示信息,或者包括用于指示UE使用保存的NAS安全上下文的指示信息,如果有的话。
目标AMF根据接收到的携带SUCI的注册请求发起主认证流程。
如果目标AMF接收到了第二通知消息,第二通知消息中携带第二指示信息,目标AMF根据第二指示信息,在向UE发送的认证请求中包括第三指示信息,该第三指示信息用于指示所述UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,用户指示UE使用保存的NAS安全上下文,如果有的话。
该第三指示信息可以为新增的指示信息,例如该第三指示信息可以命名为AMF_Reallocation_Ind2。该第三指示信息与第二指示信息可以相同,可以不同。
如果目标AMF接收到了第三通知消息,第三通知消息中携带第四指示信息,目标AMF根据第四指示信息,在向UE发送的认证请求中包括该第四指示信息,用于指示UE验证所述第四指示信息,验证成功之后,删除NAS安全上下文,处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理没有安全保护的认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,UE删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,用户指示UE使用保存的NAS安全上下文,如果有的话,处理认证请求消息。
如果目标AMF接收到了完整注册请求消息,目标AMF根据该完整注册请求消息,向UE发送认证请求消息,并在该认证请求消息中包括第五指示信息,该第五指示信息用于指示所述UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用户指示UE使用保存的NAS安全上下文,如果有的话。
如果目标AMF接收到的第二通知消息或第三通知消息中携带有ngKSI,或者如果目标AMF在接收到完整注册请求消息时还接收到ngKSI,目标AMF将该ngKSI携带在认证请求消息中发送给UE,该ngKSI指示UE删除或去激活该ngKSI对应的NAS上下文。
步骤304:UE根据该认证请求消息中包括的指示信息,删除NAS安全上下文,处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理没有安全保护的认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,UE删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,使用保存的NAS安全上下文,如果有的话,处理认证请求消息。
UE接收目标AMF发送的认证请求消息。
如果UE接收到的目标AMF发送的认证请求消息中携带第三指示信息,UE根据该第三指示信息,删除NAS安全上下文,处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理没有安全保护的认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,UE删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,用户指示UE使用保存的NAS安全上 下文,如果有的话,处理认证请求消息。
如果UE接收到的目标AMF发送的认证请求消息中携带第四指示信息,验证成功之后,删除NAS安全上下文,处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理没有安全保护的认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,UE删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,使用保存的NAS安全上下文,如果有的话,处理认证请求消息。
示例的,UE使用与初始AMF之间的共享密钥,对第四指示信息中的第一参数生成消息认证码,UE判断生成的消息认证码与接收到的第四指示信息中携带的消息认证码是否一致,如果一致,第四指示信息验证通过。如果不一致,第四指示信息验证不通过,UE丢弃接收到的认证请求消息。
如果UE接收到的目标AMF发送的认证请求消息中携带第五指示信息,UE根据该第五指示信息,删除NAS安全上下文,和/或,去激活当前NAS安全上下文,和/或,处理没有安全保护的认证请求信息,和/或,确定网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用户指示UE使用保存的NAS安全上下文,如果有的话。
如果UE接收到的认证请求消息中携带ngKSI,UE删除NAS安全上下文时,根据该ngKSI,删除该ngKSI对应的NAS安全上下文。
步骤305:UE处理该认证请求消息,向目标AMF发送没有安全保护的认证响应消息。
步骤306:目标AMF接收认证响应消息。
目标AMF通过向UE发送第六指示信息,解决了目标AMF和UE中保存的NAS安全上下文不一致,导致UE不处理目标AMF发送的认证请求消息,引起的注册流程失败的问题。
初始AMF可以将与UE之间建立的NAS安全上下文发送给目标AMF,目标AMF将该NAS安全上下文作为当前NAS安全上下文,目标AMF对认证请求消息进行安全保护,将经过安全保护的认证请求消息发送给UE,UE处理经过安全保护的认证请求消息,具体参见图4所示的注册过程,该过程包括:
步骤401:初始AMF确定进行AMF重定向,将与UE之间建立的NAS安全上下文发送给目标AMF。
初始AMF将与UE之间建立的NAS安全上下文发送给目标AMF。NAS安全上下文可以包括NAS Counts,NAS加密密钥和NAS完保密钥或者生成NAS加密密钥和NAS完保密钥的参数初始AMF选择的安全算法等。示例的,初始AMF将NAS安全上下文携带在Reroute NAS Message中发送给(R)AN,(R)AN将NAS安全上下文携带在Initial UE Message发送给目标AMF。
步骤402:目标AMF接收NAS安全上下文,将该NAS安全上下文作为当前NAS安 全上下文。
步骤403:目标AMF基于该NAS安全上下文,对待发送的认证请求消息进行安全保护,将经过安全保护的认证请求消息发送给UE。
如果目标AMF接收到的NAS安全上下文为NAS加密密钥和NAS完保密钥,目标AMF采用该密钥和初始AMF选择的安全算法对待发送的认证请求消息进行安全保护。
如果目标AMF接收到的NAS安全上下文为用于生成NAS加密密钥和NAS完保密钥的参数,目标AMF先生成NAS加密密钥和NAS完保密钥,再采用生成的NAS加密密钥和NAS完保密钥以及初始AMF选择的安全算法对待发送的认证请求消息进行安全保护。
步骤404:UE接收经过安全保护的认证请求消息,处理该经过安全保护的认证请求消息,向目标AMF发送认证响应消息。
UE接收到经过安全保护的认证请求消息,无论UE是否能够感知到AMF重定向,都可以对经过安全保护的认证请求消息进行处理。
步骤405:目标AMF接收认证响应消息。
初始AMF将与UE之间建立的NAS安全上下文发送给目标AMF,目标AMF可以采用NAS安全上下文对认证请求消息进行安全保护,解决了目标AMF和UE中保存的NAS安全上下文不一致,导致UE丢弃不处理目标AMF发送的认证请求消息,引起的注册流程失败的问题,避免了UE注册失败。
UE中也可以直接保存有认证请求消息的处理机制,UE能够直接处理没有安全保护的认证请求消息,而不需要网络侧的指示,具体参见图5所示的注册过程,该过程包括:
步骤501:UE与初始AMF建立NAS安全上下文。
步骤502:UE接收目标AMF发送的没有安全保护的认证请求消息。
步骤503:UE处理该没有安全保护的认证请求消息,向目标AMF返回没有安全保护的认证响应消息。
下面以五个具体的实施例对本申请实施例一的注册过程进行说明。
实施例一(1),初始AMF在进行AMF重定向之前通知UE,参见图6所示的注册流程,注册过程包括:
步骤601:UE发送携带SUCI的注册请求,RegistrationRequest,简写为RR。
RR中只包括cleartext IEs,不包括Requested S-NSSAIs。
步骤602:初始AMF发起主认证。
UE和初始AMF生成AMF密钥,记为Kamf,以及对应的密钥标识符ngKSI。
该NAS安全上下文包括AMF密钥Kamf,以及对应的ngKS。
步骤603:初始AMF发起安全模式命令,即NAS Security Mode Command(简写为NAS SMC),激活并开始使用主认证生成的Kamf。或者初始AMF发送携带第八指示信息的NAS SMC。该第八指示信息,用于指示UE保存当前使用的NAS安全上下文,如果有的话。
UE根据NAS SMC或者携带的第八指示信息,保存当前使用的NAS安全上下文,如果有的话。
UE返回NAS安全模式完成消息,即NAS Security Mode Complete,激活并开始使用Kamf。
在该NAS安全模式完成消息中,UE发送完整注册请求消息,包括Requested S-NSSAIs。
步骤604:根据Requested S-NSSAIs,初始AMF判断是否能为UE服务。当初始AMF确定不能为UE服务,初始AMF决定进行AMF重定向即reroute NAS。
步骤605:初始AMF向UE发送指示信息(如AMF Reallocation Notification),所述指示信息用于指示UE删除或丢弃NAS安全上下文,和/或,用于指示UE去激活(deactivate)UE的当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。
可选地,该指示消息携带有主认证生成的密钥Kamf的密钥标识符ngKSI,用于指示UE删除ngKSI对应的NAS安全上下文。
在一种可能的实现中,初始AMF发送指示信息包括:
所述初始AMF向所述UE发送第一通知消息,所述第一通知消息用于指示所述UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求消息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文。第一通知消息为新增NAS消息,或称为AMF Reallocation Notification消息。可选地,该AMF Reallocation Notification消息携带有主认证生成的密钥Kamf的密钥标识符ngKSI,用于指示UE删除ngKSI对应的NAS安全上下文。
在另一种可能的实现中,初始AMF发送的指示信息包括:
所述初始AMF向UE发送第一NAS消息,其中所述第一NAS消息中携带第一指示信息,所述第一指示信息用于指示所述UE删除NAS安全上下文,和/或,指示UE去激活当前NAS安全上下文,和/或,指示UE处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文。本申请中不对携带所述第一指示信息的第一NAS消息做限制,NAS消息可能的选项有配置更新命令(configuration update command)消息、下行NAS传输(downlink NAS transport)消息、5G系统移动管理状态(5G system mobility management status,5GMM Status)和注册拒绝(registration reject)消息等。可选地,第一NAS消息中携带有主认证生成的密钥Kamf的密钥标识符ngKSI,用于指示UE删除ngKSI对应的NAS安全上下文。
UE在接收到该指示信息,包括第一通知消息或携带第一指示信息的第一NAS消息,之后,应,丢弃或删除NAS安全上下文,和/或,去激活UE的当前NAS安全上下文,和 /或,确定不丢弃并处理接收到的没有安全保护的认证请求消息,和/或,确定网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文。如果UE接收到的指示信息中携带ngKSI,则UE删除ngKSI对应的NAS安全上下文。具体地,UE在接收到该第一通知消息,或称为AMF Reallocation Notification消息,之后,如果该第一通知消息(或称为AMF Reallocation Notification消息)中携带ngKSI,则UE删除ngKSI对应的NAS安全上下文;或者UE在接收到携带第一指示信息的第一NAS消息之后,如果该第一NAS消息中携带ngKSI,则UE删除ngKSI对应的NAS安全上下文。
