Information processing method and apparatus, communication device, and storage medium

CN117256168BActive Publication Date: 2026-08-28BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202280001185.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-19
Publication Date
2026-08-28
Estimated Expiration
2042-04-19

AI Technical Summary

Technical Problem

然而,在相关技术中,对PIN场景来说,目前仍缺乏运营商凭证安全配置技术

Benefits of technology

[0058]本公开实施例提供的技术方案,通过运营商公钥预先配置在PINE内,可以实现PINE通过PEGC连接向3GPP网络安全的申请运营商凭证,相对于通过第三方的缺省凭证验证之后再运营商凭证配置,缩短了运营商凭证流程,提升了运营商凭证的配置速率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117256168B_ABST
    Figure CN117256168B_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure provide an information processing method and device, a communication device and a storage medium. An information processing method executed by a personal Internet of Things unit (PINE) can include: sending, to a personal Internet of Things gateway (PEGC), a first request for applying for an operator credential based on a pre-configured operator public key; receiving a first response returned based on the first request; and obtaining an operator credential carried in the first response based on the operator public key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to, but is not limited to, the field of wireless communication technology, and particularly to an information processing method and apparatus, communication equipment and storage medium. Background Technology

[0002] There are many types of Internet of Things (IoT) devices to meet different application needs.

[0003] With the dramatic increase in the number of IoT devices, users are primarily using all these IoT devices in their homes, offices, factories, and / or around their bodies to create (e.g., plan, change topology) networks. A Personal IoT Network (PIN) can consist of a variety of devices that a user frequently uses.

[0004] PIN (Personal IoT Network Element, PINE) units cannot be directly connected to 5G mobile communication systems (5G). th In addition to the Generation System (5GS), 5GS requires further verification of the PINE to enhance its management. To meet this requirement, 5GS needs to provide carrier credentials to the PINE. However, in related technologies, there is currently a lack of secure carrier credential configuration technology for PIN scenarios. Summary of the Invention

[0005] This disclosure provides an information processing method and apparatus, a communication device and a storage medium.

[0006] A first aspect of this disclosure provides an information processing method, wherein the method is executed by a PINE, the method comprising:

[0007] Based on the pre-configured operator public key, send the first request to the Personal IoT Gateway PEGC to apply for operator credentials;

[0008] Receive the first response returned based on the first request;

[0009] The operator credentials carried in the first response are obtained based on the operator's public key.

[0010] A second aspect of this disclosure provides an information processing method, wherein the method is performed by a device with gateway capability (PIN Element with Gateway Capability, PEGC), the method comprising:

[0011] Receive a first request sent by PINE based on a pre-configured operator public key; wherein the first request is used to request operator credentials;

[0012] Based on the first request, a second request is sent to the first network element;

[0013] Receive the second response returned by the first network element based on the second request;

[0014] The second response is used to send the first response to the PINE.

[0015] A third aspect of this disclosure provides an information processing method, wherein the method is executed by a first network element, the method comprising:

[0016] Receive a second request sent by PEGC, wherein the second request is sent based on the first request; the first request is a request sent by PINE based on a pre-configured operator public key and used to request operator credentials;

[0017] Based on the second request, a third request is sent to the second network element;

[0018] Receive a third response based on a third request;

[0019] Based on the third response, a second response is sent to the PEGC.

[0020] A fourth aspect of this disclosure provides an information processing method, wherein the method is executed by a second network element, the method comprising:

[0021] Receive a third request;

[0022] Based on the result of processing the third request using the operator's private key, determine whether to configure operator credentials for PINE.

[0023] When it is determined that operator credentials will be configured for the PINE, a fourth request is sent to the third network element.

[0024] Receive the operator credentials returned by the fourth request;

[0025] The operator credential is processed securely using the operator's private key to obtain a securely processed operator credential.

[0026] The securely processed operator credentials are sent to the first network element along with the third response.

[0027] A fifth aspect of this disclosure provides an information processing method, wherein the method is executed by a third network element, and the method further includes:

[0028] Receive the fourth request from the second network element;

[0029] Configure operator credentials for PINE according to the fourth request, wherein PINE is a device that has not been configured with default credentials but has been pre-configured with an operator public key;

[0030] The operator credentials are carried in the fourth response and sent to the second network element. The operator credentials are used to securely process the operator private key corresponding to the operator public key and then issue it to the PINE.

[0031] A sixth aspect of this disclosure provides an information processing apparatus, wherein the apparatus includes:

[0032] The first sending module is configured to send a first request for operator credentials to the Personal IoT Gateway PEGC based on a pre-configured operator public key.

[0033] The first receiving module is configured to receive a first response based on the first request;

[0034] The first acquisition module is configured to acquire the operator credentials carried in the first response based on the operator's public key.

[0035] A seventh aspect of this disclosure provides an information processing apparatus, wherein the processing is performed by a PEGC, the apparatus comprising:

[0036] The second receiving module is configured to receive a first request sent by PINE based on a pre-configured operator public key; wherein the first request is used to request operator credentials;

[0037] The second sending module is configured to send a second request to the first network element based on the first request;

[0038] The second sending module is also configured to receive a second response returned by the first network element based on the second request;

[0039] The second sending module is also configured to send the second response to the PINE as a first response.

[0040] An eighth aspect of this disclosure provides an information processing apparatus, wherein the apparatus includes:

[0041] The third receiving module is configured to receive a second request sent by PEGC, wherein the second request is sent based on the first request; the first request is a request sent by PINE based on a pre-configured operator public key and used to request operator credentials.

[0042] The third sending module is configured to send a third request to the second network element based on the second request;

[0043] The third receiving module is configured to receive a third response based on a third request;

[0044] The third sending module is configured to send a second response to the PEGC based on the third response.

[0045] A ninth aspect of this disclosure provides an information processing apparatus, wherein the apparatus includes: a fourth receiving module, a fourth sending module, a second determining module, and a second acquiring module;

[0046] The fourth receiving module is configured to receive a third request;

[0047] The second determining module is configured to determine whether to configure operator credentials for PINE based on the result of processing the third request using the operator's private key.

[0048] The fourth sending module is configured to send a fourth request to the third network element when it is determined that operator credentials will be configured for the PINE.

