Information processing method and apparatus, communication device, and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-19
- Publication Date
- 2026-08-11
AI Technical Summary
事实上,UE-to-UE中继作为一个不受信任中间传输节点可能会受到损害,从而导致对等UE之间信息的安全性受到损害
[0026] The technical solutions provided in this disclosure, and the UE-related strategies, are determined based on the UE's physical state information. Such strategies for controlling the UE's data flow do not only consider the network conditions but also ignore the UE's physical conditions. This reduces the waste of network resources and/or poor communication quality of the UE caused by the inconsistency between the formulated strategies and the UE's physical conditions, thereby improving the UE's communication quality and reducing the waste of network resources.
Smart Images

Figure CN117256166B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to, but is not limited to, the field of wireless communication technology, and particularly to an information processing method and apparatus, communication equipment and storage medium. Background Technology
[0002] Proximity-based service (Prose) allows peer terminals to communicate via a User Equipment (UE)-to-UE relay. This means that if the source UE cannot directly reach the target UE, the source UE will attempt to discover the UE-to-UE relay to reach the target UE. Furthermore, before the source UE can communicate with the target UE via the relay UE, it needs to discover the target UE through the relay UE. In fact, the UE-to-UE relay, as an untrusted intermediate transmission node, may be compromised, thereby compromising the security of information between peer UEs.
[0003] A malicious relay UE establishing unicast links with both the source and target UEs could potentially launch a man-in-the-middle attack (MITM) against the terminal. Therefore, end-to-end connection security is required between peer terminals communicating via UE-to-UE relays.
[0004] The Direct Discovery Name Management Function (DDNMF) is a network element that provides the UE with necessary security information to protect discovery messages. Furthermore, the DDNMF can interact with the Prose Application Server to authorize discovery requests. Summary of the Invention
[0005] This disclosure provides an information processing method and apparatus, a communication device and a storage medium.
[0006] A first aspect of this disclosure provides an information processing method, wherein the method is executed by a first remote user equipment (UE), the method comprising:
[0007] Obtain a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE;
[0008] A second key is generated based on the first key, wherein the second key is used for information integrity protection between two remote UEs for mutual discovery via a relay UE.
[0009] A second aspect of this disclosure provides an information processing method, executed by a relay UE, the method comprising:
[0010] Obtain a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE;
[0011] A second key is generated based on the first key, wherein the second key is used for information integrity protection between two remote UEs for mutual discovery via a relay UE.
[0012] A third aspect of this disclosure provides an information processing method, wherein the method is executed by DDNMF, and the method further includes:
[0013] Receive request messages sent by remote UEs and / or relay UEs;
[0014] According to the request message, a first key is sent to the remote UE and / or the relay UE; the first key is used for integrity protection of communication between the first remote UE and the relay UE, and is also used to generate a second key, wherein the second key is used for information integrity protection of mutual discovery between the two remote UEs through the relay UE.
[0015] A fourth aspect of this disclosure provides an information processing apparatus, wherein the apparatus includes:
[0016] The first acquisition module is configured to acquire a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE;
[0017] The first generation module is configured to generate a second key based on the first key, wherein the second key is used for information integrity protection between two remote UEs for mutual discovery via a relay UE.
[0018] A fifth aspect of this disclosure provides an information processing apparatus, the apparatus comprising:
[0019] The second acquisition module is configured to acquire a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE;
[0020] The third generation module is configured to generate a second key based on the first key, wherein the second key is used for information integrity protection between two remote UEs for mutual discovery via a relay UE.
[0021] A sixth aspect of this disclosure provides an information processing apparatus, wherein the apparatus further includes:
[0022] The third receiving module is configured to receive request messages sent by remote UEs and / or relay UEs;
[0023] The third sending module is configured to send a first key to the remote UE and / or the relay UE according to the request message; the first key is used for integrity protection of communication between the first remote UE and the relay UE, and is also used to generate a second key, wherein the second key is used for information integrity protection of mutual discovery between the two remote UEs through the relay UE.
[0024] A seventh aspect of this disclosure provides a communication device, including a processor, a transceiver, a memory, and an executable program stored in the memory and executable by the processor, wherein when the processor executes the executable program, it performs an information processing method as provided in any one of the first to third aspects described above.
[0025] The eighth aspect of this disclosure provides a computer storage medium storing an executable program; after being executed by a processor, the executable program can implement the information processing method provided by any one of the first to third aspects.
[0026] The technical solutions provided in this disclosure, and the UE-related strategies, are determined based on the UE's physical state information. Such strategies for controlling the UE's data flow do not only consider the network conditions but also ignore the UE's physical conditions. This reduces the waste of network resources and / or poor communication quality of the UE caused by the inconsistency between the formulated strategies and the UE's physical conditions, thereby improving the UE's communication quality and reducing the waste of network resources.
[0027] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the embodiments of this disclosure. Attached Figure Description
[0028] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the embodiments of the invention.
[0029] Figure 1 This is a schematic diagram illustrating the structure of a wireless communication system according to an exemplary embodiment;
[0030] Figure 2 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0031] Figure 3 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0032] Figure 4 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0033] Figure 5 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0034] Figure 6 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0035] Figure 7 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0036] Figure 8 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0037] Figure 9 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0038] Figure 10 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;
[0039] Figure 11 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;
[0040] Figure 12 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;
[0041] Figure 13 This is a schematic diagram of the structure of a UE according to an exemplary embodiment;
[0042] Figure 14 This is a schematic diagram of the structure of a communication device according to an exemplary embodiment. Detailed Implementation
[0043] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of the present invention. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of the present invention.
[0044] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the embodiments disclosed herein. The singular forms “a,” “the,” and “the” used herein are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0045] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of this disclosure, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first information may also be referred to as second information without departing from the scope of embodiments of this disclosure, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."
[0046] Please refer to Figure 1 This illustration shows a schematic diagram of the structure of a wireless communication system provided in an embodiment of this disclosure. Figure 1 As shown, the wireless communication system is a communication system based on cellular mobile communication technology. The wireless communication system may include: several UEs 11 and several access devices 12.
[0047] UE11 can be a device that provides voice and / or data connectivity to a user. UE11 can communicate with one or more core networks via a Radio Access Network (RAN). UE11 can be an IoT UE, such as a sensor device, a mobile phone (or "cellular" phone), and a computer with an IoT UE. For example, it can be a fixed, portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted device. Examples include a station (STA), subscriber unit, subscriber station, mobile station, mobile station, remote station, access point, remote terminal, access terminal, user terminal, user agent, user device, or user equipment (UE). Alternatively, UE11 can be a device in an unmanned aerial vehicle (UAV). Alternatively, UE11 can be a vehicle-mounted device, such as a vehicle computer with wireless communication capabilities, or a wireless communication device connected to an external vehicle computer. Alternatively, UE11 can also be a roadside device, such as a street light, traffic light, or other roadside device with wireless communication capabilities.
[0048] Access device 12 can be a network-side device in a wireless communication system. This wireless communication system can be a 4G system (also known as Long Term Evolution, LTE); or it can be a 5G system (also known as a New Radio, NR, or 5G NR system). Alternatively, it can be the next generation after 5G. In this case, the access network in the 5G system can be called NG-RAN (New Generation-Radio Access Network). Alternatively, it can be an MTC system.
