Wireless communication method for registration procedure
By using encryption-based hidden identifiers (SUCI) in 5G systems, the problem of attackers obtaining SUPI through brute force guessing attacks is solved, and the enhancement of network security and the effectiveness verification of registration procedures is achieved.
Patent Information
- Application Number
- CN201980100782.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-11-08
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2039-11-08
AI Technical Summary
In 5G systems, attackers can obtain valid user permanent identifiers (SUPIs) in the network through brute force guessing attacks, thus endangering network security.
By using a hidden identifier (SUCI) between the wireless terminal and the wireless network node, the identifier is encrypted ciphertext text based on the user permanent identifier (SUPI) and check value (IMSICV). The wireless terminal sends a message containing SUCI when registering, and the wireless network node decrypts it after receiving it to obtain the SUPI and verification values, and verify its validity.
It effectively prevents attackers from obtaining SUPI through brute-force guessing attacks, enhances network security, and ensures the effectiveness of registration procedures.
Smart Images

Figure CN114450991B_ABST
Abstract
Description
Technical Field
[0001] This document relates generally to wireless communications. Background Art
[0002] Wireless communication technology is pushing the world into an increasingly connected and networked society. The 5G system applies the Elliptic Curve Integrated Encryption Scheme (ECIES) to hide the Subscription Permanent Identifier (SUPI), making it impossible for attackers to obtain the SUPI. An attacker can obtain the valid SUPI in the network through a SUPI brute force guessing attack. This is because the registration request message responded to is different considering whether the SUPI is valid. Therefore, the attacker can calculate the entire SUPI database to the private network by repeating the SUPI guessing attack multiple times. In addition, the attacker can guess all the SUPIs in the network through a brute force guessing SUPI attack, and further, the attacker can verify whether the guessed SUPI is valid in the network. This is confirmed by the user message responding to the authentication request. Summary of the invention
[0003] The present invention generally relates to methods, systems and devices for wireless communications, and in particular to methods, systems and devices for registration procedures. However, it is clear to a person skilled in the art that the present document is not limited to these wireless communications, but is also applicable to other types of wireless communications.
[0004] The present disclosure relates to a wireless communication method for use in a wireless terminal, comprising: determining a hidden identifier based on a permanent identifier and a check value; and sending a message containing the hidden identifier for a registration procedure to a wireless network node.
[0005] Various embodiments may preferably implement the following features:
[0006] Preferably, the secret value text of the hidden identifier is determined based on the check value.
[0007] Preferably, the secret value text of the hidden identifier is an encryption of the mobile subscriber identification code MSIN and the verification value of the wireless terminal.
[0008] Preferably, the permanent identifier is a user permanent identifier.
[0009] Preferably, the check value is a check value for verifying one of an International Mobile Subscriber Identity IMSI of the wireless terminal or a Mobile Subscriber Identity MSIN of the IMSI.
[0010] Preferably, the wireless communication method further comprises updating the check value by using a unified data management (UDM) control plane procedure (UPU) or an over-the-air download technology procedure (OTA).
[0011] The present disclosure also relates to a wireless communication method for use in a wireless network node, comprising: receiving a message including a hidden identifier for a registration procedure from a wireless terminal, determining a permanent identifier and a check value based on the hidden identifier, and sending a response to the wireless terminal based on determining whether the permanent identifier is stored in the wireless network node and whether the check value is equal to a check value corresponding to the permanent identifier.
[0012] Various embodiments may preferably implement the following features:
[0013] Preferably, the secret value text of the hidden identifier is determined based on the check value.
[0014] Preferably, the secret value text of the hidden identifier is an encryption of the mobile subscriber identification code MSIN and the verification value of the wireless terminal.
[0015] Preferably, the permanent identifier is a user permanent identifier.
[0016] Preferably, the check value is a check value for verifying one of an International Mobile Subscriber Identity IMSI of the wireless terminal or a Mobile Subscriber Identity MSIN of the IMSI.
