Key generation method and apparatus

CN116546490BActive Publication Date: 2026-08-11HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-25
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0005]本申请实施例提供一种密钥生成方法及装置,能够解决基于EAP的认证方式中密钥衍生存在冲突的问题

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116546490B_ABST
    Figure CN116546490B_ABST
Patent Text Reader

Abstract

This application provides a key generation method and apparatus that can resolve the problem of key derivation conflicts in different authentication methods based on the Extensible Authentication Protocol (EAP). The method includes: a terminal device requesting registration with a network and receiving an authentication request message, the authentication request message including an EAP request message. After receiving the authentication request message, the terminal device generates a master session key and an extended master session key, and receives an EAP success message. The authentication request message is used to request authentication of the terminal device, and the EAP success message indicates successful authentication of the terminal device. In response to the EAP success message, when the authentication method is EAP tunnel transport layer security, the terminal device generates an authentication key based on the extended master session key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and more particularly to a key generation method and apparatus. Background Technology

[0002] The Extensible Authentication Protocol (EAP) authentication method is a unified authentication architecture that can support a variety of different authentication methods.

[0003] In one EAP-based authentication method, the authentication server is located outside the 3rd Generation Partnership Project (3GPP) network (referred to as an external authentication device). After successful authentication, assuming the authentication credentials originate from the external authentication device, the terminal device generates a subsequent key based on the master session key (MSK). In another EAP-based authentication method where the authentication server is located outside the 3GPP network, the authentication credentials also originate from an external authentication device. After successful authentication, the terminal device generates a subsequent key based on the extended master session key (EMSK).

[0004] Although both authentication methods use external authentication devices for their credentials, one method requires the terminal device to generate a subsequent key based on the MSK, while the other requires it to generate one based on the EMSK. This creates a conflict in the key generation process. However, the industry has yet to provide a solution to this key generation conflict in EAP-based authentication methods. Summary of the Invention

[0005] This application provides a key generation method and apparatus that can solve the problem of key derivation conflicts in EAP-based authentication methods.

[0006] To achieve the above objectives, this application adopts the following technical solution:

[0007] Firstly, a key generation method is provided. The method includes: a terminal device sending a registration request message to an access and mobility management function (AM) network element; receiving an authentication request message from the AM network element; after receiving the authentication request message, the terminal device generating a master session key and an extended master session key; receiving an authentication result message from the AM network element; and, in response to a Scalable Authentication Protocol (SPA) success message, if the authentication method is determined to be SPA tunnel transport layer security, the terminal device generating an authentication key based on the extended master session key.

[0008] The registration request message is used to request registration with the network. The authentication request message is used to request authentication of the terminal device, and includes an Extensible Authentication Protocol (ESP) request message. The authentication result message includes an ESP success message, which indicates successful authentication of the terminal device. The authentication key is used to protect communication between the terminal device and the network.

[0009] Based on the key generation method provided in the first aspect, the terminal device determines the authentication method before generating the authentication key. If the authentication method is the Extensible Authentication Protocol Tunnel Transport Layer Security (EST), the terminal device generates a subsequent key based on the extended master session key. This distinguishes the terminal device from other EAP-supported authentication methods where the terminal device generates a subsequent key based on the MSK when the authentication credentials come from an external authentication device. This resolves the conflict between the terminal device generating a subsequent key based on the MSK when the authentication credentials come from an external authentication device, thereby solving the problem of key derivation conflicts in different EAP-based authentication methods.

[0010] In one possible design approach, determining the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security (ESTL) method may include: the terminal device determining the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security (ESTL) method based on the type of the Extensible Authentication Protocol message.

[0011] For example, a type field of 21 in an Extensible Authentication Protocol (ESP) message can indicate that the current authentication method is Extensible Authentication Protocol Tunnel Transport Layer Security.

[0012] In one possible design approach, the extensible authentication protocol message is obtained by the terminal device from non-access stratum messages.

[0013] For example, an Extensible Authentication Protocol (ESP) message can be an ESP request message or an ESP success message.

[0014] For example, non-access stratum messages can be authentication request messages or authentication result messages. Authentication request messages include Extensible Authentication Protocol Request messages, and authentication result messages include Extensible Authentication Protocol Success messages.

[0015] Thus, the authentication method can be determined based on the type field of the Extensible Authentication Protocol (ESP) success message, and the authentication method can also be determined based on the type field of the ESP request message.

[0016] In one possible design, determining the authentication method as the Extensible Authentication Protocol (ESP) tunneling transport layer security method may include: the terminal device determining the authentication method as the SSP tunneling transport layer security method based on access method information. Here, the access method information indicates that the current access network uses a specific access method. Optionally, the specific access method may implicitly indicate the use of the SSP tunneling transport layer security method as the authentication method, thus confirming the authentication method as the SSP tunneling transport layer security method.

[0017] For example, access methods may include 3GPP access, non-3GPP access, wireless local area network (WLAN) access, and / or non-seamless WLAN offload (NSWO) access, etc.

[0018] In one possible design approach, the access method information can be obtained by the terminal device from radio resource control layer messages or broadcast messages.

[0019] For example, radio resource control layer messages may include access method information, and broadcast messages may include access method information.

[0020] Optionally, the radio resource control (RRC) layer messages may include, but are not limited to, one or more of the following: radio resource control (RRC) setup messages, safe mode completion messages, and RRC reconfiguration messages.

[0021] In one possible design, determining the authentication method as the Extensible Authentication Protocol Tunneling Transport Layer Security (ESLTS) method includes: the terminal device determining the authentication method as the Extensible Authentication Protocol Tunneling Transport Layer Security (ESLTS) method based on the identification information of the authentication credential. The identification information of the authentication credential indicates that the authentication credential is used for the Extensible Authentication Protocol Tunneling Transport Layer Security (ESLTS) method.

[0022] Optionally, the identification information of the authentication credential can be used to identify the authentication credential.

[0023] Optionally, the identification information of the authentication credential can also be used to identify the network element storing the authentication credential, such as the AAA server.

[0024] For example, the identification information of the authentication certificate can be a permanent identifier for the contract.

[0025] In one possible design, the authentication credential's identification information includes domain information, which indicates that the authentication credential originates from an external authentication device within the Extensible Authentication Protocol Tunnel Transport Layer Security (ESL) mechanism.

[0026] In one possible design, the domain information includes a string containing "TTLS", which indicates that the authentication method of the authentication credentials is Extensible Authentication Protocol Tunneling Transport Layer Security.

[0027] For example, domain information may include “xxx.TTLS.yyy.org”, where the string “TTLS” indicates that the authentication method of the authentication credentials is EAP-tunneled transport layer security (EAP-TTLS).

[0028] In one possible design approach, the identification information of the authentication credential can be obtained by the terminal device from the user identification module of the terminal device or the mobile device of the terminal device.

[0029] Thus, if the mobile device stores authentication credentials and their identification information, these credentials can be pre-configured at the factory. If the mobile device provides a user interface, the authentication credentials and their identification information can be flexibly updated.

[0030] Since the user identification module is pluggable, if the authentication credentials and their identification information are stored on the user identification module, the authentication credentials and their identification information can be updated flexibly.

[0031] In one possible design, the process of the terminal device generating a master session key and an extended master session key after receiving an authentication request message may include: if the authentication request message includes an Extensible Authentication Protocol (ESP) request message, and the ESP request message includes a Transport Layer Security (TLS) completion message, then the terminal device generates the master session key and the extended master session key. The TLS completion message indicates that tunnel establishment has been completed.

[0032] In one possible design approach, the generation of the master session key and the extended master session key by the aforementioned terminal device may include: after receiving the authentication result message, the terminal device generates the master session key and the extended master session key.

[0033] In one possible design approach, the generation of the master session key and the extended master session key by the aforementioned terminal device may include: upon receiving a success message from the extensible authentication protocol, the terminal device generates the master session key and the extended master session key.

[0034] It should be noted that the generation of the master session key and the extended master session key by the terminal device can be performed during the process of establishing a secure tunnel between the terminal device and the AUSF network element (if such a secure tunnel establishment process exists), or after the secure tunnel is established and before the terminal device performs the authentication process with the external authentication device, or after the terminal device performs the authentication process with the internal authentication device. This application does not limit the scope of this process.

[0035] In one possible design, in response to the Extensible Authentication Protocol (ESP) success message, when the authentication method is determined to be the SSP Tunnel Transport Layer Security (TTLS) method, the terminal device generates an authentication key based on the extended master session key. This may include: in response to the SSP success message, when the authentication method is determined to be the SSP Tunnel Transport Layer Security (TTLS) method, and when the authentication credentials are determined to originate from an external authentication device, the terminal device determines to use the extended master session key to generate the authentication key. Here, the authentication credentials are those used for the SSP Tunnel Transport Layer Security (TTLS) method.

[0036] In this way, the terminal device can also make a judgment: when the authentication method is EAP-TTLS and the authentication credentials come from an external authentication device, it generates a subsequent key based on the extended master session key EMSK. This is different from other EAP-supported authentication methods where the terminal device generates a subsequent key based on MSK when the authentication credentials come from an external authentication device. This can solve the problem of key derivation conflicts in different EAP-based authentication methods.

[0037] In one possible design, in response to the Extensible Authentication Protocol (ESP) success message, when the authentication method is determined to be the SSP Tunnel Transport Layer Security (TTLS) method, the terminal device generates an authentication key based on the extended master session key. This can include: in response to the SSP success message, when the authentication method is determined to be the SSP Tunnel Transport Layer Security (TTLS) method, and the authentication credentials are determined to originate from an external authentication device, and the access mode information is determined to be an independent non-public network access mode, the terminal device determines to use the extended master session key to generate the authentication key. The access mode information indicates the access mode used by the terminal device when accessing the network.

[0038] For example, access modes may include stand-alone non-public network (SNPN) access mode or public land mobile network (PLMN) access mode.

[0039] In this way, the terminal device can determine whether the subsequent key is generated based on the extended master session key EMSK when the authentication method is EAP-TTLS, the authentication credential comes from an external authentication device, and the access mode information is SNPN. This can be distinguished from other EAP-supported authentication methods where the terminal device generates the subsequent key based on MSK when the authentication credential comes from an external authentication device. This can solve the problem of key derivation conflicts in different EAP-based authentication methods.

[0040] In one possible design approach, the access mode information is obtained by the terminal device from its mobile device. For example, the access mode information may be factory-configured in the mobile device or user-configured.

[0041] In one possible design approach, determining that the authentication credential originates from an external authentication device can include: the terminal device determining that the authentication credential originates from an external authentication device based on the identification information of the authentication credential. The identification information of the authentication credential may include domain information, which indicates that the authentication credential originates from an external authentication device.

[0042] For example, if the domain information of the identification information includes "3GPP" or "3gppnetwork", it means that the authentication credential comes from within 3GPP and from an internal authentication device (such as an AUSF network element); if the domain information of the identification information does not include "3GPP", it can mean that the authentication credential comes from outside 3GPP and from an external authentication device.

[0043] In one possible design approach, the authentication key can be Kausf.

[0044] Secondly, a key generation device is provided. This key generation device includes a transceiver module and a processing module.

[0045] The transceiver module is used to send registration request messages to network elements for access and mobility management functions. These registration request messages are used to request registration with the network.

