Method for authenticating a network element to access a communication network, network element and medium

By synchronizing authentication serial numbers on the wireless terminal and network side and using ECIES encryption, the problem of authentication serial number leakage is solved, the security of wireless terminals and networks is improved, and connectivity and denial-of-service attacks are prevented.

CN116569516BActive Publication Date: 2025-11-18ZTE CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080104240.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-30
Publication Date
2025-11-18
Estimated Expiration
2040-09-30

AI Technical Summary

Technical Problem

During the registration and authentication process of wireless terminals, the authentication serial number is easily leaked, leading to hacker attacks, especially connectivity and denial-of-service attacks, which affect the security of terminals and networks.

Method used

By maintaining synchronized authentication serial numbers (SQNMS and SQNHE) on the wireless terminal and network side, and using the Elliptic Curve Integrated Encryption Scheme (ECIES) to hide the serial number and user identifier, the exposure on the wireless interface is reduced, thus achieving the synchronization and updating of the serial number.

Benefits of technology

It effectively prevents the leakage of authentication serial numbers, reduces connectivity and denial-of-service attacks, improves the security of wireless terminals and networks, and protects user privacy and network resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116569516B_ABST
    Figure CN116569516B_ABST
Patent Text Reader

Abstract

The present disclosure relates to methods, network elements and media for authenticating a network element to access a communication network, in particular to protecting an authentication sequence number of a wireless terminal from being leaked when sending it via a wireless communication interface during a registration and authentication procedure. An incremental authentication sequence number is maintained by the wireless terminal and used in synchronization with another authentication sequence number maintained at the network side (under normal network operation) to track registration and authentication activities of the terminal device and to help detect certain types of malicious attacks (e.g. registration replay) against the wireless terminal via the wireless communication interface. The terminal side sequence number is sent to the network by a similar hiding mechanism as the hiding mechanism of the permanent user identity of the wireless terminal to reduce its exposure to the wireless interface and the authentication sequence number of the wireless terminal is synchronized with the network side authentication sequence number by tracking and updating the sequence numbers at the terminal side and the network side upon successful authentication or re-authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to the registration and authentication process between a mobile terminal and a core network, and more specifically, to techniques for preventing the leakage of authentication serial numbers, and particularly to a method, network element, and computer-readable program medium for authenticating a second network element to access the communication network, performed by a first network element of the communication network. Background Technology

[0002] A wireless terminal device can communicate with its home core network via the serving network. Before accessing the home core network, the wireless terminal can initiate a registration and authentication process. The wireless terminal, the serving network, and the home core network interact with each other to authenticate the wireless terminal to the network and vice versa. After successful registration and authentication, access credentials are generated to enable further communication between the wireless terminal and the network. Communication messages (whether encrypted or unencrypted) transmitted between the UE and the network via the wireless interface are vulnerable to hacking. Hackers may obtain confidential information about the wireless terminal through such attacks. Summary of the Invention

[0003] This disclosure generally relates to the registration and authentication process between a wireless terminal and a core network. Specifically, it relates to protecting the authentication serial number of a wireless terminal from leakage during the registration and authentication process when the wireless terminal's authentication serial number is transmitted via a wireless communication interface. Specifically, an incremental authentication serial number is maintained by the wireless terminal and used in synchronization with another authentication serial number maintained by the network side (under normal network operation) to track the registration and authentication activities of the terminal device and to help detect certain types of malicious attacks on the wireless terminal via the wireless communication interface (e.g., registration replay). The terminal-side serial number is sent to the network through a hiding mechanism similar to that used for hiding the wireless terminal's permanent user identifier, reducing its exposure to the wireless interface. Furthermore, by tracking and updating the terminal-side and network-side serial numbers upon successful authentication or re-authentication, the wireless terminal's authentication serial number is synchronized with the network-side authentication serial number.

[0004] In some exemplary implementations, a method is disclosed for authenticating a second network element to access the communication network, performed by a first network element. The method may include: receiving an authentication message initiated by the second network element; de-hiding the authentication message to obtain a de-hiding sequence number maintained by the first network element and a de-hiding user identifier of the second network element; storing the de-hiding sequence number in the first network element; generating a new sequence number and generating an authentication vector based on the new sequence number; sending the authentication vector to the second network element; and when an authentication response message for the authentication vector is received from the second network element, replacing the de-hiding sequence number stored in the first network element with the new sequence number.

[0005] In some other implementations, another method is disclosed for authenticating a second network element to access the communication network, performed by a first network element. This method may include: receiving an authentication message initiated by the second network element, wherein the authentication message contains a de-hidden user identifier of the second network element; generating a new sequence number and generating an authentication vector based on the new sequence number; sending the authentication vector to the second network element; and, upon receiving an authentication response message for the authentication vector from the second network element, replacing the previously stored sequence number associated with the first network element with the new sequence number.

[0006] In some other implementations, a network device is disclosed. The network device primarily includes one or more processors and one or more memories, wherein the one or more processors are configured to read computer code from the one or more memories to implement the method described above, executed by a first network element.

[0007] In some other implementations, a computer program product is disclosed. This computer program product may include a non-transitory computer-readable program medium on which computer code is stored, which, when executed by one or more processors, causes the one or more processors to implement the methods described above.

[0008] Other aspects and alternatives to the above embodiments and their implementations are explained in more detail in the following drawings, description and claims. Attached Figure Description

[0009] Figure 1 An exemplary communication network is shown, including terminal devices, carrier networks, data networks, and service applications.

[0010] Figure 2 Exemplary network functions or network nodes in a communication network are shown.

[0011] Figure 3 An exemplary network function or network node in a wireless communication network is shown.

[0012] Figure 4 An exemplary data structure for a user-hidden identifier used for network registration and authentication of wireless terminals is shown.

[0013] Figure 5 An exemplary data and logic flow for main network registration / authentication between a wireless terminal (User Equipment (UE)) and the core network is shown, based on the user's hidden identifier and hidden authentication serial number of the wireless terminal.

[0014] Figure 6This document illustrates an exemplary data and logic flow for re-authentication when a wireless terminal (User Equipment, UE) detects that an authentication sequence number has been desynchronized.

[0015] Figure 7 An exemplary data and logic flow for registration / authentication between a wireless terminal (User Equipment (UE)) and the core network is shown, based on a temporary identity and authentication serial number assigned by the network to an unverifiable wireless terminal.

[0016] Figure 8 An exemplary data and logic flow for registration / authentication between a wireless terminal (User Equipment (UE)) and the core network is shown, based on a temporary identity and authentication sequence number assigned by the network upon successful verification of the wireless terminal.

[0017] Figure 9 An exemplary data and logic flow for primary network registration / authentication between a wireless terminal (User Equipment (UE)) and the core network is shown when an authentication sequence number from the network side is detected for desynchronization, based on the user hidden identifier and hidden authentication sequence number of the wireless terminal.

[0018] Figure 10 This document illustrates an exemplary data and logic flow for registration / authentication between a wireless terminal (User Equipment (UE)) and the core network, based on a temporary identity and authentication sequence number assigned by the network to an unverifiable wireless terminal when an authentication sequence number discrepancy is detected from the network side.

[0019] Figure 11 This document illustrates an exemplary data and logic flow for registration / authentication between a wireless terminal (User Equipment (UE)) and the core network, based on a temporary identity and authentication sequence number assigned by the network upon successful verification of the wireless terminal during desynchronization, when an authentication sequence number from the network side is detected.

