Security establishment method, terminal device, and network device
By generating temporary keys KASME, KSEAF, and KAMF in the 5G New Radio system, the issues of SUPI privacy protection and legitimate interception in roaming networks are resolved, enabling secure and convenient SUPI transmission and key management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-10-10
- Publication Date
- 2026-03-24
AI Technical Summary
In 5G New Radio systems, roaming destination networks need to protect the privacy of subscriber identifiers (SUPIs) while ensuring the need for legitimate interception (LI), and the serving network cannot fully trust the roaming network. Existing technologies make it difficult to provide SUPIs securely and conveniently.
The terminal device and the service network mutually authenticate to generate a key pair, generate a temporary key KASME, and use KASME to generate KSEAF associated with the security anchoring function of the roaming destination network and KAMF associated with the access mobility management function, so as to realize the secure transmission of SUPI.
It enables secure and convenient delivery of SUPI to the roaming destination network, based on the network security of terminal devices and service networks, meeting the needs of privacy protection and legitimate interception, and ensuring the security and legitimacy of the key.
Smart Images

Figure CN115988487B_ABST
Abstract
Description
[0001] This application is a divisional application of the invention patent application with application number 201880065574.3 (international application number: PCT / JP2018 / 037791, application date: October 10, 2018, invention title: security establishment method, terminal device and network device). Technical Field
[0002] This invention relates to a security establishment method, a terminal device, and a network device for establishing the security of a terminal device equipped with a subscriber identification module. Background Technology
[0003] 3GPP (3rd Generation Partnership Project) standardized Long Term Evolution (LTE) and, with the aim of further increasing the speed of LTE, standardized LTE-Advanced (hereinafter referred to as LTE, including LTE-Advanced). Furthermore, 3GPP further studied the specifications for subsequent LTE systems, such as 5G New Radio (NR).
[0004] In LTE, in order to perform mutual authentication between the subscriber (terminal device) and the communication operator (also known as the service network), the International Mobile Subscriber Identity (IMSI) and the permanent key K (secret information) stored in the Universal Integrated Circuit Card (UICC) are used to perform authentication and key agreement (AKA).
[0005] In addition, whenever AKA is executed, a key (CK, IK) is generated for encryption and to ensure integrity, and it is passed from the subscriber identification module (UICC) to the terminal device (ME) (see Non-Patent Document 1).
[0006] In addition, to prevent privacy violations caused by tracking of the subscriber identifier (IMSI), a temporary subscriber identifier based on the IMSI, namely the Temporary Mobile Subscriber Identity (TMSI), is used for mutual authentication. When a subscriber (terminal device) is roaming, the IMSI and TMSI are associated with the telecommunications operator (also known as the roaming destination network) at the roaming destination.
[0007] In NR, a Subscription Permanent Identifier (SUPI) is defined as a subscriber identifier, and the enhancement of privacy protection for subscriber identifiers is studied (e.g., see Non-Patent Literature 2).
[0008] Existing technical documents
[0009] Non-patent literature
[0010] Non-patent document 1: 3GPP TS 33.401V14.3.0Subclause 6.1.1AKA procedure, 3rdGeneration Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security architecture (Release 14), 3GPP, June 2017
[0011] Non-patent document 2: 3GPP TS 33.501V0.3.0Subclause 6.1.3Authentication procedures, 3rd Generation Partnership Project; Technical Specification GroupServices and System Aspects; Security Architecture and Procedures for 5GSystem (Release 15), 3GPP, August 2017 Summary of the Invention
[0012] In NR, it is assumed that the number of service providers has become more diversified compared to generations up to LTE. In this environment, even when a terminal device roams from the subscriber's contracted mobile operator to another operator's mobile communication network (VPLMN), the privacy of the subscriber identifier (SUPI) needs to be protected.
[0013] However, communication operators providing HPLMNs sometimes cannot fully trust communication operators providing VPLMNs, so they do not provide SUPIs directly, but instead send SUPIs to the communication operator that first provides VPLMNs after the subscriber has been certified by the communication operator providing HPLMNs.
[0014] On the other hand, in a roaming destination network, when a lawful intercept (LI) is required, the roaming destination network needs to verify the legitimacy of the confidential information between the subscriber and the communication operator providing the VPLMN, without having to check the subscriber's SUPI with the PLMN (HPLMN) to which the subscriber has signed up each time.