[0049] The fourth receiving module is also configured to receive the operator credentials returned by the fourth request;

[0050] The second acquisition module is configured to use the operator's private key to perform security processing on the operator's credentials to obtain the security-processed operator's credentials;

[0051] The fourth sending module is further configured to send the securely processed operator credentials to the first network element along with the third response.

[0052] A tenth aspect of this disclosure provides an information processing apparatus, wherein the apparatus further includes:

[0053] The fifth receiving module is configured to receive the fourth request from the second network element;

[0054] The configuration module is configured to configure operator credentials for the PINE according to the fourth request, wherein the PINE is a device that has not been configured with default credentials but has been pre-configured with an operator public key;

[0055] The fifth sending module is configured to send the operator credential along with the fourth response to the second network element, wherein the operator credential is used to securely process the operator private key corresponding to the operator public key before issuing it to the PINE.

[0056] The eleventh aspect of this disclosure provides a communication device, including a processor, a transceiver, a memory, and an executable program stored in the memory and executable by the processor, wherein when the processor runs the executable program, it performs the information processing method provided by any one of the first to fifth aspects described above.

[0057] The twelfth aspect of this disclosure provides a computer storage medium storing an executable program; after being executed by a processor, the executable program is able to implement the information processing method provided in any one of the first to fifth aspects.

[0058] The technical solution provided in this disclosure, by pre-configuring the operator's public key in the PINE, enables the PINE to apply for operator credentials for the 3GPP network via PEGC connection. Compared with verifying the default credentials of a third party and then configuring the operator credentials, this shortens the operator credential process and improves the operator credential configuration speed.

[0059] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the embodiments of this disclosure. Attached Figure Description

[0060] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the embodiments of the invention.

[0061] Figure 1 This is a schematic diagram illustrating the structure of a wireless communication system according to an exemplary embodiment;

[0062] Figure 2 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0063] Figure 3 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0064] Figure 4 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0065] Figure 5 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0066] Figure 6 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0067] Figure 7This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0068] Figure 8 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0069] Figure 9 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0070] Figure 10 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0071] Figure 11 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0072] Figure 12 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0073] Figure 13 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0074] Figure 14 This is a flowchart illustrating an information processing method according to an exemplary embodiment;

[0075] Figure 15 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;

[0076] Figure 16 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;

[0077] Figure 17 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;

[0078] Figure 18 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;

[0079] Figure 19 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;

[0080] Figure 20 This is a schematic diagram of a PINE structure according to an exemplary embodiment;

[0081] Figure 21 This is a schematic diagram of the structure of a network element according to an exemplary embodiment. Detailed Implementation

[0082] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of the present invention. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of the present invention.

[0083] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the embodiments disclosed herein. The singular forms “a,” “the,” and “the” used herein are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.

[0084] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of this disclosure, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first information may also be referred to as second information without departing from the scope of embodiments of this disclosure, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0085] Please refer to Figure 1 This illustration shows a schematic diagram of the structure of a wireless communication system provided in an embodiment of this disclosure. Figure 1 As shown, the wireless communication system is a communication system based on cellular mobile communication technology. The wireless communication system may include: several UEs 11 and several access devices 12.

[0086] UE 11 can be a device that provides voice and / or data connectivity to a user. UE 11 can communicate with one or more core networks via a Radio Access Network (RAN). UE 11 can be an IoT UE, such as a sensor device, a mobile phone (or "cellular" phone), and a computer with an IoT UE. For example, it can be a fixed, portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted device. Examples include a station (STA), subscriber unit, subscriber station, mobile station, mobile station, remote station, access point, remote terminal, access terminal, user terminal, user agent, user device, or user equipment (UE). Alternatively, UE 11 can also be a device in an unmanned aerial vehicle (UAV). Alternatively, UE 11 can also be a vehicle-mounted device, such as a vehicle computer with wireless communication capabilities, or a wireless communication device connected to an external vehicle computer. Alternatively, UE 11 can also be a roadside device, such as a street light, traffic light, or other roadside device with wireless communication capabilities.

[0087] Access device 12 can be a network-side device in a wireless communication system. This wireless communication system can be a 4G system (also known as Long Term Evolution, LTE); or it can be a 5G system (also known as a New Radio, NR, or 5G NR system). Alternatively, it can be the next generation after 5G. In this case, the access network in the 5G system can be called NG-RAN (New Generation-Radio Access Network). Alternatively, it can be an MTC system.

[0088] The access device 12 can be an evolved NB (eNB) used in a 4G system. Alternatively, the access device 12 can also be a gNB (gNB) using a centralized-distributed architecture in a 5G system. When the access device 12 adopts a centralized-distributed architecture, it typically includes a central unit (CU) and at least two distributed units (DUs). The central unit is equipped with a protocol stack of the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, and the Media Access Control (MAC) layer; the distributed units are equipped with a physical (PHY) layer protocol stack. This disclosure does not limit the specific implementation of the access device 12.

[0089] Access device 12 and UE 11 can establish a wireless connection via a wireless air interface. In different implementations, the wireless air interface is a wireless air interface based on the fourth-generation mobile communication network technology (4G) standard; or, the wireless air interface is a wireless air interface based on the fifth-generation mobile communication network technology (5G) standard, such as a new air interface; or, the wireless air interface can also be a wireless air interface based on a next-generation mobile communication network technology standard based on 5G.

[0090] There are three types of Personal IoT Network Elements (PINEs) in PINs: PIN Element with Gateway Capability (PEGC), PIN Element with Management Capability (PEMC), and ordinary PINEs without gateway and management capabilities.

[0091] PEGC and PEMC are also UEs that can directly access the 5G network. PEMC can also access the 5G network through PEGC.

[0092] The IoT devices that make up PINE include, but are not limited to: wearable devices, smart home devices and / or smart office devices.

[0093] Wearable devices include, but are not limited to: headphones, smartwatches and / or health monitoring sensors.

[0094] Smart home devices include, but are not limited to: smart lights, cameras, thermostats, access control devices, voice assistant devices, speakers, refrigerators, washing machines, lawnmowers and / or robots.

[0095] Smart office equipment can be used in the offices or factories of small businesses. Typical smart office equipment includes, but is not limited to, printers, meters and / or sensors.

