WO2024146582A1 - 通信方法和通信装置 - Google Patents
通信方法和通信装置 Download PDFInfo
- Publication number
- WO2024146582A1 WO2024146582A1 PCT/CN2024/070490 CN2024070490W WO2024146582A1 WO 2024146582 A1 WO2024146582 A1 WO 2024146582A1 CN 2024070490 W CN2024070490 W CN 2024070490W WO 2024146582 A1 WO2024146582 A1 WO 2024146582A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- network element
- management function
- function network
- session management
- dns server
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
- H04W76/12—Setup of transport tunnels
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/45—Network directories; Name-to-address mapping
- H04L61/4505—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
- H04L61/4511—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
- H04W76/11—Allocation or use of connection identifiers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/02—Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
- H04W8/08—Mobility data transfer
- H04W8/12—Mobility data transfer between location registers or mobility servers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/26—Network addressing or numbering for mobility support
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/20—Manipulation of established connections
- H04W76/22—Manipulation of transport tunnels
Definitions
- the present application relates to the field of communications, and more particularly, to a communication method and a communication method.
- UE user equipment
- EHE edge hosting environment
- VPN visited public land mobile network
- the UE can initiate a registration process and a protocol data unit (PDU) session establishment process to the visited network to establish a network connection to the visited EHE.
- PDU protocol data unit
- the UE can obtain the application server address in the visited EHE by interacting with the visited domain name system (DNS) server.
- DNS visited domain name system
- the present application provides a communication method and a communication method, which can protect the communication security between a DNS server at a visited location and a communication device.
- the method includes: a session management function network element at a visited location obtains security information of a domain name system DNS server and an identifier of the DNS server at the visited location, wherein the security information is used to establish a secure connection between a terminal device and the DNS server; the session management function network element at the visited location sends the security information and the identifier of the DNS server to a session management function network element at a home location; the session management function network element at the visited location receives protocol configuration options (PCO) from the session management function network element at the home location, wherein the PCO includes the security information and the identifier of the DNS server; and the session management function network element at the visited location sends the PCO to the terminal device.
- PCO protocol configuration options
- the DNS server of the visited location can be a V-edge application server discovery function network element (V-EASDF) of the visited location.
- V-EASDF V-edge application server discovery function network element
- the V-EASDF in the embodiment of the present application is an enhanced function of the DNS server.
- V-EASDF can support all the functions of the DNS server and has been additionally enhanced. Therefore, the specific implementation method of the subsequent UE interacting with the V-EASDF to perform the server discovery process based on the security information can refer to the implementation method of the current interaction between the UE and the DNS server. For the sake of brevity, it will not be described in detail here.
- the technical solution of the present application is mainly aimed at roaming scenarios and is applied to the process of establishing or modifying a session of a terminal device, that is, the process of establishing or modifying a PDU session of a terminal device when the terminal device is located at a visited location.
- the session management function network element at the visited location obtains security information and exchanges security information with the session management function network element at the home location. Furthermore, a PCO containing security information is obtained from the session management function network element at the home location, and the PCO is sent to the terminal device, so that the terminal device can establish a secure connection with the DNS server based on the security information, thereby improving the security performance of communication between the terminal device and the DNS server.
- the DNS server is authenticated during the process of establishing a secure connection between the terminal device and the DNS server, thereby ensuring network communication security.
- the security information also includes one or more security protocol types supported by the DNS server, and/or a port number used to establish a secure connection.
- the session management function network element at the visited location before the session management function network element at the visited location receives the PCO from the session management function network element at the home location, the session management function network element at the visited location sends to the session management function network element at the home location one or more security protocol types supported by the DNS server, and/or the port number used to establish a secure connection; wherein the PCO also includes one or more security protocol types and/or port numbers among the one or more security protocol types supported by the DNS server.
- the PCO from the session management function network element at the home location is the first PCO; before the session management function network element at the visited location obtains the security information of the DNS server located at the visited location, the session management function network element at the visited location receives the second PCO from the terminal device, wherein the second PCO includes indication information for indicating that the terminal device supports security protection of DNS messages based on a security protocol; the session management function network element at the visited location sends the second PCO to the session management function network element at the home location; the session management function network element at the visited location receives a request message from the session management function network element at the home location, the request message includes indication information for indicating that the terminal device supports security protection of DNS messages based on a security protocol; wherein the session management function network element at the visited location obtains the security information of the DNS server located at the visited location, including: in response to the indication information, the session management function network element at the visited location obtains the security information.
- the indication information carried in the second PCO for indicating that the terminal device supports security protection of DNS messages based on the security protocol is sent to the session management function network element of the visited location through the session management function network element of the home location, so that the session management function network element of the visited location determines and obtains the security information of the DNS server according to the request message sent by the session management function network element of the home location, thereby increasing the considerations or basis for the session management function network element of the visited location to obtain the security information of the DNS server, so that the network can obtain security information on demand.
- the session management function network element at the visited location before the session management function network element at the visited location obtains the security information of the DNS server and the identifier of the DNS server located at the visited location, the session management function network element at the visited location receives a home routed session breakout (HR-SBO) permission indication from the mobility and access management function network element; wherein the session management function network element at the visited location obtains the security information of the DNS server and the identifier of the DNS server located at the visited location, including: the session management function network element at the visited location obtains the security information and the identifier of the DNS server according to the HR-SBO permission indication.
- HR-SBO home routed session breakout
- the session management function network element at the visited location determines and obtains the security information of the DNS server and the identifier of the DNS server according to the HR-SBO permission indication sent by the mobility and access management function network element, and increases the considerations or basis for the session management function network element at the visited location to obtain the security information of the DNS server and the identifier of the DNS server, so that the network can obtain security information on demand.
- the session management function network element of the visited location obtains security information of the DNS server located at the visited location, including: the session management function network element of the visited location obtains security information based on local configuration information.
- the session management function network element at the visited location before the session management function network element at the visited location obtains the security information of the DNS server located at the visited location, the session management function network element at the visited location receives the network identifier of the home location from the session management function network element at the home location; wherein the session management function network element at the visited location obtains the security information of the DNS server located at the visited location, including: the session management function network element at the visited location obtains the security information based on the network identifier of the terminal device.
- the session management function network element at the visited location determines and obtains the security information of the DNS server according to the local configuration information or the network identifier of the home location sent by the session management function network element at the home location, thereby increasing the considerations or basis for the session management function network element at the visited location to obtain the security information of the DNS server, so that the network can obtain accurate security information.
- the session management function network element at the visited location obtains policy information, and the policy information is used to indicate the trigger conditions for the session management function network element at the home location to send security information to the terminal device; the session management function network element at the visited location sends the policy information to the session management function network element at the home location.
- the session management function network element at the visited location sends policy information to the session management function network element at the home location, thereby adding a trigger condition for the session management function network element at the home location to send security information to the terminal device, so that the network can provide security information to the terminal device on demand.
- the session management function network element at the visited location before the session management function network element at the visited location obtains the security information of the DNS server located at the visited location, the session management function network element at the visited location receives the user plane security policy corresponding to the session from the session management function network element at the home location, and the user plane security policy indicates that user plane security protection is not enabled or is optionally enabled; wherein, the session management function network element at the visited location obtains the security information of the DNS server located at the visited location, including: the session management function network element at the visited location obtains the security information according to the user plane security policy.
- the session management function network element at the visited location determines and obtains the security information of the DNS server according to the user plane security policy sent by the session management function network element at the home location, and increases the considerations or basis for the session management function network element at the visited location to obtain the security information of the DNS server, so that the network can obtain security information on demand.
