Method and related apparatus for algorithm negotiation in a generic booting architecture

By guiding the server function network element to obtain and select the algorithm supported by the terminal device, the algorithm compatibility problem caused by the inconsistency of BSF versions in the 3GPP network is solved, and the security consistency authentication between the terminal device and BSF is realized.

CN116250211BActive Publication Date: 2025-11-07HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080104591.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-07
Publication Date
2025-11-07
Estimated Expiration
2040-08-07

AI Technical Summary

Technical Problem

In the 3GPP network architecture, inconsistencies in the BSF versions of terminal devices and the network lead to algorithm compatibility issues, causing the General Bootstrap Architecture (GBA) to fail.

Method used

The guidance server function network element obtains the algorithms supported by the terminal device, selects the target algorithm, and verifies the message authentication code through the target algorithm to ensure that the terminal device and BSF use the same algorithm, thus solving the algorithm compatibility problem.

Benefits of technology

It improves security, ensures algorithm consistency between terminal devices and BSF, and avoids GBA failures caused by different algorithms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116250211B_ABST
    Figure CN116250211B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an algorithm negotiation method in a general booting architecture and related apparatus, the method comprising: a boot server function network element obtaining an algorithm supported by a terminal device, the algorithm supported by the terminal device comprising a first algorithm and / or a second algorithm; the boot server function network element selecting a target algorithm according to the algorithm supported by the terminal device; the boot server function network element determining a first message authentication code according to the target algorithm; and the boot server function network element sending the first message authentication code to the terminal device, thereby solving the algorithm compatibility problem between the terminal device and the BSF of new and old versions in the network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and particularly relates to an algorithm negotiation method in a generic bootstrapping architecture and a related device. BACKGROUND

[0002] A security mechanism is provided in the 3rd Generation Partnership Project (3GPP) for mutual authentication and key generation between a terminal device and a bootstrapping server function (BSF) in a network, so as to perform secure communication. The generic bootstrapping architecture (GBA) is a generic mechanism defined by the 3GPP for mutual authentication and key negotiation between a terminal device and a BSF in a network.

[0003] With the continuous development of information technology, in the 3GPP network architecture, there is a problem of inconsistency between a terminal device and a BSF in a network. Due to the inconsistency between the terminal device and the BSF in the network, different algorithms are used to determine authentication credentials, which leads to failure of the generic bootstrapping architecture (GBA). Therefore, how to solve the compatibility problem of the new and old versions of the terminal device and the BSF in the network in the GBA is a technical problem to be solved by those skilled in the art. SUMMARY

[0004] Embodiments of the present application disclose an algorithm negotiation method in a generic bootstrapping architecture and a related device, which can solve the algorithm compatibility problem of the new and old versions of a terminal device and a BSF in a network.

[0005] A first aspect of embodiments of the present application discloses an algorithm negotiation method in a generic bootstrapping architecture, comprising:

[0006] A bootstrapping server function network element acquires an algorithm supported by a terminal device, wherein the algorithm supported by the terminal device comprises a first algorithm and / or a second algorithm;

[0007] The bootstrapping server function network element selects a target algorithm according to the algorithm supported by the terminal device;

[0008] The bootstrapping server function network element determines a first message authentication code according to the target algorithm;

[0009] The bootstrapping server function network element sends the first message authentication code to the terminal device.

[0010] In the method, the BSF selects a target algorithm according to an algorithm supported by the terminal device, and then verifies the first message authentication code through the target algorithm, thereby improving security, and the first message authentication code is sent to the terminal device, so that the terminal device and the BSF use the same algorithm, and the algorithm compatibility problem of the terminal device and the BSF is solved.

[0011] In a possible implementation, the method further includes: the bootstrapping server function network element sending the target algorithm to the terminal device.

[0012] In the method, the BSF sends the target algorithm to the terminal device, so that the terminal device and the BSF use different algorithms to verify the AUTN*, the algorithm consistency of the BSF and the terminal device is ensured, and the algorithm compatibility problem of the BSF and the terminal device is solved.

[0013] In another possible implementation, the first algorithm includes a secure hash algorithm 1, and the second algorithm includes a secure hash algorithm 256.

[0014] In another possible implementation, the bootstrapping server function network element obtaining the algorithm supported by the terminal device includes: the bootstrapping server function network element receiving the algorithm supported by the terminal device or first indication information or a first identifier or a second identifier from the terminal device; the bootstrapping server function network element determining, according to the first indication information, that the algorithm supported by the terminal device includes the second algorithm; or the bootstrapping server function network element determining, according to the first identifier, that the algorithm supported by the terminal device includes the second algorithm, the first identifier being generated according to the second identifier; or the bootstrapping server function network element determining that the terminal device supports the first algorithm according to the second identifier.

[0015] In the method, the algorithm supported by the terminal device can be quickly determined through the first indication information or the first identifier or the second identifier, which is simple, convenient, and time-saving.

[0016] In another possible implementation, the first identifier is generated according to the second identifier, including: the first identifier is generated according to the second identifier and an identifier protection key IPK.

[0017] In another possible implementation, the bootstrapping server function network element receives the algorithm supported by the terminal device or first indication information or a first identifier or a second identifier from the terminal device, including: the bootstrapping server function network element receiving a first bootstrapping request message from the terminal device, the first bootstrapping request message including the algorithm supported by the terminal device or the first indication information or the first identifier or the second identifier.

[0018] In the method, the resources can be reasonably utilized by carrying the algorithm supported by the terminal device or the first indication information or the first identifier or the second identifier in the first bootstrapping request message.

[0019] In a further possible implementation, the second identifier is one of a subscription permanent identifier (SUPI) of the terminal device, an Internet Protocol Multimedia Private Identity (IMPI) of the terminal device, an International Mobile Subscriber Identity (IMSI) of the terminal device, and a Generic Public Subscription Identifier (GPSI) of the terminal device.

[0020] In a further possible implementation, the bootstrapping server function network element acquires the algorithm supported by the terminal device, including: the bootstrapping server function network element receives second indication information or a second algorithm supported by the terminal device from the home subscriber server network element; the second indication information is used to indicate that the algorithm supported by the terminal device includes the second algorithm; and the bootstrapping server function network element determines, according to the second indication information, that the algorithm supported by the terminal device includes the second algorithm.

[0021] In the method, the algorithm supported by the terminal device includes the second algorithm can be quickly determined by the second indication information, which is simple, convenient, and time-saving.

[0022] In a further possible implementation, the bootstrapping server function network element determines a first message authentication code (MAC*) according to the target algorithm, including: the bootstrapping server function network element receives a second message authentication code (MAC) from the home subscriber server network element; and the bootstrapping server function network element determines the first message authentication code (MAC*) according to the target algorithm and the second message authentication code (MAC).

[0023] In a further possible implementation, the bootstrapping server function network element receives second indication information or an algorithm supported by the terminal device from the home subscriber server network element, including: the bootstrapping server function network element sends a first request message to the home subscriber server network element; and the bootstrapping server function network element receives a first response message from the home subscriber server network element, where the first response message includes the second indication information or the algorithm supported by the terminal device.

[0024] In the method, the resources can be reasonably utilized by including the second indication information or the algorithm supported by the terminal device in the first response message.

[0025] In a further possible implementation, before the guiding server function network element selects the target algorithm according to the algorithm supported by the terminal device, the method further includes: the guiding server function network element determining to use a general booting architecture enhanced based on a universal integrated circuit card (GBA_U) mechanism.

[0026] In a further possible implementation, the guiding server function network element selects the target algorithm according to the algorithm supported by the terminal device, including: if the algorithm supported by the terminal device includes the second algorithm, the guiding server function network element selects the second algorithm as the target algorithm.

[0027] In a further possible implementation, after the guiding server function network element acquires the algorithm supported by the terminal device, and before the guiding server function network element selects the target algorithm according to the algorithm supported by the terminal device, the method further includes: the guiding server function network element determining whether the guiding server function network element supports the algorithm supported by the terminal device; after the guiding server function network element determines to support the algorithm supported by the terminal device, the guiding server function network element performs the selecting of the target algorithm; after the guiding server function network element determines not to support the algorithm supported by the terminal device, the guiding server function network element sends third indication information to the terminal device, the third indication information being used to instruct the terminal device to use a general booting architecture based on a mobile equipment (GBA_ME) mechanism.

[0028] The second aspect of the embodiments of the present application discloses a method for algorithm negotiation in a general booting architecture, including:

[0029] The terminal device generates a first booting request message;

[0030] The terminal device sends the first booting request message to a guiding server function network element, the first booting request message including an algorithm supported by the terminal device or a first identifier or a second identifier or first indication information; the algorithm supported by the terminal device including a first algorithm and / or a second algorithm; the first identifier being used to instruct that the algorithm supported by the terminal device includes the second algorithm, the second identifier being used to instruct that the terminal device supports the first algorithm, the first identifier being generated according to the second identifier; the first indication information being used to instruct that the algorithm supported by the terminal device includes the second algorithm;

[0031] The terminal device receives a first message authentication code or a second message authentication code from the guiding server function network element.

[0032] In the method, the first guiding request message includes the algorithm supported by the terminal device, the first identifier, the second identifier or the first indication information, so that the BSF can quickly determine the algorithm supported by the terminal device after receiving the first guiding request message, time is saved, and resources are reasonably used.

[0033] In a possible implementation, the first algorithm includes a secure hash algorithm 1, and the second algorithm includes a secure hash algorithm 256.

[0034] In another possible implementation, the first identifier is generated according to the second identifier, including that the first identifier is generated according to the second identifier and an identity protection key IPK.

[0035] In another possible implementation, the second identifier is one of a subscription permanent identifier SUPI of the terminal device, an internet protocol multimedia private identity IMPI of the terminal device, an international mobile subscriber identity IMSI of the terminal device, or a general public subscription identity GPSI of the terminal device.

[0036] In another possible implementation, the terminal device receives a first message authentication code (MAC*) from a bootstrapping server function network element; and the method further includes that the terminal device receives a target algorithm from the bootstrapping server function network element, the target algorithm being determined according to the algorithm supported by the terminal device; the terminal device determines the second message authentication code using the target algorithm and the first message authentication code; and the second message authentication code is used to authenticate the bootstrapping server function network element.

[0037] In the method, the terminal device receives the target algorithm from the BSF, so that the terminal device and the BSF can avoid using different algorithms to verify the AUTN*, the algorithm consistency of the BSF and the terminal device is ensured, and the algorithm compatibility problem of the BSF and the terminal device is solved.

[0038] In another possible implementation, before the terminal device generates the first guiding request message, the method further includes that a mobile equipment ME of the terminal device reads an algorithm supported by a universal integrated circuit card UICC of the terminal device; and the algorithm supported by the terminal device is the algorithm supported by the universal integrated circuit card UICC.

[0039] In a further possible implementation, the terminal device receives a second message authentication code from the bootstrapping server function network element; the method further includes that the terminal device receives third indication information from the bootstrapping server function network element, the third indication information being used to indicate that the terminal device adopts a mobile equipment based generic bootstrapping architecture (GBA_ME) mechanism; and the terminal device verifies the second message authentication code.

[0040] A third aspect of the embodiments of the present application discloses a method for algorithm negotiation in a generic bootstrapping architecture, including:

[0041] A home subscriber server network element receives a first request message from a bootstrapping server function network element;

[0042] The home subscriber server network element sends a first response message to the bootstrapping server function network element, the first response message including an algorithm supported by the terminal device or second indication information, the algorithm supported by the terminal device including a first algorithm and / or a second algorithm, and the second indication information being used to indicate that the algorithm supported by the terminal device includes the second algorithm.

[0043] In the above method, the HSS can quickly determine the algorithm supported by the terminal device after the BSF receives the first response message by including the algorithm supported by the terminal device or the second indication information in the first response message, thereby saving time and reasonably utilizing resources.

[0044] In a possible implementation, the first algorithm includes a secure hash algorithm 1, and the second algorithm includes a secure hash algorithm 256.

[0045] A fourth aspect of the embodiments of the present application discloses an apparatus for algorithm negotiation in a generic bootstrapping architecture, including:

[0046] A processing unit is configured to acquire an algorithm supported by a terminal device, the algorithm supported by the terminal device including a first algorithm and / or a second algorithm;

[0047] The processing unit is further configured to select a target algorithm according to the algorithm supported by the terminal device;

[0048] The processing unit is further configured to determine a first message authentication code according to the target algorithm;

[0049] A communication unit is configured to send the first message authentication code to the terminal device.

[0050] In a possible implementation, the communication unit is further configured to send the target algorithm to the terminal device.

[0051] In a further possible implementation, the first algorithm comprises a secure hash algorithm 1, and the second algorithm comprises a secure hash algorithm 256.

[0052] In a further possible implementation, the communication unit is further configured to receive, from the terminal device, the algorithm supported by the terminal device or the first indication information or a first identifier or a second identifier; the processing unit is further configured to determine, according to the first indication information, that the algorithm supported by the terminal device comprises the second algorithm; or the processing unit is further configured to determine, according to the first identifier, that the algorithm supported by the terminal device comprises the second algorithm, the first identifier being generated according to the second identifier; or the processing unit is further configured to determine, according to the second identifier, that the terminal device supports the first algorithm.

[0053] In a further possible implementation, the first identifier is generated according to the second identifier and an identity protection key IPK.

[0054] In a further possible implementation, the communication unit is further configured to receive, from the terminal device, a first bootstrapping request message, the first bootstrapping request message comprising the algorithm supported by the terminal device or the first indication information or the first identifier or the second identifier.

[0055] In a further possible implementation, the second identifier is one of a subscription permanent identifier SUPI of the terminal device, an internet protocol multimedia private identity IMPI of the terminal device, an international mobile subscriber identity IMSI of the terminal device, or a generic public subscription identity GPSI of the terminal device.

[0056] In a further possible implementation, the communication unit is further configured to receive, from the home subscriber server network element, the second indication information or a second algorithm supported by the terminal device; the second indication information is used to indicate that the algorithm supported by the terminal device comprises the second algorithm; and the processing unit is further configured to determine, according to the second indication information, that the algorithm supported by the terminal device comprises the second algorithm.

[0057] In a further possible implementation, the communication unit is further configured to send, to the home subscriber server network element, a first request message; and the communication unit is further configured to receive, from the home subscriber server network element, a first response message, the first response message comprising the second indication information or the algorithm supported by the terminal device.

[0058] In a further possible implementation, the processing unit is further configured to determine, before selecting a target algorithm according to the algorithm supported by the terminal device, to use a generic bootstrapping architecture enhanced for universal integrated circuit card GBA_U mechanism.

[0059] In a further possible implementation, the processing unit is further configured to select the second algorithm as the target algorithm when the algorithms supported by the terminal device include the second algorithm.

[0060] In a further possible implementation, the processing unit is further configured to determine whether the algorithms supported by the terminal device are supported after obtaining the algorithms supported by the terminal device, and before selecting the target algorithm according to the algorithms supported by the terminal device; the processing unit is further configured to perform the selection of the target algorithm after determining that the algorithms supported by the terminal device are supported; and the processing unit is further configured to determine that the algorithms supported by the terminal device are not supported, and send third indication information to the terminal device, the third indication information being used to instruct the terminal device to adopt a mobile equipment based generic bootstrapping architecture (GBA_ME) mechanism.

