A user information privacy protection method and related apparatus

By performing an XOR operation on the key identifier and the AF's identity identifier, a key identifier calculated according to the target rule is generated. After being parsed and authenticated by the target network element, it is sent to the AF, thus solving the problem of AKMA key identifier abuse and realizing the privacy protection of user information.

CN116709302BActive Publication Date: 2026-02-17CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310850072.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-12
Publication Date
2026-02-17
Estimated Expiration
2043-07-12

AI Technical Summary

Technical Problem

In existing technologies, when a UE and AF establish a session, the AKMA key identifier is easily intercepted and misused, leading to the leakage of user information privacy.

Method used

By performing an XOR operation on the key identifier and the AF's identity identifier, a key identifier calculated according to the target rule is generated. After being parsed and authenticated by the target network element, it is sent to the AF to ensure that only a legitimate AF can obtain the key.

Benefits of technology

It effectively prevents the abuse of AKMA key identifiers, protects user information privacy, and prevents unauthorized network entities from obtaining the UE's private information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116709302B_ABST
    Figure CN116709302B_ABST
Patent Text Reader

Abstract

The application discloses a user information privacy protection method and related devices. After receiving a session establishment request sent by a UE, an AF sends a key identifier calculated according to a target rule and an identity identifier of the AF to a target network element, so that the target network element determines a key of the AF according to the key identifier calculated according to the target rule and the identity identifier of the AF. Then, the AF receives the key of the AF sent by the target network element, and responds to the session establishment request based on the key of the AF. By calculating the key identifier according to the target rule, other AFs can be prevented from using the key identifier after obtaining the key identifier, so that the AKMA key identifier is prevented from being abused.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of network technology and security technology, and in particular to a method and related apparatus for protecting user information privacy. Background Technology

[0002] Currently, the Authentication and Key Management for Applications (AKMA) mechanism is defined in 3GPP TS 33.535. This mechanism can establish a shared key between User Equipment (UE) and Application Function (AF), and the shared key can be used for session creation between the UE and AF.

[0003] In existing technologies, when a UE and an AF establish a session, the UE sends a session establishment request to the AF, and the session establishment request carries an AKMA key identifier. At this time, other AFs authorized to provide AKMA services can act as intermediaries to intercept the AKMA key identifier and send the intercepted AKMA key identifier and their own AF identity identifier to the target network element, thereby obtaining the keys of other AFs sent by the target network element. This can lead to the abuse of the AKMA key identifier. Summary of the Invention

[0004] This application provides a method and related apparatus for protecting user information privacy, thereby preventing the misuse of key identifiers.

[0005] In a first aspect, one embodiment of this application provides a user information privacy protection method applied to application function AF, the method comprising:

[0006] Receive a session establishment request sent by a user terminal (UE); wherein the session establishment request includes at least a key identifier calculated by the target rule;

[0007] The key identifier calculated by the target rule and the identity identifier of the AF are sent to the target network element so that the target network element can determine the key of the AF based on the key identifier calculated by the target rule and the identity identifier of the AF.

[0008] Receive the key of the AF sent by the target network element;

[0009] Based on the key of the AF, respond to the session establishment request.

[0010] Compared to existing technologies, this application calculates the key identifier according to the target rules, which can prevent other AFs from obtaining and using the key identifier, thus avoiding the abuse of the AKMA key identifier.

[0011] In one possible design, the target rule is calculated by XORing the key identifier and the identity identifier of the AF.

[0012] This application avoids the misuse of key identifiers by setting target rules to calculate key identifiers.

[0013] In one possible design, after sending the key identifier calculated according to the target rule and the identity identifier of the AF to the target network element, the method further includes:

[0014] Receive the privacy information of the UE sent by the target network element;

[0015] Based on the key of the AF, respond to the session establishment request, including:

[0016] Based on the AF's key and the UE's privacy information, the session establishment request is responded to.

[0017] This application will only send the UE's privacy information to the AF after the target network element has successfully authenticated the key identifier and the AF's identity identifier, thus avoiding the leakage of the UE's privacy information.

[0018] Secondly, one embodiment of this application provides a user information privacy protection method, applied to a target network element, the method comprising:

[0019] Receive the key identifier calculated based on the target rule and the identity identifier of the AF sent by the AF;

[0020] Based on the identity identifier of the AF, the key identifier calculated by the target rule is parsed;

[0021] Based on the parsing results and the identity identifier of the AF, the key of the AF is determined;

[0022] The key of the AF is sent to the AF so that the AF responds to the session establishment request sent by the UE based on the key of the AF.

