A replay attack processing method, a unified data management entity, and a storage medium

By comparing the reception time and anti-playback parameters of SUCI in UDM, the problem of SUCI in the prior art that cannot distinguish between legal and attacker replay is solved, ensuring the effectiveness of the SUCI retransmission mechanism, preventing playback attacks, and improving the security and stability of the system.

CN114745721BActive Publication Date: 2025-08-01CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110025012.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-08
Publication Date
2025-08-01
Estimated Expiration
2041-01-08

AI Technical Summary

Technical Problem

The prior art cannot effectively distinguish between legitimate UEs using SUCI retransmission mechanism and SUCI retransmission by attackers, resulting in a decrease in processing capabilities of UDM and UEs, resulting in DOS attacks, affecting the effectiveness of SUCI retransmission mechanism.

Method used

UDM judges whether it is a playback attack by comparing the received SUCI reception time and anti-playback parameters. If it is different, the SUCI will not be discarded, and generates an authentication vector to return to the user. Use the timestamp and the random number of anti-playback parameters and count values to confirm to ensure that the legitimate SUCI retransmission is not discarded.

Benefits of technology

It effectively prevents replay attacks, ensures that the SUCI retransmission mechanism on the UE side does not fail, avoids the processing capacity of UDM and UE and the power consumption, and improves the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114745721B_ABST
    Figure CN114745721B_ABST
Patent Text Reader

Abstract

The present invention discloses a replay attack processing method, a unified data management entity, and a storage medium, including: after the UDM confirms that the received first SUCI is not a replay attack, it marks the reception time of the first SUCI; after the UDM receives the second SUCI, when it determines that the second SUCI is within a preset time period according to the reception time of the first SUCI, it compares the first SUCI with the second SUCI. By adopting the present invention, within the preset time period, the SUCI sent by the UE to the UDM using the retransmission mechanism will not be discarded, so that the retransmission mechanism on the UE side will not fail.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of wireless communication technologies, and particularly relates to a replay attack processing method, a unified data management entity, and a storage medium. Background Art

[0002] For the reliable transmission of SUCI (Subscription Concealed Identifier), in order to achieve the reliable transmission of SUCI from a UE (User Equipment) to an AMF (Access and Mobility Management Function), Figure 1 As shown in the figure, which is a schematic diagram of the SUCI retransmission mechanism timer. In the existing solution, a SUCI retransmission mechanism is defined for the UE, and two timers are used: T3519 (60 seconds) and T3510 (15 seconds) to implement it.

[0003] After the UE generates the SUCI, it starts timers T3519 and T3510, stores the SUCI, and sends the SUCI to the AMF. If the AMF receives the SUCI, it will forward it to the AUSF (Authentication Server Function) without performing a replay check and the AUSF will forward it to the UDM (Unified Data Management). If the UE does not receive a response from the AMF within timer T3510, it will resend the stored SUCI to the network.

[0004] In extreme cases, the UE may send the same SUCI to the network five times, that is, it is possible that the UDM will receive the same SUCI five times. After timer T3519 expires, the UE generates a new SUCI and stores it, and starts a new round of SUCI transmission.

[0005] For the SUCI replay attack, after the attacker obtains the valid SUCI of the user over the air interface and then replays it to the network over the air interface, the UDM will generate an authentication vector as if it were processing the SUCI of a normal user and send an authentication request message containing RAND (Random Challenge) and AUTN (Authentication Token) to the attacker. The attacker then forwards the authentication request message to the legitimate UE. If the attacker uses the replay attack multiple times, the UDM and UE have to spend a large amount of resources to process the replay messages and authentication request messages because these messages are legitimate, resulting in a DOS (Denial of Service) attack on the UDM and UE. The DOS attack on the UE will cause the processing ability of the UE to decline and quickly consume the battery power. The DOS attack on the UDM will cause the processing ability of the UDM to decline and the response to the requests of legitimate UEs to become slower. The attacker can use the RAND and AUTN obtained through the SUCI replay attack to launch a correlation attack on the victim to determine whether the victim is in a specific area.

[0006] The deficiency of the existing anti-replay attack solutions is that the method of preventing replay attacks on the UDM cannot distinguish whether the SUCI is retransmitted by a legitimate UE using the SUCI retransmission mechanism or the SUCI replayed by the attacker, so that the SUCI retransmission mechanism on the UE side will fail. Summary of the Invention

[0007] The present invention provides a replay attack processing method, a unified data management entity, and a storage medium to solve the problem that the SUCI retransmission mechanism on the UE side fails.