[0096] Some IoT devices have very specific requirements regarding size (e.g., headphones), while others have very specific requirements regarding weight (e.g., glasses).

[0097] Some IoT devices have very specific requirements in several areas (i.e., size, weight, and power consumption).

[0098] PINEs cannot directly access 5G networks, and 5G networks need to identify PINEs for enhanced management. To meet this requirement, 5G networks need to provide operator credentials to PINEs. Using these operator credentials, the fifth-generation mobile communication system (5G5G)... th Generation System (5GS) can authenticate and identify PINEs connected via PEGC. Before providing the PINE with operator credentials issued by 5GS, the PINE's default credentials need to be authenticated. However, the lack of a mechanism for authenticating default credentials provided by third-party authentication, authorization, and accounting (AAA) servers via 5GC delays 5GC's communication control over the PINE, resulting in communication latency.

[0099] like Figure 2 As shown, this disclosure provides an information processing method executed by PINE, the method comprising:

[0100] S1110: Based on the pre-configured operator public key, send the first request to PEGC to apply for operator credentials;

[0101] S1120: Receive the first response returned based on the first request;

[0102] S1130: Obtain the operator credentials carried in the first response based on the operator's public key.

[0103] The PINE can be a variety of IoT devices, including wearable devices that can be worn by users, devices that can be carried by users, smart home devices, smart office devices, and / or smart entertainment devices used in entertainment venues.

[0104] The operator's public key can be a pre-configured public key by the telecommunications operator. For example, it could be a public key written by the telecommunications operator before the PINE is delivered to consumers.

[0105] The telecommunications operator can be a telecommunications operator within the 3GPP network.

[0106] The PEGC can be used for various devices that can access 3GPP networks, such as users' mobile phones, tablets, or home gateways.

[0107] For example, PEGC can access a 3GPP network via a Subscriber Identity Module (SIM). This SIM can be a physical card or an electronic SIM card built into the terminal.

[0108] Since PINE is pre-configured with the operator's public key, PINE does not need to pre-write the default credentials of the third party. These default credentials include, but are not limited to, credentials provided by the authentication, authorization, and accounting (AAA) server.

[0109] To facilitate PINE's rapid network access via PEGC, after PINE establishes a non-3GPP connection with PEGC, it can apply for operator credentials from the operator's network through PEGC.

[0110] For example, after a secure non-3GPP connection is established between PINE and PEGC, a first request is sent to PEGC to request operator credentials from network elements in the 3GPP network. This secure non-3GPP connection includes, but is not limited to, Bluetooth and / or WiFi connections.

[0111] In this embodiment of the disclosure, in order to securely issue operator credentials, PINE uses a pre-configured operator public key to perform secure processing on the first request. This secure processing includes, but is not limited to, encryption processing and / or signature verification processing.

[0112] In one embodiment, the first request may include at least the identifier of the PINE, thus facilitating the network elements of the 3GPP network to recognize the PINE requesting operator credentials. Exemplarily, the first request may further include a credential configuration indicator, which instructs the PINE to request the configuration of operator credentials.

[0113] In another embodiment, the first request may further include a public key identifier of the operator's public key. This facilitates the network element to decrypt and / or sign and verify at least a portion of the content in the first request after receiving the first request, based on the operator's private key corresponding to the operator's public key identified by the public key identifier in the plaintext.

[0114] If the PINE is recognized by a 3GPP network element as having the right to obtain operator credentials, the first response received by the PINE will carry the operator credentials configured for the PINE. After receiving the first response, the PINE will process the first response using the operator's public key to obtain the operator credentials carried in the first response.

[0115] Therefore, in this embodiment of the disclosure, by pre-configuring the operator's public key in the PINE, the PINE can securely obtain the PEGC after connecting to the network via the PEGC.

[0116] In some embodiments, the first request may be a request message proposed in related technologies, which is reused for PINE to configure operator credentials. By pre-configuring the operator public key within PINE, PINE can apply for operator credentials for 3GPP network security via PEGC connection. Compared to verifying the operator credentials through a third party's default credentials and then configuring the operator credentials, this shortens the operator credential process and improves the operator credential configuration speed.

[0117] In other embodiments, the first request may be a request for operator credentials dedicated to PINE, in which case the first request may not carry a credential configuration indicator.

[0118] like Figure 3 As shown, this disclosure provides an information processing method executed by PINE, the method comprising:

[0119] S1210: Use the pre-configured operator public key to encrypt the first random number and the first timestamp to obtain encrypted information;

[0120] S1220: Send a first request to the PEGC based on the encrypted information, the public key identifier of the operator's public key, and the identifier of the PINE;

[0121] S1230: Receive the first response returned based on the first request;

[0122] S1240: Obtain the operator credentials carried in the first response based on the operator's public key.

[0123] First, PINE uses a random algorithm to generate the first random number. The length of this first random number can be pre-defined, for example, as specified in a protocol. For example, the length of the first random number can be 512 bits, 256 bits, or 128 bits.

[0124] In one embodiment, the length of the first random number is not less than the length of the operator credential.

[0125] The first timestamp can be: the timestamp of generating the first random number, and / or the timestamp of encrypting the first random number with the operator's public key, or the timestamp of detecting the sending of the first request. In short, the first timestamp can represent various times, and can be the timestamp of any operation of PINE for applying for operator credentials, not limited to the examples above.

[0126] Then, encrypting the first random number and the first timestamp using a pre-configured operator public key yields encrypted information. This encrypted information can be added to an encryption unit, which is an Information Element (IE). In this embodiment of the disclosure, the first request at least includes encrypted information.

[0127] Finally, the encrypted information, the public key identifier, and the PINE identifier are sent to PEGC along with the first request. The public key identifier and the PINE identifier are carried in plaintext in the first request. Therefore, the first request includes both ciphertext and plaintext portions, with the ciphertext portion including at least the encrypted information and the plaintext portion including at least the public key identifier and the PINE identifier.

[0128] It is worth noting that, in order to further enhance security, a message verification code can be obtained by using a signature key known to both the second network element and the PINE to fully protect part or all of the encrypted information, public key identifier and / or PINE identifier. This code can then be used by 3GPP network elements for signature verification, thereby reducing the risk of information tampering during transmission.