[0015] Therefore, the present invention has been made in view of this situation, and its object is to provide a security establishment method, terminal device, and network device that, based on the establishment of security between the terminal device and the service network, can securely and conveniently provide a Subscriber Identifier (SUPI) to the roaming destination network, and obtain confidential information between the subscriber associated with the correctly provided SUPI and the communication operator providing the VPLMN.
[0016] According to one aspect of the present invention, a security establishment method is provided, the security establishment method using secret information (key K) stored in a subscriber identification module (UICC 200) and a key pair of an encryption key (encryption key CK) and an integrity key (integrity key IK) generated based on the secret information to establish the security of a terminal device (terminal device 110) equipped with the subscriber identification module, wherein the security establishment method includes the following steps: generating the key pair through mutual authentication between the terminal device and the service network (HPLMN 20), the terminal device and the service network sharing a first temporary key (K) using the generated key pair. ASME Steps (S50, S100); the terminal device and the roaming destination network (VPLMN 30) of the terminal device use the first temporary key to generate a second temporary key (K) associated with the security anchoring function (SEAF 50) of the roaming destination network. SEAF Steps (S140, S150) of the terminal device and the roaming destination network, using at least the second temporary key and the subscriber identifier (SUPI) that identifies the subscriber in the service network, generate a third temporary key (K) associated with the Access and Mobility Management Function (AMF 60) of the roaming destination network. AMF Steps (S140, S150) of )
[0017] According to one aspect of the present invention, a terminal device (terminal device 110) is provided, the terminal device being capable of carrying a subscriber identification module for identifying subscribers, wherein the terminal device includes: a first key generation unit (K ASME Generation unit 130) generates a first temporary key using a key pair of an encryption key and an integrity key generated based on the secret information stored in the subscriber identification module; second key generation unit (KSEAF Generation unit 140), which uses the first temporary key to generate a second temporary key associated with the security anchoring function of the roaming destination network of the terminal device; and a third key generation unit (K) AMF The generation unit 145 uses at least the second temporary key and a subscriber identifier that identifies the subscriber in the service network to generate a third temporary key associated with the access and mobility management functions of the roaming destination network.
[0018] According to one aspect of the present invention, a network device (SEAF 50) is provided that communicates with a terminal device capable of carrying a subscriber identification module for identifying subscribers, wherein the network device comprises: a first key generation unit that generates a first temporary key using a key pair of an encryption key and an integrity key generated based on secret information stored in the subscriber identification module; a second key generation unit that generates a second temporary key associated with a security anchoring function of a roaming destination network of the terminal device using the first temporary key; and a third key generation unit that generates a third temporary key associated with an access and mobility management function of the roaming destination network using at least the second temporary key and a subscriber identifier that identifies the subscriber in the serving network.
[0019] According to one aspect of the present invention, a security establishment method is provided, the security establishment method using secret information stored in a subscriber identification module for identifying subscribers and a key pair of an encryption key and an integrity key generated based on the secret information to establish the security of a terminal device equipped with the subscriber identification module, wherein the security establishment method includes the following steps:
[0020] The key pair is generated through mutual authentication between the terminal device and the service network, and the terminal device and the service network share the first temporary key using the generated key pair;
[0021] The terminal device generates a second temporary key, generated using the first temporary key and associated with the security anchoring function of the roaming destination network, and the roaming destination network of the terminal device obtains the second temporary key; and
[0022] The terminal device and the roaming destination network use at least the second temporary key and a subscriber identifier that identifies the subscriber in the service network to generate a third temporary key associated with the access and mobility management functions of the roaming destination network.
[0023] According to one aspect of the present invention, a terminal device is provided, the terminal device being capable of carrying a subscriber identification module for identifying subscribers, wherein the terminal device has:
[0024] The first key generation unit generates a first temporary key using a key pair of an encryption key and an integrity key generated based on the secret information stored in the subscriber identification module.
[0025] The second key generation unit uses the first temporary key to generate a second temporary key associated with the security anchoring function of the roaming destination network of the terminal device; and
[0026] The third key generation unit uses at least the second temporary key and a subscriber identifier that identifies the subscriber in the service network to generate a third temporary key associated with the access and mobility management functions of the roaming destination network.
