A privacy protection enhancement method and related apparatus

By introducing privacy-enhancing network elements into 5G mobile communication systems, and using the user terminal's private key and the network element's public key to encrypt and decrypt SUCI, the problem of complex customization of UDM network elements is solved, achieving efficient industry-specific privacy protection and simplifying the deployment and operation of operators.

CN116723502BActive Publication Date: 2026-07-31CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
Filing Date
2023-07-12
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

In existing technologies, the UDM network elements of 5G mobile communication systems need to be customized to meet the security requirements of different industries, which makes implementation complex and requires operators to invest a lot of resources. Furthermore, existing algorithm mechanisms are difficult to effectively protect user privacy.

Method used

At least one privacy-enhancing network element is introduced. The user terminal's private key and the privacy-enhancing network element's public key are used for encryption. Combined with the ECIES algorithm, the user hidden identifier SUCI is decrypted. The processing efficiency of the UDM network element is improved by identifying and selecting units.

Benefits of technology

It reduces the computational load of UDM, meets the industry's differentiated network access privacy protection and security requirements, simplifies the equipment customization and operator deployment and maintenance process, and is compatible with existing 3GPP privacy protection mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116723502B_ABST
    Figure CN116723502B_ABST
Patent Text Reader

Abstract

This application discloses a privacy protection enhancement method and related apparatus. By adding at least one privacy protection enhancement network element, each user terminal has a corresponding privacy protection enhancement network element, and then the SUCI can be decrypted through the privacy protection enhancement network element corresponding to the user terminal. This reduces the computational load of UDM and can also meet the differentiated network access privacy protection security requirements of various industries.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of network technology and security technology, and in particular to a method and related apparatus for enhancing privacy protection. Background Technology

[0002] With the development of mobile communication technology to the 5G era, 5G mobile communication systems have placed higher demands on security. To address the privacy concerns arising from the plaintext transmission of the International Mobile Subscriber Identifier (IMSI), which could lead to the leakage of user identity and location information, the 5G security standard document 3GPP TS 33.501 defines a mobile user privacy protection mechanism for the initial registration process. This mechanism employs a public-key encryption mechanism based on elliptic curve cryptography to encrypt the IMSI, and all of the above is implemented within the Unified Data Management (UDM) network element of the core network.

[0003] Because different industries have different security protection requirements for 5G mobile communication systems, current technologies use customized UDM network elements to meet the actual security needs of different industries. However, the algorithmic mechanisms for achieving the actual security needs of different industries are complex, and equipment manufacturers need to customize dedicated equipment for different industry users. Operators also need to invest in deployment, testing, operation and maintenance, which makes customized UDM difficult. Summary of the Invention

[0004] This application provides a privacy protection enhancement method and related apparatus, which can meet the differentiated network access privacy protection and security needs of various industries.

[0005] In a first aspect, one embodiment of this application provides a privacy protection enhancement system, the system comprising: a unified data management (UDM) network element and at least one privacy protection enhancement network element;

[0006] The UDM network element is used to receive a network access registration and authentication request sent by a user terminal, wherein the network access registration and authentication request includes at least a user hidden identifier (SUCI), and to determine a first privacy protection enhancement network element corresponding to the user terminal based on the network access registration and authentication request; and to send a decryption request to the first privacy protection enhancement network element, wherein the decryption request includes at least the SUCI.

[0007] The first privacy protection enhancement network element is used to receive the decryption request sent by the UDM network element, decrypt the SUCI, and send the decryption result of the SUCI to the UDM network element;

[0008] The UDM network element is also used to receive the decryption result of the SUCI sent by the first privacy protection enhancement network element, and to start authenticating the user terminal based on the decryption result of the SUCI.

[0009] Compared to existing technologies, this application adds at least one privacy protection enhancement network element, so that each user terminal has a corresponding privacy protection enhancement network element. This allows the SUCI to be decrypted through the privacy protection enhancement network element corresponding to the user terminal, reducing the computational load of UDM and meeting the differentiated network access privacy protection security requirements of various industries.

[0010] In one possible design, the UDM network element includes an identification unit and a selection unit;

[0011] The identification unit is configured to receive a network access registration and authentication request sent by a user terminal, wherein the network access registration and authentication request includes at least a user hidden identifier (SUCI), and determine the first privacy protection enhanced network element corresponding to the user terminal based on the network access registration and authentication request; and send the determination result to the selection unit.

