A method, system, and client to improve robustness of client security processes
Patent Information
- Application Number
- CN202310408469.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-17
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2043-04-17
AI Technical Summary
[0003]基于上述问题,本发明提供一种提升客户端安全过程健壮性的方法、系统和客户端,旨在解决现有技术中无法正常执行安全模式控制流程的技术问题
[0013]本发明的有益技术效果在于,通过比较鉴权请求消息中的第一标识内容和安全模式控制流程发起消息中的第二标识内容的一致性,一致则结束鉴权流程,生成安全参数之后,进入安全模式控制流程,避免因为鉴权过程未正常结束导致安全模式控制流程失败,提升安全模式控制流程的健壮性。
Smart Images

Figure CN116437347B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless communication technology, and in particular to a method, system, and client for improving the robustness of client security processes. Background Technology
[0002] After the client powers on, it typically first performs an authentication process. Only after successful authentication does it proceed to the security mode control process, allowing the client to securely communicate with the network. In the 3GPP specification, the authentication and security mode control processes are separate, but the latter often requires parameters from the former, specifically parameters of certain security algorithms. If the UE experiences an anomaly in air interface message transmission / reception during authentication, these parameters cannot be generated because the authentication process cannot terminate properly, preventing the subsequent security mode control process from functioning correctly. In some abnormal scenarios, although an uplink anomaly occurs at the access network level, downlink operations may be normal (e.g., only the network reception confirmation for uplink messages is not received). However, no anomalies occur at the core network level, meaning uplink core network messages are correctly received. In such cases, the core network assumes the authentication process has successfully completed and initiates the security mode control process normally. However, in current implementations, the UE perceives the authentication process as not having terminated properly and therefore cannot correctly execute the security mode control process. Summary of the Invention
[0003] To address the aforementioned issues, this invention provides a method, system, and client for improving the robustness of client security processes, aiming to solve the technical problem of the inability to properly execute security mode control processes in the prior art.
[0004] A method for improving the robustness of client security processes includes: Step A1, the client receives an authentication request message carrying a first identifier from the core network and enters the authentication process; Step A2, the client saves the first identifier and replies with an authentication response message to the core network; Step A3, when the client receives a security mode control process initiation message carrying a second identifier from the core network, it determines whether the authentication process has ended: if the authentication process has ended, proceed to Step A4; if the authentication process has not ended, proceed to Step A5; Step A4, if security parameters have been generated, a security mode control process completion message is sent to the core network; Step A5, when it is determined that the first identifier and the second identifier are the same, the authentication process ends normally, and security parameters are generated. After generating the security parameters, a security mode control process completion message is sent to the core network.
[0005] Furthermore, in step A3, when the client receives a successful reception message from the core network to the access network for the authentication response message, the authentication process ends normally.
[0006] Furthermore, the first identification information is the key set identifier, and the second identification information is the key set identifier.
[0007] Furthermore, in step A4, if the security parameter generation fails, a rejection message for the security mode control procedure is sent to the core network.
[0008] A client for executing a method, as described above, to improve the robustness of a client security process.
[0009] A system for improving the robustness of client security processes includes the aforementioned method for improving client security process robustness, comprising: a core network, configured to: send an authentication request message carrying a first identifier to the client; and, upon receiving an authentication response message, send a security mode control process initiation message carrying a second identifier to the client; an access network, connected to the core network, configured to enable message transmission between the core network and the client; and a client, connected to the access network, configured to: enter the authentication process upon receiving the authentication request message; save the first identifier and reply with an authentication response message to the core network; upon receiving the security mode control process initiation message, determine whether the authentication process has ended and form a determination result; if the determination result indicates that the authentication process has ended and security parameters have been generated, send a security mode control process completion message to the core network; if the determination result indicates that the authentication process has not ended, and if the first identifier and the second identifier are the same, then the authentication process ends normally, security parameters are generated, and after generating the security parameters, a security mode control process completion message is sent to the core network.
[0010] Furthermore, when the client receives a successful reception message from the core network to the access network indicating that the authentication response message has been received, the authentication process ends normally.
[0011] Furthermore, the first identification information is the key set identifier, and the second identification information is the key set identifier.
[0012] Furthermore, if the determination result is that the authentication process has ended and the security parameter generation has failed, the client sends a rejection message for the security mode control process to the core network.
[0013] The beneficial technical effect of the present invention is that by comparing the consistency between the first identifier content in the authentication request message and the second identifier content in the security mode control flow initiation message, if they are consistent, the authentication process ends, security parameters are generated, and the security mode control flow is entered. This avoids the failure of the security mode control flow due to the authentication process not ending properly, thus improving the robustness of the security mode control flow. Attached Figure Description
[0014] Figure 1 This is a flowchart illustrating the steps of a method for improving the robustness of client-side security processes according to the present invention. Figure 2 This is a schematic diagram of a system for improving the robustness of client-side security processes according to the present invention. Detailed Implementation
[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0016] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.