[0129] Due to the randomness of the value generated by the first random number itself, and the randomness of the time at which different PINEs generate the first random number, the first random number and the first timestamp can be used by network elements on the network side to perform replay attack verification on the first request, thereby reducing the phenomenon of non-send merging intercepting old requests and repeatedly requesting operator credentials from network elements in the 3GPP network.

[0130] In some embodiments, the PINE also generates a second random number. The second random number is also encrypted when the first random number is encrypted. Therefore, the encrypted information includes not only the first random number and the first timestamp, but also the second random number.

[0131] The encrypted information also includes: a second random number encrypted using the operator's public key;

[0132] The first request to send an operator credential to the network element based on the pre-configured operator public key includes:

[0133] The second random number is used to protect the integrity of the encrypted information, the public key identifier of the operator's public key, the integrity protection algorithm identifier, and the identifier of the PINE, and a message verification code is generated; based on the encrypted information, the public key identifier of the operator's public key, the identifier of the PINE, and the message verification code, a first request is sent to the PEGC.

[0134] The second random number carried in the first request is encrypted, but the message verification code is carried in plaintext in the first request. Additionally, the integrity protection algorithm identifier indicates the integrity protection algorithm used to generate the message verification code; this integrity protection algorithm identifier can also be carried in plaintext in the first request.

[0135] In this embodiment of the disclosure, in order to enhance the security of the first request, the first request will be digitally signed, thereby achieving integrity protection.

[0136] In this embodiment, integrity protection is performed using a second random number generated by PINE. A message verification code for integrity protection is calculated using a string of preset length. This preset length can be a length known to both the PINE and the network element. This string can be determined based on the second random number.

[0137] For example, assuming a preset length of 128 bits, PINE can perform one of the following operations:

[0138] If the second random number generated by PINE exceeds 128 bits, then the lower 128 bits or the higher 128 bits are used to perform integrity protection on the encrypted information, the integrity protection algorithm identifier, the public key identifier, and the PINE identifier, resulting in a message verification code. This message verification code is also sent to the network element in the first request.

[0139] If the random number generated by PINE is equal to 128 bits, then the entire second random number is used to digitally sign the encrypted information, the public key identifier, the integrity protection algorithm identifier, and the PINE identifier to obtain a message verification code.

[0140] If the second random number generated by PINE is less than 128 bits, then two or more second random numbers are concatenated to obtain a 128-bit string. The concatenated string is then used to perform integrity protection on the encrypted information, the integrity protection algorithm identifier, the public key identifier, and the PINE identifier, resulting in a message verification code.

[0141] Thus, after receiving the encrypted information, public key identifier, PINE identifier, integrity protection algorithm identifier, and message verification code, the network element on the network side (e.g., the second network element) uses its private key to decrypt the encrypted information to obtain a first random number, a second random number, and a first timestamp of the plaintext. Then, it uses the second random number to perform integrity protection on the encrypted information, integrity protection algorithm identifier, public key identifier, and PINE identifier, generating a message verification code. The generated message verification code is then compared with the message verification code received from the PINE. If they match, the first request is considered to have passed integrity protection verification, confirming that the first request has not been tampered with during transmission, further enhancing the security of the first request.

[0142] In some embodiments, if the PINE is pre-configured with an integrity protection algorithm supported by network elements on the network side, the second random number can be used to perform integrity protection on the ciphertext information, the integrity protection algorithm identifier, the PINE identifier, and the public key identifier to obtain the message verification code. In this case, the first request carries the message verification code.

[0143] If the PINE is not pre-configured with an integrity protection algorithm supported by the network-side network elements, then the second random number can be omitted for integrity protection of the ciphertext information, the PINE's identifier, and the public key identifier. In this case, the first request does not carry the message verification code.

[0144] In some embodiments, the second random number is used to perform integrity protection on the encrypted information, the integrity protection algorithm identifier, the public key identifier of the operator's public key, and the identifier of the PINE to obtain a message verification code, which may include:

[0145] Using a second random number, a transmission direction value, a bearer identifier, and a counter value, an integrity protection calculation is performed on the message consisting of the encrypted information, the public key identifier of the operator's public key, the integrity protection algorithm identifier, and the PINE identifier to obtain the message verification code.

[0146] The second random number serves as the integrity protection key for the integrity protection algorithm.

[0147] Both the transmission direction value and the bearer identifier can be preset values. The preset values ​​corresponding to the transmission direction value and the bearer identifier can be the same or different.

[0148] In one embodiment, the counter value can also be set to a specific value, which can be a value known to the second network element such as PINE and AUSF.

[0149] In another embodiment, the counter may be a 32-bit or 64-bit counter value, which may be the value of the user parameter update counter maintained by both the PINE and the second network element.

[0150] Of course, the above is just an example of calculating message verification codes based on integrity algorithms, and the actual implementation is not limited to this example.

[0151] In some embodiments, such as Figure 4 As shown, the first response includes a digital signature. This digital signature can be generated by the second network element.

[0152] The step of obtaining the operator credentials carried in the first response based on the operator's public key includes:

[0153] S1310: Verify the signature of the first response based on the operator's public key;

[0154] S1320: After the first response passes signature verification, the encrypted credentials carried in the first response are decrypted using the first random number to obtain the operator credentials, wherein the first response carrying the encrypted credentials is returned after the encrypted information is successfully decrypted and the encrypted information is verified to be free from replay attacks based on the first random number and the first timestamp.

[0155] In some embodiments, the first response includes a digital signature of the encrypted credential and a second timestamp using the operator's private key. The signature verification of the first response based on the operator's public key may include:

[0156] After successfully verifying the digital signature using the operator's public key, the verification of whether the encrypted certificate and the second timestamp have been tampered with is realized, that is, verifying whether the encrypted certificate and the second timestamp have been protected intact during transmission.

[0157] Specifically, the operator's public key is used to digitally sign the encrypted credential and the second timestamp to obtain a locally generated digital signature; the received digital signature is compared with the locally generated digital signature, and if the received digital signature and the locally generated digital signature are the same, the first response is considered to have passed signature verification.

[0158] After the signature verification of the first response is successful, the encrypted credentials carried in the first response will be decrypted to obtain the plaintext operator credentials.