[0017] Preferably, the wireless communication method further comprises updating the check value by using a unified data management (UDM) control plane procedure (UPU) or an over-the-air download technology procedure (OTA).
[0018] Preferably, the response indicates that the registration procedure has failed when the permanent identifier is not stored in the wireless network node or the check value is different from the check value corresponding to the permanent identifier.
[0019] Preferably, the response indicates that the registration procedure was successful when the permanent identifier is stored in the wireless network node and the check value is equal to the check value corresponding to the permanent identifier.
[0020] The present invention also relates to a wireless terminal, comprising: a processor configured to determine a hidden identifier based on a permanent identifier and a check value; and a communication unit configured to send a message including the hidden identifier for a registration procedure to a wireless network node.
[0021] Various embodiments may preferably implement the following features:
[0022] Preferably, the processor is configured to execute the wireless communication method described in any of the aforementioned methods.
[0023] The present disclosure also relates to a wireless network node, comprising: a communication unit, which is configured to receive a message including a hidden identifier for a registration procedure from a wireless terminal, and determine a permanent identifier and a check value based on the hidden identifier, wherein the communication unit is further configured to send a response to the wireless terminal based on determining whether the permanent identifier is stored in the wireless network node and whether the check value is equal to the check value corresponding to the permanent identifier.
[0024] Various embodiments may preferably implement the following features:
[0025] Preferably, the processor is configured to execute the wireless communication method described in any of the foregoing methods.
[0026] The present disclosure also relates to a computer program product, which includes a computer-readable program medium code stored thereon, which, when executed by a processor, causes the processor to implement the wireless communication method described in any of the aforementioned methods.
[0027] The exemplary embodiments disclosed herein are intended to provide features that will become apparent with reference to the following description when taken in conjunction with the accompanying drawings. According to various embodiments, exemplary systems, methods, devices, and computer program products are disclosed herein. However, it should be understood that these embodiments are presented as examples rather than limitations, and it will be apparent to those of ordinary skill in the art who read this disclosure that various modifications may be made to the disclosed embodiments while remaining within the scope of this disclosure.
[0028] Therefore, the present disclosure is not limited to the exemplary embodiments and applications described and illustrated herein. In addition, the specific order and / or hierarchy of steps in the methods disclosed herein are merely exemplary methods. Based on design preferences, the specific order or hierarchy of steps of the disclosed methods or processes can be rearranged while remaining within the scope of the present disclosure. Therefore, it will be understood by those of ordinary skill in the art that the methods and techniques disclosed herein present various steps or actions in an example order, and the present disclosure is not limited to the specific order or hierarchy presented, unless otherwise explicitly stated. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The above and other aspects and embodiments thereof are described in more detail in the drawings, the description and the claims.
[0030] Figure 1 The schematic architecture of a 5G system is shown.
[0031] Figure 2 An example of a schematic diagram of a network device according to an embodiment of the present disclosure is shown.
[0032] Figure 3 An example of a schematic diagram of a network node according to an embodiment of the present disclosure is shown.
[0033] Figure 4 A schematic diagram showing a process according to an embodiment of the present disclosure is shown.
[0034] Figure 5 The structure of the International Mobile Subscriber Identity IMSI is shown.
[0035] Figure 6 The structure of IMSI and verification value IMSICV is shown.
[0036] Figure 7 A schematic diagram showing a process according to an embodiment of the present disclosure is shown.
[0037] Figure 8 The structure of the hidden user identifier SUCI is shown.
[0038] Fig. 9 The scenario output for an empty scenario is shown.
[0039] Fig.10 The scheme output of the elliptic curve integrated encryption scheme attribute A is shown.
[0040] Fig.11 The scheme output of the elliptic curve integrated encryption scheme attribute B is shown.
[0041] Fig.12 The scheme output of the HPLMN-specific protection scheme is shown. DETAILED DESCRIPTION
[0042] Figure 1 The schematic architecture of the 5G system is described below. The 5G system architecture consists of the following network functions (NFs).