[0027] According to one aspect of the present invention, a network device is provided that communicates with a terminal device capable of carrying a subscriber identification module for identifying subscribers, wherein the network device comprises:
[0028] The second key generation unit obtains a second temporary key associated with the security anchoring function of the roaming destination network of the terminal device; and
[0029] The third key generation unit uses at least the second temporary key and a subscriber identifier that identifies the subscriber in the service network to generate a third temporary key associated with the access and mobility management functions of the roaming destination network. Attached Figure Description
[0030] Figure 1 This is a schematic diagram of the overall structure of the wireless communication system 10.
[0031] Figure 2 This is the function block structure diagram of UE 100.
[0032] Figure 3 This shows the temporary key (K) in the case of UE 100 roaming to VPLMN 30. ASME K SEAF and K AMF The generation of ) and the graph of shared timing.
[0033] Figure 4 This is a diagram illustrating the key hierarchy used in the wireless communication system 10.
[0034] Figure 5 This is a diagram illustrating an example of the hardware structure of UE 100. Detailed Implementation
[0035] The embodiments will now be described with reference to the accompanying drawings. Furthermore, the same or similar reference numerals will be used for the same functions and structures, and their descriptions will be omitted where appropriate.
[0036] (1) Overall general structure of wireless communication system
[0037] Figure 1 This is a schematic diagram of the overall structure of the wireless communication system 10 according to this embodiment. The wireless communication system 10 is a wireless communication system based on 5G New Radio (NR). The wireless communication system 10 includes a Home Public Land Mobile Network (hereinafter referred to as HPLMN 20) and a Visited Public Land Mobile Network (hereinafter referred to as VPLMN 30).
[0038] User equipment 100 (hereinafter referred to as UE 100) can access HPLMN 20 and VPLMN 30 and perform wireless communication with the radio base station (gNB, not shown) included in HPLMN 20 and the radio base station (gNB, not shown) included in VPLMN 30.
[0039] The UE 100 can be equipped with a Universal Integrated Circuit Card 200 (hereinafter referred to as UICC 200).
[0040] The UICC 200 stores information such as the contract with the telecommunications operator providing HPLM N20. Specifically, the UICC 200 stores a permanent key, namely key K (secret information), and a subscriber identifier (SUPI) to identify the subscriber.
[0041] HPLMN 20 includes an Authentication Server Function / Authentication Credential Repository and Processing Function (hereinafter referred to as AUSF / ARPF40). Additionally, VPLMN 30 includes a Security Anchor Function (hereinafter referred to as SEAF 50) and an Access and Mobility Management Function (hereinafter referred to as AMF 60).
[0042] AUSF / ARPF40 and SEAF 50 perform authentication processing between AUSF / ARPF40 and SEAF 50 based on requests from UE 100 roaming to VPLMN 30.
[0043] SEAF 50 provides security anchoring functionality in VPLMN 30. AMF 60 manages UE 100's access and mobility for VPLMN 30. That is, AMF 60 provides access and mobility management functions.
[0044] In addition, in this embodiment, SEAF 50 constitutes a network device that communicates with UE 100 (specifically, terminal device 110 described later).
[0045] (2) Functional block structure of wireless communication system
[0046] Next, the functional block structure of the wireless communication system 10 will be described. Specifically, the functional block structure of the UE 100 will be described. Figure 2 This is the function block structure diagram of UE 100.
[0047] like Figure 2 As shown, UE 100 consists of terminal device 110 and UICC 200. Terminal device 110 consists of the basic hardware, firmware, software, and applications of UE 100 without UICC 200, and is defined as Mobile Equipment (ME) in the 3GPP technical standard. That is, terminal device 110 can carry UICC 200 to identify the subscriber, and by carrying UICC 200, it provides the functions of UE 100.
[0048] Terminal device 110 functionally includes a wireless communication unit 120 and a K... ASME Generation Department 130, K SEAF The system includes a generation unit 140 and a security processing unit 150. Additionally, the SEAF 50 (network device) has features similar to K... ASME Generation section 130 and K SEAF The same function is applied to the generation unit 140.
