A key update method and related apparatus

By generating and updating application keys through a network server, the problems of low key update efficiency and high network signaling overhead in existing technologies are solved, and an efficient and secure key update process is achieved.

CN116709311BActive Publication Date: 2026-02-13CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310827928.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-06
Publication Date
2026-02-13
Estimated Expiration
2043-07-06

AI Technical Summary

Technical Problem

In existing technologies, the key update method in 5G networks leads to the updating of the entire key system, which reduces efficiency and increases network signaling overhead and communication system load.

Method used

The network server generates a new application key and sends a key update message. The terminal device generates a third application key based on the basic information, decrypts the response message using the second application key, and saves the new key and its lifecycle.

Benefits of technology

It improves key update efficiency, reduces unnecessary network signaling overhead, lowers the load on the communication system, and enhances system stability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116709311B_ABST
    Figure CN116709311B_ABST
Patent Text Reader

Abstract

The application discloses a key updating method and related device, and relates to the field of network security and technology.In the application, a network server generates a new second application key based on a first application key, and sends a key updating message carrying basic information required for generating the second application key to a terminal device, then receives a key updating response message encrypted by a third application key returned by the terminal device, wherein the third application key is generated by the terminal device based on the first application key and the basic information, finally, the network server decrypts the key updating response message by using the second application key, and saves the second application key and a corresponding second life cycle when the decryption is successful.In this way, the key updating efficiency is improved, unnecessary network signaling overhead is reduced, and the load pressure of the communication system is reduced without triggering the main authentication and only updating the key of the application server with the expired key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of network security and technology, and in particular to a key update method and related apparatus. Background Technology

[0002] In the fifth-generation (5G) mobile communication network architecture, the Authentication and Key Management for Applications (AKMA) service relies on the authentication capabilities of the 5G network to provide network information security protection for communication between user equipment (UE) and the application layer.

[0003] In existing technologies, after primary authentication, the AKMA service generates an AUSF key (K) through the Authentication Server Function (AUSF). AUSF ), AKMA will be based on K AUSF Derived AKMA key (K AKMA ), and K AKMA Send it to the AKMA Anchor Function (AAnF) network element, and the AAnF network element will use K... AKMA Derive the Application Function Key (K) for the UE AF The AF network element sends the key update message to the UE, and the UE updates the key according to the key update message, so that the AF and UE can communicate based on the key update message. AF To conduct secure communication.

[0004] When K AF Upon expiration, AKMA triggers master authentication to update K. AUSF and K AKMA AAnF network elements will be based on the new K AKMA Generate a new K AF However, using this key update method updates the entire key system, causing changes to the keys K of other AFs stored on network-side devices and terminals. AF The changes reduce the efficiency of key updates; secondly, since the UE involves multiple AFs, there may be multiple triggers of master authentication, resulting in unnecessary network signaling overhead, which increases the load on the communication system.

[0005] Therefore, a new key update method is needed to address the above problems. SUMMARY

[0006] The application provides a key update method and related device to improve the efficiency of key update, reduce network signaling overhead in the key update process, and reduce the load pressure of a communication system.

[0007] In a first aspect, an embodiment of the application provides a key update method, comprising:

[0008] When the first application key has reached a corresponding first life cycle, a network server generates a new second application key based on the first application key and in combination with preset key update parameters;

[0009] The network server sends a key update message to a terminal device using the first application key, and the key update message carries basic information required for generating the second application key;

[0010] The network server receives a key update response message encrypted by a third application key returned by the terminal device; the third application key is generated by the terminal device based on the basic information and in combination with the first application key after receiving the key update message;

[0011] The network server decrypts the key update response message using the second application key, and saves the second application key and a corresponding second life cycle when the decryption is successful.

[0012] In a second aspect, an embodiment of the application further provides a key update method, comprising:

[0013] A terminal device receives a key update message sent by a network server; wherein the terminal device uses a first application key, and the key update message is sent by the network server after generating a new second application key; the second application key is generated by the network server based on the first application key and in combination with preset key update parameters after the first application key reaches a corresponding first life cycle;

[0014] Obtains basic information carried in the key update information and required for generating the second application key, and generates a third application key based on the basic information;

[0015] Sends a key update response message encrypted by the third application key to the network server, so that the network server saves the second application key and a corresponding second life cycle when decrypting the key update response message using the second application key is successful.

[0016] In a third aspect, an embodiment of the application further provides a key update device, comprising:

[0017] The key generation module is configured to generate a new second application key based on the first application key and in combination with a preset key update parameter when the first application key has reached a corresponding first life cycle;

[0018] The message sending module is configured to send, by the network server, a key update message to the terminal device using the first application key, the key update message carrying basic information required for generating the second application key.

[0019] The response receiving module is configured to receive, by the network server, a key update response message encrypted by the third application key returned by the terminal device, the third application key being generated by the terminal device based on the basic information and in combination with the first application key after receiving the key update message.