[0043] The Access and Mobility Management Function (AMF) includes the following functions: UE mobility management, reachability management, connection management, etc. AMF terminates the Radio Access Network (RAN) control plane (CP) interface (i.e. Figure 1 N2 shown) and non-access layer (NAS) (i.e. Figure 1 It also distributes the Session Management (SM) NAS to the appropriate Session Management Function (SMF) via the N11 interface.
[0044] The session management function (SMF) includes: UE Internet Protocol (IP) address allocation and management, user plane (UP) function selection and control, protocol data unit (PDU) connection management, etc.
[0045] The User Plane Function (UPF) is the anchor point for intra / inter-Radio Access Technology (RAT) mobility and is the external PDU session point for interconnection with the data network. The UPF also routes and forwards packets as directed from the SMF. In addition, the UPF caches DL data when the UE is in idle mode.
[0046] Unified Data Management (UDM) stores the user attributes of the UE. ARPF (not shown) is an authentication credentials repository and processing function. UDM and ARPF belong to the home network and are implemented jointly.
[0047] The Policy Control Function (PCF) generates policies to manage network behavior based on subscriptions and instructions from the AF (Application Function). It also provides policy rules to the CP functions (AMF and SMF) to enforce them.
[0048] Figure 2 A schematic diagram of a wireless terminal 20 according to an embodiment of the present disclosure is provided. The wireless terminal 20 may be a user equipment (UE), a mobile phone, a laptop, a tablet computer, an e-book, or a portable computer system, and is not limited thereto. The wireless terminal 20 may include a processor 200 such as a microprocessor or an application-specific integrated circuit (ASIC), a storage unit 210, and a communication unit 220. The storage unit 210 may be any data storage device that stores program code 212, which is accessed and executed by the processor 200. Embodiments of the storage unit 212 include, but are not limited to, a subscriber identity module (SIM), a read-only memory (ROM), a flash memory, a random access memory (RAM), a hard disk, and an optical data storage device. The communication unit 220 may be a transceiver and is used to send and receive signals (e.g., messages or data packets) based on the processing results of the processor 200. In an embodiment, the communication unit 220 communicates with the communication unit 220 via Figure 2 At least one antenna 222 is shown in Figure 2 for transmitting and receiving signals.
[0049] In an embodiment, the storage unit 210 and the program code 212 may be omitted, and the processor 200 may include a storage unit having stored program codes.
[0050] Processor 200 may implement any of the steps of the exemplary embodiments on wireless terminal 20 , for example, by executing program code 212 .
[0051] The communication unit 220 may be a transceiver. The communication unit 220 may alternatively or additionally combine a transmitting unit and a receiving unit configured to transmit and receive signals to and from a wireless network node (eg, a base station), respectively.
[0052] Figure 3A schematic diagram of a radio network node 30 according to an embodiment of the present disclosure is provided. The radio network node 30 may be a base station (BS), a network entity, a mobility management entity (MME), a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a radio network controller (RNC), and is not limited thereto. In an embodiment, the radio network node 30 may be Figure 1 5G-RAN, AMF, UDM, PCF, SMF and / or UPF shown. The radio network node 30 may include a processor 300 such as a microprocessor or an ASIC, a storage unit 310 and a communication unit 320. The storage unit 310 may be any data storage device that stores program code 312, which is accessed and executed by the processor 300. Examples of the storage unit 312 include, but are not limited to, a SIM, a ROM, a flash memory, a RAM, a hard disk, and an optical data storage device. The communication unit 320 may be a transceiver and is used to send and receive signals (such as messages or data packets) based on the processing results of the processor 300. In the example, the communication unit 320 communicates via Figure 3 At least one antenna 322 is shown in Figure 3 for transmitting and receiving signals.
[0053] In an embodiment, the storage unit 310 and the program code 312 may be omitted. The processor 300 may include a storage unit having stored program code.
[0054] The processor 300 may implement any of the steps described in the exemplary embodiments on the radio network node 30 , for example, via executing the program code 312 .
[0055] The communication unit 320 may be a transceiver. The communication unit 320 may alternatively or additionally combine a transmitting unit and a receiving unit configured to transmit and receive signals to and from a wireless terminal (eg, user equipment), respectively.