[0008] The present invention provides the following technical solutions:

[0009] A replay attack processing method includes:

[0010] After the UDM confirms that the received first SUCI is not a replay attack, it marks the reception time of the first SUCI;

[0011] After the UDM receives the second SUCI, when it determines that the second SUCI is within a preset time period according to the reception time of the first SUCI, it compares the first SUCI with the second SUCI.

[0012] In implementation, after comparing the first SUCI with the second SUCI, it further includes:

[0013] If the first SUCI is different from the second SUCI, use the anti-replay parameter in the SUCI to judge whether the SUCI is a replay;

[0014] If the first SUCI is the same as the second SUCI, the second SUCI is not discarded, and after obtaining the SUPI according to the second SUCI, an authentication vector is generated and returned to the user.

[0015] In implementation, after confirming that the received first SUCI is not a replay attack, it further includes:

[0016] Encapsulate it into a data unit with a timestamp and the first SUCI;

[0017] When it is determined that the second SUCI is within the preset time period according to the reception time of the first SUCI, it is determined according to the timestamp in the data unit;

[0018] Comparing the first SUCI with the second SUCI is based on the first SUCI in the data unit.

[0019] In implementation, it further includes:

[0020] Encapsulate the SUPI in the data unit, and the SUPI is used for the UDM to generate an authentication vector and return it to the user.

[0021] In implementation, the preset time period is 60 seconds or the timing duration of timer T3519.

[0022] In implementation, it further includes:

[0023] Confirm whether it is a replay attack according to the random number and / or count value of the anti-replay parameter in the second SUCI.

[0024] In implementation, confirming whether it is a replay attack according to the random number and / or count value of the anti-replay parameter in the second SUCI includes:

[0025] When the random number in the second SUCI is not encrypted, if the random number in the second SUCI has not been stored before, it is confirmed that it is not a replay attack;

[0026] When the random number in the second SUCI is encrypted, if the decrypted random number in the second SUCI has not been stored before, it is confirmed that it is not a replay attack;

[0027] For each UE, when the count value in the second SUCI is not encrypted, if the count value in the second SUCI is larger than the previously stored count value, it is confirmed that it is not a replay attack;

[0028] For each UE, when the count value in the second SUCI is encrypted, if the decrypted count value in the second SUCI is larger than the previously stored count value, it is confirmed that it is not a replay attack.

[0029] In implementation, after comparing the first SUCI with the second SUCI, it further includes:

[0030] When it is confirmed that there is no replay attack, obtain the long-term key of the UE corresponding to the second SUCI, generate an authentication vector, and return it to the UE.

[0031] A UDM includes:

[0032] A processor for reading a program in a memory and performing the following processes:

[0033] After confirming that the received first SUCI is not a replay attack, identify the reception time of the first SUCI;

[0034] After receiving the second SUCI, when it is determined according to the reception time of the first SUCI that the second SUCI is within a preset time period, compare the first SUCI with the second SUCI;

[0035] A transceiver for receiving and sending data under the control of the processor.

[0036] In implementation, after comparing the first SUCI with the second SUCI, it further includes:

[0037] If the first SUCI is different from the second SUCI, use the anti-replay parameter in the SUCI to determine whether the SUCI is a replay;

[0038] If the first SUCI is the same as the second SUCI, do not discard the second SUCI, obtain the SUPI according to the second SUCI, and then generate an authentication vector and return it to the user.

[0039] In implementation, after confirming that the received first SUCI is not a replay attack, it further includes:

[0040] Encapsulate it into a data unit with a timestamp and the first SUCI;

[0041] When it is determined according to the reception time of the first SUCI that the second SUCI is within a preset time period, it is determined according to the timestamp in the data unit;

[0042] Comparing the first SUCI with the second SUCI is based on the first SUCI in the data unit.

[0043] In implementation, it further includes:

[0044] Encapsulate the SUPI in the data unit, and the SUPI is used for the UDM to generate an authentication vector and return it to the user.

[0045] In implementation, the preset time period is 60 seconds or the timing duration of the timer T3519.

[0046] In implementation, it further includes:

[0047] Verify whether it is a replay attack based on the random number and / or count value of the anti-replay parameter in the second SUCI.

[0048] In implementation, verifying whether it is a replay attack based on the random number and / or count value of the anti-replay parameter in the second SUCI includes:

[0049] When the random number in the second SUCI is not encrypted, if the random number in the second SUCI has not been stored before, it is verified that it is not a replay attack;

[0050] When the random number in the second SUCI is encrypted, if the decrypted random number in the second SUCI has not been stored before, it is verified that it is not a replay attack;

[0051] For each UE, when the count value in the second SUCI is not encrypted, if the count value in the second SUCI is larger than the previously stored count value, it is verified that it is not a replay attack;

[0052] For each UE, when the count value in the second SUCI is encrypted, if the decrypted count value in the second SUCI is larger than the previously stored count value, it is verified that it is not a replay attack.