[0023] In one possible design, the target rule is calculated by XORing the key identifier and the identity identifier of the AF;

[0024] The process of parsing the key identifier calculated based on the identity identifier of the AF, including:

[0025] Perform an XOR operation on the identity identifier of the AF and the key identifier calculated by the target rule.

[0026] In one possible design, when the UE subscribes to the application for authentication and key management AKMA service, determining the key of the AF based on the parsing result and the identity identifier of the AF includes:

[0027] Based on the parsing results, the key for the AKMA is determined;

[0028] The key of the AF is determined based on the key of the AKMA and the identity identifier of the AF.

[0029] In one possible design, after determining the key of the AF, the method further includes:

[0030] The UE's privacy information is sent to the AF.

[0031] In one possible design, before parsing the key identifier calculated based on the identity identifier of the AF, the method further includes:

[0032] The AF is authenticated based on its identity identifier.

[0033] Thirdly, one embodiment of this application provides a user information privacy protection system, the system comprising: AF, target network element, and UE;

[0034] The UE is configured to calculate the key identifier based on the target rule, and create a session establishment request based on the calculated key identifier; and send the session establishment request to the AF;

[0035] The AF is used to send the calculated key identifier and the identity identifier of the AF to the target network element;

[0036] The target network element is used to parse the calculated key identifier based on the identity identifier of the AF; determine the key of the AF based on the parsing result and the identity identifier of the AF; and send the key of the AF to the AF.

[0037] The AF is also used to respond to the session establishment request based on the key of the AF.

[0038] Fourthly, one embodiment of this application provides a user information privacy protection device, the device comprising:

[0039] The first receiving module is used to receive a session establishment request sent by a user terminal (UE); wherein the session establishment request includes at least a key identifier calculated by the target rule.

[0040] The first sending module is used to send the key identifier calculated by the target rule and the identity identifier of the AF to the target network element, so that the target network element can determine the key of the AF according to the key identifier calculated by the target rule and the identity identifier of the AF;

[0041] The second receiving module is used to receive the key of the AF sent by the target network element;

[0042] A response module is used to respond to the session establishment request based on the key of the AF.

[0043] In one possible design, the target rule is calculated by XORing the key identifier and the identity identifier of the AF.

[0044] In one possible design, the second receiving module is further used for:

[0045] Receive the privacy information of the UE sent by the target network element;

[0046] The response module is specifically used for:

[0047] Based on the AF's key and the UE's privacy information, the session establishment request is responded to.

[0048] Fifthly, one embodiment of this application provides a user information privacy protection device, the device comprising:

[0049] The third receiving module is used to receive the key identifier after the target rule calculation and the identity identifier of the AF sent by the AF;

[0050] The parsing module is used to parse the key identifier calculated by the target rule based on the identity identifier of the AF;

[0051] The determination module is used to determine the key of the AF based on the parsing result and the identity identifier of the AF;

[0052] The second sending module is used to send the key of the AF to the AF, so that the AF responds to the session establishment request sent by the UE based on the key of the AF.

[0053] In one possible design, the target rule is calculated by XORing the key identifier and the identity identifier of the AF;

[0054] The parsing module is specifically used for:

[0055] Perform an XOR operation on the identity identifier of the AF and the key identifier calculated by the target rule.

[0056] In one possible design, when the UE subscribes to the application for authentication and key management AKMA services, the determining module is specifically used for:

[0057] Based on the parsing results, the key for the AKMA is determined;

[0058] The key of the AF is determined based on the key of the AKMA and the identity identifier of the AF.

[0059] In one possible design, the second transmitting module is further used for:

[0060] The UE's privacy information is sent to the AF.

[0061] In one possible design, the third receiving module is further configured to:

[0062] The AF is authenticated based on its identity identifier.

[0063] Sixthly, one embodiment of this application provides an electronic device, including:

[0064] Processor and display;

[0065] The display is used to show the user interface;

[0066] The processor is configured to perform any of the methods provided in the first aspect above, or to perform any of the methods provided in the second aspect above.

[0067] In a seventh aspect, one embodiment of this application also provides a computer-readable storage medium, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is able to perform any of the methods provided in the first aspect above, or perform any of the methods provided in the second aspect above.

[0068] Eighthly, one embodiment of this application provides a computer program product including a computer program / instructions, which is executed by a processor using any of the methods provided in the first aspect above, or any of the methods provided in the second aspect above.