步骤606:初始AMF进行NAS reroute,即AMF重定向。初始AMF将携带有SUCI的注册请求消息携带在Reroute NAS Message中发送给(R)AN。
步骤607:(R)AN将该携带有SUCI的注册请求消息携带在Initial UE Message发送给目标AMF。
步骤608:目标AMF发起主认证,向AUSF发送Nausf_UEAuthentication_Authenticate Request,AUSF返回Nausf_UEAuthentication_Authenticate Response。
步骤609:目标AMF向UE发送认证请求Authentication Request(也简称为Auth.Request)消息。
该认证请求消息为没有安全保护的认证请求消息。
步骤610:UE处理(calculate)Authentication Request消息。
步骤611:UE返回认证响应Authentication Response消息给目标AMF。
该认证响应消息为没有安全保护的认证响应消息。
实施例一(2),初始AMF通知目标AMF,发生了AMF重定向。目标AMF在authentication request消息中,增加指示,通知UE网络侧发生了AMF重定向,并指示UE删除AMF重定向之前建立并激活的NAS安全上下文,参见图7所示的注册流程,注册过程包括:
步骤701至步骤704的实现过程同上述图6所示步骤601至步骤604,这里不再赘述。
步骤705:初始AMF将第二指示信息,或称为AMF_Reallocation_Ind1,携带在Reroute NAS Message中发送给(R)AN,该第二指示信息,或称为AMF_Reallocation_Ind1,用于指示UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示,和/或,指示UE使用保存的NAS安全上下文,如果有的话。
可选地,NAS Reroute Message中可以携带ngKSI,该ngKSI用于指示UE删除ngKSI对应的NAS安全上下文。
步骤706:(R)AN将该第二指示信息,即AMF_Reallocation_Ind1,携带在Initial UE Message发送给目标AMF。
可选地,Initial UE Message中可以携带ngKSI。
步骤707:目标AMF发起主认证,向AUSF发送Nausf_UEAuthentication_Authenticate Request,AUSF返回Nausf_UEAuthentication_Authenticate Response。
步骤708:目标AMF向UE发送认证请求Authentication Request消息。如果目标AMF在之前的Initial UE message中接收到第二指示信息,或称为AMF_Reallocation_Ind1指示,则目标AMF在Authentication Request消息中新增指示,即第三指示信息,或称为AMF_Reallocation_Ind2指示,用于通知UE网络侧发生AMF Reallocation,和/或,指示UE删除之前激活的NAS安全上下文,和/或,用于指示所述UE删除NAS安全上下文,和/或,用于指示UE去激活当前NAS安全上下文,和/或,用于指示UE处理没有安全保护的认证请求信息,和/或,用于指示UE网络侧发生AMF重定向,和/或,用于指示UE恢复无NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,用于指示UE删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,用于指示UE删除或丢弃所述新的NAS安全上下文,和/或,用于指示UE去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示UE使用保存的NAS安全上下文,如果有的话。
可选地,如果目标AMF在之前的Initial UE message中接收到ngKSI,则目标AMF在Authentication Request消息中携带ngKSI,该ngKSI用于指示UE删除ngKSI对应的ngKSI。
步骤709:UE接收到Authentication Request消息之后,如果该消息携带第三指示信息,或称为AMF_Reallocation_Ind2,则UE应,删除NAS安全上下文,处理认证请求消息,或者去激活当前NAS安全上下文,处理认证请求消息,或者处理没有安全保护的认证请求消息,或者确定网络侧发生AMF重定向,处理认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,恢复使用保存的NAS安全上下文,如果有的话。
可选地,如果该消息中有ngKSI,则UE删除ngKSI对应的NAS安全上下文;如果该消息中没有ngKSI,则UE找到之前主认证建立的,并激活的NAS安全上下文,将其删除。
或者,UE在接收到AMF_Reallocation_Ind2之后,UE跳过对Authentication Request进行安全保护验证以及解密的过程,直接处理接收到的Authentication Request消息。
步骤710:UE返回认证响应Authentication Response消息给目标AMF。
实施例一(3),初始AMF通知目标AMF,发生了AMF重定向。目标AMF在authentication request消息中,增加指示,通知UE网络侧发生了AMF重定向,并指示UE进行指示验证,删除AMF重定向之前建立并激活的NAS安全上下文,参见图8所示的注册流程,注册过程包括:
步骤801至步骤804的实现过程同上述图6所示步骤601至步骤604,这里不再赘述。
步骤805:初始AMF将新增指示,即第四指示信息,或称为Secret,携带在Reroute NAS  Message中发送给(R)AN,第四指示信息,或称为Secret,用于指示UE验证所述第四指示信息,验证成功后,UE应删除NAS安全上下文、和/或,去激活当前NAS安全上下文,和/或,处理没有安全保护的认证请求消息,和/或,指示UE网络侧发生AMF重定向,和/或,恢复无NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,和/或,UE删除或丢弃所述新的NAS安全上下文,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,和/或,用于指示所述UE恢复使用保存的NAS安全上下文,如果有的话。第四指示信息,还可用于,通知所述目标AMF发生AMF重定向,和/或,指示所述目标AMF向UE发送指示。
NAS Reroute Message中还携带了携带有SUCI的注册请求消息。
Secret中的参数包括:
1)新鲜参数。可以是一个随机数,或UE发送给初始AMF的注册消息的UL NAS Count,或UE发送给初始AMF的NAS Security Complete的UL NAS Count以及以上选项中的一种或几种。新鲜参数的目的是防止重放攻击。
如果新鲜参数为UE发送给初始AMF的注册消息的UL NAS Count,则Secret中可不携带新鲜参数。
2)UE和初始AMF之间建立的NAS安全上下文中的ngKSI,ngKSI用于指示UE删除ngKSI对应的NAS安全上下文。Secret中可不携带该ngKSI参数。
3)消息认证码MAC。该MAC为初始AMF使用UE和初始AMF之间的共享密钥对1)和/或2)中参数进行计算生成的,即对新鲜参数和/或ngKSI参数计算生成的。MAC用于证明Secret的真实性,防止攻击者的消息仿冒攻击。
可选地,该共享密钥,可以是UE和初始AMF之间通过主认证生成的Kamf,或者Kseaf,或者NAS加密密钥Knasenc,或者NAS完保密钥Knasint。
步骤806:(R)AN向目标AMF发送携带有第四指示信息(或称为Secret)的Initial UE message。
Initial UE message中还携带了携带有SUCI的注册请求消息。
步骤807:目标AMF发起主认证,向AUSF发送Nausf_UEAuthentication_Authenticate Request,AUSF返回Nausf_UEAuthentication_Authenticate Response。
步骤808:目标AMF向UE发送认证请求Authentication Request消息。该Authentication Request消息中携带有接收到的第四指示信息,或称为Secret。
步骤809:UE接收到Authentication Request消息之后,如果该Authentication Request消息携带第四指示信息,或称为Secret,则UE应验证所述第四指示信息,或称为Secret,验证成功之后,应删除NAS安全上下文,处理认证请求消息,和/或,去激活当前NAS安全上下文,处理认证请求消息,和/或,处理没有安全保护的认证请求消息,和/或,恢复无NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的新的NAS安全上下文,处理认证请求消息,和/或,删除或丢弃所述UE和所述初始AMF建立的NAS安全上下文,处理认证请求消息,和/或,UE删除或丢弃所述新的NAS安全上下文,处理认证请求消息,和/或,去激活(deactivate)所述UE和所述初始AMF建立的当前NAS安全上下文,处理认证请求消息,和/或,恢复使用保存的NAS安全上下文,如果有的话,处理认证请求消息。
UE在删除的NAS安全上下文时,如果Secret中有ngKSI,则UE删除ngKSI对应的NAS安全上下文,如果Secret中没有ngKSI,则UE删除主认证生成的,并激活的NAS上下文。然后UE处理authentication Request消息;或者UE直接处理没有保护的Authentication Request消息。
步骤810:UE返回认证响应Authentication Response消息给目标AMF。
实施例一(4),初始AMF将NAS安全上下文发送目标AMF,保持目标AMF与UE之间的NAS安全上下文一致,参见图9所示的注册流程,注册过程包括:
步骤901至步骤904的实现过程同上述图6所示步骤601至步骤604,这里不再赘述。
步骤9.5:初始AMF在NAS Reroute Message中新增NAS安全上下文,包括NAS Keys(包括NAS加密密钥Knasint,以及NAS完保密钥Knasint),和/或,生成NAS Keys需要的参数(比如Kamf和选择的安全算法),和/或,安全算法,和/或,NAS Counts等发送给(R)AN。
初始AMF在Reroute NAS Message中还可以新增NAS counts。NAS Counts用于同步初始AMF和目标AMF的NAS Counts。
步骤906:(R)AN向目标AMF发送Initial UE message,该消息中携带NAS安全上下文,包括NAS keys或者生产NAS keys的参数,和/或,安全算法等。
Initial UE Message中还可以携带NAS Counts。
步骤907:目标AMF保存接收到的NAS安全上下文。目标AMF发起主认证,向AUSF发送Nausf_UEAuthentication_Authenticate Request,AUSF返回Nausf_UEAuthentication_Authenticate Response。
目标AMF如果接收到NAS counts,采用接收到的NAS counts对自身保存的NAS counts进行更新。
步骤908:目标AMF在向UE发送认证请求Authentication Request消息之前,根据接收到的NAS安全上下文(如Knasenc和Kansint),保护认证请求Authentication Request消息。
可选地,Authentication Request消息还可以目标AMF更新后的NAS count。
步骤909:目标AMF发送经过安全保护的Authentication Request消息给UE。