[0012] The selection unit is used to send a decryption request to the first privacy-enhancing network element, and the decryption request includes at least the SUCI.

[0013] This application improves the processing efficiency of UDM network elements by dividing them into identification units and selection units, with each unit performing different designated functions.

[0014] In one possible design, the network access registration and authentication request also carries the public key of the first privacy-enhancing network element pre-stored by the user terminal; the identification unit is specifically used for:

[0015] The first privacy-enhancing network element is determined based on the public key of the first privacy-enhancing network element carried in the network access registration and authentication request.

[0016] This application improves the efficiency and accuracy of the identification unit in determining the first privacy-enhancing network element by pre-storing the public key of the corresponding first privacy-enhancing network element in the user terminal.

[0017] In one possible design, the SUCI included in the network access registration and authentication request is obtained by encrypting the user terminal's private key and the first privacy-enhancing network element's public key using the ECIES algorithm.

[0018] This application uses the user terminal's private key and the public key of the first privacy protection enhancement network element to encrypt the SUPI to obtain a securely encapsulated SUCI, thus avoiding data leakage problems after the SUCI is lost.

[0019] In one possible design, the selection unit is further configured to send the public key of the user terminal to the first privacy-enhancing network element;

[0020] The first privacy-enhancing network element is specifically used to decrypt the SUCI based on the private key of the first privacy-enhancing network element and the public key of the user terminal.

[0021] This application sends the user terminal's public key to the first privacy-enhancing network element through a selection unit, enabling the first privacy-enhancing network element to accurately decrypt SUCI using its private key and the user terminal's public key.

[0022] Secondly, one embodiment of this application provides a privacy protection enhancement method, the method comprising:

[0023] The UDM network element receives a network access registration and authentication request sent by a user terminal, wherein the network access registration and authentication request includes at least a user hidden identifier (SUCI), and determines the first privacy protection enhancement network element corresponding to the user terminal based on the network access registration and authentication request; and sends a decryption request to the first privacy protection enhancement network element, wherein the decryption request includes at least the SUCI;

[0024] After receiving the SUCI decryption request sent by the UDM network element, the first privacy protection enhancement network element decrypts the SUCI and sends the decryption result of the SUCI to the UDM network element.

[0025] After receiving the decryption result of the SUCI sent by the first privacy protection enhancement network element, the UDM network element begins to authenticate the user terminal based on the decryption result of the SUCI.

[0026] In one possible design, the network access registration and authentication request also carries the public key of the first privacy protection enhancement network element pre-stored by the user terminal; the step of determining the first privacy protection enhancement network element corresponding to the user terminal based on the network access registration and authentication request includes:

[0027] The first privacy-enhancing network element is determined based on the public key of the first privacy-enhancing network element carried in the network access registration and authentication request.

[0028] In one possible design, the SUCI included in the network access registration and authentication request is obtained by encrypting the user terminal's private key and the first privacy-enhancing network element's public key using the ECIES algorithm.

[0029] In one possible design, the method further includes:

[0030] The public key of the UDM network element to the user terminal of the first privacy protection enhancement network element;

[0031] The first privacy-enhancing network element decrypts the SUCI, including:

[0032] The SUCI is decrypted using the private key of the first privacy-enhancing network element and the public key of the user terminal.

[0033] Thirdly, one embodiment of this application provides a privacy protection enhancement device, the device comprising:

[0034] An authentication request module is used for a UDM network element to receive a network access registration and authentication request sent by a user terminal, wherein the network access registration and authentication request includes at least a user hidden identifier (SUCI), and to determine a first privacy protection enhancement network element corresponding to the user terminal based on the network access registration and authentication request; and to send a decryption request to the first privacy protection enhancement network element, wherein the decryption request includes at least the SUCI.

[0035] The decryption module is used to decrypt the SUCI after the first privacy protection enhancement network element receives the decryption request sent by the UDM network element, and send the decryption result of the SUCI to the UDM network element;

[0036] An authentication module is used by the UDM network element to start authenticating the user terminal based on the decryption result of the SUCI sent by the first privacy protection enhancement network element.

[0037] In one possible design, the network registration and authentication request also carries the public key of the first privacy-enhancing network element pre-stored by the user terminal; the authentication request module is specifically used for:

[0038] The first privacy-enhancing network element is determined based on the public key of the first privacy-enhancing network element carried in the network access registration and authentication request.