[0061] As to the technical effects brought by the fourth aspect or the various optional implementations, reference can be made to the introduction of the technical effects of the first aspect or the corresponding implementation.

[0062] The fifth aspect of the embodiments of the present application discloses an algorithm negotiation apparatus in a generic bootstrapping architecture, comprising:

[0063] a processing unit configured to generate a first bootstrapping request message;

[0064] a communication unit configured to send the first bootstrapping request message to a bootstrapping server function network element, the first bootstrapping request message including algorithms supported by the terminal device or a first identifier or a second identifier or first indication information; the algorithms supported by the terminal device including a first algorithm and / or a second algorithm; the first identifier being used to indicate that the algorithms supported by the terminal device include the second algorithm, the second identifier being used to indicate that the terminal device supports the first algorithm, the first identifier being generated according to the second identifier; and the first indication information being used to indicate that the algorithms supported by the terminal device include the second algorithm.

[0065] The communication unit is further configured to receive a first message authentication code or a second message authentication code from the bootstrapping server function network element.

[0066] In a possible implementation, the first algorithm includes a secure hash algorithm 1, and the second algorithm includes a secure hash algorithm 256.

[0067] In a further possible implementation, the first identifier is generated according to the second identifier and an identity protection key (IPK).

[0068] In a further possible implementation, the second identity is one of a subscription permanent identity (SUPI) of the terminal device, an Internet Protocol Multimedia Private Identity (IMPI) of the terminal device, an International Mobile Subscriber Identity (IMSI) of the terminal device, and a Generic Public Subscription Identity (GPSI) of the terminal device.

[0069] In a further possible implementation, the communication unit is configured to receive a target algorithm from the bootstrapping server function network element, the target algorithm being determined according to the algorithm supported by the terminal device; and the processing unit is configured to determine the second message authentication code using the target algorithm and the first message authentication code; and the second message authentication code is used to authenticate the bootstrapping server function network element.

[0070] In a further possible implementation, the processing unit is further configured to read an algorithm supported by a universal integrated circuit card (UICC) of the terminal device before generating the first bootstrapping request message; and the algorithm supported by the terminal device is the algorithm supported by the universal integrated circuit card (UICC).

[0071] In a further possible implementation, the communication unit is further configured to receive third indication information from the bootstrapping server function network element, the third indication information being used to indicate that the terminal device adopts a generic bootstrapping architecture for mobiles (GBA_ME) mechanism; and the processing unit is further configured to verify the second message authentication code.

[0072] As to the technical effects brought by the fifth aspect or various possible implementations, reference can be made to the introduction of the technical effects of the second aspect or corresponding implementations.

[0073] The sixth aspect of the embodiments of the present application discloses an algorithm negotiation apparatus in a generic bootstrapping architecture, comprising:

[0074] The processing unit is configured to receive a first request message from a bootstrapping server function network element through the communication unit;

[0075] The communication unit is further configured to send a first response message to the bootstrapping server function network element, the first response message comprising the algorithm supported by the terminal device or second indication information, the algorithm supported by the terminal device comprising a first algorithm and / or a second algorithm, and the second indication information being used to indicate that the algorithm supported by the terminal device comprises the second algorithm.

[0076] In a possible implementation, the first algorithm comprises a secure hash algorithm 1, and the second algorithm comprises a secure hash algorithm 256.

[0077] As to the technical effects brought by the sixth aspect or various optional implementations, refer to the introduction of the technical effects of the third aspect or corresponding implementations.

[0078] The seventh aspect of the embodiments of the present application discloses an algorithm negotiation device in a general booting architecture, comprising at least one processor and a transceiver, wherein the at least one processor is configured to communicate with other devices through the transceiver, the memory is configured to store a computer program, and the processor is configured to invoke the computer program to perform the following operations:

[0079] Obtaining an algorithm supported by a terminal device, wherein the algorithm supported by the terminal device comprises a first algorithm and / or a second algorithm;

[0080] Selecting a target algorithm according to the algorithm supported by the terminal device;

[0081] Determining a first message authentication code according to the target algorithm;

[0082] Sending the first message authentication code to the terminal device through the transceiver.

[0083] In a possible implementation, the processor is further configured to send the target algorithm to the terminal device through the transceiver.

[0084] In another possible implementation, the first algorithm comprises a secure hash algorithm 1, and the second algorithm comprises a secure hash algorithm 256.

[0085] In another possible implementation, the processor is further configured to receive the algorithm supported by the terminal device or first indication information or a first identifier or a second identifier from the terminal device through the transceiver; determine that the algorithm supported by the terminal device comprises the second algorithm according to the first indication information; or determine that the terminal device supports the first algorithm according to the second identifier, or determine that the algorithm supported by the terminal device comprises the second algorithm according to the first identifier, wherein the first identifier is generated according to the second identifier.

[0086] In another possible implementation, the first identifier is generated according to the second identifier and an identifier protection key IPK.

[0087] In another possible implementation, the processor is further configured to receive a first booting request message from the terminal device through the transceiver, wherein the first booting request message comprises the algorithm supported by the terminal device or the first indication information or the first identifier or the second identifier.

[0088] In a further possible implementation, the second identity is one of a subscription permanent identity (SUPI) of the terminal device, an Internet Protocol Multimedia Private Identity (IMPI) of the terminal device, an International Mobile Subscriber Identity (IMSI) of the terminal device, and a Generic Public Subscription Identity (GPSI) of the terminal device.

[0089] In a further possible implementation, the processor is further configured to receive, by the transceiver, second indication information from the home subscriber server network element or a second algorithm supported by the terminal device, and determine, according to the second indication information, that the algorithm supported by the terminal device includes the second algorithm.

[0090] In a further possible implementation, the processor is further configured to send, by the transceiver, a first request message to the home subscriber server network element, and receive, by the transceiver, a first response message from the home subscriber server network element, the first response message including the second indication information or the algorithm supported by the terminal device.

[0091] In a further possible implementation, the processor is further configured to determine, before selecting the target algorithm according to the algorithm supported by the terminal device, to use a generic bootstrapping architecture for UMTS authentication mechanism (GBA_U) mechanism.

[0092] In a further possible implementation, the processor is further configured to select, when the algorithm supported by the terminal device includes the second algorithm, the second algorithm as the target algorithm.

[0093] In a further possible implementation, the processor is further configured to, after obtaining the algorithm supported by the terminal device and before selecting the target algorithm according to the algorithm supported by the terminal device, determine whether to support the algorithm supported by the terminal device, select the target algorithm after determining to support the algorithm supported by the terminal device, and send, by the transceiver, third indication information to the terminal device, the third indication information indicating that the terminal device uses a generic bootstrapping architecture for mobile equipment (GBA_ME) mechanism.

[0094] As to the technical effects brought by the seventh aspect or various possible implementation manners, refer to the introduction of the technical effects of the first aspect or corresponding implementation manners.

[0095] The eighth aspect of the embodiments of the present application discloses an algorithm negotiation device in a general booting architecture, comprising at least one processor and a transceiver, wherein the at least one processor is configured to communicate with other devices through the transceiver, the memory is configured to store a computer program, and the processor is configured to invoke the computer program to perform the following operations:

[0096] generating a first booting request message;

[0097] sending the first booting request message to a booting server function network element through the transceiver, wherein the first booting request message comprises an algorithm supported by the terminal device or a first identifier or a second identifier or first indication information; the algorithm supported by the terminal device comprises a first algorithm and / or a second algorithm; the first identifier is used to indicate that the algorithm supported by the terminal device comprises the second algorithm, the second identifier is used to indicate that the terminal device supports the first algorithm, and the first identifier is generated according to the second identifier; and the first indication information is used to indicate that the algorithm supported by the terminal device comprises the second algorithm;

[0098] receiving a first message authentication code or a second message authentication code from the booting server function network element through the transceiver.

[0099] In a possible implementation, the first algorithm comprises a secure hash algorithm 1, and the second algorithm comprises a secure hash algorithm 256.

[0100] In another possible implementation, the first identifier is generated according to the second identifier and an identifier protection key IPK.

[0101] In another possible implementation, the second identifier is one of a subscription permanent identifier SUPI of the terminal device, an internet protocol multimedia private identity IMPI of the terminal device, an international mobile subscriber identity IMSI of the terminal device, and a general public subscription identity GPSI of the terminal device.

[0102] In another possible implementation, the processor is further configured to receive a target algorithm from the booting server function network element through the transceiver, wherein the target algorithm is determined according to the algorithm supported by the terminal device; the second message authentication code is determined using the target algorithm and the first message authentication code; and the second message authentication code is used to authenticate the booting server function network element.

[0103] In another possible implementation, the processor is further configured to read an algorithm supported by a universal integrated circuit card UICC of the terminal device before generating the first booting request message; and the algorithm supported by the terminal device is the algorithm supported by the universal integrated circuit card UICC.

[0104] In a further possible implementation form of the eighth aspect, the processing unit is further configured to receive, via the transceiver, third indication information from the bootstrapping server function network element, the third indication information indicating that the terminal device is to employ a mobile equipment based generic bootstrapping architecture (GBA_ME) mechanism, and verify the second message authentication code.

[0105] As to the technical effects brought by the eighth aspect or the various optional implementation forms, reference can be made to the introduction of the technical effects of the second aspect or the corresponding implementation forms.

[0106] The ninth aspect of the embodiments of the present application discloses an algorithm negotiation apparatus in a generic bootstrapping architecture, comprising at least one processor and a transceiver, wherein the at least one processor is configured to communicate with other apparatuses via the transceiver, and the memory is configured to store a computer program, and the processor is configured to invoke the computer program to perform the following operations:

[0107] receiving, via the transceiver, a first request message from a bootstrapping server function network element;

[0108] sending, via the transceiver, a first response message to the bootstrapping server function network element, the first response message comprising an algorithm supported by the terminal device or second indication information, the algorithm supported by the terminal device comprising a first algorithm and / or a second algorithm, and the second indication information indicating that the algorithm supported by the terminal device comprises the second algorithm.

[0109] In a possible implementation form of the ninth aspect, the first algorithm comprises a secure hash algorithm 1, and the second algorithm comprises a secure hash algorithm 256.

[0110] As to the technical effects brought by the ninth aspect or the various optional implementation forms, reference can be made to the introduction of the technical effects of the third aspect or the corresponding implementation forms.

[0111] The tenth aspect of the embodiments of the present application discloses a chip, comprising at least one processor and an interface circuit, and optionally further comprising a memory, wherein the memory, the interface circuit and the at least one processor are interconnected through a circuit, and the at least one memory stores a computer program; the computer program is executed by the processor to implement the method described in any aspect or any possible implementation form of the aspect.

[0112] The eleventh aspect of the embodiments of the present application discloses a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method described in any aspect or any possible implementation form of the aspect.

[0113] The twelfth aspect of the embodiment of the present application discloses a computer product, when the computer program product is run on a processor, a method described in any aspect or any possible implementation manner of the aspect is implemented.

[0114] The thirteenth aspect of the embodiment of the present application discloses an algorithm negotiation system in a general booting architecture, comprising a first device and a second device, wherein the first device is the device described in the seventh aspect or any possible implementation manner of the seventh aspect, and the second device is the device described in the ninth aspect or any possible implementation manner of the ninth aspect. BRIEF DESCRIPTION OF DRAWINGS

[0115] Figure 1 is a GBA schematic diagram provided by the embodiment of the present application;

[0116] Figure 2 is a booting request flow schematic diagram provided by the embodiment of the present application;

[0117] Figure 3 is an authentication vector generation schematic diagram provided by the embodiment of the present application;

[0118] Figure 4 is an execution service access flow schematic diagram provided by the embodiment of the present application;

[0119] Figure 5 is a flow schematic diagram of an algorithm negotiation method in a general booting architecture provided by the embodiment of the present application;

[0120] Figure 6 is a flow schematic diagram of an algorithm negotiation method in a general booting architecture provided by the embodiment of the present application;

[0121] Figure 7 is a flow schematic diagram of an algorithm negotiation method in a general booting architecture provided by the embodiment of the present application;

[0122] Figure 8 is a flow schematic diagram of an algorithm negotiation method in a general booting architecture provided by the embodiment of the present application;

[0123] Figure 9 is a flow schematic diagram of an algorithm negotiation method in a general booting architecture provided by the embodiment of the present application;

[0124] Figure 10 is a structure schematic diagram of an algorithm negotiation device in a general booting architecture provided by the embodiment of the present application;

[0125] Figure 11 is a structure schematic diagram of an algorithm negotiation device in a general booting architecture provided by the embodiment of the present application;

[0126] Figure 12 is a structural schematic diagram of an algorithm negotiation device in a general bootstrapping architecture provided by an embodiment of the present application;

[0127] Figure 13 is a structural schematic diagram of an algorithm negotiation device in a general bootstrapping architecture provided by an embodiment of the present application;

[0128] Figure 14 is a structural schematic diagram of an algorithm negotiation device in a general bootstrapping architecture provided by an embodiment of the present application;

[0129] Figure 15 is a structural schematic diagram of an algorithm negotiation device in a general bootstrapping architecture provided by an embodiment of the present application. DETAILED DESCRIPTION

[0130] The embodiments of the present application are described below with reference to the accompanying drawings.

[0131] A security mechanism is provided in the 3rd Generation Partnership Project (3GPP) for mutual authentication and key generation between a terminal device and a bootstrapping server function (BSF) in a network, so as to perform secure communication. The generic bootstrapping architecture (GBA) is a general mechanism defined by the 3GPP for mutual authentication and key negotiation between a terminal device and a BSF in a network. As shown in FIG. 1, Figure 1 a GBA schematic diagram is shown. The specific functions of each logical entity in the GBA architecture are as follows: Figure 1 (1) Bootstrapping Server Function (BSF): can be referred to as a bootstrapping server function network element, the BSF serves as a bootstrapping service function and is located in a home network of a user. The BSF obtains a user security setting and an authentication vector of the GBA from a home subscriber server (HSS) and completes authentication of a terminal device and establishment of a shared key (Ks). The BSF generates a network application function specific key (NSK) according to the Ks and provides the NSK to a network application function (NAF).

[0132] (1) Bootstrapping Server Function (BSF): can be referred to as a bootstrapping server function network element, the BSF serves as a bootstrapping service function and is located in a home network of a user. The BSF obtains a user security setting and an authentication vector of the GBA from a home subscriber server (HSS) and completes authentication of a terminal device and establishment of a shared key (Ks). The BSF generates a network application function specific key (NSK) according to the Ks and provides the NSK to a network application function (NAF).

[0133] (2) Network Application Function (NAF): can be referred to as a network application function network element, after receiving the terminal device application request, the NAF needs to obtain the NAF specific key NSK from the BSF. The BSF protects the communication security between the terminal device using the NAF specific key NSK.

[0134] (3) HSS: can be referred to as an HSS network element, all user security settings, user keys, user subscription data, etc. are stored in the HSS, and the HSS supports returning an authentication vector to the BSF.