[0046] The transceiver module is also used to receive authentication request messages from access and mobility management function network elements. These authentication request messages are used to request an authentication key generation device and include Extensible Authentication Protocol (ESP) request messages.

[0047] The processing module is used to generate the master session key and the extended master session key after receiving the authentication request message.

[0048] The transceiver module is also used to receive authentication result messages from access and mobility management function network elements. These authentication result messages include a Scalable Authentication Protocol (SPA) success message, which indicates successful authentication of the key generation device.

[0049] The processing module is also configured to, in response to a successful Extensible Authentication Protocol (ESP) message, generate an authentication key based on the extended master session key, provided that the authentication method is determined to be the SSP tunnel transport layer security method. The authentication key is used to protect communication between the key generation device and the network.

[0050] In one possible design, the processing module is further configured to determine the authentication method as Extensible Authentication Protocol Tunnel Transport Layer Security (EST) based on the type of the Extensible Authentication Protocol message.

[0051] In one possible design approach, the extensible authentication protocol message can be obtained from non-access stratum messages.

[0052] In one possible design, the processing module is further configured to determine the authentication method as Extensible Authentication Protocol (ESP) tunnel transport layer security based on the access method information. The access method information indicates that the current access network uses a specific access method.

[0053] In one possible design approach, access method information is obtained from radio resource control (RRC) messages or broadcast messages.

[0054] In one possible design, the processing module is further configured to determine that the authentication method is the Extensible Authentication Protocol (ESP) Tunnel Transport Layer Security (TTLS) based on the identification information of the authentication credential. The identification information of the authentication credential indicates that it is a credential used for the ESP Tunnel Transport Layer Security (TTLS) method.

[0055] In one possible design, the authentication credential's identification information includes domain information, which indicates that the authentication credential originates from an external authentication device within the Extensible Authentication Protocol Tunnel Transport Layer Security (ESL) mechanism.

[0056] In one possible design, the domain information includes a string containing "TTLS", which indicates that the authentication method of the authentication credentials is Extensible Authentication Protocol Tunneling Transport Layer Security.

[0057] In one possible design, the identification information of the authentication credential is obtained from the user identification module of the key generation device or the mobile device of the key generation device.

[0058] In one possible design, the processing module is further configured to generate a master session key and an extended master session key if the authentication request message includes an Extensible Authentication Protocol Request message, and the Extensible Authentication Protocol Request message includes a Transport Layer Security Complete message. The Transport Layer Security Complete message indicates that tunnel establishment has been completed.

[0059] In one possible design, the processing module is further configured to, in response to a successful Extensible Authentication Protocol (ESP) message, determine, upon determining that the authentication method is Extensible Authentication Protocol Tunnel Transport Layer Security (TTL), and upon determining that the authentication credentials originate from an external authentication device, generate an authentication key using an extended master session key. The authentication credentials are those used for Extensible Authentication Protocol Tunnel Transport Layer Security.

[0060] In one possible design, the processing module is further configured to, in response to a successful Extensible Authentication Protocol (ESP) message, determine, upon determining that the authentication method is the SSP tunnel transport layer security method, that the authentication credentials originate from an external authentication device, and that the access mode information is an independent non-public network access mode, generate an authentication key using an extended master session key. The access mode information can be used to indicate the access mode used by the key generation device when accessing the network.

[0061] In one possible design approach, the access mode information is obtained from the mobile device of the key generation device. For example, the access mode information may be factory-configured in the mobile device of the terminal device or user-configured.

[0062] In one possible design, the processing module is further configured to determine, based on the identification information of the authentication credential, that it originates from an external authentication device. The identification information of the authentication credential includes domain information, which indicates that the authentication credential originates from an external authentication device.

[0063] In one possible design, the authentication key is Kausf.

[0064] It should be noted that the transceiver module described in the second aspect may include a receiving module and a sending module. The receiving module is used to receive data and / or signaling from access and mobility management function network elements and access network equipment; the sending module is used to send data and / or signaling to access and mobility management function network elements and access network equipment. This application does not specifically limit the specific implementation of the transceiver module.

[0065] Optionally, the key generation apparatus described in the second aspect may further include a storage module storing a program or instructions. When the processing module executes the program or instructions, the key generation apparatus described in the second aspect can perform the method described in the first aspect.

[0066] It should be noted that the key generation device described in the second aspect can be a terminal device, or a chip (system) or other component or part that can be set in the terminal device, and this application does not limit it in this regard.

[0067] Furthermore, the technical effects of the key generation device described in the second aspect can be referenced from the technical effects of the key generation method described in any possible implementation of the first aspect, and will not be repeated here.

[0068] Thirdly, a key generation apparatus is provided. The key generation apparatus includes a processor coupled to a memory for storing a computer program.

[0069] The processor is used to execute a computer program stored in memory so that the key generation method as described in any possible implementation of the first aspect is executed.

[0070] In one possible design, the key generation device described in the third aspect may further include a transceiver. This transceiver may be a transceiver circuit or an input / output port. The transceiver can be used for communication between the key generation device and other devices.

[0071] It should be noted that the input port can be used to implement the receiving function involved in the first aspect, and the output port can be used to implement the sending function involved in the first aspect.

[0072] In this application, the key generation device described in the third aspect can be a terminal device, or a chip or chip system disposed inside the terminal device.

[0073] Furthermore, the technical effects of the key generation device described in the third aspect can be referenced from the technical effects of the key generation method described in any implementation of the first aspect, and will not be repeated here.

[0074] Fourthly, a communication system is provided. This communication system includes a key generation device as described in the second aspect and an access and mobility management / security anchor function network element.

[0075] Fifthly, a chip system is provided, comprising logic circuitry and input / output ports. The logic circuitry implements the processing functions described in the first aspect, and the input / output ports implement the transmission and reception functions described in the first aspect. Specifically, the input ports can be used to implement the receiving function described in the first aspect, and the output ports can be used to implement the transmitting function described in the first aspect.

[0076] In one possible design, the chip system also includes a memory for storing program instructions and data that implement the functions involved in the first aspect.

[0077] This chip system can consist of chips or include chips and other discrete components.

[0078] In a sixth aspect, a computer-readable storage medium is provided that stores a computer program or instructions; when the computer program or instructions are run on a computer, the key generation method described in any possible implementation of the first aspect is executed.

[0079] In a seventh aspect, a computer program product is provided, comprising a computer program or instructions that, when executed on a computer, cause the key generation method described in any possible implementation of the first aspect to be executed. Attached Figure Description

[0080] Figure 1 This application provides a schematic diagram of the architecture of a communication system.

[0081] Figure 2 A schematic diagram of an SNPN network architecture provided for an embodiment of this application;

[0082] Figure 3 A schematic diagram illustrating an EAP-based authentication method provided in this application embodiment;

[0083] Figure 4 This is a schematic diagram of another communication system architecture provided in an embodiment of this application;

[0084] Figure 5 A flowchart illustrating a key generation method provided in an embodiment of this application;

[0085] Figure 6 A flowchart illustrating another key generation method provided in this application embodiment;

[0086] Figure 7 This is a schematic diagram of the structure of a key generation device provided in an embodiment of this application;

[0087] Figure 8 This is a schematic diagram of another key generation device provided in an embodiment of this application. Detailed Implementation

[0088] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0089] The technical solutions of this application embodiment can be applied to various communication systems, such as Universal Mobile Telecommunications System (UMTS), Wireless Local Area Network, Wireless Fidelity (Wi-Fi) system, wired network, Vehicle to Everything (V2X) communication system, Device-to-Device (D2D) communication system, Vehicle-to-Everything (V2X) communication system, 4th generation (4G) mobile communication system, such as Long Term Evolution (LTE) system, Worldwide Interoperability for Microwave Access (WiMAX) communication system, 5th generation (5G) mobile communication system, such as New Radio (NR) system, and future communication systems, such as 6th generation (6G) mobile communication system, etc.

[0090] This application will present various aspects, embodiments, or features relating to systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that individual systems may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. Furthermore, combinations of these approaches are also possible.

[0091] Furthermore, in the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as an "example" in this application should not be construed as being better or more advantageous than other embodiments or designs. Rather, the use of the word "example" is intended to present the concept in a specific manner.

[0092] In the embodiments of this application, "of", "corresponding (relevant)" and "corresponding" can sometimes be used interchangeably. It should be noted that when their differences are not emphasized, their meanings are consistent.

[0093] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0094] To facilitate understanding of the embodiments of this application, let's first take... Figure 1 The communication system illustrated herein is used as an example to illustrate a communication system applicable to embodiments of this application. For example, Figure 1 This is a schematic diagram of the architecture of a communication system to which the key generation method provided in this application is applicable.

[0095] like Figure 1 As shown, the communication system includes terminal equipment and may also include core network elements. The number of core network elements can be one or more. Optionally, the communication system may also include external authentication devices. The number of external authentication devices can be one or more. When there are multiple external authentication devices, each external authentication device belongs to a different network.

[0096] The aforementioned terminal equipment refers to a terminal that is connected to the aforementioned communication system and has wireless transceiver capabilities, or a chip or chip system that can be installed in the terminal. This terminal equipment may also be referred to as user equipment (UE), user device, access terminal, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal, terminal unit, terminal station, terminal device, wireless communication equipment, user agent, or user device.

[0097] For example, the terminal device in the embodiments of this application may be a mobile phone, a wireless data card, a personal digital assistant (PDA) computer, a laptop computer, a tablet computer, a drone, a computer with wireless transceiver capabilities, a machine type communication (MTC) terminal, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, an internet of things (IoT) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home (such as a game console, smart TV, smart speaker, smart refrigerator, and fitness equipment), an in-vehicle terminal, or an RSU with terminal functionality. Access terminals can be cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handsets with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, wearable devices, etc.

[0098] For example, the terminal device in this application embodiment can be a delivery terminal in smart logistics (e.g., a device that can monitor the location of cargo vehicles, a device that can monitor the temperature and humidity of cargo, etc.), a wireless terminal in smart agriculture (e.g., a wearable device that can collect relevant data on poultry and livestock, etc.), a wireless terminal in smart buildings (e.g., smart elevators, fire monitoring equipment, and smart meters, etc.), a wireless terminal in smart healthcare (e.g., a wearable device that can monitor the physiological state of humans or animals), a wireless terminal in smart transportation (e.g., smart buses, smart vehicles, shared bicycles, charging pile monitoring equipment, smart traffic lights, smart monitoring, and smart parking equipment, etc.), and a wireless terminal in smart retail (e.g., vending machines, self-checkout machines, and unmanned convenience stores, etc.). For another example, the terminal device in this application can be an on-board module, on-board unit, on-board component, on-board chip, or on-board unit built into a vehicle as one or more components or units. The vehicle can implement the method provided in this application through the built-in on-board module, on-board unit, on-board component, on-board chip, or on-board unit.

[0099] Optional, Figure 1 The communication system shown can be applied to the communication network currently under discussion, or to other networks in the future, etc., and the embodiments of this application do not specifically limit it.

[0100] For example, Figure 1 The communication system shown is applied to an independent non-public network (SNPN) as an example. Figure 2 As shown, an SNPN network may include terminal equipment, core network elements, authentication, authorization, accounting (AAA) server, radio access network (RAN) equipment, and data network (DN).

[0101] The implementation method for terminal devices can be referred to the above. Figure 1 The description of the terminal device is as follows. Optionally, the terminal device may store authentication credentials. When performing two-way authentication with core network elements (such as AMF network elements, AUSF network elements, etc.), the terminal device can use authentication credentials to mutually verify the authenticity of the peer.

