Switching key determination method, switching method and device
Through AMF network element encryption, NH and NCC parameters in the switching path confirmation message are processed, and the key negotiation process is protected by secret sharing and hashing algorithms, which solves the problem of lack of one-hop forward security in Xn handover, and achieves higher communication security.
Patent Information
- Application Number
- CN202310826186.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-06
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2043-07-06
AI Technical Summary
During the Xn handover process defined by the 3GPP specification, the key calculated by the source base station is directly used as the key of the target base station, resulting in a lack of one-hop forward security, posing a security risk, and may lead to illegal monitoring or message tampering and other attacks.
Through the access and mobility management function AMF network element encryption, the first next hop NH and the chain counter NCC in the switching path confirmation message are processed, the first and second secret parameters are generated, and these parameters are protected using the secret sharing algorithm and hash algorithm to ensure the security of the key negotiation process.
It realizes one-hop forward security of the access layer handover process, prevents attackers from obtaining the key of the target base station, resists anti-synchronous attacks and denial of service attacks, and improves the security of the communication system.
Smart Images

Figure CN116782211B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a method for determining a switching key, a switching method, and a device. Background Art
[0002] Currently, during the Xn handover process defined by the 3rd Generation Partnership Project (3GPP) specifications, the key calculated by the source base station is directly used as the key of the target base station. In this case, the traditional solution does not provide one-hop forward security, posing a security risk. Summary of the Invention
[0003] Based on this, it is necessary to provide a method for determining a switching key, a switching method, and an apparatus that can improve security in response to the above technical problems.
[0004] In a first aspect, the present application provides a method for determining a handover key, which is applied to an access and mobility management function AMF network element, and the method includes:
[0005] In response to receiving the handover path request transmitted by the source base station, output a handover path confirmation message; the handover path confirmation message carries the first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and the second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element;
[0006] The switching path confirmation message is used to instruct the source base station to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station, and to transmit a switching message carrying the first secret parameter to the target base station; wherein, the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
[0007] In one embodiment, the first next hop NH is an initial next hop NH before the current handover, derived by the AMF network element using a root key; the method further includes:
[0008] The first next hop NH is encrypted using a secret sharing algorithm to obtain a first secret parameter.
[0009] In one embodiment, encrypting the first next hop NH using a secret sharing algorithm includes:
[0010] Assign a randomly generated prime number to each target base station and AMF network element to which the terminal is to be handed over, and obtain an assignment result;
[0011] A secret sharing method based on the Chinese Remainder Theorem (CRT) is used to obtain a first secret parameter based on the allocation result and the first next hop NH.
[0012] In one embodiment, the handover path confirmation message further carries a first message authentication code MAC for instructing the terminal to confirm the integrity of the first next hop chain counter NCC; the key agreement information is obtained by encrypting the second secret parameter and the first message authentication code MAC by the source base station using the source base station key;
[0013] The method also includes:
[0014] Encrypting the first next hop chain counter NCC using the root key to obtain a second secret parameter;
[0015] Based on the root key, the second secret parameter is processed using a hash algorithm to obtain a first message authentication code MAC.
[0016] In one of the embodiments, the switching path confirmation message also carries a sending timestamp of the switching path confirmation message;
[0017] The key negotiation information is obtained by encrypting the second secret parameter, the first message authentication code MAC and the sending timestamp of the switching path confirmation message using the source base station key when the sending timestamp of the switching path confirmation message passes the freshness verification.
[0018] In one embodiment, the root key includes a non-access stratum NAS root key; and the handover key is used for Xn handover when the terminal switches to a target base station.
[0019] In a second aspect, the present application also provides a method for determining a handover key, which is applied to a source base station, and the method includes:
[0020] Send a handover path request to the access and mobility management function AMF network element; the handover path request is used to instruct the AMF network element to feedback a handover path confirmation message; the handover path confirmation message carries the first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and the second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element;
[0021] In response to receiving the switching path confirmation message, key negotiation information obtained based on the second secret parameter is transmitted to the terminal to be switched to the target base station, and a switching message carrying the first secret parameter is transmitted to the target base station; wherein the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; and the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
[0022] In one embodiment, sending a handover path request to an access and mobility management function (AMF) network element includes:
[0023] In response to the triggering of Xn switching, a switching path request is sent to the AMF network element.
[0024] In one embodiment, the switching path confirmation message further carries a first message authentication code MAC corresponding to the first next hop chain counter NCC; the method further includes:
[0025] The source base station key is used to encrypt the second secret parameter and the first message authentication code MAC to obtain key negotiation information.
[0026] In one embodiment, the switching path confirmation message further carries a timestamp of when the switching path confirmation message was sent; and the method further includes:
[0027] If it is determined that the sending timestamp of the switching path confirmation message meets the transmission delay threshold condition, then confirming that the sending timestamp of the switching path confirmation message passes the freshness verification;
[0028] The source base station key is used to encrypt the second secret parameter, the first message authentication code MAC, and the sending timestamp of the switching path confirmation message to obtain key negotiation information.
[0029] In a third aspect, the present application further provides a switching method, applied to a terminal, the method comprising:
[0030] In response to determining the handover key, generating terminal verification data; wherein the handover key is determined based on the above-mentioned handover key determination method;
[0031] Encrypting the terminal verification data using the switching key to obtain a first terminal key;
[0032] Generate a second terminal key based on the first terminal key and the source base station key, output the second terminal key to instruct the source base station to decrypt the second terminal key, and output a handover message carrying the first secret parameter and the first terminal key; the handover message is used to instruct the target base station to which the terminal is to be handed over to feed back a handover confirmation message;
[0033] In response to receiving the handover confirmation message, the handover confirmation message is decrypted using the handover key to obtain a decryption result. If the decryption result meets the handover condition, the handover is confirmed to be completed.
[0034] In one embodiment, the terminal verification data includes a terminal random number and a terminal timestamp generated by the terminal;
[0035] Encrypting the terminal authentication data using the switching key to obtain a first terminal key includes:
[0036] Using the switching key, encrypt the terminal random number and the terminal timestamp to obtain a first terminal key;
[0037] Generating a second terminal key based on the first terminal key and the source base station key includes:
[0038] The source base station key is used to encrypt the first terminal key and the terminal timestamp to obtain a second terminal key, so as to instruct the source terminal to transmit a handover message to the target base station when the terminal timestamp passes the freshness verification.
[0039] In one embodiment, the handover message is an XnAP handover message; the handover message also carries a timestamp of the source base station;
[0040] The handover confirmation message is obtained by encrypting the terminal random number and the target base station timestamp using the handover key by the target base station when both the source base station timestamp and the terminal timestamp pass the freshness verification.
[0041] In one embodiment, if the decryption result satisfies the switching condition, confirming the completion of the switching includes:
[0042] If the random number in the decryption result is the same as the terminal random number and the target base station timestamp in the decryption result passes the freshness verification, then the Xn handover is confirmed to be completed.
[0043] In one embodiment, the method further comprises:
[0044] In response to receiving the key agreement information, decrypting the key agreement information using the source base station key to obtain a first message authentication code MAC and a second secret parameter carried in the key agreement information, decrypting the second secret parameter using the root key to obtain a first next-hop chain counter NCC;
[0045] Obtain a second message authentication code MAC of a next hop chain counter NCC corresponding to the next hop NH currently used to derive the handover key;
[0046] If the second message authentication code MAC is the same as the first message authentication code MAC, it is determined that the first next hop chain counter NCC passes the integrity check, and the handover key is derived according to the first next hop NH corresponding to the first next hop chain counter NCC;
[0047] If the second message authentication code MAC is different from the first message authentication code MAC, a switching rejection message is output; the switching rejection message is transmitted to the AMF network element via the source base station, used to instruct the AMF network element to change the first next hop NH to the initial next hop NH before this switching.
[0048] In a fourth aspect, the present application further provides a handover method, which is applied to a target base station, and the method includes:
[0049] In response to determining the handover key, decrypting the first terminal key carried in the handover message using the handover key to obtain terminal verification data generated by the terminal; wherein the handover key is determined based on the above-mentioned handover key determination method;
[0050] Based on the terminal verification data, a switching confirmation message is output; the switching confirmation message is used to instruct the terminal to decrypt the switching confirmation message using the switching key, obtain the decryption result, and confirm the completion of the switching if the decryption result meets the switching condition.
[0051] In one embodiment, the handover message further carries a timestamp of the source base station; and determining the handover key includes:
[0052] Receive the handover message transmitted by the source base station. If the source base station timestamp carried in the handover message passes the freshness verification, perform a modulo operation on the prime number allocated by the AMF network element to the target base station and the first secret parameter carried in the handover message to obtain the first next hop NH;
[0053] The handover key is derived based on the first next hop NH.
[0054] In one embodiment, the terminal verification data includes a terminal random number and a terminal timestamp generated by the terminal;
[0055] Based on the terminal verification data, a handover confirmation message is output, including:
[0056] If the terminal timestamp passes the freshness verification, the target base station timestamp is generated;
[0057] The handover key is used to encrypt the terminal random number and the target base station timestamp to obtain a handover confirmation message.