[0135] (4) Terminal device: the terminal device needs to support the third generation mobile communication network authentication and key agreement protocol (AKA) and digest authentication, and can perform bidirectional authentication with the bootstrapping server function and generate a shared key Ks, and then generate a specific key NSK according to the shared key Ks. The terminal device protects the communication security between the BSF using the specific key NSK.

[0136] (5) Subscriber Location Function (SLF): can be referred to as a subscriber location function network element, used to query the HSS of the user, not a mandatory functional unit.

[0137] The GBA process generally includes two steps: (1) performing a bootstrapping request process. Bidirectional authentication between the BSF and the terminal device is performed through the AKA protocol, and when the authentication is successful, the terminal device and the BSF establish a shared key Ks. (2) Perform the service access process. The terminal device and the NAF protect the communication security through the NSK. The following will specifically explain the execution of the bootstrapping request process, as shown in Figure 2 When the terminal device wants to interact with the NAF, and the terminal device determines that the bootstrapping process is needed, the terminal device initiates the bootstrapping request process. Otherwise, only when the terminal device receives the bootstrapping indication information sent by the NAF to the terminal device, or the key life cycle in the terminal device ends, the terminal device initiates the bootstrapping request process. The bootstrapping request process is as follows:

[0138] Step 1: the terminal device sends a bootstrapping request message to the BSF. When there is a temporary internet protocol multimedia private identity (TMPI) in the terminal device, the bootstrapping request message carries the TMPI; if there is no TMPI in the terminal device, the bootstrapping request message carries an internet protocol multimedia private identity (IMPI).

[0139] Step 2: after receiving the bootstrapping request message carrying the TMPI from the terminal device, the BSF queries the corresponding IMPI of the TMPI from a local database. If the BSF cannot find the corresponding IMPI, the BSF sends an error message to the terminal device. Correspondingly, after receiving the error message, the terminal device re-sends a bootstrapping request message carrying the IMPI.

[0140] Step 3: the BSF sends an authentication vector request message to the HSS or home location register (HLR), and the authentication vector request message carries the IMPI or IMSI. Optionally, the authentication vector request message carries a GBA user security setting (USS) timestamp.

[0141] Step 4: the HSS / HLR generates an authentication vector (AV). The AV includes = RAND || AUTN || XRES || CK || IK, wherein RAND is a random number, AUTN is an authentication token (AUTN), XRES is an eXpected response (XRES), CK is an intermediate encryption key, IK is an intermediate integrity key, and || represents a concatenation operation. As shown in Figure 3 , the CK, IK, and expected response XRES are all generated based on a long-term key K of the terminal device and a random number RAND. , wherein AMF is an authentication management domain, SQN is a sequence number, the terminal device and the HSS both save the SQN, AK is an anonymous key, and MAC is a message authentication code, denotes an exclusive OR operation, where the MAC is generated based on SQN, K, and AMF and a random number RAND. The HSS / HLR sends an authentication vector AV to the BSF. If the HSS receives a GBA USS timestamp, the HSS compares the GBA USS timestamp with a locally stored timestamp, and if the two timestamps are different, the HSS sends the GBA USS to the BSF.

[0142] Step 5: The BSF sends a random number RAND and an authentication token AUTN to the terminal device.

[0143] Step 6: The terminal device calculates CK and IK using the same method as the HSS, based on the received RAND and a locally stored long-term key, and generates a response RES using the same method as the HSS to calculate XRES; the terminal device verifies the AUTN to determine that the received RAND and authentication token AUTN come from a real network.

[0144] Step 7: The terminal device sends a digest AKA response message generated based on RES to the BSF.

[0145] Step 8: The BSF verifies the digest AKA response message using the XRES received from the HSS / HLR. The BSF generates a shared key Ks = CK || IK. The BSF generates a bootstrapping transaction identifier (B-TID) based on the random number RAND and the server name of the BSF, and generates a TMPI if the user agent request-header field in the message received from the terminal device includes a product token "3gpp-gba-tmpi". (The terminal device always carries the product token "3gpp-gba-tmpi" in the user agent request-header field in the message sent to the BSF when communicating with the BSF.)

[0146] Step 9: The BSF sends a 200 OK message to the terminal device, the message carrying the bootstrapping transaction identifier (B-TID). The 200 OK message is used to indicate that the BSF authentication is successful.

[0147] Step 10: The terminal device can generate a TMPI. The terminal device generates a TMPI if the user agent request-header field in the message received from the BSF includes a product token "3gpp-gba-tmpi". (The BSF should always carry the product token "3gpp-gba-tmpi" in the user agent request-header field in the message sent to the terminal device when communicating with the terminal device.) The terminal device and the BSF generate the TMPI using the same parameters and method.

[0148] Step 11: After the terminal device has the TMPI locally, if the terminal device initiates the bootstrapping request procedure again, the second bootstrapping request message sent to the BSF carries the TMPI.

[0149] GBA includes two mechanisms: a universal bootstrapping architecture based on universal integrated circuit card enhancement (GBA_U) and a universal bootstrapping architecture based on a mobile device (GBA_ME), under which all GBA-related functions are performed by the mobile equipment (ME), and the universal integrated circuit card (UICC) is not aware. Under the GBA_U mechanism, all GBA-related functions are jointly borne by the ME and the UICC. The above bootstrapping procedure is also applicable to the GBA_U mechanism, but with the following modifications: in step 5, the BSF determines to use the GBA_U mechanism according to the GBA USS. The BSF obtains MAC* from the message authentication code (MAC) in the received authentication vector (AV), where Trunc represents the truncation operation, SHA-1 is a secure hash algorithm 1, AUTN* is determined according to the MAC*, and The BSF then sends the random number RAND and AUTN* to the terminal device. The calculation of MAC* can also use other secure hash methods. In step 6, the ME sends the received random number RAND and AUTN* to the UICC, the UICC calculates CK and IK based on the received random number RAND and the locally stored long-term key of the terminal device, using the same method as the network side, generates the response RES using the same method as the HSS generates the expected response XRES, generates the MAC, verifies the AUTN*, and sends the RES to the ME.

[0150] When the terminal device wants to communicate with the NAF, and the terminal device and the NAF negotiate to use the GBA mechanism, the terminal device uses the security association established by the bootstrapping request procedure to communicate, as shown in Figure 4 Figure 4 ​The business access flow is executed. The specific implementation is as follows: step 1: the terminal device generates the NSK according to the shared key Ks in the bootstrapping request flow. The terminal device sends an application request (Application Request) message to the NAF, and the application request message carries a bootstrapping transaction identifier (B-TID). The application request message is securely protected based on the specific key NSK. Step 2: the NAF sends an authentication request (Authentication Request) message to the BSF according to the received bootstrapping transaction identifier (B-TID), and the authentication request message carries the bootstrapping transaction identifier (B-TID) and the identifier (NAF_Id) of the NAF. Step 3: the BSF generates the specific key NSK according to the bootstrapping transaction identifier (B-TID) to find the corresponding shared key Ks, and then sends the specific key NSK to the NAF. Step 4: the NAF sends an application response message to the terminal device, and the response message is securely protected using the specific key NSK. In this way, the NAF and the terminal device can securely communicate based on the specific key NSK.

[0151] Some terms in the present application are explained below to facilitate understanding by those skilled in the art.

[0152] (1) International mobile subscriber identity (IMSI), used to identify the terminal device, and the IMSI is composed of a mobile country code (MCC), a mobile network code MCC (mobile network code, MNC), and a mobile subscription identification number (MSIN). The MCC is 3 bits long, the length of the MNC is determined by the value of the MCC, and can be 2 bits or 3 bits, and the value of the MSIN is allocated by the operator. For example, the IMSI is 310150123456789, in which the MCC is 310, the MNC is 150, and the MSIN is 123456789.

[0153] (2) Internet protocol multimedia private identity (IMPI), used to identify the terminal device. The IMPI is obtained by using the IMSI. The format of the IMPI is <imsi>@ims.mnc <mnc>.mcc <mcc>http: / / www.3gppnetwork.org". For example, if the IMSI of a terminal device is 234150999999999 (i.e. MCC=234, MNC=15, MSIN=0999999999), then the IMPI of the terminal device is 234150999999999@ims.mnc015.mcc234.3gppnetwork.org.

[0154] (3) Temporary Internet Protocol Multimedia Private Identity (TMPI) is used to identify a terminal device. The TMPI is generated by both the terminal device and the BSF. The TMPI is TEMP@tmpi.bsf.3gppnetwork.org, where the TEMP generation parameters include the characters "gba-me", a random number RAND, the IMPI, and CK||IK.

[0155] (4) NAF-specific key NSK is used to protect the communication between the terminal device and the NAF. The NSK is generated using the parameters Ks (i.e. CK||IK), the characters "gba_me" or "gba_u", a random number RAND, the IMPI, and the identity of the NAF (NAF-Id). When GBA_U is used, then the NSK is generated using the characters "gba_u", otherwise the characters "gba_me" are used.

[0156] (5) Generic Public Subscription Identifier (GPSI) is used to identify a terminal device. The GPSI includes a GPSI type and a GPSI value. The GPSI type is either a Mobile Subscription ISDN Number (MSISDN) type or an External Identifier type. When the GPSI type is the MSISDN type, the GPSI value is the MSISDN; when the GPSI type is the External Identifier type, the GPSI value is the External Identifier. The MSISDN includes a country code (CC), a national destination code (NDC), and a subscriber number (SN). The External Identifier has the format username@realm, where username is the user part and realm is the domain.

[0157] In the above method, under the GBA_U mechanism, the old version of the BSF uses the secure hash algorithm 1 (SHA-1) to calculate the MAC*, or the UICC in the old version of the terminal device uses the secure hash algorithm 1 (SHA-1) to verify the AUTN* when. The SHA-1 algorithm is an unsafe algorithm, in 5G, the new version of the terminal device and the new version of the BSF will no longer use SHA-1, and will use SHA-26 security algorithm, therefore, when the old version of the terminal device communicates with the new version of the BSF, or the new version of the terminal device and the old version of the BSF communicate, because the terminal device and the BSF use different algorithms, it will cause the verification of AUTN* to fail, thereby causing the GBA to fail, therefore, how to solve the compatibility problem of new and old versions is a technical problem that persons skilled in the art are solving.

[0158] See Figure 5 , Figure 5 is a general boot architecture algorithm negotiation method provided by the embodiment of the application, which includes but is not limited to the following steps:

[0159] Step S501: The terminal device generates a first boot request message.

[0160] Specifically, the first boot request message includes an identifier of the terminal device, and / or first indication information, and / or an algorithm supported by the terminal device. The identifier of the terminal device includes a first identifier or a second identifier or a third identifier. The algorithm supported by the terminal device can include a first algorithm and / or a second algorithm. In an example, the first algorithm can include a secure hash algorithm 1 (SHA-1), and the second algorithm can include a secure hash algorithm 2 (SHA2), wherein the SHA2 can include one or more of a secure hash algorithm 224 (SHA-224), a secure hash algorithm 256 (SHA-256), a secure hash algorithm 384 (SHA-384), and a secure hash algorithm 512 (SHA-512). The first algorithm can include one or more algorithms, and the second algorithm can include one or more algorithms, which are not limited in the embodiment of the application. For example, the first algorithm can include a secure hash algorithm 1 (SHA-1), and the second algorithm can include a secure hash algorithm 256 (SHA-256). The first indication information is used to indicate that the algorithm supported by the terminal device includes the second algorithm. The first identifier is used for the BSF to determine that the algorithm supported by the terminal device includes the second algorithm according to the first identifier. The second identifier is used for the BSF to determine that the terminal device supports the first algorithm according to the second identifier. In a possible implementation, the first indication information can also be the first identifier, which is not limited in the embodiment of the application. In the embodiment of the application, the second identifier can also be referred to as the second identifier of the terminal device, and the first identifier can also be referred to as the first identifier of the terminal device, which is not limited in the embodiment of the application.

[0161] In the present application, the algorithm supported by the terminal device includes the second algorithm, indicating that the terminal device supports the second algorithm, or the terminal device supports the first algorithm and the second algorithm.

[0162] Specifically, the first identifier is generated according to the second identifier. In an example, the first identifier is generated according to the second identifier and an identity public key (IPK), for example, the first identifier is generated by encrypting the second identifier using the IPK. That is, the first identifier can be an encrypted identifier of the terminal device, and the second identifier can be a plaintext identifier of the terminal device. In the present embodiment, the identity public key IPK can be a public key of the network, or other keys, which are not limited in the present embodiment. The identity public key can be configured on the HSS, and / or UDM, and / or BSF. In an example, the first identifier is a subscription concealed identifier (SUCI) of the terminal device. Assuming that the first identifier is the SUCI, and the second identifier is the SUPI, the first identifier SUCI is generated by encrypting the second identifier SUPI using the public key of the network.

[0163] In the present embodiment, when the second identifier is the SUPI of the terminal device, the first identifier is referred to as SUPI*; when the second identifier is the IMPI of the terminal device, the first identifier is referred to as IMPI*; when the second identifier is the IMSI of the terminal device, the first identifier is referred to as IMSI*; and when the second identifier is the GPSI of the terminal device, the first identifier is referred to as GPSI*.

[0164] In another example, the first bootstrapping request message includes a third identifier of the terminal device. In the present embodiment, the third identifier of the terminal device can be referred to as the third identifier. The third identifier is the GPSI of the terminal device, or the GPSI of the External Identifier type. When the third identifier is the GPSI of the terminal device, the first identifier is referred to as GPSI*, and the third identifier is used by the BSF to determine that the algorithm supported by the terminal device includes the second algorithm according to the third identifier.

[0165] Optionally, in a possible implementation, before the terminal device generates the first bootstrapping request message, the terminal device or a mobile equipment (ME) of the terminal device reads an algorithm supported by a universal integrated circuit card (UICC) of the terminal device, and the algorithm supported by the terminal device included in the first bootstrapping request message is the algorithm supported by the UICC. In an example, assuming that the ME of the terminal device reads that the UICC of the terminal device supports the algorithms SHA-1 and SHA-256, the terminal device supports the algorithms SHA-1 and SHA-256, which are included in the first bootstrapping request message.

[0166] Step S502: The terminal device sends a first bootstrapping request message to the BSF.

[0167] Specifically, the first bootstrapping request message includes an algorithm supported by the terminal device, or first indication information, or a first identifier, or a second identifier, or a third identifier.

[0168] Step S503: The BSF receives the first bootstrapping request message from the terminal device.

[0169] Specifically, the first bootstrapping request message includes an algorithm supported by the terminal device, or first indication information, or a first identifier, or a second identifier, or a third identifier.

[0170] In a possible implementation, the BSF determines, according to the first indication information, that the algorithm supported by the terminal device includes a second algorithm. For example, assuming that the second algorithm is SHA-256, the BSF determines, according to the first indication information, that the algorithm supported by the terminal device includes SHA-256.