- the session management function network element at the visited location before the session management function network element at the visited location obtains the security information of the DNS server and the identifier of the DNS server located at the visited location, the session management function network element at the visited location receives HR-SBO authorization information from the session management function network element at the home location; wherein the session management function network element at the visited location obtains the security information of the DNS server and the identifier of the DNS server located at the visited location, including: the session management function network element at the visited location obtains the security information and the identifier of the DNS server based on the HR-SBO authorization information.
- the session management function network element at the visited location obtains security information and the identifier of the DNS server based on the HR-SBO authorization information, including: when it is determined that the terminal device meets the HR-SBO session establishment conditions, the session management function network element at the visited location obtains security information and the identifier of the DNS server based on the HR-SBO authorization information.
- the DNS server is a functional network element for the edge server discovery.
- the session management function network element of the home location exchanges security information with the session management function network element of the visited location, and further sends the PCO containing the security information to the terminal device, so that the terminal device can establish a secure connection with the DNS server based on the security information, thereby ensuring the security of network communications.
- the DNS server is authenticated during the process of establishing a secure connection between the terminal device and the DNS server, thereby improving the security performance of communication between the terminal device and the DNS server.
- the second PCO also includes one or more security protocol types supported by the terminal device; wherein the session management function network element at the home location generates the PCO, including: the session management function network element at the home location generates a first PCO based on the one or more security protocol types supported by the terminal device carried in the second PCO, and one or more security protocol types supported by the DNS server, wherein the PCO includes one or more security protocol types among the one or more security protocol types supported by both the DNS server and the terminal device.
- the session management function network element at the visited location determines and obtains the security information of the DNS server according to the user plane security policy sent by the session management function network element at the home location, thereby increasing the considerations or basis for the session management function network element at the visited location to obtain the security information of the DNS server, so that the network can obtain security information on demand.
- the transceiver unit can perform the reception and transmission processing in the aforementioned second aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned second aspect.
- a terminal device such as a UE
- the device includes: a transceiver unit, configured to send a second PCO to a session management function network element of a visited location, wherein the second PCO includes indication information for indicating that the terminal device supports security protection of DNS messages based on a security protocol; the transceiver unit is also configured to receive a first PCO from the session management function network element of the visited location, wherein the first PCO includes security information and an identifier of a DNS server; and a processing unit, configured to establish a secure connection with the DNS server based on the security information.
- the memory may be integrated with the processor, or the memory may be provided separately from the processor.
- a computer program product which includes: a computer program code, when the computer program code is executed by a terminal device, the terminal device executes the method in the above-mentioned first aspect, second aspect, or third aspect and any possible implementation manner thereof.
- FIG8 is a flow chart of a communication method 800 provided in an embodiment of the present application.
- FIG9 is a schematic diagram of the structure of a terminal device 1000 provided in an embodiment of the present application.
- FIG. 10 is a schematic diagram of the structure of another terminal device 2000 provided in an embodiment of the present application.
- the above-mentioned device providing wireless communication function for the terminal device 110 is collectively referred to as access network equipment or RAN or AN for short. It should be understood that the specific type of access network equipment is not limited herein.
- SMF 139 is a control plane network function provided by the operator network, responsible for managing the PDU session of the terminal device 110.
- the PDU session is a channel for transmitting PDUs.
- the terminal device needs to transmit PDUs to and from the data network DN 140 through the PDU session.
- the PDU session is established, maintained, and deleted by the SMF network function 139.
- the SMF network function 139 includes session management (such as session establishment, modification, and release, including tunnel maintenance between the user plane function UPF 130 and (R)AN 120), selection and control of the UPF network function 130, service and session continuity (SSC) mode selection, roaming, and other session-related functions.
- session management such as session establishment, modification, and release, including tunnel maintenance between the user plane function UPF 130 and (R)AN 120
- SSC service and session continuity
- the HR PDU session refers to a home routed PDU session, and this type of PDU session is supported by the SMF controlled by the home network (home PLMN, HPLMN), the SMF controlled by the VPLMN, at least one UPF controlled by the HPLMN, and at least one UPF controlled by the VPLMN.
- the SMF in the HPLMN selects the UPF in the HPLMN
- the SMF in the VPLMN selects the UPF in the VPLMN.
- FIG1( b ) The functions of some network elements in FIG1( b ) are briefly described below.
- UDM sends SDM information (SDM information) to AMF; correspondingly, AMF receives SDM information from UDM.
- SDM information SDM information
- AMF sends a create session management context request to V-SMF; correspondingly, V-SMF receives the create session management context request from AMF.
- V-SMF determines to create an HR VSBO session
- V-SMF sends a PDU session Create Request message including a VSBO request, a V-EASDF address or a V-DNS server address to H-SMF.
- H-SMF requests UDM to obtain SDM information; correspondingly, UDM receives the request for obtaining SDM information from H-SMF.
- the SDM information includes allowed HR-SBO (HR-SBO allowed), for example, it can be HR-SBO authorization indication, and/or HR-SBO authorization information.
- H-SMF sends a create HR-SBO session response to V-SMF; correspondingly, V-SMF receives a create HR-SBO session response from H-SMF.
- the creation of HR-SBO session response includes HR-SBO authorization indication, protocol configuration option (PCO) and the address of the home DNS server.
- H-SMF determines that the establishment of HR-SBO PDU session is allowed
- H-SMF sets the DNS server address in PCO to the address of V-EASDF, and sends a PDU session Create Response message including HR-SBO permission indication, PCO, and home DNS server address to V-SMF.
- V-SMF triggers the local UPF to insert ULCL/BP.
- V-SMF sends a DNS context creation request to V-EASDF; correspondingly, V-EASDF receives the DNS context creation request from V-SMF.
- the DNS context creation request may be a Neasdf_DNSContextCreat Request message, where the request includes a DNS message handling rule (DNS Message Handling Rule), a UE IP address, and a DNN.
- DNS message handling rule DNS Message Handling Rule
- V-SMF sends N1N2 message transmission to AMF; correspondingly, AMF receives N1N2 message transmission from V-SMF.
- the N1N2 message transmission can be N1N2_MessageTransfer, which contains the information of PDU session establishment acceptance or rejection (PDU session Establishment Accept/Reject).
- AMF sends a PDU session establishment acceptance or rejection to the UE; correspondingly, the UE receives a PDU session establishment acceptance or rejection from the AMF.
- steps S205 to S215 are the process of UE requesting PDU session establishment.
- the specific implementation method can refer to the relevant description in 3GPP TS23.502. For the sake of brevity, no further details will be given here.
- a security measure for protecting DNS messages is defined, which can be used when user plane integrity protection cannot be used.
- the specific security method includes that the UE and the DNS server support DNS based on (D)TLS.
- the NDS server deployed in the 3GPP network can force the use of the DNS protection mechanism based on (D)TLS.
- the UE can pre-configure the security information of the DNS server, or receive the security information from the DNS server of the core network, so that when using DNS based on (D)TLS, it is necessary to negotiate the TLS cipher suite that supports integrity protection.
- the above-mentioned provision of security information of the DNS server through the core network can be achieved.
- the UE can carry an extended protocol configuration option (ePCO) information element (IE) and a security information indicator of the DNS server in a PDU session establishment request message (for example, step S205 of the above method 200).