[0058] In a fifth aspect, the present application also provides a device for determining a handover key, which is applied to an access and mobility management function AMF network element, and the device includes:
[0059] A path confirmation module is configured to output a switching path confirmation message in response to receiving a switching path request transmitted by a source base station; the switching path confirmation message carries a first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and a second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element;
[0060] The switching path confirmation message is used to instruct the source base station to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station, and to transmit a switching message carrying the first secret parameter to the target base station; wherein, the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
[0061] In a sixth aspect, the present application further provides a device for determining a handover key, which is applied to a source base station, and the device includes:
[0062] A handover request module is configured to send a handover path request to an access and mobility management function (AMF) network element; the handover path request is configured to instruct the AMF network element to feed back a handover path confirmation message; the handover path confirmation message carries a first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and a second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element;
[0063] A switching prompt module is used to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station in response to receiving a switching path confirmation message, and to transmit a switching message carrying the first secret parameter to the target base station; wherein the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; and the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
[0064] In a seventh aspect, the present application further provides a switching device, applied to a terminal, comprising:
[0065] A verification data generation module, configured to generate terminal verification data in response to determining the switching key; wherein the switching key is determined based on the above-mentioned switching key determination method;
[0066] A first key generation module, configured to encrypt the terminal verification data using the switching key to obtain a first terminal key;
[0067] A second key generation module is configured to generate a second terminal key based on the first terminal key and the source base station key, output the second terminal key to instruct the source base station to decrypt the second terminal key, and output a handover message carrying the first secret parameter and the first terminal key; the handover message is used to instruct the target base station to which the terminal is to be handed over to feed back a handover confirmation message;
[0068] The switching module is configured to, in response to receiving the switching confirmation message, decrypt the switching confirmation message using the switching key to obtain a decryption result, and confirm that the switching is completed if the decryption result meets the switching condition.
[0069] In an eighth aspect, the present application further provides a switching device, applied to a target base station, the device comprising:
[0070] a decryption module configured to, in response to determining the handover key, decrypt the first terminal key carried in the handover message using the handover key to obtain terminal verification data generated by the terminal; wherein the handover key is determined based on the above-mentioned handover key determination method;
[0071] The switching confirmation module is used to output a switching confirmation message based on the terminal verification data; the switching confirmation message is used to instruct the terminal to decrypt the switching confirmation message using the switching key to obtain the decryption result, and confirm the completion of the switching if the decryption result meets the switching conditions.
[0072] In a ninth aspect, the present application further provides a core network device, including a memory and a processor, the memory storing a computer program, the core network device being an access and mobility management function AMF network element;
[0073] When the processor executes the computer program, it implements the steps of the above-mentioned method for determining the switching key from the perspective of the AMF network element.
[0074] In a tenth aspect, the present application further provides a base station, comprising a memory and a processor, wherein the memory stores a computer program, and the base station is a source base station;
[0075] When the processor executes the computer program, the steps of the above-mentioned method for determining the handover key from the perspective of the source base station are implemented.
[0076] In the eleventh aspect, the present application also provides a terminal device, including a memory and a processor, the memory stores a computer program, and the processor implements the steps of the above-mentioned switching method implemented from the perspective of the terminal device when executing the computer program.
[0077] In a twelfth aspect, the present application further provides a base station, including a memory and a processor, the memory storing a computer program, and the base station being a target base station;
[0078] When the processor executes the computer program, the steps of the above-mentioned handover method implemented from the perspective of the target base station are implemented.
[0079] In a thirteenth aspect, the present application further provides a communication system, comprising:
[0080] Access and mobility management function AMF network element, used to perform the steps of the above method
[0081] A source base station, configured to execute the steps of the above method;
[0082] A target base station, configured to execute the steps of the above method;
[0083] The terminal device is used to execute the steps of the above method.
[0084] In a fourteenth aspect, the present application also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0085] In a fifteenth aspect, the present application also provides a computer program product, comprising a computer program, which implements the steps of the above method when executed by a processor.
[0086] The above-mentioned method for determining the switching key, the switching method and the device, when the access layer triggers the switching, the source base station transmits the switching path request to the AMF network element, and the AMF network element feeds back the switching path confirmation message, which carries the first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and the second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element, and then the source base station outputs the key negotiation information and the switching message, so that the terminal can determine the switching key according to the second secret parameter, and the target base station can determine the switching key according to the first secret parameter. In this application, the key communication parameters NH and NCC are shared as secrets between the source base station and the target base station to which the terminal is to switch, so that even if the attacker obtains certain information of the source base station, he cannot calculate the key of the target base station, so that the switching process of the access layer has one-hop forward security. BRIEF DESCRIPTION OF THE DRAWINGS
[0087] Figure 1 This is a schematic diagram of the traditional 3GPP Xn handover process;
[0088] Figure 2 A diagram of an application environment of a method for determining a switching key and a switching method in one embodiment;
[0089] Figure 3 1 is a flow chart of a method for determining a handover key from the perspective of an AMF network element in one embodiment;
[0090] Figure 4 Schematic diagram of a process for obtaining a first secret parameter in one embodiment;
[0091] Figure 5 FIG. 1 is a flow chart of obtaining a first message authentication code MAC in one embodiment;
[0092] Figure 6 1 is a flow chart of a method for determining a handover key from the perspective of a source base station in one embodiment;
[0093] Figure 7 1 is a flow chart of a switching method implemented from the perspective of a terminal device in one embodiment;
[0094] Figure 8 FIG1 is a flow chart of a handover method implemented from the perspective of a target base station in one embodiment;
[0095] Figure 9 A schematic diagram of a specific flow chart of a switching method in one embodiment;
[0096] Figure 10 2 is a structural block diagram of a device for determining a handover key implemented from the perspective of an AMF network element in one embodiment;
[0097] Figure 11 1 is a structural block diagram of a device for determining a handover key implemented from the perspective of a source base station in one embodiment;
[0098] Figure 12 is a structural block diagram of a switching device implemented from the perspective of a terminal device in one embodiment;
[0099] Figure 13 is a structural block diagram of a switching device implemented from the perspective of a target base station in one embodiment;
[0100] Figure 14 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0101] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0102] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application pertains. The terms used herein in the specification of this application are for the purpose of describing specific embodiments only and are not intended to limit this application.
[0103] It is understood that terms such as "first" and "second" in this application are only used to distinguish similar objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features.
[0104] It can be understood that the “connection” in the following embodiments should be understood as “electrical connection”, “communication connection”, etc. if there is transmission of electrical signals or data between the connected circuits, modules, units, etc.
[0105] It will be understood that "at least one" means one or more, and "a plurality of" means two or more.
[0106] As used herein, the singular forms "a," "an," and "the" may also include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the terms "include," "comprising," "having," and the like specify the presence of stated features, integers, steps, operations, components, parts, or combinations thereof, but do not preclude the presence or addition of one or more other features, integers, steps, operations, components, parts, or combinations thereof. Furthermore, the term "and / or" as used in this specification includes any and all combinations of the relevant listed items.
[0107] like Figure 1 As shown, Xn handover is a type of handover within the 3GPP domain. Specifically, when the UE (User Equipment) is in a connected state and has a relatively small mobility range, the Xn interface is switched under the same AMF (Access and Mobility Management Function), and the UPF (User Plane Function) remains unchanged, that is, the UE's AS (Access Stratum) context (access layer information) is directly exchanged between base stations (gNBs).
[0108] Access layer root key K during Xn handover process gNB The role of is to protect the communication between UE and gNB. When the UE switches from the source base station (s-gNB) to the target base station (t-gNB), the key between the UE and t-gNB is used to protect the communication between UE and gNB. By K gNB Or NH (Next Hop, next hop value). By K gNB When it is derived, it is called horizontal key derivation (Formula ①); when When it is derived from NH, it is called vertical key derivation (Formula ②).
[0109]
[0110]
[0111] PCI stands for Physical Cell Identity. ARFCN-DL stands for Absolute Radio Frequency Channel Number-Down Link. KDF stands for Key Derivation Function, a one-way pseudo-random function commonly used to stretch a key into a longer key or obtain a key in a desired format. The "||" operator concatenates the preceding and following values.
[0112] After initial authentication, both UE and AMF hold the same NAS (Non-Access Stratum) root key K AMF , and after the AS initial security context is established, the UE and AMF use K AMF Generate K gNB , NH and the NCC (Next Hop Chaining Count) value that matches the NH, and then AMF will generate K gNB Therefore, before the first Xn handover occurs, both the UE and the AMF hold the same K AMF , K gNB , NH and matching NCC (initial 1), while the gNB connected to the UE only has the initial K gNB (NCC value is 0). The calculation formula of NH is as follows:
[0113] NH=KDF(K AMF ||K gNB ) ③
[0114] NH * =KDF(K AMF ||NH) ④
[0115] Formula ③ is used only to calculate the initial NH value. Its associated NCC value is 1. The initial NH is not sent to the gNB and serves only as the initial value of the NH chain. All subsequent NH values are calculated using Formula ④.
[0116] The traditional Xn handover process includes: 1. After the access layer determines that an Xn handover is required, the s-gNB first calculates the Xn handover time according to the formula (Formula ① is used for the initial handover, and Formula ② is used for non-initial handover). and will The XnAP (Xn Application Protocol) handover message is sent to the t-gNB. After receiving the message, the t-gNB Directly as your own KgNB 2. The t-gNB generates a master key update prompt, which includes the NCC value obtained from the s-gNB, to instruct the UE to generate the same NCC value using the formula (Formula ① for initial handover and Formula ② for non-initial handover). And calculate the new NH according to formula ④ and associate it with the new NCC value.