[0049] The access device 12 can be an evolved NB (eNB) used in a 4G system. Alternatively, the access device 12 can also be a gNB (gNB) using a centralized-distributed architecture in a 5G system. When the access device 12 adopts a centralized-distributed architecture, it typically includes a central unit (CU) and at least two distributed units (DUs). The central unit is equipped with a protocol stack of the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, and the Media Access Control (MAC) layer; the distributed units are equipped with a physical (PHY) layer protocol stack. This disclosure does not limit the specific implementation of the access device 12.
[0050] Access device 12 and UE11 can establish a wireless connection via a wireless air interface. In different implementations, the wireless air interface is a wireless air interface based on the fourth-generation mobile communication network technology (4G) standard; or, the wireless air interface is a wireless air interface based on the fifth-generation mobile communication network technology (5G) standard, such as a new air interface; or, the wireless air interface can also be a wireless air interface based on a next-generation mobile communication network technology standard based on 5G.
[0051] like Figure 2 As shown, this disclosure provides an information processing method, which is executed by a first remote UE, the method comprising:
[0052] S1110: Obtain a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE;
[0053] S1120: Generate a second key based on the first key, wherein the second key is used for information integrity protection between two remote UEs for mutual discovery via a relay UE.
[0054] The first remote UE can be either the source UE or the target UE for UE-to-UE relay communication.
[0055] The first key can be an integrity protection key used by the first remote UE when communicating with the network device through the relay UE. It can be used as a key for integrity protection when the first remote UE sends data to the network through the relay UE, or as a key for integrity protection when the relay UE forwards data provided by the network device to the first remote UE.
[0056] The length of the first key can be 128 bits, 256 bits, 64 bits, or 512 bits, etc.
[0057] In some embodiments, for example, the second key is derived from the first key using a key derivation function. Further, the second key is derived from the first key itself and the length of the first key using the same key derivation function.
[0058] In this embodiment of the disclosure, a second key is generated based on the first key. This second key can be used for integrity protection between two remote UEs through mutual discovery between relay UEs, thereby ensuring the security of mutual discovery between the two remote UEs.
[0059] like Figure 3 As shown, this disclosure provides an information processing method, which is executed by a first remote UE, the method comprising:
[0060] S1210: Obtain a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE;
[0061] S1220: Send a first random number to the relay UE;
[0062] S1230: Receive the second random number sent by the relay UE;
[0063] S1240: Generate the second key based on the first random number, the second random number, and the first key.
[0064] Here, the random number exchanged between the first remote UE and the relay UE, together with the first key, is used as the input parameter for generating (or deriving) the second key.
[0065] Therefore, in some embodiments, S1240 may include: generating the second key based on the first random number, the second random number, and the first key.
[0066] Specifically, S1240 may include: generating the second key based on the first random number itself, the length of the first random number, the second random number itself, the length of the second random number, and the first key.
[0067] The lengths of the first random number and the second random number can be respectively: the number of bits of the first random number written in binary and the number of bits of the second random number written in binary.
[0068] In other embodiments, S1240 may further include:
[0069] The second key is generated based on the first key and the identifier of the integrity protection algorithm between the first remote UE and the second remote UE. For example, the second key is generated based on the first key, the length of the first key, the identifier itself, and the length of the identifier.
[0070] Of course, the above is just an example of generating a second key, and the actual implementation is not limited to the example above.
[0071] In some embodiments, the method further includes:
[0072] Receive the authentication method identification information sent by the relay UE;
[0073] The step of generating the second key based on the first random number, the second random number, and the first key includes:
[0074] The second key is generated based on the first random number, the second random number, the first key, and the identification information.
[0075] The authentication method sent by the relay UE is used for mutual discovery between the first remote UE and the second remote UE. The identification information of this authentication method can also be used as the input parameter of the second key.
[0076] This authentication method is used for mutual authentication when establishing an end-to-end connection between the first remote UE and the second remote UE.
[0077] For example, generating the second key based on the first random number, the second random number, the first key, and the identification information includes:
[0078] The second key is generated based on the first random number, the second random number, the identification information, the length of the identification information, and the first key.
[0079] For example, generating the second key based on the first random number, the second random number, the identification information, the length of the identification information, and the first key may include: generating the second key based on the first random number, the length of the first random number, the second random number, the length of the second random number, the identification information, the length of the identification information, and the first key.
[0080] There can be multiple authentication methods, and different authentication methods can generate different second keys. The authentication methods also differ after the first remote UE and the second remote UE discover each other. The first remote UE and the second remote UE can be mutually trusted UEs through authentication methods.
[0081] like Figure 4As shown, this disclosure provides an information processing method, which is executed by a first remote UE, the method comprising:
[0082] S1310: When the authentication method is a predetermined method, a first message is sent to the relay UE, wherein the first message uses a second key for integrity protection; the second key can be a key determined by any of the aforementioned technical solutions;
[0083] S1320: Receive the second message sent by the second remote UE forwarded by the relay UE;
[0084] S1330: Perform integrity protection verification on the second message according to the second key;
[0085] S1340; When the second message passes the integrity protection verification, it is determined that an end-to-end connection between the first remote UE and the second remote UE is established through the relay UE.
[0086] When the predetermined method includes, but is not limited to, Internet Key Exchange Protocol Version 2 (IKEv2), the first remote UE will send a first message to the relay UE.
[0087] The first message is protected for integrity using the second key. Therefore, after receiving the first message, the relay UE first protects its integrity using the second key. If the integrity protection of the first message passes, the relay UE forwards the first message to the second remote UE. If the relay UE discovers that the first message from the first remote UE has been tampered with using the second key, the first remote UE may receive a rejection message or a notification. The rejection message indicates a refusal to establish an end-to-end connection between the first and second remote UEs. The notification can be used to indicate that the first message has been tampered with and that the first message received by the relay UE failed integrity protection verification.
[0088] If the first remote UE is the source UE for UE-to-UE relay communication, then the second remote UE is the target UE; if the first remote UE is the target UE for UE-to-UE relay communication, then the second remote UE is the source UE.
[0089] Of course, it is also possible that the first UE receives the second message from the relay UE first, and then the first UE sends the first message.
[0090] In this embodiment, the first remote UE uses a second key to protect the integrity of the second message. After successful verification, an end-to-end connection is established between the first remote UE and the second remote UE via a relay UE.
[0091] In some embodiments, the second message includes a checksum of 1; the step of protecting the integrity of the second message according to the second key includes:
[0092] The second key and the integrity protection algorithm are used to calculate the content of the second message other than the verification value 1 to obtain the verification value 2;
[0093] Compare the check value 1 and the check value 2;
[0094] If the verification value 1 and the verification value 2 are the same, then the second message is determined to have passed the integrity protection verification.
[0095] In some embodiments, the second message may also carry a certificate sending indicator, which instructs the return of the certificate of the first remote UE to the second remote UE. If the first remote UE receives the certificate sending indicator and determines that a secure end-to-end connection has been established with the second remote UE, it will return the certificate of the first remote UE to the second remote UE during the information exchange process of establishing the end-to-end connection.