[0102] For example, core network elements may include, but are not limited to, one or more of the following: user plane function (UPF) network elements, core access and mobility management function (AMF) / security anchor function (SEAF) network elements, session management function (SMF) network elements, authentication server function (AUSF) network elements, network slice selection function (NSSF) network elements, network exposure function (NEF) network elements, network exposure function repository function (NRF) network elements, policy control function (PCF) network elements, unified data management (UDM) network elements, application function (AF) network elements, and network slice-specific and SNPN authentication and authorization function (NSSAAF) network elements. Specifically, the terminal device accesses the 5G network through the RAN device, and the terminal device communicates with the AMF through the N1 interface (N1 for short); the RAN device can communicate with the AMF through the N2 interface (N2 for short); the RAN device can communicate with the UPF through the N3 interface (N3 for short); the SMF communicates with the UPF through the N4 interface (N4 for short), and the UPF accesses the data network through the N6 interface (N6 for short).

[0103] also, Figure 2The control plane functions shown, such as AUSF, AMF / SEAF, SMF, NSSF, NEF, NRF, PCF, UDM, NSSAAF, or AF, interact using service-oriented interfaces. For example, the service-oriented interface provided by AUSF is Nausf; AMF and SEAF can be co-located, with AMF providing Namf; SMF providing Nsmf; NSSF providing Nnssf; NEF providing Nnef; NRF providing Nnrf; PCF providing Npcf; UDM providing Nudm; NSSAAF providing Nnssaaf; and AF providing Naf.

[0104] The AMF (Access Frame Function) network element is primarily responsible for signaling processing, including functions such as access control, mobility management, attach and detach, and gateway selection. Terminal devices and AMF network elements communicate via N1 Non-Access Stratum (NAS) messages. Communication between the terminal device and the AMF network element is relayed through N2 messages from the access network equipment, and the access network equipment communicates with the AMF network element via N2 messages. AMF and SEAF (Security Attachment Frame) network elements can be co-located. The SEAF network element can provide security anchor functions, such as authenticating terminal devices, which can be a function of the AMF network element.

[0105] SMF network elements are responsible for user plane network element selection, user plane network element redirection, Internet Protocol (IP) address allocation, bearer establishment, modification and release, and quality of service (QoS) control.

[0106] The UPF network element is responsible for forwarding and receiving user data in the terminal equipment. The UPF network element can receive user data from the data network and transmit it to the terminal equipment via the RAN equipment; the UPF network element can also receive user data from the terminal equipment via the RAN equipment and forward it to the data network. The transmission resources and scheduling functions that provide services to the terminal equipment in the UPF network element are managed and controlled by the SMF network element.

[0107] AUSF network elements support both 3GPP and non-3GPP access authentication. NSSF network elements are primarily responsible for network slice selection. They can determine the allowed network slice instances for terminal devices based on slice selection auxiliary information and subscription information, and can be used to verify the authenticity of terminal devices. In internal authentication scenarios, AUSF network elements can authenticate terminal devices.

[0108] The NEF network element primarily supports secure interaction between 3GPP networks and third-party applications. The NRF network element can support network function registration and discovery. The PCF network element is responsible for policy control decisions, providing policy rules for control plane functions, as well as traffic-based billing control functions.

[0109] UDM network elements are primarily responsible for the management of subscription data for terminal devices, including the storage and management of terminal device identifiers and access authorization for terminal devices, and can complete user authentication and authorization.

[0110] AF network elements primarily support interaction with the 3GPP core network to provide services, such as influencing data routing decisions, policy control functions, or providing third-party services to the network side.

[0111] The primary function of the NSSAAF network element is to connect to external AAA servers, acting as a service-based interface (SBI) and AAA interface translator. It serves as an intermediary network element connecting internal 3GPP network elements with external AAA servers. For example, the NSSAAF is pre-configured with a mapping between AAA server address information and domain information. When the NSSAAF receives domain information, it can determine the AAA server based on its address information and then forward the received message to the AAA server. Alternatively, the NSSAAF can request the AAA server's address information from the domain name server (DNS) based on the domain information, obtain the AAA server's address information from the DNS server, and then forward the received message to the AAA server.

[0112] The above Figure 1 The external authentication device shown can be Figure 2 The AAA server shown here refers to an external authentication device, which can be called an AAA server or external authentication server, etc. The external authentication device stores authentication credentials, which can be used to authenticate the identity of terminal devices. It provides authentication, authorization, and accounting functions, processes access requests from terminal devices, provides verification, authorization, and accounting services, manages user access to the network server, and provides services to terminal devices with access rights.

[0113] The aforementioned access network equipment is a device located on the network side of the aforementioned communication system and having wireless transceiver functionality, or a chip or chip system that can be installed in the device. The access network equipment includes, but is not limited to: access points (APs) in wireless fidelity (Wi-Fi) systems, such as home gateways, routers, servers, switches, and bridges; evolved Node Bs (eNBs), radio network controllers (RNCs), Node Bs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved Node Bs, or home Node Bs, HNBs), baseband units (BBUs), wireless relay nodes, wireless backhaul nodes, and transmission and reception points (TRPs or TPs). It can also be 5G, such as gNBs in new radio (NR) systems, or transmission points (TRPs or TPs), one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or network nodes constituting gNBs or transmission points, such as baseband units (BBUs) or distributed units (DMUs). It can be a base station unit (DU), a roadside unit (RSU) with base station functions, or a satellite or other future base station.

[0114] It should be noted that the key generation method provided in this application embodiment can be applied to... Figure 1 , Figure 2 The system shown can be specifically implemented by referring to the following method embodiments, which will not be repeated here.

[0115] It should be noted that the solutions in the embodiments of this application can also be applied to other communication systems, and the corresponding names can be replaced by the names of the corresponding functions in other communication systems.

[0116] It should be understood that Figure 1 This is a simplified diagram for ease of understanding only. The communication system may also include other network devices and / or other terminal devices. Figure 1 It was not drawn in the middle.

[0117] To make the embodiments of this application clearer, the following provides a unified introduction to some of the contents and concepts related to the embodiments of this application.

[0118] The first item is the subscription concealed identifier (SUCI) and the subscription permanent identifier (SUPI):

[0119] For example, the format of SUCI may include network access identifier (NAI) format and international mobile subscriber identity (IMSI) format. For example, the formats of SUPI and SUCI may include NAI format and IMSI format, etc.

[0120] Taking the NAI format as an example, SUCI can include username and domain information. SUPI can also include username and domain information. Optionally, the subscription hidden identifier is obtained by encrypting the subscription permanent identifier, for example, encrypting the username information in SUPI to obtain SUCI. Correspondingly, the subscription permanent identifier is obtained by decrypting the subscription hidden identifier, for example, decrypting SUCI to obtain SUPI.

[0121] Specifically, both the username information included in SUCI and SUPI can identify the terminal device. For example, the username information may include a routing indicator (RID).

[0122] Both the domain information included in SUCI and SUPI can include the user's home network information, which can be used by relevant network elements / functional entities to determine the network where the subscription data corresponding to the username information is located. For example, domain information indicates the identifier of the network to which the authentication device capable of authenticating terminal devices belongs.

[0123] It should be noted that the hidden sign-up identifier can be called the hidden sign-up user identifier or the hidden user identifier, and similarly, the permanent sign-up identifier can be called the permanent sign-up user identifier or the permanent user identifier, etc. This application does not limit the relevant names.

[0124] The second method is EAP-based authentication:

[0125] EAP is a general authentication framework protocol that can carry multiple authentication methods. The two ends of the communication can achieve authentication based on different authentication methods carried by EAP.

[0126] EAP can carry authentication methods including authentication and key agreement (AKA), transport level security (TLS), and TTLS. Different names can be used to represent different authentication methods carried by EAP. For example, if the authentication method carried is TTLS, then EAP-TTLS is used to indicate an authentication method based on EAP and carrying TTLS.

[0127] EAP's communication channels include an authenticator and a peer. The authenticator uses a specific authentication method and the peer's authentication credentials to authenticate the peer.

[0128] The messages sent from the authenticating end to the authenticated end include EAP request messages or EAP success / failure messages. The messages sent from the authenticated end to the authenticating end include EAP response messages. The authenticating end and the authenticated end complete the authentication process through EAP request messages and EAP response messages. The authenticating end then notifies the authenticated end of the authentication result through EAP success / failure messages.

[0129] For different authentication methods, the authenticating end and the authenticated end can exchange multiple rounds of different EAP request messages and EAP authentication response messages. For example, for AKA, the authenticating end usually completes authentication with one round of EAP request and response interaction with the authenticated end. That is, the authenticating end sends an EAP request message to the authenticated end, the authenticated end sends an EAP response message to the authenticating end, and then the authenticating end sends an EAP success message to the authenticated end to notify that the authentication was successful.

[0130] In this application, the authenticated end can be a terminal device, and the authentication end can be an external authentication device.

[0131] The third item is the authentication process based on EAP when the authentication server is located outside the 3GPP network:

[0132] An authentication server located outside the 3GPP network can be called an external authentication device, such as an AAA server. External authentication devices store authentication credentials for the authenticating terminal devices.

[0133] For example, Figure 3 This is a flowchart illustrating an EAP-based authentication method provided in an embodiment of this application.

[0134] like Figure 3 As shown, the key generation method includes the following steps:

[0135] S301, the terminal device sends a registration request message to the AMF network element. Correspondingly, the AMF network element receives the registration request message from the terminal device.

[0136] For example, in Figure 3 In the method shown, the AMF network element can also be a SEAF network element. This application uses the AMF network element as an example for illustration.

[0137] Optionally, the registration request message may include SUCI.

[0138] For example, a registration request message can be used to request registration with the network.

[0139] For example, the network can be an SNPN, and this application does not limit this.

[0140] S302, the AMF network element sends an authentication request message to the AUSF network element. Correspondingly, the AMF network element receives the authentication request message from the AUSF network element.

[0141] Optionally, the authentication request message may include SUCI.

[0142] S303, the AUSF network element sends an authentication request message to the UDM network element. Correspondingly, the UDM network element receives the authentication request message from the AUSF network element.

[0143] For example, an authentication get request message may include SUCI.

[0144] Optionally, AUSF network elements can obtain UDM network elements based on the routing instructions of SUCI.

[0145] S304, UDM network element determines the authentication method.

[0146] For example, authentication methods may include external authentication methods. External authentication methods may refer to using external authentication devices to authenticate the terminal device.

[0147] Optionally, the UDM network element resolves SUPI from SUCI.

[0148] S305, the UDM network element sends an authentication acquisition response message to the AUSF network element. Correspondingly, the AUSF network element receives the authentication acquisition response message from the UDM network element.

[0149] For example, the authentication acquisition response message may include SUPI and authentication method indication information.

[0150] For example, authentication method indication information can be used to indicate external authentication methods.

[0151] S306, the AUSF network element sends an authentication request message to the NSSAAF network element according to the authentication method instruction information. Correspondingly, the NSSAAF network element receives the authentication request message from the AUSF network element.

[0152] For example, an authentication request message can be used to request authentication of a terminal device.

[0153] In some embodiments, the authentication request message may include SUPI.

[0154] Optionally, the AUSF network element selects one NSSAAF from one or more NSSAAFs based on the authentication method indication information and local configuration information, and sends an authentication request message to that NSSAAF.