- the PDU session establishment request message can also carry the security protocol support of the DNS server to indicate the type of security protocol that the UE wants to support.
- the network may carry the ePCO IE in the PDU Session Establishment Accept message sent to the UE, including the security information of the DNS server with a length of two octets.
- the SMF selects EASDF as the DNS server based on the DNS over (D)TLS capability supported by the UE carried in the ePCO, and optionally, the type of security protocol supported by the UE, and provides the security information of EASDF to the UE.
- the SMF selects EASDF as the DNS server based on the DNS over (D)TLS capability supported by the UE carried in the ePCO, and optionally, the type of security protocol supported by the UE, and provides the security information of EASDF to the UE.
- the SMF selects EASDF as the DNS server based on the DNS over (D)TLS capability supported by the UE carried in the ePCO, and optionally, the type of security protocol supported by the UE, and provides the security information of EASDF to the UE.
- an HR PDU session which is managed by the V-SMF and the H-SMF
- V-SMF can determine V-EASDF as the DNS server. Since ePCO is transparently transmitted from V-SMF to H-SMF during the PDU session establishment process, V-SMF does not parse the content of ePCO. Therefore, V-SMF cannot perceive whether the UE supports DNS over (D)TLS and which type of security protocol the UE supports, and thus cannot determine whether to use DNS over (D)TLS. In contrast, H-SMF can obtain whether the UE supports DNS over (D)TLS and which type of security protocol the UE supports, but H-SMF does not perceive the information of V-EASDF. When the user plane security (such as integrity protection) of the established HR PDU session is not enabled, the network cannot provide security protection for the DNS messages exchanged between the UE and V-EASDF.
- the user plane security such as integrity protection
- V-SMF determines to use V-EASDF to process DNS messages
- how to ensure the security of DNS messages between UE and V-EASDF is a technical problem that needs to be solved urgently.
- the present application provides a communication method and device, which supports the process of establishing or modifying a session in an edge environment in a visited network for a terminal device.
- the session management function network element at the visited location exchanges security information with the session management function network element at the home location, and the session management function network element at the home location sends the security information to the terminal device, so that the terminal device can establish a secure connection with the DNS server based on the security information, thereby ensuring the security of network communications.
- “at least one” means one or more, and “more than one” means two or more.
- “And/or” describes the association relationship of the associated objects, indicating that there can be three kinds of relationships.
- a and/or B can mean: A exists alone, A and B exist at the same time.
- B the case where B exists alone, wherein A and B can be singular or plural.
- the character “/” generally indicates that the objects associated before and after are in an "or” relationship.
- “At least one of the following” or similar expressions refers to any combination of these items, including any combination of single items or plural items.
- At least one of a, b and c can represent: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c.
- a, b and c can be single or multiple, respectively.
- first”, “second” and various numerical numbers indicate distinctions made for ease of description and are not used to limit the scope of the embodiments of the present application. For example, to distinguish between different messages, etc., rather than to describe a specific order or sequence. It should be understood that the objects described in this way can be interchanged where appropriate so as to be able to describe solutions other than the embodiments of the present application.
- used for indication may include being used for direct indication and being used for indirect indication.
- indication information may include that the indication information directly indicates A or indirectly indicates A, but it does not mean that the indication information must carry A.
- the indication method involved in the embodiments of the present application should be understood to include various methods that can enable the party to be indicated to know the information to be indicated.
- the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and/or sending time of these sub-information can be the same or different.
- the present application does not limit the specific sending method.
- the "indication information" in the embodiments of the present application may be an explicit indication, i.e., directly indicated by signaling, or obtained by combining other rules or other parameters or by deduction according to the parameters indicated by the signaling. It may also be an implicit indication, i.e., obtained according to a rule or relationship, or according to other parameters, or by deduction. The present application does not make specific restrictions on this.
- protocol may refer to a standard protocol in the field of communications, such as 5G protocol, NR protocol, and related protocols used in future communication systems, which are not limited in this application.
- Predefined may include pre-definition. For example, protocol definition.
- Preconfiguration can be implemented by pre-saving corresponding codes, tables, or other methods that can be used to indicate relevant information in the device, and this application does not limit its specific implementation method.
- the SMF in the HPLMN is recorded as H-SMF
- the SMF in the vPLMN is recorded as V-SMF in the embodiment of the present application, and the following related parts will not be repeated.
- the security information of the DNS server is obtained through the V-SMF of the visited location, and information is exchanged with the H-SMF of the home location. Further, the H-SMF sends the security information of the DNS server to the terminal device, so that the terminal device and the DNS server can communicate securely subsequently.
- the security information of the DNS server is obtained through the V-SMF of the visited location, and information is exchanged with the H-SMF of the home location.
- the H-SMF sends the security information of the DNS server to the terminal device, so that the terminal device and the DNS server can communicate securely subsequently.
- methods 300 to 800 please refer to the description of methods 300 to 800 below.
- Fig. 3 is a flow chart of a communication method 300 provided in an embodiment of the present application. As shown in Fig. 3, the method is applied to the process of establishing or modifying a session of a terminal device in a roaming scenario, and includes the following steps. For the parts not described in detail, reference may be made to existing protocols.
- the second PCO includes indication information for indicating that the terminal device supports security protection of DNS messages based on a security protocol.
- the PCO from the session management function network element of the home location is the first PCO
- the PCO from the terminal device is the second PCO
- the relevant parts are not repeated below.
- the first PCO or the second PCO can be an extended protocol configuration option (extended protocol configuration option, ePCO), which is not limited in the present application.
- the session management function network element of the visited location obtains the security information of the DNS server of the visited location and the identifier of the DNS server.
- the session management function network element of the visited location further obtains one or more security protocol types supported by the DNS server and/or the port number used to establish a secure connection. That is, the session management function network element of the visited location obtains the security information of the DNS server of the visited location, one or more security protocol types supported by the DNS server, and/or the port number used to establish a secure connection, and the identifier of the DNS server.
- the security information may also be acquired by a session management function network element at the visited location from local configuration.
- the session management function network element at the visited location before the session management function network element at the visited location obtains the security information of the DNS server at the visited location, the session management function network element at the visited location receives a second PCO from the terminal device, wherein the second PCO includes indication information for indicating that the terminal device supports security protection of DNS messages based on a security protocol; the session management function network element at the visited location sends the second PCO to the session management function network element at the home location; the session management function network element at the visited location receives a request message from the session management function network element at the home location, wherein the request message includes indication information for indicating that the terminal device supports security protection of DNS messages based on a security protocol. Further, in response to the indication information, the session management function network element at the visited location obtains security information.
- the request message may also include one or more of the following: user plane security policy for the PDU session, HPLMN ID, and DNS server security protocol support.
- the request message includes the HPLMN ID
- the session management function network element of the visited location can determine the security information of the DNS server based on the HPLMN ID.
- the security information is used for secure message interaction between the contracted users in the PLMN corresponding to the HPLMN ID and the DNS server.
- the session management function network element of the visited location can provide security information of the DNS server based on the local policy and the user plane security policy of the PDU session.
- the local policy indicates that when the terminal device supports DNS over (D)TLS and the terminal device belongs to the HPLMN, the session management function network element of the visited location can provide security information for the terminal device in the PLMN to interact securely with the DNS server.
- the local policy indicates that the security information is obtained when the terminal device supports DNS over (D) TLS. For example, if the second PCO received by the session management function network element at the visited location includes DNS over (D) TLS, it is determined to obtain the security information.