[0069] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0070] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0071] Figure 1 This is a schematic diagram illustrating an application scenario of a user information privacy protection system provided in an embodiment of this application;

[0072] Figure 2 This is a schematic flowchart of a user information privacy protection method provided in an embodiment of this application;

[0073] Figure 3 This is a schematic flowchart of a user information privacy protection method provided in an embodiment of this application;

[0074] Figure 4 This is a schematic flowchart of a user information privacy protection method provided in an embodiment of this application;

[0075] Figure 5 This is a schematic diagram of the structure of a user information privacy protection device provided in an embodiment of this application;

[0076] Figure 6 This is a schematic diagram of the structure of a user information privacy protection device provided in an embodiment of this application;

[0077] Figure 7 A schematic diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0078] To enable those skilled in the art to better understand the technical solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0079] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data used can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0080] Currently, the AKMA mechanism is defined in 3GPP TS 33.535. This mechanism can establish a shared key between the UE and AF, and the shared key can be used for session creation between the UE and AF.

[0081] In existing technologies, when a UE and an AF establish a session, the UE sends a session establishment request to the AF, and the session establishment request carries an AKMA key identifier. At this time, other AFs authorized to provide AKMA services can act as intermediaries to intercept the AKMA key identifier and send the intercepted AKMA key identifier and their own AF identity identifier to the target network element, thereby obtaining the keys of other AFs sent by the target network element. This can lead to the abuse of the AKMA key identifier.

[0082] Therefore, this application provides a method and related apparatus for protecting user information privacy. By calculating the key identifier according to the target rule, it can prevent other AFs from obtaining the key identifier and using it, thus avoiding the abuse of the AKMA key identifier.

[0083] After introducing the design concept of the embodiments of this application, the following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application can be applied. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.

[0084] refer to Figure 1 This diagram illustrates an application scenario of a user information privacy protection system provided in this application. The application scenario includes UE101, AAnF102, AF103, and AUSF104. Here, AAnF102, AUSF104, and UDM105 are all located in the 5G core network. This is merely an example using AAnF102 as the target network element; this application does not limit the interaction between UE101 and specific network elements in the 5G core network.

[0085] When UE101 subscribes to the AKMA service, after UE101 sends the master authentication to AUSF104 via gNB and the authentication is successful, UE101 and AUSF104 will each generate an AKMA key (e.g., using K). AKMA The AUSF104 will send the AKMA key and key identifier (e.g., A-KID) to the AAnF102.

[0086] For example, the format of A-KID can be username@realm, where username includes Router-identifier (RID) and AKMA temporary UE identity identifier (represented by A-TID), and realm includes HN identifier (represented by HNI).

[0087] After generating the AKMA key and key identifier, UE101 calculates the key identifier based on the target rule and creates a session establishment request based on the calculated key identifier; it then sends the session establishment request, which includes at least the calculated key identifier, to AF103.

[0088] Furthermore, the target rule calculation involves XORing the A-TID in the key identifier with the identity identifier of the AF (e.g., represented by AF-ID) to obtain the result A-AKID. For example, A-AKID = A-TID ⊕ AF-ID. The session establishment request may also include RID and HNI. AF-ID may also include information such as the AF's FQDN and Ua* identifier.

[0089] Here, as Figure 1 As shown, UE101 may include a calculation module 101-1, which calculates the key identifier according to the target rule. This is only an example illustrating how the target rule calculates the key identifier, and this application does not limit the specific method by which the target rule calculates the key identifier.

[0090] After receiving the session establishment request from UE101, if AF103 does not have the A-KID-related context, it can send the calculated key identifier and AF-ID from the session establishment request to AAnF102. Upon receiving the calculated key identifier and AF identity identifier from AF103, AAnF102 parses the calculated key identifier based on the AF identity identifier and determines the AF's key based on the parsing result and the AF identity identifier. Then, it sends the AF's key to AF103, enabling AF103 to respond to the session establishment request based on the AF's key.

[0091] Here, as Figure 1 As shown, AAnF102 may include an AF-ID authentication module 102-1, an A-TID parsing module 102-2, and an A-TID authentication module 102-3.

[0092] To ensure the authenticity of the AF103 identity when UE101 requests to create a session, the AF-ID received by AAnF102 can be authenticated through the AF-ID authentication module 102-1. For example, the AF-ID can be obtained during the authentication process between the 5G core network and AF103, and then compared with the AF-ID received by AAnF102.