[0155] For example, the AUSF network element determines that external authentication is required based on the authentication method indication information. The AUSF then obtains the address of the NSSAAF based on the local configuration information, such as the mapping relationship between the SUPI and NSSAAF addresses, and sends an authentication request message to the NSSAAF.

[0156] Optionally, the AUSF network element selects one or more NSSAAFs from the authentication method indication information and the domain information in SUPI, and sends an authentication request message to that NSSAAF.

[0157] For example, the AUSF network element determines that external authentication is required based on the authentication method instruction information. The AUSF then obtains the address of the NSSAAF based on the domain information in the SUPI and sends an authentication request message to the NSSAAF.

[0158] Since external authentication devices are located outside the 3GPP network and use different protocols than 3GPP, NSSAAF network elements are required to perform protocol conversion. For example, for AUSF network elements, NSSAAF network elements provide the underlying protocol conversion from SBI to AAA protocols; for AAA servers, NSSAAF network elements provide the underlying protocol conversion from AAA to SBI protocols.

[0159] S307, the NSSAAF network element sends an EAP response message to the external authentication device. Correspondingly, the external authentication device receives the EAP response message from the NSSAAF network element.

[0160] Optionally, the NSSAAF network element generates an EAP response message based on the authentication request message of S306.

[0161] Optionally, the EAP response message may include SUPI.

[0162] Optionally, the type field of the EAP response message is identity.

[0163] Optionally, the NSSAAF network element can select one or more external authentication devices from the SUPI domain information and trigger EAP-based authentication to that external authentication device.

[0164] S308, External authentication devices perform EAP-based authentication with terminal devices.

[0165] Optionally, depending on the different authentication methods carried on the EAP, the external authentication device and the terminal device can exchange EAP request messages and EAP response messages in multiple rounds.

[0166] Optionally, the EAP request message can be carried within an authentication request message. The EAP response message can be carried within an authentication response message.

[0167] Optionally, during the EAP authentication process between the terminal device and the external authentication device, the external authentication device generates MSK and EMSK, and the terminal device generates MSK and EMSK.

[0168] For example, if the authentication method based on EAP is EAP-TLS, step S308 may include the following steps a-f.

[0169] In step a, the external authentication device sends an EAP request message to the terminal device. This EAP request message is of type EAP-TLS and does not encapsulate a data field. The Extensible Authentication Protocol Request Message may also include a flag field, where the S field can be set to 1 to indicate that the Extensible Authentication Protocol Request Message is a start message.

[0170] Step b: The terminal device sends an EAP response message to the external authentication device. The type of the EAP response message is EAP-TLS. The data field encapsulates one or more TLS records. The TLS records encapsulate a TLS client greeting (client_Hello) handshake message.

[0171] Step c: The external authentication device sends an EAP request message to the terminal device. This EAP request message is of type EAP-TLS, and its data field encapsulates one or more TLS records. Each TLS record encapsulates a TLS server-side greeting (server_Hello) handshake message. Optionally, the TLS record may also encapsulate a TLS certificate message, a TLS server-side key exchange message, a TLS certificate request message, a TLS server-side greeting completion message, and / or a TLS change-cipher_spec message.

[0172] Step d: The terminal device sends an EAP response message to the external authentication device. The type of the EAP response message is EAP-TLS. The data field encapsulates one or more TLS records. The TLS records encapsulate one or more TLS records. Optionally, the TLS records may encapsulate TLS client key exchange messages, TLS change cipher spec messages, TLS finished messages, TLS certificate messages, and / or TLS certificate verify messages.

[0173] In step e, the external authentication device sends an EAP request message to the terminal device. The type of the EAP request message is EAP-TLS, and the data field encapsulates one or more TLS records. Optionally, the TLS record may encapsulate a TLS change cipher_spec message and a TLS finish message.

[0174] Step f: The terminal device sends an EAP response message to the external authentication device. The type of the EAP response message is EAP-TLS and does not encapsulate a data field.

[0175] Among them, EAP request messages and EAP response messages are transparently transmitted by AMF network elements.

[0176] S309, the external authentication device sends an EAP success message and MSK to the NSSAAF network element. Correspondingly, the NSSAAF network element receives the EAP success message and MSK from the external authentication device.

[0177] For example, an EAP success message can be used to indicate that an external authentication device has successfully authenticated the terminal device.

[0178] S310, the NSSAAF network element sends an authentication response message to the AUSF network element. Correspondingly, the AUSF network element receives the authentication response message from the NSSAAF.

[0179] Optionally, the authentication response message may include an EAP success message and an MSK.

[0180] S311, the AUSF network element responds to the EAP success message and generates an authentication key based on the MSK.

[0181] For example, an AUSF network element can generate an authentication key Kausf based on the MSK.

[0182] Optionally, the AUSF network element generates an intermediate key Kseaf based on Kausf.

[0183] S312, the AUSF network element sends an authentication response message to the AMF network element. Correspondingly, the AMF network element receives the authentication response message from the AUSF network element.

[0184] Optionally, the authentication response message may include an EAP success message, a contract permanent identifier, and / or an intermediate key Kseaf.

[0185] S313, the AMF network element sends an N1 message to the terminal device. Correspondingly, the terminal device receives the N1 message from the AMF network element.

[0186] For example, the N1 message may include: an EAP success message.

[0187] S314, in response to the EAP success message, the terminal device generates an authentication key based on the MSK.

[0188] For example, if the terminal device receives an EAP success message, the terminal device infers Kausf based on MSK.

[0189] Optionally, the terminal device derives Kseaf from Kausf.

[0190] In this way, terminal equipment and AMF network elements can use Kseaf for subsequent communication protection.

[0191] Specifically, the terminal device determines to use MSK to generate the authentication key based on the fact that the authentication credentials come from an external authentication device.

[0192] Thus, in Figure 3 In the EAP-based authentication method shown, the authentication credentials come from an external authentication device. The terminal device generates a subsequent key based on the MSK, thereby protecting subsequent communication.

[0193] Fourthly, EAP-TTLS authentication method:

[0194] EAP-TTLS authentication is another authentication method where the authentication server is located outside the 3GPP network. Similarly, the external authentication device stores the authentication credentials of the authentication terminal device. NSSAAF network elements can perform protocol conversion; see reference [link / reference]. Figure 3 The corresponding explanations of the methods shown will not be repeated here.

[0195] The authentication process based on EAP-TTLS authentication consists of two phases. The first phase involves establishing a secure tunnel between the terminal device and the network (e.g., an AUSF network element) using the TLS protocol. The second phase involves an external authentication device authenticating the terminal device based on the secure tunnel. The AUSF network element is located within the 3GPP network and stores the security credentials used to establish the secure tunnel. The external authentication device is located outside the 3GPP network and stores the authentication credentials used to authenticate the terminal device.

[0196] Figure 4 A schematic diagram of the communication system architecture for the EAP-TTLS authentication method provided in this application embodiment.

[0197] like Figure 4 As shown, AUSF network elements can be Figure 4 The TTLS AAA server shown can be used as an external authentication device, such as an AAA / H server.

[0198] The security credentials belong to the TTLS AAA server and can be the TTLS AAA server's certificate. These credentials can be used by end devices to authenticate internal authentication devices (such as the TTLS AAA server) and generate MSK and EMSK.

[0199] Authentication credentials belong to the terminal device and can be a username and / or password, or a certificate from a Certificate Authority (CA) that issued the certificate for the terminal device. Authentication credentials can be used to authenticate terminal devices using external authentication devices (such as AAA / H servers).

[0200] by Figure 4For example, in the EAP-TTLS authentication method, the terminal device and the TTLS AAA server authenticate the terminal device to the TTLS AAA server based on security credentials. Simultaneously, based on the security credentials, an MSK, an EMSK, and keys for protecting the secure tunnel are generated (e.g., client-write-MAC-secret, server-write-MAC-secret, client-write-key, server-write-key, etc.). The secure tunnel is then successfully established using these keys. Within the established secure tunnel, the terminal device authenticates itself with the AAA / H server based on authentication credentials.

[0201] Due to the unique architecture of the communication system corresponding to the EAP-TTLS authentication method, the MSK and EMSK are generated by the TTLS AAA server located within the 3GPP network. Since the MSK may be sent to external network elements for use, while the EMSK cannot be sent externally and is only for internal use, from a security perspective, the TTLS AAA server and the terminal device should generate subsequent keys based on the EMSK. However, in the EAP-TTLS authentication method, the authentication credentials originate from an external authentication device, which conflicts with the requirement of another EAP-based authentication method (where, if the authentication credentials are determined to originate from an external authentication device, the terminal device generates subsequent keys based on the MSK).

[0202] This application provides Figure 3 In the EAP-based authentication method shown, the authentication credentials originate from an external authentication device, and the terminal device generates the subsequent key based on the MSK. In the EAP-TTLS authentication method, while the authentication credentials also originate from an external authentication device, the terminal device generates the subsequent key based on the EMSK. Therefore, a key derivation conflict exists.

[0203] From a higher security perspective, this application provides a key generation method. Before generating the authentication key, the terminal device determines the authentication method. If the authentication method is EAP-TTLS, the subsequent key is generated based on EMSK. This can solve the problem of key derivation conflict between the EAP-TTLS authentication method and another EAP-based authentication method.

[0204] The following will combine Figures 5-6 The key generation method provided in the embodiments of this application will be described in detail. Figures 5-6 by Figure 2The AUSF, AMF, UDM, and NSSAAF examples are used for illustration. The key generation method provided in this application can also be applied to other and future network architectures. The corresponding names can also be replaced by the names of the corresponding functions in other and future network architectures.

[0205] For example, Figure 5 This is a flowchart illustrating a key generation method provided in an embodiment of this application.

[0206] like Figure 5 As shown, the key generation method includes the following steps:

[0207] S501, the terminal device sends a registration request message to the access and mobility management function (AMU) network element. Correspondingly, the AMU network element receives the registration request message from the terminal device.

[0208] For example, a registration request message can be used to request registration with the network.

[0209] For example, the network can be an SNPN, and this application does not limit this.

[0210] For example, the access and mobility management function network element can be an AMF network element or a SEAF network element. This application uses the AMF network element as an example for illustration.

[0211] Optionally, the registration request message may include the Subscription Hidden Identifier (SUCI).

[0212] In step S502, the access and mobility management function (AM) network element sends an authentication request message to the terminal device. Correspondingly, the terminal device receives the authentication request message from the AM network element.

[0213] For example, an authentication request message can be used to request authentication of a terminal device via a network.

[0214] Optionally, the authentication request message may include an Extensible Authentication Protocol (EAP) request message. The AMF network element does not parse the EAP request message, but instead forwards it to the terminal device.

[0215] For example, setting the type field of an Extensible Authentication Protocol Request message to 21 can indicate that the current authentication method is EAP-TTLS.

[0216] Optionally, the Extensible Authentication Protocol Request message may also include a code field, which may be set to 1 to indicate that the current message is an Extensible Authentication Protocol Request message.

[0217] Optionally, the Extensible Authentication Protocol (ESP) request message may include a TLS finish message, which confirms the success of the key exchange and authentication process.

[0218] S503: After receiving the authentication request message, the terminal device generates a master session key and an extended master session key.