- the local policy may also include PLMN information to indicate which PLMN users can be provided with HR-SBO services.
- the session management function network element at the visited location may determine whether the terminal device belongs to the PLMN, for example, whether the HPLMN of the terminal device is For the PLMN, or whether the terminal device is a subscriber of the PLMN, if the HPLMN of the terminal device is not the PLMN, or the terminal device does not belong to the PLMN, the session management function network element of the visited location can skip the discovery of the DNS server; if the HPLMN of the terminal device is the PLMN, or the terminal device belongs to the PLMN, the session management function network element of the visited location can select a DNS server that supports HR-SBO, such as V-EASDF.
- HR-SBO such as V-EASDF
- the session management function network element of the visited location can determine the security information of the DNS server according to the identification of the HPLMN of the terminal device, and the security information is used for the subscriber in the PLMN corresponding to the HPLMN ID to perform secure message interaction with the DNS server. Therefore, in this implementation, different security information of the DNS server can be determined for different HPLMNs. In other words, for terminal devices of different HPLMNs, the security information used to authenticate the DNS server, such as credentials, is also different.
- the session management function network element at the visited location before the session management function network element at the visited location obtains the security information of the DNS server at the visited location, the session management function network element at the visited location receives the user plane security policy corresponding to the session from the session management function network element at the home location. Further, the session management function network element at the visited location obtains the security information according to the user plane security policy.
- the user plane security policy indicates not to enable or to enable user plane security protection.
- the user plane security policy can also be understood as a user plane integrity protection policy, and the two can be used interchangeably.
- the session management function network element of the visited site may determine to use DNS over (D)TLS, and the session management function network element of the visited site may provide security information; alternatively, if the user plane security policy of the PDU session indicates that user plane integrity protection is required, the session management function network element of the visited site may not provide security information.
- the session management function network element at the visited location obtains security information and an identifier of the DNS server according to the HR-SBO authorization information.
- the session management function network element at the home location receives security information and DNS server information from the session management function network element at the visited location. 's logo.
- the first PCO may further include one or more of the following: one or more security protocol types among one or more security protocol types supported by the DNS server, and a port number used to establish a secure connection between the terminal device and the DNS server.
- the session management function network element at the visited location before the session management function network element at the visited location receives the first PCO from the session management function network element at the home location, the session management function network element at the visited location sends to the session management function network element at the home location one or more security protocol types supported by the DNS server, and/or the port number used to establish a secure connection; wherein the first PCO also includes one or more security protocol types and/or port numbers among the one or more security protocol types supported by the DNS server.
- the session management function network element of the home location can determine to include the security information of the V-EASDF in the first ePCO based on the received DNS server address, the indication information for indicating that the terminal device supports security protection of DNS messages based on the security protocol, the VPLMN ID, and the type of security protocol supported by the DNS server.
- the edge application server discovery function network element of the visited location as V-EASDF the session management function network element of the visited location as V-SMF
- the session management function network element of the home location as H-SMF the mobility management function network element as AMF
- the unified data management function network element as UDM the schemes for establishing a secure connection between the UE and V-EASDF are respectively explained.
- UE sends a PDU session establishment request #a to AMF; correspondingly, AMF receives a PDU session establishment request #a from the UE.
- AMF selects V-SMF.
- V-SMF sends a create session management context response to AMF; correspondingly, AMF receives a create session management context response from V-SMF.
- the specific implementation method of the above steps S402 to S405, and the specific name or meaning of the interactive message can refer to the relevant description of steps S205 to S207 of the above method 200. For the sake of brevity, they will not be repeated here.
- V-SMF obtains the security information #a of V-EASDF.
- the local policy may also include PLMN information to indicate which PLMN users can be provided with HR-SBO services.
- V-SMF can determine whether the UE belongs to the PLMN, that is, whether the HPLMN of the UE is the PLMN or the UE is a subscriber of the PLMN. If the UE does not belong to the PLMN, V-SMF skips the discovery of V-EASDF; if the UE belongs to the PLMN, V-SMF selects V-EASDF that supports HR-SBO.
- the V-SMF can determine the security information #a of the V-EASDF according to the identifier of the HPLMN of the UE. Therefore, in this implementation, different security information of the V-EASDF can be determined for different HPLMNs. In other words, for UEs of different HPLMNs, the credentials used to authenticate the V-EASDF are also different.
- V-SMF may also obtain policy information #a, carry it in step S407 and send it to H-SMF, so that H-SMF can determine whether to provide the security information #a of V-EASDF to the UE.
- policy information #a indicates that when the UE supports DNS over (D)TLS, H-SMF can provide the security information of V-EASDF to the UE; for another example, policy information #a indicates that when the UE supports DNS over (D)TLS and the PDU session user plane security policy indicates that integrity protection is not required, H-SMF can provide the security information of V-EASDF to the UE, etc.
- policy information #a indicates that when the UE supports DNS over (D)TLS
- H-SMF can provide the security information of V-EASDF to the UE, etc.
- V-SMF sends a PDU session establishment request #b to H-SMF; correspondingly, H-SMF receives the PDU session establishment request #b from V-SMF.
- the PDU session establishment request #b includes ePCO #a, V-EASDF security information #a and the address of V-EASDF.
- UDM sends SDM information to H-SMF; correspondingly, H-SMF receives SDM information from UDM.
- H-SMF when H-SMF confirms the authorization of HR-SBO, it confirms the security information #b (i.e., an example of security information) of V-EASDF.
- security information #b i.e., an example of security information
- the security information #b may include authentication credentials, i.e., credentials for authenticating the V-EASDF.
- the security information #b may also include: Including the security protocol information supported by V-EASDF (or, the security mechanism supported by V-EASDF), and/or port number, etc.
- the H-SMF determines to generate the ePCO#b including the security information #b of the V-EASDF.
- the ePCO#b also includes the address of the V-EASDF.
- the H-SMF may determine that the security information #b of the V-EASDF is included in the ePCO#b according to the local policy and/or the user plane security policy of the PDU session. For example, when the user plane security policy of the PDU session indicates that the integrity protection of the user plane is not required, the H-SMF determines that the security information #b of the V-EASDF is included in the ePCO#b; for another example, when the local policy indicates that the user plane security policy of the PDU session indicates that the integrity protection of the user plane is not required, the H-SMF determines that the security information #b of the V-EASDF is included in the ePCO#b.
- the H-SMF can determine that the security information #b of V-EASDF is contained in ePCO#b.
- the H-SMF can determine the security protocol finally used based on the DNS server security protocol support carried in ePCO#a and the security protocol information carried in the security information #a of the V-EASDF received in step S407, and carry the DNS server security protocol as part of the security information #b of the V-EASDF in ePCO#b.
- the security information #b of V-EASDF may be the same as or different from the security information #a of V-EASDF.
- the security information #b of V-EASDF is included in the security information #a of V-EASDF, or the security information #b of V-EASDF is a subset of the security information #a of V-EASDF.
- the security information #b of V-EASDF includes credential 1 and security protocol 1
- the security information #a of V-EASDF includes credential 1, security protocol 1 and security protocol 2.
- the PDU session establishment response #a includes an N1SM container, that is, providing the UE with the security information #b of the V-EASDF and the address of the V-EASDF.
- the UE uses the security information #b of the V-EASDF to send a DNS message with security protection to the V-EASDF; correspondingly, the V-EASDF receives the DNS message with security protection from the UE.
- UE sends a PDU session establishment request #A to AMF; correspondingly, AMF receives a PDU session establishment request #A from the UE.