[0020] The key saving module is configured to decrypt, by the network server, the key update response message using the second application key, and save the second application key and a corresponding second life cycle when the decryption is successful.

[0021] Optionally, before the network server sends the key update message to the terminal device using the first application key, the message sending module is further configured to:

[0022] The network server acquires key usage permission information of the terminal device.

[0023] Based on the key usage permission information, the network server determines the terminal device having the first application key usage permission, and sends the key update message to the terminal device.

[0024] Optionally, the key update message carries the basic information required for generating the second application key, and the message sending module is further configured to:

[0025] The key update message at least carries an application identifier corresponding to the first application key and a key update parameter encrypted by the first application key.

[0026] Optionally, after saving the second application key and the corresponding second life cycle, the key saving module is further configured to:

[0027] The network server sends a key matching success message to the terminal device.

[0028] Optionally, after the network server sends the key update message to the terminal device using the first application key, the message sending module is further configured to:

[0029] If the network server fails to send the key update message, a first alarm information is generated, wherein the first alarm information at least includes a key identifier corresponding to the first application key, a device identifier corresponding to the terminal device, and a sending time of the key update message.

[0030] In a fourth aspect, the embodiments of the present application further provide a key updating device, comprising:

[0031] a message receiving module, configured to receive a key updating message sent by a network server by a terminal device; wherein the terminal device uses a first application key, and the key updating message is sent by the network server after generating a new second application key, and the second application key is generated by the network server based on the first application key and in combination with a preset key updating parameter after the first application key reaches a corresponding first life cycle;

[0032] a key generating module, configured to obtain basic information required for generating the second application key carried in the key updating information, and generate a third application key based on the basic information;

[0033] an updating response module, configured to send a key updating response message encrypted by the third application key to the network server, so that the network server saves the second application key and a corresponding second life cycle when the key updating response message is decrypted successfully by the second application key.

[0034] Optionally, the basic information at least includes an application identifier corresponding to the network server, the key updating parameter encrypted by the first application key, and the key generating module is further configured to:

[0035] obtain the first application key based on the application identifier;

[0036] decrypt the encrypted key updating parameter by using the first application key to obtain the decrypted key updating parameter;

[0037] generate the third application key by using a preset key updating algorithm in combination with the key updating parameter based on the first application key.

[0038] Optionally, after sending the key updating response message encrypted by the third application key to the network server, the updating response module is further configured to:

[0039] receive a key matching success message sent by the network server;

[0040] save the third application key.

[0041] Optionally, after sending the key updating response message encrypted by the third application key to the network server, the updating response module is further configured to:

[0042] if the sending of the encrypted key updating response message to the network server fails, generate second alarm information; wherein the second alarm information at least includes a key identifier corresponding to the third application key, an application identifier corresponding to the first application key, and a sending time of the key updating response message.

[0043] In a fifth aspect, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory and executable by the processor, and the processor implements the method of any one of the first aspect and the second aspect when executing the computer program.

[0044] In a sixth aspect, a computer readable storage medium is provided, which stores a computer program, and the computer program, when executed by a processor, implements the steps of the method of any one of the first aspect and the second aspect.

[0045] In a seventh aspect, a computer program product is provided, which, when invoked by a computer, causes the computer to execute the method of the first aspect and the second aspect.

[0046] In the embodiments of the present application, the network server generates a new second application key based on the first application key, sends a key update message carrying the basic information required for generating the second application key to the terminal device, receives a key update response message returned by the terminal device, and finally decrypts the key update response message using the second application key, and saves the second application key and the corresponding second life cycle when the decryption is successful.

[0047] In this way, when updating the key, the primary authentication does not need to be triggered, and the key update is only performed for the application server whose key expires, and the application keys corresponding to other application servers are not updated, thereby improving the key update efficiency, reducing unnecessary network signaling overhead, and reducing the load pressure of the communication system. Moreover, by updating the specific key, unknown risks caused by updating the entire key system in the primary authentication process are avoided, and the system stability is improved. Finally, in the key update process, the network server verifies the key generated by the terminal device, ensures the consistency of the keys generated on both sides of the network server and the terminal device, and strengthens the security guarantee of the key update process. BRIEF DESCRIPTION OF DRAWINGS

[0048] Figure 1 FIG. 1 is a schematic diagram of a system architecture in the embodiments of the present application;

[0049] Figure 2 FIG. 2 is a schematic diagram of a key update method in the embodiments of the present application;

[0050] Figure 3 FIG. 3 is a schematic diagram of a method for determining whether the first application key has reached the corresponding first life cycle in the embodiments of the present application;

[0051] Figure 4 FIG. 4 is a schematic diagram of a process for the network server to determine the terminal device to which the key update message needs to be sent in the embodiments of the present application;

[0052] Figure 5 A flowchart of a process for a network server to decrypt a key update message in an embodiment of the present application;

[0053] Figure 6 A flowchart of a process for another key update method in an embodiment of the present application;

[0054] Figure 7 A flowchart of a process for a terminal device to generate a third application key in an embodiment of the present application;

[0055] Figure 8 A flowchart of a process for a key update method in an embodiment of the present application;

[0056] Figure 9 A structural diagram of a key update device in an embodiment of the present application;

[0057] Figure 10 A structural diagram of another key update device in an embodiment of the present application;

[0058] Figure 11 A structural diagram of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0059] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions of the present application will be described below in connection with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments described in the present application document, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the technical solutions of the present application.