[0096] When the second message passes integrity protection verification, determining that an end-to-end connection is established between the first remote UE and the second remote UE through the relay UE includes:
[0097] When the second message passes the integrity protection verification, the relay UE sends a connection establishment request to the second remote UE and receives a connection establishment response from the second remote UE based on the connection establishment request.
[0098] or,
[0099] Upon receiving the connection establishment request from the second remote UE, if the second message passes the integrity protection verification, a connection establishment response indicating agreement to the connection establishment is sent to the second remote UE to establish an end-to-end connection with the second remote UE.
[0100] In some embodiments, the introduction of a second key can enable integrity protection of messages between the first remote UE and the second remote UE, thus ensuring the security of information between the first remote UE and the second remote UE through the end-to-end connection.
[0101] In one embodiment, the end-to-end connection may be an end-to-end connection based on the PC5 interface.
[0102] In some embodiments, the method further includes:
[0103] A key seed is generated based on the first random number and first key exchange information carried in the first message and the second random number and second key exchange information carried in the second message.
[0104] Based on the key seed, an integrity protection key and a confidentiality protection key are generated, wherein the integrity protection key and the confidentiality protection key are used for integrity protection and confidentiality protection when the first remote UE and the second remote UE establish end-to-end communication through the relay UE.
[0105] In this embodiment of the disclosure, the first key exchange information may be one or more parameters for generating the key seed.
[0106] For example, the key seed may be a private key seed used for asymmetric confidentiality protection or asymmetric integrity protection between the first remote UE and the second remote UE. Of course, the above is just an example.
[0107] After the key seed is generated, an integrity protection key and a confidentiality protection key are generated based on the key seed.
[0108] The integrity protection key can be used for integrity protection of information transmitted by the first remote UE and the second remote UE through the relay UE.
[0109] The confidentiality protection key can be used for the encryption protection of information transmitted by the first remote UE and the second remote UE through the relay UE.
[0110] In some embodiments, determining the establishment of an end-to-end connection between the first remote UE and the second remote UE via the relay UE includes:
[0111] Send a third message to the second remote UE; wherein the third message is protected by the integrity protection key and the confidentiality protection key, respectively;
[0112] A fourth message corresponding to the third message is received, wherein the integrity protection key is used to protect the integrity of the fourth message, and the confidentiality protection key is used to decrypt the fourth message.
[0113] One of the third and fourth messages here can be a connection establishment request, and the other a connection establishment response. Of course, this is just an example of the third and fourth messages, and the actual implementation is not limited to this example.
[0114] The third and fourth messages do not have a fixed order. For example, the first remote UE can receive the fourth message first and then send the third message; or, the first remote UE can send the third message first and then receive the fourth message; or, the first remote UE can send the third message at the same time as receiving the fourth message.
[0115] The third message includes at least one of the following:
[0116] The certificate of the first remote UE;
[0117] A certificate sending indicator is used to indicate the certificate to be returned to the second remote UE;
[0118] The first check value is used by the second remote UE to verify whether the first message, the second random number, and the identifier of the first remote UE have been correctly received by the first remote UE.
[0119] In one embodiment, the third message may include at least: the identifier of the first remote UE.
[0120] The identifier of the first remote UE may be: the device identifier and / or application identifier of the first remote UE.
[0121] The device identifier includes: the Subscription Concealed Identifier (SUCI), the Subscription Permanent Identifier (SUPI), or the 5G Globally Unique Temporary UE Identity (5G-GUTI) of the first remote UE. The application identifier can be the identifier (ID) of various Proximity Based Service (ProSe) applications.
[0122] In another embodiment, the third message may include at least: an identifier of the first remote UE and a first checksum. The first checksum is used by the second remote UE to verify whether the first remote UE has correctly received the first message, the second random number, and the identifier of the first remote UE. This first checksum may be generated based on a key seed.
[0123] In one embodiment, the third message may further include:
[0124] The certificate of the first remote UE; and / or,
[0125] A certificate sending indicator is used to indicate the certificate to be returned to the second remote UE;
[0126] The certificate of the first remote UE is sent to the second remote UE in a third message. After the first remote UE and the second remote UE establish an end-to-end connection, the certificate can be used for mutual authentication.
[0127] The third message also includes: a certificate sending indicator returns the certificate to the first remote UE from the second remote UE, so that the first remote UE will receive the certificate sent by the second remote UE in the future.
[0128] In one embodiment, if the third message carries a certificate indicator, the second remote UE sends a certificate to the first remote UE; if the third message does not carry a certificate sending indicator, the second remote UE may not need to send a certificate to the first remote UE.
[0129] In another embodiment, the certificate sending indicator corresponds to one or more bits; if the bit corresponding to the certificate indicator has a first value, the second remote UE does not need to send a certificate to the first remote UE; if the bit corresponding to the certificate indicator has a second value, the second remote UE does not need to send a certificate to the first remote UE. The second value is different from the first value.
[0130] In one embodiment, according to the protocol or factory configuration, it can be assumed that an interaction certificate is required when the first remote UE and the second remote UE interact with messages.
[0131] In another embodiment, if the first remote UE and the second remote UE do not explicitly indicate that they need to exchange certificates, then they will not exchange certificates with each other, according to the agreement or factory configuration.
[0132] In some embodiments, the fourth message includes at least one of the following:
[0133] The identifier of the second remote UE;
[0134] The certificate of the second remote UE;
[0135] The second verification value is used by the first remote UE to verify whether the second message, the first random number, and the identifier of the second remote UE have been correctly received by the second remote UE.
[0136] Similarly, the fourth message may include at least: the identifier of the second remote UE; the device identifier and / or application identifier of the second remote UE. The device identifier includes: the SubscriptionConcealed Identifier (SUCI), the Subscription Permanent Identifier (SUPI), or the 5G Globally Unique Temporary UE Identity (5G-GUTI) of the second remote UE. In some embodiments, the identifier of the first remote UE includes: the Restricted Proximity Application User Identifier (RPAUID) of the first remote UE and the identifier of the proximity application of the first remote UE; and / or, the identifier of the second remote UE includes: the RPAUID of the second remote UE and the identifier of the proximity application of the second remote UE.
[0137] The above are just the identifiers that are exchanged when establishing an end-to-end connection between the first remote UE and the second remote UE, including but not limited to RPAUID and the identifier of the adjacent service application.
[0138] It is worth noting that the certificate of the second remote UE in the fourth message is optional.
[0139] In some embodiments, the method further includes:
[0140] When the first message is correctly received by the second remote UE and the second message is correctly received by the first remote UE, it is determined that an end-to-end connection is established between the first remote UE and the second remote UE.
[0141] This process involves exchanging first and second messages to determine whether to establish an end-to-end connection between the first remote UE and the second remote UE. If it is determined that an end-to-end connection needs to be established, then the connection is initiated. Specifically, establishing the end-to-end connection can be achieved through the exchange of one or more messages, thus establishing a secure end-to-end connection between the first and second remote UEs.
[0142] If the first message and the second message are correctly received by the two remote UEs, it can be considered that the first remote UE and the second remote UE have completed mutual authentication, and can be used to establish an end-to-end connection between the first remote UE and the second remote UE.
[0143] In some embodiments, the first key is: the integrity protection key used by the first remote UE to send data to the relay UE; or, the first key is: the integrity protection key used by the relay UE to send data to the first remote UE.