[0020] Figure 12 An exemplary data and logic flow for primary network registration / authentication between a wireless terminal (User Equipment (UE)) and the core network is shown when a registration replay attack via a registration message timestamp from the network side is detected. This flow is based on the user's hidden identifier and hidden timestamp of the corresponding registration message.

[0021] Figure 13This document illustrates an exemplary data and logic flow for registration / authentication between a wireless terminal (User Equipment (UE)) and the core network when a registration replay attack via a registration message timestamp from the network side is detected. This flow involves a temporary identity assigned by the network to an unverifiable wireless terminal and a hidden timestamp of the corresponding registration message. Detailed Implementation

[0022] Exemplary communication network

[0023] like Figure 1 As shown in 100, the exemplary communication network may include terminal devices 110 and 112, a carrier network 102, various service applications 140, and other data networks 150. For example, carrier network 102 may include access network 120 and core network 130. Carrier network 102 may be configured to transmit voice, data, and other information (collectively referred to as data services) between terminal devices 110 and 112, between terminal devices 110 and 112 and service applications 140, or between terminal devices 110 and 112 and other data networks 150. Following the authentication process described in further detail below, communication sessions and corresponding data paths can be established and configured for such data transmission.

[0024] Access network 120 can be configured to provide network access to core network 130 to terminal devices 110 and 112. Core network 130 may include various network nodes or network functions configured to control communication sessions and perform network access management and data service routing. Service application 140 may be hosted by various application servers accessible to terminal devices 110 and 112 through core network 130 of carrier network 102. Service application 140 may be deployed as a data network external to core network 130. Similarly, terminal devices 110 and 112 may access other data networks 150 through core network 130, and these other data networks may appear as data destinations or data sources for specific communication sessions instantiated in carrier network 102.

[0025] Figure 1 The core network 130 may include various geographically distributed and interconnected network nodes or functions to provide network coverage for the service area of ​​the carrier network 102. These network nodes or functions may be implemented as dedicated hardware network elements. Alternatively, these network nodes or functions may be virtualized and implemented as virtual machines or software entities. Each network node may be configured with one or more types of network functions. These network nodes or network functions may collectively provide provisioning and routing functions for the core network 130. The terms "network node" and "network function" are used interchangeably in this disclosure.

[0026] Figure 2Further examples illustrate the exemplary division of network functions within the core network 130 of the communication network 200. Although in Figure 2 Only a single instance of a network node or function is shown, but those skilled in the art will understand that each of these network nodes or functions can be instantiated as multiple instances of network nodes distributed throughout the core network 130. Figure 2 As shown, the core network 130 may include, but is not limited to, network nodes, such as Access Management Network Node (AMNN) 230, Authentication Network Node (AUNN) 260, Network Data Management Network Node (NDMNN) 270, Session Management Network Node (SMNN) 240, Data Routing Network Node (DRNN) 250, Policy Control Network Node (PCNN) 220, and Application Data Management Network Node (ADMNN) 210. Exemplary signaling and data exchange between various types of network nodes through various communication interfaces is provided by… Figure 2 Various solid lines in the diagram represent connections between data points. Such signaling and data exchanges can be carried by signaling or data messages that follow a predetermined format or protocol.

[0027] Above Figure 1 and 2 The implementation described herein can be applied to both wireless and wired communication systems. Figure 3 It shows the basis Figure 2 An exemplary cellular wireless communication network 300 is a general implementation of the communication network 200. Figure 3 The wireless communication network 300 is shown to include a wireless terminal or user equipment (UE) 310 (used as... Figure 2 Terminal device 110), Radio Access Network (RAN) 320 (used as a terminal device 110), Radio Access Network (RAN) 320 Figure 2The network includes an access network 120, service applications 140, a data network (DN) 150, and a core network 130. The core network includes an Access and Mobility Management Function (AMF) 330 (used as...). Figure 2 AMNN 230), Session Management Function (SMF) 340 (used as AMNN 230), Session Management Function (SMF) 340 Figure 2 SMNN 240), Application Function (AF) 390 (used as Figure 2 ADMNN 210), User Plane Management Function (UPF) 350 (used as Figure 2 DRNN 250), policy control function 322 (used as Figure 2 PCNN 220), Authentication Server Function (AUSF) 360 (used as Figure 2 AUNN 260), and Unified Data Management / Authentication Credential Repository and Processing Function (UDM / ARPF) 370 (used as... Figure 2 (UDMNN270). Furthermore, although in Figure 3 Only a single instance of some network functions or nodes of the wireless communication network 300 (particularly the core network 130) is shown in the illustration, but those skilled in the art will understand that each of these network nodes or functions may have multiple instances distributed throughout the wireless communication network 300.

[0028] exist Figure 3In this context, UE 310 can be implemented as various types of wireless devices or terminals configured to access core network 130 via RAN 320. UE 310 can include, but is not limited to, mobile phones, laptops, tablets, Internet of Things (IoT) devices, distributed sensor network nodes, wearable devices, etc. UE 310 may include a Mobile Station (ME) and a Subscriber Identity Module (SIM). The SIM module can be implemented, for example, as a Universal Mobile Telecommunication System SIM (USIM), which includes some computing capabilities for network registration and authentication. The computation required to perform network registration and authentication can be performed by the USIM or the ME in the UE. For example, RAN 320 may include multiple wireless base stations distributed across the service area of ​​the carrier network. Communication between UE 310 and RAN 320 can be carried over an over-the-air (OTA) radio interface, such as... Figure 3 As shown in 311.

[0029] continue Figure 3 The UDM 370 can serve as a persistent storage or database for user contract and subscription profiles and data. The UDM may also include an authentication credential store and processing capabilities (ARPF, such as...). Figure 3 As shown in UDM / ARPF370, it is used to store long-term security credentials for user authentication and to perform calculations of authentication vectors and encryption keys using such long-term security credentials as input, as described in more detail below. To prevent unauthorized exposure of UDM / ARPF data, UDM / ARPF370 can be located in a secure network environment of a network operator or a third party.

[0030] The AMF / SEAF 330 can communicate with RAN320, SMF 340, AUSF 360, UDM / ARPF 370, and PCF 322 via various communication interfaces indicated by solid lines connecting these network nodes or functions. The AMF / SEAF 330 can handle signaling management from the UE to the Non-Access Stratum (NAS), and is responsible for UE 310's provisioning registration and access to the core network 130, as well as SMF 340 allocation to support the communication needs of specific UEs. The AMF / SEAF 330 can further handle UE mobility management. The AMF may also include a Security Anchor Function (SEAF), such as... Figure 3As shown in 330 (and described in more detail below), this security anchor function interacts with AUSF 360 and UE 310 for user authentication and management of encryption / decryption keys at various levels. AUSF 360 can terminate user registration / authentication / key generation requests from AMF / SEAF 330 and interact with UDM / ARPF 370 to complete such user registration / authentication / key generation.

[0031] SMF 340 can be assigned by AMF / SEAF 330 for a specific communication session instantiated in wireless communication network 300. SMF 340 can be responsible for assigning UPF 350 to support communication sessions and data flows in the user data plane, and for provisioning / regulating the assigned UPF 350 (e.g., for developing packet detection and forwarding rules for the assigned UPF 350). Alternatively, UPF 350 can be assigned by AMF / SEAF 330 for a specific communication session and data flow, instead of SMF 340. UPF 350, assigned and provisioned by SMF 340 and AMF / SEAF 330, can be responsible for data routing and forwarding, and for reporting network usage for a specific communication session. For example, UPF 350 can be responsible for routing end-to-end data flows between UE 310 and DN 150, and between UE 310 and service application 140. DN 150 and service application 140 may include, but are not limited to, data networks and services provided by the operator of wireless communication network 300 or by third-party data network and service providers.