[0117] t-gNB sends a handover path request to AMF. AMF will add 1 to the NCC value, calculate the new NH value according to formula ④, and feed the new NH and NCC values back to t-gNB. This new set of NH and NCC values will be used to generate a new NH value according to formula ② in future handover processes.
[0118] In the 3GPP 5G (5th Generation Mobile Communication Technology) access layer Xn handover specification, the communication between the UE and the base station (gNB) uses the root key K gNB When the UE switches from the source base station (s-gNB) to the target base station (t-gNB), the encryption between the UE and the t-gNB is The key K of s-gNB gNB Or derived from NH. If an attacker hijacks the s-gNB and obtains the s-gNB key K gNB , physical cell identifier PCI and target downlink frequency ARFCN-DL, then the attacker can deduce the t-gNB key according to the formula given in the 3GPP specification. Therefore, although the Xn handover process defined in the 3GPP specification has backward security and two-hop forward security, it does not have one-hop forward security, posing a security risk.
[0119] Among them, n-hop forward security (n=1 or 2) means that after n handovers, it is impossible for the gNB before the handover to calculate the key used for future connections between the UE and the gNB after the handover.
[0120] At the same time, during the Xn switching process, suppose an attacker hijacks a legitimate s-gNB and makes the s-gNB incorrectly update the NCC value. For example, the attacker maliciously sets the NCC to a large number, and then the t-gNB will compare the large number with its own key. When the UE checks whether the NCC value is one greater than the local NCC value, it will find that the NCC value does not match. The UE will then continue to calculate NH* (because the NCC value is incremented by 1 each time NH* is calculated) until the NCC value matches the received NCC value, hindering key negotiation between the UE and the t-gNB and causing a desynchronization attack. Alternatively, in the case of multiple handovers, the source gNB hijacked by the attacker could maliciously set a very small NCC value, preventing the UE from matching the NCC value no matter how it calculates. This can continuously consume the UE's computing resources and capabilities, ultimately causing a denial of service attack and posing a significant security risk.
[0121] As mentioned above, in 3GPP specifications, the key calculated by the source gNB is directly used as the target gNB's key. In this case, an attacker could potentially use the source gNB's key to obtain the target gNB's key, potentially enabling attacks such as illegal eavesdropping or message tampering. Furthermore, in 3GPP specifications, the NCC is associated with the NH value, allowing the UE to determine which NH value to use to derive session keys. An attacker could potentially control a legitimate base station or set up a rogue base station to send a false NCC value to the UE, potentially causing a DoS (Denial of Service) attack.
[0122] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Global System of Mobile communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD), Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system or 5G system, or subsequent versions of communication systems.
[0123] The base station in the embodiment of the present application may include various forms of macro base stations, micro base stations, relay stations, access points, transceiver nodes, transmission nodes, etc. In communication systems using different wireless access technologies, the names of devices with base station functions may be different. Exemplarily, the base station may include one of the following or a combination of at least two: an evolved base station (eNB or eNodeB) in a Long Term Evolution (LTE) system, a Next Generation Radio Access Network (NG RAN) device, a base station (gNB) in an NR system, a small station, a micro station, a wireless controller in a Cloud Radio Access Network (CRAN), an access point for Wireless-Fidelity (Wi-Fi), a Transmission Reception Point (TRP), a relay station, an access point, a vehicle-mounted device, a wearable device, a hub, a switch, a bridge, a router, a network device in a future evolved Public Land Mobile Network (PLMN), etc.
[0124] Furthermore, the terminal device in the embodiment of the present application is a handheld device, vehicle-mounted device, wearable device, computing device or other processing device connected to a wireless modem with wireless communication capabilities. The terminal device in the embodiment of the present application can be referred to as user equipment (UE), mobile station (MS), mobile terminal (MT), subscriber unit, subscriber station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device.
[0125] The method for determining the switching key and the switching method provided in the embodiments of the present application can be applied to Figure 2 In the application environment shown. Figure 2 In the communication system shown, a terminal device switches from a source base station to a target base station. Figure 2 The target base station in the example can be any type of base station among the above base stations, for example, it can be an eNodeB in an LTE network, or a gNB in a 5G system; the source base station can also be any type of base station among the above base stations.
[0126] Exemplarily, the communication system may further include a core network device for communicating with the base station. Optionally, the core network device may be a 5G core network device, such as an access and mobility management function (AMF), which is responsible for access and mobility management and has functions such as user authentication, handover, and location update.
[0127] In one embodiment, Figure 3 As shown, a method for determining a switching key is provided, and the method is applied to Figure 2 The access and mobility management function AMF network element in the communication system is used as an example to illustrate the process, including the following steps:
[0128] Step 202: In response to receiving the switching path request transmitted by the source base station, output a switching path confirmation message; the switching path confirmation message carries the first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and the second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element.
[0129] The switching path confirmation message is used to instruct the source base station to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station, and to transmit a switching message carrying the first secret parameter to the target base station; wherein, the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
[0130] The handover key may refer to the key between the terminal device (UE) and the target base station (t-gNB) when the terminal device (UE) switches from the source base station (s-gNB) to the target base station (t-gNB). This embodiment of the application only modifies the handover process after the handover decision is completed. For example, this embodiment of the application improves the 5G access layer Xn handover process described in TS33.501.
[0131] Optionally, taking Xn switching as an example, after the access layer decides that Xn switching is required, the source base station (s-gNB) can send a switching path request to the AMF network element, and the AMF network element enters the parameter preparation stage. In an embodiment of the present application, the source base station sends a switching path request to the AMF network element in response to the triggering of the Xn switching. The AMF network element receives the switching path request transmitted by the source base station, and after parameter preparation, it feeds back a switching path confirmation message. Among them, the switching path confirmation message carries the first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and the second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element.
[0132] In this embodiment of the present application, the key parameter NH is disguised as a first secret parameter. Even if an attacker obtains the first secret parameter, due to encryption, the attacker cannot decrypt the value of NH from the first secret parameter and cannot obtain the handover key of the target base station (t-gNB). This ensures that the handover process at the access layer has one-hop forward security. In addition, the first next-hop chain counter NCC is encrypted as a second secret parameter to protect the integrity of the NCC. This allows the terminal (UE) to perform an integrity check before using NH to obtain the handover key (if an illegal gNB sends a false NCC value, the UE will find a mismatch during the check). This protects the handover process from anti-synchronization attacks and DoS (Denial of Service) attacks.
[0133] Exemplarily, the first secret parameter can be the first next hop NH encrypted by the AMF network element using a secret sharing method. Even if the attacker obtains the first secret parameter, due to the protection of the secret sharing algorithm, the attacker cannot decipher the value of NH from the first secret parameter, and thus cannot obtain the switching key of the target base station (t-gNB); optionally, the second secret parameter can be the first next hop chain counter NCC encrypted by the AMF network element using a root key, and then the terminal (UE) can check the integrity of the NCC corresponding to the NH before using the NH, thereby preventing DoS attacks and anti-synchronization attacks. The embodiment of the present application does not limit the specific method of AMF network element encryption.
[0134] It should be noted that the embodiment of the present application only modifies the handover process after the handover decision is completed, and the types of keys held by the terminal (UE), base station (gNB) and AMF network element remain unchanged. Taking Xn handover as an example, before the first Xn handover occurs, the terminal (UE) and AMF network element both hold the same root key (K AMF ), source base station key (K gNB ), the initial next hop NH and the matching NCC (initial 1), while the base station (gNB) connected to the terminal (UE) only has the initial K gNB (NCC value is 0).
[0135] In the above-mentioned handover key determination method, the key communication parameters NH and NCC are shared as secrets between the source base station and the target base station to which the terminal is to be handed over. This prevents an attacker from calculating the key of the target base station even if they obtain certain information about the source base station, thereby ensuring that the handover process at the access layer has one-hop forward security.
[0136] In one embodiment, the first next hop NH is an initial next hop NH before the current handover, derived by the AMF network element using a root key, and the method further includes:
[0137] The first next hop NH is encrypted using a secret sharing algorithm to obtain a first secret parameter.
[0138] Specifically, after receiving the handover path request sent by the source base station (s-gNB), the AMF network element enters the parameter preparation phase. The AMF network element can calculate a new NH (first next hop NH) based on the initial next hop NH before the handover and associate it with a new NCC value (first next hop chain counter NCC). For example, the initial next hop NH can be processed using the above formula ④ to obtain the first next hop NH. Furthermore, the AMF network element can encrypt the first next hop NH using a secret sharing algorithm to obtain a first secret parameter.
[0139] This application adopts a secret sharing scheme, in which the source base station (s-gNB) and all possible target base stations (t-gNB) form a group, and the key communication parameters NH and NCC are shared as secrets between the source base station (s-gNB) and the only target base station (t-gNB). This ensures that even if an attacker obtains certain information about the source base station (s-gNB), he cannot calculate the key of the target base station (t-gNB), thereby ensuring that the Xn handover process at the access layer (e.g., the 5G access layer) has one-hop forward security.
[0140] In one embodiment, Figure 4 As shown, the encryption of the first next hop NH by using the secret sharing algorithm includes:
[0141] Step 302: assigning randomly generated prime numbers to each target base station and AMF network element to be handed over by the terminal, and obtaining an assignment result;
[0142] Specifically, taking Xn handover as an example, after the access layer decides that Xn handover is required, the source base station (s-gNB) sends a handover path request to the AMF network element, and the AMF network element enters the parameter preparation phase:
[0143] Assume there are n gNBs to be handed over, that is, there are n candidate target base stations (t-gNB).