[0171] In a possible implementation, the BSF determines, according to the first identifier or the third identifier, that the algorithm supported by the terminal device includes a second algorithm. For example, assuming that the first identifier is SUPI* and the second algorithm is SHA-256, the BSF determines, according to the first identifier SUPI*, that the algorithm supported by the terminal device includes the second algorithm SHA-256. Assuming that the third identifier is GPSI and the second algorithm is SHA-256, the BSF determines, according to the third identifier GPSI, that the algorithm supported by the terminal device includes the second algorithm SHA-256.

[0172] In a possible implementation, the BSF determines, according to the second identifier, that the terminal device supports a first algorithm. For example, assuming that the second identifier is IMPI or SUPI and the first algorithm is SHA-1, the BSF determines, according to the second identifier IMPI or SUPI, that the terminal device supports the first algorithm SHA-1.

[0173] Step S504: The BSF generates a third request message.

[0174] Specifically, the third request message includes the first identifier or the second identifier or the third identifier, and the third request message is used to obtain a first authentication vector of the terminal device or is used to invoke a first authentication service of the HSS to obtain the first authentication vector of the terminal device.

[0175] Optionally, before generating the third request message, the BSF determines to generate the third request message or determines to send the third request message to the HSS. The BSF determines to generate the third request message or determines to send the third request message to the HSS can be determined according to the received first identifier or the third identifier of the terminal device.

[0176] Optionally, the BSF can further determine to generate the fifth identity (TMPI*), or determine that the terminal device supports 5G GBA, or determine that the terminal device is a 5G terminal device, or determine to perform 5G GBA authentication and key agreement according to the first identity or the third identity.

[0177] In a possible implementation, if the BSF receives the first identity, the BSF acquires the second identity according to the received first identity and the IPK, and includes the second identity in the third request message. The BSF acquires the second identity according to the received first identity and the IPK can be that the BSF acquires the second identity by using the IPK to decrypt the first identity. For example, assuming that the first identity is IMPI*, the BSF determines the second identity to be IMPI according to the first identity and the IPK.

[0178] In a possible implementation, if the BSF receives the first identity, the BSF includes the received first identity in the third request message; in a possible implementation, if the BSF receives the third identity, the BSF includes the received third identity in the third request message. In a possible implementation, if the BSF receives the second identity, the BSF includes the received second identity in the third request message.

[0179] Step S505: The BSF sends a third request message to the HSS.

[0180] Specifically, the third request message includes the first identity or the second identity or the third identity, and the third request message is used to acquire the first authentication vector of the terminal device or to invoke the first authentication service of the HSS to acquire the first authentication vector of the terminal device.

[0181] Step S506: The HSS receives the third request message from the BSF.

[0182] Specifically, the third request message includes the first identity or the second identity or the third identity.

[0183] Step S507: The HSS acquires the first authentication vector of the terminal device according to the received first identity or the second identity or the third identity.

[0184] In particular, the first authentication vector has any of the following possible implementation manners. In one possible implementation manner, the first authentication vector can be an authentication vector AV, where AV = RAND || AUTN || XRES || CK and || IK, RAND is a random number, AUTN is an authentication token, XRES represents an expected response, CK is an intermediate encryption key, and IK is an intermediate integrity key. The details can be as described above, which will not be repeated here. In another possible implementation manner, the first authentication vector can also be generated in the manner of an improved extensible authentication protocol method for 3rd generation authentication and key agreement (EAP-AKA') for the UDM to generate an EAP-AKA' authentication vector corresponding to the EAP-AKA', the EAP-AKA' authentication vector including a random number RAND, an authentication credential AUTN, XRES, a first intermediate encryption key CK', and a first intermediate integrity key IK', the generation parameters of the first intermediate encryption key CK' and the first intermediate integrity key IK' including an intermediate encryption key CK, an intermediate integrity key IK, a sequence number SQN, an anonymous key AK, and a service network name SN-Name, the service network name SN-Name being generated by the UDM or sent by the HSS. The service network name SN-Name includes a service code and a service network identifier SN-Id, the service network identifier SN-Id including a mobile country code MCC and a mobile network code MNC, where in one example, MCC = 000, MNC = 00, MNC = 000, and in another example, MCC = 999, MNC = 99 or MNC = 999. The service code includes a "5g" and / or "gba" string.

[0185] In one possible implementation manner, the third request message includes the second identifier or the third identifier, and the HSS generates the first authentication vector of the terminal device according to the second identifier or the third identifier.

[0186] In another possible implementation manner, the third request message includes the first identifier, the HSS acquires the second identifier according to the first identifier and the IPK, and the HSS generates the first authentication vector of the terminal device according to the second identifier. For example, the HSS can decrypt the first identifier using the IPK to acquire the second identifier.

[0187] In a possible implementation, the HSS sends a second request message to a unified data management (UDM) according to the received first identifier, or the second identifier, or the third identifier. Specifically, the second request message includes the first identifier or the second identifier or the third identifier, and the second request message is used to request the UDM to generate the first authentication vector of the terminal device, or to invoke a first authentication service of the UDM to obtain the first authentication vector of the terminal device. Then, after the UDM generates the first authentication vector, the UDM sends a second response message to the HSS, and the second response message includes the first authentication vector.

[0188] In another possible implementation, the HSS obtains the second identifier according to the received first identifier and the IPK, and then sends a second request message to the UDM, where the second request message includes the obtained second identifier, so that the UDM generates the first authentication vector of the terminal device according to the second identifier. Then, after the UDM generates the first authentication vector, the UDM sends a second response message to the HSS, and the second response message includes the first authentication vector.

[0189] Step S508: The HSS sends a third response message to the BSF.

[0190] Specifically, the third response message includes the first authentication vector of the terminal device.

[0191] Step S509: The BSF receives the third response message from the HSS.

[0192] Specifically, the third response message includes the first authentication vector of the terminal device.

[0193] Step S510: The BSF selects a target algorithm according to an algorithm supported by the terminal device.

[0194] Specifically, the algorithm supported by the terminal device includes the first algorithm and / or the second algorithm.

[0195] The BSF determines the algorithm supported by the terminal device, which is described in step S503 and will not be repeated here.

[0196] In a possible implementation, if the algorithm supported by the terminal device includes the second algorithm, the BSF selects the second algorithm as the target algorithm. For example, in an example, the first algorithm is SHA-1, the second algorithm is SHA-256, the algorithm supported by the terminal device includes SHA-1 and SHA-256, and the BSF selects SHA-256 as the target algorithm. In another example, the second algorithm is SHA-256, and the algorithm supported by the terminal device is SHA-256. The BSF selects SHA-256 as the target algorithm. In a possible implementation, if the algorithm supported by the terminal device is the first algorithm, the BSF selects the first algorithm as the target algorithm. For example, in an example, the first algorithm is SHA-1, and the algorithm supported by the terminal device is SHA-1. The BSF selects SHA-1 as the target algorithm.

[0197] In a possible implementation, before the BSF selects the target algorithm according to the algorithm supported by the terminal device, the BSF determines to use a general bootstrapping architecture for universal integrated circuit card enhancement (GBA_U) mechanism.

[0198] In a possible implementation, after the BSF selects the target algorithm according to the algorithm supported by the terminal device, the BSF sends the target algorithm to the terminal device. In an example, after the BSF selects the target algorithm as SHA-256 according to the algorithm supported by the terminal device, the BSF sends the target algorithm SHA-256 to the terminal device.

[0199] In the method described above, by sending the target algorithm to the terminal device, it can be ensured that the terminal device and the BSF use the same algorithm to verify the AUTN*, and the problem of algorithm compatibility between the terminal device and the BSF is solved.

[0200] Optionally, before the BSF selects the target algorithm according to the algorithm supported by the terminal device, the BSF determines whether to support the algorithm supported by the terminal device:

[0201] Specifically, the algorithm supported by the terminal device includes the first algorithm and / or the second algorithm. In an example, the first algorithm is SHA-1, and the second algorithm is SHA-256.

[0202] In a possible implementation, the BSF determines an algorithm supported by the terminal device, for example, in an example, assuming that the algorithm supported by the terminal device is SHA-1, and the algorithm supported by the BSF includes SHA-1, the BSF determines the algorithm supported by the terminal device; in another example, assuming that the algorithm supported by the terminal device is SHA-256, and the algorithm supported by the BSF includes SHA-256, the BSF determines the algorithm supported by the terminal device; in yet another example, assuming that the algorithm supported by the terminal device is SHA-1 and SHA-256, and the algorithm supported by the BSF includes SHA-1 and SHA-256, the BSF determines the algorithm supported by the terminal device.

[0203] In a possible implementation, the BSF determines an algorithm not supported by the terminal device, for example, in an example, assuming that the algorithm supported by the terminal device is SHA-256, and the algorithm supported by the BSF does not include SHA-256, the BSF determines the algorithm not supported by the terminal device; in another example, assuming that the algorithm supported by the terminal device is SHA-1 and SHA-256, and the algorithm supported by the BSF does not include SHA-256 and SHA-1, the BSF determines the algorithm not supported by the terminal device.

[0204] In a possible implementation, after the BSF determines the algorithm not supported by the terminal device, the BSF sends third indication information to the terminal device, the third indication information being used to instruct the terminal device to use a mobile equipment based generic bootstrapping architecture (GBA_ME) mechanism, and after the terminal device receives the third indication information, the terminal device uses the GBA_ME mechanism, that is, verifies a second message authentication code (MAC) or an authentication token (AUTN). That is, when the terminal device uses the GBA_ME mechanism, the terminal device receives the second message authentication code MAC from the BSF accordingly.

[0205] The BSF can select the target algorithm at any time point after the BSF receives the first bootstrapping request message, which is not limited in the present application.

[0206] Step S511: The BSF determines a first message authentication code according to the target algorithm.

[0207] Specifically, the first message authentication code is MAC*.

[0208] In an example, assuming that the target algorithm is SHA-256, the BSF obtains the first message authentication code MAC* according to the second message authentication code MAC in the received first authentication vector, where Trunc represents a truncation operation.

[0209] In a possible implementation, after determining the first message authentication code according to the target algorithm, the BSF determines the AUTN* according to the first message authentication code MAC*, wherein wherein AMF is an authentication management domain, SQN is a sequence number, the terminal device and the HSS both store the SQN, and AK is an anonymous key.

[0210] In a possible implementation, the BSF receives a second message authentication code (MAC) from the HSS; and then the BSF determines a first message authentication code (MAC*) according to the target algorithm and the second message authentication code (MAC). In an example, assuming that the target algorithm is SHA-256, the BSF determines the first message authentication code according to the target algorithm SHA-256 and the second message authentication code as follows: wherein Trunc represents a truncation operation.

[0211] Optionally, before determining the first message authentication code, the BSF determines to use the GBA_U mechanism.

[0212] Step S512: The BSF sends the random number RAND and the AUTN* to the terminal device.

[0213] Specifically, the AUTN* includes the first message authentication code MAC*.

[0214] Optionally, the BSF also sends the target algorithm to the terminal device.

[0215] Step S513: The terminal device receives the random number RAND and the AUTN* from the BSF.

[0216] Possibly, the terminal device receives the target algorithm from the BSF.

[0217] Step S514: The terminal device determines a second message authentication code.

[0218] Specifically, the first message authentication code can be MAC*, and the second message authentication code can be MAC, which is used to authenticate the BSF.

[0219] In a possible implementation, the terminal device determines the second message authentication code, including: if the terminal device receives the target algorithm, the terminal device determines the second message authentication code using the target algorithm and the first message authentication code; or if the terminal device does not receive the target algorithm, if the terminal device supports the first algorithm and the second algorithm, the terminal device determines the second message authentication code using the first algorithm and the first message authentication code.

[0220] In an example, assuming that the target algorithm is SHA-256, and the first message authentication code is MAC*, wherein, The terminal device determines the MAC using SHA-256 and MAC*.

[0221] Specifically, after receiving the random number RAND and the AUTN*, the terminal device or the UICC calculates the IK using the same method as the network side device, and calculates Further, the terminal device or the UICC can also calculate and verify that the AUTN is from an authorized network.

[0222] Optionally, before calculating the second message authentication code, the terminal device determines to use the GBA_U mechanism.

[0223] In the method shown in Figure 5 , the BSF determines the target algorithm according to the algorithm supported by the terminal device or the indication information or the identification information of the terminal device in the boot request message received from the terminal device, and then sends the target algorithm to the terminal device in a manner, which can avoid the case that the terminal device and the BSF use different algorithms to verify the AUTN*, ensures that the terminal device and the BSF use the same algorithm, and thus solves the algorithm compatibility problem of the terminal device and the BSF.

[0224] Please refer to Figure 6 , Figure 6 is an algorithm negotiation method in a general boot architecture provided by the embodiment of the application, which includes but is not limited to the following steps:

[0225] Step S601: The terminal device generates a second boot request message.

[0226] Step S602: The terminal device sends the second boot request message to the BSF.

[0227] Step S603: The BSF receives the second boot request message from the terminal device.

[0228] Step S604: The BSF generates a first request message.

[0229] Step S605: The BSF sends the first request message to the HSS.

[0230] Specifically, the first request message is used to obtain the first authentication vector of the terminal device, or is used to call the first authentication service of the HSS to obtain the first authentication vector of the terminal device.

[0231] Step S606: The HSS receives the first request message from the BSF.

[0232] Step S607: The HSS generates a first response message.

[0233] Specifically, the first response message comprises the first authentication vector of the terminal device. The possible implementation of the first authentication vector of the terminal device is as described in step S507, which will not be repeated here. The first response message comprises an algorithm supported by the terminal device or second indication information, the algorithm supported by the terminal device comprises the first algorithm and / or the second algorithm, in an example, the first algorithm can comprise a secure hash algorithm 1 (SHA-1), and the second algorithm can comprise a secure hash algorithm 2 (SHA2), wherein the SHA2 can comprise one or more of a secure hash algorithm 224 (SHA-224), a secure hash algorithm 256 (SHA-256), a secure hash algorithm 384 (SHA-384), and a secure hash algorithm 512 (SHA-512). Wherein the first algorithm can comprise one or more secure hash algorithms, and the second algorithm can comprise one or more secure hash algorithms, which are not limited by the embodiments of the present application. For example, the first algorithm can be a secure hash algorithm 1 (SHA-1), and the second algorithm can be a secure hash algorithm 256 (SHA-256). The second indication information is used to indicate that the algorithm supported by the terminal device comprises the second algorithm. In an example, assuming that the second algorithm is SHA-256, the second indication information is used to indicate that the terminal device supports SHA-256.

[0234] Step S608: The HSS sends the first response message to the BSF.

[0235] Specifically, the first response message comprises the first authentication vector of the terminal device. The first response message comprises an algorithm supported by the terminal device or second indication information, the algorithm supported by the terminal device comprises the first algorithm and / or the second algorithm, and the second indication information is used to indicate that the algorithm supported by the terminal device comprises the second algorithm.

[0236] Step S609: The BSF receives the first response message from the HSS.

[0237] Specifically, the first response message comprises the first authentication vector of the terminal device. The first response message comprises an algorithm supported by the terminal device or second indication information, the algorithm supported by the terminal device comprises the first algorithm and / or the second algorithm, and the second indication information is used to indicate that the algorithm supported by the terminal device comprises the second algorithm.