[0219] Optionally, the generation of the master session key and extended master session key by the terminal device in S503 above can be performed during the process of establishing a secure tunnel between the terminal device and the AUSF network element (if such a secure tunnel establishment process exists), or after the secure tunnel is established and before the terminal device performs the authentication process with the external authentication device, or after the terminal device performs the authentication process with the internal authentication device. This application does not limit this.

[0220] In one possible design, S503 above may include: when the authentication request message includes an Extensible Authentication Protocol (EAP) request message and the EAP request message includes a Transport Layer Security (TLS) completion message, the terminal device generates a master session key and an extended master session key.

[0221] For example, a terminal device receives an authentication request message from an access and mobility management function network element. This authentication request message includes an EAP request message, and the EAP request message includes a TLS completion message. After parsing the TLS completion message, the terminal device can generate a master session key and an extended master session key.

[0222] Optionally, a Transport Layer Security (TLS) completion message can indicate that tunnel establishment has been completed.

[0223] Optionally, S503 above may include: after receiving the authentication result message (see S504), the terminal device generates MSK and EMSK.

[0224] Optionally, S503 above may include: when the terminal device receives a success message of the extensible authentication protocol (see S504), the terminal device generates MSK and EMSK.

[0225] S504, the access and mobility management function network element sends an authentication result message to the terminal device. Correspondingly, the terminal device receives the authentication result message from the access and mobility management function network element.

[0226] For example, an authentication result message may include a success message for the Extensible Authentication Protocol.

[0227] For example, an Extensible Authentication Protocol (ESP) success message can be used to indicate successful authentication of an end device. For instance, an ESP success message indicates that an external authentication device has successfully authenticated the end device.

[0228] In one possible design approach, Figure 5 The method shown may further include: the AUSF network element sending an authentication response message to the AMF network element. Correspondingly, the AMF network element receives the authentication response message from the AUSF network element. This step can be performed before S504 described above.

[0229] Optionally, the authentication response message may include a successful message for the Extensible Authentication Protocol, and may also include a signed permanent identifier and / or an intermediate key Kseaf.

[0230] For example, an AUSF network element can generate an authentication key Kausf based on EMSK, and an intermediate key Kseaf based on Kausf. Kseaf can be used to derive keys that protect communication between the NAS and the access stratum (AS) layer, such as Knas-enc, Knas-int, Krrc-enc, Krrc-int, Kup-enc, and Kup-int.

[0231] Optionally, if the AUSF network element is Figure 4 As shown in the TTLS AAA server role, the AUSF network element can generate the authentication key Kausf based on EMSK.

[0232] S505, in response to the Extensible Authentication Protocol success message, if the authentication method is determined to be Extensible Authentication Protocol Tunnel Transport Layer Security, the terminal device generates an authentication key based on the extended master session key.

[0233] For example, authentication keys can be used to protect communication between terminal devices and networks.

[0234] Optionally, the authentication key is Kausf.

[0235] Optionally, upon receiving a success message from the extensible authentication protocol, the terminal device generates a master session key and an extended master session key.

[0236] For example, when a terminal device receives a success message from an access and mobility management function network element for the Extensible Authentication Protocol (ESP), the terminal device generates an MSK and an EMSK after parsing the ESP success message.

[0237] In one possible design, in S505 above, in response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be the Extensible Authentication Protocol Tunnel Transport Layer Security (TTL) method, the terminal device generates an authentication key based on the extended master session key. This may include: after parsing the SSP success message, if the terminal device determines that the authentication method is the Extensible Authentication Protocol Tunnel Transport Layer Security (TTL) method, the terminal device generates an authentication key based on the extended master session key.

[0238] Optionally, the terminal device obtains the authentication key by taking the first 256 bits of the EMSK.

[0239] In one possible design approach, in the above S505, determining the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security (ESTL) method may include: the terminal device can determine the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security (ESTL) method based on the type of the Extensible Authentication Protocol message.

[0240] For example, if the type field in the EAP message is 21, it indicates that the current authentication method is EAP-TTLS.

[0241] In some embodiments, the Extensible Authentication Protocol (ESP) message may be obtained by the end device from a Non-Access Stratum (NAS) message.

[0242] For example, the NAS message can be an authentication request message received in step S502, which may include an EAP request message with a type field of 21.

[0243] In other words, the Extensible Authentication Protocol (EAP) message can be an EAP request message, thus the authentication method can be determined based on the type field of the EAP request message.

[0244] For example, the NAS message is the authentication result message received in S505, which may include an EAP success message, in which the type field is 21.

[0245] In other words, the Extensible Authentication Protocol message can be an EAP success message, thus the authentication method can be determined based on the type field of the EAP success message.

[0246] In one possible design approach, in the above S505, determining the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security method may include: the terminal device determining the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security method based on the access method information.

[0247] Optionally, the access method information may indicate the access method by which the terminal device accesses the network.

[0248] Optionally, the access method may include 3GPP access, non-3GPP access, wireless LAN access, and / or gapped WLAN offloading access.

[0249] For example, if the access method information indicates that the terminal device is currently accessing the mobile network through a specific access method, then the terminal device determines that the authentication method is the Extensible Authentication Protocol Tunnel Transport Layer Security (ESL).

[0250] For example, if the access method is a seamd WLAN offloading access, it means that the current authentication method is EAP-TTLS.

[0251] In some embodiments, the access method information is obtained by the terminal device from radio resource control layer messages or broadcast messages.

[0252] For example, the radio resource control layer message or broadcast message may be received by the terminal device from the access network device.

[0253] For example, Radio Resource Control (RRC) messages may include access method information. As another example, broadcast messages may include access method information.

[0254] Optionally, the Radio Resource Control (RRC) messages may include, but are not limited to, one or more of the following: RRC setup messages, security mode complete (SMP) messages, and RRC reconfiguration messages.

[0255] In one possible design approach, in S505 above, determining the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security (ESTTS) method may include: the terminal device can determine the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security (ESTTS) method based on the identification information of the authentication credential.

[0256] Optionally, the identification information of the authentication credential can be used to identify the authentication credential.

[0257] Optionally, the identification information of the authentication credential can also be used to identify the network element storing the authentication credential, such as the AAA server.

[0258] Optionally, the identification information of the authentication credential may indicate that the authentication credential is a credential used for the Extensible Authentication Protocol Tunnel Transport Layer Security method.

[0259] For example, if the identification information of the authentication credential indicates that the authentication credential is a credential for the Extensible Authentication Protocol Tunneling Transport Layer Security (ESLTS) method, then the terminal device determines that the authentication method is the Extensible Authentication Protocol Tunneling Transport Layer Security (ESLTS) method.

[0260] In some embodiments, the identification information of the authentication credential includes domain information, which indicates that the authentication credential originates from an external authentication device in the Extensible Authentication Protocol Tunnel Transport Layer Security (EAS) method.

[0261] For example, the identification information of the authentication certificate can be SUPI.

[0262] For example, the domain information indicates that the authentication credential is a credential used for EAP-TTLS authentication.

[0263] In some embodiments, the domain information includes a string containing the word "TTLS", which indicates that the authentication method of the authentication credential is Extensible Authentication Protocol Tunneling Transport Layer Security.

[0264] For example, domain information may include "xxx.TTLS.yyy.org", where the string "TTLS" indicates that the authentication method of the authentication credentials is EAP-TTLS.

[0265] For example, domain information may include "abc.EAP-TTLS.external.org", where the string "EAP-TTLS" indicates that the authentication method of the authentication credentials is EAP-TTLS, and the string "external" indicates that the authentication server is outside of 3GPP.

[0266] In some embodiments, the identification information of the authentication credential may be obtained by the terminal device from the user identification module of the terminal device or the mobile device of the terminal device.

[0267] For example, the subscriber identity module (SIM) of a terminal device can store authentication credentials and the identification information of the authentication credentials.

[0268] Thus, since the SIM card is removable, if the authentication credentials and their identification information are stored on the SIM, the authentication credentials and their identification information can be updated flexibly.

[0269] For example, mobile equipment (ME) of a terminal device can store authentication credentials and the identification information of the authentication credentials.

[0270] Thus, if ME stores authentication credentials and their identification information, the authentication credentials and their identification information can be pre-configured when the device leaves the factory. If ME provides a user interface, the authentication credentials and their identification information can be flexibly updated.

[0271] It should be noted that determining the authentication method as the Extensible Authentication Protocol (ESP) tunnel transport layer security method can be done by using one or more of the aforementioned Extensible Authentication Protocol messages, access method information, and authentication credential identification information. For specific implementations of determining the authentication method using the aforementioned Extensible Authentication Protocol messages, access method information, and authentication credential identification information, the corresponding implementation methods described above can be combined, which will not be elaborated here.

[0272] The terminal device determines the authentication method based on the existing and available scalable authentication protocol messages, access method information, and authentication credential identification information. It can reuse existing information cells to reduce changes to the communication protocols between the SIM card, ME, and the network side.

[0273] In one possible design, S505 may include: in response to a successful message from the Extensible Authentication Protocol (ESP), if the authentication method is determined to be the SSP tunnel transport layer security method and the authentication credentials are determined to come from an external authentication device, the terminal device determines to generate the authentication key using an extended master session key.

[0274] It should be noted that the specific implementation method for determining the authentication method can be referred to the above description, and will not be repeated here.

[0275] Optionally, the authentication credentials are credentials used for the Extensible Authentication Protocol Tunnel Transport Layer Security method.

[0276] For example, the authentication credential is a credential used to authenticate the terminal device.

[0277] In some embodiments, determining that the authentication credential comes from an external authentication device may include: the terminal device determining that the authentication credential comes from an external authentication device based on the identification information of the authentication credential.

[0278] Optionally, the identification information of the authentication credential may include domain information, which may indicate that the authentication credential originates from an external authentication device.

[0279] Optionally, the authentication credential originating from an external authentication device can be determined based on the domain information in the authentication credential's identification information. If the domain information indicates that the authentication credential originates from an external authentication device, then the authentication credential originates from the external authentication device.

[0280] For example, if the domain information of the identification information includes "3GPP" or "3gppnetwork", it means that the authentication credential comes from within 3GPP and from an internal authentication device (such as an AUSF network element); if the domain information of the identification information does not include "3GPP", it can mean that the authentication credential comes from outside 3GPP and from an external authentication device.

[0281] For example, if the domain information of the identification information includes "aaa", it can indicate that the authentication credential comes from outside 3GPP and from an external authentication device; if the domain information of the identification information does not include "aaa", it indicates that the authentication credential comes from inside 3GPP and from an internal authentication device (such as an AUSF network element).

[0282] For example, the identification information of the authentication certificate can be SUPI.

[0283] In this way, the terminal device can also make a judgment: when the authentication method is EAP-TTLS and the authentication credentials come from an external authentication device, it generates a subsequent key based on the extended master session key EMSK. This is different from other EAP-supported authentication methods where the terminal device generates a subsequent key based on MSK when the authentication credentials come from an external authentication device. This can solve the problem of key derivation conflicts in different EAP-based authentication methods.

[0284] In one possible design, the above S505 may include: in response to the Extensible Authentication Protocol success message, if it is determined that the authentication method is Extensible Authentication Protocol Tunnel Transport Layer Security, the authentication credentials are from an external authentication device, and the access mode information is SNPN access mode, the terminal device determines to generate an authentication key using an extended master session key.

[0285] Optionally, the access mode information is used to indicate the access mode used when the terminal device accesses the network.