[0144] The AMF network element randomly generates n+1 large prime numbers and assigns a prime number to each of the above possible handover target base stations (t-gNB), which is recorded as S i , i=1,...,n. Among them, a large prime number is also assigned to the AMF network element itself, denoted as S0. Among them, S0 and S i It can be understood as the distribution result.
[0145] Step 304 : Using a secret sharing method based on the Chinese Remainder Theorem CRT, a first secret parameter is obtained based on the allocation result and the first next hop NH.
[0146] Specifically, the AMF network element can calculate the new NH (first next hop NH) according to the above formula ④, associate the new NCC value (first next hop chain counter NCC), and perform the following calculation:
[0147] calculate:
[0148] For each i (i=1, ..., n), calculate and
[0149] calculate:
[0150] Calculate the first secret parameter: β = λNH
[0151] In the above embodiments of the present application, a new parameter β is used to hide the key parameter NH, and the new parameter β is protected by the CRT (Chinese Remainder Theorem) secret sharing algorithm. Using a secret sharing scheme based on the Chinese Remainder Theorem (CRT), the key parameter NH is disguised as β. Even if an attacker obtains the value of β, due to the protection of the CRT secret sharing algorithm, the attacker cannot decipher the value of NH from β, and thus cannot obtain the key of the target base station (t-gNB). This ensures that the handover process of the 5G access layer has one-hop forward security.
[0152] In one embodiment, the handover path confirmation message further carries a first message authentication code MAC (Message Authentication Code) for indicating that the terminal confirms the integrity of the first next hop chain counter NCC; the key agreement information is obtained by encrypting the second secret parameter and the first message authentication code MAC by the source base station using the source base station key;
[0153] like Figure 5 As shown, the method further includes:
[0154] Step S402: encrypt the first next hop chain counter NCC using the root key to obtain a second secret parameter;
[0155] Specifically, during the parameter preparation phase, the AMF network element can use the root key (e.g. K AMF ) encrypts the new NCC value (first next hop chain counter NCC) to obtain the second secret parameter K AMF {NCC}.
[0156] Step S404: Based on the root key, a hash algorithm is used to process the second secret parameter to obtain a first message authentication code MAC.
[0157] Specifically, during the parameter preparation phase, the AMF network element calculates: MAC = H(K AMF {NCC}||K AMF ).
[0158] Here, “H(x)” refers to the summary of x calculated using the hash function. x {y}" refers to the key K used by X x Encrypt y.
[0159] For example, after the parameter preparation phase is completed, the AMF network element enters the handover phase: after completing the calculation work in the preparation phase, the AMF also needs to use the root key (for example, K AMF ) encrypts the new NCC value and puts {β, K AMF {NCC}, MAC} is sent to the source base station (s-gNB).
[0160] Optionally, the key agreement information is obtained by encrypting the second secret parameter and the first message authentication code MAC by the source base station using the source base station key; illustratively, after the source base station (s-gNB) receives the handover path confirmation message, it can use the source base station key (K gNB ) Encrypt the information and write the encrypted information K gNB {K AMF {NCC}, MAC} is sent to the terminal (UE).
[0161] In one of the embodiments, the switching path confirmation message also carries a sending timestamp of the switching path confirmation message;
[0162] The key negotiation information is obtained by encrypting the second secret parameter, the first message authentication code MAC and the sending timestamp of the switching path confirmation message using the source base station key when the sending timestamp of the switching path confirmation message passes the freshness verification.
[0163] Specifically, after the parameter preparation phase is completed, the AMF network element enters the switching phase: After completing the calculation work in the preparation phase, the AMF network element also needs to use K AMF Encrypt the new NCC value and put {β, K AMF {NCC}, MAC, t1} is sent to the source base station (s-gNB), where t1 is the timestamp of the time the message was sent. By using timestamps, the present embodiment verifies the freshness of the timestamp at each step of the handover process.
[0164] After receiving the message, the source base station (s-gNB) first checks the freshness of the timestamp t1. If the timestamp is within the allowed range (0 < t ≤ γ, γ is the average transmission delay time), it stores the first secret parameter β. gNB Encrypt the information, and then use the encrypted information K gNB {K AMF {NCC}, MAC, t1} is sent to the terminal (UE).
[0165] In one embodiment, the root key includes a non-access stratum NAS root key; and the handover key is used for Xn handover when the terminal switches to a target base station.
[0166] For example, the root key K in the embodiment of the present application is AMF It can refer to the non-access layer NAS root key. Furthermore, the handover key is used for Xn handover when the terminal switches to the target base station. The embodiment of the present application can be applied to the process of 5G access layer Xn handover. Optionally, the embodiment of the present application improves the process of 5G access layer Xn handover described in TS33.501.
[0167] In the above handover key determination method, the handover key determination process is modified so that the handover key (for example, the new access layer root key ) is not calculated at the source base station (s-gNB), but at the target base station (t-gNB). AMF ) encrypts the NCC, the AMF network element calculates the digest MAC value of the NCC, and the terminal (UE) can perform integrity verification of the NCC.
[0168] In an embodiment of the present application, the key communication parameters NH and NCC are shared as secrets between the source base station and the target base station to which the terminal is to be switched, so that even if an attacker obtains certain information of the source base station, he cannot calculate the key of the target base station, thereby making the switching process of the access layer have one-hop forward security.
[0169] The embodiment of the present application modifies the key negotiation process of the switching process, first using the AMF key (K AMF ) encrypts the NCC value, and then designs the AMF network element to calculate the MAC value to protect the integrity of the NCC. Before using the NH value, the UE checks whether the MAC value of the NCC corresponding to the NH is equal to the received MAC value. If an unauthorized gNB sends a false NCC value, the UE will detect the mismatch when checking the MAC value, making the handover process more secure against desynchronization attacks and DoS attacks.
[0170] In one embodiment, Figure 6 As shown, a method for determining a switching key is provided, and the method is applied to Figure 2Taking the source base station in the communication system as an example, the following steps are included:
[0171] Step 502: Send a handover path request to the access and mobility management function AMF network element; the handover path request is used to instruct the AMF network element to feedback a handover path confirmation message; the handover path confirmation message carries the first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and the second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element;
[0172] Specifically, the source base station (s-gNB) sends a handover path request to the AMF network element, and the AMF enters the parameter preparation stage; among them, regarding the method of obtaining the first secret parameter and the second secret parameter, please refer to the method for determining the handover key implemented from the perspective of the AMF network element in the previous article, which will not be repeated here.
[0173] Exemplarily, sending a handover path request to an access and mobility management function (AMF) network element includes:
[0174] In response to the triggering of Xn switching, a switching path request is sent to the AMF network element.
[0175] Specifically, taking Xn switching as an example, after the access layer decides that Xn switching is required, the source base station (s-gNB) sends a switching path request to the AMF network element, and the AMF enters the parameter preparation stage.
[0176] Step 504: In response to receiving the switching path confirmation message, key negotiation information obtained based on the second secret parameter is transmitted to the terminal to be switched to the target base station, and a switching message carrying the first secret parameter is transmitted to the target base station; wherein the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; and the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
[0177] Specifically, the source base station (s-gNB) receives the switching path confirmation message transmitted by the AMF network element, and can transmit the key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station, and transmit the switching message carrying the first secret parameter to the target base station, so that the terminal and the target base station can complete the confirmation of the switching key.
[0178] In one embodiment, the switching path confirmation message further carries a first message authentication code MAC corresponding to the first next hop chain counter NCC; the method further includes:
[0179] The source base station key is used to encrypt the second secret parameter and the first message authentication code MAC to obtain key negotiation information.
[0180] Specifically, the source base station (s-gNB) receives the handover path confirmation message {β, K AMF {NCC}, MAC}, pass the key K of s-gNB gNB Encrypt the information, and then use the encrypted information K gNB {K AMF {NCC}, MAC} is sent to the terminal (UE).
[0181] In one embodiment, the switching path confirmation message further carries a timestamp of when the switching path confirmation message was sent; and the method further includes:
[0182] If it is determined that the sending timestamp of the switching path confirmation message meets the transmission delay threshold condition, then confirming that the sending timestamp of the switching path confirmation message passes the freshness verification;
[0183] The source base station key is used to encrypt the second secret parameter, the first message authentication code MAC, and the sending timestamp of the switching path confirmation message to obtain key negotiation information.
[0184] Specifically, the source base station s-gNB receives the handover path confirmation message {β, K AMF {NCC}, MAC, t1}, first check the freshness of the timestamp (t1) of the handover path confirmation message. If the timestamp is within the allowed range (0 < t ≤ γ, γ is the average transmission delay time), store β. gNB Encrypt the information, and then use the encrypted information K gNB {K AMF {NCC}, MAC, t1} is sent to the terminal (UE).
[0185] The key negotiation information may refer to the encrypted information K gNB {K AMF {NCC}, MAC, t1}. The transmission delay threshold condition may refer to 0<t≤γ.
[0186] In the above embodiment of the present application, the determination process of the switching key is modified so that the switching key (for example, the new access layer root key ) is not calculated at the source base station (s-gNB), but at the target base station (t-gNB), which enables the handover process of the 5G access layer to have one-hop forward security.