- AMF selects V-SMF.
- AMF sends a create session management context request to V-SMF; correspondingly, V-SMF receives the create session management context request from AMF.
- the specific implementation method of the above steps S501 to S505, and the specific name or meaning of the interactive message can refer to the relevant description of steps S401 to S405 of the above method 400. For the sake of brevity, they will not be repeated here.
- step S504 includes an HR-SBO permission indication
- the V-SMF selects a V-EASDF that supports HR-SBO and obtains the address of the V-EASDF.
- H-SMF determines that the HR-SBO PDU session is authorized based on the HR-SBO authorization indication and/or HR-SBO authorization information carried in the SDM information of step S509; at the same time, if the ePCO#A received in step S507 carries the DNS server security information indication, H-SMF triggers to obtain the security information #a of V-EASDF from V-SMF, that is, executes steps S511 to S513.
- V-SMF can determine to use DNS over (D)TLS based on the DNS server security information indication, and carry the security information #a of V-EASDF in the security information response in step S513.
- V-SMF may determine to provide security information #a of V-EASDF based on the DNS server security protocol support.
- V-SMF can determine whether to provide security information #a of V-EASDF based on local policy and user plane security policy of PDU session. For example, local policy indicates that V-SMF can provide security information #a of V-EASDF only when the user plane security policy of PDU session indicates that user plane integrity protection is not required.
- V-SMF can determine whether to provide security information #a of V-EASDF based on local policy and HPLMN ID. For example, local policy indicates that when UE supports DNS over (D)TLS and UE belongs to the HPLMN, V-SMF can provide security information #a for secure interaction between users in the corresponding PLMN and V-EASDF, and so on.
- V-SMF sends a security information response to H-SMF; correspondingly, H-SMF receives the security information response from V-SMF.
- the UE uses the security information #b of the V-EASDF to send a DNS message with security protection to the V-EASDF; correspondingly, the V-EASDF receives the DNS message with security protection from the UE.
- the UE receives the security information #b of the V-EASDF, and the UE transfers the security information #b to the upper layer. Further, the UE uses the security information #b of the V-EASDF to establish a secure connection with the V-EASDF, and uses the established secure connection to send a DNS message.
- the PDU session establishment request #22 includes ePCO #11.
- the specific implementation method of the above steps S601 to S608, as well as the specific name or meaning of the interactive message, can refer to the relevant description of steps S401 to S405 and S407 to S409 of the above method 400. For the sake of brevity, they will not be repeated here.
- the H-SMF determines that the HR-SBO PDU session is authorized according to the HR-SBO authorization indication and/or HR-SBO authorization information carried in the SDM information of step S608, and further generates ePCO#22.
- ePCO#22 includes the security information of the H-DNS server and the address of the H-DNS server.
- the H-SMF may determine to include the security information of the corresponding H-DNS server in ePCO#22 based on the local policy and/or the user plane security policy of the PDU session.
- H-SMF sends a PDU session establishment response #22 to V-SMF; correspondingly, V-SMF receives a PDU session establishment response #22 from H-SMF.
- the PDU session establishment response #22 includes ePCO #22.
- the PDU session establishment response #22 may also include an HR-SBO authorization indication or HR-SBO authorization information; if the ePCO#11 received by the H-SMF in step S606 includes a DNS server security information indication, and/or DNS server security protocol support, the PDU session establishment response #22 may also include a DNS server security information indication, and/or DNS server security protocol support.
- V-SMF determines whether to provide the security information #a of V-EASDF.
- the specific implementation method of the above steps S615 to S618, as well as the specific name of the interaction message can refer to the relevant description of steps S412 and S415 of the above method 400. For the sake of brevity, they will not be repeated here.
- V-SMF sends the address of V-EASDF and the security information #a of V-EASDF to H-SMF according to the HR-SBO authorization indication from H-SMF when determining to initiate the HR-SBO PDU session, so that H-SMF can send ePCO#33 containing the security information #b of V-EASDF to UE.
- the DNS messages exchanged between V-EASDF and UE can be protected to maintain network security communication.
- AMF sends an N1SM container to the UE; correspondingly, the UE receives the N1SM container from the AMF.
- the processor in the embodiment of the present application can be an integrated circuit chip with signal processing capabilities.
- each step of the above method embodiment can be completed by an integrated logic circuit of hardware in the processor or an instruction in the form of software.