[0238] In a possible implementation, the BSF determines, according to the second indication information, that the algorithm supported by the terminal device comprises the second algorithm. For example, assuming that the second algorithm is SHA-256, the BSF determines, according to the second indication information, that the algorithm supported by the terminal device comprises SHA-256.

[0239] Steps S610-S614 can refer to steps S510-S514, which will not be repeated here.

[0240] In Figure 6 In the illustrated method, the BSF determines the target algorithm according to the algorithm or indication information supported by the terminal device in the response message received from the HSS, and then sends the target algorithm to the terminal device, which can avoid the case that the terminal device and the BSF use different algorithms to verify the AUTN*, ensures that the terminal device and the BSF use the same algorithm, and thus solves the algorithm compatibility problem of the terminal device and the BSF.

[0241] See Figure 7 , Figure 7 is a method for algorithm negotiation in a general bootstrapping architecture provided by the embodiments of the present application, which includes but is not limited to the following steps:

[0242] Step S701: The terminal device generates a third bootstrapping request message or a fourth bootstrapping request message.

[0243] In an example, the third bootstrapping request message includes a first identifier of the terminal device, or the first identifier of the terminal device and third indication information, or a second identifier. In the embodiments of the present application, the first identifier of the terminal device can also be referred to as a first identifier, and the second identifier of the terminal device can also be referred to as a second identifier. The first identifier is generated according to the second identifier. The first identifier does not involve the privacy of the terminal device, and the second identifier involves the privacy of the terminal device. The second identifier includes one of a subscription permanent identifier (SUPI) of the terminal device, an Internet Protocol Multimedia Private Identity (IMPI) of the terminal device, an International Mobile Subscriber Identity (IMSI) of the terminal device, and a GPSI.

[0244] In an example, the first identifier is generated according to the second identifier and an identity protection key (IPK), such as the first identifier is generated by encrypting the second identifier using the IPK. That is, the first identifier can be an encrypted identifier of the terminal device, and the second identifier can be a plaintext identifier of the terminal device. In the embodiments of the present application, one possibility of the identity protection key IPK is a public key of the network. The identity protection key is configured on the HSS, and / or UDM, and / or BSF. In an example, the first identifier is a subscription concealed identifier (SUCI) of the terminal device. Assuming that the first identifier is SUCI and the second identifier is SUPI, the first identifier SUCI is generated by encrypting the second identifier SUPI using the public key of the network.

[0245] In the embodiments of the present application, the first identifier is referred to as SUPI* when the second identifier is the SUPI of the terminal device; the first identifier is referred to as IMPI* when the second identifier is the IMPI of the terminal device; the first identifier is referred to as IMSI* when the second identifier is the IMSI of the terminal device; and the first identifier is referred to as GPSI* when the second identifier is the GPSI of the terminal device.

[0246] In yet another example, the third bootstrapping request message includes a third identifier of the terminal device, or the third identifier of the terminal device and third indication information. In the embodiments of the present application, the third identifier of the terminal device can be referred to as third identifier. The third identifier is the GPSI of the terminal device, or the GPSI of the type of External Identifier type; and the first identifier is referred to as GPSI* when the third identifier is the GPSI of the terminal device.

[0247] In yet another example, the third indication information is used to indicate that the BSF generates a fifth identifier (TMPI*) of the terminal device, or to indicate that the terminal device supports 5g GBA, or to indicate that the BSF sends the first request message, or to indicate that the terminal device is a 5G terminal device, or to indicate that the authentication and key agreement of 5G GBA is performed, or to indicate that the algorithm supported by the terminal device includes the second algorithm. In the embodiments of the present application, the fifth identifier of the terminal device can also be referred to as fifth identifier.

[0248] In a possible implementation, the third indication information is a character for identifying 5G in the user agent request header information in the third bootstrapping request message. Possibly, the character for identifying 5G is a character including "5" or "5g", such as "3gpp-5gba-tmpi" or "3gpp-gba-5tmpi" or "3gpp-5g-gba-tmpi" or "3gpp-gba-5gtmpi".

[0249] By including the third indication information in the third bootstrapping request message, resources can be reasonably utilized.

[0250] In a possible implementation, if the terminal device has the fifth identity (TMPI*) locally, the terminal device sends a fourth bootstrapping request message to the BSF, where the fourth bootstrapping request message includes the fifth identity (TMPI*), or the fifth identity and the third indication information. The parameters used to generate the fifth identity (TMPI*) include TEMP* and a BSF domain name*, such as the fifth identity being TEMP*@BSF domain name*. The parameters used to generate TEMP* include one or more of the following: a random number RAND, a 5G GBA key, a second identity of the terminal device, an identity of the BSF, and a character used to identify 5G. The 5G GBA key is generated based on CK and IK, and the character used to identify 5G can be a character containing "5", and / or "5g", and / or "5g-gba", and / or "5g-gba-me", and / or "5g-gba-u", and / or "gba", and / or "5gba", and / or "5gba-me", and / or "5gba-u", and / or "5gba". The BSF domain name* can include a character containing the character used to identify 5G.

[0251] Possibly, the BSF can determine, according to the fifth identity, that the algorithm supported by the terminal device includes the second algorithm.

[0252] In a possible implementation, before the terminal device sends the third bootstrapping request message to the BSF, the terminal device generates a first identity according to the second identity and an identity public key (IPK), such as the terminal device encrypting the second identity by using the identity public key IPK to generate the first identity.

[0253] In a possible implementation, before the terminal device sends the fourth bootstrapping request message to the BSF, the terminal device generates the fifth identity. The parameters used to generate the fifth identity are as described above.

[0254] By including the first identity in the third bootstrapping request message or the fourth bootstrapping request message, compared with directly carrying the second identity, that is, the plaintext identity of the terminal device, in the third bootstrapping request message, it can avoid the privacy information of the terminal device being leaked, and improve the security of communication.

[0255] Step S702: The terminal device sends a third bootstrapping request message or a fourth bootstrapping request message to a bootstrapping server function BSF.

[0256] Specifically, the third bootstrapping request message includes any one of the following: the first identity, or the first identity and the third indication information, or the third identity, or the third identity and the third indication information. The fourth bootstrapping request message includes the fifth identity, or the fifth identity and the third indication information.

[0257] Step S703: The BSF receives the third bootstrapping request message or the fourth bootstrapping request message from the terminal device.

[0258] Specifically, the third bootstrapping request message includes the first identity or the third identity, and the first identity is generated according to the second identity. The third identity is the GPSI of the terminal device or is the GPSI of the type of External Identifier type. The fourth bootstrapping request message includes the fifth identity. Optionally, the third bootstrapping request message or the fourth bootstrapping request message further includes the third indication information.

[0259] In a possible implementation, the BSF determines, according to the first identity or the third identity or the third indication information or the fifth identity, that the algorithm supported by the terminal device includes the second algorithm.

[0260] In a possible implementation, the BSF determines, according to the second identity, that the algorithm supported by the terminal device is the first algorithm.

[0261] Step S704: The BSF generates a fourth request message.

[0262] Specifically, the fourth request message includes the first identity or the second identity or the third identity, and the fourth request message is used to acquire the first authentication vector of the terminal device or is used to invoke the first authentication service of the HSS to acquire the first authentication vector of the terminal device.

[0263] Optionally, before the BSF generates the fourth request message, the BSF determines to generate the fourth request message or determines to send the fourth request message to the HSS. The BSF determines to generate the fourth request message or determines to send the fourth request message to the HSS can be determined according to the received first identity or the third identity or the fifth identity or the third indication information of the terminal device.

[0264] Optionally, the BSF can further determine to generate the fifth identity (TMPI*), or determine that the terminal device supports 5g GBA, or determine that the terminal device is a 5G terminal device, or determine to perform 5G GBA authentication and key agreement according to the first identity or the third identity or the fifth identity or the third indication information.

[0265] In a possible implementation, if the BSF receives the first identity, the BSF acquires the second identity according to the received first identity and IPK, and includes the second identity in the fourth request message. The BSF acquires the second identity according to the received first identity and IPK can be that the BSF uses the IPK to decrypt the first identity to acquire the second identity. For example, assuming that the first identity is IMPI*, the BSF determines that the second identity is IMPI according to the first identity and IPK.

[0266] In a possible implementation, if the BSF receives the first identity, the BSF includes the received first identity in the fourth request message; in a possible implementation, if the BSF receives the third identity, the BSF includes the received third identity in the fourth request message. If the BSF receives the second identity, the BSF includes the received second identity in the fourth request message.

[0267] In a possible implementation, after receiving the first identity, if the BSF fails to decrypt the first identity to obtain the second identity, the BSF sends an error message to the terminal device, the error message being used to instruct the terminal device to resend the third bootstrapping request message carrying the first identity, or being used to instruct the terminal device that the first identity cannot be decrypted to obtain the second identity. Correspondingly, after receiving the error message, the terminal device resends the third bootstrapping request message carrying the first identity.

[0268] In a possible implementation, if the BSF receives the fifth identity, the BSF determines the second identity corresponding to the fifth identity, and includes the second identity in the fourth request message.

[0269] Step S705: The BSF sends a fourth request message to the HSS.

[0270] Specifically, the fourth request message includes the first identity or the second identity or the third identity, and the fourth request message is used to obtain the first authentication vector of the terminal device or to invoke the first authentication service of the HSS to obtain the first authentication vector of the terminal device.

[0271] Step S706: The HSS receives the fourth request message from the BSF.

[0272] Specifically, the fourth request message includes the first identity or the second identity or the third identity.

[0273] Step S707: The HSS obtains the first authentication vector of the terminal device according to the received first identity or second identity or third identity.

[0274] In a possible implementation, the fourth request message includes the second identity or the third identity, and the HSS generates the first authentication vector of the terminal device according to the second identity or the third identity. Then the HSS directly proceeds to step S711. The possible implementation of the first authentication vector of the terminal device is described in step S507.

[0275] In yet another possible implementation, the fourth request message comprises the first identity, the HSS obtains the second identity according to the first identity and the IPK, and the HSS generates the first authentication vector of the terminal device according to the second identity. Then the HSS directly performs step S711. The HSS obtains the second identity according to the first identity and the IPK, for example, the HSS can decrypt the first identity using the IPK to obtain the second identity.

[0276] In a possible implementation, the HSS sends a fifth request message to a unified data management (UDM) according to the received first identity, or the second identity, or the third identity. Specifically, the fifth request message comprises the first identity or the second identity or the third identity, and the fifth request message is used to request the UDM to generate the first authentication vector of the terminal device, or to invoke the first authentication service of the UDM to obtain the first authentication vector of the terminal device.

[0277] In yet another possible implementation, the HSS obtains the second identity according to the received first identity and the IPK, and then sends a fifth request message to the UDM, wherein the fifth request message comprises the obtained second identity, so that the UDM generates the first authentication vector of the terminal device according to the second identity.

[0278] Step S708: The UDM receives the fifth request message and generates the first authentication vector according to the first identity or the second identity or the third identity in the fifth request message.

[0279] Specifically, possible implementations of the first authentication vector can be seen in step S507, which will not be described here again. The UDM can generate the first authentication vector according to the first identity or the second identity or the third identity in any of the following possible implementations.

[0280] In a possible implementation, the UDM receives the first identifier, and the UDM obtains the second identifier according to the first identifier and the IPK. For example, the UDM decrypts the first identifier using the IPK to obtain the second identifier, and then generates the first authentication vector according to the second identifier. Alternatively, the UDM obtains the second identifier according to the first identifier and the IPK, and the second identifier is the SUPI. Then the UDM generates the first authentication vector according to the SUPI. For example, assuming that the first identifier is SUCI, the UDM invokes the single network slice selection assistance information (SIDF) to dehide the SUCI to obtain the SUPI, and the UDM generates the first authentication vector of the terminal device according to the SUPI. Assuming that the first identifier is IMPI*, the UDM obtains the IMPI according to the IMPI* and the IPK. Further, the UDM further obtains the SUPI according to the IMPI, and generates the first authentication vector of the terminal device according to the SUPI. Assuming that the first identifier is IMSI*, the UDM obtains the IMSI according to the IMSI* and the IPK. Further, the UDM further generates the SUPI according to the IMSI, and generates the first authentication vector of the terminal device according to the SUPI. Assuming that the first identifier is GPSI*, the UDM obtains the GPSI according to the GPSI* and the IPK, obtains the SUPI according to the GPSI, and generates the first authentication vector of the terminal device according to the SUPI.

[0281] In a possible implementation, the UDM receives the second identifier, and the UDM generates the first authentication vector according to the second identifier. For example, assuming that the second identifier is IMSI, the UDM generates the SUPI according to the IMSI, and generates the first authentication vector of the terminal device according to the SUPI. Assuming that the second identifier is IMPI, the UDM generates the SUPI according to the IMPI, and generates the first authentication vector of the terminal device according to the SUPI.

[0282] In a possible implementation, the UDM receives the third identifier, and the UDM generates the first authentication vector according to the third identifier. For example, assuming that the third identifier is GPSI, the UDM obtains the corresponding SUPI according to the GPSI, and generates the first authentication vector of the terminal device according to the SUPI.

[0283] Step S709: The UDM sends a fifth response message to the HSS.

[0284] Specifically, the fifth response message includes the first authentication vector, or the first authentication vector and the second identifier.

[0285] Step S710: The HSS receives the fifth response message from the UDM.

[0286] Specifically, the second response information comprises the first authentication vector, or, the first authentication vector and the second identity.

[0287] Step S711: The HSS sends a fourth response message to the BSF.

[0288] Specifically, the fourth response message comprises the first authentication vector, or, the first authentication vector and the second identity. Optionally, the fourth response message comprises third indication information, the third indication information being used for indicating the BSF to generate a fifth identity (TMPI*) of the terminal device, or indicating that the terminal device supports 5g GBA, or indicating that the terminal device is a 5G terminal device, or indicating to perform authentication and key agreement of 5G GBA, or indicating that the algorithm supported by the terminal device comprises the second algorithm.

[0289] Step S712: The BSF receives the fourth response message from the HSS.

[0290] Specifically, the fourth response message comprises the first authentication vector, or, the first authentication vector and the second identity. Optionally, the fourth response message comprises third indication information, the third indication information being used for indicating the BSF to generate a fifth identity (TMPI*) of the terminal device, or indicating that the terminal device supports 5g GBA, or indicating that the terminal device is a 5G terminal device, or indicating to perform authentication and key agreement of 5G GBA, or indicating that the algorithm supported by the terminal device comprises the second algorithm.

[0291] Step S713: The BSF selects a target algorithm according to the identity of the terminal device or the third indication information.

[0292] Specifically, the third bootstrapping request message comprises any one of the following: the first identity, or the first identity and the third indication information, or the third identity, or the third identity and the third indication information, or the second identity. The fourth bootstrapping request message comprises the fifth identity, or the fifth identity and the third indication information.

[0293] The identity of the terminal device comprises any one of the following: the first identity, the second identity, the third identity, or the fifth identity.