[0286] For example, the access mode can include SNPN access mode or PLMN access mode.

[0287] In some embodiments, the access mode information may be obtained by the terminal device from the terminal device's mobile device.

[0288] For example, access mode information can be factory-configured in the mobile device or configured by the user.

[0289] In this way, when the authentication method is EAP-TTLS, the authentication credentials come from an external authentication device, and the access mode information is SNPN, the terminal device can generate a subsequent key based on the extended master session key EMSK. This is different from other EAP-supported authentication methods where the terminal device generates a subsequent key based on MSK when the authentication credentials come from an external authentication device. This can solve the problem of key derivation conflicts in different EAP-based authentication methods.

[0290] based on Figure 5The method shown involves a terminal device requesting registration with the network and receiving an authentication request message, which includes an Extensible Authentication Protocol (ESP) request message. Upon receiving the authentication request message, the terminal device generates a master session key (MSK) and an extended MSK, and receives an ESP success message. The authentication request message is used to request authentication of the terminal device, and the ESP success message indicates successful authentication. In response to the ESP success message, the terminal device can generate an authentication key based on the extended MSK, provided the authentication method is EAP-TTLS. Thus, before generating the authentication key, the terminal device determines the authentication method. If the authentication method is EAP-TTLS, the subsequent key is generated based on the extended MSK, providing higher security and resolving the conflict issue when the authentication credentials originate from an external authentication device, where the terminal device generates a subsequent key based on the MSK.

[0291] For example, Figure 6 This is a flowchart illustrating another key generation method provided in an embodiment of this application. Figure 6 by Figure 3 The method shown is illustrated in detail using an EAP-TTLS authentication scenario as an example.

[0292] like Figure 6 As shown, the key generation method includes the following steps:

[0293] S601, the terminal device sends a registration request message to the access and mobility management function (AMU) network element. Correspondingly, the AMU network element receives the registration request message from the terminal device.

[0294] For the specific implementation of S601, please refer to S501 above, which will not be repeated here.

[0295] S602, the AMF network element sends an authentication request message to the AUSF network element. Correspondingly, the AMF network element receives the authentication request message from the AUSF network element.

[0296] For the specific implementation of S602, please refer to S302 above, which will not be repeated here.

[0297] S603, the AUSF network element sends an authentication request message to the UDM network element. Correspondingly, the UDM network element receives the authentication request message from the AUSF network element.

[0298] For the specific implementation of S603, please refer to S303 above, which will not be repeated here.

[0299] S604, UDM network element determines the authentication method.

[0300] For example, the authentication method may include EAP-TTLS.

[0301] Optionally, the UDM network element resolves SUPI from SUCI.

[0302] S605, the UDM network element sends an authentication acquisition response message to the AUSF network element. Correspondingly, the AUSF network element receives the authentication acquisition response message from the UDM network element.

[0303] For example, the authentication acquisition response message may include SUPI and authentication method indication information.

[0304] For example, authentication method indication information can be used to indicate the EAP-TTLS method.

[0305] S606, the AUSF network element sends an authentication response message to the AMF network element according to the authentication method instruction information. Correspondingly, the AMF network element receives the authentication response message from the AUSF network element.

[0306] Optionally, the authentication response message may include an EAP request message.

[0307] Optionally, the EAP request message can be of type EAP-TTLS and does not encapsulate a data field. The Extensible Authentication Protocol (EAP) request message may also include a flag field, where the S field can be set to 1 to indicate that the EAP request message is a start message.

[0308] S607, the access and mobility management function network element sends an authentication request message to the terminal device. Correspondingly, the terminal device receives the authentication request message from the access and mobility management function network element.

[0309] Optionally, the authentication request message includes the EAP request message.

[0310] It should be noted that in S607, the access and mobility management function network element transparently transmits the EAP request message in S606 to the terminal device. The implementation method of the EAP request message in S607 refers to the corresponding description in S606, and will not be repeated here.

[0311] S608, the terminal device sends an EAP response message to the access and mobility management function (AMU) network element. Correspondingly, the AMU network element receives the EAP response message from the terminal device.

[0312] Optionally, the type of the EAP response message is EAP-TTLS, and the data field encapsulates one or more TLS records, which may encapsulate client greeting (client_Hello) handshake messages.

[0313] S609, the access and mobility management function network element sends an EAP response message to the authentication server function network element. Correspondingly, the authentication server function network element receives the EAP response message from the access and mobility management function network element.

[0314] It should be noted that in S609, the access and mobility management function network element transparently transmits the EAP response message in S608 to the authentication server function network element. The implementation method of the EAP response message in S609 can refer to the corresponding description in S608 above, and will not be repeated here.

[0315] S610, the authentication server function network element sends an EAP request message to the access and mobility management function network element. Correspondingly, the access and mobility management function network element receives the EAP request message from the authentication server function network element.

[0316] Optionally, the type of the EAP request message is EAP-TTLS, and the data field encapsulates one or more TLS records, which may encapsulate server-side greeting (server_Hello) handshake messages.

[0317] Optionally, the TLS record may also encapsulate server certificate messages, server key exchange messages, and / or server hello done messages.

[0318] S611, the access and mobility management function (AMU) network element sends an EAP request message to the terminal device. Correspondingly, the terminal device receives the EAP request message from the AMU network element.

[0319] It should be noted that in S611, the access and mobility management function network element transmits the EAP request message in S610 to the terminal device. The implementation method of the EAP request message in S611 can refer to the corresponding description in S610 above, and will not be repeated here.

[0320] In some embodiments, the access and mobility management function network element can send a key identifier to the terminal device.

[0321] S612, Terminal device verifies server certificate.

[0322] S613, the terminal device sends an EAP response message to the access and mobility management function (AMU) network element. Correspondingly, the AMU network element receives the EAP response message from the terminal device.

[0323] Optionally, the type of the EAP response message is EAP-TTLS, and the data field encapsulates one or more TLS records.

[0324] Optionally, the TLS record may encapsulate client key exchange messages, change cipher spec messages, and / or TLS finish messages.

[0325] S614, the access and mobility management function network element sends an EAP response message to the authentication server function network element. Correspondingly, the authentication server function network element receives the EAP response message from the access and mobility management function network element.

[0326] It should be noted that in S614, the access and mobility management function network element transparently transmits the EAP response message in S613 to the authentication server function network element. The implementation method of the EAP response message in S614 can refer to the corresponding description in S613 above, and will not be repeated here.

[0327] S615, the authentication server function network element skips the authentication of the terminal device (UE).

[0328] S616, the authentication server function network element sends an EAP request message to the access and mobility management function network element. Correspondingly, the access and mobility management function network element receives the EAP request message from the authentication server function network element.

[0329] Optionally, the type of the EAP request message is EAP-TTLS, and the data field encapsulates one or more TLS records.

[0330] Optionally, the TLS record may encapsulate a change cipher_spec message and / or a TLS finish message.

[0331] S617, the access and mobility management function network element sends an authentication request message to the terminal device. Correspondingly, the terminal device receives the authentication request message from the access and mobility management function network element.

[0332] For the specific implementation of S617, please refer to S502 above, which will not be repeated here.

[0333] Optionally, the authentication request message may include an Extensible Authentication Protocol Request message.

[0334] It should be noted that in S617, the access and mobility management function network element transmits the EAP request message in S616 to the terminal device. The implementation of the extensible authentication protocol request message in S617 can be referred to the corresponding description in S616 above, and will not be repeated here.

[0335] In S606 to S607 above, the terminal equipment and the AUSF network element establish a secure tunnel by sending EAP request messages and EAP response messages, including TLS messages, to each other based on the TLS protocol.

[0336] For example, this application does not limit the TLS protocol, which may include TLS 1.1, TLS 1.2, and / or TLS 1.3. Specifically, TLS 1.1 can be referenced in RFC 4346, TLS 1.2 in RFC 5246, and TLS 1.3 in RFC 8446.

[0337] S618, the terminal device generates the master session key and the extended master session key.

[0338] For details on the specific implementation of S618, please refer to S503 above, which will not be repeated here.

[0339] In one possible design, S618 above may include: when the authentication request message includes an EAP request message, and the EAP request message includes a TLS completion message, the terminal device generates a master session key and an extended master session key. For specific implementation details, please refer to the corresponding description in S503 above; further elaboration will not be repeated here.

[0340] For example, after receiving the authentication request message in S617 above, the terminal device can generate a master session key and an extended master session key.

[0341] In one possible design, S618 may include: after receiving the authentication result message (see S622 below), the terminal device generates a master session key and an extended master session key.

[0342] In one possible design, S618 above may include: upon receiving a successful message from the Extensible Authentication Protocol (which is included in the authentication result message in S622 below), the terminal device generates a master session key and an extended master session key.

[0343] For example, after receiving the authentication result message in S622 below, the terminal device can generate a master session key and an extended master session key.

[0344] It should be noted that the generation of the master session key and the extended master session key by the terminal device in S618 can be performed at any time from the time the authentication request message is received in S617 to the time the authentication key is generated in S623 below, and this application does not limit this.

[0345] S619, AUSF network elements generate master session keys and extended master session keys.

[0346] Optionally, the AUSF network element can generate a master session key and an extended master session key after the mobile network and terminal equipment have completed tunnel establishment.

[0347] Optionally, if the AUSF network element is a TTLS AAA server, the AUSF network element can generate MSK and EMSK.

[0348] Optionally, the AUSF network element determines its role as a TTLS AAA server based on the authentication method indication information.

[0349] It should be noted that the AUSF network element generating the master session key and the extended master session key in S619 above can be performed at any time from receiving the EAP response message in S614 to sending the authentication response message in S621 below, and this application does not limit this.

[0350] S620: The terminal device performs the authentication process with the external authentication device.

[0351] For example, the terminal device and the AUSF network element can perform the authentication process based on AVP. Optionally, the authentication process can be based on EAP, the challenge-handshake authentication protocol (CHAP), the Microsoft challenge-handshake authentication protocol (MS-CHAP), the Microsoft challenge-handshake authentication protocol-version 2 (MS-CHAP-V2), and / or the password authentication protocol (PAP). For details, please refer to RFC 5281.

[0352] For example, in the above S620, the terminal device and the AUSF network element complete the establishment of a secure tunnel. It is assumed that the communication between AUSF and NSSAAF, and between NSSAAF and the external authentication device, has end-to-end security protection. In the secure tunnel UE-AUSF-NSSAAF-AAA (external authentication device), the terminal device and the external authentication device perform the authentication process.

[0353] S621, the AUSF network element sends an authentication response message to the AMF network element. Correspondingly, the AMF network element receives the authentication response message from the AUSF network element.

[0354] Optionally, the authentication response message may include a successful message for the Extensible Authentication Protocol, and may also include a signed permanent identifier and / or an intermediate key Kseaf.

[0355] For example, the AUSF network element generates an authentication key Kausf based on EMSK, and generates an intermediate key Kseaf based on Kausf.

[0356] Optionally, if the AUSF network element is a TTLS AAA server, the AUSF network element generates the authentication key Kausf based on EMSK.

[0357] Optionally, the AUSF network element determines its role as a TTLS AAA server based on the authentication method indication information.

[0358] S622, the access and mobility management function network element sends an authentication result message to the terminal device. Correspondingly, the terminal device receives the authentication result message from the access and mobility management function network element.