- the above processor can be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.
- the processor in the embodiment of the present application can implement or execute the methods, steps and logic block diagrams disclosed in the embodiment of the present application.
- the general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
- the logic circuit 3010 can be a processing circuit in the chip system 3000.
- the logic circuit 3010 can be coupled to the storage unit and call the instructions in the storage unit so that the chip system 3000 can implement the methods and functions of each embodiment of the present application.
- the input/output interface 3020 can be an input/output circuit in the chip system 3000, outputting information processed by the chip system 3000, or inputting data or signaling information to be processed into the chip system 3000 for processing.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Databases & Information Systems (AREA)
- Mobile Radio Communication Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (52)
- 一种通信方法,其特征在于,所述方法应用于建立或修改终端设备的会话过程中,包括:拜访地的会话管理功能网元获取位于所述拜访地的域名系统DNS服务器的安全信息和所述DNS服务器的标识,所述安全信息用于所述终端设备与所述DNS服务器之间建立安全连接;所述拜访地的会话管理功能网元向归属地的会话管理功能网元发送所述安全信息和所述DNS服务器的标识;所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的协议配置选项PCO,所述PCO包括所述安全信息和所述DNS服务器的标识;所述拜访地的会话管理功能网元将所述PCO发送给所述终端设备。
- 根据权利要求1所述的方法,其特征在于,所述安全信息包括用于认证所述DNS服务器的凭证。
- 根据权利要求2所述的方法,其特征在于,所述安全信息还包括所述DNS服务器支持的一种或者多种安全协议类型,和/或建立所述安全连接所使用的端口号。
- 根据权利要求2所述的方法,其特征在于,在所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的PCO之前,所述方法还包括:所述拜访地的会话管理功能网元向所述归属地的会话管理功能网元发送所述DNS服务器支持的一种或者多种安全协议类型,和/或建立所述安全连接所使用的端口号;其中,所述PCO中还包括所述DNS服务器支持的一种或者多种安全协议类型中的一个或者多个安全协议类型和/或所述端口号。
- 根据权利要求1至4中任一项所述的方法,其特征在于,来自所述归属地的会话管理功能网元的所述PCO为第一PCO;在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息之前,所述方法还包括:所述拜访地的会话管理功能网元接收来自所述终端设备的第二PCO,其中,所述第二PCO包括用于指示所述终端设备支持基于安全协议对DNS消息进行安全保护的指示信息;所述拜访地的会话管理功能网元向所述归属地的会话管理功能网元发送所述第二PCO;所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的请求消息,所述请求消息包括所述指示信息;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息,包括:响应于所述指示信息,所述拜访地的会话管理功能网元获取所述安全信息。
- 根据权利要求1至4中任一项所述的方法,其特征在于,在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息和所述DNS服务器的标识之前,所述方法还包括:所述拜访地的会话管理功能网元接收来自移动和接入管理功能网元的归属地路由会话疏导HR-SBO允许指示;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息和所述DNS服务器的标识,包括:所述拜访地的会话管理功能网元根据所述HR-SBO允许指示,获取所述安全信息和所述DNS服务器的标识。
- 根据权利要求1至4中任一项所述的方法,其特征在于,在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息之前,所述方法还包括:所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的所述归属地的网络标识;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息,包括:所述拜访地的会话管理功能网元根据所述终端设备的所述网络标识,获取所述安全信息。
- 根据权利要求1至7中任一项所述的方法,其特征在于,所述方法还包括:所述拜访地的会话管理功能网元获取策略信息,所述策略信息用于指示所述归属地的会话管理功能网元向所述终端设备发送所述安全信息的触发条件;所述拜访地的会话管理功能网元向所述归属地的会话管理功能网元发送所述策略信息。
- 根据权利要求1至4中任一项所述的方法,其特征在于,在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息之前,所述方法还包括:所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的与所述会话对应的用户面安全策略;其中,所述用户面安全策略指示不开启或者可选开启用户面安全保护;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息,包括:所述拜访地的会话管理功能网元根据所述用户面安全策略,获取所述安全信息。
- 根据权利要求1至4中任一项所述的方法,其特征在于,在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息和所述DNS服务器的标识之前,所述方法还包括:所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的HR-SBO授权信息;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息和所述DNS服务器的标识,包括:所述拜访地的会话管理功能网元根据所述HR-SBO授权信息,获取所述安全信息和所述DNS服务器的标识。
- 根据权利要求10所述的方法,其特征在于,所述拜访地的会话管理功能网元根据所述HR-SBO授权信息,获取所述安全信息和所述DNS服务器的标识,包括:在确定所述终端设备满足HR-SBO会话建立条件的情况下,所述拜访地的会话管理功能网元根据所述HR-SBO授权信息,获取所述安全信息和所述DNS服务器的标识。
- 根据权利要求1至11中任一项所述的方法,其特征在于,所述DNS服务器为边缘服务器发现功能网元。
- 根据权利要求1至12中任一项所述的方法,其特征在于,所述方法还包括:所述拜访地的会话管理功能网元接收来自网络功能存储库功能网元的所述安全信息。
- 一种通信方法,其特征在于,所述方法应用于建立或修改终端设备的会话过程中,包括:归属地的会话管理功能网元接收来自拜访地的会话管理功能网元的域名系统DNS服务器的安全信息和所述DNS服务器的标识,所述安全信息用于所述终端设备与所述DNS服务器之间建立安全连接;所述归属地的会话管理功能网元生成协议配置选项PCO,所述PCO包括所述安全信息和所述DNS服务器的标识;所述归属地的会话管理功能网元通过所述拜访地的会话管理功能网元向所述终端设备发送所述PCO。
- 根据权利要求14所述的方法,其特征在于,所述安全信息包括用于认证所述DNS服务器的凭证。
- 根据权利要求15所述的方法,其特征在于,所述安全信息还包括所述DNS服务器支持的一种或者多种安全协议类型,和/或建立所述安全连接所使用的端口号。
- 根据权利要求15所述的方法,其特征在于,在所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送所述PCO之前,所述方法还包括:所述归属地的会话管理功能网元接收来自所述拜访地的会话管理功能网元的所述DNS服务器支持的一种或者多种安全协议类型,和/或建立所述安全连接所使用的端口号;其中,所述PCO中还包括所述DNS服务器支持的一种或者多种安全协议类型中的一个或者多个安全协议类型和/或所述端口号。
- 根据权利要求14至17中任一项所述的方法,其特征在于,所述方法还包括:所述归属地的会话管理功能网元向统一数据管理功能网元发送签约数据管理请求消息;所述归属地的会话管理功能网元接收来自所述统一数据管理功能网元的签约数据管理响应消息,其中,所述签约数据管理响应消息包括归属地路由会话疏导HR-SBO授权信息;其中,所述归属地的会话管理功能网元生成PCO,包括:响应于所述HR-SBO授权信息,所述归属地的会话管理功能网元生成所述PCO。
- 根据权利要求14至18中任一项所述的方法,其特征在于,在所述归属地的会话管理功能网元接收来自拜访地的会话管理功能网元的DNS服务器的安全信息之前,所述方法还包括:所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送所述HR-SBO授权信息,所述HR-SBO授权信息用于请求获取所述安全信息和所述DNS服务器的标识。
- 根据权利要求14至18中任一项所述的方法,其特征在于,所述归属地的会话管理功能网元生成的PCO为第一PCO;在所述归属地的会话管理功能网元生成PCO之前,所述方法还包括:所述归属地的会话管理功能网元接收来自所述拜访地的会话管理功能网元的第二PCO,所述第二 PCO包括用于指示所述终端设备支持基于安全协议对DNS消息进行安全保护的指示信息;所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送请求消息,所述请求消息包括所述指示信息。
- 根据权利要求20所述的方法,其特征在于,所述第二PCO还包括所述终端设备支持的一种或者多种安全协议类型;其中,所述归属地的会话管理功能网元生成PCO,包括:所述归属地的会话管理功能网元根据所述终端设备支持的一种或者多种安全协议类型,以及所述DNS服务器支持的一种或者多种安全协议类型,生成所述第一PCO,其中,所述第一PCO还包括所述DNS服务器与所述终端设备都支持的一个或者多个安全协议类型。
- 根据权利要求14至18中任一项所述的方法,其特征在于,在所述归属地的会话管理功能网元生成PCO之前,所述方法还包括:所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送用户面安全策略,其中,所述用户面安全策略用于指示不开启或者可选开启用户面安全保护。
- 根据权利要求14至18中任一项所述的方法,其特征在于,在所述归属地的会话管理功能网元生成PCO之前,所述方法还包括:所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送所述归属地的网络标识。