[0032] Service application 140 can be provided by AF 390 via, for example, network exposure functionality provided by core network 130 (in... Figure 3 Not shown in the image, but described below. Figure 7 (as shown in the diagram) to manage and provide. When managing a specific communication session involving service application 140 (e.g., between UE 310 and service application 140), SMF 340 can interact with AF 390 associated with service application 140 via communication interface 313.

[0033] PCF 322 can manage and provide AMF / SEAF 330 and SMF 340 with policies and rules at various levels applicable to communication sessions associated with UE 310. Thus, for example, AMF / SEAF 330 can assign SMF 340 to a communication session based on the policies and rules associated with UE 310 and obtained from PCF 322. Similarly, SMF 340 can assign UPF 350 to handle data routing and forwarding for the communication session based on the policies and rules obtained from PCF 322.

[0034] To enable UE 310 to access the core network of its subscribed home carrier network, it can first communicate with the available RAN 320 and the AMF / SEAF 330 associated with RAN 320. RAN 320 and AMF / SEAF 330 may or may not belong to the home carrier network (e.g., they may be associated with another carrier network that UE 310 has not subscribed to, and may be referred to as the serving network; the term "serving network" can be used generically to refer to an access network having an AMF / SEAF belonging to another carrier network or to the same home core carrier network). The AMF / SEAF 330 of the serving network can communicate with AUSF 360 and UDM / ARPF 370 of UE 310's home carrier network for authentication, and then with SMF 340 and PCF 322 of the home carrier network to establish a communication session after successful authentication.

[0035] The various devices, terminals, and network nodes described above may include computing and communication components, such as processors, memory, various communication interfaces, various user display / operation interfaces, operating systems, and applications configured to implement the various embodiments described in this disclosure.

[0036] Authentication process, connectability, and Denial-of-Service (DoS) attacks

[0037] The registration and authentication process may involve UE 310 communicating with its home UDM / ARPF 370 via serving RAN 320, serving AMF / SEAF 330, home AUSF 360, and home UDM / ARPF, as described in more detail below. During the registration and authentication process, UE 310 verifies that it is communicating with a legitimate network, and the network similarly verifies that UE 310 is authorized to access the network. After successful authentication between UE 310 and core network 300, a temporary access identity can be assigned to UE 310 for further communication with the core network. This temporary access identifier can be frequently modified / replaced to reduce the harm to attackers from user identity, location, and communication content. Authentication can be initiated by UE 310 sending a registration request to the serving AMF / SEAF 330, which contains its hidden or encrypted unique permanent identity, such as a Subscriber Concealed Identity (SUCI). Furthermore, after successful registration, temporary user identifiers such as the Global Unique Temporary Identity (GUTI) can be assigned to the UE 310 by the AMF / SEAF 330 for further network access.

[0038] Due to external attacks via the radio interface, a user's identity, location, or communications may be compromised. Examples of such attacks include, but are not limited to, linkability attacks and denial-of-service (DoS) attacks. For instance, an attacker intercepting a SUCI via the radio interface can be used in a linkability attack, where the attacker can potentially determine whether a UE observed at a certain location / time X is the same as a UE observed at another location / time Y, thus tracking the UE. For example, an attacker could record the SUCI that UE A has used via the radio interface. An attacker can also perform an active attack to obtain a SUCI if UE A uses a GUTI instead of a SUCI for authentication, for example, by compromising the GUTI sent by UE A. This would likely result in an AMF / SEAF 330 SUCI request and, in response, a SUCI transmission from the UE. When later, a UE B sends a registration request to a fake base station operated by the same attacker as a relay station, the attacker can modify UE B's registration request by exchanging its SUCI or GUTI with the previously captured SUCI from UE A and forward the modified request to the network. The attacker then monitors the responses between the network and UE B to determine if UE B is the same as UE A, potentially allowing them to track this UE. For example, the attacker might then monitor the wireless interface to see if a successful Authentication and Key Agreement (AKA) operation was performed and if the network accepted the registration request. If so, UE A and UE B would be identified as the same UE by the attacker.

[0039] This type of linkability attack cannot be mitigated by simply hiding the content of the AKA response, because an attacker can detect whether the AKA operation was successful from various subsequent messages intercepted in the wireless interface, without needing to know the content of the AKA response. If the content of the AKA response is not hidden, an attacker can directly use such content to determine whether the attacked UE is near a fake base station.

[0040] Therefore, by replaying the SUCI, an attacker can observe whether the AKA can be successfully executed using the replayed SUCI, i.e., whether the replayed registration request is accepted by the network. If so, the attacker can link a UE observed in one location with a UE observed in another location (by replaying their SUCI). When the attacker performs this action in several locations, even if the attacked UE may remain anonymous, the attacker can still track the anonymous UE in different locations, compromising its privacy and untraceability.

[0041] For example, the network may be vulnerable to DoS attacks by attackers replaying SUCIs. Specifically, attackers can replay SUCIs to force the network and / or UE to perform frequent and repetitive processes (e.g., SUCI de-hiding and authentication processes). This is especially likely to occur when the de-hiding scheme (e.g., Elliptic Curve Integrated Encryption Scheme (ECIES)) does not have any mechanism to detect or adjust whether the received SUCI is the same SUCI previously sent to the network by the UE.

[0042] Thus, if an attacker launches multiple SUCI replay attacks, the UDM and UE may be forced to expend significant resources processing the replayed SUCI and authentication request messages separately, as these messages appear legitimate. This triggers a DoS attack on both the UDM and UE. A DoS attack on the UE may cause a decrease in the UE's processing power and rapid battery depletion. A DoS attack on the UDM may cause a decrease in the UDM's processing power and delays in responding to legitimate registration requests and other types of requests.

[0043] Hidden authentication serial number

[0044] In some implementations, to combat the aforementioned connectivity and DoS attacks, the UE 310 and the carrier network can maintain a pair of sequence numbers (or authentication sequence numbers) to track the UE's authentication and re-authentication. These sequence numbers can be referred to as SQNs. MS (on the UE side) and SQN HE (On the carrier network side). For example, SQN HE These serial numbers can be maintained by the UDM / ARPF 370 in a home environment (HE). They are only allowed to increment as the UE is authenticated and re-authenticated. Under normal network access conditions, the UE 310 and the carrier network can maintain the SQN. MS and SQN HE Synchronization between them. For example, during authentication or re-authentication processes, detection of desynchronization by the UE 310 or network can indicate potential attacks and other problems.

[0045] In some implementations of sequence number synchronization, the SQN is maintained by UE 310. MS It can be transmitted to the carrier network during some authentication processes. Similarly, the SQN maintained by UDM / ARPF... HEIt can also be transmitted to the UE. However, to protect these serial numbers from being leaked, their transmission can be minimized, and when transmission is necessary, it can be transmitted in a form considered secure and encrypted. In an exemplary implementation described in more detail below, during the authentication process, SQN MS It can be transmitted together with the Subscription Permanent Identifier (SUPI) from UE 310 to the AMF / SEAF330 of the serving network and in the same manner. Furthermore, the SQN from the UDM / ARPF side... HE It is embedded and encrypted in the authentication vector and then transmitted to the UE, as described in further detail below.