[0093] Alternatively, the calculated key identifier can be parsed using the A-TID parsing module 102-2. For example, an XOR operation is performed between the AF-ID and the calculated key identifier. For instance, if the calculated key identifier is represented by A-TID⊕AF-ID, then the parsing result is represented by AF-ID⊕(A-TID⊕AF-ID), which is A-TID.

[0094] The parsed results can then be authenticated using the A-TID authentication module 102-3. For example, in AUSF104, K... AKMA After sending the A-KID to AAnF102, AAnF102 can determine the A-TID from the A-KID. The parsed A-TID is then compared with the A-TID determined by the A-KID. After successful authentication of the parsed A-TID, the KID is then used... AKMA AF-ID can generate AF keys (e.g., using K). AF (Representation). K AF The UE's Generic Public Subscription Identifier (GPSI) is sent to the AF103 so that the AF103 can be based on K AF The UE's GPSI is used to respond to the session establishment request.

[0095] This application safeguards the security of the UE's GPSI and other privacy information during the AKMA service process, controls the exposure surface, and prevents unauthorized network entities from obtaining the UE's privacy information. This application can implement the above method without changing the interface of 5G network elements, which is beneficial to the advancement of the 3GPP AKMA standard. Even if other AFs authorized by AKMA obtain the A-AKID through a MITM attack and send the A-AKID and their own AF1-ID to AAnF, AAnF cannot parse the A-AKID based on the AF1-ID, and therefore cannot obtain the UE's GPSI.

[0096] Of course, the methods provided in the embodiments of this application are not limited to... Figure 1 The application scenarios shown can also be used in other possible scenarios, and this application embodiment does not impose any limitations. Figure 1The functions that each device in the application scenario shown can achieve will be described in subsequent method embodiments, and will not be elaborated on here.

[0097] To further illustrate the technical solutions provided in the embodiments of this application, a detailed description is provided below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiments of this application provide method operation steps as shown in the following embodiments or drawings, the method may include more or fewer operation steps based on conventional or non-inventive methods. In steps where there is no logically necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application.

[0098] The following is combined with Figure 1 The application scenarios shown illustrate the technical solutions provided in the embodiments of this application.

[0099] like Figure 2 As shown in the figure, an embodiment of this application discloses a flowchart of a user information privacy protection method, which includes the following steps:

[0100] S201, the UE sends the master authentication to the AUSF;

[0101] S202, AUSF generates a K after successful primary authentication. AKMA And A-KID, and S202, will K AKMA Send A-KID to AAnF;

[0102] S203, After successful primary authentication, the UE generates a K. AKMA The A-KID is obtained by XORing the A-TID and AF-ID in the A-KID; a session establishment request is created based on the A-AKID; and a session establishment request that includes at least the A-AKID is sent to the AF.

[0103] S204, In the case where AF does not have the context related to A-KID, AF sends A-AKID and AF-ID to AAnF;

[0104] S205, AAnF authenticates AF-ID;

[0105] S206, AAnF performs an XOR operation on AF-ID and A-AKID to obtain A-TID;

[0106] S207, AAnF certifies A-TID;

[0107] S208, AAnF via K AKMA Generate K with AF-ID AF and K AF The UE's GPSI is sent to the AF;

[0108] Here, K can also be used. AF The effective period and the user's permanent identifier (SUbscription PermanentIdentifier, SUPI) are sent to AF.

[0109] S209, AF based on K AF The UE's GPSI is used to respond to the session establishment request.

[0110] here, Figure 2 The AUSF and NEF mentioned are merely illustrative examples and do not limit the specific network elements in the 5G core network.

[0111] like Figure 3 As shown in the figure, an embodiment of this application discloses a flowchart of a user information privacy protection method, applied to application function AF, the method including the following steps:

[0112] S301, Receive a session establishment request sent by the user terminal UE; wherein the session establishment request includes at least the key identifier calculated by the target rule;

[0113] S302, send the key identifier calculated by the target rule and the identity identifier of the AF to the target network element so that the target network element can determine the key of the AF according to the key identifier calculated by the target rule and the identity identifier of the AF;

[0114] S303, Receive the AF key sent by the target network element;

[0115] S304, based on the AF key, responds to the session establishment request.

[0116] like Figure 4 As shown in the figure, an embodiment of this application discloses a flowchart of a user information privacy protection method, applied to a target network element. The method includes the following steps:

[0117] S401, Receive the key identifier after the target rule calculation and the identity identifier of the AF sent by the AF;

[0118] S402, based on the identity identifier of AF, parse the key identifier calculated by the target rule;

[0119] S403, Based on the parsing result and the identity of the AF, determine the key of the AF;

[0120] S404, send the AF's key to the AF so that the AF responds to the session establishment request sent by the UE based on the AF's key.