[0159] In one embodiment, if the network element on the network side is an encrypted certificate obtained by encrypting the operator's certificate using the operator's public key corresponding to the operator's private key, then PINE uses the operator's private key to decrypt the encrypted certificate to obtain the plaintext operator's certificate.

[0160] In another embodiment, if the network element on the network side encrypts the operator credential using the random number sent in the first request, then PINE can use its own generated first random number to decrypt the encrypted credential, thereby obtaining the plaintext operator credential. If the operator credential is encrypted or decrypted using the first random number generated by PINE, then the integrity protection and confidentiality protection of the first response use different keys, thereby further enhancing the security of the first response.

[0161] In some embodiments, the first response further includes a second timestamp.

[0162] The second timestamp could be: a timestamp for configuring operator credentials for PINE, or a timestamp for when the encrypted operator receives encrypted credentials, etc. The second timestamp included in the first response can be used by PINE to verify whether the first response has been subjected to a replay attack.

[0163] In some embodiments, such as Figure 5 As shown, obtaining the operator credentials carried in the first response based on the operator's public key includes:

[0164] S1410: Verify the signature of the first response based on the operator's public key;

[0165] S1420: Determine whether the first response has been subjected to a replay attack based on the second timestamp.

[0166] S1430: After the first response passes signature verification and it is determined that no replay attack has been received, the encrypted credentials carried in the first response are decrypted using the first random number to obtain the operator credentials.

[0167] Since the second timestamp can be carried in plaintext in the first response, there is no fixed order between replay attack verification and integrity verification.

[0168] For example, in one embodiment, after verifying the integrity of the encrypted credentials and the second timestamp using the operator's public key, it is determined whether the first response has been subjected to a replay attack based on the second timestamp.

[0169] For example, in another embodiment, replay attack verification is performed based on a second timestamp carried by the first response before or during signature verification of the first response.

[0170] Determining whether cryptographic credentials have been subjected to a replay attack may include at least one of the following:

[0171] If the time of the second timestamp indicated by PINE is earlier than the time of the first timestamp indicated, it can be considered that the first response has been subjected to a replay attack.

[0172] The first calculation time is obtained by summing the time indicated by the second timestamp and the first time offset value; if the first calculation time is earlier than the current time, the first response can be considered to have been subjected to a replay attack;

[0173] The second time is calculated by summing the time indicated by the second timestamp and the second time offset value; if the second time is earlier than the current time, the first response can be considered to have been subjected to a replay attack.

[0174] The second time offset value is greater than the first time offset value.

[0175] In summary, there are multiple ways to verify whether the first response has been subjected to a replay attack based on the second timestamp, which will not be listed here.

[0176] In this embodiment of the disclosure, when the first response passes the signature verification and it is determined that the first response has not been subjected to a replay attack, the first random number is used to decrypt the encryption credential to obtain the PINE operator credential.

[0177] If the first response fails the integrity protection verification or is determined to be subjected to a replay attack, the decryption of the first response is stopped.

[0178] Furthermore, the method further includes: sending an attack alert to the network via PEGC if the first response fails integrity protection verification or if it is determined that the first response has been subjected to a replay attack; and / or, if the first response fails integrity protection verification or if it is determined that the first response has been subjected to a replay attack, resending the first request for operator credentials based on the operator's public key.

[0179] In some embodiments, the method further includes:

[0180] When the first response contains a credential confirmation indicator and the operator credential is correctly received, a first reception confirmation value indicating that the operator credential has been correctly received is generated using the operator's public key.

[0181] The first receipt confirmation value is sent to the PEGC.

[0182] In some embodiments, the first response may include a credential confirmation indicator. If the PINE has correctly received the carrier credential, it needs to send a first reception confirmation value to the network. Otherwise, the PINE may not send the first reception confirmation value to the network, or it may send a credential failure message, etc.

[0183] In some embodiments, if PINE sends a first reception acknowledgment value to the network, it also sends a credential acknowledgment indicator to the network along with the first reception acknowledgment value. In this case, the credential acknowledgment indicator is used to inform the network of the first reception acknowledgment value currently sent by PINE.

[0184] Before sending the first reception confirmation value to the network, PINE first generates the first reception confirmation value based on the operator's public key.

[0185] For example, the first receipt confirmation value is generated using the operator's public key and the operator's credentials as input parameters.

[0186] For example, the first reception confirmation value is generated using the operator's public key, the length of the operator's public key, the identifier of the PINE, and the length of the PINE identifier as input parameters.

[0187] In summary, there are multiple ways to generate the first reception confirmation value, and the specific implementation is not limited to any of the methods mentioned above. However, if the input parameters for generating the first reception confirmation value are parameters known to the network element on the network side, then the network element on the network side can verify the first reception confirmation value without further obtaining the input parameters.

[0188] In this embodiment of the disclosure, the confirmation of the operator credential is no longer a simple reception indicator, but a unique first reception confirmation value, thereby reducing the confirmation of counterfeit operator credentials.

[0189] In some embodiments, generating a first reception acknowledgment value using the operator's public key to indicate that the operator's credentials have been correctly received includes:

[0190] A first reception confirmation value is generated based on the operator's public key, the operator's credentials, and the PINE identifier.

[0191] For example, the first receipt confirmation value is obtained by encrypting the encryption credential and the identifier of the PINE using the operator's public key.

[0192] For example, the first receipt confirmation value is obtained by encrypting the encryption credential, the first random number, and the identifier of the PINE using the operator's public key.

[0193] In one embodiment, sending the first receipt confirmation value to the PEGC includes sending the first receipt confirmation value and a credential confirmation indicator to the PEGC.

[0194] For example, the length of the credential confirmation indicator is the length of a binary credential indicator. The length of the PINE identifier is the length of a binary PINE identifier. The above lengths can be in bits.

[0195] In one embodiment, a credential confirmation indicator can be used to indicate that the operator credential has been correctly received, while the first reception confirmation value can be used by the network element to verify whether the operator credential has been correctly received by the PINE.

[0196] In another embodiment, the credential confirmation indicator is used only to indicate a message carrying the credential confirmation indicator, which carries a first receipt confirmation value.

[0197] The above is merely an example of generating the first received confirmation value; the specific implementation method is not limited to the example above.