[0144] like Figure 5 As shown, this disclosure provides an information processing method, which is executed by a first remote UE, the method comprising:
[0145] S1410: Send a request message to DDNMF;
[0146] S1420: A response message returned based on the request message, wherein the response message includes: a first key, which is used to determine a second key; the second key is used for integrity protection for mutual discovery between the first remote UE and the second remote UE.
[0147] The first key can be generated by DDNMF, so that the first remote UE can directly request it from DDNMF. For example, the first remote UE sends a request message to DDNMF through a relay UE, and receives a response message from DDNMF through the relay UE. This relay UE can be a UE-to-network (UE-to-network) relay device.
[0148] like Figure 6 As shown, this disclosure provides an information processing method, executed by a relay UE, the method comprising:
[0149] S2110: Obtain a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE.
[0150] S2120: Generate a second key based on the first key, wherein the second key is used for information integrity protection between two remote UEs for mutual discovery via a relay UE.
[0151] The relay UE can be any UE providing relay services. The relay UE can be a UE located within the network coverage area.
[0152] The relay UE can be a UE located between the first remote UE and the second remote UE.
[0153] In this embodiment of the disclosure, the relay UE can query the pre-acquired first key locally, or request the first key from the DDNMF.
[0154] The first key may be a key used for UE integrity protection when the first remote UE communicates with the network device through the relay UE.
[0155] After receiving the first key, the relay UE will deduce the second key locally.
[0156] In some embodiments, the method includes:
[0157] Receive the first random number from the first remote UE;
[0158] Send a second random number to the first remote UE;
[0159] S2120 may include: generating the second key based on the first random number, the second random number, and the first key.
[0160] In some embodiments, the second key is derived based on the first random number, the second random number, the first key, and the key derivation function.
[0161] For example, generating the second key based on the first random number, the second random number, and the first key may include: generating the second key based on the first random number, the second random number, the identification information, the length of the identification information, and the first key.
[0162] Exemplarily, the method further includes:
[0163] The authentication method identification information is sent to the first remote UE, wherein the authentication method is used for mutual authentication when establishing an end-to-end connection between the first remote UE and the second remote UE.
[0164] The identification information of this authentication method indicates the method by which an end-to-end connection is established and mutual authentication is performed between two remote ends. In addition to IKEv2 mentioned above, this authentication method can also be IKEv1, or other proprietary authentication protocols, which will not be listed here.
[0165] In some embodiments, generating the second key based on the first random number, the second random number, and the first key includes:
[0166] The second key is generated based on the first random number, the second random number, the first key, and the identification information.
[0167] For example, generating the second key based on the first random number, the second random number, the first key, and the identification information may include: generating the second key based on the first random number, the length of the first random number, the second random number, the degree of the second random number, the identification information itself, the length of the identification information, and the first key.
[0168] like Figure 7 As shown, this disclosure provides an information processing method, executed by a relay UE, the method comprising:
[0169] S2210: Send a request message to DDNMF;
[0170] S2220: A response message returned based on the request message, wherein the response message includes: a first key. The first key is used for integrity protection of communication between the remote UE and the relay UE; the first key is also used to generate a second key; the second key is used for integrity protection of mutual discovery between the first remote UE and the second remote UE.
[0171] In this embodiment of the disclosure, the relay UE obtains the first key by requesting it from the DDNMF. By sending a request message to the DDNMF, a response message will be received from the DDNMF, which may include the first key.
[0172] like Figure 8 As shown, this disclosure provides an information processing method, wherein the method is executed by DDNMF, and the method further includes:
[0173] S3110: Receive a request message sent by a UE; the UE is a relay UE and / or a remote UE;
[0174] S3120: According to the request message, send a first key to the UE; the first key is used for integrity protection of communication between the first remote UE and the relay UE, and is also used to generate a second key, wherein the second key is used for integrity protection of mutual discovery between the two remote UEs through the relay UE.
[0175] Upon receiving a request message, including a request message sent by the remote UE and / or the relay UE, DDNMF will return a first key to the UE. This first key can be used by the remote UE and the relay UE to derive a second key. This second key can then be used by the two remote UEs to establish secure end-to-end communication based on the relay UE.
[0176] A secure end-to-end connection is established between the source UE and the target UE via a relay UE. This relay UE can be a UE-to-UE relay device. Access to the ProSe service is then achieved through the relay UE.
[0177] Information is provided with integrity and confidentiality protection by relaying UEs.
[0178] Ensure that the remote UE can monitor and identify malicious attacks on the relay UE.
[0179] When a remote UE and a UE-to-UE relay UE are within network coverage, they will obtain security information (also known as discovery security information) from the network side to discover each other. This security information is time-sensitive and becomes invalid after it expires. If a UE does not have valid security information, the remote UE and UE-to-UE Relay need to connect to the ProSe Application Server and obtain new security information in order to use the 5G ProSe UE-to-UE relay service.
[0180] like Figure 9 As shown, the information processing method provided in this disclosure embodiment may include:
[0181] Steps 1a-1c involve remote UE1 and remote UE2.
[0182] Step 1a. The remote UE sends a request message (also known as a discovery request message) to the 5G DDNMF (which is the remote UE's DDNMF) to obtain relevant security information such as discovery query filters(s) for monitoring queries and ProSe Response Codes for declaration. Furthermore, the discovery request message may contain security capability information of the remote UE, including a list of encryption algorithms supported by the UE.
[0183] Step 1b. The remote UE's 5G DDNMF may determine from the ProSe application server whether the remote UE has the authority to make declarations, based on the configuration of the 5G DDNMF.
[0184] Step 1c. The remote UE's 5G DDNMF will return the ProSe response code, send-code security parameters (Code-Send-SecParams), discovery query filter, receive-code security parameters (Code-Rcv-SecParams), current time information (CURRENT_TIME), maximum offset (MAX_OFFSET), and algorithm information of the selected PC5 encryption algorithm for each discovery filter. This algorithm information may include at least: algorithm identifier.
[0185] The Send Code Security Parameter provides the necessary information to protect the transmission of the ProSe response code and is stored together with the ProSe response code.
[0186] The received code security parameters provide the information needed by the remote UE to verify the protection applied to the ProSe query code.
[0187] The remote UE performs a replay attack verification on the current time information (CURRENT_TIME) and the maximum offset (MAX_OFFSET).
[0188] The 5G DDNMF of the remote UE carries the selected PC5 encryption algorithm in its discovery response message. The 5G DDNMF determines the selected PC5 encryption algorithm based on the PC5 UE's security capability information and ProSe code received in step 1a. The UE will store the received PC5 encryption algorithm and ProSe response code.
[0189] It is worth noting that steps 1a-1c above are performed when the 5G remote UE is within network coverage.
[0190] When a remote UE is in roaming mode, the 5G DDNMF in the Home Public Land Mobile Network (HPLMN) and the Visited Public Land Mobile Network (VPLMN) of the remote UE may exchange messages.
[0191] Steps 2a-2f involve UE-to-UE (i.e., involve relay UEs).
[0192] Step 2a. The UE-to-UE relay sends a discovery request message containing PC5 UE security capability information to the 5G DDNMF, requesting the DDNMF to allow the UE-to-UE relay to be discovered and to provide relay services to one or more remote UEs.