- 根据权利要求14至22中任一项所述的方法,其特征在于,所述归属地的会话管理功能网元生成PCO,包括:所述归属地的会话管理功能网元接收来自所述拜访地的会话管理功能网元的策略信息;其中,所述策略信息用于指示所述归属地的会话管理功能网元向所述终端设备发送所述安全信息的触发条件;在满足所述触发条件的情况下,所述归属地的会话管理功能网元生成所述PCO。
- 根据权利要求14至24中任一项所述的方法,其特征在于,所述DNS服务器为边缘服务器发现功能网元。
- 一种通信方法,其特征在于,所述方法应用于建立或修改终端设备的会话过程中,包括:通信装置通过拜访地的会话管理功能网元向归属地的会话管理功能网元发送第二协议配置选项PCO,所述第二PCO包括用于指示所述通信装置支持基于安全协议对DNS消息进行安全保护的指示信息;所述通信装置通过所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的第一PCO,其中,所述第一PCO包括所安全信息和位于所述拜访地的域名系统DNS服务器的标识;所述通信装置基于所述安全信息,建立与所述DNS服务器之间安全连接。
- 根据权利要求26所述的方法,其特征在于,所述安全信息包括用于认证所述DNS服务器的凭证。
- 根据权利要求27所述的方法,其特征在于,所述安全信息还包括所述DNS服务器支持的一种或者多种安全协议类型,和/或建立所述安全连接所使用的端口号。
- 根据权利要求26至28中任一项所述的方法,其特征在于,所述第二PCO还包括所述通信装置支持的一种或者多种安全协议类型;其中,所述第一PCO还包括所述DNS服务器支持的一种或者多种安全协议类型中的一个或者多个安全协议类型。
- 根据权利要求24至27中任一项所述的方法,其特征在于,所述DNS服务器为边缘服务器发现功能网元。
- 一种通信方法,其特征在于,所述方法应用于建立或修改终端设备的会话过程中,包括:拜访地的会话管理功能网元获取位于所述拜访地的域名系统DNS服务器的安全信息和所述DNS服务器的标识,所述安全信息用于所述终端设备与所述DNS服务器之间建立安全连接;所述拜访地的会话管理功能网元向归属地的会话管理功能网元发送所述安全信息和所述DNS服务器的标识,所述归属地的会话管理功能网元接收来自所述拜访地的会话管理功能网元的所述安全信息和所述DNS服务器的标识;所述归属地的会话管理功能网元生成协议配置选项PCO,所述PCO包括所述安全信息和所述DNS服务器的标识;所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送所述PCO,所述拜访地的会 话管理功能网元接收来自所述归属地的会话管理功能网元的PCO;所述拜访地的会话管理功能网元将所述PCO发送给所述终端设备,所述终端设备接收来自所述拜访地的会话管理功能网元的所述PCO。
- 根据权利要求31所述的方法,其特征在于,所述方法还包括:所述通信装置基于所述安全信息,建立与所述DNS服务器之间安全连接。
- 根据权利要求31或32所述的方法,其特征在于,所述安全信息包括用于认证所述DNS服务器的凭证。
- 根据权利要求33所述的方法,其特征在于,所述安全信息还包括所述DNS服务器支持的一种或者多种安全协议类型,和/或建立所述安全连接所使用的端口号。
- 根据权利要求31至34中任一项所述的方法,其特征在于,在所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送所述PCO之前,所述方法还包括:所述拜访地的会话管理功能网元向所述归属地的会话管理功能网元发送所述DNS服务器支持的一种或者多种安全协议类型,和/或建立所述安全连接所使用的端口号,所述归属地的会话管理功能网元接收来自所述拜访地的会话管理功能网元的所述DNS服务器支持的一种或者多种安全协议类型,和/或建立所述安全连接所使用的端口号;其中,所述PCO中还包括所述DNS服务器支持的一种或者多种安全协议类型中的一个或者多个安全协议类型和/或所述端口号。
- 根据权利要求31至35中任一项所述的方法,其特征在于,所述归属地的会话管理功能网元生成的PCO为第一PCO;在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息之前,所述方法还包括:所述终端设备向所述拜访地的会话管理功能网元发送第二PCO,所述拜访地的会话管理功能网元接收来自所述终端设备的第二PCO,其中,所述第二PCO包括用于指示所述终端设备支持基于安全协议对DNS消息进行安全保护的指示信息;所述拜访地的会话管理功能网元向所述归属地的会话管理功能网元发送所述第二PCO,所述归属地的会话管理功能网元接收来自所述拜访地的会话管理功能网元的所述第二PCO;所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送请求消息,所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的请求消息,所述请求消息包括所述指示信息;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息,包括:响应于所述指示信息,所述拜访地的会话管理功能网元获取所述安全信息。
- 根据权利要求36所述的方法,其特征在于,所述第二PCO还包括所述终端设备支持的一种或者多种安全协议类型;其中,所述归属地的会话管理功能网元生成PCO,包括:所述归属地的会话管理功能网元根据所述终端设备支持的一种或者多种安全协议类型,以及所述DNS服务器支持的一种或者多种安全协议类型,生成所述第一PCO,其中,所述第一PCO还包括所述DNS服务器与所述终端设备都支持的一个或者多个安全协议类型。
- 根据权利要求31至35中任一项所述的方法,其特征在于,在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息和所述DNS服务器的标识之前,所述方法还包括:移动和接入管理功能网元向所述拜访地的会话管理功能网元发送归属地路由会话疏导HR-SBO允许指示,所述拜访地的会话管理功能网元接收来自所述移动和接入管理功能网元的归属地路由会话疏导HR-SBO允许指示;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息和所述DNS服务器的标识,包括:所述拜访地的会话管理功能网元根据所述HR-SBO允许指示,获取所述安全信息和所述DNS服务器的标识。
- 根据权利要求31至35中任一项所述的方法,其特征在于,所述方法还包括:所述归属地的会话管理功能网元向统一数据管理功能网元发送签约数据管理请求消息,所述统一数据管理功能网元接收来自所述归属地的会话管理功能网元的所述签约数据管理请求消息;所述统一数据管理功能网元向所述归属地的会话管理功能网元发送签约数据管理响应消息,所述归 属地的会话管理功能网元接收来自所述统一数据管理功能网元的所述签约数据管理响应消息,其中,所述签约数据管理响应消息包括HR-SBO授权信息;其中,所述归属地的会话管理功能网元生成PCO,包括:响应于所述HR-SBO授权信息,所述归属地的会话管理功能网元生成所述PCO。
- 根据权利要求39所述的方法,其特征在于,在所述归属地的会话管理功能网元接收来自拜访地的会话管理功能网元的DNS服务器的安全信息之前,所述方法还包括:所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送所述HR-SBO授权信息,所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的所述HR-SBO授权信息,所述HR-SBO授权信息用于请求获取所述安全信息和所述DNS服务器的标识;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息和所述DNS服务器的标识,包括:所述拜访地的会话管理功能网元根据所述HR-SBO授权信息,获取所述安全信息和所述DNS服务器的标识。
- 根据权利要求40所述的方法,其特征在于,所述拜访地的会话管理功能网元根据所述HR-SBO授权信息,获取所述安全信息和所述DNS服务器的标识,包括:在确定所述终端设备满足HR-SBO会话建立条件的情况下,所述拜访地的会话管理功能网元根据所述HR-SBO授权信息,获取所述安全信息和所述DNS服务器的标识。
- 根据权利要求31至41中任一项所述的方法,其特征在于,在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息之前,所述方法还包括:所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送用户面安全策略,所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的所述用户面安全策略,其中,所述用户面安全策略指示不开启或者可选开启用户面安全保护;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息,包括:所述拜访地的会话管理功能网元根据所述用户面安全策略,获取所述安全信息。
- 根据权利要求31至41中任一项所述的方法,其特征在于,在所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息之前,所述方法还包括:所述归属地的会话管理功能网元向所述拜访地的会话管理功能网元发送所述归属地的网络标识,所述拜访地的会话管理功能网元接收来自所述归属地的会话管理功能网元的所述归属地的网络标识;其中,所述拜访地的会话管理功能网元获取位于所述拜访地的DNS服务器的安全信息,包括:所述拜访地的会话管理功能网元根据所述终端设备的所述网络标识,获取所述安全信息。
- 根据权利要求31至43中任一项所述的方法,其特征在于,所述归属地的会话管理功能网元生成PCO,包括:所述拜访地的会话管理功能网元获取策略信息,所述策略信息用于指示所述归属地的会话管理功能网元向所述终端设备发送所述安全信息的触发条件;所述拜访地的会话管理功能网元向所述归属地的会话管理功能网元发送所述策略信息,所述归属地的会话管理功能网元接收来自所述拜访地的会话管理功能网元的所述策略信息;在满足所述触发条件的情况下,所述归属地的会话管理功能网元生成所述PCO。
- 根据权利要求31至44中任一项所述的方法,其特征在于,所述DNS服务器为边缘服务器发现功能网元。
- 一种通信系统,其特征在于,包括:拜访地的会话管理功能网元和归属地的会话管理功能网元,其中,所述拜访地的会话管理功能网元用于执行如权利要求1至13中任一项所述的方法,所述归属地的会话管理功能网元用于执行如权利要求14至25中任一项所述的方法。
- 根据权利要求46所述的通信系统,其特征在于,所述通信系统还包括终端设备,所述终端设备用于执行如权利要求26至30中任一项所述的方法。
- 一种通信装置,其特征在于,包括:一个或多个功能模块,所述一个或多个功能模块或网元用于执行如权利要求1至13中任一项所述的方法,或者,所述一个或多个功能模块或网元用于执行如权利要求14至25中任一项所述的方法,或者,所述一个或多个功能模块或网元用于执行如权利要求26至30 中任一项所述的方法。
- 一种通信装置,其特征在于,包括:处理器,所述处理器与存储器耦合;所述处理器,用于执行所述存储器中存储的计算机程序,以使得所述装置执行如权利要求1至13中任一项所述的方法,或者以使得所述装置执行如权利要求14至25中任一项所述的方法,或者以使得所述装置执行如权利要求26至30中任一项所述的方法。
- 一种计算机可读存储介质,其特征在于,包括:所述计算机可读存储介质上存储有计算机程序代码或指令,当所述计算机程序代码或指令运行时,使得所述计算机执行如权利要求1至13中任一项所述的方法,或者使得所述计算机执行如权利要求14至25中任一项所述的方法,或者使得所述计算机执行如权利要求26至30中任一项所述的方法。
- 一种计算机程序产品,其特征在于,所述计算机程序产品被通信装置执行时,实现如权利要求1至13中任一项所述的方法,或者实现如权利要求14至25中任一项所述的方法,或者实现如权利要求26至30中任一项所述的方法。