[0198] like Figure 6 As shown, this disclosure provides an information processing method, wherein the method is executed by PEGC, and the method includes:

[0199] S2110: Receive a first request sent by PINE based on a pre-configured operator public key; wherein, the first request is used to request operator credentials;

[0200] S2120: Based on the first request, send a second request to the first network element;

[0201] S2130: Receive the second response returned by the first network element based on the second request;

[0202] S2140: Send the second response to the PINE and send the first response.

[0203] This PEGC can be used for devices that have obtained operator credentials through PINE and are already registered with the 3GPP network.

[0204] A secure non-3GPP connection is established between PEGC and PINE.

[0205] If a PINE connection without configured carrier credentials connects to PEGC, a PINE first request will be received. Part of the information in this first request is secured by the carrier pre-configured by PINE.

[0206] After receiving the first request, PEGC will encapsulate the content carried by the first request into a second request and send it to the first network element.

[0207] If the network element on the network side configures the operator credentials for PINE, then PEGC will receive a second response, which will carry the operator credentials.

[0208] In S2140, the second response is sent to the PINE as a container or IE (Internet Information Service) within the first response. In this way, the PINE can receive the network element's configuration of operator credentials, or know whether the network element has configured operator credentials for it.

[0209] In some embodiments, the second request includes the content of the first request, and further includes at least one of the following:

[0210] The credential configuration indicator directs the user to request operator credentials.

[0211] The identifier of the PEGC is used to verify whether the PEGC is valid.

[0212] In one embodiment, the second request may be a request specifically for configuring operator credentials for PINE, in which case the second request may or may not carry a credential configuration indicator.

[0213] In another embodiment, the second request may be an existing request for other information transmission, which can be reused to request operator credentials for PINE. In this case, the second request may carry a credential configuration indicator to explicitly indicate that the current second request is used to request operator credentials for PINE.

[0214] In one embodiment, the second request carries an identifier for the PEGC. The device identifier of the PEGC (or simply the identifier of the PEGC or the PEGC identifier) ​​may include, but is not limited to, the PEGC's Subscription Concealed Identifier (SUCI) and / or Subscription Permanent Identifier (SUPI).

[0215] If the PEGC verification is valid, the network element will confirm that the various information for applying for the operator certificate is credible; otherwise, it is untrustworthy and can stop configuring the operator certificate for PINE.

[0216] like Figure 7 As shown, this disclosure provides an information processing method, wherein the method is executed by PEGC, and the method includes:

[0217] S2210: Receive a first request sent by PINE based on a pre-configured operator public key; wherein, the first request is used to request operator credentials;

[0218] S2220: Based on the first request, send a second request to the first network element;

[0219] S2230: Receive the second response returned by the first network element based on the second request;

[0220] S2240: Send the second response to the PINE and send the first response.

[0221] S2250: Receive a first reception confirmation value; wherein, the first reception confirmation value is generated by the PINE based on the operator's public key, the encryption certificate, and the identifier of the PINE after the PINE has correctly received the operator's certificate;

[0222] S2260: Send the first receipt confirmation value to the first network element.

[0223] The encrypted credential is generated after the operator credential configured for PINE is encrypted. For example, the encrypted credential is obtained by encrypting the operator credential configured for PINE using a random number provided by PINE.

[0224] In one embodiment, the PEGC sends the first reception confirmation value to the first network element after receiving it.

[0225] In another embodiment, after receiving the first reception confirmation value, PEGC appends a credential confirmation indicator and then sends it to the first network element.

[0226] In another embodiment, PEGC receives a first reception confirmation value and a credential confirmation indicator from PINE, and sends the first reception confirmation value and the credential confirmation indicator together to the first network element.

[0227] like Figure 8 As shown, this embodiment of the disclosure provides an information processing method, executed by a first network element, wherein the method includes:

[0228] S3110: Receive a second request sent by PEGC, wherein the second request is sent based on the first request; the first request is a request sent by PINE based on a pre-configured operator public key and used to request operator credentials;

[0229] S3120: Based on the second request, send a third request to the second network element;

[0230] S3130: Receive a third response based on a third request;

[0231] S3140: Based on the third response, send a second response to the PEGC.

[0232] The first network element includes, but is not limited to, network elements of various core networks. For example, the first network element may be an AMF.

[0233] The first network element can serve as the network element that configures the PEGEC and operator credentials, and can also serve as an intermediate network element for communication between the PEGEC and other network elements.

[0234] After receiving the PEGC, the first network element sends a third request to the second network element based on the second request. This third request includes the second request. For example, the second request is added to a container or IE in the third request and then sent to the second network element.

[0235] Subsequently, the first network element will receive a third response from the second network element in response to the third request. After receiving the third response, the first network element returns the second response to PEGC. For example, the third response can be added to the container or IE of the second response.

[0236] like Figure 9 As shown, this embodiment of the disclosure provides an information processing method, executed by a first network element, wherein the method includes:

[0237] S3210: Receive a second request sent by PEGC, wherein the second request is sent based on the first request; the first request is a request sent by PINE based on a pre-configured operator public key and used to request operator credentials;

[0238] S3220: Based on the second request, send a third request to the second network element;

[0239] S3230: Receive a third response based on a third request;

[0240] S3240: Send a second response to the PEGC based on the third response;

[0241] S3250: Receive the first reception confirmation value sent by the PEGC; the first reception confirmation value is generated by the PINE based on the operator's public key, the encryption certificate and the identifier of the PINE after the PINE has correctly received the operator's certificate;

[0242] S3260: Send the first receipt confirmation value to the second network element.

[0243] If PINE correctly receives the operator's credentials and the third response carries a credentials confirmation indicator, PINE will generate a first reception confirmation value. At this time, the first network element will send the first reception confirmation value to the second network element.

[0244] In some embodiments, the first reception confirmation value is accompanied by a credential response indicator provided by PEGC or PINE. In this case, the first network element sends the first reception confirmation value and the credential response indicator together to the second network element.

[0245] like Figure 10 As shown, this disclosure provides an information processing method, which is executed by a second network element. The method includes:

[0246] S4110: Receive a third request;

[0247] S4120: Based on the result of processing a third request using the operator's private key, determine whether to configure operator credentials for PINE;

[0248] S4130: When it is determined that operator credentials will be configured for the PINE, a fourth request is sent to the third network element;

[0249] S4140: Receive the operator credentials returned by the fourth request;

[0250] S4150: Use the operator's private key to perform security processing on the operator's credential to obtain the security-processed operator's credential;

[0251] S4160: Send the securely processed operator credentials along with the third response to the first network element.