[0046] Specifically, SQN can be protected by transmitting the encrypted data via a wireless interface to the AMF / SEAF 330 after encryption based on, for example, an Elliptic Curve Integrated Encryption Scheme (ECIES). MS In other words, the use of ECIES to conceal SUPI during the authentication process can be extended to adapt to SQN. MS And SUPI. In some implementations, SUPI can be used with SQN. MS Combined and used as a plaintext block for symmetric encryption under ECIES. SQN MS Combinations with SUPI can take the form of serialization, interleaving, etc. For example, when the International Mobile Subscriber Identity (IMSI) is used for authentication instead of SUPI, the Mobile Subscription Identification Number (MSIN) (e.g., 9 to 10 digits) and SQN are used. MS The UE can combine and encrypt / hide these messages. Correspondingly, in the home network, ECIES-based symmetric decryption can be used to dehide SUPI (or MSIN) and SQN. MS .

[0047] Hidden registration timestamp

[0048] In some other implementations of countering the aforementioned SUCI replay attacks, UE 310 can transmit a timestamp along with the SUCI to the network in the registration or authentication request message. The network can rely on such a timestamp to detect SUCI replay attacks. Similar to the authentication sequence number mentioned above, the timestamp can be combined with the SUPI, and then the combination can be encrypted using ECIES. The combination of SUPI and timestamp can be based on other forms of concatenation or interleaving.

[0049] Hiding the timestamp of the registration / authentication request can be performed as an alternative to or supplement to hiding the authentication sequence number mentioned above. For example, SUPI, the sequence number, and / or the timestamp can be combined (e.g., concatenated or interleaved) and then encrypted using the ECIES scheme.

[0050] SUCI Data Structure

[0051] SUPI (or MSIN) and SQN MS Hidden concatenation of timestamps and / or timestamps can be sent as part of the SUCI data structure to the AMF / SEAF 330 of the service network. Figure 4 An example of a SUCI data structure 400 is shown below. The SUCI structure 400 contains a SUPI type field 402, whose values ​​range from, for example, 0 to 7, to identify the type of identifier hidden in the "Scheme Output" field 412 and other fields of the SUCI structure 400. For example, various values ​​can be used in field 402 to indicate the following SUPI types:

[0052] -0: IMSI

[0053] -1: Network-specific identifier

[0054] -2: Global Line Identifier (GLI)

[0055] -3: Global Cable Identifier (GCI)

[0056] -4: SUPI and SQN MS And / or a combination of message timestamps (e.g., concatenation).

[0057] -5 to 7: Reservation values ​​for other indicators.

[0058] The SUPI type values ​​and type correspondences listed above are for illustrative purposes only. Other correspondences may be used. For example, other values, including reserved values, can be used to indicate hiding from SQN. MSThe SUPI is a combination of the registration message timestamp and / or the SUCI structure 400. Other fields of the SUCI structure 400 include, for example, the home network identifier 404, the routing indicator 406, the protection scheme identifier 408, and the home network public key identifier 410.

[0059] Authentication based on hidden SUPI and authentication serial number

[0060] Figure 5 It shows the use of SQN MS An exemplary data and logic flow 500 describes a hidden SUCI used for primary network registration / authentication between UE 310 and the home core networks AUSF 360 and UDM / ARPF 370 via the serving network AMF / SEAF 330, assuming successful authentication between UE 310 and the network. The logic and data flow 500 may include the following exemplary steps, which have... Figure 5 The corresponding step numbers.

[0061] 1. During the main authentication process 500, the USIM and ME combine the UE 310's SUPI and the current SQN maintained by the USIM or ME via, for example, concatenation or interleaving. MS SUPI and SQN MS Combinations of plaintext blocks (e.g., concatenation or interleaving) can be encrypted using the ECIES method in USIM or ME. (Follow) Figure 4 The SUCI data structure can be constructed to include SUPI and SQN. MS The encrypted combination. SUCI structure ( Figure 4 The "SUPI type" field of the 402) can be set to indicate that the SUCI structure contains SUPI and SQN. MS Hidden combinations. For example, you can set the value to "4" in the "SUPI type" field of the SUCI structure.

[0062] 2. The UE can use a registration request message containing a hidden SQN sent from UE 310 to serving AMF / SEAF 330. MS The SUCI data structure.

[0063] 3. Once a registration request message is received from UE 310, whenever the serving AMF / SEAF 330 wishes to initiate authentication, it can invoke the AFS service (represented as Nausf_UEAuthentication service) by sending an AFS service request message (represented as Nausf_UEAuthentication_Authenticate request message) to the home AFS 360. For example, the Nausf_UEAuthentication_Authenticate request message can contain embedded hidden SUPI and SQN. MS SUCI and service network name.

[0064] 4. Upon receiving a Nausf_UEAuthentication_Authenticate request message, the home AUSF 360 can check whether the requesting AMF / SEAF 330 in the serving network is authorized to use the serving network name included in the Nausf_UEAuthentication_Authenticate request by comparing the received serving network name with the expected serving network name. The home AUSF 360 may temporarily store the received serving network name. If the serving network is not authorized to use the received serving network name, the AUSF 360 may respond to the UE 310 in a response message representing a Nausf_UEAuthentication_Authenticate response, indicating that the serving network is not authorized. If the serving network is authorized to use the received serving network name, a UDM authentication request message representing a Nudm_UEAuthentication_Get request may be sent from the home AUSF 360 to the home UDM / ARPF 370. The Nudm_UEAuthentication_Get request may contain the following information:

[0065] -Includes hidden SUPI and SQN MS SUPI; and

[0066] - Service network name.

[0067] 5. Once a Nudm_UEAuthentication_Get request is received, if it belongs to UDM / ARPF 370, determine the SUPI type based on the SUPI type field of the received SUCI data structure. MSIf the combined SUPI is received, the UDM / ARPF370 can invoke the De-concealment Function (SIDF). Therefore, before the UDM 370 can process the request, the SIDF can deconceal the received SUCI to obtain the SUPI and SQN. MS Based on SUPI, UDM / ARPF370 can perform its authentication process. (De-hidden SQN) MS It can be stored in UDM 370 for future use (see below for reference). Figure 6 (More detailed description). The UDM 370 can also generate new SQNs. HE It is greater than the current SQN maintained by the UDM. HE Then, the current SQN HE Updated SQN HE Replacement. Also based on the updated SQN. HE Other information is used to generate an authentication vector (the components of the authentication vector are in step 6 below).

[0068] 6. For each Nudm_Authenticate_Get request, the UDM / ARPF 370 can create a Home Environment Authentication Vector (HE AV). More specifically, the UDM / ARPF 370 does this by generating an authentication vector (AV) with the Authentication Management Field (AMF) separator bit set to "1". The UDM / ARPF 370 can then export the AUSF key K. AUSF And calculate the expected response denoted by XRES*. Finally, the UDM / ARPF 370 can be configured based on the random number denoted by RAND, the authentication key denoted by AUTN, XRES*, and K. AUSF To create a HE AV. For example, AUTN contains SQN. HE The UDM / ARPF 370 can then return the HE AV along with an indication that the HE AV will be used for AKA in the response to the AUSF 360 represented by the Nudm_UEAuthentication_Get response. The UDM / ARPF 370 can also include the de-hidden SUPI in the Nudm_UEAuthentication_Get response.

[0069] 7. The AUSF 360 can temporarily store XRES* together with SUPI received from the UDM / ARPF 370.

[0070] 8. Then, the AUSF 360 can generate an AV based on the HE AV received from the UDM / ARPF 370 by: calculating the hash XRES represented by HXRES* from XRES* and the hash from K... AUSF by K SEAF The SEAF key is represented, and in HE AV, XRES* is replaced with HXRES* and K is used. SEAF Replace K AUSF .