[0056] Figure 4 A schematic diagram of a process according to an embodiment of the present disclosure is shown. In this embodiment, a user equipment (UE) determines a hidden identifier based on a stored permanent identifier and a check value (i.e., an International Mobile Subscriber Identity IMSI and a check value (IMSICV)), and sends a hidden identifier to a wireless network node (e.g., Figure 1 The UDM shown in FIG. 10A sends a message (registration request message) containing a hidden identifier for a registration procedure.
[0057] like Figure 4As shown in , the radio network node receives a message containing a hidden identifier for a registration procedure and then determines a permanent identifier and a check value, i.e., IMSICV, based on the hidden identifier, and then sends a response to the UE based on determining whether the permanent identifier is stored in the radio network node and whether the check value is equal to the check value corresponding to the permanent identifier.
[0058] In an embodiment, the response indicates that the registration procedure was successful when the radio network node determines that the permanent identifier is stored, for example in a database of the radio network node and the check value is equal to the check value corresponding to the permanent identifier.
[0059] In an embodiment, the response indicates that the registration procedure failed when the radio network node determines that the permanent identifier is not stored in the radio network node and / or the check value is not equal to the check value corresponding to the permanent identifier.
[0060] In an embodiment, the UE and / or the radio network node updates the check value by using a unified data management (UDM) control plane procedure (UPU) and / or an over-the-air procedure (OTA).
[0061] Figure 5 The structure of the IMSI is shown. According to an embodiment, the IMSI includes a mobile country code (MCC) consisting of three digits. The MCC uniquely identifies the country to which the mobile user belongs. The IMSI also includes a mobile network code (MNC) consisting of two or three digits for 3GPP network applications. The MNC identifies the home PLMN (public land mobile network) of the mobile user. The length of the MNC (two or three digits) depends on the value of the MCC. It is possible to mix two and three digit MNC codes within a single MCC area, but it is not necessarily recommended. In addition, the IMSI includes a mobile subscriber identification number (MSIN) that identifies the mobile user within the PLMN.
[0062] Figure 6 The structure of IMSI and verification value (IMSICV) is shown. According to an embodiment, IMSICV includes as shown in reference Figure 5 The various characteristics of the IMSI described are the Mobile Country Code (MCC), Mobile Network Code (MNC) and Mobile Subscriber Identity Number (MSIN). Figure 6 As shown, the check value is used to verify the validity of the IMSI or MSIN. The length of the check value depends on the network operator. The check value can be updated by the home network through OTA and / or UPU procedures.
[0063] Figure 7 FIG. 12 is a schematic diagram showing a process according to an embodiment of the present disclosure. In this embodiment, the IMSICV is stored in the UE and the UDM / ARPF. In step 1201, the UE sends a packet containing a SUCI (User Hidden Identifier) (i.e., Figure 4 The SUCI sends a Registration Request message to the AMF / SEAF (Security Anchor Function, which is collocated with the AMF) with a hidden identifier in the SUCI header, which will be described in more detail below. The SUCI includes the SUPI type, home network identifier, routing indicator, protection scheme identifier, home network public key identifier and scheme output. The encrypted text in the scheme output is the encryption of the MSIN and the check value.
[0064] At step 1202, SEAF invokes the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate Request message including SUCI to AUSF.
[0065] At step 1203, a Nudm_UEAuthentication_Get Request including the SUCI is sent from the AUSF to the UDM.
[0066] Upon receiving Nudm_UEAuthentication_GetRequest, the UDM calls SIDF (User Identity Demasking Function) to demask the SUCI to obtain (e.g., determine) the SUPI and the check value at step 1204. The UDM determines whether the SUPI is stored in the database at step 1205. If the SUPI is found in the UDM's database, the UDM determines whether the check value is also stored in the database.