[0252] The second network element can also be a core network element. For example, the second network element includes, but is not limited to, the Authentication Server Function (AUSF).

[0253] The third request originates from the first network element. Upon receiving the third request, the first network element processes it using the operator's private key corresponding to the aforementioned operator's public key, thereby obtaining a processing result. Based on this result, it is determined whether to configure operator credentials for PINE.

[0254] If it is determined that operator credentials will be configured for PINE, a fourth request will be sent to the third network element to request the third network element to configure operator credentials for PINE. If it is determined that operator credentials will not be configured for PINE, the configuration process will stop.

[0255] Receive the fourth response returned by the third network element based on the fourth request. This fourth response includes: the operator credentials configured by the third network element for the PINE, which are in plaintext at this time.

[0256] Upon receiving the carrier credential, in order to ensure the secure issuance of the carrier credential to PINE, the plaintext carrier credential is processed using the carrier's private key to obtain the securely processed carrier credential.

[0257] In some embodiments, the operator's private key can be used to decrypt operator credentials encrypted with the operator's public key, or to protect the integrity of operator credentials.

[0258] The securely processed operator credentials can be directly returned from the second network element to the first network element, or the securely processed operator credentials can be returned to the third network element, which will then return them to PINE via the second network element, the first network element, and PEGC.

[0259] In short, the operator's credentials, after being securely processed, will be returned to the first network element.

[0260] In some embodiments, such as Figure 11As shown, S4120 may include:

[0261] S4121: Determine the operator's private key based on the public key identifier of the operator's public key carried in the third request;

[0262] S4122: Use the operator's private key to decrypt the encrypted information carried in the third request to obtain a first random number and a first timestamp;

[0263] S4123: Determine whether the encrypted information has been subjected to a replay attack based on the first random number and the first timestamp;

[0264] S4124: When the encrypted information is not subjected to a replay attack, determine to configure operator credentials for the PINE.

[0265] The operator's public key pre-configured in PINE and the operator's private key stored in the second network element are asymmetric encryption key pairs.

[0266] The third request, carrying the public key identifier of the operator's public key, will retrieve the information of the key pair and obtain the operator's private key.

[0267] The encrypted information carried in the third request is decrypted using the operator's private key. This encrypted information may include at least: a PINE random number and a first timestamp. After decryption, the random number and first timestamp provided by PINE will be obtained.

[0268] In some embodiments, after the second network element decrypts the encrypted information to obtain a first random number and a first timestamp, it determines whether the encrypted information has been received by the second network element based on the combination of the first random number and the first timestamp. If the second network element has received the encrypted information, it can be considered that the encrypted information has been subjected to a replay attack.

[0269] In other embodiments, the second network element can also determine whether the encrypted information has been subjected to a replay attack based on the time difference between the time when the first random number was generated (indicated by the first timestamp) and the time when the third request was received. For example, if the time difference is too large or too small, the encrypted information may have been subjected to a replay attack.

[0270] The above are merely examples of whether encrypted information is susceptible to replay attacks; specific implementations are not limited to the examples above.

[0271] In some embodiments, the encrypted information further includes: a second random number; the third request further includes a message verification code; and the method further includes:

[0272] The message containing the encrypted information, the public key identifier, the integrity protection algorithm identifier, and the PINE identifier is verified based on the message verification code and the second random number.

[0273] When the encrypted information is not subjected to a replay attack, determining to configure operator credentials for the PINE includes:

[0274] When the encrypted information is not subjected to a replay attack and the integrity protection verification is passed, it is determined to configure operator credentials for the PINE.

[0275] In some embodiments, the encrypted information, integrity protection algorithm identifier, public key identifier, and PINE identifier may be integrity protected. If integrity protected, the encrypted information also includes an encrypted second random number, and the third request also includes a message verification code generated by the PINE. The second network element then obtains the message verification code from the third request. If the message verification code is successfully obtained from the third request, the second network element uses the decrypted second random number to perform integrity protection verification on the encrypted information, public key identifier, integrity protection algorithm identifier, and PINE identifier, obtaining a locally generated message verification code. The received message verification code and the locally generated message verification code are compared. If they match, the integrity protection verification of the first request is considered successful, and the integrity of the first request is protected; otherwise, the first request is considered to have been tampered with during transmission.

[0276] In this embodiment, integrity protection verification is performed using a second random number generated by PINE. A digital signature is performed using a string of preset length. This preset length can be a length known to both the PINE and the network element. This string can be determined based on the second random number.

[0277] For example, assuming a preset length of 128 bits, PINE can perform one of the following operations:

[0278] If the second random number generated by PINE exceeds 128 bits, then the lower 128 bits or the higher 128 bits are used to perform integrity protection verification on the encrypted information, integrity protection algorithm identifier, public key identifier, and PINE identifier, resulting in a locally generated message verification code.

[0279] If the second random number generated by PINE is equal to 128 bits, then the entire random number is used to perform integrity protection verification on the encrypted information, public key identifier, integrity protection algorithm identifier, and PINE identifier, resulting in a locally generated message verification code.

[0280] If the second random number generated by PINE is less than 128 bits, then two or more second random numbers are concatenated to obtain a 128-bit string. The concatenated string is then used to perform integrity protection verification on the encrypted information, integrity protection algorithm identifier, public key identifier, and PINE identifier, resulting in a locally generated message verification code.

[0281] Therefore, in some embodiments, the encrypted information further includes: a second random number; the third request further includes a message verification code, and the method further includes:

[0282] The message containing the encrypted information, the public key identifier, the integrity protection algorithm identifier, and the PINE identifier is verified based on the message verification code and the second random number.

[0283] When the encrypted information is not subjected to a replay attack, determining to configure operator credentials for the PINE includes:

[0284] When the encrypted information is not subjected to a replay attack and the integrity protection verification is passed, it is determined to configure operator credentials for the PINE.

[0285] Integrity protection verification can further enhance the security of operator credential configuration.