[0359] For example, the authentication result message may include an Extensible Authentication Protocol success message.

[0360] For details on the specific implementation of S622, please refer to S504 above, which will not be repeated here.

[0361] S623, in response to the Extensible Authentication Protocol success message, if the authentication method is determined to be Extensible Authentication Protocol Tunnel Transport Layer Security, the terminal device generates an authentication key based on the extended master session key.

[0362] For details on the specific implementation of S623, please refer to S505 above, which will not be repeated here.

[0363] based on Figure 6 The method shown allows the terminal device to determine the authentication method before generating the authentication key. If the authentication method is EAP-TTLS, the subsequent key is generated based on the extended master session key, which not only provides higher security but also resolves the conflict with the terminal device generating the subsequent key based on the MSK when the authentication credentials come from an external authentication device.

[0364] In this application, unless otherwise specified, the same or similar parts between the various embodiments can be referred to each other. In the various embodiments of this application, and in the various implementation methods / methods / implementations within each embodiment, unless otherwise specified or logically conflicting, the terminology and / or descriptions between different embodiments and between the various implementation methods / methods / implementations within each embodiment are consistent and can be mutually referenced. The technical features in different embodiments and the various implementation methods / methods / implementations within each embodiment can be combined according to their inherent logical relationships to form new embodiments, implementation methods, methods, or implementation approaches. The embodiments described below do not constitute a limitation on the scope of protection of this application.

[0365] The above combination Figures 5-6 The key generation method provided in the embodiments of this application is described in detail below. Figures 7-8 This application provides a detailed description of the key generation apparatus provided in its embodiments.

[0366] Figure 7 This is a schematic diagram of a key generation apparatus that can be used to execute the key generation method provided in the embodiments of this application. The key generation apparatus 700 can be a key generation device, or it can be a chip or other component with corresponding functions applied in a key generation apparatus. Figure 7As shown, the key generation device 700 may include a processor 701. Optionally, the key generation device 700 may also include one or more of a memory 702 and a transceiver 703. The processor 701 may be coupled to one or more of the memory 702 and the transceiver 703, for example, via a communication bus; the processor 701 may also be used independently.

[0367] The following is combined Figure 7 A detailed description of each component of the key generation device 700 is provided below:

[0368] Processor 701 is the control center of key generation device 700. It can be a single processor or a collective term for multiple processing elements. For example, processor 701 can be one or more central processing units (CPUs), application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).

[0369] The processor 701 can perform various functions of the key generation device 700 by running or executing software programs stored in the memory 702 and calling data stored in the memory 702.

[0370] In a specific implementation, as one example, the processor 701 may include one or more CPUs, for example... Figure 7 CPU0 and CPU1 are shown in the diagram.

[0371] In a specific implementation, as one example, the key generation device 700 may also include multiple processors, for example... Figure 7 The processors 701 and 704 are shown. Each of these processors can be a single-core processor (CPU) or a multi-core processor (CPU). Here, "processor" can refer to one or more communication devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).

[0372] Optionally, the memory 702 may be a read-only memory (ROM) or other type of static storage communication device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage communication device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage communication devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. The memory 702 may be integrated with the processor 701 or exist independently, and may be connected via the input / output port of the key generation device 700. Figure 7 (Not shown in the image) is coupled to the processor 701, but this embodiment does not specifically limit this.

[0373] For example, the input port can be used to implement the receiving function performed by the terminal device in any of the above method embodiments, and the output port can be used to implement the sending function performed by the terminal device in any of the above method embodiments.

[0374] The memory 702 can be used to store software programs that execute the scheme of this application, and the execution is controlled by the processor 701. Specific implementation methods described above can be found in the following method embodiments, which will not be repeated here.

[0375] Optionally, transceiver 703 is used for communication with other devices. For example, transceiver 703 can be used to communicate with AMF network elements. Furthermore, transceiver 703 may include a receiver and a transmitter. Figure 7 (Not shown separately). The receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function. The transceiver 703 can be integrated with the processor 701 or exist independently, and is connected to the input / output port of the key generation device 700 (…). Figure 7 (Not shown in the image) is coupled to the processor 701, but this application embodiment does not specifically limit this.

[0376] It should be noted that, Figure 7 The structure of the key generation device 700 shown does not constitute a limitation on the key generation device. An actual key generation device may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0377] Among them, the above Figures 5-6 The operation of the key generation device can be controlled by Figure 7 The processor 701 in the key generation device 700 shown calls the application code stored in the memory 702 to instruct the key generation device to execute.

[0378] It should be noted that all relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.

[0379] Figure 8 This is a schematic diagram of another key generation device provided in an embodiment of this application. For ease of explanation, Figure 8 Only the main components of the key generation device are shown.

[0380] The key generation device 800 includes a transceiver module 801 and a processing module 802. The key generation device 800 can be the terminal device in the aforementioned method embodiments.

[0381] It should be noted that the transceiver module 801 may include a receiving module and a sending module. The receiving module is used to receive data and / or signaling from access and mobility management function network elements and / or access network equipment; the sending module is used to send data and / or signaling to access and mobility management function network elements and / or access network equipment. This application does not specifically limit the specific implementation of the transceiver module 801.

[0382] The key generation device 800 may also include a storage module ( Figure 8 (Not shown in the image), this storage module stores programs or instructions. When the processing module 802 executes the program or instructions, it enables the key generation device 800 to perform operations. Figures 5-6 The function of the terminal device in the key generation method shown.

[0383] In this embodiment, the key generation device 800 is presented in an integrated manner, divided into various functional modules. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the key generation device 800 can employ... Figure 7 The key generation device 700 shown is in the form of the key generation device.

[0384] for example, Figure 7 The processor 701 in the key generation device 700 shown can execute the key generation method in the above method embodiment by calling computer execution instructions stored in the memory 702.

[0385] Specifically, Figure 8 The functions / implementation process of the transceiver module 801 and the processing module 802 can be obtained through... Figure 7 The processor 701 in the key generation device 700 shown calls computer execution instructions stored in the memory 702 to implement the key generation. Figure 8 The function / implementation process of the transceiver module 801 can be obtained through Figure 7 This is achieved by the transceiver 703 in the key generation device 700 shown.

[0386] Since the key generation device 800 provided in this embodiment can execute the above key generation method, the technical effects it can achieve can be referred to the above method embodiment, and will not be repeated here.

[0387] In one possible design scheme, Figure 8 The key generation device 800 shown is applicable to Figure 1 In the communication system shown, the execution Figure 5 and Figure 6 The function of the terminal device in the key generation method shown.

[0388] The transceiver module 801 is used to send registration request messages to the access and mobility management function network elements. These registration request messages are used to request registration with the network.

[0389] The transceiver module 801 is also used to receive authentication request messages from access and mobility management function network elements. These authentication request messages request the authentication key generation device 800 and include extensible authentication protocol request messages.

[0390] After receiving the authentication request message, the processing module 802 generates the master session key and the extended master session key.

[0391] The transceiver module 801 is also used to receive authentication result messages from access and mobility management function network elements. These authentication result messages include a Scalable Authentication Protocol (SAIP) success message, which indicates successful authentication of the key generation device 800.

[0392] In response to the Extensible Authentication Protocol (ESP) success message, and if the authentication method is determined to be the SSP tunnel transport layer security method, the processing module 802 further generates an authentication key based on the extended master session key. The authentication key is used to protect the communication between the key generation device 800 and the network.

[0393] In one possible design, the processing module 802 is further configured to determine the authentication method as Extensible Authentication Protocol Tunnel Transport Layer Security based on the type of the Extensible Authentication Protocol request message.

[0394] In one possible design approach, the Extensible Authentication Protocol Request message can be obtained from a non-access stratum message.

[0395] In one possible design, the processing module 802 is further configured to determine the authentication method as Extensible Authentication Protocol (ESP) tunnel transport layer security based on the access method information. The access method information indicates that the current access network uses a specific access method.

[0396] In one possible design approach, access method information is obtained from radio resource control (RRC) messages or broadcast messages.

[0397] In one possible design, the processing module 802 is further configured to determine that the authentication method is the Extensible Authentication Protocol Tunneling Transport Layer Security (ESTTS) method based on the identification information of the authentication credential. The identification information of the authentication credential indicates that the authentication credential is used for the SSTTS method.

[0398] In one possible design, the authentication credential's identification information includes domain information, which indicates that the authentication credential originates from an external authentication device within the Extensible Authentication Protocol Tunnel Transport Layer Security (ESL) mechanism.

[0399] In one possible design, the domain information includes a string containing the word "TTLS", which indicates that the authentication method of the authentication credentials is Extensible Authentication Protocol Tunneling Transport Layer Security.

[0400] In one possible design, the identification information of the authentication credential is obtained from the user identification module of the key generation device 800 or the mobile device of the key generation device 800.

[0401] In one possible design, the processing module 802 is further configured to determine, based on the mode information, that the authentication method is the Extensible Authentication Protocol (EXPCP) tunnel transport layer security method. The mode information indicates that the current access network access mode is an independent, non-public network access mode.

[0402] In one possible design, the pattern information is obtained from the mobile device of the key generation device 800.

[0403] In one possible design, if the authentication request message includes an Extensible Authentication Protocol Request message, and the Extensible Authentication Protocol Request message includes a Transport Layer Security Complete message, the processing module 802 is further configured to generate a master session key and an extended master session key. The Transport Layer Security Complete message indicates that tunnel establishment has been completed.

[0404] In one possible design, in response to a successful Extensible Authentication Protocol (ESP) message, and after determining that the authentication method is the SSP Tunnel Transport Layer Security (TTLS) method and that the authentication credentials originate from an external authentication device, the processing module 802 is further configured to determine that an authentication key is generated using an extended master session key. The authentication credentials are those used for the SSP Tunnel Transport Layer Security (TTLS) method.

[0405] In one possible design, in response to a successful Extensible Authentication Protocol (ESP) message, and after determining that the authentication method is the SSP tunnel transport layer security method, that the authentication credentials originate from an external authentication device, and that the access mode information is an independent non-public network access mode, the processing module 802 is further configured to determine that an authentication key is generated using an extended master session key. The access mode information indicates the access mode used by the key generation device 800 when accessing the network.

[0406] In one possible design, the access mode information is obtained from the mobile device of the key generation device 800.

[0407] In one possible design, the processing module 802 is further configured to determine, based on the identification information of the authentication credential, that the authentication credential originates from an external authentication device. The identification information of the authentication credential includes domain information, which indicates that the authentication credential originates from an external authentication device.

[0408] In one possible design, the authentication key is Kausf.

[0409] Optionally, the storage module stores a program or instructions. When the processing module 802 executes the program or instructions, the key generation device 800 can perform the above-mentioned... Figures 5-6 The key generation method described above.

[0410] It should be noted that the key generation device 800 may be a chip (system) or other component or assembly that can be set in the terminal device, and this application does not limit it.

[0411] In addition, the technical effectiveness of the key generation device 800 can be referenced. Figure 5 and Figure 6 The technical effects of the key generation method shown will not be elaborated here.

[0412] This application provides a communication system. The communication system may include a terminal device and an AMF network element, and may also include access network equipment. The terminal device is used to execute the actions of the terminal device in the above method embodiments; the specific execution methods and processes can be referred to the above method embodiments, and will not be repeated here.