UE处理该经过安全保护的Authentication Request消息。
步骤910:UE返回认证响应Authentication Response消息给目标AMF。
实施例一(5),初始AMF将完整的注册请求消息发送目标AMF,目标AMF确定发生了AMF重定向,并指示UE处理接收到的认证请求消息,参见图10所示的注册流程,注册过程包括:
步骤1001至步骤1005的实现过程同上述图6所示步骤601至步骤604,这里不再赘述。
步骤1006:初始AMF在Reroute NAS Message中携带完整的注册请求消息(如complete initial NAS message),发送给(R)AN。
该完整的注册请求消息是初始AMF从步骤1004中获取到的。
步骤1007:(R)AN在Initial UE Message中携带完整的注册请求消息发送给目标AMF。
步骤1008:目标AMF发起主认证,向AUSF发送Nausf_UEAuthentication_Authenticate Request,AUSF返回Nausf_UEAuthentication_Authenticate Response。
目标AMF根据完整的注册请求消息确定发生了AMF重定向(determines AMF reallocation has occured)。
步骤1009:目标AMF将指示信息indicator携带在认证请求Authentication Request消息中发送给UE,该指示信息indicator用于指示UE网络侧发生了AMF重定向,或者指示UE处理接收到认证请求。
UE根据该指示信息indicator,处理接收到的认证请求消息。
步骤1010:UE返回认证响应Authentication Response消息给目标AMF。
实施例二
初始AMF在UE的注册过程中决定发起通过(R)AN的AMF重定向或通过(R)AN的NAS Reroute,并决定重定向到目标AMF,初始AMF应请求目标AMF为UE分配一个新的5G-GUTI(5G Globally Unique TemporaryUE Identity,5G网络中UE的全球唯一临时标识),或初始AMF给UE分配一个新的5G-GUTI,或者初始AMF应请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI或者初始AMF为UE分配一个用于AMF重定向的特殊的新的5G-GUTI,初始AMF应将新的5G-GUTI发送给UE,初始AMF应发起去注册流程或者注册拒绝消息,指示UE进行重注册,以及初始AMF应可选地发起RRC链接释放,UE应根据指示,进行重选注册,UE应向目标AMF发起携带有新的5G-GUTI的注册请求消息RR。在该实施例中初始AMF应跳过图1中步骤105和步骤106所示的通过(R)AN的NAS reroute的步骤,即跳过了初始AMF将接收到的注册请求发送给(R)AN,(R)AN将注册请求发送给目标AMF的过程。
参见图11所示的注册过程,注册过程包括:
步骤1101:初始AMF决定发起通过(RAN)的重定向到目标AMF或通过(RAN)的NAS reroute到目标AMF,初始AMF应跳过通过(R)AN的NAS reroute流程,初始AMF应请求目标AMF为UE分配一个新的5G-GUTI,(见下面方式一的描述),或者初始AMF应为UE分配一个新的5G-GUTI,(见下面方式二描述),或者初始AMF应请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI,(见下面方式三描述)或者初始AMF应为UE分配一个用于AMF重定向的特殊的新的5G-GUTI(见下面方式四描述)。
方式一:
初始AMF应向目标AMF发送请求为UE分配新的5G-GUTI的信息,目标AMF应为UE分配一个新的5G-GUTI,目标AMF应将携带有新的5G-GUTI的消息发送给初始AMF。
可选的,初始AMF应在向目标AMF发送的请求分配新的5G-GUTI的信息中包括初始SUCI,该SUCI为初始AMF接收到的注册请求消息中携带的SUCI。
可选的,目标AMF通过(R)AN将携带有新的5G-GUTI的消息发送给初始AMF,即目标AMF将携带有新的5G-GUTI的消息发送给(R)AN,(R)AN将携带有新的5G-GUTI的消息发送给初始AMF。
目标AMF分配一个新的5G-GUTI后,对该新的5G-GUTI做标记,如标记该新的5G-GUTI为AMF重定向场景中使用的5G-GUTI,和/或标记该新的5G-GUTI是为UE分配的新的5G-GUTI。
示例的,初始AMF请求目标AMF分配一个新的5G-GUTI。
可选的,初始AMF将用于请求分配一个新的5G-GUTI的信息发送给目标AMF。
又一示例的,初始AMF将接收到的注册请求中携带的SUCI发送给目标AMF。
可选的,初始AMF通过(R)AN向目标AMF发送SUCI,即初始AMF将SUCI发送给(R)AN,(R)AN将SUCI发送给目标AMF。
其中,该SUCI可以携带在消息中,对携带有SUCI的消息不做限定。
可选的,目标AMF在接收到初始AMF发送的SUCI后,可以存储该SUCI,建立该SUCI与新的5G-GUTI的对应关系。
另一示例的,初始AMF通知目标AMF发生AMF重定向。
可选的,初始AMF通过(R)AN向目标AMF发送用于通知目标AMF发生AMF重定向的指示信息或消息,即初始AMF将用于通知目标AMF发生AMF重定向的指示信息或消息发送给(R)AN,(R)AN将用于通知目标AMF发生重定向的指示信息发送给目标AMF。
其中,该用于通知目标AMF发生AMF重定向的指示信息可以携带在消息中。
方式二:
初始AMF为UE分配一个新的5G-GUTI。
初始AMF分配一个新的5G-GUTI后,对UE进行标记或者对该新的5G-GUTI做标记,如标记该新的5G-GUTI为AMF重定向场景中使用的5G-GUTI,和/或标记该新的5G-GUTI是为UE分配的新的5G-GUTI。
可选的,初始AMF中保存有目标AMF的信息。
方式三:
AMF应请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI,目标AMF应为UE分配一个用于AMF重定向的特殊的新的5G-GUTI,目标AMF应将携带有用于AMF重定向的特殊的新的5G-GUTI的消息发送给初始AMF。
目标AMF分配用于AMF重定向的特殊的新的5G-GUTI后,无需标记该5G-GUTI。
可选的,目标AMF通过(R)AN将携带有用于AMF重定向的特殊的新的5G-GUTI的消息发送给初始AMF,即目标AMF将携带有用于AMF重定向的特殊的新的5G-GUTI发送给(R)AN,(R)AN将携带有用于AMF重定向的特殊的新的5G-GUTI发送给初始AMF。
示例的,初始AMF请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI。
可选的,初始AMF将用于请求分配一个用于AMF重定向的特殊的新的5G-GUTI的信息发送给目标AMF。
又一示例的,初始AMF将接收到的注册请求中携带的SUCI发送给目标AMF。
可选的,初始AMF通过(R)AN向目标AMF发送SUCI,即初始AMF将SUCI发送给(R)AN,(R)AN将SUCI发送给目标AMF。
其中,该SUCI可以携带在消息中,对携带有SUCI的消息不做限定。
可选的,目标AMF在接收到初始AMF发送的SUCI后,可以存储该SUCI,建立该SUCI与用于AMF重定向的特殊的新的5G-GUTI的对应关系。
另一示例的,初始AMF通知目标AMF发生AMF重定向。
可选的,初始AMF通过(R)AN向目标AMF发送用于通知目标AMF发生AMF重定向的指示信息或消息,即初始AMF将用于通知目标AMF发生AMF重定向的指示信息或消息发送给(R)AN,(R)AN将用于通知目标AMF发生重定向的指示信息发送给目 标AMF。
其中,该用于通知目标AMF发生AMF重定向的指示信息可以携带在消息中。
方式四:
初始AMF应为UE分配一个用于AMF重定向的特殊的新的5G-GUTI。
初始AMF分配用于AMF重定向的特殊的新的5G-GUTI后,无需标记该5G-GUTI。
可选的,初始AMF中保存有目标AMF的信息。
步骤1102:初始AMF应将第二消息发送给UE,第二消息中应携带为该UE分配的新的5G-GUTI。
可选的,该第二消息为注册接受(Registration Accept)消息或为配置更新命令(Configuration Update Command)。
步骤1103:初始AMF发起去注册流程或者注册拒绝消息,并指示UE进行重注册。
如果第二消息为注册接受消息,初始AMF发送去注册流程;如果第二消息为配置更新命令,初始AMF发送注册拒绝消息。
步骤1104:可选地,初始AMF发起RRC链接释放。
步骤1105:UE重新发起注册请求,注册请求消息RR中应携带有新的5G-GUTI。
在上述步骤1101的方式一中,(R)AN将携带有新的5G-GUTI的RR发送给目标AMF。
在上述步骤1101的方式二中,(R)AN将携带有新的5G-GUTI的RR发送给初始AMF,初始AMF检查RR中携带的5G-GUTI,如果初始AMF在本地对5G-GUTI有标注,和/或如果初始AMF确定该5G-GUTI为AMF重定向场景中使用的5G-GUTI,初始AMF应发起通过(R)AN的NAS reroute流程,通过(R)AN将RR发送给目标AMF。
在上述步骤1101的方式三中,(R)AN将携带有用于AMF重定向的特殊的新的5G-GUTI的RR发送给目标AMF。
在上述步骤1101的方式四中,(R)AN将携带有用于AMF重定向的特殊的新的5G-GUTI的RR发送给初始AMF,初始AMF检查RR中携带的用于AMF重定向的特殊的新的5G-GUTI,初始AMF应发起通过(R)AN的NAS reroute流程,通过(R)AN将RR发送给目标AMF。
可选的,初始AMF将RR中携带的SUCI发送给目标AMF。
步骤1106:目标AMF接收注册请求RR,检查RR中携带的5G-GUTI。
在上述步骤1101的方式一中,如果目标AMF在本地对5G-GUTI有标注,目标AMF应发起身份请求流程获取UE的SUCI,进行主认证,以实现UE的成功注册。
或者,如果目标AMF在本地对5G-GUTI有标注,目标AMF查找SUCI与5G-GUTI的对应关系,进行主认证,以实现UE的成功注册。
在上述步骤1101的方式二和四中,如果目标AMF之前接收到SUCI,发起主认证,以实现UE的成功注册。
或者,如果目标AMF未接收到SCUI,目标AMF发起身份请求流程获取UE的SUCI,进行主认证,以实现UE的成功注册。
在上述步骤1101的方式三中,如果目标AMF确定该5G-GUTI为AMF重定向场景中使用的5G-GUTI,目标AMF应发起身份请求流程获取UE的SUCI,进行主认证,以实现UE的成功注册。
或者,如果目标AMF确定该5G-GUTI为AMF重定向场景中使用的5G-GUTI,目标 AMF查找SUCI与5G-GUTI的对应关系,进行主认证,以实现UE的成功注册。
下面以两个具体的实施例对本申请实施例二的注册过程进行说明。
实施例二(1),初始AMF应向目标AMF发送请求为UE分配一个新的5G-GUTI的信息,或者初始AMF应请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI,目标AMF为UE分配一个新的5G-GUTI,或者目标AMF为UE分配一个用于AMF重定向的特殊的新的5G-GUTI,参见图12所示的注册流程,注册过程包括:
步骤1201至步骤1204的实现过程同上述图1所示步骤101至步骤103,这里不再赘述。
可选的,注册请求消息RR中携带有SUCI。
步骤1205:初始AMF应根据Requested S-NSSAIs,判断是否能够为UE服务,如果初始AMF确定不能为UE服务,初始AMF决定需要进行通过(R)AN的NAS reroute(decides to reroute NAS via(R)AN is needed),初始AMF应跳过(R)AN的NAS reroute(skip NAS reroute via(R)AN)。
步骤1206初始AMF应通过(R)AN向目标AMF请求一个新的5G-GUTI(requesets a new 5G-GUTI from Target AMF),或者初始AMF应通过(R)AN向目标AMF请求一个用于AMF重定向的特殊的新的5G-GUTI。