[0071] 9. AUSF 360 can then remove K. SEAF In a response message represented as Nausf_UEAuthentication_Authenticate, it returns a service environment authentication vector (including RAND, AUTN, and HXRES*) represented as SE AV to SEAF 330.

[0072] 10. SEAF 330 can send RAND and AUTN, included in the AV, to the UE in the Non-Access Stratum (NAS) message authentication request. This message can also include ngKSI, which the UE and AMF will use to identify the K... AMF And a portion of the local security context created upon successful authentication. The ME can forward the RAND and AUTN received in the NAS message authentication request to the USIM.

[0073] 11. Upon receiving RAND and AUTN, the UE (e.g., USIM or ME) can verify the freshness of the AV by checking whether the AUTN is acceptable. For example, the UE can extract the SQN contained in the AUTN. HE and with local SQN MS Compare. If SQN HE Not less than SQN MS If the sequence number is successfully synchronized, the UE can determine that the sequence number synchronization has failed. Otherwise, the UE determines that the sequence number synchronization has failed. When the UE determines the sequence number SQN... MS and SQN HE During synchronization, the UE executes Figure 5 The remaining steps are as follows. If sequence number synchronization is confirmed, the USIM can calculate the response represented by RES. The USIM can return RES, CK, and IK to the ME. If the USIM calculates Kc (i.e., GPRS Kc) based on CK and IK using the conversion function c3 and sends it to the ME, the ME can ignore this GPRS Kc and not store it on the USIM or in the ME. The ME can then calculate RES* based on RES. The ME can calculate K based on CK||IK.AUSF ME can be based on K AUSF Calculate K SEAF The ME (Member of Access) accessing the network can check during authentication whether the "separator bit" in the AUTN's AMF field is set to 1. The "separator bit" is the 0th bit of the AUTN's AMF field. Once the SQN is determined... MS and SQN HE To synchronize the sequence numbers between them, the UE uses the extracted SQN. HE To update (or replace) its SQN MS For future synchronization purposes.

[0074] 12. UE 310 can return RES* to SEAF in the NAS message authentication response.

[0075] 13. SEAF 330 can then calculate HRES* based on RES*, and SEAF 330 can compare HRES* and HXRES*. If they match, from the perspective of the serving network, SEAF 330 can consider UE 310's authentication successful. When authentication is successful, follow the steps below. Figure 5 The remaining steps. If unsuccessful, SEAF 330 can notify the network of authentication failure by, for example, sending a response message with a fault code and / or discarding / stopping / exiting authentication. If the UE is not contacted (e.g., no response is received from the UE), and SEAF 330 never receives RES*, SEAF can consider authentication to have failed and indicate the failure to AUSF 360.

[0076] 14. SEAF 330 may send RES* received from UE 310 to AUSF 360 in a message represented by the Nausf_UEAuthentication_Authenticate request message.

[0077] 15. When AUSF 360 receives a Nausf_UEAuthentication_Authenticate request message including RES* as authentication confirmation, it can verify whether the AV has expired. If the AV has expired, from the perspective of the home network, AUSF 360 can consider UE 310's authentication unsuccessful. After successful authentication, AUSF 360 can store K. AUSF AUSF 360 can compare the received RES* with the stored XRES*. If RES* and XRES* are equal, from the perspective of the home network, AUSF 360 can consider UE 310's authentication successful and follow the steps below. Figure 5The remaining steps. AUSF 360 can notify UDM 370 of the authentication result. In the event of failure (RES* and XRES* are not equal), AUSF 360 can notify the network of authentication failure by, for example, sending a response message with a fault code and / or discarding / stopping / exiting authentication.

[0078] 16. AUSF 360 can indicate to SEAF 330, from the home network's perspective, whether authentication was successful in a response message represented as Nausf_UEAuthentication_Authenticate. If authentication is successful, the K can be included in the Nausf_UEAuthentication_Authenticate response. SEAF Send to SEAF 330. If authentication is successful, AUSF 360 may also include SUPI in the Nausf_UEAuthentication_Authenticate response message.

[0079] 17. AUSF 360 can use a request message represented as Nudm_UEAuthentication_ResultConfirmation request to notify UDM 370 of the result and timing of the authentication process with UE 310. This request may include SUPI, the timestamp of the authentication, the authentication type (e.g., EAP method or AKA), and the service network name.

[0080] 18. UDM 370 can store the authentication status of UE 310 (SUPI, authentication result, timestamp, and service network name), and use the current SQN. HE Update its previously stored SQN MS This is for future authentication serial number synchronization purposes.

[0081] 19. UDM 370 can respond to AUSF 360 with a response message represented as Nudm_UEAuthentication_ResultConfirmation.

[0082] 20. Upon receiving a subsequent UE-related procedure (e.g., Nudm_UECM_Registration_Request from AMF 330), UDM 370 may apply actions based on the home operator's policies to detect and implement protection against certain types of fraud.

[0083] 21. Finally, AMF 330 assigns a GUTI to UE 310 for further authentication.

[0084] Verification steps 13 and 15 may fail, indicating that UE authentication cannot be performed. In these cases, a fault message can be sent to the UDM 370 in a serialized manner. Similar to step 18 above, the UDM 370 can still store the authentication state and use the current SQN. HE Update stored SQN MS .

[0085] Serial number synchronization failure handling

[0086] In such Figure 5 As shown and in step 11 as described above, when the SQN is extracted from the AUTN received from the AMF 310 HE Less than the local SQN MS At this time, UE 310 can determine that the sequence number synchronization has failed. Figure 6 Exemplary logic and data flow 600 for re-authentication (RA) following such sequence number synchronization failure are shown.

[0087] In RA0, such as Figure 6 As shown, UE 310 can avoid calculating the embedded SQN. MS Any authentication failure information (e.g., AUTS) used to transmit to the AMF 330 to avoid SQN MS Another exposure in the radio interface. Instead, UE 310 simply sends a response message to AMF330 indicating that the failure was due to sequence number desynchronization. For example, this desynchronization could occur when UE 310 and the network are subjected to a SUCI replay attack. As an example of RA1, UE 310 could respond to NAS message authentication failure with only a cause value indicating that the failure was due to SQN failure / mismatch, without calculating AUTS and without sharing that AUTS with the network.

[0088] In RA2, when an authentication failure message is received from UE 310, SEAF 330 can send a request message to AUSF 360, which is represented as Nausf_UEAuthentication_Authenticate request message.

[0089] In RA3, once the Nausf_UEAuthentication_Authenticate request message is received from the AMF 330, the AUSF360 sends a request message to the UDM / ARPF 370, which is represented as the Nudm_UEAuthentication_Get request message.

[0090] In RA4, when the UDM / ARPF 370 receives a Nudm_UEAuthentication_Get request message from the AUSF 360, the ARPF 370 can be mapped to HE / AuC. The UDM / ARPF 370 can send a response message represented by a Nudm_UEAuthentication_Get response message, used to access the SQN stored in the UDM 370. MS (For example, in) Figure 5 (in step 5 or 18) instead of updating the SQN HE The new authentication vector is used for UE re-authentication. AUSF 360 follows... Figure 5 Steps 6-11 follow the principle of the new authentication process for UE 310.

[0091] SUPI failed GUTI authentication

[0092] Figure 7 The logic and data flow 700 for the registration / authentication process are shown, which is initiated by the UE 310 using a network-assigned temporary identifier, for example, via a previous registration and authentication process (e.g., from...). Figure 5 The GUTI obtained in step 21) of the SUCI registration process is shown below. Figure 7 Steps 0-2 in the process.

[0093] 0.UE 310 can use temporary identities such as GUTI to initiate the registration process.