[0060] The terms "first", "second", and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0061] Some terms in the embodiments of the present application are explained below to facilitate understanding by those skilled in the art.

[0062] (1) Application Identity Authentication and Key Management Service (AKMA): a security protection service function introduced in Release 16 of the 3rd Generation Partnership Project (3GPP) to support authentication and key management based on 3GPP credentials in 5G, which can ensure the security between a user equipment (UE) and an application function entity (AF).

[0063] (2) Primary authentication: an identity authentication procedure initiated by a terminal when accessing a network, which verifies the legitimacy of the identity of the terminal through bidirectional authentication with a core network.

[0064] (3) AKMA key anchoring function (AAnF): a function in a network server that generates an application key to facilitate a UE and an AF to conduct a session based on the application key and maintain the security of the session.

[0065] (4) Application key: a credential for establishing a connection between entities of a UE and an AF for a session, which is generated by the AAnF based on a base key and an application server identifier.

[0066] (5) Lifetime: a time period during which a key generated at a time point can be used; when the use duration of the key reaches its lifetime, the key needs to be destroyed or updated, thereby enhancing the security of the key.

[0067] The design idea of the embodiments of the present application is briefly introduced as follows:

[0068] In the 5G network architecture, an application identity authentication and key management service is applied, relying on the authentication capability of the 5G network to provide an application key between a user equipment (UE) and an application server and to provide information security protection for the communication between the two.

[0069] In the prior art, after a terminal device conducts primary authentication, an authentication server function (AUSF) derives an AUSF key (K AUSF ), the AKMA derives an AKMA key (K AUSF ) based on K AKMA , and sends K AKMA to an AKMA key anchoring function (AAnF) network element, the AAnF network element derives an application key (K AF ) and a lifetime for the UE based on K AKMA , and sends them to an application function entity (AF), at the same time, the AAnF network element sends a key update message to the UE, and the UE updates the key according to the key update message, so that the AF and the UE conduct secure communication based on K AF .

[0070] When K AF expires, the AKMA triggers primary authentication to update K AUSF and K AKMA , and the AAnF network element generates a new K AF based on the new K AKMA . However, this key update method updates the entire key system, resulting in the storage of other AF keys K AFChanges, thereby reducing the efficiency of key update; second, because the UE involves multiple AFs, there may be multiple triggers for primary authentication, resulting in unnecessary network signaling overhead, thereby increasing the load pressure of the communication system.

[0071] Therefore, in the embodiments of the present application, a new key update method, device, electronic equipment and storage medium are proposed.

[0072] In the embodiments of the present application, the network server generates a new second application key based on the first application key, and sends a key update message carrying the basic information required for generating the second application key to the terminal device, then receives the key update response message encrypted by the third application key returned by the terminal device, wherein the third application key is generated by the terminal device based on the first application key and the basic information, finally, the network server decrypts the key update response message using the second application key, and when the decryption is successful, saves the second application key and the corresponding second life cycle.

[0073] Through this technical solution, first, when performing key update, primary authentication is not triggered, only the application server whose key expires is updated, and the application keys corresponding to other application servers are not updated, thereby improving the key update efficiency, reducing unnecessary network signaling overhead, and reducing the load pressure of the communication system; second, the unknown risks brought by updating the entire key system in the primary authentication process are avoided, and the system stability is improved; finally, in the key update process, the network server verifies the key generated by the terminal, thereby improving the security guarantee of the key update process.

[0074] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application, and the embodiments of the present application and the features in the embodiments can be combined with each other without conflict.

[0075] Reference is made to Figure 1As shown in the figure, it is a system architecture schematic diagram in the embodiment of the present application, which contains an application server 101, a network server 102, and a terminal device 103. The application server 101 and the terminal device 103 have a session based on an application key, and the network server detects whether the application key is expired. When the network server detects that the first application key is expired, the network server 102 generates a new second application key based on the first application key, and sends a key update message carrying the basic information required for generating the second application key to the terminal device 103 using the first application key, then receives a key update response message encrypted by a third application key returned by the terminal device 103, wherein the third application key is generated by the terminal device 103 based on the first application key and the basic information, finally, the network server 102 decrypts the key update response message using the second application key, and when the decryption is successful, saves the second application key and the corresponding second life cycle.