[0049] The wireless communication unit 120 performs wireless communication based on the NR method. Specifically, the wireless communication unit 120 transmits and receives wireless signals with a wireless base station (gNB) based on the NR method. User data or control data is multiplexed in the wireless signal.
[0050] K ASME Generation unit 130 generates a temporary key, K, that is not permanently used. ASME(First temporary key). Additionally, ASME is an abbreviation for Access Security Management Entity.
[0051] Specifically, K ASME The generation unit 130 uses a key pair (CK and IK) generated based on the key K stored in UICC 200 to generate K. ASME .
[0052] Here, Figure 4 The key hierarchy used in the wireless communication system 10 is shown. For example... Figure 4 As shown, the UICC 200 and the AuC (Authentication Center, not shown) on the service network (HPLMN 20) side share a key K in advance. Each time authentication and key negotiation (AKA) is performed, an encryption key CK and an integrity key IK are generated.
[0053] Terminal device 110 (ME) uses a key generation function based on a serving network identifier (SNID) to generate K based on the generated encryption key CK and integrity key IK. ASME This K ASME The generation method and the K of LTE ASME The generation method is the same (refer to Chapter TS33.4016.1.1).
[0054] With K ASME Similarly, K SEAF Generation unit 140 generates a temporary key, namely K. SEAF (Second temporary key). Specifically, K SEAF Generation unit 140 generates K associated with SEAF 50 (Security Anchoring Function). SEAF .
[0055] In this embodiment, K SEAF Generation unit 140 will be generated by K ASME K generated by generation unit 130 ASME Generate as K SEAF That is, K SEAF Generating Unit 140 will K ASME K used as an association with security anchoring function SEAF (Second temporary key).
[0056] With K ASME and K SEAF Similarly, K AMF Generation unit 145 generates a temporary key, namely K. AMF (Third temporary key). Specifically, KAMF Generation unit 145 uses at least K SEAF And identify subscribers' SUPI (Subscriber Identifier) within the service network, generating K associated with AMF 60 (Access and Mobility Management Functions). AMF .
[0057] like Figure 4 As shown, terminal device 110 (ME) inputs K to the Key Derivation Function (KDF). SEAF (=K ASME ) and SUPI, generate K AMF As described below, K AMF It is shared by UE 100 and VPLMN30 (specifically, SEAF 50). Similar to terminal device 110, SEAF 50 utilizes KDF to generate K... AMF .
[0058] In addition, such as Figure 4 As shown, K AMF Used for key K NASenc and key K NASint The generation of the key K NASenc Encryption for the Non-Access Stratum (NAS) protocol between UE 100 and the network side, the key K NASint Used to ensure integrity.
[0059] K AMF The generation unit 145 can use not only K SEAF In addition to SUPI, other parameters are used to generate K. AMF Specifically, K AMF Generation unit 145 uses K SEAF SUPI and information representing the capabilities of SEAF 50 are used to generate K AMF In addition, information indicating the capabilities of SEAF 50 includes the availability of features related to communication with SEAF 50, such as so-called SEAF capabilities, versions, or specific functionalities.
[0060] Or, K AMF Generator 145 can also use K SEAF K is generated using the numbers of SUPI and the feature set of the terminal device 110 equipped with UICC 200. AMF Additionally, the function set of the terminal device 110 can also be called FeatureSetUE, which can be expressed as m=1,2,... etc., and is a type of version number.
[0061] The security processing unit 150 uses the aforementioned keys to perform security processing with the network (HPLMN 20 or VPLMN 30). That is, the security processing unit 150 uses a key pair of key K, encryption key CK, and integrity key IK to establish security between the terminal device 110 and the network.
[0062] Specifically, the security processing unit 150 encrypts the SUPI and generates a Subscription Concealed Identifier (SUCI). Furthermore, the security processing unit 150 sends an N1 message containing the generated SUCI (encrypted identifier) to the network.
[0063] In addition, the security processing unit 150 sends authentication requests to the network or receives authentication responses sent from the network.
[0064] (3) Operation of wireless communication system
[0065] Next, the operation of the wireless communication system 10 will be explained. Specifically, the authentication process of the Subscriber Identifier (SUPI) in the case of UE 100 roaming to VPLMN 30 will be explained.