[0039] In one possible design, the SUCI included in the network access registration and authentication request is obtained by encrypting the user terminal's private key and the first privacy-enhancing network element's public key using the ECIES algorithm.

[0040] In one possible design, the device further includes:

[0041] The UDM network element sends the public key of the user terminal to the first privacy protection enhancement network element;

[0042] The decryption module is specifically used for:

[0043] The SUCI is decrypted using the private key of the first privacy-enhancing network element and the public key of the user terminal.

[0044] Fourthly, one embodiment of this application provides an electronic device, including:

[0045] Processor and display;

[0046] The display is used to show the user interface;

[0047] The processor is configured to perform any of the methods provided in the second aspect above.

[0048] Fifthly, an embodiment of this application also provides a computer-readable storage medium that, when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform any of the methods provided in the second aspect above.

[0049] In a sixth aspect, one embodiment of this application provides a computer program product including a computer program / instructions that, when executed by a processor, implement any of the methods provided in the second aspect of this application.

[0050] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0051] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0052] Figure 1 This application provides an illustration of an application scenario for a privacy protection enhancement system.

[0053] Figure 2 A schematic flowchart illustrating a privacy protection enhancement method provided in an embodiment of this application;

[0054] Figure 3 A schematic flowchart illustrating a privacy protection enhancement method provided in an embodiment of this application;

[0055] Figure 4 A schematic diagram of a privacy protection enhancement device provided in an embodiment of this application;

[0056] Figure 5A schematic diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0057] To enable those skilled in the art to better understand the technical solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0058] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data used can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0059] With the development of mobile communication technology to the 5G era, 5G mobile communication systems have placed higher demands on security. To address the privacy issues such as user identity and location leakage caused by plaintext transmission of the IMSI, the 5G security standard document 3GPP TS 33.501 defines a mobile user privacy protection mechanism for the initial registration process. This mechanism employs a public-key encryption mechanism based on elliptic curve cryptography to encrypt the IMSI, and all of the above is implemented in the core network UDM element.

[0060] Because different industries have different security protection requirements for 5G mobile communication systems, current technologies use customized UDM network elements to meet the actual security needs of different industries. However, the algorithmic mechanisms for achieving the actual security needs of different industries are complex, and equipment manufacturers need to customize dedicated equipment for different industry users. Operators also need to invest in deployment, testing, operation and maintenance, which makes customized UDM difficult.

[0061] Therefore, this application provides a privacy protection enhancement method and related apparatus. By adding at least one privacy protection enhancement network element, each user terminal has a corresponding privacy protection enhancement network element, and then the SUCI can be decrypted through the privacy protection enhancement network element corresponding to the user terminal. This reduces the computational load of UDM and can also meet the industry's differentiated network access privacy protection security requirements.

[0062] After introducing the design concept of the embodiments of this application, the following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application can be applied. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.

[0063] refer to Figure 1 This diagram illustrates an application scenario of the privacy protection enhancement system provided in this application embodiment. The application scenario includes: a user equipment (UE) 101, a UDM 102, and at least one enhanced privacy protection network element (EPPF) 103, such as EPPF103-1, ..., EPPF103-n. The UDM 102 also includes an identification unit 102-1 and a selection unit 102-2. Here, the UE 101 and UDM 102 can interact through the core unit (Access and Mobility Management Function, AMF) 104. The UE 101 can also interact with the AMF 104 through the next-generation Node B (gNB, abbreviated as gNodeB). The UDM 102 and at least one EPPF 103 interact through a service-based interface (SBI). The AMF 104, UDM 102, and at least one EPPF 103 constitute the 5G core network.

[0064] The UE101 pre-stores the UDM public key and the corresponding first EPPF public key PK. EPPF In UE101, the private key and the first EPPF public key PK stored in the UE are used. EPPF The ECIES algorithm is used to encrypt SUPI, resulting in SUCI. This is based on the first EPPF public key PK. EPPF Generate a network access registration and authentication request using SUCI and the service network name SN-NAME, and send the network access registration and authentication request to UDM102.

[0065] For example, a symmetric key is first negotiated using the private key stored in the UE and the first EPPF public key. Then, a key is derived based on the symmetric key, and the derived key is used to encrypt the SUPI to obtain the SUCI.