- 一种芯片,其特征在于,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的通信装置执行如权利要求1至13中任一项所述的方法,或者使得安装有所述芯片的通信装置执行如权利要求14至25中任一项所述的方法,或者使得安装有所述芯片的通信装置执行如权利要求26至30中任一项所述的方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP24738515.6A EP4642072A4 (en) | 2023-01-06 | 2024-01-04 | COMMUNICATION METHOD AND COMMUNICATION APPARATUS |
| US19/261,662 US20250338123A1 (en) | 2023-01-06 | 2025-07-07 | Communication method and communication apparatus |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202310021264.4A CN118317301A (zh) | 2023-01-06 | 2023-01-06 | 通信方法和通信装置 |
| CN202310021264.4 | 2023-01-06 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US19/261,662 Continuation US20250338123A1 (en) | 2023-01-06 | 2025-07-07 | Communication method and communication apparatus |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024146582A1 true WO2024146582A1 (zh) | 2024-07-11 |
Family
ID=91728166
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/070490 Ceased WO2024146582A1 (zh) | 2023-01-06 | 2024-01-04 | 通信方法和通信装置 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20250338123A1 (zh) |
| EP (1) | EP4642072A4 (zh) |
| CN (1) | CN118317301A (zh) |
| WO (1) | WO2024146582A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20250350949A1 (en) * | 2024-05-10 | 2025-11-13 | Lenovo (Singapore) Pte. Ltd. | Apparatus and method for security event monitoring in a wireless communications system |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20200366794A1 (en) * | 2017-08-11 | 2020-11-19 | Samsung Electronics Co., Ltd. | Manual roaming and data usage rights |
| CN112188574A (zh) * | 2018-05-21 | 2021-01-05 | 华为技术有限公司 | 切换方法、设备及系统 |
| CN114125808A (zh) * | 2021-11-29 | 2022-03-01 | 中国联合网络通信集团有限公司 | 一种边缘应用服务器的发现方法及装置 |
| CN114286335A (zh) * | 2020-09-17 | 2022-04-05 | 华为技术有限公司 | 一种服务器选择方法和装置 |
-
2023
- 2023-01-06 CN CN202310021264.4A patent/CN118317301A/zh active Pending
-
2024
- 2024-01-04 WO PCT/CN2024/070490 patent/WO2024146582A1/zh not_active Ceased
- 2024-01-04 EP EP24738515.6A patent/EP4642072A4/en active Pending
-
2025
- 2025-07-07 US US19/261,662 patent/US20250338123A1/en active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20200366794A1 (en) * | 2017-08-11 | 2020-11-19 | Samsung Electronics Co., Ltd. | Manual roaming and data usage rights |
| CN112188574A (zh) * | 2018-05-21 | 2021-01-05 | 华为技术有限公司 | 切换方法、设备及系统 |
| CN114286335A (zh) * | 2020-09-17 | 2022-04-05 | 华为技术有限公司 | 一种服务器选择方法和装置 |
| CN114125808A (zh) * | 2021-11-29 | 2022-03-01 | 中国联合网络通信集团有限公司 | 一种边缘应用服务器的发现方法及装置 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP4642072A1 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20250338123A1 (en) | 2025-10-30 |
| CN118317301A (zh) | 2024-07-09 |
| EP4642072A1 (en) | 2025-10-29 |
| EP4642072A4 (en) | 2026-03-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3817423B1 (en) | Network access method, related device, and system | |
| CN116193431B (zh) | 切片认证方法及装置 | |
| WO2020029938A1 (zh) | 安全会话方法和装置 | |
| CN108574969A (zh) | 多接入场景中的连接处理方法和装置 | |
| EP4030798A1 (en) | Method for implementing external authentication, communication device and communication system | |
| US20250365578A1 (en) | Communication method and communication apparatus | |
| US20240292219A1 (en) | Method and device for operating terminal in wireless communication system | |
| US12470917B2 (en) | Registering a user equipment to a communication network | |
| US20250227465A1 (en) | Communication method and communication apparatus | |
| US20250338123A1 (en) | Communication method and communication apparatus | |
| EP4564866A1 (en) | Communication method and communication apparatus | |
| JP2017143363A (ja) | 通信システム及びその認証接続方法 | |
| WO2024169468A1 (zh) | 通信方法和通信装置 | |
| CN120380786A (zh) | 用于针对归属路由会话疏导向vplmn传达业务卸载策略的方法和装置 | |
| WO2024094108A1 (zh) | 通信方法和通信装置 | |
| EP4661339A1 (en) | Communication method and communication apparatus | |
| EP4456508A1 (en) | Policy configuration method and apparatus | |
| WO2025031156A1 (zh) | 通信方法和通信装置 | |
| WO2025031157A1 (zh) | 通信方法和通信装置 | |
| WO2025167553A1 (zh) | 通信方法和相关装置 | |
| WO2024235111A1 (zh) | 一种通信方法和通信装置 | |
| WO2025209303A1 (zh) | 通信方法和通信装置 | |
| WO2023160390A1 (zh) | 通信方法与装置 | |
| WO2024146315A1 (zh) | 通信方法和通信装置 | |
| WO2025167832A1 (zh) | 一种通信方法和通信装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24738515 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202547066922 Country of ref document: IN |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024738515 Country of ref document: EP |
|
| REG | Reference to national code |
Ref country code: BR Ref legal event code: B01A Ref document number: 112025014037 Country of ref document: BR |
|
| WWP | Wipo information: published in national office |
Ref document number: 202547066922 Country of ref document: IN |
|
| ENP | Entry into the national phase |
Ref document number: 2024738515 Country of ref document: EP Effective date: 20250721 |
|
| ENP | Entry into the national phase |
Ref document number: 2024738515 Country of ref document: EP Effective date: 20250721 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2024738515 Country of ref document: EP Effective date: 20250721 |
|
| WWP | Wipo information: published in national office |
Ref document number: 2024738515 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 112025014037 Country of ref document: BR Kind code of ref document: A2 Effective date: 20250707 |