[0053] In implementation, after comparing the first SUCI and the second SUCI, it further includes:

[0054] When it is verified that it is not a replay attack, obtain the long-term key of the UE corresponding to the SUPI of the second SUCI, generate an authentication vector and return it to the UE.

[0055] A UDM includes:

[0056] A time module, used to identify the reception time of the first SUCI after verifying that the received first SUCI is not a replay attack;

[0057] A comparison module, used to compare the first SUCI and the second SUCI when the second SUCI is received and the second SUCI is within a preset time period according to the reception time of the first SUCI.

[0058] In implementation, the comparison module is further used to, after comparing the first SUCI and the second SUCI, if the first SUCI and the second SUCI are different, use the anti-replay parameter in the SUCI to judge whether the SUCI is a replay;

[0059] If the first SUCI and the second SUCI are the same, the second SUCI is not discarded, and an authentication vector is generated and returned to the user after obtaining the SUPI according to the second SUCI.

[0060] In implementation, the time module is further used to encapsulate the received first SUCI into a data unit with a timestamp and the first SUCI after confirming that it is not a replay attack.

[0061] The comparison module is further used to determine that the second SUCI is within a preset time period based on the reception time of the first SUCI, which is determined according to the timestamp in the data unit; the comparison between the first SUCI and the second SUCI is made according to the first SUCI in the data unit.

[0062] In implementation, the time module is further used to encapsulate the SUPI in the data unit, and the SUPI is used for the UDM to generate an authentication vector and return it to the user.

[0063] In implementation, the comparison module is further used to use 60 seconds or the timing duration of timer T3519 as the preset time period.

[0064] In implementation, the comparison module is further used to confirm whether it is a replay attack according to the anti-replay parameter random number and / or count value in the second SUCI.

[0065] In implementation, when the comparison module is further used to confirm whether it is a replay attack according to the anti-replay parameter random number and / or count value in the second SUCI, it includes:

[0066] When the random number in the second SUCI is not encrypted, if the random number in the second SUCI has not been stored before, it is confirmed that it is not a replay attack;

[0067] When the random number in the second SUCI is encrypted, if the decrypted random number in the second SUCI has not been stored before, it is confirmed that it is not a replay attack;

[0068] For each UE, when the count value in the second SUCI is not encrypted, if the count value in the second SUCI is larger than the previously stored count value, it is confirmed that it is not a replay attack;

[0069] For each UE, when the count value in the second SUCI is encrypted, if the decrypted count value in the second SUCI is larger than the previously stored count value, it is confirmed that it is not a replay attack.

[0070] In implementation, after the comparison module compares the first SUCI and the second SUCI and confirms that it is not a replay attack, it obtains the long-term key of the UE corresponding to the second SUCI, generates an authentication vector and returns it to the UE.

[0071] A computer-readable storage medium stores a computer program for executing the above replay attack processing method.

[0072] The beneficial effects of the present invention are as follows:

[0073] In the technical solution provided by the embodiment of the present invention, after it is confirmed that the received SUCI is not a replay attack, a judgment is made based on this time. For SUCI within a preset time period, as long as the SUCI is the same, it will not be discarded and can be further processed. That is, within the preset time period, for example, within the time of timer T3519, the SUCI sent by the UE to the UDM using the retransmission mechanism will not be discarded, so that the retransmission mechanism on the UE side will not fail. Brief Description of the Drawings

[0074] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:

[0075] Figure 1 It is a schematic diagram of the SUCI retransmission mechanism timer in the background technology;

[0076] Figure 2 It is a schematic flowchart of the implementation process of the replay attack processing method in the embodiment of the present invention;

[0077] Figure 3 It is a schematic diagram of the UDM structure in the embodiment of the present invention. Detailed Embodiments

[0078] The inventor noticed during the invention process that:

[0079] The current SUCI anti-replay attack solutions are divided into the following two categories according to whether the anti-replay parameters (random number, count value) in the SUCI are encrypted:

[0080] (1) The anti-replay parameters in the SUCI are not encrypted.

[0081] In this type of solution, the UE sends the anti-replay parameters in the SUCI without encryption to the UDM. After receiving the SUCI, the UDM judges whether the SUCI is a replay based on the anti-replay parameters. When the anti-replay parameter is a random number, the UDM searches the database to find whether there is a previously received random number equal to the just received random number. If an equal one is found, the UDM judges that the received SUCI is a replay attack and discards this SUCI; if no equal one is found, the UDM judges that the received SUCI is not a replay attack and proceeds to the next step. Another solution is to use the user public key in the SUCI to prevent SUCI replay attacks. The network-side UDM determines whether the received SUCI message is a replay message by comparing the user public key in the SUCI received from the UE side with the previous user public key stored in the database.