该步骤的实现过程可以参见上述图11中步骤1101中的方式一或方式三,这里不再指数。
步骤1207:目标AMF应分配一个新的5G-GUTI(allocate a new 5G-GUTI),或者目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI,目标AMF应通过(R)AN向初始AMF发送携带有新的5G-GUTI的消息,或者目标AMF应通过(R)AN向初始AMF发送携带有用于AMF重定向的特殊的新的5G-GUTI的消息。
步骤1208:初始AMF应在注册接收消息Registration Accept中携带新的5G-GUTI发送给UE,或者初始AMF应在Registration Accept中携带用于AMF重定向的特殊的新的5G-GUTI发送给UE。
或者初始AMF可以在配置更新命令(Configuration Update Command)中携带新的5G-GUTI发送给UE,或者在配置更新命令中携带用于AMF重定向的特殊的新的5G-GUTI发送给UE。
步骤1209:初始AMF应发起去注册流程(de-regiatration procedure),并指示UE进行重注册。
或者初始AMF可以发送注册拒绝消息给UE,并指示UE进行重注册。
步骤1210:可选的,初始AMF发起RRC链接释放(如N2RRC Release)。
步骤1211:UE应发送注册请求消息RR给目标AMF,RR中携带有新的5G-GUTI。
步骤1212:目标AMF接收RR,应检查RR中携带的5G-GUTI。
如果目标AMF在本地对5G-GUTI有标注,或者如果目标AMF确定该5G-GUTI为AMF重定向场景中使用的5G-GUTI,目标AMF发起身份请求流程获取UE的SUCI,进行主认证,以实现UE的成功注册。
或者,如果目标AMF在本地对5G-GUTI有标注,或者如果目标AMF确定该5G-GUTI为AMF重定向场景中使用的5G-GUTI,目标AMF查找SUCI与5G-GUTI的对应关系,进行主认证,以实现UE的成功注册。
实施例二(2),初始AMF应为UE分配一个新的5G-GUTI,或者初始AMF应为UE分配一个用于AMF重定向的特殊的新的5G-GUTI,参见图13所示的注册流程,注册过程包括:
步骤1301至步骤1304的实现过程同上述图12所示步骤1201至步骤1204,这里不再赘述。
可选的,注册请求消息RR中携带有SUCI。
步骤1305:初始AMF应根据Requested S-NSSAIs,判断是否能够为UE服务,如果初始AMF确定不能为UE服务,初始AMF决定需要进行通过(RAN)的NAS reroute(decides to reroute NAS via(R)AN is needed),初始AMF应跳过(R)AN的NAS reroute。初始AMF应分配一个新的5G-GUTI,对UE进行标记(assign a new 5G-GUTI,and flag theUE),或者初始AMF应分配一个用于AMF重定向的特殊的新的5G-GUTI。
步骤1306:初始AMF在注册接收消息Registration Accept中携带新的5G-GUTI发送给UE,或者初始AMF应在Registration Accept中携带用于AMF重定向的特殊的新的5G-GUTI发送给UE。
或者初始AMF可以在配置更新命令(Configuration Update Command)中携带新的5G-GUTI发送给UE,或者在配置更新命令中携带用于AMF重定向的特殊的新的5G-GUTI发送给UE。
步骤1307:初始AMF发起去注册流程(de-regiatration procedure),并指示UE进行重注册。
或者初始AMF可以发送注册拒绝消息给UE,并指示UE进行重注册。
步骤1308:可选的,初始AMF发起RRC链接释放(如N2RRC Release)。
步骤1309:UE应将携带有5G-GUTI的RR发送给初始AMF。
步骤1310:初始AMF检查RR中携带的5G-GUTI,如果初始AMF在本地对5G-GUTI有标注,或者如果初始AMF确定该5G-GUTI为AMF重定向场景中使用的5G-GUTI,初始AMF应发起通过(RAN)的NAS reroute流程(perform NAS reroute)。
步骤1311:初始AMF应通过(R)AN将RR发送给目标AMF。
其中,RR中携带有5G-GUTI。
可选的,初始AMF将RR中携带的SUCI发送给目标AMF。
步骤1312:目标AMF接收RR,应检查RR中携带的5G-GUTI。
如果目标AMF跟5G-GUTI指向的AMF(在图13中为初始AMF)之间没有直接连接,则:
如果目标AMF之前接收到SUCI,发起主认证,以实现UE的成功注册。
或者,如果目标AMF未接收到SUCI,目标AMF发起身份请求流程获取UE的SUCI,进行主认证,以实现UE的成功注册。
实施例三
UE在注册请求RR中可选地携带指示Indicator 1,初始AMF在决定进行NAS reroute时,根据RR中是否携带指示Indicator 1,执行不同的步骤,从而实现UE的成功注册。
实施例三(1),UE在注册请求RR中可选地携带指示Indicator 1。
示例的,该指示Indicator 1用于指示:
UE为非15版本的UE;和/或
UE为16版本或16版本之后的UE;和/或
UE支持16版本及以后的能力;和/或
UE支持通过(R)AN进行NAS reroute的能力;和/或
UE支持通过(R)AN进行AMF重定向的能力;和/或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)NAS安全上下文回退的能力;和/或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)(恢复)使用老的NAS安全上下文的能力;和/或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)删除新的NAS安全上下文的能力;和/或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)持恢复到无NAS安全上下文的能力;和/或
UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)进行NAS reroute中NAS安全上下文处理的能力。
如图14所示的注册过程,注册过程包括:
步骤1401:UE向初始AMF发送注册请求RR,RR中携带有5G-GUTI。
可选的,RR中携带有Indicator 1,或者RR中不携带Indicator 1。
步骤1402的实现过程同图1中步骤102至步骤103,这里不再赘述。
步骤1403:初始AMF判断是否能够为UE服务,如果初始AMF确定不能为UE服务,初始AMF应决定进行通过(R)AN的NAS reroute(或通过(R)AN的AMF重定向):
如果初始AMF没有接收到指示Indicator 1,或者初始AMF根据注册请求消息,
判断UE为版本15的UE;和/或
判断UE为非16版本或16版本之后的UE,和/或
判断UE不支持16版本及以后的能力;和/或
判断UE不支持通过(R)AN进行NAS reroute的能力;和/或
判断UE不支持通过(R)AN进行AMF重定向的能力;和/或
判断不UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)NAS安全上下文回退的能力;和/或
判断UE不支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)(恢复)使用老的NAS安全上下文的能力;和/或
判断UE不支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)删除新的NAS安全上下文的能力;和/或
判断UE不支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)持恢复到无NAS安全上下文的能力;和/或
判断UE不支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)进行NAS reroute中NAS安全上下文处理的能力。
则初始AMF可以进行如下过程中的一种:
a1,初始AMF应进行直接NAS reroute或初始AMF应直接将注册请求消息转发目标AMF,即初始AMF调用Target AMF提供的Namf_Communication_N1MessageNotify服务 操作。Namf_Communication_N1MessageNotify服务操作中,应包括接全部的注册请求消息和UE的上下文,如果有的话。详细过程可以参见TS 23.502中章节4.2.2.2.3中定义的步骤7(A)。
a2,初始AMF应向目标AMF发送请求为UE分配一个新的5G-GUTI的信息,或者初始AMF应请求目标AMF分配一个用于AMF重定向的特殊的新的5G-GUTI。详细过程可以参见上述实施例二(1)所示的过程,这里不做赘述。
a3,初始AMF应为UE分配一个新的5G-GUTI,或者初始AMF应为UE分配一个用于AMF重定向的特殊的新的5G-GUTI。详细过程可以参见上述实施例二(2)所示的过程,这里不做赘述。
如果初始AMF接收到指示Indicator 1,或初始AMF根据注册请求消息,
判断UE为非版本15的UE;和/或
判断UE为16版本或16版本之后的UE,和/或
判断UE支持16版本及以后的能力;和/或
判断UE支持通过(R)AN进行NAS reroute的能力;和/或
判断UE支持通过(R)AN进行AMF重定向的能力;和/或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)NAS安全上下文回退的能力;和/或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)(恢复)使用老的NAS安全上下文的能力;和/或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)删除新的NAS安全上下文的能力;和/或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)持恢复到无NAS安全上下文的能力;和/或
判断UE支持(通过(RAN)进行NAS reroute中/通过(RAN)进行AMF重定向中)进行NAS reroute中NAS安全上下文处理的能力。
初始AMF应根据本地策略和订阅信息决定是进行直接NAS reroute(即初始AMF直接将注册请求消息发送给目标AMF)还是通过(R)AN的NAS reroute(即初始AMF通过(R)AN将注册请求消息发给目标AMF)。初始AMF如果根据本地策略和订阅信息决定进行直接NAS reroute或初始AMF如果根据本地策略和订阅信息决定直接将注册请求消息转发目标AMF,则初始AMF调用Target AMF提供的Namf_Communication_N1MessageNotify服务操作。Namf_Communication_N1MessageNotify服务操作中,应包括接全部的注册请求消息和UE的上下文,如果有的话。详细过程可以参见TS 23.502中章节4.2.2.2.3中定义的步骤7(A)。
初始AMF如果根据本地策略和订阅信息决定进行通过(R)AN的NAS reroute(或通过(R)AN将注册请求消息发送给目标AMF),则初始AMF可进行如下过程中的一种:
b1,初始AMF应通知UE发送AMF重定向,或初始AMF应指示UE删除NAS安全上下文,或初始AMF应返回到发送注册请求时的安全,或初始AMF应指示UE接收并处理没有保护的认证请求消息等,即执行上述实施例一(1)所示的过程,这里不做赘述。
b2,初始AMF应通知目标AMF发生AMF重定向,即执行上述实施例一(2)所示的过程,这里不做赘述。
b3,初始AMF应通知目标AMF发生AMF重定向等,即执行上述实施例一(3)所示的过程,这里不做赘述。
b4,初始AMF应将NAS安全上下文发送给目标AMF,即执行上述实施例一(4)所示的过程,这里不做赘述。
b5,初始AMF应将完整的注册请求消息发送给目标AMF,即执行上述实施例一(5)所示的过程,这里不做赘述。