[0121] The implementation process of the above method can be referred to the description of the user information privacy protection system mentioned above, and will not be repeated here.

[0122] refer to Figure 5 This application provides a user information privacy protection device, the device 500 including:

[0123] The first receiving module 501 is used to receive a session establishment request sent by the user terminal UE; wherein the session establishment request includes at least the key identifier calculated by the target rule;

[0124] The first sending module 502 is used to send the key identifier calculated by the target rule and the identity identifier of the AF to the target network element, so that the target network element can determine the key of the AF according to the key identifier calculated by the target rule and the identity identifier of the AF;

[0125] The second receiving module 503 is used to receive the AF key sent by the target network element;

[0126] Response module 504 is used for AF-based keys to respond to session establishment requests.

[0127] In one possible design, the target rule is computed by XORing the key identifier and the identity identifier of the AF.

[0128] In one possible design, the second receiving module 503 is also used for:

[0129] Receive UE privacy information sent by the target network element;

[0130] Response module 504 is specifically used for:

[0131] Based on the AF key and the UE's privacy information, respond to the session establishment request.

[0132] refer to Figure 6 This application provides a user information privacy protection device, device 600 including:

[0133] The third receiving module 601 is used to receive the key identifier after the target rule calculation and the identity identifier of the AF sent by the AF.

[0134] Parsing module 602 is used to parse the key identifier calculated by the target rule based on the identity identifier of AF;

[0135] Module 603 is used to determine the key of the AF based on the parsing result and the identity identifier of the AF;

[0136] The second sending module 604 is used to send the AF's key to the AF so that the AF responds to the session establishment request sent by the UE based on the AF's key.

[0137] In one possible design, the target rule is computed by XORing the key identifier and the identity identifier of the AF.

[0138] The parsing module 602 is specifically used for:

[0139] Perform an XOR operation on the identity identifier of AF and the key identifier calculated according to the target rule.

[0140] In one possible design, when the UE subscribes to the application's authentication and key management AKMA service, module 603 is specifically used for:

[0141] Based on the parsing results, determine the AKMA key;

[0142] The key of AF is determined based on the key of AKMA and the identity of AF.

[0143] In one possible design, the second transmitting module 604 is also used for:

[0144] Send the UE's privacy information to the AF.

[0145] In one possible design, the third receiving module 601 is also used for:

[0146] AF is authenticated based on its identity identifier.

[0147] After introducing a user information privacy protection method and related apparatus according to an exemplary embodiment of this application, the electronic device according to another exemplary embodiment of this application will be introduced next.

[0148] Those skilled in the art will understand that various aspects of this application can be implemented as a system, method, or program product. Therefore, various aspects of this application can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, collectively referred to herein as a "circuit," "module," or "system."

[0149] In some possible implementations, the electronic device according to this application may include at least one processor and at least one memory. The memory stores program code that, when executed by the processor, causes the processor to perform the steps of the user information privacy protection method according to the various exemplary embodiments of this application described above. For example, the processor may perform steps such as those in the user information privacy protection method.

[0150] The following reference Figure 7 To describe an electronic device 70 according to this embodiment of the present application. Figure 7 The electronic device 70 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0151] like Figure 7 As shown, the terminal device 70 is presented in the form of a general-purpose electronic device. The components of the electronic device 70 may include, but are not limited to: at least one processor 71, at least one memory 72, and a bus 73 connecting different system components (including memory 72 and processor 71).

[0152] Bus 73 represents one or more of several bus structures, including a memory bus or memory controller, peripheral bus, processor, or a local bus using any of the various bus structures.

[0153] The memory 72 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 721 and / or cache memory 722, and may further include read-only memory (ROM) 723.

[0154] The memory 72 may also include a program / utility 725 having a set (at least one) of program modules 724, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0155] Electronic device 70 can also communicate with one or more external devices 74 (e.g., keyboard, pointing device, etc.), and with one or more devices that enable a user to interact with electronic device 70, and / or with any device that enables electronic device 70 to communicate with one or more other electronic devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 75. Furthermore, electronic device 70 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 76. As shown, network adapter 76 communicates with other modules used in electronic device 70 via bus 73. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 70, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0156] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory 72 including instructions, which can be executed by a processor 71 to perform the above-described method. Optionally, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0157] In an exemplary embodiment, a computer program product is also provided, including a computer program / instructions that, when executed by a processor 71, implement any of the user information privacy protection methods provided in this application.