[0066] Figure 3 This shows the temporary key (K) in the case of UE 100 roaming to VPLMN 30. ASME K SEAF and K AMF The generation and sharing timing of ) are assumed. Here, we assume that UE 100 is roaming to VPLMN 30.
[0067] like Figure 3 As shown, UICC 200 obtains the public key (PubK) of HPLMN 20 from terminal device 110 (ME) (S10).
[0068] Terminal device 110 uses PubK to encrypt SUPI and generate SUCI (S20). In addition, terminal device 110 sends an N1 message containing the generated SUCI to SEAF 50 on VPLMN 30 (S30).
[0069] SEAF 50 sends an Authentication Information Request (S40) containing the received SUCI to AUSF / ARPF40 on HPLMN 20.
[0070] AUSF / ARPF40 takes the encryption key CK, integrity key IK, sequence number (SQN), anonymity key (AK), and service network identifier (SNID) as inputs to the Key Derivation Function (KDF) to generate K. ASME (S50). Additionally, in Figure 3 In this context, based on the relationship in the description, it is represented as K_ASME.
[0071] AUSF / ARPF40 sends a message containing K to SEAF 50. ASME The authentication information response (S60) includes SQN, random number (RAND), expected response (HXRES), authentication token (AUTN), and SUPI.
[0072] SEAF 50 sends an authentication request (S70) containing the SQN, RAND, and AUTN to terminal device 110.
[0073] Terminal device 110 sends the SQN, RAND, and AUTN (S80) included in the authentication request to UICC 200.
[0074] UICC 200 performs AKA based on the received SQN, RAND, and AUTN, and sends the encryption key CK, integrity key IK, and response (RES) to the terminal device 110 (S90).
[0075] Terminal device 110 generates K by inputting encryption key CK, integrity key IK, SQN, AK and SNID into KDF. ASME (S100).
[0076] Thus, a key pair (encryption key CK and integrity key IK) is generated through mutual authentication between terminal device 110 and the service network (HPLMN 20). Terminal device 110 and the service network share K using the generated key pair. ASME (First temporary key).
[0077] Terminal device 110 sends a response to the authentication request, namely the authentication response (S110), to SEAF 50. The authentication response includes the RES received from UICC 200.
[0078] SEAF 50 confirms whether the RES received from terminal device 110 is consistent with HXRES (S120). If the RES is consistent with HXRES, SEAF 50 sends an authentication confirmation containing the RES to AUSF / ARPF40 (S130).
[0079] Next, terminal device 110 uses K ASME To generate K SEAF (Second temporary key), which then generates K AMF (Third temporary key) (S140). Additionally, in Figure 3 In this context, based on the relationship expressed, it is represented as K_SEAF, K_AMF.
[0080] Specifically, terminal device 110 uses the K generated in step S100 ASME Generate a security anchoring function with the roaming destination network, namely K associated with AMF 60. SEAF (Second temporary key). As described above, in this embodiment, terminal device 110 will use K ASME K used as an association with security anchoring function SEAF (Second temporary key).
[0081] In addition, terminal device 110 uses at least K SEAF And the SUPI that identifies the subscriber in the serving network (HPLMN 20) to generate a K associated with the access and mobility management functions (specifically, AMF 60) of the roaming destination network. AMF Specifically, terminal device 110 inputs K to KDF. SEAF And SUPI generates K AMF .
[0082] Furthermore, as shown by the “…” in K_AMF=(K_SEAF,SUPI,……), the terminal device 110 can use not only K SEAF In addition to SUPI, it also uses other information from SEAF 50, such as SEAF capabilities, to generate K. AMF .
[0083] Similarly, the roaming destination network (specifically SEAF 50) generates K SEAF And input K to KDF SEAF And SUPI, to generate K AMF (S150).
[0084] Additionally, as shown by the “…” in K_AMF=(K_SEAF,SUPI,,……), SEAF 50 can use not only K SEAFIn addition to SUPI, it also uses other information from SEAF 50, such as SEAF capabilities, to generate K. AMF .
[0085] Therefore, terminal device 110 uses K SEAF And to generate K by identifying subscriber SUPIs in the service network (HPLMN 20). AMF Furthermore, the roaming destination network of terminal device 110 (specifically SEAF 50) uses K notified from the serving network. SEAF And SUPI to generate K AMF Therefore, terminal device 110 shares K with the roaming destination network. SEAF and K AMF .