[0294] In a possible implementation, the BSF determines, according to the first identifier, the third identifier, or the fifth identifier, or the third indication information, that the algorithm supported by the terminal device includes the second algorithm. In an example, assuming that the first identifier is SUCI or GPSI*, and the second algorithm is SHA-256, the BSF determines that the algorithm supported by the terminal device includes SHA-256. In an example, assuming that the third identifier is IMPI*, and the second algorithm is SHA-256, the BSF determines that the algorithm supported by the terminal device includes SHA-256. In an example, assuming that the fifth identifier is TMPI*, and the second algorithm is SHA-256, the BSF determines that the algorithm supported by the terminal device includes SHA-256.

[0295] In a possible implementation, the BSF determines, according to the second identifier, that the algorithm supported by the terminal device is the first algorithm. For example, assuming that the second identifier is IMPI or SUPI, and the first algorithm is SHA-1, the BSF determines, according to the IMPI or the SUPI, that the algorithm supported by the terminal device is SHA-1.

[0296] In a possible implementation, if the algorithm supported by the terminal device includes the second algorithm, the BSF selects the second algorithm as the target algorithm. For example, in an example, the first algorithm is SHA-1, the second algorithm is SHA-256, and the algorithm supported by the terminal device includes SHA-1 and SHA-256, the BSF selects SHA-256 as the target algorithm. In another example, the second algorithm is SHA-256, and the algorithm supported by the terminal device includes SHA-256, the BSF selects SHA-256 as the target algorithm. In a possible implementation, if the algorithm supported by the terminal device is the first algorithm, the BSF selects the first algorithm as the target algorithm. For example, in an example, the first algorithm is SHA-1, and the algorithm supported by the terminal device is SHA-1, the BSF selects SHA-1 as the target algorithm.

[0297] Optionally, before the BSF selects the target algorithm according to the identifier of the terminal device or the third indication information, the BSF determines that the BSF supports the algorithm supported by the terminal device.

[0298] Specifically, the algorithm supported by the terminal device includes the first algorithm and / or the second algorithm. In an example, the first algorithm is SHA-1, and the second algorithm is SHA-256.

[0299] In a possible implementation, the BSF determines to support the algorithm supported by the terminal device, for example, in an example, assuming that the algorithm supported by the terminal device is SHA-1, and the algorithm supported by the BSF includes SHA-1, the BSF determines to support the algorithm supported by the terminal device; in another example, assuming that the algorithm supported by the terminal device is SHA-256, and the algorithm supported by the BSF includes SHA-256, the BSF determines to support the algorithm supported by the terminal device; in yet another example, assuming that the algorithm supported by the terminal device is SHA-1 and SHA-256, and the algorithm supported by the BSF includes SHA-1 and SHA-256, the BSF determines to support the algorithm supported by the terminal device.

[0300] In a possible implementation, the BSF determines not to support the algorithm supported by the terminal device, for example, in an example, assuming that the algorithm supported by the terminal device is SHA-256, and the algorithm supported by the BSF does not include SHA-256, the BSF determines not to support the algorithm supported by the terminal device; in another example, assuming that the algorithm supported by the terminal device is SHA-1 and SHA-256, and the algorithm supported by the BSF does not support SHA-256 and SHA-1, the BSF determines not to support the algorithm supported by the terminal device.

[0301] In a possible implementation, after the BSF determines not to support the algorithm supported by the terminal device, the BSF sends third indication information to the terminal device, the third information being used to instruct the terminal device to use the mobile equipment based generic bootstrapping architecture (GBA_ME) mechanism, and after the terminal device receives the third indication information, the terminal device uses the GBA_ME mechanism, that is, verifies the second message authentication code (MAC) or the authentication token (AUTN). That is, when the terminal device uses the GBA_ME mechanism, the terminal device receives the second message authentication code (MAC) from the BSF correspondingly.

[0302] The BSF selecting the target algorithm can also be at any time point after the BSF receiving the first bootstrapping request message, which is not limited in the present application.

[0303] In a possible implementation, before the BSF selects the target algorithm according to the identifier of the terminal device, the BSF determines to use the universal integrated circuit card enhanced generic bootstrapping architecture (GBA_U) mechanism.

[0304] In a possible implementation, after the BSF selects the target algorithm, the BSF sends the target algorithm to the terminal device. In an example, assuming that the BSF selects the target algorithm as SHA-256 according to the identifier of the terminal device in the third bootstrapping request message or the fourth bootstrapping request message, the BSF sends the target algorithm SHA-256 to the terminal device.

[0305] Step S714: The BSF determines the first message authentication code (MAC*) according to the target algorithm.

[0306] In an example, assuming the target algorithm is SHA-256, the BSF obtains a first message authentication code MAC* from a second message authentication code MAC in the received first authentication vector, where Trunc represents a truncation operation.

[0307] In a possible implementation, after the BSF determines the first message authentication code MAC* according to the target algorithm, the BSF determines AUTN* according to the first message authentication code MAC*, where where AMF is an authentication management domain, SQN is a sequence number, the terminal device and the HSS both save the SQN, and AK is an anonymous key.

[0308] Optionally, before the BSF determines the first message authentication code MAC* and the AUTN* according to the target algorithm, the BSF determines to use the GBA_U mechanism.

[0309] Step S715: The BSF sends a random number RAND and the AUTN* to the terminal device.

[0310] Specifically, the AUTN* includes the first message authentication code MAC*.

[0311] Optionally, the BSF also sends the target algorithm to the terminal device.

[0312] Step S716: The terminal device receives the random number RAND and the AUTN* from the BSF.

[0313] Optionally, the terminal device also receives the target algorithm from the BSF.

[0314] Step S717: The terminal device determines a second message authentication code.

[0315] Specifically, the second message authentication code can be MAC, and the second message authentication code is used to authenticate the BSF.

[0316] If the terminal device receives the target algorithm from the BSF, the terminal device determines the second message authentication code using the target algorithm and the first message authentication code; or if the terminal device does not receive the target algorithm, if the terminal device supports the first algorithm and the second algorithm, the terminal device determines the second message authentication code using the first algorithm and the first message authentication code.

[0317] In an example, assuming the target algorithm is SHA-256, the first message authentication code is MAC*, where The terminal device determines MAC using SHA-256 and MAC*.

[0318] Specifically, after receiving the random number RAND and the AUTN*, the terminal device or the UICC calculates the IK by using the same method as the network side device, and calculates Further, the terminal device or the UICC can also calculate and verify that the AUTN is from an authorized network.

[0319] Optionally, before calculating the second message authentication code, the terminal device determines to use the GBA_U mechanism.

[0320] Step S718: If the terminal device does not receive the target algorithm from the BSF, the terminal device verifies the AUTN* and the MAC* by using the first algorithm SHA-1.

[0321] Step S719: The terminal device sends the authentication response information generated based on the RES to the BSF.

[0322] Step S720: The BSF verifies the authentication response information, and sends the result of verifying the authentication response information to the terminal device.

[0323] In a possible implementation, before sending the result of verifying the authentication response information to the terminal device, the BSF generates a fifth identity; or the BSF generates the fifth identity (TMPI*) according to the third indication information in the fourth response message or the third indication information in the third bootstrapping request message. The description of the content included in the fifth identity can be referred to the description in step S501, which is not described here again. The BSF saves the correspondence between the fifth identity and the second identity. The correspondence is used for, when the BSF receives the fourth bootstrapping request message including the fifth identity, the BSF determines the second identity corresponding to the fifth identity according to the correspondence.

[0324] In a possible implementation, after generating the fifth identity, the BSF sends the fifth identity to the terminal device.

[0325] In a further possible implementation, the BSF generates the first bootstrapping transaction identifier information (B-TID*) before sending the result of verifying the authentication response information to the terminal device. Specifically, the first bootstrapping transaction identifier information (B-TID*) is used to identify a bootstrapping transaction between the terminal device and the BSF. The parameters used to generate the B-TID* include one or more of the random number RAND, the 5G GBA key, the second identifier, the identifier of the BSF, and the character used to identify 5G. The 5G GBA key is generated based on the CK and the IK, and the character used to identify 5G can be a character containing "5", and / or "5g", and / or "5g-gba", and / or "5g-gba-me", and / or "5g-gba-u", and / or "gba", and / or "5gba", and / or "5gba-me", and / or "5gba-u", and / or "5gba".

[0326] In a further possible implementation, the BSF generates the first bootstrapping transaction identifier information (B-TID*) according to the character used to identify 5G before sending the first bootstrapping transaction identifier information (B-TID*) to the terminal device.

[0327] Step S721: The terminal device acquires the first bootstrapping transaction identifier information (B-TID*) and / or the fifth identifier (TMPI*).

[0328] Specifically, the first bootstrapping transaction identifier information (B-TID*) and the fifth identifier (TMPI*) are as described above, and will not be described here again.

[0329] In a possible implementation, the terminal device receives the first bootstrapping transaction identifier information (B-TID*) and / or the fifth identifier (TMPI*) from the BSF.

[0330] In a further possible implementation, the terminal device generates the first bootstrapping transaction identifier information (B-TID*) and / or the fifth identifier (TMPI*) of the terminal device. The parameters used to generate the first bootstrapping transaction identifier information (B-TID*) and the fifth identifier (TMPI*) are as described above, and will not be described here again.

[0331] Step S722: Optionally, the terminal device sends an application request message to a network application function NAF.

[0332] Specifically, the application request message includes the first bootstrapping transaction identifier information (B-TID*).

[0333] Step S723: The NAF receives the application request message from the terminal device.

[0334] Specifically, after receiving the application request message from the terminal device, the NAF can determine the BSF that performs the bootstrapping request procedure with the terminal device according to the BSF domain name carried in the first bootstrapping transaction identifier information (B-TID*), and obtain the key for secure communication with the terminal device from the BSF.

[0335] In the method shown in the figure, the BSF determines the target algorithm according to the identifier of the terminal device included in the bootstrapping request message from the terminal device, and sends the target algorithm to the terminal device, in this way, the terminal device and the BSF can use the same algorithm to verify the AUTN*, and the algorithm compatibility problem of the terminal device and the BSF is solved. Figure 7

[0336] Please refer to Figure 8 , Figure 8 The method is an algorithm negotiation method in a general bootstrapping architecture provided by the embodiment of the application, and includes but is not limited to the following steps.

[0337] Step S801: The terminal device obtains the algorithm supported by the BSF.

[0338] Specifically, the algorithm supported by the BSF includes a first algorithm and / or a second algorithm. In an example, the first algorithm can be a secure hash algorithm 1 (SHA-1), and the second algorithm can be a secure hash algorithm 2 (SHA2), wherein the SHA2 includes a secure hash algorithm 224 (SHA-224), a secure hash algorithm 256 (SHA-256), a secure hash algorithm 384 (SHA-384), and a secure hash algorithm 512 (SHA-512). The first algorithm can include one or more algorithms, and the second algorithm can include one or more algorithms, which are not limited by the embodiment of the application. For example, the first algorithm can be a secure hash algorithm 1 (SHA-1), and the second algorithm can be a secure hash algorithm 256 (SHA-256).

[0339] Step S802: The terminal device selects a target algorithm according to the algorithm supported by the BSF.

[0340] In an example, if the algorithm supported by the BSF includes SHA-256, the terminal device selects SHA-256 as the target algorithm. If the algorithm supported by the BSF is SHA-1, the terminal device selects SHA-1 as the target algorithm.

[0341] Step S803: The terminal device sends a fifth bootstrapping request message to the BSF.

[0342] Specifically, the fifth bootstrapping request message includes the target algorithm.

[0343] Step S804: The BSF receives the fifth bootstrapping request message from the terminal device.​

[0344] Step S805: The BSF sends a fifth request message to the HSS.

[0345] Specifically, the fifth request message is used to obtain the first authentication vector of the terminal device, or is used to invoke the first authentication service of the HSS to obtain the first authentication vector of the terminal device.

[0346] Step S806: The HSS receives the fifth request message from the BSF.

[0347] Specifically, the fifth request message is used to obtain the first authentication vector of the terminal device, or is used to invoke the first authentication service of the HSS to obtain the first authentication vector of the terminal device.

[0348] Step S807: The HSS generates the first authentication vector of the terminal device.

[0349] Specifically, the first authentication vector of the terminal device can be generated by the HSS, or the HSS sends a request message to the UDM to make the UDM generate the first authentication vector. The possible implementation of the first authentication vector is seen in step S507, which will not be repeated here.

[0350] Step S808: The HSS sends a fifth response message to the BSF.

[0351] Specifically, the fifth response message includes the first authentication vector of the terminal device. The possible implementation of the first authentication vector is seen in step S507, which will not be repeated here.

[0352] Step S809: The BSF receives the fifth response message from the HSS.

[0353] Specifically, the fifth response message includes the first authentication vector of the terminal device. The possible implementation of the first authentication vector is seen in step S507, which will not be repeated here.

[0354] Step S810: The BSF determines the first message authentication code MAC* using the target algorithm.

[0355] In one example, assuming that the target algorithm is SHA-256, the BSF obtains the first message authentication code MAC* from the second message authentication code MAC in the received first authentication vector, where Trunc represents the truncation operation.

[0356] In one possible implementation, after the BSF determines the first message authentication code MAC* according to the target algorithm, the BSF determines AUTN* according to the first message authentication code MAC*, wherein where AMF is an authentication management domain, SQN is a sequence number, the terminal device and the HSS both save the SQN, and AK is an anonymous key.

[0357] Optionally, before determining the first message authentication code MAC*, the BSF determines to use a generic bootstrapping architecture for UICC enhanced (GBA_U) mechanism.

[0358] Step S811: The BSF sends the random number RAND and the AUTN* to the terminal device.

[0359] Specifically, the AUTN* includes the first message authentication code MAC*.

[0360] Step S812: The terminal device receives the random number RAND and the AUTN* from the BSF.

[0361] Specifically, the first message authentication code is MAC*.

[0362] Step S813: The terminal device verifies the AUTN* and the MAC* using the target algorithm.

[0363] In an example, assuming that the target algorithm is SHA-256, the first message authentication code is MAC*, wherein, The terminal device determines the MAC using the SHA-256 and the MAC*.

[0364] In an example, assuming that the target algorithm is SHA-256, after receiving the random number RAND and the AUTN*, the terminal device or the UICC calculates the IK using the same method as the network side, and calculates Further, the terminal device or the UICC can also calculate and verify that the AUTN is from an authorized network.

[0365] Optionally, before verifying the AUTN* and the MAC* using the target algorithm, the terminal device determines to use the GBA_U mechanism.

[0366] In the method shown in Figure 8 , the terminal device can avoid using different algorithms with the BSF by acquiring the algorithms supported by the BSF, selecting a target algorithm, and sending the target algorithm to the BSF, thereby ensuring that the terminal device and the BSF use the same algorithm for the GBA_U mechanism, and solving the algorithm compatibility problem of the terminal device and the BSF of new and old versions.

[0367] Please refer to Figure 9 , Figure 9 is a method for algorithm negotiation in a generic bootstrapping architecture, which includes but is not limited to the following steps:

[0368] Step S901: The terminal device generates a sixth bootstrapping request message.