[0017] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, but this is not intended to limit the scope of the invention.
[0018] See Figure 1 This invention provides a method for improving the robustness of client security processes, comprising: Step A1, the client receives an authentication request message carrying a first identifier from the core network and enters the authentication process; Step A2, the client saves the first identifier and replies with an authentication response message to the core network; Step A3, when the client receives a security mode control process initiation message carrying a second identifier from the core network, it determines whether the authentication process has ended: if the authentication process has ended, proceed to Step A4; if the authentication process has not ended, proceed to Step A5; Step A4, if security parameters have been generated, a security mode control process completion message is sent to the core network; Step A5, when it is determined that the first identifier and the second identifier are the same, the authentication process ends normally, and security parameters are generated. After generating the security parameters, a security mode control process completion message is sent to the core network.
[0019] In this invention, the authentication process is completed by comparing the first identifier content carried in the authentication request message with the second identifier content carried in the security mode control flow initiation message. If they match, the authentication process ends normally, and security parameters are generated to enter the security mode control flow. In this case, the normal termination of the authentication process is the same as the normal termination when the client receives a successful reception message from the core network sent by the access network. This avoids the security mode control flow from failing to terminate normally, thus improving the robustness of the client's security mode process.
[0020] Furthermore, the first identification information is the key set identifier, and the second identification information is the key set identifier.
[0021] The key set identity is KSI.
[0022] In step A1, the authentication process begins, and the core network sends an AUTHENTICATION REQUEST message. The AUTHENTICATION REQUEST carries the KSI (First Identifier). The client receives the AUTHENTICATION REQUEST message and begins the authentication process.
[0023] In step A2, the client identifies and saves the KSI in the authentication request message. It then replies with an uplink authentication response message (AUTHENTICATION RESPONSE) to the core network.
[0024] In step A3, once the core network successfully receives the AUTHENTICATION RESPONSE message, it will generate a security mode control procedure initiation message. This message primarily consists of the SECURITY MODE COMMAND command, used by the client to enter the security mode control procedure. The initiation message carries the KSI, or second identifier. Further, in step A3, when the client receives a success message from the access network confirming the core network's receipt of the AUTHENTICATION RESPONSE message, the authentication process normally terminates.
[0025] Normally, after the authentication process completes successfully, some security parameters required for the safe mode control process are generated. When the client receives the safe mode control process initiation message, it uses these security parameters to run the safe mode control process, thus putting the client into safe mode. In some cases, the client receives the safe mode control process initiation message before the authentication process has finished, and the safe mode control process cannot function properly.
[0026] There are two scenarios where the client fails to properly terminate the authentication process: either the client does not receive a successful reception message from the access network indicating that the core network has acknowledged the AUTHENTICATION RESPONSE, or the client receives a message from the access network instructing the uplink core network to fail to receive the AUTHENTICATION RESPONSE. In both cases, the authentication process does not terminate normally. If a SECURITY MODE COMMAND is received at this point, the security parameters that the security mode control process relies on for this authentication process cannot be generated. This invention compares the KSI carried in the security mode control process initiation message with the KSI carried in the authentication request message. If they match, it indicates that the core network has received the authentication response message and completed the authentication process. Therefore, the client terminates the authentication process normally, generates security parameters based on the KSI, and improves the robustness of the client's security process.
[0027] Furthermore, in step A4, if the security parameter generation fails, a rejection message for the security mode control procedure is sent to the core network.
[0028] In step A5, if the first and second identifier contents are different, the client may run the security mode control procedure using security parameters generated through other means. If the security parameters are successfully generated, a completion message for the security mode control procedure can also be sent to the core network. For example, if the first and second identifier contents are different in step A5, an older set of security parameters will be activated. If the second identifier contents match the older set of security parameters, a completion message for the security mode control procedure will be sent back to the core network. If the second identifier contents do not match the older set of security parameters, a rejection message for the security mode control procedure will be sent to the core network.
[0029] The present invention also provides a client for executing the aforementioned method for improving the robustness of a client security process.
[0030] See Figure 2 The present invention also provides a system for improving the robustness of client security processes, including the aforementioned method for improving client security process robustness, comprising: a core network, configured to execute: sending an authentication request message carrying a first identifier to the client; and, upon receiving an authentication response message, sending a security mode control process initiation message carrying a second identifier to the client; an access network, connected to the core network, configured to enable message transmission between the core network and the client; and a client, connected to the access network, configured to execute: entering the authentication process after receiving the authentication request message; saving the first identifier and replying to the core network with an authentication response message; when receiving the security mode control process initiation message, determining whether the authentication process has ended and forming a determination result; if the determination result indicates that the authentication process has ended and security parameters have been generated, sending a security mode control process completion message to the core network; if the determination result indicates that the authentication process has not ended, and if the first identifier and the second identifier are the same, then the authentication process ends normally, and security parameters are generated, and after generating the security parameters, a security mode control process completion message is sent to the core network.