[0193] Step 2b. The 5G DDNMF of the UE-to-UE relay (this DDNMF is the UE-to-UE relay DDNMF) sends an authorization request to the ProSe Application Server. If the UE-to-UE relay is allowed to discover at least one remote UE, the ProSe Application Server will return an authorization response.
[0194] Step 2c. If the discovery request carries authorization, and the PLMN IDs of the remote UE and the UE-to-UE relay are different, the 5G DDNMF of the UE-to-UE relay will interact with the 5G DDNMF of the remote UE. The 5G DDNMF of the UE-to-UE relay sends a discovery request message to the 5G DDNMF of the remote UE, which may include: the security capability information of the remote UE.
[0195] Step 2d. The 5G DDNMF of the remote UE may interact with the ProSe Application Server to exchange authorization messages.
[0196] If the PC5 UE security capability information in step 2a includes the algorithm information of the selected PC5 encryption algorithm, the remote UE's 5G DDNMF responds to the UE-to-UE relay's 5G DDNMF with a discovery response message. This discovery response message may include the ProSe query code and its associated transmission code security parameters, the response code and its associated reception code security parameters, and the algorithm information of the selected PC5 encryption algorithm. The transmission code security parameters provide the information required to protect the ProSe query code. The reception code security parameters include the integrity protection key (DUIK) of the ProSe response code, which is used to verify the protection of the remote UE application. This DUIK is one of the aforementioned first keys.
[0197] Step 2f. UE-to-UE relay (i.e. Figure 9 The 5G DDNMF of the relay UE (UE-to-UE) returns the discovery response filter and receive code security parameters, ProSe query code, send code security parameters, CURRENT_TIME and MAX_OFFSET parameters, and algorithm information of the selected PC5 encryption algorithm. The UE-to-UE relay determines whether the discovery response message has been subjected to a replay attack based on CURRENT_TIME and MAX_OFFSET. The UE-to-UE relay stores the discovery response filter and receive code security parameters, ProSe query code and send code security parameters, and the algorithm identifier and ProSe code of the selected PC5 encryption algorithm.
[0198] Steps 2a-2f are performed when the 5G UE-to-UE relay is within network coverage.
[0199] When a UE-to-UE relay is in roaming mode, the 5G DDNMF in the HPLMN and VPLMN may exchange authentication messages.
[0200] Steps 3a through 3d occur during the discovery process of PC5.
[0201] Step 3a. The remote UE sends a Query Request message, which may include a ProSe Query Code, a list of supported U2U relay authentication methods, and a Nonce 1 used to obtain the Negotiation User Integrity Key (NUIK).
[0202] During the discovery slot, if the system-provided UTC-based counter is within the MAX_OFFSET range of the remote UE's ProSe clock and the validity timer has not expired, the remote UE will also listen for a response message. The remote UE calculates a 32-bit Message Integrity Check (MIC) value to protect the query request.
[0203] Step 3b. If the UTC-based counter provided by the system is within the MAX_OFFSET range of the ProSe clock of the UE-to-UE relay during the discovery time slot, the UE-to-UE relay will listen for request messages that satisfy its discovery filter and will then detect the corresponding remote UE.
[0204] Step 3c. The UE-to-UE relay sends the ProSe response code associated with the discovered ProSe query code, the selected U2U relay authentication method, and a random number 2 (Nonce 2) used to derive the NUIK. The NUIK can be calculated based on either the DUIK in the received code parameters or the DUIK in the sent code parameters, which needs to be determined in advance. The calculated NUIK is associated with a validity period; if the validity period expires, the NUIK becomes invalid. The UE-to-UE relay forms a response message and calculates a 32-bit MIC to protect the query response. The UE-to-UE relay selects the U2U relay authentication method based on the ProSe query code and the authentication methods supported by the received terminal.
[0205] Step 3d. The remote UE listens for response messages that satisfy its discovery filter. The remote UE uses the stored DUIK to check the integrity of the response message itself and derives the NUIK to protect the negotiation message.
[0206] The calculated NUIK is associated with an expiration time (or validity period), after which the NUIK becomes invalid.
[0207] The remote UE needs to store the selected authentication method, which is used to establish an end-to-end IPsec connection in a UE-to-UE relay scenario.
[0208] If remote UE1 and remote UE2 choose the IKEv2 protocol to establish an end-to-end connection, then proceed to steps 4a-4d. This end-to-end connection can be a connection based on Internet Protocol Security (IPSec).
[0209] Step 4a. Remote UE1 sends an IKE_SA_INIT_Request to the UE-to-UE relay. Specifically, remote UE1 forms a request message (IKE_SA_INIT_Request) and protects it with a random number 1 (NUIK1). Once received, the UE-to-UE relay verifies the IKE_SA_INIT_Request using NUIK1 shared with remote UE1, then protects the IKE_SA_INIT_Request with a random number 2 (NUIK2) shared with remote UE2, and sends the IKE_SA_INIT_Request protected with NUIK2 to remote UE2.
[0210] Step 4b. Remote UE2 responds to remote UE1 with an IKE_SA_INIT_Response message via UE-to-UE relay. The IKE_SA_INIT_Response message is first protected by remote UE2 using NUIK2, and then by UE-to-UE relay using NUIK1. A key seed (SKEYSEED) is calculated based on the random number (nonces) and the Diffie-Hellman shared secret exchanged during the IKE_SA_INIT exchange. This key seed can be used to calculate another integrity protection key for subsequent integrity protection. Step 4c. Remote UE1 identifies itself, for example, by a combination of RPAUID and Prose application ID, represented by ID1. The contents of the first message in the ID1 payload and the integrity protection authentication (AUTH) payload are used. Remote UE1 also sends its certificate in the Certificate (CERT) payload and a list of its trusted anchors in the Certificate Indicator (CERTREQ) payload. The remote UE1 generates an IKE_Auth_Request message and protects it with a key derived from SKEYSEED.
[0211] Step 4d. Remote UE2 uses the ID2 payload to declare its identity and sends one or more certificates to remote UE1 to verify its identity RPAUID. It also uses the AUTH payload to protect the integrity of the second message. Remote UE2 generates an IKE_Auth_Response message and protects it with a key derived from the key seed (SKEYSEED).
[0212] It is worth noting that the certificates exchanged in steps 4c and 4d are provided by the Prose application (APP).
[0213] The remote UE and / or relay UE should be able to derive the IKE initial negotiation key from the available ProSe discovery key. This ProSe discovery key is one of the aforementioned first keys.
[0214] The remote UE should be able to send its list of U2U trunk authentication methods to the trunk UE.
[0215] The relay UE should be able to select and send the selected U2U relay authentication method to the remote UE.
[0216] The remote UE should be able to store the selected U2U trunk authentication method received from the trunk UE.
[0217] The remote UE should be able to ensure the authenticity of the UE-to-UE relay by checking the integrity of the query response.
[0218] Remote UEs and relay UEs should be able to protect the IKE initial negotiation message.
[0219] The relay UE should be able to forward negotiation messages between the source remote UE and the target remote UE.
[0220] 5G DDNMF can provide relay UEs and / or remote UEs with security information and parameters used for UE-to-UE relay.