[0076] Based on the above system architecture, refer to Figure 2 As shown in the figure, it is a flowchart of a key update method in the embodiment of the present application. The following will be described in combination with the accompanying Figure 2 The specific execution steps will be described in detail as follows:

[0077] Step 20: When the first application key has reached the corresponding first life cycle, the network server generates a new second application key based on the first application key and in combination with a preset key update parameter.

[0078] The value of the key update parameter can be a random number or a time source, so that different key update parameters are used in each key update, thereby generating different application keys.

[0079] Specifically, in the embodiment of the present application, before step 20 is executed, it is necessary to judge whether the first application key has reached the corresponding first life cycle, and the specific judgment method is as follows:

[0080] If the existing time length of the first application key is less than the first life cycle, it is determined that the first application key has not reached the first life cycle.

[0081] If the existing time length of the first application key is not less than the first life cycle, it is determined that the first application key has reached the first life cycle.

[0082] When it is determined that the first application key has reached the corresponding first life cycle, the network server generates a new second application key based on the first application key and in combination with a preset key update parameter, using a preset key update algorithm.

[0083] For example, refer to Figure 3As shown, it is a method schematic diagram for determining whether the first application key has reached the corresponding first life cycle in the embodiment of the present application. Assuming that the first life cycle is 30 days, if the first application key has existed for 20 days, it is determined that the first application key has not reached the corresponding first life cycle. If the first application key has existed for 31 days, it is determined that the first application key has reached the corresponding first life cycle, and then a new second application key K AF , in combination with the preset key update parameter S, the AAnF network element in the network server can generate a new second application key K AF′ using a key derivation function (KDF) or a pseudo random function (PRF).

[0084] K AF′ = KDF(K AF , S)

[0085] Step 21: The network server sends a key update message to the terminal device using the first application key.

[0086] The key update message carries the basic information required for generating the second application key.

[0087] Specifically, the network server sends a connection request to the terminal device using the first application key, and after successfully connecting with the terminal device, sends a key update message to the terminal device. The key update message carries the basic information required for generating the second application key, at least including: the application identifier corresponding to the first application key, the key update parameter encrypted by the first application key.

[0088] For example, the key update information carries the first application key K AF , the application identifier A001 corresponding to the first application key, the key update parameter S ′ encrypted by the first application key using the data encryption standard (DES) algorithm, and a key update indicator, wherein the key update indicator is used to indicate that the application key corresponding to the application identifier A001 needs to be updated.

[0089] In the embodiment of the present application, before step 21 is performed, the network server can also perform the following steps. Referring to Figure 4 , it is a flow schematic diagram for the network server to determine the terminal device that needs to send a key update message in the embodiment of the present application. The following will be described in detail in combination with Figure 4 .

[0090] Step 210: The network server obtains the key usage permission information of the terminal device.

[0091] In this embodiment of the application, the AAnF network element in the network server generates a key usage permission information table corresponding to the application key and the SUPI information based on the user permanent identifier (SUPI) information obtained from the Unified Data Management (UDM) network element.

[0092] Step 211: Based on the key usage permission information, determine the terminal device with the first application key usage permission, and send a key update message to the terminal device.

[0093] In this embodiment, the AAnF network element, based on the generated key usage permission information table and according to the correspondence between SUPI information and terminal devices, determines the device possessing the first application key K. AF Access to the terminal device is granted, and a key update message is sent to the terminal device.

[0094] For example, K is determined based on the key usage permission information table. AF For the corresponding terminal device U001, it is determined that it has K AF If the terminal device with access rights is U001, then a Re-keying Request message is sent to U001, carrying the key. AF The corresponding application identifier A001, based on K AF Update parameters using the key encrypted with the DES algorithm.

[0095] If the network server fails to send the key update message during step 211, a first alarm message is generated; wherein the first alarm message includes at least: the key identifier corresponding to the first application key, the device identifier corresponding to the terminal device, and the sending time of the key update message.

[0096] For example, if the network server fails to send a key update message, an alarm message Warning1 is generated, which includes the following information:

[0097] First application key K AF The corresponding application identifier is A001, the device identifier corresponding to the terminal device is U001, the key update information was sent at 10:43:20 on June 1, 2023, and the reason for the failure to send the information was signal interruption.

[0098] It is worth mentioning that the steps 210 and 211 are not necessary to be executed, and the steps 210 and 211 can not be executed in the case that the network server has determined the target terminal device to which the key update message is sent.

[0099] Step 22: The network server receives the key update response message encrypted by the third application key returned by the terminal device.

[0100] The third application key is generated by the terminal device based on the basic information and the first application key after receiving the key update message.

[0101] For example, the network server receives the key update response message Rekeying Response returned by the terminal device, which is encrypted by the terminal device based on the third application key K AF″ using the DES algorithm.