[0086] Furthermore, the roaming destination network can obtain a SUPI only if authentication between the terminal device 110 and the service network is successful, and obtain a K from the obtained SUPI. AMF .
[0087] Additionally, SEAF 50 can obtain SUPI from the SUCI obtained in step S30. Therefore, terminal device 110 in K SEAF and K AMF Before sharing, the SUCI (encrypted identifier) obtained by encrypting the SUPI is provided to the roaming destination network (SEAF 50).
[0088] (4) Functions and Effects
[0089] According to the above-described embodiments, the following effects can be obtained. Specifically, according to this embodiment, the terminal device 110 and VPLMN 30 respectively use K SEAF (=K ASME ) and SUPI to generate K AMF Therefore, VPLMN 30 (SEAF 50) can securely obtain K using only the SUPI of the mutually authenticated UE 100 (subscriber). SEAF and K AMF .
[0090] In other words, HPLMN 20 (AUSF / ARPF40) does not need to directly provide SUPI to VPLMN30 before successful authentication with the subscriber. Furthermore, HPLMN 20 is able to achieve high-level security of confidential information between the subscriber associated with the correctly provided SUPI and the communication operator providing VPLMN 30, while maintaining subscriber privacy.
[0091] That is, according to this embodiment, the subscriber's SUPI can be provided to the VPLMN 30 safely and conveniently, based on the established security of the terminal device 110 and HPLMN 20.
[0092] In this embodiment, terminal device 110 and SEAF 50 not only use K SEAF In addition to SUPI, it can also use other information from SEAF 50, such as SEAF capabilities, or the terminal device 110 or the SEAF 50 function set to generate K. AMF Therefore, the terminal device 110 can perform processing corresponding to the functions corresponding to SEAF 50. Similarly, SEAF 50 can access K... AMF The version of the function corresponding to the terminal device 110 is extracted, so that processing corresponding to the function of the terminal device 110 can be performed.
[0093] In this embodiment, terminal device 110 and VPLMN 30 share K. SEAF and K AMF VPLMN 30 is able to obtain K from the correct subscriber's SUPI. SEAF and K AMF This eliminates the need to query HPLMN 20. Therefore, even in cases where a Lawful Interception (LI) is required in VPLMN 30, the subscriber's LI can be performed securely and conveniently by VPLMN 30.
[0094] In this embodiment, the terminal device 110 shares K with the VPLMN 30. SEAF and K AMF Previously, the SUPI was encrypted and then sent to the VPLMN 30 (SEAF 50) to obtain the SUCI. Therefore, the VPLMN 30 can only obtain the SUPI from this SUCI and share it with the terminal device 110, along with the K associated with the corresponding SUPI. SEAF and K AMF Therefore, VPLMN 30 can securely and conveniently obtain the K associated with the subscriber's SUPI. SEAF and K AMF .
[0095] (5) Other implementation methods
[0096] The present invention has been described above according to the embodiments, but the present invention is not limited to these descriptions, and it is obvious that various modifications and improvements can be made.
[0097] For example, in the above implementation, it is described that K is shared between HPLMN 20 and VPLMN 30. SEAF and K AMF Examples, but such K SEAF and K AMF The sharing is not necessarily limited to HPLMN and VPLMN. For HPLMN 20, any network (serving network) that the UE 100 subscriber has signed up for is acceptable. For VPLMN 30, any network (roaming destination network) that the subscriber has not directly signed up for, i.e., does not have a SUPI allocated by the telecommunications operator, is acceptable.
[0098] Furthermore, the block diagrams used in the above description of the embodiments ( Figure 2 The diagram illustrates the functional blocks. These functional blocks (components) can be implemented through any combination of hardware and / or software. Furthermore, there are no particular limitations on the means of implementing each functional block. That is, each functional block can be implemented through a single device that is physically and / or logically combined, or through multiple devices that are physically and / or logically separate (e.g., via wired and / or wireless connections) that are directly connected and / or indirectly connected.
[0099] In addition, the UE 100 (terminal device 110) described above can function as a computer for performing the processing of the present invention. Figure 5 This is a diagram illustrating an example of the hardware structure of UE 100. (See diagram below.) Figure 5 As shown, UE 100 can be configured as a computer device including processor 1001, memory 1002, storage 1003, communication device 1004, input device 1005, output device 1006, and bus 1007.