[0067] If the SUPI and the check value are found in the UDM's database, the UDM selects an authentication method based on the SUPI. The UDM then generates authentication data including an authentication vector and sends it to the AUSF in a Nudm_UEAuthentication_Get Response message with "200 OK" at step 1206. If the SUPI or the check value is not found in the database, the UDM returns "404NotFound" and "USER_NOT_FOUND" in a Nudm_UEAuthentication_GetResponse message at step 1206.
[0068] After receiving "200OK", AUSF sends "201Created" to AMF / SEAF in step 1207, where UEAuthentictionCtx contains the authentication vector in the Nausf_UEAuthentication_Authenticate Response message. After receiving "404Not Found", AUSF sends "404Not Found" and "USER_NOT_FOUND" to AMF / SEAF in step 1207.
[0069] Finally, in step 1208A, in the case of "201 Created", AMF / SEAF sends RAND and AUTN to the UE in the AuthenticationRequest message. Otherwise, in step 1208B, in the case of "404 Not Found", AMF / SEAF sends a Registration Reject message with Cause#3 to the UE.
[0070] In other words, Figure 7 A procedure for protecting a user permanent identifier from brute force attacks. A SUPI and a check value are stored in a UE and a home network, respectively. The UE obtains (e.g., determines) a SUCI by encrypting the SUPI and the check value, and sends the SUCI to the home network. Next, the home network decrypts the SUCI to obtain the SUPI and the check value, and determines whether the SUPI is stored in a database. If the SUPI is found in a database of the UDM, the UDM determines whether the check value is stored in the database. If both the SUPI and the check value exist in the database of the UDM, the home network returns a success response to the UE. If one of the SUPI or the check value is not found in the database of the UDM, the home network returns a failure response to the UE.
[0071] The above SUPI is a globally unique 5G user permanent identifier assigned to each user in the 5G system. SUPI is defined as:
[0072] - SUPI Type: In this release, it may indicate either IMSI or Network Specific Identifier; and
[0073] - Value depending on SUPI type:
[0074] -IMSI; or
[0075] - A network specific identifier, which takes the form of a Network Access Identifier (NAI).
[0076] Figure 8The structure of the User Concealed Identifier (SUCI) is shown. The SUCI is a privacy-preserving identifier that contains a concealed SUPI.
[0077] The SUCI includes a SUPI Type, which consists of a value in the range of 0 to 7. It identifies the type of SUPI hidden in the SUCI. The following values are defined:
[0078] -0:IMSI
[0079] -1: Network specific identifier
[0080] -2 to 7: Reserve values for future use.
[0081] The SUCI also includes a Home Network Identifier, which identifies the user's home network. When the SUPI type is IMSI, the Home Network Identifier consists of two parts:
[0082] - Mobile Country Code (MCC), which consists of three decimal digits. The MCC uniquely identifies the country of origin of the mobile subscriber; and
[0083] - Mobile Network Code (MNC), which consists of two or three decimal digits. The MNC identifies the home PLMN of the mobile user.
[0084] When the SUPI Type is a Network Specific Identifier, the Home Network Identifier consists of a character string with a variable length representing a domain name.
[0085] The SUCI also includes a routing indicator, consisting of a 1 to 4 decimal digit number allocated by the home network operator and provisioned in the USIM, which allows network signaling with the SUCI to be routed along with the home network identifier to the AUSF and UDM instances capable of serving the user.
[0086] Each decimal digit present in the routing indicator shall be considered significant (e.g. the value "012" is different from the value "12"). If the routing indicator is not configured on the USIM, this data field shall be set to the value 0 (i.e. consist of only one decimal digit "0").
[0087] The SUCI also includes a protection scheme identifier, which consists of a value ranging from 0 to 15. It indicates a null scheme or a non-null scheme or a protection scheme specified by the HPLMN.
[0088] In addition, the SUCI also includes a Home Network Public Key Identifier, which consists of a value in the range of 0 to 255. It represents the public key provided by the HPLMN and it is used to identify the key used for SUPI protection. In case the Null scheme is used, this data field shall be set to the value 0.
[0089] SUCI also includes a scheme output, which consists of a character string with variable length or hexadecimal numbers, depending on the protection scheme used. It represents the output of the public key protection scheme or the output of the protection scheme specified by the HPLMN.