[0369] Step S902: The terminal device sends the sixth bootstrapping request message to the BSF.

[0370] Step S903: The BSF receives the sixth bootstrapping request message from the terminal device.

[0371] Step S904: The BSF sends a sixth request message to the HSS.

[0372] Specifically, the sixth request message is used to obtain the first authentication vector of the terminal device, or is used to invoke the first authentication service of the HSS to obtain the first authentication vector of the terminal device.

[0373] Step S905: The HSS receives the sixth request message of the BSF.

[0374] Specifically, the sixth request message is used to obtain the first authentication vector of the terminal device, or is used to invoke the first authentication service of the HSS to obtain the first authentication vector of the terminal device.

[0375] Step S906: The HSS obtains the first authentication vector of the terminal device.

[0376] Specifically, the first authentication vector of the terminal device can be generated by the HSS, or the HSS sends a request message to the UDM to make the UDM generate the first authentication vector. The possible implementation of the first authentication vector is seen in step S507, which will not be repeated here.

[0377] Step S907: The HSS sends a sixth response message to the BSF.

[0378] Specifically, the sixth response message includes the first authentication vector of the terminal device, and the possible implementation of the first authentication vector is seen in step S507, which will not be repeated here. The sixth response message includes fourth indication information, which is used to instruct the BSF to adopt the GBA_ME mechanism, that is, the fourth indication information is used to instruct the BSF not to adopt the GBA_U mechanism.

[0379] Step 908: The BSF receives the sixth response message from the BSF.

[0380] Specifically, the sixth response message includes the first authentication vector of the terminal device, and the sixth response message includes fourth indication information, which is used to instruct the BSF to adopt the GBA_ME mechanism, that is, the fourth indication information is used to instruct the BSF not to adopt the GBA_U mechanism.

[0381] Step S909: The BSF determines to adopt the GBA_ME mechanism according to the fourth indication information.

[0382] Specifically, if the BSF uses the GBA_ME mechanism, the BSF sends a random number RAND and an authentication token AUTN to the terminal device.

[0383] Step S910: BSF sends the fifth instruction information to the terminal device.

[0384] Specifically, this step is optional, and the fifth instruction information is used to instruct the terminal device to adopt the GBA_ME mechanism.

[0385] Step S911: The terminal device receives the fifth instruction information from the BSF.

[0386] Specifically, this step is optional, and the fifth instruction information is used to instruct the terminal device to adopt the GBA_ME mechanism.

[0387] Step S912: The terminal device determines to use the GBA_ME mechanism based on the fifth instruction information.

[0388] Step S913: The terminal device verifies the authentication token AUTN.

[0389] Specifically, authentication token In this domain, AMF stands for Authentication Management Domain, SQN is the Serial Number (both the terminal device and HSS store the SQN), AK is the Anonymous Key, and MAC is the Message Authentication Code. This represents the XOR operation, where MAC is generated based on SQN, K, AMF, and the random number RAND.

[0390] from Figure 9 In the method shown, the BSF obtains indication information from the terminal device or HSS. This indication information is used to instruct the BSF not to use the GBA_U mechanism, thereby ensuring that both the BSF and the terminal device use the GBA_ME mechanism. This also ensures that both the BSF and the terminal device use the first algorithm, avoiding the problem of inconsistent algorithms and solving the problem of algorithm compatibility between the terminal device and the BSF.

[0391] The methods of the embodiments of this application have been described in detail above, and the apparatus of the embodiments of this application is provided below.

[0392] Please see Figure 10 , Figure 10 This is a schematic diagram of the structure of an algorithm negotiation device in a general boot architecture provided in this application embodiment. The algorithm negotiation device in the general boot architecture may include a processing unit 1001 and a communication unit 1002, wherein the detailed description of each unit is as follows.

[0393] The processing unit 1001 is used to obtain the algorithms supported by the terminal device, wherein the algorithms supported by the terminal device include a first algorithm and / or a second algorithm;

[0394] The processing unit 1001 is further configured to select a target algorithm according to an algorithm supported by the terminal device.

[0395] The processing unit 1001 is further configured to determine a first message authentication code according to the target algorithm.

[0396] The communication unit 1002 is configured to send the first message authentication code to the terminal device.

[0397] In a possible implementation, the communication unit 1002 is further configured to send the target algorithm to the terminal device.

[0398] In another possible implementation, the first algorithm includes a secure hash algorithm 1, and the second algorithm includes a secure hash algorithm 256.

[0399] In another possible implementation, the communication unit 1002 is further configured to receive, from the terminal device, the algorithm supported by the terminal device or first indication information or a first identifier or a second identifier; the processing unit 1001 is further configured to determine, according to the first indication information, that the algorithm supported by the terminal device includes the second algorithm; or the processing unit 1001 is further configured to determine, according to the first identifier, that the algorithm supported by the terminal device includes the second algorithm, the first identifier being generated according to the second identifier; or the processing unit 1001 is further configured to determine, according to the second identifier, that the terminal device supports the first algorithm.

[0400] In another possible implementation, the first identifier is generated according to the second identifier and an identity protection key IPK.

[0401] In another possible implementation, the communication unit 1002 is further configured to receive, from the terminal device, a first bootstrapping request message, the first bootstrapping request message including the algorithm supported by the terminal device or the first indication information or the first identifier or the second identifier.

[0402] In another possible implementation, the second identifier is one of a subscription permanent identifier SUPI of the terminal device, an internet protocol multimedia private identity IMPI of the terminal device, an international mobile subscriber identity IMSI of the terminal device, or a generic public subscription identity GPSI of the terminal device.

[0403] In a further possible implementation, the communication unit 1002 is further configured to receive second indication information from the home subscriber server network element or a second algorithm supported by the terminal device; the second indication information is used to indicate that the algorithm supported by the terminal device includes the second algorithm; and the processing unit 1001 is further configured to determine, according to the second indication information, that the algorithm supported by the terminal device includes the second algorithm.

[0404] In a further possible implementation, the communication unit 1002 is further configured to send a first request message to the home subscriber server network element; and the communication unit 1002 is further configured to receive a first response message from the home subscriber server network element, the first response message including the second indication information or the algorithm supported by the terminal device.

[0405] In a further possible implementation, the processing unit 1001 is further configured to determine, before selecting a target algorithm according to the algorithm supported by the terminal device, to use a general bootstrapping architecture enhanced by universal integrated circuit card (GBA_U) mechanism.

[0406] In a further possible implementation, the processing unit 1001 is further configured to select the second algorithm as the target algorithm when the algorithm supported by the terminal device includes the second algorithm.

[0407] In a further possible implementation, the processing unit 1001 is further configured to determine, after obtaining the algorithm supported by the terminal device and before selecting a target algorithm according to the algorithm supported by the terminal device, whether to support the algorithm supported by the terminal device; the processing unit 1001 is further configured to perform the selection of the target algorithm after determining to support the algorithm supported by the terminal device; and the processing unit 1001 is further configured to determine not to support the algorithm supported by the terminal device, and send third indication information to the terminal device, the third indication information being used to instruct the terminal device to use a general bootstrapping architecture based on mobile equipment (GBA_ME) mechanism.

[0408] It should be noted that the implementation and advantages of each unit can also be referred to the corresponding description of the method embodiment shown in Figure 5 .

[0409] Please refer to Figure 11 , Figure 11 is a structure diagram of an algorithm negotiation device in a general bootstrapping architecture provided by the embodiment of the present application. The algorithm negotiation device in the general bootstrapping architecture can include a processing unit 1101 and a communication unit 1102, and the detailed description of each unit is as follows.

[0410] The processing unit 1101 is configured to generate a first bootstrapping request message.

[0411] The communication unit 1102 is configured to send, to a bootstrap server function network element, a first bootstrap request message, wherein the first bootstrap request message comprises an algorithm supported by the terminal device or a first identifier or a second identifier or first indication information; the algorithm supported by the terminal device comprises a first algorithm and / or a second algorithm; the first identifier is used to indicate that the algorithm supported by the terminal device comprises the second algorithm, the second identifier is used to indicate that the terminal device supports the first algorithm, and the first identifier is generated according to the second identifier; and the first indication information is used to indicate that the algorithm supported by the terminal device comprises the second algorithm.

[0412] The communication unit 1102 is further configured to receive a first message authentication code or a second message authentication code from the bootstrap server function network element.

[0413] In a possible implementation, the first algorithm comprises a secure hash algorithm 1, and the second algorithm comprises a secure hash algorithm 256.

[0414] In another possible implementation, the first identifier is generated according to the second identifier and an identifier protection key IPK.

[0415] In another possible implementation, the second identifier is one of a subscription permanent identifier SUPI of the terminal device, an internet protocol multimedia private identity IMPI of the terminal device, an international mobile subscriber identity IMSI of the terminal device, and a generic public subscription identity GPSI of the terminal device.

[0416] In another possible implementation, the communication unit 1102 is configured to receive, from the bootstrap server function network element, a target algorithm, wherein the target algorithm is determined according to the algorithm supported by the terminal device; and the processing unit 1101 is configured to determine the second message authentication code by using the target algorithm and the first message authentication code, and the second message authentication code is used to authenticate the bootstrap server function network element.

[0417] In another possible implementation, the processing unit 1101 is further configured to read an algorithm supported by a universal integrated circuit card UICC of the terminal device before generating the first bootstrap request message, and the algorithm supported by the terminal device is the algorithm supported by the universal integrated circuit card UICC.

[0418] In yet another possible implementation, the communication unit 1102 is further configured to receive third indication information from the bootstrapping server function network element, the third indication information being used to indicate that the terminal device adopts a mobile equipment based generic bootstrapping architecture (GBA_ME) mechanism; and the processing unit 1101 is further configured to verify the second message authentication code.

[0419] It should be noted that the implementation and beneficial effects of each unit can also be correspondingly referred to the corresponding description of the method embodiments shown in Figure 5

[0420] Please refer to Figure 12 , Figure 12 is a structure diagram of an algorithm negotiation device in a generic bootstrapping architecture, provided by an embodiment of the present application. The algorithm negotiation device in the generic bootstrapping architecture can include a processing unit 1201 and a communication unit 1202, and the detailed description of each unit is as follows.

[0421] The processing unit 1201 is configured to receive a first request message from a bootstrapping server function network element through the communication unit.

[0422] The communication unit 1202 is further configured to send a first response message to the bootstrapping server function network element, the first response message including an algorithm supported by the terminal device or second indication information, the algorithm supported by the terminal device including a first algorithm and / or a second algorithm, and the second indication information being used to indicate that the algorithm supported by the terminal device includes the second algorithm.

[0423] In a possible implementation, the first algorithm includes a secure hash algorithm 1, and the second algorithm includes a secure hash algorithm 256.

[0424] It should be noted that the implementation and beneficial effects of each unit can also be correspondingly referred to the corresponding description of the method embodiments shown in Figure 5

[0425] Please refer to Figure 13 , Figure 13 is an algorithm negotiation device 1300 in a generic bootstrapping architecture, provided by an embodiment of the present application. The device 1300 includes a processor 1301 and a transceiver 1303, and optionally includes a memory 1302. The processor 1301, the memory 1302 and the transceiver 1303 are connected with each other through a bus 1304.

[0426] ​​The memory 1302 includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM), or a compact disc read-only memory (CD-ROM), which is used to store relevant instructions and data. The transceiver 1303 is used to receive and send data.

[0427] The processor 1301 can be one or more central processing units (CPUs). In the case where the processor 1301 is a CPU, the CPU can be a single-core CPU or a multi-core CPU.

[0428] The processor 1301 in the apparatus 1300 reads a computer program stored in the memory 1302, and is configured to perform the following operations:

[0429] Obtain an algorithm supported by a terminal device, wherein the algorithm supported by the terminal device includes a first algorithm and / or a second algorithm;

[0430] Select a target algorithm according to the algorithm supported by the terminal device;

[0431] Determine a first message authentication code according to the target algorithm;

[0432] Send the first message authentication code to the terminal device through the transceiver 1303.

[0433] In a possible implementation, the processor 1301 is further configured to send the target algorithm to the terminal device through the transceiver 1303.

[0434] In another possible implementation, the first algorithm includes a secure hash algorithm 1, and the second algorithm includes a secure hash algorithm 256.

[0435] In another possible implementation, the processor 1301 is further configured to receive, through the transceiver 1303, the algorithm supported by the terminal device or first indication information or a first identifier or a second identifier from the terminal device; determine, according to the first indication information, that the algorithm supported by the terminal device includes the second algorithm; or determine, according to the first identifier, that the algorithm supported by the terminal device includes the second algorithm, wherein the first identifier is generated according to the second identifier; or determine, according to the second identifier, that the terminal device supports the first algorithm.

[0436] In a further possible implementation, the first identity is generated according to the second identity and an identity protection key IPK.

[0437] In a further possible implementation, the processor 1301 is further configured to receive, through the transceiver 1303, a first bootstrapping request message from the terminal device, the first bootstrapping request message comprising the algorithm supported by the terminal device or the first indication information or the first identity or the second identity.

[0438] In a further possible implementation, the second identity is one of a subscription permanent identity SUPI of the terminal device, an Internet Protocol Multimedia Private Identity IMPI of the terminal device, an International Mobile Subscriber Identity IMSI of the terminal device, and a Generic Public Subscription Identity GPSI of the terminal device.

[0439] In a further possible implementation, the processor 1301 is further configured to receive, through the transceiver 1303, second indication information or a second algorithm supported by the terminal device from the home subscriber server network element; the second indication information is used to indicate that the algorithm supported by the terminal device comprises the second algorithm; and the algorithm supported by the terminal device is determined to comprise the second algorithm according to the second indication information.

[0440] In a further possible implementation, the processor 1301 is further configured to send, through the transceiver 1303, a first request message to the home subscriber server network element; and receive, through the transceiver 1303, a first response message from the home subscriber server network element, the first response message comprising the second indication information or the algorithm supported by the terminal device.

[0441] In a further possible implementation, the processor 1301 is further configured to determine to use a generic bootstrapping architecture enhanced for universal integrated circuit card GBA_U mechanism before selecting a target algorithm according to the algorithm supported by the terminal device.

[0442] In a further possible implementation, the processor 1301 is further configured to select the second algorithm as the target algorithm when the algorithm supported by the terminal device comprises the second algorithm.

[0443] In yet another possible implementation, the processor 1301 is further configured to, after acquiring the algorithm supported by the terminal device and before selecting the target algorithm according to the algorithm supported by the terminal device, determine whether the algorithm supported by the terminal device is supported; after determining that the algorithm supported by the terminal device is supported, perform the selecting of the target algorithm; and after determining that the algorithm supported by the terminal device is not supported, send, through the transceiver 1303, third indication information to the terminal device, where the third indication information is used to instruct the terminal device to adopt a general booting architecture based on a mobile equipment (GBA_ME) mechanism.

[0444] It should be noted that the implementation and advantages of each operation can also be correspondingly described with reference to the descriptions of the method embodiments shown in Figure 5

[0445] Please refer to Figure 14 , Figure 14 The apparatus 1400 provided in the embodiments of the present application is an algorithm negotiation apparatus 1400 in a general booting architecture, which comprises a processor 1401 and a transceiver 1403, and optionally further comprises a memory 1402, wherein the processor 1401, the memory 1402 and the transceiver 1403 are connected to each other through a bus 1404.