[0066] After receiving the network access registration and authentication request, UDM102 parses the request through identification unit 102-1 to obtain the first EPPF public key PK. EPPF Then, the EPPF corresponding to UE101 is determined to be the first EPPF. The determination result is sent to the selection unit 102-2, which calls the service interface of the first EPPF and sends a SUCI decryption request to the first EPPF through the service interface of the first EPPF.

[0067] After receiving the SUCI decryption request sent by selection unit 102-2, the first EPPF decrypts the SUCI and sends the decryption result to UDM network element 102. Then, in UDM network element 102, authentication of UE101 begins based on the SUCI decryption result. For example, after receiving the SUCI decryption result, UDM network element 102 begins a standard 5G primary authentication process with UE101. During this process, the network authenticates whether UE101 has the right to access the network. If the authentication is successful, the authentication of UE101 is completed. This is only an example, and this application does not limit the specific authentication process between UDM network element 102 and UE101.

[0068] Of course, the methods provided in the embodiments of this application are not limited to... Figure 1 The application scenarios shown can also be used in other possible application scenarios.

[0069] To further illustrate the technical solutions provided in the embodiments of this application, a detailed description is provided below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiments of this application provide method operation steps as shown in the following embodiments or drawings, the method may include more or fewer operation steps based on conventional or non-inventive methods. In steps where there is no logically necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application.

[0070] The following is combined Figure 1 The application scenarios shown illustrate the technical solutions provided in the embodiments of this application.

[0071] refer to Figure 2 This application provides a privacy protection enhancement method, which includes the following steps:

[0072] S201, using the private key and the first EPPF public key PK stored in the UE. EPPF Encrypt SUPI to obtain SUCI.

[0073] Here, you can use the SM2 / 3 / 4 national cryptographic algorithm, private key, and PK. EPPF The encryption of SUPI is only an example here, and this application does not limit the specific algorithm.

[0074] S202, based on the UE's public key and the first EPPF public key PK EPPF Generate network access registration and authentication requests using SUCI and SN-NAME.

[0075] S203 sends the network access registration and authentication request to the UDM network element.

[0076] S204 parses the network registration and authentication request to obtain the first EPPF public key PK. EPPF According to PK EPPF The EPPF corresponding to the UE is determined to be the first EPPF.

[0077] S205, send a SUCI decryption request to the first EPPF.

[0078] S206, send the UE's public key to the first EPPF.

[0079] S207, the SUCI is decrypted using the first EPPF private key stored in the first EPPF and the UE's public key, and the decryption result of the SUCI is sent to the UDM network element.

[0080] For example, such as Figure 1 In EPPF103-1, the private key storage 1 of the network element and the public key of the UE are used to decrypt SUCI using algorithm A to obtain SUPI. Similarly, the private key storage n of the network element in EPPF103-n and the public key of the UE are used to decrypt SUCI using algorithm X to obtain SUPI. Here, the algorithm can be an asymmetric algorithm; this is merely an example.

[0081] S208, Based on the decryption result of SUCI, begin authenticating the UE.

[0082] This application adds at least one EPPF, enabling the security algorithm required by industry users to complete the SUCI decryption problem. Through the EPPF public key index and standard inter-network element service interfaces, the UDM can call different EPPFs. This simultaneously meets the network access privacy protection security requirements of different industry users, facilitates operator deployment and maintenance, and reduces the impact on existing 5G network elements. This application is also compatible with 3GPP privacy protection mechanisms and the calculation process of the elliptic curve integrate encrypt scheme (ECIES).

[0083] like Figure 3 As shown in the figure, an embodiment of this application discloses a flowchart of a privacy protection enhancement method, which includes the following steps:

[0084] S301, the UDM network element receives a network access registration and authentication request sent by the user terminal, wherein the network access registration and authentication request includes at least the user hidden identifier SUCI, and determines the first privacy protection enhancement network element corresponding to the user terminal based on the network access registration and authentication request; and sends a decryption request to the first privacy protection enhancement network element, wherein the decryption request includes at least the SUCI;

[0085] S302, after receiving the decryption request sent by the UDM network element, the first privacy protection enhancement network element decrypts the SUCI and sends the decryption result of the SUCI to the UDM network element.

[0086] S303, after receiving the decryption result of SUCI sent by the first privacy protection enhancement network element, the UDM network element begins to authenticate the user terminal based on the decryption result of SUCI.