[0082] When the anti-replay parameter in the SUCI is a count value, since the count value is associated with the UE, the UDM needs to first decrypt the SUCI to obtain the SUPI (Subscription Permanent Identifier), find the corresponding UE, and then compare it with the count value stored by the corresponding UE last time. If the received count value is greater than the last count value, the UDM determines that the received SUCI is not a replay attack and proceeds to the next step. If the received count value is less than or equal to the last count value, the UDM determines that the received SUCI is a replay attack, and the UDM discards this SUCI.

[0083] (2) Encryption of the anti-replay parameter in the SUCI.

[0084] In such a scheme, the UE encrypts the anti-replay parameter in the SUCI and sends it to the UDM. After receiving the SUCI, the UDM first decrypts the SUCI and then determines whether the SUCI is a replay based on the anti-replay parameter. The method of determining whether the SUCI is a replay based on a random number and a count value is the same as the method introduced above. One scheme proposes a method using a one-time random number (nonce) N to prevent replay attacks and mitigate DoS attacks. N is introduced into the encryption operation as follows:

[0085] IMSIEnc = MCC||MNC||EncPK(MSIN,N),

[0086] where MCC and MNC are not encrypted because they are needed for routing in roaming scenarios, || is a concatenation operation, and EncPK(X) represents encrypting the plaintext X using the key PK. After receiving IMSIEnc, the network side decrypts it to obtain N and first verifies whether N is new. If the home PLMN (Public Land Mobile Network) has seen N before, a replay attack is detected.

[0087] The existing methods for anti-replay attacks on the UDM cannot distinguish whether the SUCI is retransmitted by a legitimate UE using the SUCI retransmission mechanism or is a SUCI replayed by an attacker. Once the UDM detects that the SUCI is a replay, it discards the received SUCI. As a result, the SUCI retransmission mechanism on the UE side fails.

[0088] Based on this, the technical solution provided by the embodiments of the present invention will solve the problem of the failure of the SUCI retransmission mechanism on the UE side on the UDM. The specific implementation manners of the present invention will be described below with reference to the accompanying drawings.

[0089] Figure 2 As shown in the figure, it can be included for the schematic flow chart of the replay attack processing method:

[0090] Step 201: After the UDM confirms that the received first SUCI is not a replay attack, it identifies the reception time of the first SUCI.

[0091] Step 202: After the UDM receives the second SUCI, when it determines that the second SUCI is within the preset time period according to the reception time of the first SUCI, it compares the first SUCI with the second SUCI.

[0092] Through the comparison, it can be determined whether the second SUCI is a replay attack.

[0093] In implementation, after comparing the first SUCI with the second SUCI, it may further include:

[0094] If the first SUCI is different from the second SUCI, use the anti-replay parameters in the SUCI to judge whether the SUCI is a replay.

[0095] If the first SUCI is the same as the second SUCI, the second SUCI is not discarded. After obtaining the SUPI according to the second SUCI, an authentication vector is generated and returned to the user.

[0096] Specifically, if the first SUCI is different from the second SUCI, further use the anti-replay parameters (random number, count value) in the SUCI to judge whether the SUCI is a replay.

[0097] If the first SUCI is the same as the second SUCI, the second SUCI is not discarded. Obtain the SUPI according to it and generate an authentication vector, and return it to the user.

[0098] In implementation, after confirming that the received first SUCI is not a replay attack, it may further include:

[0099] Encapsulate it into a data unit with a timestamp and the first SUCI;

[0100] When it is determined that the second SUCI is within the preset time period according to the reception time of the first SUCI, it is determined according to the timestamp in the data unit;

[0101] The comparison of the first SUCI and the second SUCI is based on the first SUCI in the data unit.

[0102] In implementation, it further includes:

[0103] Encapsulate the SUPI in the data unit, and the SUPI is used for the UDM to generate an authentication vector and return it to the user.

[0104] In implementation, the preset time period is 60 seconds or the timing duration of timer T3519. That is, the duration of T3519.

[0105] Specifically, in the solution, after confirming that the received SUCI is not a replay attack, it is encapsulated into a DU (Data Unit) with a timestamp (Timestamp), and its structure can be: DU = {SUCI, SUPI, Timestamp}. Taking the duration of the preset time period T3519 as an example, within the timer T3519, the DU is used as a comparison tag to identify whether the received SUCI is a SUCI retransmitted by a legitimate user, that is, the subsequently received SUCI is compared with the SUCI in the DU. If they are the same, the received SUCI is not discarded and further processed. If they are different, the anti-replay parameters (such as random numbers, count values) in the SUCI are continued to be used to determine whether the SUCI is a replay. The following solutions will separately explain the anti-replay parameters in the SUCI as random numbers and count values. In the solution, the SUCI sent by the UE to the UDM using the retransmission mechanism within the timer T3519 will not be discarded, so that the retransmission mechanism on the UE side will not fail.