[0446] The memory 1402 comprises, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM), or a compact disc read-only memory (CD-ROM), and is used for storing relevant instructions and data. The transceiver 1403 is used for receiving and sending data.

[0447] The processor 1401 can be one or more central processing units (CPUs), and in the case where the processor 1401 is a CPU, the CPU can be a single-core CPU or a multi-core CPU.

[0448] The processor 1401 in the apparatus 1400 reads a computer program stored in the memory 1402, and is configured to perform the following operations:

[0449] generating a first booting request message;

[0450] ​send, by the transceiver 1403, the first bootstrapping request message to a bootstrapping server function network element, the first bootstrapping request message comprising an algorithm or a first identity or a second identity or a first indication information supported by the terminal device; the algorithm supported by the terminal device comprises a first algorithm and / or a second algorithm; the first identity is used to indicate that the algorithm supported by the terminal device comprises the second algorithm, the second identity is used to indicate that the terminal device supports the first algorithm, and the first identity is generated according to the second identity; and the first indication information is used to indicate that the algorithm supported by the terminal device comprises the second algorithm.

[0451] receive, by the transceiver 1403, a first message authentication code or a second message authentication code from the bootstrapping server function network element.

[0452] In a possible implementation, the first algorithm comprises a secure hash algorithm 1, and the second algorithm comprises a secure hash algorithm 256.

[0453] In another possible implementation, the first identity is generated according to the second identity and an identity protection key IPK.

[0454] In another possible implementation, the second identity is one of a subscription permanent identity SUPI of the terminal device, an internet protocol multimedia private identity IMPI of the terminal device, an international mobile subscriber identity IMSI of the terminal device, and a generic public subscription identity GPSI of the terminal device.

[0455] In another possible implementation, the processor 1401 is further configured to receive, by the transceiver 1403, a target algorithm from the bootstrapping server function network element, the target algorithm being determined according to the algorithm supported by the terminal device; determine the second message authentication code using the target algorithm and the first message authentication code; and use the second message authentication code to authenticate the bootstrapping server function network element.

[0456] In another possible implementation, the processor 1401 is further configured to read an algorithm supported by a universal integrated circuit card UICC of the terminal device before generating the first bootstrapping request message; and the algorithm supported by the terminal device is the algorithm supported by the universal integrated circuit card UICC.

[0457] In another possible implementation, the processing unit is further configured to receive, by the transceiver 1403, third indication information from the bootstrapping server function network element, the third indication information being used to indicate that the terminal device adopts a mobile equipment based generic bootstrapping architecture GBA_ME mechanism; and verify the second message authentication code.

[0458] It should be noted that the implementation and beneficial effects of each operation can also be correspondingly referred to Figure 5 the corresponding description of the method embodiments shown.

[0459] Please refer to Figure 15 , Figure 15 An algorithm negotiation device 1500 in a general booting architecture provided by the embodiment of the present application, the device 1500 comprises a processor 1501 and a transceiver 1503, and optionally further comprises a memory 1502, the processor 1501, the memory 1502 and the transceiver 1503 are connected with each other through a bus 1504.

[0460] The memory 1502 comprises but is not limited to a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM) or a compact disc read-only memory (CD-ROM), which is used for relevant instructions and data. The transceiver 1503 is used for receiving and sending data.

[0461] The processor 1501 can be one or more central processing units (CPUs), in the case of the processor 1501 being a CPU, the CPU can be a single-core CPU or a multi-core CPU.

[0462] The processor 1501 in the device 1500 reads the computer program stored in the memory 1502, for performing the following operations:

[0463] receiving a first request message from a boot server function network element through the transceiver 1503;

[0464] sending a first response message to the boot server function network element through the transceiver 1503, the first response message comprising an algorithm supported by the terminal device or second indication information, the algorithm supported by the terminal device comprising a first algorithm and / or a second algorithm, the second indication information being used for indicating that the algorithm supported by the terminal device comprises the second algorithm.

[0465] In a possible implementation manner, the first algorithm is a secure hash algorithm 1, and the second algorithm is a secure hash algorithm 256.

[0466] It should be noted that the implementation and beneficial effects of each operation can also be correspondingly referred to Figure 5 the corresponding description of the method embodiments shown.

[0467] The embodiment of the present application further provides a chip system, which comprises at least one processor, a memory and an interface circuit, the memory, the transceiver and the at least one processor are interconnected through a line, and the at least one memory stores instructions; when the instructions are executed by the processor, Figure 5 The method flow shown is implemented.

[0468] The embodiment of the present application further provides a computer readable storage medium, which stores instructions, when the instructions are executed on a boot server function network element or a home subscription user server network element or a terminal device, Figure 5 The method flow shown is implemented.

[0469] The embodiment of the present application further provides a computer program product, when the computer program product is executed on a boot server function network element or a home subscription user server network element or a terminal device, Figure 5 The method flow shown is implemented.

[0470] The embodiment of the present application further provides an algorithm negotiation system in a general boot architecture, which comprises a first device and a second device, wherein the first device is a boot server function as described in the embodiment of the present application, Figure 5 and the second device is a home subscription user server as described in the embodiment of the present application. Figure 5

[0471] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by a computer program instructing relevant hardware, and the program can be stored in a computer readable storage medium. When the program is executed, the processes of the above-mentioned method embodiments can be included. The aforementioned storage medium includes ROM, random access memory (RAM), magnetic disk or optical disk and other various storage media that can store program codes.​< / mcc> < / mnc> < / imsi>

Claims

1. A method for algorithm negotiation in a general bootstrapping architecture, characterized in that, The method comprises the following steps: The bootstrapping server function network element receives a first authentication vector and second indication information from a home subscriber server network element, and the second indication information is used to indicate that an algorithm supported by a terminal device comprises a second algorithm, and the second algorithm comprises a secure hash algorithm 256; The bootstrapping server function network element determines the second algorithm as a target algorithm according to the second indication information; The bootstrapping server function network element determines a first message authentication code according to the target algorithm and a second message authentication code in the first authentication vector; The bootstrapping server function network element sends the first message authentication code to the terminal device.

2. The method of claim 1, wherein, The bootstrapping server function network element sends the first message authentication code to the terminal device, which comprises the following steps: The bootstrapping server function network element sends a random number RAND and AUTN* to the terminal device, and the AUTN* comprises the first message authentication code.

3. The method according to claim 1 or 2, characterized in that, The bootstrapping server function network element determines a first message authentication code according to the target algorithm and a second message authentication code in the first authentication vector, which comprises the following steps: The bootstrapping server function network element determines the first message authentication code MAC* = MAC ⊕ Trunc(SHA-256(IK)) according to the secure hash algorithm 256 and the second message authentication code MAC, wherein Trunc represents a truncation operation, and ⊕ represents an exclusive or operation.

4. The method according to claim 1 or 2, characterized in that, The bootstrapping server function network element determines the second algorithm as a target algorithm according to the second indication information, which comprises the following steps: The bootstrapping server function network element determines that the algorithm supported by the terminal device comprises the second algorithm according to the second indication information.

5. The method according to claim 1 or 2, characterized in that, The bootstrapping server function network element receives a first authentication vector and second indication information from a home subscriber server network element, which comprises the following steps: The bootstrapping server function network element sends a first request message to the home subscriber server network element; The bootstrapping server function network element receives a first response message from the home subscriber server network element, and the first response message comprises the first authentication vector and the second indication information.

6. The method of claim 1 or 2, wherein, Before the bootstrapping server function network element determines a first message authentication code according to the target algorithm and a second message authentication code in the first authentication vector, the method further comprises the following steps: The bootstrapping server function network element determines to use a general bootstrapping architecture enhanced by a universal integrated circuit card (GBA_U) mechanism.

7. The method according to claim 1 or 2, characterized in that, The bootstrapping server function network element determines the second algorithm as a target algorithm according to the second indication information, which comprises the following steps: The bootstrapping server function network element determines that the algorithm supported by the terminal device comprises the second algorithm according to the second indication information, and selects the second algorithm as the target algorithm.

8. The method of claim 1 or 2, wherein, The method further comprises the following steps: The bootstrapping server function network element sends the target algorithm to the terminal device.

9. A method for algorithm negotiation in a generic boot architecture, the method comprising: The method is applied to an algorithm negotiation device, which comprises the following steps: A second bootstrapping request message is generated; The second bootstrapping request message is sent to a bootstrapping server function network element; receive a first message authentication code from the bootstrapping server function network element, the first message authentication code being determined according to a second message authentication code in a first authentication vector and a second algorithm supported by the algorithm negotiation device, the second algorithm comprising a secure hash algorithm 256; determine the second message authentication code according to the second algorithm and the first message authentication code, the second message authentication code being used to authenticate the bootstrapping server function network element.

10. The method of claim 9, wherein, The receiving the first message authentication code from the bootstrapping server function network element comprises: receiving a random number RAND and an AUTN* from the bootstrapping server function network element, the AUTN* comprising the first message authentication code.

11. The method according to claim 9 or 10, characterized in that, The determining the second message authentication code according to the second algorithm and the first message authentication code comprises: determining the second message authentication code MAC = MAC* ⊕ Trunc(SHA-256(IK)) according to the secure hash algorithm 256 and the first message authentication code MAC*, wherein Trunc represents a truncation operation, and ⊕ represents an exclusive or operation.

12. A method for algorithm negotiation in a generic boot architecture, the method comprising: comprise: a home subscriber server network element receiving a first request message from a bootstrapping server function network element; the home subscriber server network element sending a first authentication vector and second indication information to the bootstrapping server function network element, the second indication information being used to indicate that an algorithm supported by a terminal device comprises a second algorithm, the second algorithm comprising a secure hash algorithm 256.

13. The method of claim 12, wherein, The home subscriber server network element sending the first authentication vector and the second indication information to the bootstrapping server function network element comprises: the home subscriber server network element sending a first response message to the bootstrapping server function network element, the first response message comprising the first authentication vector and the second indication information.

14. An algorithm negotiation device in a general bootstrapping architecture, characterized in that, comprise: a communication unit configured to receive a first authentication vector and second indication information from a home subscriber server network element, the second indication information being used to indicate that an algorithm supported by a terminal device comprises a second algorithm, the second algorithm comprising a secure hash algorithm 256; a processing unit configured to determine, according to the second indication information, that the second algorithm is a target algorithm, and determine a first message authentication code according to a second message authentication code in the first authentication vector and the target algorithm; the communication unit is further configured to send the first message authentication code to the terminal device.

15. The apparatus of claim 14, wherein the communication unit is further configured to send a random number RAND and an AUTN* to the terminal device, the AUTN* comprising the first message authentication code.

16. The apparatus of claim 14 or 15, wherein the processing unit is further configured to determine the first message authentication code MAC* = MAC ⊕ Trunc(SHA-256(IK)) according to the secure hash algorithm 256 and the second message authentication code MAC, wherein Trunc represents a truncation operation, and ⊕ represents an exclusive or operation.

17. The apparatus of claim 14 or 15, wherein The processing unit is further configured to determine, according to the second indication information, that the algorithm supported by the terminal device includes the second algorithm.

18. The apparatus of claim 14 or 15, wherein, The communication unit is further configured to send a first request message to the home subscriber server network element; The communication unit is further configured to receive a first response message from the home subscriber server network element, the first response message including the first authentication vector and the second indication information.

19. The apparatus of claim 14 or 15, wherein, The processing unit is further configured to determine, before determining a first message authentication code according to the target algorithm and a second message authentication code in the first authentication vector, to use a generic bootstrapping architecture for UMTS (GBA_U) mechanism based on universal integrated circuit card (UICC) enhancement.

20. The apparatus of claim 14 or 15, wherein, The processing unit is further configured to select, when the algorithm supported by the terminal device includes the second algorithm, the second algorithm as the target algorithm.

21. The apparatus of claim 14 or 15, wherein, The communication unit is further configured to send the target algorithm to the terminal device.

22. An algorithm negotiation apparatus in a generic boot architecture, comprising: comprising: a processing unit configured to generate a second bootstrapping request message; a communication unit configured to send the second bootstrapping request message to a bootstrapping server function network element; The communication unit is further configured to receive a first message authentication code from the bootstrapping server function network element, the first message authentication code being determined according to a second algorithm supported by the algorithm negotiation apparatus and a second message authentication code in a first authentication vector, the second algorithm including a secure hash algorithm 256 (SHA-256); The processing unit is further configured to determine the second message authentication code according to the second algorithm and the first message authentication code, the second message authentication code being used to authenticate the bootstrapping server function network element.

23. The apparatus of claim 22, wherein, The communication unit is further configured to receive a random number RAND and an AUTN* from the bootstrapping server function network element, the AUTN* including the first message authentication code.

24. The apparatus of claim 22 or 23, wherein, The processing unit is further configured to determine the second message authentication code MAC = MAC* ⊕ Trunc(SHA-256(IK)) according to the secure hash algorithm 256 (SHA-256) and the first message authentication code MAC*, wherein Trunc represents a truncation operation and ⊕ represents an exclusive or operation.

25. An algorithm negotiation apparatus in a generic boot architecture, comprising: comprising: a communication unit configured to receive a first request message from a bootstrapping server function network element; The communication unit is further configured to send a first authentication vector and second indication information to the bootstrapping server function network element, the second indication information being used to indicate that an algorithm supported by a terminal device includes a second algorithm, the second algorithm including a secure hash algorithm 256 (SHA-256).

26. The apparatus of claim 25, wherein, The communication unit is further configured to send a first response message to the bootstrapping server function network element, the first response message comprising the first authentication vector and the second indication information.

27. An algorithm negotiation system in a generic boot architecture, characterized by Comprise: The home subscriber server network element sends a first authentication vector and second indication information to a bootstrapping server function network element, the second indication information indicating that the algorithms supported by the terminal device include a second algorithm, the second algorithm including a secure hash algorithm 256; The bootstrapping server function network element receives the first authentication vector and the second indication information from the home subscriber server network element, determines the second algorithm as a target algorithm according to the second indication information, and determines a first message authentication code according to the target algorithm and a second message authentication code in the first authentication vector; The bootstrapping server function network element sends the first message authentication code to the terminal device.

28. A computer-readable storage medium, characterized in that, The computer readable storage medium stores program instructions, when the program instructions are run on the processor, the method of any one of claims 1-8, any one of claims 9-11, or any one of claims 12-13 is implemented.

29. A computer program product, characterised in that, When the computer program is executed, the method of any one of claims 1-8, any one of claims 9-11, or any one of claims 12-13 is implemented.

30. An algorithm negotiation system in a generic boot architecture, characterized by The system comprises a first device and a second device, the first device being the algorithm negotiation device of any one of claims 14-21, and the second device being the algorithm negotiation device of any one of claims 25-26.

Citation Information

Patent Citations

  • Secure class negotiation method in general guide system

    CN101170811A

  • Ub interface information interaction method in general guiding frame

    CN1878169A