[0090] Fig. 9 The scenario output for the empty scenario above is shown. The Mobile Subscriber Identification Number (MSIN) or Username identifies the mobile subscriber within the home network. The scenario output is formatted as a variable length character.
[0091] Fig.10 The scheme output for the Elliptic Curve Integrated Cryptography scheme Property A is shown. The ECC temporary public key is formatted as a 64-bit hexadecimal number, which allows 256 bits to be encoded. The ciphertext value is formatted as a variable length hexadecimal number. The MAC tag value is formatted as a 16-bit hexadecimal number, which allows 64 bits to be encoded.
[0092] Fig.11 The scheme output for the Elliptic Curve Integrated Cryptography scheme Property B is shown. The ECC ephemeral public key is formatted as 66 hexadecimal digits, which allows 264 bits to be encoded. The ciphertext value is formatted as a variable length hexadecimal digit. The MAC tag value is formatted as 16 hexadecimal digits, which allows 64 bits to be encoded.
[0093] Fig.12 The scheme output of the HPLMN proprietary protection scheme is shown. The scheme output defined by the HPLMN is formatted as a variable length hexadecimal number. As an example, assuming IMSI 234150999999999, where MCC=234, MNC=15 and MSIN=0999999999, CV=88888, routing indicator 678, and home network public key identifier 27:
[0094] - The SUCI for the null scheme consists of the following: 0, 234, 15, 678, 0, 0, and 0999999999.
[0095] - For attributes The SUCI of the protection scheme consists of the following: 0, 234, 15, 678, 1, 27, <EEC temporary public key value>, <encrypted 099999999988888>, and <MAC tag value>.
[0096] When the SUPI is defined as a network-specific identifier, the SUCI shall be in the form of a Network Access Identifier (NAI). In this case, the NAI format of the SUCI shall have the form username@realm, where the realm part shall be the same as the realm part of the network-specific identifier.
[0097] When the SUPI is defined as an IMSI, the SUCI in the NAI format shall have the form of a username without a realm part.
[0098] The username part of the NAI shall be in one of the following forms:
[0099] a) For the null scheme:
[0100] type<supi type>.rid<routing indicator>.schid<protection scheme id>.userid<MSIN or network-specific identifier SUPI username>
[0101] b) For the scheme output of elliptic curve integrated encryption scheme attributes A and B:
[0102] type<supi type>.rid<routing indicator>.schid<protection scheme id>.hnkey<home network public key id>.ecckey<ECC temporary public key value>.cip<ciphertext value>.mac<MAC tag value>
[0103] c) For the HPLMN proprietary protection scheme:
[0104] type<supi type>.rid<routing indicator>.schid<protection scheme id>.hnkey<home network public key id>.out<scheme output defined by HPLMN>
[0105] Next, some examples are provided:
[0106] Assume IMSI 234150999999999, where MCC = 234, MNC = 15 and MSIN = 0999999999, CV = 88888, routing indicator 678, and home network public key identifier 27. The NAI format of the SUCI adopts the following format:
[0107] - For the null scheme:
[0108] type0.rid678.schid0.userid0999999999
[0109] -For properties Protection scheme:
[0110] type0.rid678.schid1.hnkey27.ecckey<ECC temporary public key>.cip<Encryption 099999999988888>.mac<MAC tag value>
[0111] Assuming a network-specific identifier user17@example.com, a routing indicator 678, and a home network public key identifier 27, the NAI format of the SUCI takes the following form:
[0112] - For the empty scheme:
[0113] type1.rid678.schid0.useriduser17@example.com
[0114] - For attributes Protection Scheme:
[0115] type1.rid678.schid1.hnkey27.ecckey<ECC temporary public key>.cip<encryption of user17>.mac<MAC tag value>@example.com
[0116] Although various embodiments of the present disclosure have been described above, it should be understood that they are presented by way of example and not limitation. Similarly, the various figures may depict exemplary architectures or configurations, and the various figures are provided to enable those of ordinary skill in the art to understand the exemplary features and functions of the present disclosure. However, these persons will understand that the present disclosure is not limited to the exemplary architectures or configurations shown, but may be implemented using various alternative architectures and configurations. In addition, as will be understood by those of ordinary skill in the art, one or more features of one embodiment may be combined with one or more features of another embodiment described herein. Therefore, the breadth and scope of the present disclosure should not be limited by any of the above exemplary embodiments.