其中,初始AMF进行通过(R)AN的NAS reroute的详细过程可以参见TS 23.502中章节4.2.2.2.3中定义的步骤7(B)。
实施例四
初始AMF在UE的注册过程中根据本地策略决定发起AMF重定向,初始AMF决定进行直接NAS Reroute,即将注册请求(或NAS消息)直接发送到目标AMF时,初始AMF应将当前的NAS安全上下文发送给目标AMF,使目标AMF采用NAS安全上下文保护认证请求发送给UE,实现UE的成功注册(具体参见上述实施例一(4)),或者初始AMF应根据本地策略决定是否进行水平Kamf推演,生成新的Kamf,将新生成的Kamf发送给目标AMF,并且UE生成新的Kamf,从而保证目标AMF和UE两侧的NAS安全上下文一致,从而实现UE的成功注册。
参见图15所示的注册过程,注册过程包括:
步骤1501:初始AMF根据本地策略决定进行直接NAS Reroute(即重定向),或者初始AMF根据本地策略决定将注册请求(或NAS消息)直接发送到目标AMF,则初始AMF应将当前的NAS安全上下文发送给目标AMF,或者初始AMF根据本地策略决定是否进行水平Kamf推演,如果决定进行水平Kamf推演,初始AMF生成一个新的Kamf,将新生成的Kamf发送给目标AMF,如果决定不进行水平Kamf推演,初始AMF将当前的NAS安全上下文(图1步骤102中生成的NAS安全上下文)发送给目标AMF。
具体的,初始AMF应将新生成的Kamf或者当前的NAS安全上下文携带在Namf_Communication_N1MessageNotify消息中发送给目标AMF。
示例的,初始AMF进行水平Kamf推演,生成一个新的Kamf包括以下中的一种:
初始AMF应根据当前的Kamf(图1步骤102中生成的Kamf)及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf。
初始AMF应根据当前的Kamf和接收到的NAS Security Mode Complete消息中的uplink NAS COUNT的值,生成新的Kamf。
初始AMF应根据当前的Kamf和最近接收到的N1消息的uplink NAS COUNT的值,生成新的Kamf。具体的,N1消息包括注册请求RR和/或NAS Security Mode Complete消息,即如果初始AMF接收到了UE发送的NAS Security Mode Complete消息,则该NAS Security Mode Complete消息为最近接收到的N1消息,初始AMF根据当前的Kamf和接收到的NAS Security Mode Complete消息中的uplink NAS COUNT的值,生成新的Kamf;否则,注册请求RR为最近接收到的N1消息,初始AMF根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf。
初始AMF应根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF和UE之间没有激活/使用/生成/建立新的NAS安全上下文,初始AMF 应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;否则,初始AMF应根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF仅接收到了一个NAS消息,并且该NAS消息为注册请求RR,初始AMF根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;否则,初始AMF根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF与UE之间没有进行NAS security mode command/control流程,初始AMF应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;否则,初始AMF根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF接收到的NAS消息只有注册请求消息RR,初始AMF应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf;否则,初始AMF根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf。
如果初始AMF接收到除注册请求RR外还接收到了其他NAS消息,初始AMF应根据当前的Kamf和当前的downlink NAS COUNT的值,生成新的Kamf;否则,初始AMF应根据当前的Kamf及接收到的注册请求RR中的uplink NAS COUNT的值,生成新的Kamf。其中,其他NAS消息包括NAS Security Mode Complete消息。
如果初始AMF生成了新的Kamf或如果初始AMF进行了水平Kamf推演,则初始AMF应一个生成了新的Kamf的指示Indicator2,或一个进行了水平Kamf推演的指示发送给目标AMF;初始AMF还应将一个需要做AS key re-keying的指示发送给目标AMF。
具体的,初始AMF应在Namf_Communication_N1MessageNotify消息中包括Indicator2、或进行了水平Kamf推演的指示,初始AMF应在Namf_Communication_N1MessageNotify消息中包括新的Kamf、新的ngKSI和需要做AS key re-keying的指示。
如果Initial AMF生成新的Kamf使用了当前的downlink NAS COUNT,则Initial AMF应将该downlink NAS COUNT值发送给目标AMF。具体地,Initial AMF在Namf_Communication_N1MessageNotify中应包括生成新的Kamf所使用的downlink NAS COUNT值。
可选地,初始AMF应将生成新的Kamf所用的uplink NAS COUNT值发送给目标AMF;或者如果初始AMF在生成新的Kamf时使用了注册请求的uplink NAS COUNT,初始AMF应将一个用于指示“使用注册请求消息的uplink NAS COUNT值生成新的Kamf”的指示Indicator3发送给目标AMF;或者如果初始AMF在生成新的Kamf时使用了NAS Security Mode Complete消息的uplink NAS COUNT,初始AMF将一个用于指示“使用NAS Security Mode Complete消息的uplink NAS COUNT值生成新的Kamf”的指示Indicator4发送给目标AMF。
可选的,初始AMF发送一个指示IndicatorX给Target AMF,该指示IndicatorX用于指示“注册请求消息来自验证过的UE”,或者“UE已经通过验证”,或者“注册消息已通过验证”,或者“不需要验证UE”,或者“不需要验证注册消息”。具体地,初始AMF在Namf_Communication_N1MessageNotify消息中可选地包括IndicatorX发给目标AMF。
可选的,如果初始AMF跟UE之间建立的新的NAS安全上下文,则初始AMF应将IndicatorX发送给目标AMF。
步骤1502:目标AMF接收Kamf,目标AMF根据本地策略决定是否使用接收到的Kamf,如果决定使用接收到的Kamf,并且如果目标AMF接收到生成了新的Kamf的指示或需要进行水平Kamf推演的指示,则目标AMF应将UE进行水平Kamf推演的指示发送给UE。
如果决定不使用接收到的Kamf,目标AMF可以发起重新认证,与UE重新建立新的NAS安全上下文。
示例的,目标AMF应设置K_AMF_change_flag(UE进行水平Kamf推演的指示)为1。
具体的,目标AMF应将UE水平Kamf推演的指示携带在NAS Security Mode Command消息中发送给UE。
可选的,目标AMF还将生成新Kamf所使用的值的信息发送给UE,具体的包括以下中的一种:
如果目标AMF接收到downlink NAS COUNT值,则目标AMF应将downlink NAS COUNT值发送给UE,具体地,目标AMF应将downlink NAS COUNT值包括在NAS Container中包括downlink NAS COUNT值。
或者如果目标AMF接收到uplink NAS COUNT值,则目标AMF应将uplink NAS COUNT值发送给UE,具体地,目标AMF应将uplink NAS COUNT值包括在NAS Securtiy Mode Command消息中。
或者如果目标AMF接收到Indicator3,则目标AMF应向UE发送一个用于指示“采用注册请求消息中的uplink NAS COUNT值生成新的Kamf”的指示Indicator5,具体地目标AMF应将该Indicator5包括在NAS Security Mode Command消息中发给UE。
或者如果目标AMF接收到Indicator4,则目标AMF应向UE发送一个用于指示“采用NAS security mode complete消息中的uplink NAS COUNT值生成新的Kamf”的指示Indicator6,具体地目标AMF应将该Indicator6包括在NAS Security Mode Command消息中发给UE。
可选的,如果目标AMF接收到IndicatorX,目标AMF对接收到注册请求RR不做验证,或者目标AMF不对UE做验证。
步骤1503:UE接收需要进行水平Kamf推演的指示,进行水平Kamf推演,生成新的Kamf。
其中,UE进行水平Kamf推演的过程与初始AMF进行水平Kamf推演的过程相同,从而保证目标AMF中的NAS安全上下文与UE中的NAS安全上下文一致。
如果UE接收到将K_AMF_change_flag的值为1时,确定接收到指示UE水平Kamf推演的信息。
可选的,UE根据指示生成新Kamf所使用的值的信息,进行水平Kamf推演,生成新的Kamf,具体的包括以下中的一种:
如果UE接收到downlink NAS COUNT值,则UE使用该downlink NAS COUNT值生成新的Kamf。
或者如果UE接收到uplink NAS COUNT值,则UE使用该uplink NAS COUNT值生成新的Kamf。
或者如果UE接收到Indicator4,则UE使用注册请求消息中的uplink NAS COUNT值 生成新的Kamf。
或者如果UE接收到Indicator5,则UE使用NAS Security Mode Complete中的uplink NAS COUNT值生成新的Kamf。
否则,UE使用最近发送的N1消息中的uplink NAS COUNT的值生成新的Kamf,具体地,如果UE最近发送了NAS Security Command消息,则UE使用NAS Security Command消息中的uplink NAS COUNT值生成新的Kamf,否则UE使用发送了的注册请求消息中的uplink NAS COUNT值。
下面以一个具体的实施例对本申请实施例四的注册过程进行说明。
参见图16所示的注册流程,注册过程包括:
步骤1601至步骤1604的实现过程同上述图1所示步骤101至步骤103,这里不再赘述。
步骤1605:初始AMF判断是否能够为UE服务,如果初始AMF确定不能为UE服务,初始AMF决定需要进行直接NAS reroute或者初始AMF决定需要将注册请求消息(或NAS消息)直接发送给目标AMF时,初始AMF将当前的安全上下文发送给目标AMF,或者初始AMF根据本地策略决定是否进行水平Kamf推演,如果决定进行水平Kamf推演(horizontal key derivation),初始AMF生成一个新的Kamf,将新生成的Kamf发送给目标AMF,如果决定不进行水平Kamf推演,初始AMF将当前的NAS安全上下文发送给目标AMF。
步骤1606:初始AMF向目标AMF发送Namf_Communication_N1MessageNotify消息,Namf_Communication_N1MessageNotify消息中包括新的Kamf和指示Indicator 1,可选的,Namf_Communication_N1MessageNotify消息中包括指示IndicatorX。