[0221] like Figure 10 As shown, this disclosure provides an information processing apparatus, wherein the apparatus includes:
[0222] The first acquisition module 110 is configured to acquire a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE.
[0223] The first generation module 120 is configured to generate a second key based on the first key, wherein the second key is used for integrity protection for mutual discovery between two remote UEs via a relay UE.
[0224] The information processing apparatus provided in this embodiment may be included within a first remote UE.
[0225] In some embodiments, the first acquisition module 110 and the first generation module 120 may be program modules; after the program module is executed by the processor, it can acquire the first key and generate the second key.
[0226] In other embodiments, the first acquisition module 110 and the first generation module 120 may be hardware-software combined modules; the hardware-software combined modules include, but are not limited to, programmable arrays; the programmable arrays include, but are not limited to, field-programmable arrays and / or complex programmable arrays.
[0227] In some embodiments, the first acquisition module 110 and the first generation module 120 may be pure hardware modules; the pure hardware modules include, but are not limited to, application-specific integrated circuits.
[0228] In some embodiments, the device includes:
[0229] The first transmitting module is configured to send a first random number to the relay UE;
[0230] The first receiving module is configured to receive a second random number sent by the relay UE;
[0231] The first generation module 120 is configured to generate the second key based on the first random number, the second random number, and the first key.
[0232] In some embodiments, the first receiving module is configured to receive the authentication method identification information sent by the relay UE;
[0233] The first generation module 120 is configured to generate the second key based on the first random number, the second random number, the first key, and the identification information.
[0234] In some embodiments, the first generation module 120 is configured to generate the second key based on the first random number, the second random number, the identification information, the length of the identification information, and the first key.
[0235] In some embodiments, the first sending module is configured to send a first message to the relay UE when the authentication method is a predetermined method, wherein the first message uses the second key for integrity protection;
[0236] The first receiving module is configured to receive a second message sent by a second remote UE and forwarded by the relay UE;
[0237] The device further includes:
[0238] The first verification module is configured to perform integrity protection verification on the second message based on the second key;
[0239] The first establishment module is configured to determine, when the second message passes the integrity protection verification, to establish an end-to-end connection between the first remote UE and the second remote UE through the relay UE.
[0240] In some embodiments, the apparatus further includes:
[0241] The second generation module is configured to generate a key seed based on the first random number and first key exchange information carried in the first message and the second random number and second key exchange information carried in the second message.
[0242] The third generation module is configured to generate an integrity protection key and a confidentiality protection key based on the key seed, wherein the integrity protection key and the confidentiality protection key are used for integrity protection and confidentiality protection when the first remote UE and the second remote UE establish end-to-end communication through the relay UE.
[0243] In some embodiments, the first sending module is configured to send a third message to the second remote UE; wherein the third message is protected for integrity and confidentiality using the integrity protection key and the confidentiality protection key, respectively.
[0244] The first receiving module is configured to receive a fourth message corresponding to the third message, wherein the integrity protection key is used to protect the integrity of the fourth message, and the confidentiality protection key is used to decrypt the fourth message.
[0245] In some embodiments, the third message includes at least one of the following:
[0246] The identifier of the first remote UE;
[0247] The certificate of the first remote UE;
[0248] A certificate sending indicator is used to indicate the certificate to be returned to the second remote UE;
[0249] The first check value is used by the second remote UE to verify whether the first message, the second random number, and the identifier of the first remote UE have been correctly received by the first remote UE.
[0250] In some embodiments, the fourth message includes at least one of the following:
[0251] The identifier of the second remote UE;
[0252] The certificate of the second remote UE;
[0253] A certificate sending indicator is used to indicate the certificate to be returned to the second remote UE;
[0254] The second verification value is used by the first remote UE to verify whether the second message, the first random number, and the identifier of the second remote UE have been correctly received by the second remote UE.
[0255] In some embodiments, the identifier of the first UE includes: the restricted proximity service application user identifier (RPAUID) of the first remote UE and the identifier of the proximity service application of the first remote UE.
[0256] And / or,
[0257] The identifier of the second remote UE includes: the RPAUID of the second remote UE and the identifier of the adjacent service application of the second remote UE.
[0258] In some embodiments, the apparatus further includes:
[0259] The first determining module is configured to determine to establish an end-to-end connection between the first remote UE and the second remote UE when the first message is correctly received by the second remote UE and the second message is correctly received by the first remote UE.
[0260] In some embodiments, the first key is: the integrity protection key used by the first remote UE to send data to the relay UE;
[0261] or,
[0262] The first key is the integrity protection key used by the relay UE to send data to the first remote UE.
[0263] In some embodiments, the first acquisition module 110 is configured to send a request message to the Direct Connected Discovery Name Management Function (DDNMF); and a response message returned based on the request message, wherein the response message includes: a first key.
[0264] like Figure 11 As shown, this disclosure provides an information processing apparatus, the apparatus comprising:
[0265] The second acquisition module 210 is configured to acquire a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE.
[0266] The third generation module 220 is configured to generate a second key based on the first key, wherein the second key is used for integrity protection for mutual discovery between two remote UEs via a relay UE.
[0267] The information processing device may be included in a relay UE.
[0268] In some embodiments, the second acquisition module 210 and the third generation module 220 may be program modules; after being executed by the processor, the program module can acquire the first key and generate the second key.
[0269] In other embodiments, the second acquisition module 210 and the third generation module 220 may be hardware-software hybrid modules; the hardware-software hybrid modules include, but are not limited to, programmable arrays; the programmable arrays include, but are not limited to, field-programmable arrays and / or complex programmable arrays.
[0270] In some embodiments, the second acquisition module 210 and the third generation module 220 may be pure hardware modules; the pure hardware modules include, but are not limited to, application-specific integrated circuits.
[0271] In some embodiments, the device includes:
[0272] The second receiving module is configured to receive a first random number from the first remote UE.
[0273] The second sending module is configured to send a second random number to the first remote UE;
[0274] The third generation module 220 is configured to generate the second key based on the first random number, the second random number, and the first key.
[0275] In some embodiments, the second sending module is configured to send identification information of an authentication method to the first remote UE, wherein the authentication method is used for authentication between the first remote UE and the second remote UE in establishing an end-to-end connection.
[0276] In some embodiments, the second generation module is configured to generate the second key based on the first random number, the second random number, the first key, and the identification information.
[0277] In some embodiments, the second acquisition module 210 is configured to send a request message to the Direct Discovery Name Management Function (DDNMF); and return a response message based on the request message, wherein the response message includes: a first key.
[0278] like Figure 12 As shown in the figure, this disclosure provides an information processing apparatus, wherein the apparatus further includes:
[0279] The third receiving module 310 is configured to receive request messages sent by a remote UE and / or a relay UE;
[0280] The third sending module 320 is configured to send a first key to the remote UE and / or the relay UE according to the request message; the first key is used for integrity protection of communication between the first remote UE and the relay UE, and is also used to generate a second key, wherein the second key is used for integrity protection of mutual discovery between the two remote UEs through the relay UE.
[0281] The information processing apparatus may be included in DDNMF.
[0282] In some embodiments, the third receiving module 310 and the third sending module 320 may be program modules; after being executed by the processor, the program modules are able to perform the above operations.