[0117] It should also be understood that any reference in this document to elements by names such as "first", "second", etc. generally does not limit the number or order of these elements. Instead, these names may be used herein as a convenient means of distinguishing between two or more elements or instances of elements. Thus, the reference to a first element and a second element does not mean that only two elements can be employed, or that the first element must precede the second element in some manner.
[0118] In addition, those of ordinary skill in the art will understand that any of a variety of different technologies and processes may be used to represent information and signals. For example, data, instructions, commands, information, signals, bits, and symbols that may be referred to in the above description may be represented by voltage, current, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0119] Those skilled in the art will further understand that any of the various illustrative logical blocks, units, processors, devices, circuits, methods, and functions described in connection with the aspects disclosed herein may be implemented by electronic hardware (e.g., digital implementations, analog implementations, or a combination of both), firmware, various forms of programs or design codes containing instructions (for convenience, which may be referred to herein as "software" or "software units"), or any combination of these technologies.
[0120] In order to clearly illustrate this interchangeability of hardware, firmware and software, various illustrative components, blocks, units, circuits and steps have been described above generally according to their functions. Whether this function is implemented as hardware, firmware or software, or a combination of these technologies, depends on the specific application and design constraints imposed on the entire system. Those skilled in the art can implement the described functions in various ways for each specific application, but such implementation decisions will not lead to deviations from the scope of this disclosure. According to various embodiments, processors, devices, components, circuits, structures, machines, units, etc. can be configured to perform one or more of the functions described herein. As used herein, the term "configured to" or "configured for" regarding a specified operation or function refers to a processor, device, component, circuit, structure, machine, unit, etc. that is physically constructed, programmed and / or arranged to perform a specified operation or function.
[0121] In addition, it will be appreciated by those skilled in the art that the various illustrative logic blocks, units, devices, components and circuits described herein may be implemented in or performed by an integrated circuit (IC), which may include a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, or any combination thereof. The logic blocks, units and circuits may also include antennas and / or transceivers to communicate with various components within a network or within a device. The general purpose processor may be a microprocessor, but in an alternative, the processor may be any conventional processor, controller or state machine. The processor may also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors combined with a DSP core, or any other suitable configuration to perform the functions described herein. If implemented in software, these functions may be stored on a computer readable medium as one or more instructions or codes. Therefore, the steps of the method or algorithm disclosed herein may be implemented as software stored on a computer readable medium.
[0122] Computer-readable media include computer storage media and communication media, including any medium that can transfer a computer program or code from one place to another. Storage media can be any available medium that can be accessed by a computer. By way of example and not limitation, such computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code in the form of instructions or data structures and can be accessed by a computer.
[0123] In this document, the term "unit" as used herein refers to software, firmware, hardware, and any combination of these elements for performing the relevant functions described herein. In addition, for discussion purposes, various units are described as discrete units; however, it is obvious to those of ordinary skill in the art that two or more units can be combined to form a single unit that performs the relevant functions according to embodiments of the present disclosure.
[0124] In addition, memory or other storage and communication components may be used in embodiments of the present disclosure. It should be understood that, for the sake of clarity, the above description has described embodiments of the present disclosure with reference to different functional units and processors. However, it is apparent that any suitable functional distribution between different functional units, processing logic elements or domains may be used without departing from the present disclosure. For example, functions shown to be performed by separate processing logic elements or controllers may be performed by the same processing logic elements or controllers. Therefore, references to specific functional units are only references to suitable devices that provide the described functions, rather than representing a strict logical or physical structure or organization.