[0094] 1. UE 310 can use a temporary identity GUTI in the registration request message, which is sent to the serving AMF / SEAF 330.

[0095] 2. The serving AMF / SEAF 330 may attempt to obtain the UE's SUPI from, for example, the older AMF / SEAF702 identified in the registration message, and if the serving AMF / SEAF 330 fails to obtain the UE context from the older AMF / SEAF702 ( Figure 7 In step 2a), the serving AMF / SEAF 330 can send an identity request message with an identity type to the UE 310. Figure 7 Step 2b). When an identity request message is received, UE 310 can send an identity response message to AMF / SEAF 330, wherein the SUCI embeds the current SQN. MS ( Figure 7 Step 2c).

[0096] The remaining steps 3-21 in logic and data flow 700 essentially use SUCI to perform the authentication process, and correspond to Figure 5 The logic and data flow are described in steps 3-21 of section 500. These steps are... Figure 7 As shown in the middle, and above about Figure 5 The explanation has already been provided, so it will not be repeated here.

[0097] Additionally, if in Figure 7 If the SQN synchronization check fails at UE 310 in step 11, then you can follow the steps below. Figure 6 The logic and data flow 600 are used to perform the re-authentication process, as described in more detail above.

[0098] Furthermore, verification steps 13 and 15 may fail, indicating that UE 310 cannot be authenticated by the network. In those cases, as described above... Figure 5 As described, fault messages can be sent to the UDM 370 in a serial manner. Similar to... Figure 7 Step 18 and above Figure 5 As described in step 18, the UDM can still store the authentication state and use the current SQN. HE Update stored SQN MS .

[0099] Successfully obtained SUPI's GUTI certification

[0100] Figure 8 The diagram illustrates the logic and data flow 800 for a registration / authentication process initiated by UE 310 using a network-assigned temporary identifier, for example, via a previous registration and authentication process (e.g., from...). Figure 5 or Figure 7 The GUTI obtained in step 21) of the SUCI registration process shown indicates that the serving network has successfully identified the UE's SUPI. Apart from steps 0-5, Figure 8 The logic and data flow are similar to 800. Figure 5 The logic and data flow of 500 will be described in more detail below.

[0101] 0. The home UDM 370 had previously stored the SQN of UE 310. MS .

[0102] 1a.UE 310 can initiate a registration process with GUTI.

[0103] 1b. UE 310 may use GUTI in the registration request message instead of SUCI sent to AMF / SEAF 330.

[0104] 2. Service AMF / SEAF 330 successfully obtained a UE context with SUPI from the older AMF / SEAF702.

[0105] 3. Whenever the service's AMF / SEAF 330 wishes to initiate authentication, it can invoke the AUSF authentication service by sending a Nausf_UEAuthentication_Authenticate request message to the AUSF360. The Nausf_UEAuthentication_Authenticate request message can include the SUPI and the service network name.

[0106] 4. Upon receiving the Nausf_UEAuthentication_Authenticate request message, the home AUSF 360 can check whether the requesting AMF / SEAF 330 in the serving network is authorized to use the serving network name included in the Nausf_UEAuthentication_Authenticate request by comparing the received serving network name with the expected serving network name. The home AUSF 360 may temporarily store the received serving network name. If the serving network is not authorized to use the serving network name, the home AUSF 360 can respond by indicating in a response message represented by the Nausf_UEAuthentication_Authenticate response that the serving network is not authorized. The AUSF 360 can then send a request message represented as a Nudm_UEAuthentication_Get request to the home UDM / ARPF 370. The Nudm_UEAuthentication_Get request may include the UE's SUPI and the serving network name.

[0107] 5. Once a Nudm_UEAuthentication_Get request is received from the home AUSF 360, the home UDM / ARPF 370 can select an authentication method based on SUPI. At the home UDM 370, an updated SQN greater than the previous sequence number used for UE 310 is used. HE To generate the home environment AV vector.

[0108] Figure 8 The logic and data flow of 800 are related to the above steps. Figure 5 The difference between the logic and the corresponding steps in data flow 500 is that, during the authentication process, SUPI is passed from the serving network to the home network instead of SUCI. Thus, the UE's SQN... MS It will not be sent to the home UDM / ARPF 370, and as Figure 8 As indicated in step 0, the SQN previously stored in the home UDM MS The current SQN will not be used. MS Update.

[0109] Figure 8 The remaining steps 6-21 in the logic and data flow 800 essentially perform the authentication process, which corresponds to Figure 5 The logic and data flow are described in steps 6-21 of section 500. These steps are... Figure 8 The above summarizes and combines... Figure 5 The explanation has already been provided, so it will not be repeated here.

[0110] In addition, if in Figure 8 If the SQN synchronization check fails at the UE in step 11, then you can follow the steps below. Figure 6 The logic and data flow 600 are used to perform the re-authentication process, as described in more detail above. In the re-authentication logic and data flow 600, the new authentication vector generated by the home UDM 370 in step RA4 can be based on the previously stored SQN. MS Any successful certification (in) Figure 8 Logic and data flow 800 Figure 7 500 and Figure 7 (In 700) all of them will cause the SQN maintained at UDM 370 to be affected. MS Update (or synchronize), this is done at step 18 of these logic and data flows using the current SQN. HE Replace stored SQN MS As a result, updates are missing in steps 1-5 of the GUTI authentication process in logic and data flow 800, therefore the SQN maintained at UDM 370 is also missing. MS It won't become out of sync.

[0111] also, Figure 8 The logic and data flow 800 verification steps 13 and 15 may fail, indicating that UE 310 cannot be authenticated by the network. In those cases, as described above for... Figure 5 As described, fault messages can be sent to the UDM370 in a serial manner. Similar to... Figure 8 Step 18 and above Figure 5 As described in step 18, the UDM 370 can still store the authentication status and use the current SQN. HE Update stored SQN MS .

[0112] Using SQN to counter SUCI replay attacks on the network side

[0113] In some implementations, it can be based on the UE-side sequence number SQN MS and HE side serial number SQN HE Detect SUCI replay attacks on the network side. Because in Figure 5 and Figure 7The transmission in steps 1-5 shows a hidden permanent UE identity and a hidden SQN. MS SUCI, therefore SQN MS It becomes available on the network side.

[0114] Figure 9 The example shown is UE 310 using SUCI (e.g., SUPI) and SQN with hidden network identities. MS Exemplary logic and data flow 900 for initiating a registration / authentication process. Logic and data flow 900 are similar to... Figure 5 The logic and data flow 500, except in step 5, are performed by the home UDM 370 to perform the SUCI replay attack detection process.

[0115] Specifically, in step 5 of the logic and data flow 900, upon receiving a Nudm_UEAuthentication_Get request sent from the home AUSF 360, if the SUPI type is consistent with SQN... MS If the home UDM 370 can invoke the SIDF for the combined SUPI, then the SIDF procedure can hide the received SUCI before the home UDM 370 can process the request, in order to obtain the SUPI and SQN associated with UE 310. MS .

[0116] for Figure 9 In step 5 of the logic and data flow 900, the SUCI replay attack detection from the network side, belonging to the UDM370, makes the following exemplary determination process:

[0117] -If the home domain UDM 370 does not yet have the SQN of UE 310's local storage. MS Then the SQN received via SUCI can be stored. MS Furthermore, the authentication method is selected based on SUPI, and based on the updated and added SQN. HE Generate AV.

[0118] -If the home UDM 370 has a previously stored SQN for UE 310 MS It can then be configured to receive SQN MS With previously stored SQN MS Compare them.