[0106] During implementation, it can further include:

[0107] Confirm whether it is a replay attack according to the anti-replay parameters random number and / or count value in the second SUCI.

[0108] During implementation, after comparing the first SUCI and the second SUCI, it can further include:

[0109] When confirming that it is not a replay attack, obtain the long-term key of the UE corresponding to the SUPI of the second SUCI, generate an authentication vector and return it to the UE.

[0110] To implement replay attack detection, the SUCI in the solution contains anti-replay parameters.

[0111] 1. The random number is used as an anti-replay parameter.

[0112] There are two situations where the random number is used as an anti-replay parameter in the SUCI: the random number is not encrypted and the random number is encrypted. The UDM can analyze these two situations separately when judging whether the received SUCI is a replay according to the received SUCI.

[0113] 1) The random number is not encrypted.

[0114] When the random number in the second SUCI is not encrypted, if the random number in the second SUCI has not been stored, it is confirmed that it is not a replay attack.

[0115] The UDM will use the message queue of the stored data unit (DU) and the database storing the random number to jointly judge whether the received SUCI is a replay attack. Specifically, it can be as follows:

[0116] After receiving the SUCI, the UDM sets the timestamp to the time point when the SUCI is received, and searches for the SUCI in the message queue storing the DUs. If the SUCI is found and the timestamp in the corresponding DU is within the T3519 time, the UDM obtains the SUPI of the corresponding DU, finds the long-term key of the UE corresponding to the SUPI, generates an authentication vector and returns it to the UE (User Equipment).

[0117] The UDM removes the DUs with a time before T3519 from the message queue according to the timestamp.

[0118] If the UDM does not find the SUCI in the message queue, it extracts the random number from the received SUCI.

[0119] The UDM searches the database storing the random numbers for the random number corresponding to the SUCI. If found, it confirms that the SUCI is not a replay attack and interrupts the connection; if not found, it also confirms that the SUCI is not a replay attack. Then it decrypts the SUCI to obtain the SUPI. Based on the long-term key of the UE corresponding to the SUPI, it generates an authentication vector and returns it to the UE. The UDM constructs a data unit DU = {SUCI, SUPI, Timestamp} and moves it into the message queue.

[0120] 2) Random number encryption.

[0121] When encrypting the random number in the second SUCI, if the decrypted random number in the second SUCI has not been stored before, it is confirmed that it is not a replay attack.

[0122] The UDM uses the message queue storing the data units (DUs) and the database storing the random numbers to determine whether the received SUCI is a replay attack. Specifically, it can be as follows:

[0123] After receiving the SUCI, the UDM sets the timestamp to the time point when the SUCI is received, and searches for the SUCI in the message queue storing the DUs. If the SUCI is found and the timestamp in the corresponding DU is within the T3519 time, the UDM obtains the SUPI of the corresponding DU, finds the long-term key of the UE corresponding to the SUPI, generates an authentication vector and returns it to the UE.

[0124] The UDM removes the DUs with a time before T3519 from the message queue according to the timestamp.

[0125] If the UDM does not find the corresponding SUCI in the message queue, it decrypts the received SUCI to obtain the random number and the SUPI.

[0126] The UDM searches the database storing random numbers for the random number corresponding to the SUCI. If found, it confirms that the SUCI is a replay attack and interrupts the connection; if not found, it confirms that the SUCI is not a replay attack. Based on the long-term key of the UE corresponding to the SUPI, it generates an authentication vector and returns it to the UE. The UDM constructs a data unit DU = {SUCI, SUPI, Timestamp} and moves it into the message queue.

[0127] 2. The count value is used as an anti-replay parameter.

[0128] There are two cases where the count value is used as an anti-replay parameter in the SUCI: the count value is not encrypted and the count value is encrypted. The UDM analyzes these two cases separately when judging whether the SUCI is a replay based on the received SUCI.

[0129] 1) The count value is not encrypted.

[0130] For each UE, when the count value in the second SUCI is not encrypted, if the count value in the second SUCI is larger than the previously stored count value, it is confirmed that it is not a replay attack.

[0131] For each UE, the UDM uses the message queue to store the data unit (DU) and the previously stored count value together to judge whether the received SUCI is a replay attack. Specifically, it can be as follows:

[0132] After receiving the SUCI, the UDM sets the timestamp to the time point when the SUCI is received, and searches for the SUCI in the message queue storing the DU. If the SUCI is found and the timestamp in the corresponding DU is within the T3519 time, the UDM obtains the SUPI of the corresponding DU, finds the long-term key of the UE corresponding to the SUPI, generates an authentication vector and returns it to the UE.