[0125] Various modifications to the embodiments described in this disclosure will be apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the embodiments shown herein, but is to be consistent with the broadest scope consistent with the novel features and principles disclosed herein, as described in the following claims.
Claims
1. A wireless communication method for use in a wireless terminal, comprising: determining a hidden identifier based on the permanent identifier and the check value; as well as sending a message including said hidden identifier for a registration procedure to a wireless network node, The check value is a check value for verifying one of the international mobile user identity of the wireless terminal or the mobile user identity of the international mobile user identity.
2. The wireless communication method according to claim 1, wherein: A secret value text of the hidden identifier is determined based on the check value.
3. The wireless communication method according to claim 2, wherein: The secret value text of the hidden identifier is an encryption of the mobile user identification code and the verification value of the wireless terminal.
4. The wireless communication method according to any one of claims 1 to 3, wherein: The permanent identifier is a user permanent identifier.
5. The wireless communication method according to any one of claims 1 to 4, further comprising: The check value is updated by using a unified data management (UDM) control plane procedure (UPU) or an over-the-air download technology procedure (OTA).
6. A wireless communication method for use in a wireless network node, comprising: receiving a message from a wireless terminal including a hidden identifier for a registration procedure, determining a permanent identifier and a check value based on the hidden identifier, and sending a response to the wireless terminal based on determining whether the permanent identifier is stored in the wireless network node and whether the check value is equal to a check value corresponding to the permanent identifier, The check value is a check value for verifying one of the international mobile user identity of the wireless terminal or the mobile user identity of the international mobile user identity.
7. The wireless communication method according to claim 6, wherein: A secret value text of the hidden identifier is determined based on the check value.
8. The wireless communication method according to claim 7, wherein: The secret value text of the hidden identifier is an encryption of the mobile user identification code and the verification value of the wireless terminal.
9. The wireless communication method according to any one of claims 6 to 8, wherein: The permanent identifier is a user permanent identifier.
10. The wireless communication method according to any one of claims 6 to 9, further comprising: The check value is updated by using a unified data management (UDM) control plane procedure (UPU) or an over-the-air download technology procedure (OTA).
11. The wireless communication method according to any one of claims 6 to 10, wherein: The response indicates that the registration procedure failed when the permanent identifier is not stored in the radio network node or the check value is different from the check value corresponding to the permanent identifier.
12. The wireless communication method according to any one of claims 6 to 10, wherein: The response indicates that the registration procedure was successful when the permanent identifier is stored in the radio network node and the check value is equal to the check value corresponding to the permanent identifier.
13. A wireless terminal, comprising: a processor configured to determine a hidden identifier based on the permanent identifier and the check value; and a communication unit configured to send a message including the hidden identifier for a registration procedure to a wireless network node, The check value is a check value for verifying one of the international mobile user identity of the wireless terminal or the mobile user identity of the international mobile user identity.
14. The wireless terminal according to claim 13, wherein: The processor is configured to execute the wireless communication method according to any one of claims 2 to 5.
15. A wireless network node, comprising: a communication unit configured to receive a message including a hidden identifier for a registration procedure from a wireless terminal, and a processor configured to determine a permanent identifier and a check value based on the hidden identifier, wherein the communication unit is further configured to send a response to the wireless terminal based on determining whether the permanent identifier is stored in the wireless network node and whether the check value is equal to the check value corresponding to the permanent identifier, The check value is a check value for verifying one of the international mobile user identity of the wireless terminal or the mobile user identity of the international mobile user identity.
16. The wireless network node according to claim 15, wherein: The processor is configured to execute the wireless communication method according to any one of claims 7 to 12.
17. A computer program product comprising computer-readable program medium code stored thereon, which, when executed by a processor, causes the processor to implement the wireless communication method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Authentication processing method, system, client side and server for network access
CN101977383A
Method and device for maintaining effectiveness of mobile terminal, method and device for uploading information of mobile terminal as well as system for maintaining effectiveness of mobile terminal
CN104754556A
Subscription concealed identifier
CN111133728A
Integrity check value for WLAN pseudonym
US20040193891A1