如果Initial AMF生成新的Kamf使用了当前的downlink NAS COUNT,则Initial AMF应将该downlink NAS COUNT值发送给目标AMF。具体地,Initial AMF在Namf_Communication_N1MessageNotify中应包括生成新的Kamf所使用的downlink NAS COUNT值。
可选地,Initial AMF将生成新的Kamf所用的uplink NAS COUNT值发送给Target AMF;或者如果Initial AMF在生成新的Kamf时使用了注册请求的uplink NAS COUNT,Initial AMF将一个用于指示“使用注册请求消息的uplink NAS COUNT值生成新的Kamf”的指示Indicator3发送给Target AMF;或者如果Initial AMF在生成新的Kamf时使用了NAS Security Mode Complete消息的uplink NAS COUNT,Initial AMF将一个用于指示“使用NAS Security Mode Complete消息的uplink NAS COUNT值生成新的Kamf”的指示Indicator4发送给Target AMF。
步骤1607:目标AMF接收新的Kamf和指示Indicator 1,根据本地策略决定使用接收到的新Kamf;如果不使用,目标AMF可发起重新认证,和UE建立新的NAS安全上下文。如果目标AMF根据本地策略决定使用接收到的Kamf,如果目标AMF应设置K_AMF_change_flag为1。
步骤1608:目标AMF将K_AMF_change_flag为1包括在安全模式命令Security Mode Command消息中发送给UE,Security Mode Command消息中应指示生成新Kamf所使用的值的信息。
具体的,如果目标AMF接收到downlink NAS COUNT值,则目标AMF应将downlink  NAS COUNT值发送给UE,具体地,目标AMF应将downlink NAS COUNT值包括在NAS Container中包括downlink NAS COUNT值。
或者如果目标AMF接收到uplink NAS COUNT值,则目标AMF应将uplink NAS COUNT值发送给UE,具体地,目标AMF应将uplink NAS COUNT值包括在NAS Securtiy Mode Command消息中。
或者如果目标AMF接收到Indicator32,则目标AMF应向UE发送一个用于指示“采用注册请求消息中的uplink NAS COUNT值生成新的Kamf”的指示Indicator5,具体地目标AMF应将该Indicator5包括在NAS Security Mode Command消息中发给UE。
或者如果目标AMF接收到Indicator4,则目标AMF应向UE发送一个用于指示“采用NAS security mode complete消息中的uplink NAS COUNT值生成新的Kamf”的指示Indicator6,具体地目标AMF应将该Indicator6包括在NAS Security Mode Command消息中发给UE。
步骤1609:UE接收到K_AMF_change_flag的值为1确定进行水平Kamf推演,并根据接收到的生成新Kamf所使用的值,生成新Kamf。
具体的,如果UE接收到值为1的K_AMF_change_flag,并且,
如果UE接收到downlink NAS COUNT值,则UE使用该downlink NAS COUNT值生成新的Kamf。
或者如果UE接收到uplink NAS COUNT值,则UE使用该uplink NAS COUNT值生成新的Kamf。
或者如果UE接收到Indicator4,则UE使用注册请求消息中的uplink NAS COUNT值生成新的Kamf。
或者如果UE接收到Indicator5,则UE使用NAS Security Mode Complete中的uplink NAS COUNT值生成新的Kamf。
否则,UE使用最近发送的N1消息中的uplink NAS COUNT的值生成新的Kamf,具体地,如果UE最近发送了NAS Security Command消息,则UE使用NAS Security Command消息中的uplink NAS COUNT值生成新的Kamf,否则UE使用发送了的注册请求消息中的uplink NAS COUNT值。
以上结合图2至图17详细说明了本申请实施例的注册方法,基于与上述注册方法的同一发明构思,如图17所示,本申请实施例还提供了一种注册装置1700的结构示意图。装置1700可用于实现上述应用于AMF或UE的方法实施例中描述的方法,可以参见上述方法实施例中的说明。
所述装置1700包括一个或多个处理器1701。所述处理器1701可以是通用处理器或者专用处理器等。例如可以是基带处理器、或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,基站、终端、或芯片等)进行控制,执行软件程序,处理软件程序的数据。所述通信装置可以包括收发单元,用以实现信号的输入(接收)和输出(发送)。例如,所述收发单元可以为收发器,射频芯片等。
所述装置1700包括一个或多个所述处理器1701,所述一个或多个处理器1701可实现上述所示的实施例中AMF或UE的方法。
可选的,处理器1701除了实现上述所示的实施例的方法,还可以实现其他功能。
可选的,一种设计中,处理器1701可以执行指令,使得所述装置1700执行上述方法实施例中描述的方法。所述指令可以全部或部分存储在所述处理器内,如指令1703,也可以全部或部分存储在与所述处理器耦合的存储器1702中,如指令1704,也可以通过指令1703和1704共同使得装置1700执行上述方法实施例中描述的方法。
在又一种可能的设计中,通信装置1700也可以包括电路,所述电路可以实现前述方法实施例中AMF或UE的功能。
在又一种可能的设计中所述装置1700中可以包括一个或多个存储器1702,其上存有指令1704,所述指令可在所述处理器上被运行,使得所述装置1700执行上述方法实施例中描述的方法。可选的,所述存储器中还可以存储有数据。可选的处理器中也可以存储指令和/或数据。例如,所述一个或多个存储器1702可以存储上述实施例中所描述的对应关系,或者上述实施例中所涉及的相关的参数或表格等。所述处理器和存储器可以单独设置,也可以集成在一起。
在又一种可能的设计中,所述装置1700还可以包括收发单元1705以及天线1706。所述处理器1701可以称为处理单元,对装置(终端或者基站)进行控制。所述收发单元1705可以称为收发机、收发电路、或者收发器等,用于通过天线1706实现装置的收发功能。
应注意,本申请实施例中的处理器可以是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法实施例的各步骤可以通过处理器中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器可以是通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现成可编程门阵列(Field Programmable Gate Array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本申请实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器,处理器读取存储器中的信息,结合其硬件完成上述方法的步骤。
可以理解,本申请实施例中的存储器可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDR SDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synchlink DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DR RAM)。应注意,本文描述的系统和方法的存储器旨在包括但不限于这些和任意其它适合类型的存储器。
本申请实施例还提供了一种计算机可读介质,其上存储有计算机程序,该计算机程序被计算机执行时实现上述应用于AMF或UE的任一方法实施例所述的注册方法。
本申请实施例还提供了一种计算机程序产品,该计算机程序产品被计算机执行时实现上述应用于AMF或UE的任一方法实施例所述的注册方法。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机指令时,全部或部分地产生按照本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(Digital Subscriber Line,DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质(例如,软盘、硬盘、磁带)、光介质(例如,高密度数字视频光盘(Digital Video Disc,DVD))、或者半导体介质(例如,固态硬盘(Solid State Disk,SSD))等。
本申请实施例还提供了一种处理装置,包括处理器和接口;所述处理器,用于执行上述应用于AMF或UE的任一方法实施例所述的注册方法。
应理解,上述处理装置可以是一个芯片,所述处理器可以通过硬件来实现也可以通过软件来实现,当通过硬件实现时,该处理器可以是逻辑电路、集成电路等;当通过软件来实现时,该处理器可以是一个通用处理器,通过读取存储器中存储的软件代码来实现,改存储器可以集成在处理器中,可以位于所述处理器之外,独立存在。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、计算机软件或者二者的结合来实现,为了清楚地说明硬件和软件的可互换性,在上述说明中已经按照功能一般性地描述了各示例的组成及步骤。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。
所属领域的技术人员可以清楚地了解到,为了描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另外,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口、装置或单元的间接耦合或通信连接,也可以是电的,机械的或其它的形式连接。
作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本申请实施例方案的目的。
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以是两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
通过以上的实施方式的描述,所属领域的技术人员可以清楚地了解到本申请可以用硬件实现,或固件实现,或它们的组合方式来实现。当使用软件实现时,可以将上述功能存储在计算机可读介质中或作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是计算机能够存取的任何可用介质。以此为例但不限于:计算机可读介质可以包括RAM、ROM、EEPROM、CD-ROM或其他光盘存储、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质。此外。任何连接可以适当的成为计算机可读介质。例如,如果软件是使用同轴电缆、光纤光缆、双绞线、数字用户线(DSL)或者诸如红外线、无线电和微波之类的无线技术从网站、服务器或者其他远程源传输的,那么同轴电缆、光纤光缆、双绞线、DSL或者诸如红外线、无线和微波之类的无线技术包括在所属介质的定影中。如本申请所使用的,盘(Disk)和碟(disc)包括压缩光碟(CD)、激光碟、光碟、数字通用光碟(DVD)、软盘和蓝光光碟,其中盘通常磁性的复制数据,而碟则用激光来光学的复制数据。上面的组合也应当包括在计算机可读介质的保护范围之内。
总之,以上所述仅为本申请技术方案的较佳实施例而已,并非用于限定本申请的保护范围。凡在本申请的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本申请的保护范围之内。