[0133] The UDM removes the DUs in the message queue whose time is before T3519 according to the timestamp.

[0134] If the UDM does not find the corresponding SUCI in the message queue, it extracts the count value in the received SUCI.

[0135] The UDM compares the previously stored count value with the corresponding count value in the SUCI. If the corresponding count value in the SUCI is less than or equal to the previously stored count value, it confirms that the SUCI is a replay attack and interrupts the connection.

[0136] If the count value corresponding to the SUCI is greater than the previously stored count value, confirm that the SUCI is not a replay attack, and decrypt the SUCI to obtain the SUPI. Generate an authentication vector based on the long-term key of the UE corresponding to the SUPI and return it to the UE. The UDM constructs a data unit DU = {SUCI, SUPI, Timestamp} and moves it into the message queue.

[0137] 2) Encryption of the count value.

[0138] For each UE, when encrypting the count value in the second SUCI, if the decrypted count value in the second SUCI is greater than the previously stored count value, confirm that it is not a replay attack.

[0139] For each UE, the UDM uses the message queue to store the data unit (DU) and the previously stored count value together to determine whether the received SUCI is a replay attack. Specifically, it can be as follows:

[0140] After receiving the SUCI, the UDM sets the timestamp to the time point when the SUCI is received, and searches for the SUCI in the message queue storing the DU. If the SUCI is found and the timestamp in the corresponding DU is within the T3519 time, the UDM obtains the SUPI of the corresponding DU, finds the long-term key of the UE corresponding to the SUPI, generates an authentication vector and returns it to the UE.

[0141] The UDM removes the DUs in the message queue whose time is before T3519 according to the timestamp.

[0142] If the UDM does not find the corresponding SUCI in the message queue, decrypt the received SUCI to obtain the SUPI and the count value.

[0143] The UDM compares the previously stored count value with the count value corresponding to the SUCI. If the count value corresponding to the SUCI is less than or equal to the previously stored count value, confirm that the SUCI is a replay attack, and then interrupt the connection.

[0144] If the count value corresponding to the SUCI is greater than the previously stored count value, confirm that the SUCI is not a replay attack. Generate an authentication vector based on the long-term key of the UE corresponding to the SUPI and return it to the UE. The UDM constructs a data unit DU = {SUCI, SUPI, Timestamp} and moves it into the message queue.

[0145] Based on the same inventive concept, embodiments of the present invention also provide a UDM and a computer-readable storage medium. Since the principles of these devices for solving problems are similar to those of the replay attack processing method, the implementation of these devices can refer to the implementation of the method, and the repeated parts will not be described again.

[0146] When implementing the technical solution provided by the embodiments of the present invention, it can be implemented in the following manner.

[0147] Figure 3 It is a schematic diagram of the UDM structure. As shown in the figure, the UDM includes:

[0148] A processor 300, configured to read a program in a memory 320 and execute the following processes:

[0149] After confirming that the received first SUCI is not a replay attack, mark the reception time of the first SUCI;

[0150] After receiving a second SUCI, when determining that the second SUCI is within a preset time period according to the reception time of the first SUCI, compare the first SUCI with the second SUCI;

[0151] A transceiver 310, configured to receive and send data under the control of the processor 300.

[0152] During implementation, after comparing the first SUCI with the second SUCI, it further includes:

[0153] If the first SUCI and the second SUCI are different, use the anti-replay parameter in the SUCI to determine whether the SUCI is a replay;

[0154] If the first SUCI and the second SUCI are the same, the second SUCI is not discarded, and an authentication vector is generated and returned to the user after obtaining the SUPI according to the second SUCI.

[0155] During implementation, after confirming that the received first SUCI is not a replay attack, it further includes:

[0156] Encapsulate it into a data unit with a timestamp and the first SUCI;

[0157] When determining that the second SUCI is within a preset time period according to the reception time of the first SUCI, it is determined according to the timestamp in the data unit;

[0158] Comparing the first SUCI with the second SUCI is based on the first SUCI in the data unit.

[0159] During implementation, it further includes:

[0160] Encapsulate the SUPI in the data unit, and the SUPI is used for the UDM to generate an authentication vector and return it to the user.

[0161] During implementation, the preset time period is 60 seconds or the timing duration of a timer T3519.

[0162] During implementation, it further includes:

[0163] Confirm whether it is a replay attack according to the random number and / or count value of the anti-replay parameter in the second SUCI.