[0413] This application provides a chip system including logic circuits and input / output ports. The logic circuits can be used to implement the processing functions involved in the key generation method provided in this application, and the input / output ports can be used for the transmit / receive functions involved in the key generation method provided in this application.

[0414] For example, the input port can be used to implement the receiving function of the key generation method provided in the embodiments of this application, and the output port can be used to implement the sending function of the key generation method provided in the embodiments of this application.

[0415] For example, the processor in the key generation device 700 can be used to perform, for example, but not limited to, baseband-related processing, and the transceiver in the key generation device 700 can be used to perform, for example, but not limited to, radio frequency transceiver. The aforementioned devices can be disposed on separate chips, or at least partially or entirely on the same chip. For example, the processor can be further divided into an analog baseband processor and a digital baseband processor. The analog baseband processor can be integrated with the transceiver on the same chip, while the digital baseband processor can be disposed on a separate chip. With the continuous development of integrated circuit technology, more and more devices can be integrated on the same chip. For example, a digital baseband processor can be integrated with multiple application processors (e.g., but not limited to, graphics processors, multimedia processors, etc.) on the same chip. Such a chip can be called a system-on-a-chip (SoC). Whether the various devices are disposed independently on different chips or integrated on one or more chips often depends on the specific needs of the product design. This application does not limit the specific implementation of the aforementioned devices.

[0416] In one possible design, the chip system further includes a memory for storing program instructions and data that implement the functions involved in the key generation method provided in the embodiments of this application.

[0417] This chip system can consist of chips or include chips and other discrete components.

[0418] This application provides a computer-readable storage medium that stores a computer program or instructions. When the computer program or instructions are run on a computer, the key generation method provided in this application is executed.

[0419] This application provides a computer program product, which includes a computer program or instructions that, when run on a computer, cause the key generation method provided in this application to be executed.

[0420] It should be understood that the processor in the embodiments of this application can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0421] It should also be understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0422] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0423] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0424] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.

[0425] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0426] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0427] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0428] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0429] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0430] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0431] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0432] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A key generation method, characterized in that, include: The terminal device sends a registration request message to the access and mobility management function network element; wherein, the registration request message is used to request registration with the network; The terminal device receives an authentication request message from the access and mobility management function network element; wherein, the authentication request message is used to request authentication of the terminal device, and the authentication request message includes an extensible authentication protocol request message; Upon receiving the authentication request message, the terminal device generates a master session key and an extended master session key; The terminal device receives an authentication result message from the access and mobility management function network element; wherein, the authentication result message includes an extensible authentication protocol success message, which indicates that the terminal device has been successfully authenticated; In response to the Extensible Authentication Protocol (ESP) success message, and if the authentication method is determined to be the Extensible Authentication Protocol Tunnel Transport Layer Security (TETL) method, the terminal device generates an authentication key based on the extended master session key; wherein the authentication key is used to protect the communication between the terminal device and the network.

2. The key generation method according to claim 1, characterized in that, The authentication method is determined to be the Extensible Authentication Protocol (ESP) tunnel transport layer security method, including: The terminal device determines the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security method based on the type of the Extensible Authentication Protocol message.

3. The key generation method according to claim 2, characterized in that, The Extensible Authentication Protocol (ESP) message is obtained by the terminal device from non-access stratum messages.

4. The key generation method according to claim 1, characterized in that, The authentication method is determined to be the Extensible Authentication Protocol (ESP) tunnel transport layer security method, including: The terminal device determines the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security method based on the access method information; wherein, the access method information indicates that the current access method to the network is a specific access method.

5. The key generation method according to claim 4, characterized in that, The access method information is obtained by the terminal device from radio resource control layer messages or broadcast messages.

6. The key generation method according to claim 1, characterized in that, The authentication method is determined to be the Extensible Authentication Protocol (ESP) tunnel transport layer security method, including: The terminal device determines the authentication method as the Extensible Authentication Protocol Tunnel Transport Layer Security (ESLTS) based on the identification information of the authentication credential; wherein the identification information of the authentication credential indicates that the authentication credential is a credential used for the SRLTS.

7. The key generation method according to claim 6, characterized in that, The authentication credential's identification information includes domain information, which indicates that the authentication credential originates from an external authentication device in the Extensible Authentication Protocol Tunnel Transport Layer Security method.

8. The key generation method according to claim 7, characterized in that, The domain information includes a string containing "TTLS", which indicates that the authentication method of the authentication credential is the Extensible Authentication Protocol Tunnel Transport Layer Security (ESL).

9. The key generation method according to any one of claims 6-8, characterized in that, The authentication credential's identification information is obtained by the terminal device from the terminal device's user identification module or the terminal device's mobile device.

10. The key generation method according to any one of claims 1-8, characterized in that, Upon receiving the authentication request message, the terminal device generates a master session key and an extended master session key, including: When the authentication request message includes the Extensible Authentication Protocol Request message, and the Extensible Authentication Protocol Request message includes a Transport Layer Security Complete message, the terminal device generates the master session key and the extended master session key; wherein, the Transport Layer Security Complete message indicates that tunnel establishment has been completed.

11. The key generation method according to claim 9, characterized in that, Upon receiving the authentication request message, the terminal device generates a master session key and an extended master session key, including: When the authentication request message includes the Extensible Authentication Protocol Request message, and the Extensible Authentication Protocol Request message includes a Transport Layer Security Complete message, the terminal device generates the master session key and the extended master session key; wherein, the Transport Layer Security Complete message indicates that tunnel establishment has been completed.

12. The key generation method according to any one of claims 1-8 and 11, characterized in that, In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be Extensible Authentication Protocol Tunnel Transport Layer Security (ETL), the terminal device generates an authentication key based on the extended master session key, including: In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be the SSP Tunnel Transport Layer Security (TTLS) method and the authentication credentials are determined to originate from an external authentication device, the terminal device determines to generate the authentication key using the extended master session key; wherein the authentication credentials are credentials used for the SSP Tunnel Transport Layer Security (TTLS) method.

13. The key generation method according to claim 9, characterized in that, In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be Extensible Authentication Protocol Tunnel Transport Layer Security (ETL), the terminal device generates an authentication key based on the extended master session key, including: In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be the SSP Tunnel Transport Layer Security (TTLS) method and the authentication credential is determined to originate from an external authentication device, the terminal device determines to generate the authentication key using the extended master session key; wherein the authentication credential is a credential used for the SSP Tunnel Transport Layer Security (TTLS) method.

14. The key generation method according to claim 10, characterized in that, In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be Extensible Authentication Protocol Tunnel Transport Layer Security (ETL), the terminal device generates an authentication key based on the extended master session key, including: In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be the SSP Tunnel Transport Layer Security (TTLS) method and the authentication credentials are determined to originate from an external authentication device, the terminal device determines to generate the authentication key using the extended master session key; wherein the authentication credentials are credentials used for the SSP Tunnel Transport Layer Security (TTLS) method.

15. The key generation method according to any one of claims 1-8 and 11, characterized in that, In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be Extensible Authentication Protocol Tunnel Transport Layer Security (ETL), the terminal device generates an authentication key based on the extended master session key, including: In response to the success message of the Extensible Authentication Protocol (ESP), if it is determined that the authentication method is the SSP tunnel transport layer security method, the authentication credentials are from an external authentication device, and the access mode information is an independent non-public network access mode, the terminal device determines to generate the authentication key using the extended master session key; wherein, the access mode information is used to indicate the access mode used by the terminal device when accessing the network.

16. The key generation method according to claim 9, characterized in that, In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be Extensible Authentication Protocol Tunnel Transport Layer Security (ETL), the terminal device generates an authentication key based on the extended master session key, including: In response to the Extensible Authentication Protocol (ESP) success message, if it is determined that the authentication method is the SSP tunnel transport layer security method, the authentication credential comes from an external authentication device, and the access mode information is an independent non-public network access mode, the terminal device determines to generate the authentication key using the extended master session key; wherein, the access mode information is used to indicate the access mode used by the terminal device when accessing the network.

17. The key generation method according to claim 10, characterized in that, In response to the Extensible Authentication Protocol (ESP) success message, if the authentication method is determined to be Extensible Authentication Protocol Tunnel Transport Layer Security (ETL), the terminal device generates an authentication key based on the extended master session key, including: In response to the success message of the Extensible Authentication Protocol (ESP), if it is determined that the authentication method is the SSP tunnel transport layer security method, the authentication credentials are from an external authentication device, and the access mode information is an independent non-public network access mode, the terminal device determines to generate the authentication key using the extended master session key; wherein, the access mode information is used to indicate the access mode used by the terminal device when accessing the network.

18. The key generation method according to claim 15, characterized in that, The access mode information is obtained by the terminal device from its mobile device.

19. The key generation method according to claim 16 or 17, characterized in that, The access mode information is obtained by the terminal device from its mobile device.

20. The key generation method according to claim 12, characterized in that, The determination that the authentication credentials originate from an external authentication device includes: The terminal device determines that the authentication credential originates from the external authentication device based on the identification information of the authentication credential; wherein, the identification information of the authentication credential includes domain information, and the domain information indicates that the authentication credential originates from the external authentication device.

21. The key generation method according to any one of claims 13-14 and 16-18, characterized in that, The determination that the authentication credentials originate from an external authentication device includes: The terminal device determines that the authentication credential originates from the external authentication device based on the identification information of the authentication credential; wherein, the identification information of the authentication credential includes domain information, and the domain information indicates that the authentication credential originates from the external authentication device.

22. The key generation method according to claim 15, characterized in that, The determination that the authentication credentials originate from an external authentication device includes: The terminal device determines that the authentication credential originates from the external authentication device based on the identification information of the authentication credential; wherein, the identification information of the authentication credential includes domain information, and the domain information indicates that the authentication credential originates from the external authentication device.

23. The key generation method according to claim 19, characterized in that, The determination that the authentication credentials originate from an external authentication device includes: The terminal device determines that the authentication credential originates from the external authentication device based on the identification information of the authentication credential; wherein, the identification information of the authentication credential includes domain information, and the domain information indicates that the authentication credential originates from the external authentication device.

24. The key generation method according to any one of claims 1-8, 11, 13-14, 16-18, 20, and 22-23, characterized in that, The authentication key is Kausf.

25. The key generation method according to claim 9, characterized in that, The authentication key is Kausf.

26. The key generation method according to claim 10, characterized in that, The authentication key is Kausf.

27. The key generation method according to claim 12, characterized in that, The authentication key is Kausf.

28. The key generation method according to claim 15, characterized in that, The authentication key is Kausf.

29. The key generation method according to claim 19, characterized in that, The authentication key is Kausf.

30. The key generation method according to claim 21, characterized in that, The authentication key is Kausf.

31. A key generation device, characterized in that, The key generation apparatus includes a unit or module for performing the method as described in any one of claims 1-30.

32. A key generation device, characterized in that, The key generation apparatus includes: a processor; the processor is configured to execute a computer program stored in a memory, causing the apparatus to perform the key generation method as described in any one of claims 1-30.

33. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or instructions that, when executed on a computer, cause the key generation method as described in any one of claims 1-30 to be performed.

34. A computer program product, characterized in that, The computer program product includes: a computer program or instructions that, when run on a computer, cause the key generation method as described in any one of claims 1-30 to be executed.

Citation Information

Patent Citations

  • Network access authentication method based on non-3GPP network, and related device and system

    WO2018170617A1

  • Methods and devices for a secure connection

    WO2020041933A1