[0283] In other embodiments, the third receiving module 310 and the third transmitting module 320 may be hardware-software hybrid modules; the hardware-software hybrid modules include, but are not limited to, programmable arrays; the programmable arrays include, but are not limited to, field-programmable arrays and / or complex programmable arrays.
[0284] In some embodiments, the third receiving module 310 and the third transmitting module 320 may be pure hardware modules; such pure hardware modules include, but are not limited to, application-specific integrated circuits.
[0285] This disclosure provides a communication device, including:
[0286] Memory used to store processor-executable instructions;
[0287] The processor is connected to the memory separately;
[0288] The processor is configured to execute the information processing method provided by any of the aforementioned technical solutions.
[0289] The processor may include various types of storage media, which are non-transitory computer storage media that can continue to store information after the communication device loses power.
[0290] Here, the communication device includes: a UE or a network element, which may be the aforementioned DDNMF. The UE may be a relay UE and / or a remote UE.
[0291] The processor can be connected to the memory via a bus or similar means to read executable programs stored in the memory, for example, such as... Figures 2 to 9 At least one of the methods shown.
[0292] Figure 13This is a block diagram illustrating a UE 800 according to an exemplary embodiment. For example, the UE 800 may be a mobile phone, computer, digital broadcast user equipment, messaging transceiver, game console, tablet device, medical device, fitness equipment, personal digital assistant, etc.
[0293] Reference Figure 13 UE800 may include one or more of the following components: processing component 802, memory 804, power supply component 806, multimedia component 808, audio component 810, input / output (I / O) interface 812, sensor component 814, and communication component 816.
[0294] Processing component 802 typically controls the overall operation of UE 800, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 802 may include one or more processors 820 to execute instructions to generate all or part of the steps of the methods described above. Furthermore, processing component 802 may include one or more modules to facilitate interaction between processing component 802 and other components. For example, processing component 802 may include a multimedia module to facilitate interaction between multimedia component 808 and processing component 802.
[0295] Memory 804 is configured to store various types of data to support operation on UE 800. Examples of this data include instructions for any application or method operating on UE 800, contact data, phonebook data, messages, pictures, videos, etc. Memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0296] Power supply component 806 provides power to various components of UE800. Power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to UE800.
[0297] The multimedia component 808 includes a screen that provides an output interface between the UE 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, the multimedia component 808 includes a front-facing camera and / or a rear-facing camera. When the UE 800 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.
[0298] Audio component 810 is configured to output and / or input audio signals. For example, audio component 810 includes a microphone (MIC) configured to receive external audio signals when UE 800 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 804 or transmitted via communication component 816. In some embodiments, audio component 810 also includes a speaker for outputting audio signals.
[0299] I / O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.
[0300] Sensor assembly 814 includes one or more sensors for providing status assessments of various aspects of UE 800. For example, sensor assembly 814 can detect the on / off state of UE 800, the relative positioning of components such as the display and keypad of UE 800, changes in the position of UE 800 or one of its components, the presence or absence of user contact with UE 800, the orientation or acceleration / deceleration of UE 800, and temperature changes of UE 800. Sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 814 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 814 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.
[0301] Communication component 816 is configured to facilitate wired or wireless communication between UE 800 and other devices. UE 800 can access wireless networks based on communication standards, such as WiFi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, communication component 816 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 816 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0302] In an exemplary embodiment, UE800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.
[0303] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions that can be executed by a processor 820 of the UE 800 to generate the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0304] like Figure 14 As shown in the illustration, one embodiment of this disclosure illustrates the structure of an access device. For example, the communication device 900 can be provided as a network-side device. This communication device can be various network elements such as the aforementioned access network elements and / or network functions.
[0305] Reference Figure 14 The communication device 900 includes a processing component 922, which further includes one or more processors, and memory resources represented by a memory 932 for storing instructions, such as application programs, that can be executed by the processing component 922. The application programs stored in the memory 932 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processing component 922 is configured to execute instructions to perform any of the methods described above applied to the access device, such as... Figures 2 to 9 Any of the methods shown.
[0306] The communication device 900 may also include a power supply component 1926 configured to perform power management of the communication device 900, a wired or wireless network interface 950 configured to connect the communication device 900 to a network, and an input / output (I / O) interface 958. The communication device 900 can operate on an operating system stored in memory 932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or similar.
[0307] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.
[0308] It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. An information processing method, wherein, Performed by a first remote user equipment (UE), the method includes: Obtain a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE; Send a first random number to the relay UE; The system receives a second random number sent by the relay UE and identification information of the authentication method, wherein the authentication method is used for authentication between the first remote UE and the second remote UE in establishing an end-to-end connection. A second key is generated based on the first random number, the second random number, the first key, and the identification information. The second key is used for integrity protection for mutual discovery between two remote UEs via a relay UE.
2. The method according to claim 1, wherein, The step of generating the second key based on the first random number, the second random number, the first key, and the identification information includes: The second key is generated based on the first random number, the second random number, the identification information, the length of the identification information, and the first key.
3. The method according to claim 1, wherein, The method further includes: When the authentication method is a predetermined method, a first message is sent to the relay UE, wherein the first message uses the second key for integrity protection; Receive the second message sent by the second remote UE forwarded by the relay UE; The integrity protection verification of the second message is performed based on the second key; When the second message passes the integrity protection verification, it is determined that an end-to-end connection between the first remote UE and the second remote UE is established through the relay UE.
4. The method according to claim 3, wherein, The method further includes: A key seed is generated based on the first random number and first key exchange information carried in the first message and the second random number and second key exchange information carried in the second message. Based on the key seed, an integrity protection key and a confidentiality protection key are generated, wherein the integrity protection key and the confidentiality protection key are used for integrity protection and confidentiality protection when the first remote UE and the second remote UE establish end-to-end communication through the relay UE.
5. The method according to claim 4, wherein, The determination of establishing an end-to-end connection between the first remote UE and the second remote UE through the relay UE includes: Send a third message to the second remote UE; wherein the third message is protected by the integrity protection key and the confidentiality protection key, respectively; A fourth message corresponding to the third message is received, wherein the integrity protection key is used to protect the integrity of the fourth message, and the confidentiality protection key is used to decrypt the fourth message.
6. The method according to claim 5, wherein, The third message includes at least one of the following: The identifier of the first remote UE; The certificate of the first remote UE; A certificate sending indicator is used to indicate the certificate to be returned to the second remote UE; The first check value is used by the second remote UE to verify whether the first message, the second random number, and the identifier of the first remote UE have been correctly received by the first remote UE.
7. The method according to claim 5 or 6, wherein, The fourth message includes at least one of the following: The identifier of the second remote UE; The certificate of the second remote UE; A certificate sending indicator is used to indicate the certificate to be returned to the second remote UE; The second verification value is used by the first remote UE to verify whether the second message, the first random number, and the identifier of the second remote UE have been correctly received by the second remote UE.
8. The method according to claim 6, wherein, The identifier of the first remote UE includes: the restricted proximity service application user identifier (RPAUID) of the first remote UE and the identifier of the proximity service application of the first remote UE; And / or, The identifier of the second remote UE includes: the RPAUID of the second remote UE and the identifier of the adjacent service application of the second remote UE.