[0087] The implementation process of the above method can be referred to the description of the privacy protection enhancement system above, and will not be repeated here.

[0088] refer to Figure 4 This application provides a privacy protection enhancement device, device 400 including:

[0089] The authentication request module 401 is used for the UDM network element to receive a network access registration and authentication request sent by a user terminal, wherein the network access registration and authentication request includes at least a user hidden identifier (SUCI), and determines the first privacy protection enhancement network element corresponding to the user terminal based on the network access registration and authentication request; and sends a decryption request to the first privacy protection enhancement network element, wherein the decryption request includes at least the SUCI.

[0090] The decryption module 402 is used to decrypt the SUCI after the first privacy protection enhancement network element receives the decryption request sent by the UDM network element, and send the decryption result of the SUCI to the UDM network element.

[0091] The authentication module 403 is used by the UDM network element to start authenticating the user terminal based on the decryption result of SUCI sent by the first privacy protection enhancement network element.

[0092] In one possible design, the network registration and authentication request also carries the public key of the first privacy-enhancing network element pre-stored by the user terminal; the authentication request module 401 is specifically used for:

[0093] The first privacy-enhancing network element is determined based on the public key of the first privacy-enhancing network element carried in the network access registration and authentication request.

[0094] In one possible design, the SUCI included in the network access registration and authentication request is obtained by encrypting the user terminal's private key and the first privacy-enhancing network element's public key using the ECIES algorithm.

[0095] In one possible design, the device also includes:

[0096] The UDM network element sends the user terminal's public key to the first privacy-enhancing network element;

[0097] The decryption module 402 is specifically used for:

[0098] SUCI is decrypted using the private key of the first privacy-enhancing network element and the public key of the user terminal.

[0099] Having introduced the privacy protection enhancement method and related apparatus according to exemplary embodiments of this application, we will now introduce an electronic device according to another exemplary embodiment of this application.

[0100] Those skilled in the art will understand that various aspects of this application can be implemented as a system, method, or program product. Therefore, various aspects of this application can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, collectively referred to herein as a "circuit," "module," or "system."

[0101] In some possible implementations, the electronic device according to this application may include at least one processor and at least one memory. The memory stores program code that, when executed by the processor, causes the processor to perform the steps in the privacy enhancement methods according to the various exemplary embodiments of this application described above. For example, the processor may perform steps such as those in the privacy enhancement methods.

[0102] The following reference Figure 5 To describe an electronic device 50 according to this embodiment of the present application. Figure 5 The electronic device 50 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0103] like Figure 5 As shown, the terminal device 50 is presented in the form of a general-purpose electronic device. The components of the electronic device 50 may include, but are not limited to: at least one processor 51, at least one memory 52, and a bus 53 connecting different system components (including memory 52 and processor 51).

[0104] Bus 53 represents one or more of several bus structures, including a memory bus or memory controller, peripheral bus, processor, or a local bus using any of the various bus structures.

[0105] The memory 52 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 521 and / or cache memory 522, and may further include read-only memory (ROM) 523.

[0106] The memory 52 may also include a program / utility 525 having a set (at least one) of program modules 524, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0107] Electronic device 50 can also communicate with one or more external devices 54 (e.g., keyboard, pointing device, etc.), and with one or more devices that enable a user to interact with electronic device 50, and / or with any device that enables electronic device 50 to communicate with one or more other electronic devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 55. Furthermore, electronic device 50 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 56. As shown, network adapter 56 communicates with other modules used in electronic device 50 via bus 53. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with electronic device 50, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0108] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory 52 including instructions that can be executed by a processor 51 to perform the above-described method. Optionally, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0109] In an exemplary embodiment, a computer program product is also provided, including a computer program / instructions that, when executed by a processor 51, implement any of the privacy-enhancing methods provided in this application.

[0110] In an exemplary embodiment, various aspects of the privacy enhancement method provided in this application can also be implemented as a program product, which includes program code that, when the program product is run on a computer device, causes the computer device to perform the steps of a privacy enhancement method according to various exemplary embodiments of this application as described above.

[0111] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0112] The program product for unlocking electronic devices according to embodiments of this application can employ a portable compact disc read-only memory (CD-ROM) and include program code, and can run on the electronic device. However, the program product of this application is not limited thereto. In this document, the readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0113] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take many forms, including—but not limited to—electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0114] The program code contained on the readable medium may be transmitted using any suitable medium, including—but not limited to—wireless, wired, fiber optic, RF, etc., or any suitable combination thereof.