[0031] In this invention, the authentication process is completed by comparing the first identifier content carried in the authentication request message with the second identifier content carried in the security mode control flow initiation message. If they match, the authentication process ends normally, and security parameters are generated to enter the security mode control flow. In this case, the normal termination of the authentication process is the same as the normal termination when the client receives a successful reception message from the core network sent by the access network. This avoids the security mode control flow from failing to terminate normally, thus improving the robustness of the client's security mode process.
[0032] Furthermore, when the client receives a successful reception message from the core network to the access network indicating that the authentication response message has been received, the authentication process ends normally.
[0033] Furthermore, the first identification information is the key set identifier, and the second identification information is the key set identifier.
[0034] Furthermore, if the determination result is that the authentication process has ended and the security parameter generation has failed, the client sends a rejection message for the security mode control process to the core network.
[0035] The core network, or CN, is used to provide user connectivity, manage users, and carry services. Devices serving as the core network can be Access and Mobility Management Functions (AMFs), but are not limited to AMFs.
[0036] The Radio Access Network (RAN) is primarily responsible for radio resource management, Quality of Service (QoS) management, data compression, and encryption on the air interface side. RAN equipment can include various types of base stations, such as macro base stations, micro base stations (also known as small cells), relay stations, and access points. The names of base station-equipped devices may differ depending on the radio access technology used. For example, in 5G systems, they are called gNBs; in LTE systems, they are called evolved node Bs (eNBs or eNodeBs); and in 3G systems, they are called node Bs, etc.
[0037] The client, also known as the User Equipment (UE), accesses the network through the access network. The UE can be, for example, a handheld terminal, laptop, subscriber unit, cellular phone, smartphone, wireless data card, personal digital assistant (PDA) computer, tablet computer, handheld device, laptop computer, or other device capable of network access. The client UE communicates with the access network using some form of air interface technology.
[0038] The above are merely preferred embodiments of the present invention and are not intended to limit the implementation methods and protection scope of the present invention. Those skilled in the art should recognize that any equivalent substitutions and obvious changes made based on the description and illustrations of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for improving the robustness of client-side security processes, characterized in that, include: Step A1: After receiving the authentication request message carrying the first identifier from the core network, the client enters the authentication process. Step A2: The client saves the first identifier content and replies with an authentication response message to the core network; Step A3: When the client receives the security mode control process initiation message carrying the second identifier content issued by the core network, it determines whether the authentication process has ended. If the authentication process has been completed, proceed to step A4; If the authentication process has not yet ended, proceed to step A5; Step A4: If the security parameters have been generated, send a security mode control process completion message to the core network. Step A5: When it is determined that the content of the first identifier and the content of the second identifier are the same, the authentication process ends normally and security parameters are generated. After generating the security parameters, a security mode control process completion message is sent to the core network. The first identifier is the key set identifier carried in the authentication request information; The second identifier is the key set identifier carried in the initiation message of the security mode control process.
2. The method for improving the robustness of client security processes as described in claim 1, characterized in that, In step A3, when the client receives a success message from the access network indicating that the core network has successfully received the authentication response message, the authentication process ends normally.
3. The method for improving the robustness of client security processes as described in claim 1, characterized in that, In step A4, if the generation of security parameters fails, a rejection message for the security mode control procedure is sent to the core network.
4. A client application, characterized in that, Used to perform a method for improving the robustness of a client security process as described in any one of claims 1-3.
5. A system for improving the robustness of client security processes, characterized in that, A method for improving the robustness of a client security process as described in any one of claims 1-3, comprising: The core network is used to execute: An authentication request message carrying the first identifier content is sent to the client; After receiving the authentication response message, a security mode control process initiation message carrying the second identifier content is sent to the client; An access network, connected to the core network, is used to enable message transmission between the core network and the client; The client, connected to the access network, is used to perform: Upon receiving the authentication request message, the authentication process begins. Save the first identifier content and reply with an authentication response message to the core network; When the initiation message of the security mode control process is received, it is determined whether the authentication process has ended, and a determination result is formed; When the determination result indicates that the authentication process has ended and the security parameters have been generated, a completion message for the security mode control process is sent to the core network. If the determination result indicates that the authentication process has not yet ended, and if the first identifier content and the second identifier content are the same, the authentication process ends normally, and security parameters are generated. After generating the security parameters, a security mode control process completion message is sent to the core network.
6. The system for improving the robustness of client security processes as described in claim 5, characterized in that, When the client receives a success message from the access network indicating that the core network has successfully received the authentication response message, the authentication process ends normally.
7. The system for improving the robustness of client security processes as described in claim 5, characterized in that, When the determination result indicates that the authentication process has ended and the security parameter generation has failed, the client sends a rejection message for the security mode control process to the core network.
Citation Information
Patent Citations
Communication method and related device
CN115250469A
Method for user terminal to operate safety mode
CN1816196A