[0164] In implementation, confirming whether it is a replay attack according to the random number and / or count value of the anti-replay parameter in the second SUCI includes:

[0165] When the random number in the second SUCI is not encrypted, if the random number in the second SUCI has not been stored before, confirm that it is not a replay attack;

[0166] When the random number in the second SUCI is encrypted, if the decrypted random number in the second SUCI has not been stored before, confirm that it is not a replay attack;

[0167] For each UE, when the count value in the second SUCI is not encrypted, if the count value in the second SUCI is larger than the previously stored count value, confirm that it is not a replay attack;

[0168] For each UE, when the count value in the second SUCI is encrypted, if the decrypted count value in the second SUCI is larger than the previously stored count value, confirm that it is not a replay attack.

[0169] In implementation, after comparing the first SUCI and the second SUCI, it further includes:

[0170] When it is confirmed that it is not a replay attack, obtain the long-term key of the UE corresponding to the SUPI of the second SUCI, generate an authentication vector and return it to the UE.

[0171] Among them, in Figure 3 The bus architecture may include any number of interconnected buses and bridges, specifically, various circuits represented by one or more processors represented by processor 300 and a memory represented by memory 320 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 310 may be multiple elements, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on the transmission medium. The processor 300 is responsible for managing the bus architecture and general processing, and the memory 320 can store the data used by the processor 300 when performing operations.

[0172] An embodiment of the present invention also provides a UDM, including:

[0173] A time module, configured to identify the reception time of the first SUCI after confirming that the received first SUCI is not a replay attack;

[0174] A comparison module, configured to, after receiving a second SUCI, compare the first SUCI with the second SUCI when it is determined according to the reception time of the first SUCI that the second SUCI is within a preset time period.

[0175] In implementation, the comparison module is further configured to, after comparing the first SUCI with the second SUCI, if the first SUCI and the second SUCI are different, use the anti-replay parameter in the SUCI to determine whether the SUCI is a replay.

[0176] If the first SUCI and the second SUCI are the same, the second SUCI is not discarded, and after obtaining the SUPI according to the second SUCI, an authentication vector is generated and returned to the user.

[0177] In implementation, the time module is further configured to, after confirming that the received first SUCI is not a replay attack, encapsulate it into a data unit with a timestamp and the first SUCI.

[0178] The comparison module is further configured to, when it is determined according to the reception time of the first SUCI that the second SUCI is within a preset time period, determine it according to the timestamp in the data unit; and compare the first SUCI with the second SUCI according to the first SUCI in the data unit.

[0179] In implementation, the time module is further configured to encapsulate the SUPI in the data unit, and the SUPI is used for the UDM to generate an authentication vector and return it to the user.

[0180] In implementation, the comparison module is further configured to use 60 seconds or the timing duration of timer T3519 as the preset time period.

[0181] In implementation, the comparison module is further configured to confirm whether it is a replay attack according to the random number and / or count value of the anti-replay parameter in the second SUCI.

[0182] In implementation, when the comparison module confirms whether it is a replay attack according to the random number and / or count value of the anti-replay parameter in the second SUCI, it includes:

[0183] When the random number in the second SUCI is not encrypted, if the random number in the second SUCI has not been stored, it is confirmed that it is not a replay attack.

[0184] When the random number in the second SUCI is encrypted, if the decrypted random number in the second SUCI has not been stored, it is confirmed that it is not a replay attack.

[0185] For each UE, when the count value in the second SUCI is not encrypted, if the count value in the second SUCI is larger than the previously stored count value, it is confirmed that it is not a replay attack.

[0186] For each UE, when encrypting the count value in the second SUCI, if the decrypted count value in the second SUCI is larger than the previously stored count value, it is confirmed that there is no replay attack.

[0187] In implementation, the comparison module is further configured to, after comparing the first SUCI and the second SUCI, when it is confirmed that there is no replay attack, obtain the long-term key of the UE corresponding to the SUPI of the second SUCI, generate an authentication vector and return it to the UE.

[0188] For the convenience of description, each part of the above-described device is described separately as various modules or units according to functions. Of course, when implementing the present invention, the functions of the various modules or units can be implemented in one or more software or hardware.

[0189] An embodiment of the present invention also provides a computer-readable storage medium storing a computer program for executing the above replay attack processing method.

[0190] For specific implementation, reference can be made to the implementation of the replay attack processing method on the UDM.

[0191] In summary, the embodiment of the present invention provides a solution for resisting SUCI replay attacks on the UDM. Within the time of timer T3519, the data unit DU will be used as a comparison tag to identify whether the received SUCI is a retransmission by a legitimate user, that is, the subsequently received SUCI will be compared with the SUCI in the DU. If they are the same, the received SUCI will not be discarded and will be further processed.