[0119] If the comparison shows the received SQN MS Less than or equal to the previously stored SQN MS If the UDM 370 determines that a SUCI replay attack has occurred, it will respond with a fault code or discard the message to stop the authentication process.

[0120] However, if the comparison shows the received SQN MS SQN greater than storage MS The UDM 370 can then be alternatively configured to select a SUPI-based authentication method, generating SQNs based on updates and additions. HE AV, and continue Figure 9 The remaining authentication process.

[0121] If SQN HE Less than or equal to the stored SQN MS Then, UDM 370 will discard AV and SQN. HE And generate an updated SQN. HE The new AV.

[0122] Figure 9 The logic and data flow 900, except for step 5, essentially perform an authentication process, which corresponds to... Figure 5 The corresponding steps in the logic and data flow of 500. These steps are in Figure 9 The above summarizes and combines... Figure 5 The explanation has already been provided, so it will not be repeated here.

[0123] Similarly, Figure 10 The logic and data flow 1000 for the registration / authentication process are shown, which is initiated by the UE 310 using a network-assigned temporary identifier, for example, via a previous registration and authentication process (e.g., from...). Figure 9 The GUTI obtained in step 21) of the SUCI registration process is shown. Except for step 5, which includes procedures for detecting SUCI replay attacks. Figure 10 The steps are similar to Figure 7 The steps. Figure 10 The logic and data flow in step 5 of 1000 are similar. Figure 9 The logic and data flow in step 900 are shown above, and described in detail. Thus, Figure 10 The steps summarized in the previous section will not be repeated here.

[0124] also, Figure 11 The diagram illustrates a registration / authentication process initiated by UE 310 using a network-assigned temporary identifier, for example, via a previous registration and authentication process (e.g., from...). Figure 9 or Figure 11 The GUTI obtained in step 21) of the SUCI registration process shown here, wherein the serving network successfully identifies the UE's SUPI. Figure 11 The steps are similar to Figure 8In addition to step 5, the UDM 370 can select the authentication method based on SUPI and based on SQN. HE Generate AV if SQN HE Less than or equal to SQN MS Then the UDM 370 can discard AV and SQN. HE And generate new AV and SQN. HE .

[0125] In addition, if in Figure 9 , 10 If the SQN synchronization check at the UE fails in step 11 of step 11, then you can follow the steps below. Figure 6 The logic and data flow 600 are used to perform the re-authentication process, as described in more detail above. In the re-authentication logic and data flow 600, the new authentication vector generated by the home UDM 370 in step RA4 can be based on the previously stored SQN. MS .

[0126] Countering SUCI replay attacks on the network side by using registration request message timestamps

[0127] In some implementations, SUCI replay attacks can be detected on the network side based on the UE registration request timestamp. Since the transmission embeds a hidden UE identity and a hidden timestamp in the SUCI as described above, the registration timestamp becomes available to the network side.

[0128] Figure 12 Exemplary logic and data flow 1200 of a registration / authentication process initiated by UE 310 using a SUCI with a hidden network identity (e.g., SUPI) and a hidden registration request timestamp are shown. Logic and data flow 1200 are similar to... Figure 9 The logic and data flow 900, besides the information hidden in SUCI including UE identity and registration request timestamp, are not UE identity and SQN. MS Furthermore, in step 5, the UDM 370 performs the SUCI replay attack detection process based on the registration request timestamp rather than the authentication sequence number.

[0129] The following describes in more detail, such as Figure 12 Exemplary steps 1-5 of the logic and data flow 1200 shown.

[0130] 1. During the main authentication process, UE 310 (e.g., USIM) combines the SUPI and the registration request or message timestamp represented as MESSAGE_TIME through concatenation, interleaving, or other combinations. For example, MESSAGE_TIME could represent the UTC-based time when the message (e.g., a registration or authentication message) was sent. (Following...) Figure 4The SUCI data structure can be constructed as an encrypted combination of SUPI and MESSAGE_TIME. SUCI structure ( Figure 4 The "SUPI type" field of 402) can be set to indicate that the SUCI structure contains a hidden combination of SUPI and MESSAGE_TIME. For example, the value of the "SUPI type" field in the SUCI structure can be set to "4".

[0131] 2. The UE can use a SUCI containing a hidden MESSAGE_TIME in the registration request message, which is sent from UE310 to the serving AMF / SEAF 330.

[0132] 3. When a registration request message is received from UE 310, whenever AMF / SEAF 330 wishes to initiate authentication, the serving AMF / SEAF 330 can invoke the AUSF service (represented as Nausf_UEAuthentication service) by sending an AUSF service request message (represented as Nausf_UEAuthentication_Authenticate request message) to AUSF 360. For example, the Nausf_UEAuthentication_Authenticate request message can contain a SUCI with hidden SUPI and MESSAGE_TIME embedded, as well as the service network name.

[0133] 4. Upon receiving a Nausf_UEAuthentication_Authenticate request message, the home AUSF 360 can check whether the requesting AMF / SEAF 330 in the serving network is authorized to use the serving network name included in the Nausf_UEAuthentication_Authenticate request by comparing the received serving network name with the expected serving network name. The AUSF 360 can temporarily store the received serving network name. If the serving network is not authorized to use the received serving network name, the AUSF 360 can respond to the UE 310 in a response message representing a Nausf_UEAuthentication_Authenticate response, indicating that the serving network is not authorized. If the serving network is authorized to use the received serving network name, a UDM authentication request message representing a Nudm_UEAuthentication_Get request can be sent from the home AUSF 360 to the home UDM / ARPF 370. The Nudm_UEAuthentication_Get request sent from the AUSF 360 to the UDM 370 can include the following information:

[0134] - Includes hidden SUPI and MESSAGE_TIME SUPI; and

[0135] - Service network name.

[0136] 5. Upon receiving a Nudm_UEAuthentication_Get request from the home AUSF 360, the home UDM 370 can invoke SIDF. If the SUPI type is a SUPI combined with MESSAGE_TIME, the SIDF procedure can hide the received SUCI before the home UDM 370 can process the request, thus obtaining the SUPI and MESSAGE_TIME. For SUCI replay attack detection from the network side in step 5, the home UDM 370 can compare the received MESSAGE_TIME with the current UTC-based time and perform the following exemplary determination process:

[0137] - If the received MESSAGE_TIME is less than the current UTC-based time minus the predetermined maximum delay time (denoted as MAX_DELAY), the home UDM 370 can respond with a fault code or discard and stop processing the message. MAX_DELAY represents, for example, a maximum transmission time threshold. For example, MAX_DELAY can be predetermined based on the estimated data transmission rate between UE 310 and UDM 370. MAX_DELAY can be further adjusted as needed.

[0138] - If the received MESSAGE_TIME is greater than or equal to the current UTC-based time minus MAX_DELAY, and less than the current UTC-based time, then the home UDM 370 can be configured to select the SUPI-based authentication method, generate an AV, and continue. Figure 12 The remaining authentication steps.

[0139] Figure 12 In the logic and data flow 1200, except for steps 1-5, the remaining steps essentially perform the authentication process, which corresponds to... Figure 5 The logic and corresponding steps in the data flow 500, except that step 11 may not require the UE-side SQN to be involved. MS The update and step 18 may not require SQN that does not involve the network side. MS Update. These steps are in... Figure 12 The above summarizes and combines... Figure 5 The explanation has already been provided, so it will not be repeated here.