[0115] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's electronic device, partially on the user's device, as a standalone software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In cases involving remote electronic devices, the remote electronic device can be connected to the user's electronic device via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external electronic device (e.g., via the Internet using an Internet service provider).

[0116] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0117] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0118] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0119] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable electronic device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable electronic device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0120] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable electronic device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0121] These computer program instructions may also be loaded onto a computer or other programmable electronic device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0122] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0123] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A privacy protection enhancement system, characterized in that, The system includes: a unified data management (UDM) network element and at least one privacy protection enhanced network element; The UDM network element is used to receive network access registration and authentication requests sent by user terminals. The network access registration and authentication request includes at least a User Hidden Identifier (SUCI) and a public key of the corresponding first privacy-enhancing network element pre-stored by the user terminal. Based on the public key of the corresponding first privacy-enhancing network element carried in the network access registration and authentication request, the UDM element determines the first privacy-enhancing network element corresponding to the user terminal. It then calls the service interface of the first privacy-enhancing network element corresponding to the user terminal and sends a decryption request to the first privacy-enhancing network element through the service interface. The decryption request includes at least the SUCI. The first privacy protection enhancement network element is used to receive the decryption request sent by the UDM network element, decrypt the SUCI, and send the decryption result of the SUCI to the UDM network element; The UDM network element is also used to receive the decryption result of the SUCI sent by the first privacy protection enhancement network element, and to start authenticating the user terminal based on the decryption result of the SUCI.

2. The system according to claim 1, characterized in that, The UDM network element includes an identification unit and a selection unit; The identification unit is configured to receive a network access registration and authentication request sent by a user terminal, wherein the network access registration and authentication request includes at least a user hidden identifier (SUCI) and a public key of a corresponding first privacy protection enhanced network element pre-stored by the user terminal, and to determine the first privacy protection enhanced network element corresponding to the user terminal based on the public key of the corresponding first privacy protection enhanced network element carried in the network access registration and authentication request; and to send the determination result to the selection unit. The selection unit is used to call the service interface of the first privacy protection enhancement network element corresponding to the user terminal, and send a decryption request and the public key of the user terminal to the first privacy protection enhancement network element through the service interface. The decryption request includes at least the SUCI.

3. The system according to claim 2, characterized in that, The SUCI included in the network access registration and authentication request is obtained by encrypting the private key of the user terminal and the public key of the first privacy protection enhancement network element using the ECIES algorithm.

4. The system according to claim 2, characterized in that, The selection unit is further configured to send the public key of the user terminal to the first privacy-enhancing network element; The first privacy-enhancing network element is specifically used to decrypt the SUCI based on the private key of the first privacy-enhancing network element and the public key of the user terminal.

5. A privacy protection enhancement method, characterized in that, The method includes: The UDM network element receives a network access registration and authentication request sent by a user terminal. The request includes at least a user hidden identifier (SUCI) and a public key of the corresponding first privacy-enhancing network element pre-stored by the user terminal. Based on the public key of the first privacy-enhancing network element carried in the request, the element determines the first privacy-enhancing network element corresponding to the user terminal. It then invokes the service interface of the first privacy-enhancing network element corresponding to the user terminal and sends a decryption request to the first privacy-enhancing network element through the service interface. The decryption request includes at least the SUCI. After receiving the decryption request sent by the UDM network element, the first privacy protection enhancement network element decrypts the SUCI and sends the decryption result of the SUCI to the UDM network element. After receiving the decryption result of the SUCI sent by the first privacy protection enhancement network element, the UDM network element begins to authenticate the user terminal based on the decryption result of the SUCI.

6. The method according to claim 5, characterized in that, The SUCI included in the network access registration and authentication request is obtained by encrypting the private key of the user terminal and the public key of the first privacy protection enhancement network element using the ECIES algorithm.

7. The method according to claim 5, characterized in that, The method further includes: The UDM network element sends the public key of the user terminal to the first privacy protection enhancement network element; The first privacy-enhancing network element decrypts the SUCI, including: The SUCI is decrypted using the private key of the first privacy-enhancing network element and the public key of the user terminal.

8. An electronic device, characterized in that, include: Processor and display; The display is used to show the user interface; The processor is configured to perform the method as described in any one of claims 5-7.