9. The method according to claim 7, wherein, The method further includes: When the first message is correctly received by the second remote UE and the second message is correctly received by the first remote UE, it is determined that an end-to-end connection is established between the first remote UE and the second remote UE.
10. The method according to any one of claims 1 to 6, wherein, The first key is: the integrity protection key used by the first remote UE to send data to the relay UE; or, The first key is the integrity protection key used by the relay UE to send data to the first remote UE.
11. The method according to any one of claims 1 to 6, wherein, The process of obtaining the first key includes: Send a request message to the Direct Discovery Name Management (DDNMF) function; The response message returned based on the request message includes: a first key.
12. An information processing method, executed by a relay UE, the method comprising: Obtain a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE; Receive the first random number sent by the first remote UE; Send a second random number and authentication method identification information to the first remote UE, wherein the authentication method is used for authentication between the first remote UE and the second remote UE to establish an end-to-end connection; A second key is generated based on the first random number, the second random number, the first key, and the identification information. The second key is used for integrity protection for mutual discovery between two remote UEs via a relay UE.
13. The method according to claim 12, wherein, The process of obtaining the first key includes: Send a request message to the Direct Discovery Name Management (DDNMF) function; The response message returned based on the request message includes: a first key.
14. An information processing method, wherein, Performed by DDNMF, the method further includes: Receive request messages sent by remote UEs and / or relay UEs; According to the request message, a first key is sent to the remote UE and / or the relay UE; the first key is used for integrity protection of communication between the first remote UE and the relay UE, and is also used to generate a second key, wherein the second key is used for integrity protection of mutual discovery between the two remote UEs through the relay UE; the second key is generated based on a first random number, a second random number, the first key, and the identification information of the authentication method, wherein the identification information of the authentication method is sent by the relay UE to the remote UE.
15. An information processing apparatus, wherein, The device includes: The first acquisition module is configured to acquire a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE; The first transmitting module is configured to send a first random number to the relay UE; The first receiving module is configured to receive a second random number and an authentication method identifier sent by the relay UE, wherein the authentication method is used for authentication between the first remote UE and the second remote UE to establish an end-to-end connection. The first generation module is configured to generate a second key based on the first random number, the second random number, the first key, and the identification information, wherein the second key is used for integrity protection for mutual discovery between two remote UEs via a relay UE.
16. The apparatus according to claim 15, wherein, The first generation module is configured to generate the second key based on the first random number, the second random number, the identification information, the length of the identification information, and the first key.
17. The apparatus according to claim 15, wherein, The first sending module is configured to send a first message to the relay UE when the authentication method is a predetermined method, wherein the first message uses the second key for integrity protection; The first receiving module is configured to receive a second message sent by a second remote UE and forwarded by the relay UE; The device further includes: The first verification module is configured to perform integrity protection verification on the second message based on the second key; The first establishment module is configured to determine, when the second message passes the integrity protection verification, to establish an end-to-end connection between the first remote UE and the second remote UE through the relay UE.
18. The apparatus according to claim 17, wherein, The device further includes: The second generation module is configured to generate a key seed based on the first random number and first key exchange information carried in the first message and the second random number and second key exchange information carried in the second message. The third generation module is configured to generate an integrity protection key and a confidentiality protection key based on the key seed, wherein the integrity protection key and the confidentiality protection key are used for integrity protection and confidentiality protection when the first remote UE and the second remote UE establish end-to-end communication through the relay UE.
19. The apparatus according to claim 18, wherein, The first sending module is configured to send a third message to the second remote UE; wherein the third message is protected for integrity and confidentiality using the integrity protection key and the confidentiality protection key, respectively. The first receiving module is configured to receive a fourth message corresponding to the third message, wherein the integrity protection key is used to protect the integrity of the fourth message, and the confidentiality protection key is used to decrypt the fourth message.
20. The apparatus according to claim 19, wherein, The third message includes at least one of the following: The identifier of the first remote UE; The certificate of the first remote UE; A certificate sending indicator is used to indicate the certificate to be returned to the second remote UE; The first check value is used by the second remote UE to verify whether the first message, the second random number, and the identifier of the first remote UE have been correctly received by the first remote UE.
21. The apparatus according to claim 19 or 20, wherein, The fourth message includes at least one of the following: The identifier of the second remote UE; The certificate of the second remote UE; A certificate sending indicator is used to indicate the certificate to be returned to the second remote UE; The second verification value is used by the first remote UE to verify whether the second message, the first random number, and the identifier of the second remote UE have been correctly received by the second remote UE.
22. The apparatus according to claim 20, wherein, The identifier of the first remote UE includes: the restricted proximity service application user identifier (RPAUID) of the first remote UE and the identifier of the proximity service application of the first remote UE; And / or, The identifier of the second remote UE includes: the RPAUID of the second remote UE and the identifier of the adjacent service application of the second remote UE.
23. The apparatus according to claim 20, wherein, The device further includes: The first determining module is configured to determine to establish an end-to-end connection between the first remote UE and the second remote UE when the first message is correctly received by the second remote UE and the second message is correctly received by the first remote UE.
24. The apparatus according to any one of claims 15 to 20, wherein, The first key is: the integrity protection key used by the first remote UE to send data to the relay UE; or, The first key is the integrity protection key used by the first remote UE of the relay UE to send data.
25. The apparatus according to any one of claims 15 to 20, wherein, The first acquisition module is configured to send a request message to the Direct Connect Discovery Name Management Function (DDNMF). The response message returned based on the request message includes: a first key.
26. An information processing apparatus, the apparatus comprising: The second acquisition module is configured to acquire a first key, wherein the first key is used for integrity protection of communication between the first remote UE and the relay UE. The second receiving module is configured to receive a first random number sent by the first remote UE. The second sending module is configured to send a second random number and authentication method identification information to the first remote UE, wherein the authentication method is used for authentication between the first remote UE and the second remote UE to establish an end-to-end connection. The third generation module is configured to generate a second key based on the first random number, the second random number, the first key, and the identification information, wherein the second key is used for integrity protection for mutual discovery between two remote UEs via a relay UE.
27. The apparatus according to claim 26, wherein, The second acquisition module is configured to send a request message to the Direct Discovery Name Management Function (DDNMF). The response message returned based on the request message includes: a first key.
28. An information processing apparatus, wherein, The device further includes: The third receiving module is configured to receive request messages sent by remote UEs and / or relay UEs; The third sending module is configured to send a first key to the remote UE and / or the relay UE according to the request message; the first key is used for integrity protection of communication between the first remote UE and the relay UE, and is also used to generate a second key, wherein the second key is used for integrity protection of mutual discovery between the two remote UEs through the relay UE; the second key is generated based on a first random number, a second random number, the first key, and authentication method identification information, the authentication method identification information being sent by the relay UE to the remote UE.
29. A communication device, comprising a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being executed by the processor, wherein, When the processor runs the executable program, it performs the method provided as claimed in any one of claims 1 to 11, 12 to 13, or 14.
30. A computer storage medium storing an executable program; the executable program, when executed by a processor, is capable of implementing the method provided in any one of claims 1 to 11, 12 to 13, or 14.
Citation Information
Patent Citations
Method and device for protecting communication
CN113784343A
Secure communication link establishment for a UE-to-UE relay
US20220109996A1