[0187] Based on the same inventive concept, an embodiment of the present application further provides a switching method implemented based on the aforementioned method for determining a switching key. The implementation solution provided by this switching method is similar to the implementation solution described in the aforementioned method for determining a switching key. Therefore, the specific limitations in one or more switching method embodiments provided below can be found in the above-mentioned limitations on the method for determining a switching key, and will not be repeated here.
[0188] In one embodiment, Figure 7 As shown, a switching method is provided, which is applied to Figure 2 The terminal device in the communication system shown is used as an example for description, and the following steps are included:
[0189] Step 602: In response to determining the handover key, generating terminal verification data; wherein the handover key is determined based on the above-mentioned handover key determination method;
[0190] Specifically, the terminal (UE) determines the switching key based on the above-mentioned switching key determination method. Afterwards, terminal verification data can be generated; the terminal (UE) generates the terminal verification data to ensure that the message has not been tampered with.
[0191] For example, the terminal verification data may include a terminal random number and a terminal timestamp generated by the terminal, for example, when determining a new key Afterwards, the terminal (UE) generates a random number n and a timestamp t2, wherein the terminal (UE) generates the random number n to ensure that the message has not been tampered with.
[0192] Step 604: Encrypt the terminal verification data using the switching key to obtain a first terminal key;
[0193] Specifically, after generating the terminal verification data, the terminal may encrypt it using the switching key.
[0194] Exemplarily, encrypting the terminal authentication data using the handover key to obtain the first terminal key may include:
[0195] Using the switching key, encrypt the terminal random number and the terminal timestamp to obtain a first terminal key;
[0196] Specifically, when determining the new key After that, the terminal (UE) generates a random number n (terminal random number) and timestamp t2 (terminal timestamp), and uses the new key Encryption to obtain the first terminal key
[0197] Step 606: Generate a second terminal key based on the first terminal key and the source base station key, output the second terminal key to instruct the source base station to decrypt the second terminal key, and output a handover message carrying the first secret parameter and the first terminal key; the handover message is used to instruct the target base station to which the terminal is to be handed over to feedback a handover confirmation message;
[0198] Specifically, after acquiring the first terminal key, the terminal (UE) may generate a second terminal key using the source base station key.
[0199] Exemplarily, generating the second terminal key based on the first terminal key and the source base station key may include:
[0200] The source base station key is used to encrypt the first terminal key and the terminal timestamp to obtain a second terminal key, so as to instruct the source terminal to transmit a handover message to the target base station when the terminal timestamp passes the freshness verification.
[0201] Specifically, taking Xn handover as an example, the terminal (UE) can use the key K of the source base station (s-gNB) gNB Encrypt the information and put the second terminal key Sent to the source base station (s-gNB).
[0202] Then, the source base station (s-gNB) uses its own key K gNB Decrypt the message sent by the terminal (UE) and check whether the timestamp t2 meets the requirements (0<t≤γ, γ is the average transmission delay time). If it meets the requirements (meeting the requirements means that the terminal timestamp passes the freshness verification), the source base station (s-gNB) will send the handover message to Sent to the target base station (t-gNB) so that the target base station (t-gNB) can feedback the switching confirmation message to the terminal (UE).
[0203] Step 608: In response to receiving the handover confirmation message, decrypt the handover confirmation message using the handover key to obtain a decryption result. If the decryption result meets the handover condition, the handover is confirmed to be completed.
[0204] Specifically, the terminal (UE) receives the handover confirmation message fed back by the target base station and can use the handover key Decryption is performed to obtain a decryption result; illustratively, the decryption result may refer to terminal verification data received by the terminal (UE), and then the terminal (UE) verifies whether the received terminal verification data meets the switching condition. If the switching condition is met, it is determined that the Xn switching between gNBs is completed.
[0205] Exemplarily, if the decryption result satisfies the switching condition, confirming that the switching is completed may include:
[0206] If the random number in the decryption result is the same as the terminal random number and the target base station timestamp in the decryption result passes the freshness verification, then the Xn handover is confirmed to be completed.
[0207] Specifically, the target base station timestamp t4 can be generated by the target base station (t-gNB), and then the target base station timestamp t4 can be generated by the target base station (t-gNB) through the handover confirmation message. Sent to the terminal (UE) so that each step of the handover process has a timestamp freshness check.
[0208] The terminal (UE) receives the handover confirmation message and uses the key After decryption, the received random number n is verified to be consistent with the random number previously sent to the source base station (s-gNB), and the timestamp t4 is verified to be consistent with the requirements (0 < t ≤ γ, where γ is the average transmission delay). If the random number n is consistent and the timestamp t4 is consistent, the inter-gNB Xn handover and key agreement are completed.
[0209] In one embodiment, the handover message is an XnAP handover message; the handover message also carries a timestamp of the source base station;
[0210] The handover confirmation message is obtained by encrypting the terminal random number and the target base station timestamp using the handover key by the target base station when both the source base station timestamp and the terminal timestamp pass the freshness verification.
[0211] Specifically, the handover message may be an XnAP handover message. Optionally, the handover message also carries the source base station timestamp t3; illustratively, the terminal (UE) sends the second terminal key Sent to s-gNB, the source base station (s-gNB) uses its own key K gNB Decrypt the message sent by the terminal (UE) and check whether the timestamp t2 meets the requirements (0<t≤γ, γ is the average transmission delay time). If it meets the requirements, the XnAP switching message is used to Sent to t-gNB.
[0212] In one embodiment, the method further comprises:
[0213] In response to receiving the key agreement information, decrypting the key agreement information using the source base station key to obtain a first message authentication code MAC and a second secret parameter carried in the key agreement information, decrypting the second secret parameter using the root key to obtain a first next-hop chain counter NCC;
[0214] Obtain a second message authentication code MAC of a next hop chain counter NCC corresponding to the next hop NH currently used to derive the handover key;
[0215] If the second message authentication code MAC is the same as the first message authentication code MAC, it is determined that the first next hop chain counter NCC passes the integrity check, and the handover key is derived according to the first next hop NH corresponding to the first next hop chain counter NCC;
[0216] If the second message authentication code MAC is different from the first message authentication code MAC, a switching rejection message is output; the switching rejection message is transmitted to the AMF network element via the source base station, used to instruct the AMF network element to change the first next hop NH to the initial next hop NH before this switching.
[0217] Specifically, in the 3GPP specification, NCC is associated with NH value, and then UE can know which NH to use to derive session key through NCC value. The embodiment of the present application modifies the key negotiation process of the handover process, and the NCC value (first next hop chain counter NCC) uses AMF key (NAS root key K AMF ) is encrypted, and the AMF network element then calculates the MAC value (first message authentication code MAC) to ensure the integrity of the NCC. Before using the NH, the UE checks whether the MAC value of the NCC corresponding to the NH (second message authentication code MAC) is equal to the received MAC value (first message authentication code MAC). If an unauthorized gNB sends a false NCC value, the UE will detect the mismatch when checking the MAC, thus preventing DoS and desynchronization attacks.
[0218] For example, the terminal (UE) uses the key K of the source base station (s-gNB) gNB , decrypt the key negotiation information transmitted by the source base station (s-gNB) and verify whether the MAC is correct. If the MAC fails to pass the verification, the UE cannot ensure that K AMF {NCC} integrity, the UE will reject the handover and transparently transmit the handover rejection message to the AMF network element through the source base station (s-gNB), causing the AMF network element to fall back to the old NH and NCC. If the MAC passes the integrity check, the terminal (UE) calculates the new key according to the formula (the above formula ① is used for the initial handover, and the above formula ② is used for non-initial handover)
[0219] Above, the embodiment of the present application modifies the key negotiation process of the switching process, first using the AMF key K AMF The NCC value is encrypted, and the AMF is designed to calculate the MAC value to protect the integrity of the NCC. Before using the NH value, the UE checks whether the MAC value of the NCC corresponding to the NH is equal to the received MAC value. If an unauthorized gNB sends a false NCC value, the UE will detect the mismatch when checking the MAC value, thus protecting the handover process from desynchronization attacks and DoS attacks.
[0220] In one embodiment, Figure 8 As shown, a switching method is provided, which is applied to Figure 2 Taking the target base station in the communication system as an example, the following steps are included:
[0221] Step 702: In response to determining the handover key, decrypt the first terminal key carried in the handover message using the handover key to obtain terminal verification data generated by the terminal; wherein the handover key is determined based on the above-mentioned handover key determination method;
[0222] Specifically, the target base station (t-gNB) receives a handover message (e.g., an XnAP handover message) transmitted by the source base station (s-gNB) and can determine the handover key based on the first secret parameter β carried in the handover message, for example, by obtaining the handover key through a modular operation.
[0223] Exemplarily, the handover message may further carry a timestamp of the active base station; and determining the handover key includes:
[0224] Receive the handover message transmitted by the source base station. If the source base station timestamp carried in the handover message passes the freshness verification, perform a modulo operation on the prime number allocated by the AMF network element to the target base station and the first secret parameter carried in the handover message to obtain the first next hop NH;
[0225] The handover key is derived based on the first next hop NH.
[0226] Specifically, the target base station (t-gNB) receives the handover message transmitted by the source base station (s-gNB) Check whether the source base station timestamp t3 meets the requirements (0 < t ≤ γ, where γ is the average transmission delay). If so, the source base station timestamp t3 passes the freshness verification. Then, the target base station (t-gNB) can calculate the new NH (first next hop NH) using the following formula:
[0227] NH=βmodS i
[0228] Among them, S i It is a large prime number allocated by the AMF network element to the target base station (t-gNB) during the preparation phase.