[0102] Step 23: The network server decrypts the key update response message using the second application key, and saves the second application key and the corresponding second life cycle when the decryption is successful.

[0103] In the embodiment of the application, the network server decrypts the key update message, and the following steps are executed. Referring to Figure 5 , which is a flowchart of the decryption of the key update message by the network server in the embodiment of the application, the following will be described in detail in combination with Figure 5 the specific operations performed:

[0104] Step 230: The network server decrypts the key update response message using the second application key, and executes step 231 if the decryption is successful, or executes step 232.

[0105] For example, the network server can decrypt the key update response message using the DES algorithm corresponding to the terminal device.

[0106] It can be understood that if the decryption is successful, it proves that the third application key generated by the terminal device is consistent with the second application key generated by the network server, otherwise, it proves that the third application key generated by the terminal device is inconsistent with the second application key generated by the network server.

[0107] Step 231: Save the second application key and the corresponding life cycle.

[0108] Specifically, after the network server successfully decrypts the key update response message, the third application key identifier carried in the key update response message is obtained, and the second application key and the corresponding second life cycle are saved.

[0109] Step 232: Delete the second application key.

[0110] In the embodiment, after the second application key and the corresponding second life cycle are saved, the network server further sends a key matching success message to the terminal device.

[0111] In the embodiment, the key matching success message carries a key identifier K003 corresponding to the third application key, wherein the K003 is obtained from a key update response message Rekeying Response returned by the terminal device.

[0112] On the other hand, referring to Figure 6 , which is a flowchart of another key update method in the embodiment, the specific execution steps are described in detail as follows. Figure 6

[0113] Step 60: The terminal device receives the key update message sent by the network server.

[0114] The terminal device uses the first application key, and the key update message is sent by the network server after a new second application key is generated. The second application key is generated by the network server based on the first application key and a preset key update parameter after the first application key reaches the corresponding first life cycle.

[0115] In the embodiment, the terminal device receives the connection request sent by the network server, establishes a connection with the network server after verification, and then receives the key update message sent by the network server.

[0116] Step 61: Obtain the basic information carried in the key update information for generating the second application key, and generate the third application key based on the basic information.

[0117] The basic information at least includes an application identifier corresponding to the first application key and a key update parameter encrypted by the first application key.

[0118] Specifically, when step 61 is executed, the terminal device performs the following operations. Referring to Figure 7 , which is a flowchart of the terminal device generating the third application key in the embodiment, the specific execution steps are described in detail as follows. Figure 7

[0119] Step 610: Obtain the first application key based on the application identifier.

[0120] ​​In this embodiment, the terminal device obtains and identifies the key update indicator carried in the key update message, determines to start the key update process, searches for the corresponding key identifier K_ID from the key information database based on the application identifier AF_ID corresponding to the first application key, and obtains the corresponding first application key K based on K_ID. AF .

[0121] Step 611: Decrypt the encrypted key update parameters using the first application key to obtain the decrypted key update parameters.

[0122] For example, based on the first application key K AF The DES algorithm is used to update the parameter S of the encrypted key. ′ Decrypt the key to obtain the decrypted key update parameter S.

[0123] Step 612: Based on the first application key and combined with the key update parameters, generate the third application key using a preset key update algorithm.

[0124] For example, based on the first application key K AF Combining the key update parameter S, the third application key K is generated using the KDF function, a key update algorithm corresponding to the terminal device. AF″ The specific key derivation formula is as follows:

[0125] K AF″ =KDF(K AF ,S)

[0126] Step 62: Send a key update response message encrypted with the third application key to the network server, so that when the network server successfully decrypts the key update response message using the second application key, it saves the second application key and the corresponding second lifecycle.

[0127] In this embodiment of the application, the key update response message carries a third application key K. AF″ The corresponding key identifier is K003.

[0128] Specifically, after sending a key update response message encrypted with a third application key to the network server, the terminal device can also perform the following steps:

[0129] Step 620: Receive a key matching success message from the network server.

[0130] Specifically, after receiving the key matching success message sent by the network server, the terminal device obtains the key identifier carried in it, verifies that the key identifier is the identifier corresponding to the third application key, and then determines that the third application key is consistent with the second application key generated by the network server.

[0131] Step 621: save the third application key.

[0132] Further, the terminal device further performs the following operations when sending the encrypted key update response message to the network server:

[0133] If the sending of the encrypted key update response message to the network server fails, the terminal device generates a second alarm information.

[0134] The second alarm information at least includes: a key identifier corresponding to the third application key, an application identifier corresponding to the first application key, and a sending time of the key update response message.

[0135] For example, if the terminal device fails to send the key update message, the terminal device generates an alarm information Warning2, which includes the following information:

[0136] The key identifier K003 corresponding to the third application key, the application identifier A001 corresponding to the first application key, the sending time of the key update response message: 2023-06-01 11:40:20, and the sending failure reason: connection interruption.