[0158] In an exemplary embodiment, various aspects of the user information privacy protection method provided in this application can also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to cause the computer device to perform the steps in the user information privacy protection method according to the various exemplary embodiments of this application described above.

[0159] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0160] The program product for unlocking electronic devices according to embodiments of this application can employ a portable compact disc read-only memory (CD-ROM) and include program code, and can run on the electronic device. However, the program product of this application is not limited thereto. In this document, the readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0161] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take many forms, including—but not limited to—electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0162] The program code contained on the readable medium may be transmitted using any suitable medium, including—but not limited to—wireless, wired, fiber optic, RF, etc., or any suitable combination thereof.

[0163] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's electronic device, partially on the user's device, as a standalone software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In cases involving remote electronic devices, the remote electronic device can be connected to the user's electronic device via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external electronic device (e.g., via the Internet using an Internet service provider).

[0164] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0165] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0166] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0167] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable electronic device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable electronic device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0168] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable electronic device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0169] These computer program instructions may also be loaded onto a computer or other programmable electronic device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0170] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0171] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A user information privacy protection method, characterized by, The method applied to an application function (AF) comprises: receiving a session establishment request sent by a user equipment (UE); wherein the session establishment request comprises at least a target rule calculated key identifier; the target rule calculation is an exclusive or calculation on the key identifier and an identity of the AF; sending the target rule calculated key identifier and the identity of the AF to a target network element, so that the target network element performs an exclusive or calculation on the identity of the AF and the target rule calculated key identifier to obtain a resolution result, and determines a key of the AF based on the resolution result and the identity of the AF; receiving the key of the AF sent by the target network element; responding to the session establishment request based on the key of the AF.

2. The method of claim 1, wherein, After the target rule calculated key identifier and the identity of the AF are sent to the target network element, the method further comprises: receiving privacy information of the UE sent by the target network element; responding to the session establishment request based on the resolution result and the identity of the AF, comprising: responding to the session establishment request based on the key of the AF and the privacy information of the UE.

3. A user information privacy protection method characterized by comprising: The method applied to a target network element comprises: receiving a target rule calculated key identifier and an identity of an AF sent by the AF; performing an exclusive or calculation on the identity of the AF and the target rule calculated key identifier to obtain a resolution result; the target rule calculation is an exclusive or calculation on the key identifier and the identity of the AF; determining a key of the AF based on the resolution result and the identity of the AF; sending the key of the AF to the AF, so that the AF responds to a session establishment request sent by a UE based on the key of the AF.

4. The method of claim 3, wherein, When the UE subscribes to an authentication and key management for applications (AKMA) service, the determination of the key of the AF based on the resolution result and the identity of the AF comprises: determining the key of the AKMA based on the resolution result; determining the key of the AF according to the key of the AKMA and the identity of the AF.

5. The method of claim 3, wherein, After the key of the AF is determined, the method further comprises: sending privacy information of the UE to the AF.

6. The method of claim 3, wherein, Before the target rule calculated key identifier is resolved based on the identity of the AF, the method further comprises: authenticating the AF based on the identity of the AF.

7. A user information privacy protection system, characterized by, The system comprises an AF, a target network element and a UE; the UE is configured to calculate a key identifier based on a target rule, create a session establishment request according to the calculated key identifier, and send the session establishment request to the AF; the target rule calculation is an exclusive or calculation on the key identifier and an identity of the AF; the AF is configured to send the calculated key identifier and the identity of the AF to the target network element; and the target network element is configured to perform an exclusive or calculation on the identity of the AF and the target rule calculated key identifier to obtain a resolution result, and determine a key of the AF based on the resolution result and the identity of the AF. The target network element is used to perform an XOR operation on the identity identifier of the AF and the key identifier calculated by the target rule to obtain a parsing result; based on the parsing result and the identity identifier of the AF, determine the key of the AF; and send the key of the AF to the AF. The AF is also used to respond to the session establishment request based on the key of the AF.

8. An electronic device, comprising: include: Processor and display; The display is used to show the user interface; The processor is configured to perform the method as described in any one of claims 1-2, or to perform the method as described in any one of claims 3-6.

Citation Information

Patent Citations

  • Key management method, device and system

    CN113676901A

  • Key updating method, network element, user equipment and storage medium

    CN115915124A