[0229] As described above, compared with the 5G handover authentication and key agreement protocol defined in 3GPP, the embodiment of the present application mainly adds modular multiplication and modular inverse operations. The amount of calculation is not increased much, and the changes to the original protocol are relatively small, which is feasible.
[0230] Furthermore, after the target base station (t-gNB) obtains the value of NH, it can calculate the handover key according to the above formula ② Then the first terminal key can be decrypted to obtain the terminal verification data generated by the terminal. Decrypt the first terminal key Get the terminal random number n and terminal timestamp t2.
[0231] Step 704: Output a handover confirmation message based on the terminal verification data; the handover confirmation message is used to instruct the terminal to decrypt the handover confirmation message using the handover key to obtain a decryption result, and confirm the completion of the handover if the decryption result meets the handover condition.
[0232] Specifically, the target base station (t-gNB) obtains the terminal verification data and can output a switching confirmation message to the terminal (UE) to instruct the terminal to decrypt the switching confirmation message using the switching key, obtain the decryption result, and confirm the completion of the switching if the decryption result meets the switching conditions.
[0233] In one embodiment, the terminal verification data includes a terminal random number and a terminal timestamp generated by the terminal;
[0234] Based on the terminal verification data, a handover confirmation message is output, including:
[0235] If the terminal timestamp passes the freshness verification, the target base station timestamp is generated;
[0236] The handover key is used to encrypt the terminal random number and the target base station timestamp to obtain a handover confirmation message.
[0237] Specifically, after obtaining the terminal random number n and the terminal timestamp t2, the target base station (t-gNB) can check whether the terminal timestamp t2 meets the requirements (0 < t ≤ γ, γ is the average transmission delay time). If it meets the requirements, it is determined that the terminal timestamp t2 has passed the freshness verification, and then the target base station (t-gNB) generates its own timestamp t4 (target base station timestamp) and sends it to the target base station through the handover confirmation message. Sent to UE.
[0238] In order to further illustrate the solution of this application, a specific example is given below. Figure 9 As shown, taking the communication system including the access and mobility management function AMF network element, the source base station (s-gNB), the target base station (t-gNB) and the terminal equipment (UE) as an example, the embodiment of the present application only modifies the handover process after the handover decision is completed. The type of key held by the UE, gNB and AMF remains unchanged. Before the first Xn handover occurs, the UE and AMF both hold the same K AMF , K gNB , NH and matching NCC (initial 1), while the gNB connected to the UE only has the initial K gNB(NCC value is 0). The specific process may include the following:
[0239] 1. After the access layer determines that Xn handover is required, the s-gNB sends a handover path request to the AMF, and the AMF enters the parameter preparation phase:
[0240] Assume there are n gNBs to be switched, that is, there are n candidate t-gNBs.
[0241] 2. AMF randomly generates n+1 large prime numbers and assigns a prime number to each possible t-gNB to be switched in step 1, which is recorded as S i , i = 1, ..., n. A large prime number is also assigned to the AMF itself, denoted as S0.
[0242] AMF calculates the new NH according to the above formula ④, associates it with the new NCC value, and performs the following calculations:
[0243] calculate:
[0244] For each i (i=1, ..., n), calculate and
[0245] calculate:
[0246] Calculate the first secret parameter: β = λNH
[0247] Calculation: MAC = H(K AMF {NCC}||K AMF )
[0248] Here, “H(x)” refers to the summary of x calculated using the hash function. x {y}" refers to the key K used by X x Encrypt y.
[0249] After the AMF parameter preparation phase is completed, the handover phase begins:
[0250] 1. After completing the calculation work in the preparation phase, AMF also needs to use K AMF Encrypt the new NCC value and put {β, K AMF {NCC}, MAC, t1} is sent to the s-gNB, where t1 is the timestamp of the time when the message is sent.
[0251] 2. After receiving the message, the s-gNB first checks the freshness of the timestamp t1. If the timestamp is within the allowed range (0 < t ≤ γ, γ is the average transmission delay time), it stores β. gNBEncrypt the information, and then use the encrypted information K gNB {K AMF {NCC}, MAC, t1} is sent to the UE.
[0252] 3. UE uses the key K of s-gNB gNB Decrypt the message and verify whether the MAC is correct. If the MAC fails to pass the verification, the UE cannot ensure that K AMF If the integrity of {NCC} is not verified, the UE will reject the handover and transparently transmit the handover rejection message to the AMF through the s-gNB, causing the AMF to fall back to the old NH and NCC. If the MAC passes the integrity check, the UE calculates the new key according to the formula (the above formula ① is used for the initial handover and the above formula ② is used for non-initial handover) Generate a random number n and timestamp t2, and use the new key Finally, the UE uses the s-gNB's key K gNB Encrypt information, Sent to s-gNB.
[0253] 4. s-gNB uses its own key K gNB Decrypt the message sent by UE and check whether the timestamp t2 meets the requirements (0<t≤γ, γ is the average transmission delay time). If it meets the requirements, the XnAP switching message is used to Sent to t-gNB.
[0254] 5. After receiving the message, t-gNB checks whether the timestamp t3 meets the requirements (0<t≤γ, γ is the average transmission delay time), and uses the formula NH=βmodS i Calculate the new NH, where S i It is the large prime number assigned by AMF to t-gNB in step 2 of the preparation phase. After t-gNB obtains the value of NH, it can calculate the new You can decrypt Get the random number n and timestamp t2. Then check whether the timestamp t2 meets the requirements (0<t≤γ, γ is the average transmission delay time). If it meets the requirements, the t-gNB generates its own timestamp t4 and sends it to the t-gNB through the handover confirmation message. Sent to UE.
[0255] 6. UE receives the message and uses the key After decryption, the received random number n is verified to be consistent with the random number previously sent to the s-gNB, and the timestamp t4 is verified to be consistent with the requirements (0 < t ≤ γ, where γ is the average transmission delay). If the random number n is consistent and the timestamp t4 is consistent, the inter-gNB Xn handover and key agreement are completed.
[0256] As described above, the embodiments of the present application provide security supplements for the problems existing in the 3GPP specifications for the handover authentication and key agreement protocol of the 5G access layer, so that the handover process has one-hop forward security and can effectively prevent DoS attacks and anti-synchronization attacks.
[0257] This application proposes a handover authentication and key agreement method for the 5G access layer, theoretically applicable to all Xn handover scenarios involving gNBs. Compared to the 5G handover authentication and key agreement protocol defined in 3GPP, this application adds modular multiplication and modular inverse operations, which only slightly increases the computational load and makes relatively minor changes to the original protocol, making it feasible. This embodiment of the application can improve the security of the 5G access layer handover authentication and key agreement protocol and reduce the success rate of attacks on the 5G network at the access layer.
[0258] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0259] Based on the same inventive concept, embodiments of the present application also provide a device for determining a handover key for implementing the aforementioned method for determining a handover key. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations in the embodiments of one or more handover key determination devices provided below can be found in the limitations of the handover key determination method described above and will not be repeated here.
[0260] In one embodiment, Figure 10 As shown, a handover key determination device 100 is provided, which is applied to an access and mobility management function AMF network element. The device 100 includes:
[0261] The path confirmation module 110 is configured to output a switching path confirmation message in response to receiving a switching path request transmitted by the source base station; the switching path confirmation message carries a first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and a second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element;
[0262] The switching path confirmation message is used to instruct the source base station to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station, and to transmit a switching message carrying the first secret parameter to the target base station; wherein, the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
[0263] In one embodiment, the first next hop NH is an initial next hop NH before the current handover, which is derived by the AMF network element using a root key; the apparatus 100 further includes:
[0264] The first encryption module is used to encrypt the first next hop NH by using a secret sharing algorithm to obtain a first secret parameter.
[0265] In one of the embodiments, the first encryption module is used to assign randomly generated prime numbers to each target base station and AMF network element to be switched by the terminal to obtain an allocation result; and use a secret sharing method based on the Chinese remainder theorem CRT to obtain a first secret parameter based on the allocation result and the first next hop NH.
[0266] In one embodiment, the handover path confirmation message further carries a first message authentication code MAC for instructing the terminal to confirm the integrity of the first next hop chain counter NCC; the key agreement information is obtained by encrypting the second secret parameter and the first message authentication code MAC by the source base station using the source base station key;
[0267] The apparatus 100 further includes:
[0268] The second encryption module is used to encrypt the first next hop chain counter NCC with a root key to obtain a second secret parameter; and is used to process the second secret parameter with a hash algorithm based on the root key to obtain a first message authentication code MAC.
[0269] In one of the embodiments, the switching path confirmation message also carries a sending timestamp of the switching path confirmation message;
[0270] The key negotiation information is obtained by encrypting the second secret parameter, the first message authentication code MAC and the sending timestamp of the switching path confirmation message using the source base station key when the sending timestamp of the switching path confirmation message passes the freshness verification.
[0271] In one embodiment, the root key includes a non-access stratum NAS root key; and the handover key is used for Xn handover when the terminal switches to a target base station.