[0137] Based on the above embodiments, refer to Figure 8 The figure is a schematic diagram of the overall flow of a key update method in the embodiments of the present application, which specifically includes:

[0138] Step 801: when the first application key has reached the corresponding first life cycle, the network server generates a new second application key based on the first application key and in combination with a preset key update parameter.

[0139] Step 802: the network server obtains key usage permission information of the terminal device.

[0140] Step 803: the network server determines the terminal device having the usage permission of the first application key based on the key usage permission information.

[0141] Step 804: the network server sends a key update message to the terminal device having the usage permission of the first application key.

[0142] Step 805: the terminal device receives the key update message sent by the network server.

[0143] Step 806: the terminal device obtains the basic information required for generating the second application key carried in the key update information, wherein the basic information at least includes an application identifier corresponding to the network server and the key update parameter encrypted by the first application key.

[0144] Step 807: the terminal device obtains the first application key based on the application identifier.

[0145] Step 808: The terminal device decrypts the encrypted key update parameter by using the first application key, and obtains the decrypted key update parameter.

[0146] Step 808: The terminal device generates a third application key by using a preset key update algorithm based on the first application key and in combination with the key update parameter.

[0147] Step 810: The terminal device sends a key update response message encrypted by the third application key to the network server.

[0148] Step 811: The network server receives the key update response message encrypted by the third application key returned by the terminal device.

[0149] Step 812: The network server decrypts the key update response message by using the second application key, and saves the second application key and the corresponding second life cycle when the decryption is successful.

[0150] Step 813: The network server sends a key matching success message to the terminal device.

[0151] Step 814: The terminal device receives the key matching success message sent by the network server.

[0152] Step 815: The terminal device saves the third application key.

[0153] Based on the same technical concept, referring to Figure 9 The embodiments of the present application provide a key update device, which comprises:

[0154] The key generation module 901 is configured to generate a new second application key based on a first application key and in combination with a preset key update parameter when the first application key has reached a corresponding first life cycle.

[0155] The message sending module 902 is configured to send a key update message to a terminal device using the first application key by the network server, and the key update message carries basic information required for generating the second application key.

[0156] The response receiving module 903 is configured to receive a key update response message encrypted by a third application key returned by the terminal device, and the third application key is generated by the terminal device based on the basic information and in combination with the first application key after receiving the key update message.

[0157] The key saving module 904 is configured to decrypt the key update response message by using the second application key, and save the second application key and the corresponding second life cycle when the decryption is successful.

[0158] Optionally, before the network server sends the key update message to the terminal device using the first application key, the message sending module 902 is further configured to:

[0159] The network server obtains the key usage permission information of the terminal device.

[0160] Based on the key usage permission information, the terminal device with the first application key usage permission is determined, and the key update message is sent to the terminal device.

[0161] Optionally, the key update message carries the basic information required to generate the second application key, and the message sending module 902 is further configured to:

[0162] The key update message at least carries the application identifier corresponding to the first application key and the key update parameter encrypted by the first application key.

[0163] Optionally, after saving the second application key and the corresponding second life cycle, the key saving module 904 is further configured to:

[0164] The network server sends a key matching success message to the terminal device.

[0165] Optionally, after the network server sends the key update message to the terminal device using the first application key, the message sending module 902 is further configured to:

[0166] If the network server fails to send the key update message, a first alarm information is generated; wherein the first alarm information at least includes: the key identifier corresponding to the first application key, the device identifier corresponding to the terminal device, and the sending time of the key update message.

[0167] Based on the same technical concept, refer to Figure 10 The embodiments of the present application also provide a key update device, which comprises:

[0168] The message receiving module 1001 is configured to receive the key update message sent by the network server by the terminal device; wherein the terminal device uses the first application key, and the key update message is sent by the network server after generating a new second application key, and the second application key is generated by the network server based on the first application key and in combination with a preset key update parameter after the first application key reaches a corresponding first life cycle.

[0169] The key generation module 1002 obtains the basic information required to generate the second application key carried in the key update information, and generates a third application key based on the basic information.

[0170] Update response module 1003: Sends a key update response message encrypted with the third application key to the network server, so that when the network server successfully decrypts the key update response message using the second application key, it saves the second application key and the corresponding second lifecycle.

[0171] Optionally, the basic information includes at least the application identifier corresponding to the first application key, and the key update parameters encrypted with the first application key. The key generation module 1002 is also used for:

[0172] Obtain the first application key based on the application identifier;

[0173] The encrypted key update parameters are decrypted using the first application key to obtain the decrypted key update parameters;

[0174] Based on the first application key and combined with the key update parameters, a third application key is generated using a preset key update algorithm.