[0192] After it is confirmed that the received SUCI is not a replay attack, it is encapsulated into a data unit with a timestamp (DU: DataUnit), and its structure is DU = {SUCI, SUPI, Timestamp}.

[0193] The replay prevention processes on the UDM side when a random number is used as a replay prevention parameter and when a count value is used as a replay prevention parameter are also provided.

[0194] Based on this solution, the SUCI sent by the UE to the UDM using the retransmission mechanism within the time of timer T3519 will not be discarded, so that the retransmission mechanism on the UE side will not fail.

[0195] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories and optical memories, etc.) containing computer-usable program code.

[0196] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0197] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0198] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0199] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A replay attack processing method, characterized in that, It includes: After the unified data management entity UDM confirms that the received first subscription encryption identifier SUCI is not a replay attack, it identifies the reception time of the first SUCI; After the UDM receives the second SUCI, when it determines that the second SUCI is within a preset time period according to the reception time of the first SUCI, it compares the first SUCI with the second SUCI; Among them, after comparing the first SUCI with the second SUCI, it further includes: If the first SUCI is different from the second SUCI, it uses the anti-replay parameter in the first SUCI to determine whether the second SUCI is a replay; If the first SUCI is the same as the second SUCI, the second SUCI is not discarded, and after obtaining the subscription permanent identifier SUPI according to the second SUCI, an authentication vector is generated and returned to the user.

2. The method according to claim 1, wherein After confirming that the received first SUCI is not a replay attack, it further includes: Encapsulating it into a data unit with a timestamp and the first SUCI; When it is determined that the second SUCI is within a preset time period according to the reception time of the first SUCI, it is determined according to the timestamp in the data unit; Comparing the first SUCI with the second SUCI is based on the first SUCI in the data unit.

3. The method according to claim 2, wherein It further includes: Encapsulating the SUPI in the data unit, and the SUPI is used for the UDM to generate an authentication vector and return it to the user.

4. The method according to claim 1, characterized in that, The preset time period is 60 seconds or the timing duration of the timer T3519.

5. The method according to any one of claims 1 to 4, characterized in that It further includes: According to the random number and / or count value of the anti-replay parameter in the second SUCI, it confirms whether it is a replay attack.

6. The method according to claim 5, wherein According to the random number and / or count value of the anti-replay parameter in the second SUCI to confirm whether it is a replay attack, it includes: When the random number in the second SUCI is not encrypted, if the random number in the second SUCI has not been stored, it is confirmed that it is not a replay attack; When the random number in the second SUCI is encrypted, if the decrypted random number in the second SUCI has not been stored, it is confirmed that it is not a replay attack; For each user equipment UE, when the count value in the second SUCI is not encrypted, if the count value in the second SUCI is larger than the previously stored count value, it is confirmed that it is not a replay attack; For each UE, when the count value in the second SUCI is encrypted, if the decrypted count value in the second SUCI is larger than the previously stored count value, it is confirmed that it is not a replay attack.

7. The method according to claim 1, wherein After comparing the first SUCI with the second SUCI, it further includes: When it is confirmed that it is not a replay attack, it obtains the long-term key of the UE corresponding to the second SUCI, generates an authentication vector and returns it to the UE.

8. A UDM, characterized in that, It includes: A processor, used to read the program in the memory and execute the following processes: After confirming that the received first SUCI is not a replay attack, it identifies the reception time of the first SUCI; After receiving the second SUCI, when it determines that the second SUCI is within a preset time period according to the reception time of the first SUCI, it compares the first SUCI with the second SUCI; A transceiver, used to receive and send data under the control of the processor; Among them, after comparing the first SUCI with the second SUCI, it further includes: If the first SUCI is different from the second SUCI, use the anti-replay parameter in the first SUCI to determine whether the second SUCI is a replay; If the first SUCI is the same as the second SUCI, the second SUCI is not discarded. After obtaining the subscribed permanent identifier SUPI according to the second SUCI, an authentication vector is generated and returned to the user.

9. A UDM, characterized in that, It includes: A time module, configured to identify the reception time of the first SUCI after confirming that the received first SUCI is not a replay attack; A comparison module, configured to compare the first SUCI with the second SUCI when the second SUCI is within a preset time period according to the reception time of the first SUCI after receiving the second SUCI; Among them, after comparing the first SUCI with the second SUCI, it further includes: If the first SUCI is different from the second SUCI, use the anti-replay parameter in the first SUCI to determine whether the second SUCI is a replay; If the first SUCI is the same as the second SUCI, the second SUCI is not discarded. After obtaining the subscribed permanent identifier SUPI according to the second SUCI, an authentication vector is generated and returned to the user.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program for executing the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Message replay attack detection method, message replay attack detection device and electronic equipment

    CN109768991A