[0272] In one embodiment, Figure 11As shown, a handover key determination device 200 is provided, which is applied to a source base station. The device 200 includes:
[0273] The handover request module 210 is configured to send a handover path request to the access and mobility management function AMF network element; the handover path request is used to instruct the AMF network element to feedback a handover path confirmation message; the handover path confirmation message carries a first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and a second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element;
[0274] The switching prompt module 220 is used to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station in response to receiving the switching path confirmation message, and transmit a switching message carrying the first secret parameter to the target base station; wherein the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; and the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
[0275] In one embodiment, the switching request module 210 is used to send a switching path request to the AMF network element in response to the triggering of the Xn switching.
[0276] In one embodiment, the switching path confirmation message further carries a first message authentication code MAC corresponding to the first next hop chain counter NCC; the apparatus 200 further includes:
[0277] The key negotiation module is used to encrypt the second secret parameter and the first message authentication code MAC using the source base station key to obtain key negotiation information.
[0278] In one of the embodiments, the switching path confirmation message also carries a sending timestamp of the switching path confirmation message;
[0279] The key negotiation module is used to confirm that the sending timestamp of the switching path confirmation message passes the freshness verification if it is determined that the sending timestamp of the switching path confirmation message meets the transmission delay threshold condition; and use the source base station key to encrypt the second secret parameter, the first message authentication code MAC and the sending timestamp of the switching path confirmation message to obtain key negotiation information.
[0280] Based on the same inventive concept, embodiments of the present application further provide a switching device for implementing the aforementioned switching method. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations in one or more switching device embodiments provided below can be found in the above-described limitations on the switching method and will not be further elaborated here.
[0281] In one embodiment, Figure 12 As shown, a switching device 300 is provided, which is applied to a terminal. The device 300 includes:
[0282] The verification data generating module 310 is configured to generate terminal verification data in response to determining the handover key; wherein the handover key is determined based on the above-mentioned handover key determination method;
[0283] A first key generation module 320 is configured to encrypt the terminal verification data using the switching key to obtain a first terminal key;
[0284] A second key generation module 330 is configured to generate a second terminal key based on the first terminal key and the source base station key, output the second terminal key to instruct the source base station to decrypt the second terminal key, and output a handover message carrying the first secret parameter and the first terminal key; the handover message is used to instruct the target base station to which the terminal is to be handed over to feed back a handover confirmation message;
[0285] The switching module 340 is configured to, in response to receiving the switching confirmation message, decrypt the switching confirmation message using the switching key to obtain a decryption result, and confirm that the switching is completed if the decryption result meets the switching condition.
[0286] In one embodiment, the terminal verification data includes a terminal random number and a terminal timestamp generated by the terminal;
[0287] A first key generation module 320 is configured to encrypt the terminal random number and the terminal timestamp using the switching key to obtain a first terminal key;
[0288] The second key generation module 330 is used to encrypt the first terminal key and the terminal timestamp using the source base station key to obtain a second terminal key to instruct the source terminal to transmit a handover message to the target base station when the terminal timestamp passes the freshness verification.
[0289] In one embodiment, the handover message is an XnAP handover message; the handover message also carries a timestamp of the source base station;
[0290] The handover confirmation message is obtained by encrypting the terminal random number and the target base station timestamp using the handover key by the target base station when both the source base station timestamp and the terminal timestamp pass the freshness verification.
[0291] In one embodiment, the switching module 340 is configured to confirm that the Xn switching is completed if the random number in the decryption result is the same as the terminal random number and the target base station timestamp in the decryption result passes the freshness verification.
[0292] In one embodiment, the apparatus 300 further includes:
[0293] a negotiation decryption module, configured to, in response to receiving the key negotiation information, decrypt the key negotiation information using the source base station key, obtain a first message authentication code MAC and a second secret parameter carried in the key negotiation information, decrypt the second secret parameter using the root key, and obtain a first next-hop chain counter NCC;
[0294] A verification code acquisition module is used to obtain a second message authentication code MAC of a next hop chain counter NCC corresponding to the next hop NH currently used to derive the handover key;
[0295] a handover key acquisition module, configured to determine that the first next hop chain counter NCC passes the integrity check if the second message authentication code MAC is the same as the first message authentication code MAC, and derive the handover key based on the first next hop NH corresponding to the first next hop chain counter NCC;
[0296] The switching rejection module is used to output a switching rejection message if the second message authentication code MAC is different from the first message authentication code MAC; the switching rejection message is transmitted to the AMF network element via the source base station, and is used to instruct the AMF network element to change the first next hop NH to the initial next hop NH before this switching.
[0297] In one embodiment, Figure 13 As shown, a switching device 400 is provided, which is applied to a target base station. The device 400 includes:
[0298] a decryption module 410 configured to, in response to determining the handover key, decrypt the first terminal key carried in the handover message using the handover key to obtain terminal verification data generated by the terminal; wherein the handover key is determined based on the above-mentioned handover key determination method;
[0299] The handover confirmation module 420 is used to output a handover confirmation message based on the terminal verification data; the handover confirmation message is used to instruct the terminal to decrypt the handover confirmation message using the handover key to obtain a decryption result, and confirm the completion of the handover if the decryption result meets the handover condition.
[0300] In one embodiment, the handover message further carries a timestamp of the source base station; and the apparatus 400 further includes:
[0301] The modular operation module is used to receive the handover message transmitted by the source base station. If the source base station timestamp carried in the handover message passes the freshness verification, the modular operation is performed on the prime number allocated by the AMF network element to the target base station and the first secret parameter carried in the handover message to obtain the first next hop NH;
[0302] The key acquisition module is used to derive a handover key according to the first next hop NH.
[0303] In one embodiment, the terminal verification data includes a terminal random number and a terminal timestamp generated by the terminal;
[0304] The handover confirmation module 420 is configured to generate a target base station timestamp if the terminal timestamp passes the freshness verification; and encrypt the terminal random number and the target base station timestamp using the handover key to obtain a handover confirmation message.
[0305] Each module in the above-mentioned apparatus may be implemented in whole or in part by software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to each module.
[0306] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 14 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface, the display unit and the input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a switching method is implemented. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.
[0307] Those skilled in the art will understand that Figure 14 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0308] In one embodiment, a core network device is provided, including a memory and a processor, wherein the memory stores a computer program, and the core network device is an access and mobility management function (AMF) network element;
[0309] When the processor executes the computer program, it implements the steps of the above-mentioned method for determining the switching key from the perspective of the AMF network element.
[0310] In one embodiment, a base station is provided, comprising a memory and a processor, wherein the memory stores a computer program, and the base station is a source base station;
[0311] When the processor executes the computer program, the steps of the above-mentioned method for determining the handover key from the perspective of the source base station are implemented.
[0312] In one embodiment, a terminal device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the switching method implemented from the perspective of the terminal device when executing the computer program.
[0313] In one embodiment, a base station is provided, comprising a memory and a processor, wherein the memory stores a computer program, and the base station is a target base station;
[0314] When the processor executes the computer program, the steps of the above-mentioned handover method implemented from the perspective of the target base station are implemented.
[0315] In one embodiment, a communication system is provided, comprising:
[0316] Access and mobility management function AMF network element, used to perform the steps of the above method
[0317] A source base station, configured to execute the steps of the above method;
[0318] A target base station, configured to execute the steps of the above method;
[0319] The terminal device is used to execute the steps of the above method.
[0320] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are implemented.
[0321] In one embodiment, a computer program product is provided, comprising a computer program, which implements the steps of the above method when executed by a processor.
[0322] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.
[0323] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0324] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A method for determining a switching key, characterized in that: Applied to an access and mobility management function (AMF) network element, the method includes: In response to receiving the handover path request transmitted by the source base station, output a handover path confirmation message; the handover path confirmation message carries the first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and the second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element; The switching path confirmation message is used to instruct the source base station to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station, and to transmit a switching message carrying the first secret parameter to the target base station; wherein the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; and the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
2. The method according to claim 1, characterized in that The first next hop NH is an initial next hop NH before the current handover, derived by the AMF network element using a root key; the method further includes: The first next hop NH is encrypted using a secret sharing algorithm to obtain the first secret parameter.
3. The method according to claim 2, characterized in that The adopting a secret sharing algorithm to encrypt the first next hop NH includes: Allocate randomly generated prime numbers to each target base station to be switched by the terminal and the AMF network element, respectively, to obtain an allocation result; The first secret parameter is obtained based on the allocation result and the first next hop NH by using a secret sharing method based on the Chinese Remainder Theorem CRT.
4. The method according to claim 1, wherein The switching path confirmation message further carries a first message authentication code MAC for instructing the terminal to confirm the integrity of the first next hop chain counter NCC; The key agreement information is obtained by encrypting the second secret parameter and the first message authentication code MAC by the source base station using the source base station key; The method further comprises: Encrypting the first next-hop chain counter NCC using a root key to obtain the second secret parameter; Based on the root key, the second secret parameter is processed using a hash algorithm to obtain the first message authentication code MAC.
5. The method according to claim 4, characterized in that The switching path confirmation message also carries a sending timestamp of the switching path confirmation message; The key negotiation information is obtained by encrypting the second secret parameter, the first message authentication code MAC and the sending timestamp of the switching path confirmation message using the source base station key when the sending timestamp of the switching path confirmation message passes the freshness verification.
6. The method according to any one of claims 2 to 5, characterized in that The root key includes a non-access stratum NAS root key; the handover key is used for Xn handover when the terminal switches to the target base station.