[0100] Functional blocks of UE 100 (refer to) Figure 2 This can be achieved through any hardware element of the computer device, or a combination of such hardware elements.
[0101] The processor 1001, for example, enables the operating system to operate and controls the computer as a whole. The processor 1001 may also be composed of a central processing unit (CPU) that includes interfaces with peripheral devices, control devices, arithmetic devices, registers, etc.
[0102] Memory 1002 is a computer-readable recording medium, and may be composed of at least one of ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), RAM (Random Access Memory), etc. Memory 1002 may also be referred to as a register, cache, main memory (main storage device), etc. Memory 1002 can store programs (program code), software modules, etc., that can execute the methods involved in the above embodiments.
[0103] The memory 1003 is a computer-readable recording medium, which may be composed of at least one of the following: CD-ROM (CD-ROM disk), hard disk drive, floppy disk, magneto-optical disk (e.g., CD-ROM, digital multifunction disk, Blu-ray disc), smart card, flash memory (e.g., card, stick, key drive), floppy disk, magnetic stripe, etc. The memory 1003 may also be referred to as an auxiliary storage device. The aforementioned storage medium may be, for example, a database, server, or other suitable medium that includes memory 1002 and / or memory 1003.
[0104] The communication device 1004 is hardware (transceiver) used for communication between computers via wired and / or wireless networks. For example, it may also be called a network device, network controller, network card, communication module, etc.
[0105] Input device 1005 is an input device that accepts input from external sources (e.g., keyboard, mouse, microphone, switch, button, sensor, etc.). Output device 1006 is an output device that performs output to external sources (e.g., display, speaker, LED, etc.). Alternatively, input device 1005 and output device 1006 can also be integrated (e.g., a touch panel).
[0106] Furthermore, the processor 1001, memory 1002, and other devices are connected via a bus 1007 for communicating information. The bus 1007 can consist of a single bus or different buses between devices.
[0107] Furthermore, information notification is not limited to the above-described implementation methods and can also be performed through other methods. For example, information notification can be implemented through physical layer signaling (e.g., DCI (Downlink Control Information), UCI (Uplink Control Information)), higher layer signaling (e.g., RRC (Radio Resource Control) signaling, MAC (Medium Access Control) signaling, broadcast information (MIB (Master Information Block), SIB (System Information Block)), other signals, or combinations thereof. Additionally, RRC signaling can also be referred to as RRC messages, such as RRC Connection Setup messages, RRC Connection Reconfiguration messages, etc.
[0108] Furthermore, input or output information can be stored in a specific location (e.g., memory) or managed in a management table. Input or output information can be rewritten, updated, or appended. Output information can also be deleted. Input information can also be sent to other devices.
[0109] The order of the processes and procedures in the above implementation methods can be changed as long as there is no contradiction.
[0110] Furthermore, in the above embodiments, specific actions performed by AUSF / ARPF40 or SEAF 50 are sometimes also performed by other network nodes (devices). Additionally, the functionality of AUSF / ARPF40 or SEAF 50 can be provided by a combination of multiple other network nodes.
[0111] Furthermore, the terms used in this specification and / or for understanding this specification may be replaced with terms that have the same or similar meanings. For example, where there is a corresponding description, a channel and / or symbol may be a signal. Furthermore, a signal may be a message. Additionally, terms such as "system" and "network" may be used interchangeably.
[0112] In addition, parameters can be represented by absolute values, relative values with respect to specified values, or other corresponding information. For example, wireless resources can be indicated by indexes.
[0113] A gNB (base station) can accommodate one or more (e.g., three) cells (also called sectors). When a base station accommodates multiple cells, the overall coverage area of the base station can be divided into multiple smaller areas, and each of these smaller areas can also provide communication services through a base station subsystem (e.g., a small indoor base station RRH: Remote Radio Head).
[0114] Terms such as "cell" or "sector" refer to a portion or the entire coverage area of a base station and / or base station subsystem that provides communication services within that coverage area.
[0115] Furthermore, the terms "base station," "eNB," "cell," and "sector" can be used interchangeably in this manual. For base stations, the following terms are also used: fixed station, NodeB, eNodeB (eNB), gNodeB (gNB), access point, femtocell, small cell, etc.