[0175] Optionally, after sending the key update response message encrypted with the third application key to the network server, the update response module 1003 is further configured to:

[0176] Receive a key matching success message from the network server;

[0177] Save the third application key.

[0178] Optionally, the update response module 1003 sends a key update response message encrypted with a third application key to the network server. The update response module 1003 is also used for:

[0179] If sending the encrypted key update response message to the network server fails, a second alarm message is generated; the second alarm message includes at least: the key identifier corresponding to the third application key, the application identifier corresponding to the first application key, and the sending time of the key update response message.

[0180] Based on the same technical concept, this application also provides an electronic device that can implement the key update method provided in the above embodiments of this application.

[0181] See Figure 11 As shown, the electronic device includes:

[0182] At least one processor 1101 and a memory 1102 connected to at least one processor 1101. In this embodiment, the specific connection medium between the processor 1101 and the memory 1102 is not limited. Figure 11 The example shown is the connection between processor 1101 and memory 1102 via bus 1100. Bus 1100 is... Figure 11The connection between the other components is indicated by a thick line, which is only illustrative and not limited. The bus 1100 can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, Figure 11 The bus 1100 is indicated by only one thick line, but it does not mean that there is only one bus or only one type of bus. Alternatively, the processor 1101 can also be called a controller, and the name is not limited.

[0183] In the embodiment of the present application, the memory 1102 stores instructions executable by the at least one processor 1101, and the at least one processor 1101 can execute the method of updating the key discussed above by executing the instructions stored in the memory 1102. The processor 1101 can implement the functions of various modules in the apparatus as shown in the apparatus. Figure 9 and Figure 10 The functions of various modules in the apparatus as shown in the apparatus.

[0184] The processor 1101 is the control center of the apparatus, and can connect various parts of the control device through various interfaces and lines, and process data and monitor the apparatus as a whole by running or executing instructions stored in the memory 1102 and calling data stored in the memory 1102.

[0185] In a possible design, the processor 1101 can include one or more processing units, and the processor 1101 can integrate an application processor and a modem processor, where the application processor mainly processes operating systems, user interfaces, and application programs, and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 1101. In some embodiments, the processor 1101 and the memory 1102 can be implemented on the same chip, and in some embodiments, they can also be implemented on separate chips respectively.

[0186] The processor 1101 can be a general-purpose processor, such as a CPU, a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, and can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method of updating the key disclosed in the embodiments of the present application can be directly embodied as execution by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0187] The memory 1102, as a non-volatile computer readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 1102 can include at least one type of storage medium, for example, can include flash memory, hard disk, multimedia card, card type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. The memory 1102 is any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but is not limited thereto. The memory 1102 in the embodiments of the present application can also be a circuit or any other device capable of realizing a storage function, used for storing program instructions and / or data.

[0188] By designing and programming the processor 1101, the code corresponding to the key update method introduced in the foregoing embodiments can be fixed in the chip, so that the chip can execute the steps of the key update method shown in Figure 2 and Figure 6 when running. How to design and program the processor 1101 is a technology known to those skilled in the art, which will not be described here.

[0189] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions, when the computer instructions run on a computer, the computer instructions make the computer execute the key update method discussed above.

[0190] In some possible implementations, the various aspects of the key update method provided by the present application can also be implemented in the form of a program product, which includes program code for causing the control device to execute the steps of the key update method according to various exemplary embodiments of the present application described above in the specification when the program product runs on the device.

[0191] It should be noted that, although several units or sub-units of the apparatus are mentioned in the above detailed description, such a division is merely exemplary and not mandatory. Indeed, according to an embodiment of the application, the features and functionalities of two or more units described above can be embodied in one unit. Conversely, the features and functionalities of one unit described above can be further divided into units embodied by several units.

[0192] Moreover, although the operations of the method(s) herein can be described in a particular, sequential order, this order is not meant to be a limitation and is not intended to imply that

[0193] Those of skill in the art would understand that embodiments of the present application can be provided as a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, and the like) embodying computer readable program code.

[0194] The present application is described in reference to flow diagrams and / or block diagrams of methods, apparatus (systems) and computer program products according to this application. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagram and / or block diagram in which the flow diagram and / or block diagram and combinations of blocks in the flow diagrams and / or block diagrams can be implemented by computer program instructions. Figure 1 Means for carrying out any one or more of the functionality described in the flow diagram and / or block diagram block or blocks.

[0195] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagram and / or block diagram in which the flow diagram and / or block diagram and combinations of blocks in the flow diagrams and / or block diagrams can be implemented by computer program instructions. Figure 1 Means for carrying out any one or more of the functionality described in the flow diagram and / or block diagram block or blocks.

[0196] These computer program instructions can also be loaded into a computer or other programmable data processing devices, so that a series of operational steps are performed on the computer or other programmable data processing devices to generate computer-implemented processes, thus the instructions executed on the computer or other programmable data processing devices provide processes for implementing the functions specified in the flowchart Figure 1 one or more flows and / or blocks Figure 1 one or more blocks or steps of the functions specified in the flowchart

[0197] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application belong to the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.