Claims (21)

  1. 一种注册方法,其特征在于,包括:
    初始接入与移动管理网元AMF确定进行AMF重定向;
    所述初始AMF向UE发送指示信息,所述指示信息用于指示用户设备UE删除非接入层NAS安全上下文。
  2. 如权利要求1所述的方法,其特征在于,所述初始AMF发送指示信息包括:
    所述初始AMF向所述UE发送第一通知消息,所述第一通知消息用于指示所述UE删除NAS安全上下文;或者,
    所述初始AMF向UE发送第一NAS消息,其中所述第一NAS消息中携带第一指示信息,所述第一指示信息用于指示所述UE删除NAS安全上下文。
  3. 如权利要求2所述的方法,其特征在于,所述第一通知消息或所述第一NAS消息中携带有下一代密钥集标识符ngKSI,所述ngKSI用于指示所述UE删除所述ngKSI对应的NAS安全上下文。
  4. 一种注册方法,其特征在于,包括:
    用户设备UE接收初始AMF发送的指示信息,所述指示信息用于指示UE删除非接入层NAS安全上下文;
    所述UE根据所述指示信息,删除NAS安全上下文;
    所述UE如果接收目标AMF发送的认证请求消息,处理所述认证请求消息,向所述目标AMF发送认证响应消息。
  5. 如权利要求4所述的方法,其特征在于,所述UE接收初始AMF发送的指示信息包括:
    UE接收初始AMF发送的第一通知消息;或
    UE接收初始AMF发送的第一NAS消息,所述第一NAS消息中携带有第一指示信息。
  6. 如权利要求5所述的方法,其特征在于,所述第一通知消息或所述第一NAS消息中携带有下一代密钥集标识符ngKSI,所述UE根据所述指示信息,删除NAS安全上下文包括:
    所述UE根据所述ngKSI,删除所述ngKSI对应的NAS安全上下文。
  7. 一种注册方法,其特征在于,包括:
    目标接入与移动管理网元AMF接收第六指示信息,所述第六指示信息用于指示用户设备UE删除非接入层NAS安全上下文;
    所述目标AMF根据所述第六指示信息,在向所述UE发送的认证请求消息中包括用于指示所述UE删除NAS安全上下文的指示信息;
    接收所述UE发送的认证响应消息。
  8. 如权利要求7所述的方法,其特征在于,所述目标AMF接收第六指示信息包括:
    所述目标AMF接收无线接入网络RAN发送的第二通知消息,所述第二通知消息中携带第二指示信息,所述第二指示信息用于指示UE删除NAS安全上下文;
    所述目标AMF根据第二指示信息,在向UE发送的认证请求消息中包括第三指示信息,用于指示所述UE删除NAS安全上下文。
  9. 如权利要求7所述的方法,其特征在于,所述目标AMF接收第六指示信息,包括:
    所述目标AMF接收无线接入网络RAN发送的第三通知消息,所述第三通知消息中携带第四指示信息,用于指示所述UE验证所述第四指示信息并删除NAS安全上下文;
    所述目标AMF根据所述第四指示信息,在向UE发送的认证请求消息中包括所述第四指示信息,用于指示所述UE验证所述第四指示信息并删除NAS安全上下文。
  10. 如权利要求7所述的方法,其特征在于,所述目标AMF接收第六指示信息包括:
    所述目标AMF接收无线接入网络RAN发送的完整的注册请求消息;
    所述目标AMF根据所述完整的注册请求消息,向UE发送认证请求消息,并在所述认证请求消息中包括第五指示信息,用于指示所述UE删除NAS安全上下文。
  11. 如权利要求7-10任一项所述的方法,其特征在于,所述目标AMF向UE发送认证请求消息,指示所述UE删除NAS安全上下文包括:
    所述目标AMF根据获取到的下一代密钥集标识ngKSI,将所述ngKSI携带在认证请求消息中发送给UE,所述ngKSI用于指示所述UE删除所述ngKSI对应的NAS安全上下文。
  12. 一种注册方法,其特征在于,包括:
    用户设备UE接收目标接入与移动管理网元AMF发送的认证请求消息,所述认证请求信息中包括用于指示UE删除非接入层NAS安全上下文的指示信息;
    所述UE根据所述认证请求消息中包括的用于指示UE删除NAS安全上下文的指示信息,删除NAS安全上下文;
    所述UE处理所述认证请求,向所述目标AMF发送认证响应消息。
  13. 如权利要求12所述的方法,其特征在于,所述认证请求消息中携带的用于指示UE删除NAS安全上下文的指示信息为第三指示信息;
    所述UE根据所述认证请求消息中包括的用于指示UE删除NAS安全上下文的指示信息,删除NAS安全上下文包括:
    所述UE根据所述第三指示信息,删除NAS安全上下文。
  14. 如权利要求12所述的方法,其特征在于,所述认证请求消息中携带的用于指示UE删除NAS安全上下文的指示信息为第四指示信息;
    所述UE根据所述认证请求消息中包括的用于指示UE删除NAS安全上下文的指示信息,删除NAS安全上下文包括:
    所述UE验证所述第四指示信息,删除NAS安全上下文。
  15. 如权利要求12所述的方法,其特征在于,所述认证请求消息中携带的用于指示UE删除NAS安全上下文的指示信息为第五指示信息;
    所述UE根据所述认证请求消息中包括的用于指示UE删除NAS安全上下文的指示信息,删除NAS安全上下文包括:
    所述UE根据所述第五指示信息,删除NAS安全上下文。
  16. 如权利要求12-15任一项所述的方法,其特征在于,所述认证请求消息中携带有下一代密钥集标识符ngKSI,所述UE删除NAS安全上下文包括:
    所述UE根据所述ngKSI,删除所述ngKSI对应的NAS安全上下文。
  17. 一种注册方法,其特征在于,包括:
    用户设备UE与初始接入与移动管理网元AMF建立非接入层NAS安全上下文;
    所述UE接收目标AMF发送的没有安全保护的认证请求消息;
    所述UE处理所述没有安全保护的认证请求消息;
    所述UE发送没有安全保护的认证响应消息。
  18. 一种监控事件的装置,其特征在于,包括处理器和存储器,所述处理器与所述存储器耦合;
    存储器,用于存储计算机程序;
    处理器,用于执行所述存储器中存储的计算机程序,以使得所述装置执行如权利要求1-17中任一项所述的方法。
  19. 一种计算机可读存储介质,其特征在于,包括程序或指令,当所述程序或指令在计算机上运行时,如权利要求1-17中任意一项所述的方法被执行。
  20. 一种计算机程序产品,其特征在于,包括程序或指令,当所述程序或指令在计算机上运行时,如权利要求1-17中任意一项所述的方法被执行。
  21. 一种芯片,其特征在于,所述芯片与存储器耦合,用于读取并执行所述存储器中存储的程序指令,以执行权利要求1-17中任意一项所述的方法。
PCT/CN2020/087062 2019-04-29 2020-04-26 一种注册方法及装置 Ceased WO2020221175A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP20799587.9A EP3952378A4 (en) 2019-04-29 2020-04-26 REGISTRATION PROCEDURE AND DEVICE
US17/512,757 US12309734B2 (en) 2019-04-29 2021-10-28 Registration method and apparatus for registering user equipment