[0116] For UE 100, those skilled in the art sometimes also use the following terms: subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handheld device, user agent, mobile client, client, or some other appropriate terms.
[0117] The use of the word "according to" in this specification, unless otherwise stated, does not mean "according to only". In other words, the use of the word "according to" means both "according to only" and "according to at least" both.
[0118] Furthermore, the terms "including," "comprising," and their variations are intended to mean "inclusive" in the same way as "having." Additionally, the term "or" used in this specification or claims means not XOR.
[0119] Any reference to elements using the terms "first," "second," etc., as used in this specification does not necessarily limit the number or order of these elements. These designations are used in this specification as a convenient way to distinguish between two or more elements. Therefore, reference to the first or second element does not imply that only two elements can be used here, or that in any form the first element must precede the second element.
[0120] Throughout this specification, for example, where articles such as a, an, and the are added in translation, these articles may be considered to include multiple articles unless the context clearly indicates otherwise.
[0121] Embodiments of the present invention have been described as above, but the discussions and drawings that form part of this disclosure should not be construed as limiting the invention. Various alternative embodiments, examples, and applications will be apparent to those skilled in the art based on this disclosure.
[0122] Label Explanation:
[0123] 10 Wireless Communication Systems
[0124] 20HPLMN
[0125] 30VPLMN
[0126] 40AUSF / ARPF
[0127] 50SEAF
[0128] 60AMF
[0129] 100UE
[0130] 110 terminal device
[0131] 120 Wireless Communications Department
[0132] 130K ASME Generation Department
[0133] 140K SEAF Generation Department
[0134] 145K AMF Generation Department
[0135] 150 Security Processing Department
[0136] 200UICC
[0137] 1001 processor
[0138] 1002 memory
[0139] 1003 Memory
[0140] 1004 Communication device
[0141] 1005 Input Device
[0142] 1006 Output Device
[0143] 1007 bus
Claims
1. A security establishment method, wherein the security establishment method uses secret information stored in a subscriber identification module for identifying subscribers and a key pair of an encryption key and an integrity key generated based on the secret information to establish the security of a terminal device equipped with the subscriber identification module, wherein, The security establishment method includes the following steps: The key pair is generated through mutual authentication between the terminal device and the service network, and the terminal device and the service network share the first temporary key using the generated key pair; The terminal device uses the first temporary key to generate a second temporary key associated with the security anchoring function of the roaming destination network of the terminal device, and the roaming destination network obtains the second temporary key; as well as The terminal device and the roaming destination network input the second temporary key and the subscriber identifier that identifies the subscriber in the service network into the key derivation function (KDF) to generate a third temporary key associated with the access and mobility management functions of the roaming destination network.
2. The security establishment method according to claim 1, wherein, The third temporary key is generated by inputting information about the capabilities or feature set of the security anchoring function into the KDF.
3. A terminal device, said terminal device being equipped with a subscriber identification module for identifying subscribers, wherein, The terminal device has: The first key generation unit generates a first temporary key using a key pair of an encryption key and an integrity key generated based on the secret information stored in the subscriber identification module. The second key generation unit uses the first temporary key to generate a second temporary key associated with the security anchoring function of the roaming destination network of the terminal device; as well as The third key generation unit inputs the second temporary key and the subscriber identifier that identifies the subscriber in the service network into the key derivation function (KDF) to generate a third temporary key associated with the access and mobility management functions of the roaming destination network.
4. The terminal device according to claim 3, wherein, The third key generation unit inputs information about the capabilities or feature set of the security anchoring function into the KDF to generate the third temporary key.
5. A network device that communicates with a terminal device capable of carrying a subscriber identification module for identifying subscribers, wherein, The network device has: The second key generation unit obtains a second temporary key associated with the security anchoring function of the roaming destination network of the terminal device; as well as The third key generation unit inputs the second temporary key and the subscriber identifier that identifies the subscriber in the service network into the key derivation function (KDF) to generate a third temporary key associated with the access and mobility management functions of the roaming destination network.
6. The network device according to claim 5, wherein, The third key generation unit inputs information about the capabilities or feature set of the security anchoring function into the KDF to generate the third temporary key.