7. A method for determining a switching key, characterized in that: Applied to a source base station, the method includes: Send a handover path request to the access and mobility management function AMF network element; the handover path request is used to instruct the AMF network element to feedback a handover path confirmation message; the handover path confirmation message carries the first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and the second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element; In response to receiving the switching path confirmation message, key negotiation information obtained based on the second secret parameter is transmitted to the terminal to be switched to the target base station, and a switching message carrying the first secret parameter is transmitted to the target base station; wherein the key negotiation information is used to instruct the terminal to determine the switching key according to the second secret parameter; and the switching message is used to instruct the target base station to determine the switching key according to the first secret parameter.
8. The method according to claim 7, characterized in that The sending a handover path request to an access and mobility management function AMF network element includes: In response to the triggering of Xn switching, the switching path request is sent to the AMF network element.
9. The method according to claim 7, characterized in that The switching path confirmation message further carries a first message authentication code MAC corresponding to the first next hop chain counter NCC; the method further includes: The source base station key is used to encrypt the second secret parameter and the first message authentication code MAC to obtain the key negotiation information.
10. The method according to claim 9, characterized in that The switching path confirmation message also carries a sending timestamp of the switching path confirmation message; and the method further includes: If it is determined that the sending timestamp of the switching path confirmation message meets the transmission delay threshold condition, confirming that the sending timestamp of the switching path confirmation message passes the freshness verification; The source base station key is used to encrypt the second secret parameter, the first message authentication code MAC, and the sending timestamp of the switching path confirmation message to obtain the key negotiation information.
11. A switching method, characterized in that: Applied to a terminal, the method includes: In response to determining the handover key, generating terminal verification data; wherein the handover key is determined based on the handover key determination method according to any one of claims 1 to 10; Encrypting the terminal verification data using the switching key to obtain a first terminal key; generating a second terminal key based on the first terminal key and the source base station key, outputting the second terminal key to instruct the source base station to decrypt the second terminal key, and outputting the handover message carrying the first secret parameter and the first terminal key; the handover message is used to instruct the target base station to which the terminal is to be handed over to feed back a handover confirmation message; In response to receiving the handover confirmation message, the handover confirmation message is decrypted using the handover key to obtain a decryption result. If the decryption result meets the handover condition, the handover is confirmed to be completed.
12. The method according to claim 11, characterized in that The terminal verification data includes a terminal random number and a terminal timestamp generated by the terminal; The step of encrypting the terminal verification data using the switching key to obtain the first terminal key includes: Encrypting the terminal random number and the terminal timestamp using the handover key to obtain the first terminal key; Generating a second terminal key based on the first terminal key and the source base station key includes: The first terminal key and the terminal timestamp are encrypted using the source base station key to obtain the second terminal key, so as to instruct the source base station to transmit the switching message to the target base station when the terminal timestamp passes the freshness verification.
13. The method according to claim 12, characterized in that The handover message is an XnAP handover message; the handover message also carries an active base station timestamp; The handover confirmation message is obtained by encrypting the terminal random number and the target base station timestamp by the target base station using the handover key when both the source base station timestamp and the terminal timestamp pass the freshness verification.
14. The method according to claim 13, characterized in that If the decryption result satisfies the switching condition, confirming that the switching is completed includes: If the random number in the decryption result is the same as the terminal random number and the target base station timestamp in the decryption result passes the freshness verification, then the Xn handover is confirmed to be completed.
15. The method according to claim 11, characterized in that The method further comprises: In response to receiving the key agreement information, decrypting the key agreement information using the source base station key to obtain a first message authentication code MAC and the second secret parameter carried by the key agreement information, and decrypting the second secret parameter using the root key to obtain the first next-hop chain counter NCC; Obtain a second message authentication code MAC of a next hop chain counter NCC corresponding to the next hop NH currently used to derive the handover key; If the second message authentication code MAC is the same as the first message authentication code MAC, determining that the first next hop chaining counter NCC passes the integrity check, and deriving the handover key according to the first next hop NH corresponding to the first next hop chaining counter NCC; If the second message authentication code MAC is different from the first message authentication code MAC, a handover rejection message is output; the handover rejection message is transmitted to the AMF network element via the source base station, used to instruct the AMF network element to change the first next hop NH to the initial next hop NH before this handover.
16. A switching method, characterized in that: Applied to a target base station, the method includes: In response to determining the handover key, decrypting the first terminal key carried in the handover message using the handover key to obtain terminal verification data generated by the terminal; wherein the handover key is determined based on the handover key determination method according to any one of claims 1 to 10; Based on the terminal verification data, a switching confirmation message is output; the switching confirmation message is used to instruct the terminal to decrypt the switching confirmation message using the switching key to obtain a decryption result, and confirm the completion of the switching if the decryption result meets the switching condition.
17. The method according to claim 16, characterized in that The handover message also carries the timestamp of the active base station; Determining the switching key includes: Receive the handover message transmitted by the source base station, and if the source base station timestamp carried by the handover message passes the freshness verification, perform a modulo operation on the prime number allocated by the AMF network element to the target base station and the first secret parameter carried by the handover message to obtain the first next hop NH; The handover key is derived according to the first next hop NH.
18. The method according to claim 17, characterized in that The terminal verification data includes a terminal random number and a terminal timestamp generated by the terminal; The outputting a handover confirmation message based on the terminal verification data includes: If the terminal timestamp passes the freshness verification, generating a target base station timestamp; The handover key is used to encrypt the terminal random number and the target base station timestamp to obtain the handover confirmation message.
19. A device for determining a switching key, characterized in that: Applicable to an access and mobility management function (AMF) network element, the device includes: A path confirmation module is configured to output a switching path confirmation message in response to receiving a switching path request transmitted by a source base station; the switching path confirmation message carries a first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and a second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element; The switching path confirmation message is used to instruct the source base station to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station, and to transmit a switching message carrying the first secret parameter to the target base station; wherein the key negotiation information is used to instruct the terminal to determine the switching key based on the second secret parameter; and the switching message is used to instruct the target base station to determine the switching key based on the first secret parameter.
20. A device for determining a switching key, characterized in that: Applied to a source base station, the apparatus includes: A handover request module is configured to send a handover path request to an access and mobility management function (AMF) network element; the handover path request is used to instruct the AMF network element to feed back a handover path confirmation message; the handover path confirmation message carries a first secret parameter obtained by encrypting the first next hop NH by the AMF network element, and a second secret parameter obtained by encrypting the first next hop chain counter NCC corresponding to the first next hop NH by the AMF network element; A switching prompt module is used to transmit key negotiation information obtained based on the second secret parameter to the terminal to be switched to the target base station in response to receiving the switching path confirmation message, and transmit a switching message carrying the first secret parameter to the target base station; wherein the key negotiation information is used to instruct the terminal to determine the switching key according to the second secret parameter; and the switching message is used to instruct the target base station to determine the switching key according to the first secret parameter.
21. A switching device, characterized in that: Applied to a terminal, the device includes: A verification data generation module, configured to generate terminal verification data in response to determining a handover key; wherein the handover key is determined based on the handover key determination method according to any one of claims 1 to 10; A first key generation module, configured to encrypt the terminal verification data using a switching key to obtain a first terminal key; a second key generation module, configured to generate a second terminal key based on the first terminal key and the source base station key, output the second terminal key to instruct the source base station to decrypt the second terminal key, and output the handover message carrying the first secret parameter and the first terminal key; the handover message is used to instruct the target base station to which the terminal is to be handed over to feed back a handover confirmation message; The switching module is configured to, in response to receiving the switching confirmation message, decrypt the switching confirmation message using the switching key to obtain a decryption result, and confirm that the switching is completed if the decryption result meets the switching condition.
22. A switching device, characterized in that: Applied to a target base station, the device includes: a decryption module, configured to, in response to determining a handover key, decrypt the first terminal key carried in the handover message using the handover key to obtain terminal verification data generated by the terminal; wherein the handover key is determined based on the handover key determination method according to any one of claims 1 to 10; The switching confirmation module is used to output a switching confirmation message based on the terminal verification data; the switching confirmation message is used to instruct the terminal to decrypt the switching confirmation message using the switching key to obtain a decryption result, and confirm the completion of the switching when the decryption result meets the switching condition.
23. A core network device comprising a memory and a processor, wherein the memory stores a computer program, wherein: The core network device is an access and mobility management function AMF network element; When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
24. A base station comprising a memory and a processor, wherein the memory stores a computer program, wherein: The base station is a source base station; When the processor executes the computer program, the steps of the method according to any one of claims 7 to 10 are implemented.
25. A terminal device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 11 to 15 are implemented.
26. A base station comprising a memory and a processor, wherein the memory stores a computer program, wherein: The base station is a target base station; When the processor executes the computer program, the steps of the method according to any one of claims 16 to 18 are implemented.
27. A communication system, characterized in that: include: Access and mobility management function AMF network element, configured to perform the steps of the method according to any one of claims 1 to 6 A source base station, configured to perform the steps of the method according to any one of claims 7 to 10; A target base station, configured to perform the steps of the method according to any one of claims 11 to 15; A terminal device, configured to execute the steps of the method according to any one of claims 16 to 18.
28. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 18 are implemented.
29. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 18 are implemented.
Citation Information
Patent Citations
Key generation method and system in switching process
CN103139771A
Switching method, network equipment, user equipment and communication system
CN113938970A