Applications Claiming Priority (6)

Application Number Priority Date Filing Date Title
CN201910357072 2019-04-29
CN201910357072.4 2019-04-29
CN201910521938 2019-06-17
CN201910521938.0 2019-06-17
CN201910765736.0A CN111866874B (zh) 2019-04-29 2019-08-19 一种注册方法及装置
CN201910765736.0 2019-08-19

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US17/512,757 Continuation US12309734B2 (en) 2019-04-29 2021-10-28 Registration method and apparatus for registering user equipment

Publications (1)

Publication Number Publication Date
WO2020221175A1 true WO2020221175A1 (zh) 2020-11-05

Family

ID=72970624

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/087062 Ceased WO2020221175A1 (zh) 2019-04-29 2020-04-26 一种注册方法及装置

Country Status (4)

Country Link
US (1) US12309734B2 (zh)
EP (1) EP3952378A4 (zh)
CN (1) CN111866874B (zh)
WO (1) WO2020221175A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023070643A1 (en) 2021-11-01 2023-05-04 Zte Corporation Method, device, and system for core network node re-allocation in wireless network
EP4256850A4 (en) * 2021-05-20 2024-09-11 ZTE Corporation METHOD, DEVICE AND SYSTEM FOR REALLOCATING CORE NETWORK DEVICE IN WIRELESS NETWORK

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2592356B (en) * 2020-02-12 2022-07-27 Samsung Electronics Co Ltd Network security
EP4250786A4 (en) * 2020-12-31 2024-01-17 Huawei Technologies Co., Ltd. EVENT MANAGEMENT METHOD AND APPARATUS
WO2022154484A1 (ko) * 2021-01-13 2022-07-21 삼성전자 주식회사 무선통신시스템에서 nas 메시지를 이용하여 애플리케이션의 보안을 지원하는 방법 및 장치
US12207219B2 (en) * 2021-01-21 2025-01-21 Mediatek Inc. NID provisioning under UE mobility scenarios
EP4586661A4 (en) * 2022-10-07 2025-08-27 Samsung Electronics Co Ltd METHOD AND DEVICE FOR SUPPORTING USER PRIVACY PROTECTION IN WIRELESS COMMUNICATION SYSTEM
CN118283782A (zh) * 2022-12-31 2024-07-02 华为技术有限公司 注册方法及相关设备
EP4576851A1 (en) * 2023-12-22 2025-06-25 Mavenir Systems, Inc. Method for targeted amf offload
CN121568087A (zh) * 2026-01-23 2026-02-24 中国星网网络系统研究院有限公司 一种网络接入方法、装置、设备、介质及程序产品

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101505479A (zh) * 2009-03-16 2009-08-12 中兴通讯股份有限公司 一种认证过程中安全上下文协商方法和系统
WO2018174524A1 (ko) * 2017-03-20 2018-09-27 엘지전자(주) 무선 통신 시스템에서 계층간 상호작용 방법 및 이를 위한 장치
CN109314942A (zh) * 2016-11-10 2019-02-05 Lg 电子株式会社 在无线通信系统中通过属于相同plmn的网络接入的注册方法及其设备

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108347728B (zh) * 2017-01-23 2021-06-08 中国移动通信有限公司研究院 一种信息处理方法及装置
US10582561B2 (en) * 2017-03-27 2020-03-03 Electronics And Telecommunications Research Institute Method for releasing context of user equipment in non-3GPP access network and network entity performing the same
CN108966220B (zh) * 2017-07-28 2019-07-23 华为技术有限公司 一种密钥推演的方法及网络设备
CN107580324B (zh) * 2017-09-22 2020-05-08 中国电子科技集团公司第三十研究所 一种用于移动通信系统imsi隐私保护的方法
US10542428B2 (en) * 2017-11-20 2020-01-21 Telefonaktiebolaget Lm Ericsson (Publ) Security context handling in 5G during handover
US10813161B2 (en) * 2018-03-06 2020-10-20 Mediatek Singapore Pte. Ltd. Apparatuses and methods for protection of an initial non-access stratum (NAS) message
CN114629645B (zh) * 2018-04-10 2024-09-03 联发科技(新加坡)私人有限公司 移动通信中错误ksi处理的改进方法、装置及计算机可读存储介质
US11917412B2 (en) * 2019-06-17 2024-02-27 Telefonaktiebolaget Lm Ericsson (Publ) AMF reallocation handling using UE exceptions to security context rules

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101505479A (zh) * 2009-03-16 2009-08-12 中兴通讯股份有限公司 一种认证过程中安全上下文协商方法和系统
CN109314942A (zh) * 2016-11-10 2019-02-05 Lg 电子株式会社 在无线通信系统中通过属于相同plmn的网络接入的注册方法及其设备
WO2018174524A1 (ko) * 2017-03-20 2018-09-27 엘지전자(주) 무선 통신 시스템에서 계층간 상호작용 방법 및 이를 위한 장치

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
3GPP TS 23.502
See also references of EP3952378A4

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4256850A4 (en) * 2021-05-20 2024-09-11 ZTE Corporation METHOD, DEVICE AND SYSTEM FOR REALLOCATING CORE NETWORK DEVICE IN WIRELESS NETWORK
WO2023070643A1 (en) 2021-11-01 2023-05-04 Zte Corporation Method, device, and system for core network node re-allocation in wireless network
EP4393226A4 (en) * 2021-11-01 2025-04-23 ZTE Corporation Method, device, and system for core network node re-allocation in wireless network

Also Published As

Publication number Publication date
CN111866874B (zh) 2022-05-10
US20220053446A1 (en) 2022-02-17
US12309734B2 (en) 2025-05-20
CN111866874A (zh) 2020-10-30
EP3952378A4 (en) 2022-05-04
EP3952378A1 (en) 2022-02-09

Similar Documents

Publication Publication Date Title
CN111866874B (zh) 一种注册方法及装置
US11463874B2 (en) User profile, policy, and PMIP key distribution in a wireless communication network
TWI463856B (zh) 促進安全性配置的同步的方法和裝置
US11445365B2 (en) Communication method and communications apparatus
CN109587688B (zh) 系统间移动性中的安全性
CN101772021B (zh) 无线通讯系统处理保密设定的方法及其相关通讯装置
WO2021218978A1 (zh) 密钥管理方法、设备及系统
US20100172500A1 (en) Method of handling inter-system handover security in wireless communications system and related communication device
US11751160B2 (en) Method and apparatus for mobility registration
US20110123029A1 (en) Method and system for generating an identity identifier of a key
US11689922B2 (en) Re-establishing a radio resource control connection
US20110135095A1 (en) Method and system for generating key identity identifier when user equipment transfers
JP7623072B2 (ja) 非アクセス層コンテキストを処理するための方法および装置
WO2020029075A1 (en) Method and computing device for carrying out data integrity protection
JP2025128072A (ja) 進化型パケットシステム非アクセス層セキュリティアルゴリズムを構成する方法、および関連装置
CN101557589A (zh) 防止空完整性保护算法用于正常通信的方法和系统
WO2023011263A1 (zh) 消息传输方法及通信装置
JP7813355B2 (ja) 端末を通信ネットワークに登録するための方法、デバイス、及びシステム
CN118869195B (zh) 一种通信方法和装置
KR102437822B1 (ko) 보안 알고리즘 협상을 위한 방법 및 장치
CN117202186A (zh) 一种认证方法、装置、设备及可读存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20799587

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2020799587

Country of ref document: EP

Effective date: 20211028

WWW Wipo information: withdrawn in national office

Ref document number: 2020799587

Country of ref document: EP