[0140] Similarly, Figure 13The diagram illustrates the logic and data flow 1300 of a registration / authentication process initiated by UE 310 using a network-assigned temporary identifier, for example, via a previous registration and authentication process (e.g., from...). Figure 12 The GUTI obtained in step 21) of the SUCI registration process shown. Figure 13 The steps are similar to Figure 7 The steps, except that steps 1-5 use hidden timestamps instead of SQNs. MS (as in) Figure 12 Steps 1-5 are described above. Step 5 includes a process for detecting SUCI replay attacks, similar to... Figure 12 The logic and data flow 1200 shown in step 5, as described in detail above, may not require the involvement of the SQN on the UE side in step 11. MS Update, and in step 18, SQN that does not involve the network side may not be required. MS Update. That's it. Figure 13 The steps summarized in the previous section will not be repeated here.

[0141] Hidden SQN MS The combination of the hidden registration request message timestamp

[0142] In some other implementations, SQN can be used simultaneously. MS And the registration message timestamp. In other words, SQN MS Both the registration message timestamp and the SUPI can be combined and hidden to generate the SUCI for registration and authentication. This way, Figure 5 , 7 The various logical data streams in 9, 10, and 11 can be compared with... Figure 12 and 13 The logic and data flow in SQN are combined to form other logic and data flows. For example, SQN MS Both the registration message timestamp and the data can be transmitted to the SQN storage. MS It belongs to UDM370, and both the serial number and timestamp can be used to detect and respond to SUCI replay attacks.

[0143] The accompanying drawings and description provide specific exemplary embodiments and implementations. However, the described subject matter can be embodied in various different forms, and therefore, the covered or claimed subject matter is intended to be construed as not being limited to any of the exemplary embodiments set forth herein. A reasonably broad scope is intended for the claimed or covered subject matter. Furthermore, for example, the subject matter can be embodied as a method, apparatus, component, system, or non-transitory computer-readable medium for storing computer code. Therefore, embodiments can take the form of, for example, hardware, software, firmware, storage media, or any combination thereof. For example, the above-described method embodiments can be implemented by a component, apparatus, or system including a memory and a processor by executing computer code stored in the memory.

[0144] Throughout the specification and claims, terms may have implied or implied meanings in the context, in addition to their expressly stated meanings. Similarly, the phrase "in one embodiment / implementation" as used herein does not necessarily refer to the same embodiment, and the phrase "in another embodiment / implementation" as used herein does not necessarily refer to a different embodiment. For example, the claimed subject matter is intended to include, in whole or in part, a combination of exemplary embodiments.

[0145] Generally, terms can be understood at least in part from their use in context. For example, the terms “and,” “or,” and “and / or” as used herein can include a variety of meanings, which can depend at least in part on the context in which they are used. Typically, “or” (if used to relate a list, such as A, B, or C) is intended to mean: A, B, and C, in the sense of inclusion; and A, B, or C, in the sense of exclusivity. Furthermore, the term “one or more” as used herein depends at least in part on the context and can be used to describe any feature, structure, or characteristic in a singular sense, or a combination of features, structures, or characteristics in a plural sense. Similarly, the terms “a,” “an,” or “the” can be understood to convey either a singular or a plural usage, depending at least in part on the context. Moreover, the term “based on” can be understood to not necessarily convey an exclusive set of factors, but rather to allow for the presence of additional factors that are not necessarily explicitly described, again depending at least in part on the context.

[0146] Throughout this specification, references to features, advantages, or similar language do not imply that all features and advantages achievable with this solution should be included in any single implementation thereof. Rather, language relating to features and advantages is understood to mean that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of this solution. Therefore, throughout this specification, discussions of features and advantages, as well as similar language, may, but do not necessarily, refer to the same embodiment.

[0147] Furthermore, in one or more embodiments, the features, advantages, and characteristics of this solution can be combined in any suitable manner. Those skilled in the art will recognize that, based on the description herein, this solution can be implemented without one or more specific features or advantages of a particular embodiment. In other instances, additional features and advantages that may not be present in all embodiments of this solution may be recognized in certain embodiments.

Claims

1. A method for authenticating a second network element to access the communication network, performed by a first network element of the communication network, the method comprising: Receive authentication messages initiated from the second network element; The authentication message is hidden to obtain the hidden serial number maintained by the second network element and the hidden user identifier of the second network element; If the first network element does not store the de-hiding sequence number maintained by the second network element, the obtained de-hiding sequence number is stored in the first network element; If the first network element has already stored the de-hiding sequence number maintained by the second network element, the obtained de-hiding sequence number is compared with the de-hiding sequence number already stored in the first network element, wherein... If the obtained de-hiding sequence number is less than or equal to the de-hiding sequence number already stored in the first network element, the authentication message is discarded; if the obtained de-hiding sequence number is greater than the de-hiding sequence number already stored in the first network element, an authentication method is determined, a new sequence number is generated on the first network element side, and an authentication vector is generated based on the new sequence number. Send the authentication vector to the second network element; and When an authentication response message for the authentication vector is received from the second network element, the de-hiding sequence number stored in the first network element is replaced with the new sequence number.

2. The method according to claim 1, wherein, After replacing the hidden serial number stored in the first network element with the new serial number, the method further includes: Receive an authentication failure message from the second network element, wherein the authentication failure message is used to indicate that the second network element has detected a sequence number synchronization failure; A re-authentication vector is generated based on the stored, replaced, de-hidden sequence number; and The re-authentication vector is sent to the second network element.

3. The method according to claim 1, wherein, De-hiding the authentication message to obtain the de-hiding serial number and the de-hiding user identifier includes: Obtain the hidden identifier of the second network element from the authentication message; Decrypt the hidden identifier to obtain the decrypted composite data item; and Extract the dehidden user identifier and the dehidden serial number from the decrypted composite data item.

4. The method according to claim 3, further comprising: Extract a type indicator from the authentication message, wherein the type indicator is used to indicate the type of the hidden identifier; and Before decrypting the hidden identifier, the type indicator is determined to indicate that the hidden identifier includes a hidden composite data item, wherein the hidden composite data item includes a hidden user identifier and a hidden serial number.

5. The method of claim 4, wherein when indicating that the hidden identifier is a composite data item, the type indicator includes a unique value, wherein, The unique value is used to indicate that the hidden identifier includes a hidden combination of user identifier and serial number.

6. The method according to claim 4, wherein, The hidden identifier is encapsulated in the user hidden identifier SUCI.

7. The method according to claim 3, wherein, The decrypted composite data item includes the dehidden user identifier concatenated with the dehidden serial number.

8. The method according to claim 3, wherein, The decrypted composite data item includes the dehidden user identifier intertwined with the dehidden serial number.

9. The method according to claim 3, wherein, The hidden identifier is decrypted using the Elliptic Curve Integrated Encryption scheme ECIES to obtain the decrypted composite data item.

10. The method according to claim 3, wherein, The process of removing the hidden user identifier includes the user's permanent identifier SUPI.

11. The method according to claim 1, wherein, The first network element includes at least one of the unified data management (UDM) or authentication credential repository and processing function (ARPF) of the communication network, and the second network element includes user equipment (UE).

12. The method according to claim 1, wherein, The authentication message includes one of the following: The registration request message initiated by the first network element; or The first network element responds to the identity response message sent from the identity request from the communication network.

13. The method according to claim 1, wherein, The authentication vector is sent to the second network element via at least one other intermediate network element of the communication network.

14. A network element comprising a processor configured to implement the method according to any one of claims 1-13.

15. A computer-readable program medium having computer code stored thereon, which, when executed by a processor, causes the processor to implement the method according to any one of claims 1-13.

Citation Information

Patent Citations

  • Clone-resistant mutual authentication in a radio communication network

    WO2006064359A1