Claims

1. A key update method characterized by comprising: The application comprises the following steps: When the first application key reaches the corresponding first life cycle, the network server generates a new second application key based on the first application key and a preset key update parameter; The network server sends a key update message to a terminal device using the first application key, and the key update message carries the basic information required for generating the second application key; wherein the basic information at least includes an application identifier corresponding to the first application key and a key update parameter encrypted by the first application key; The network server receives a key update response message encrypted by a third application key returned by the terminal device; the third application key is generated by the terminal device based on the basic information and the first application key after receiving the key update message; The network server decrypts the key update response message by using the second application key, and saves the second application key and the corresponding second life cycle when the decryption is successful.

2. The method of claim 1, wherein, Before the network server sends the key update message to the terminal device using the first application key, the network server further comprises the following steps: The network server obtains the key usage permission information of the terminal device; Based on the key usage permission information, the network server determines the terminal device having the usage permission of the first application key and sends the key update message to the terminal device.

3. The method of claim 1 or 2, wherein, After saving the second application key and the corresponding second life cycle, the network server further comprises the following steps: The network server sends a key matching success message to the terminal device.

4. The method of claim 1 or 2, wherein, After the network server sends the key update message to the terminal device using the first application key, the network server further comprises the following steps: If the network server fails to send the key update message, a first alarm information is generated; wherein the first alarm information at least includes a key identifier corresponding to the first application key, a device identifier corresponding to the terminal device, and a sending time of the key update message.

5. A key update method characterized by comprising: The terminal device receives a key update message sent by a network server; wherein the terminal device uses a first application key, and the key update message is sent by the network server after generating a new second application key, and the second application key is generated by the network server based on the first application key and a preset key update parameter after the first application key reaches a corresponding first life cycle; The terminal device obtains the basic information carried in the key update message and generates a third application key based on the basic information; wherein the basic information at least includes an application identifier corresponding to the first application key and a key update parameter encrypted by the first application key; The terminal device sends a key update response message encrypted by the third application key to the network server, so that the network server saves the second application key and the corresponding second life cycle when the decryption of the key update response message by using the second application key is successful. The step of generating a third application key based on the basic information comprises the following steps:

6. The method of claim 5, wherein, Based on the application identifier, a first application key is obtained; ​ decrypt the encrypted key update parameter by using the first application key, to obtain a decrypted key update parameter; generate the third application key by using a preset key update algorithm based on the first application key and in combination with the key update parameter.

7. The method of claim 5, wherein, After sending the key update response message encrypted by the third application key to the network server, the method further includes: receiving a key matching success message sent by the network server; saving the third application key.

8. The method of claim 7, wherein, After sending the key update response message encrypted by the third application key to the network server, the method further includes: generating a second alarm information if the sending of the encrypted key update response message to the network server fails, wherein the second alarm information at least includes a key identifier corresponding to the third application key, an application identifier corresponding to the first application key, and a sending time of the key update response message.

9. A key update apparatus characterized by comprising: The method includes: generating, by a network server, a new second application key based on a first application key and in combination with a preset key update parameter when the first application key has reached a corresponding first life cycle; sending, by the network server, a key update message to a terminal device using the first application key, wherein the key update message carries basic information required for generating the second application key, and the basic information at least includes an application identifier corresponding to the first application key and a key update parameter encrypted by the first application key; receiving, by the network server, a key update response message encrypted by a third application key returned by the terminal device, wherein the third application key is generated by the terminal device based on the basic information and in combination with the first application key after receiving the key update message; decrypting, by the network server, the key update response message by using the second application key, and saving the second application key and a corresponding second life cycle when the decryption is successful.

10. A key update apparatus characterized by comprising: The method includes: receiving, by a terminal device, a key update message sent by a network server, wherein the terminal device uses a first application key, and the key update message is sent by the network server after generating a new second application key, and the second application key is generated by the network server based on the first application key and in combination with a preset key update parameter after the first application key reaches a corresponding first life cycle; generating, by the terminal device, a third application key based on basic information carried in the key update message and required for generating the second application key, wherein the basic information at least includes an application identifier corresponding to the first application key and a key update parameter encrypted by the first application key; and An updating response module is configured to send a key updating response message encrypted by the third application key to the network server, so that the network server saves the second application key and the corresponding second life cycle when the key updating response message is successfully decrypted by the second application key.

11. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1-8.

12. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1-8.

13. A computer program product, characterised in that, The computer program product, when invoked by a computer, causes the computer to execute the method of any one of claims 1-8.

Citation Information

Patent Citations

  • Updating method, network side equipment, terminal and computer readable storage medium

    CN115706663A

  • Key updating method, network element, user equipment and storage medium

    CN115915124A