[0286] For example, if the second network element fails to obtain the message verification code from the third request, it is assumed that the PINE has not pre-configured an integrity protection algorithm, and therefore no integrity protection verification is performed. It is possible to configure operator credentials for the PINE when it is determined that the encrypted information has not been subjected to a replay attack.

[0287] In some embodiments, S4150 may include:

[0288] The operator credential is encrypted using the first random number contained in the encrypted information to obtain an encrypted credential.

[0289] The digital signature is obtained by signing the encrypted credential and the second timestamp generated by the encrypted credential using the operator's private key.

[0290] The operator's certificate in plaintext is received from the third network element. A first random number is used as the encryption key, and the operator's certificate is encrypted according to an agreed-upon confidentiality algorithm to obtain an encrypted certificate. The confidentiality algorithm can be agreed upon by the protocol.

[0291] In this embodiment, the random number provided by PINE can be used to verify whether the encrypted information has been subjected to a replay attack, and can also serve as a key encryption operator credential, thus achieving a dual purpose for the information.

[0292] Furthermore, the operator's private key is used to digitally sign the encrypted credential and its second timestamp. Specifically, the operator's private key, the encrypted credential itself, and the second timestamp can be used as input parameters to generate a digital signature for signature verification.

[0293] With only one operator private key in the second network element, both confidentiality and integrity protection of the operator credentials are provided.

[0294] In some embodiments, encrypting the operator credential based on a first random number contained in the encrypted information to obtain an encrypted credential includes:

[0295] The first random number is XORed with the operator's certificate to obtain the encrypted certificate.

[0296] In one scenario, if the number of binary bits in the first random number is equal to the number of binary bits in the operator's credential, then a bitwise XOR operation is performed directly.

[0297] In another scenario, if the number of bits in the first random number is greater than the number of bits in the operator's credential, then the high S bits or low S bits of the binary string of the first random number are XORed with the operator's credential. Here, S is the number of bits in the operator's credential.

[0298] In another scenario, if the number of binary digits in the first random number is less than the number of binary digits in the operator's credential, then the number of binary digits in the random number can be repeatedly concatenated until a concatenated binary string of length S bits or greater is obtained. If the concatenated binary string is greater than S, then the higher S bits or the lower S bits can be XORed with the operator's credential.

[0299] In this embodiment of the disclosure, the encryption of the operator credential is achieved by bitwise XORing a first random number with the operator credential. The specific implementation is not limited to the examples described above.

[0300] In some embodiments, the method further includes:

[0301] When the encrypted information is subjected to a replay attack, the operator credential configuration of the PINE is stopped;

[0302] And / or,

[0303] If the integrity protection verification fails, stop the operator credential configuration of the PINE.

[0304] In this embodiment of the disclosure, if the encrypted information from PINE fails the replay attack verification and / or the integrity verification passes, it is determined that the operator credential configuration will not be performed, thereby improving the security of operator credential configuration.

[0305] In some embodiments, the method further includes:

[0306] The securely processed operator credentials are sent to the third network element;

[0307] The step of sending the processed operator credentials along with the fourth response to the second network element includes:

[0308] Receive the configuration result provided by the third network element based on the operator credentials after the security processing;

[0309] The securely processed operator credentials are sent to the first network element along with the third response.

[0310] Sending the securely processed operator credentials to the third network element may include:

[0311] The digital signature obtained by signing the encrypted certificate with the operator's private key and the second timestamp will be sent to the third network element.

[0312] After the digital signature, encryption credential, and second timestamp are sent to the third network element, the first network element receives the configuration result returned by the third network element. The second network element then includes this configuration result in a third response and returns it to the first network element.

[0313] In some embodiments, the configuration result may include: digital signature, cryptographic credential, second timestamp, PEGC identifier, and PINE identifier.

[0314] In other embodiments, the configuration result may include: a digital signature, an encrypted credential, a second timestamp, a PEGC identifier, a PINE identifier, and a credential response indicator. The credential response indicator can be used to instruct the PINE to return a first reception confirmation value after correctly receiving the carrier credential.

[0315] In another embodiment, after generating the digital signature, the second network element does not return the digital signature, encryption certificate, and second timestamp to the third network element. Instead, it directly returns the third response, which includes the digital signature, encryption certificate, and second timestamp, to the first network element. If PINE needs to correctly receive the first acceptance confirmation value of the operator's certificate, the second network element will send a certificate response indicator to the first network element along with the digital signature. In some embodiments, this certificate response indicator may also be referred to as a certificate reception indicator.

[0316] In some embodiments, the method further includes sending the securely processed operator credentials along with the third response to the first network element.

[0317] Generate a second confirmation value;

[0318] Receive the first reception confirmation value sent by the first network element;

[0319] When the second reception confirmation value is the same as the first reception confirmation value, it is determined that the PINE has correctly received the operator certificate;

[0320] Send a notification to the third network element that the operator's certificate has been correctly received.

[0321] In some embodiments, the second network element generates not only a digital signature, an encrypted certificate, and a second timestamp, but also a second reception confirmation value. After receiving the first reception confirmation value from the PINE, the two are compared to determine whether the PINE has correctly received the operator certificate. If the PINE has correctly received the operator certificate, it sends a corresponding notification to the third network element, indicating the configuration result of the operator certificate. Otherwise, it does not send a notification to the third network element indicating that the operator certificate has been correctly received, or it sends a notification indicating that the operator certificate has not been correctly received.

[0322] In this embodiment, the second reception confirmation value does not need to be transmitted to the third network element, and the comparison between the second reception confirmation value and the first reception confirmation value is performed by the second network element, thereby shortening the configuration process of PINE's operator credentials and improving configuration efficiency.

[0323] It is worth noting that in this scheme where the second network element compares the first and second received confirmation values, after the second network element generates the digital signature, encryption certificate, and second timestamp, it directly includes the digital signature in the third response and returns it to the first network element without returning the digital signature, encryption certificate, and second timestamp to the third network element.

[0324] In another embodiment, the method further includes:

[0325] A second reception confirmation value is generated, and the second reception value is provided to the third network element along with the securely processed operator credential.

[0326] Receive the first reception confirmation value sent by the first network element;

[0327] The first reception confirmation value is sent to the third network element, wherein the first reception confirmation value is used by the third network element and the second reception confirmation value to determine whether the PINE has correctly received the operator certificate.

[0328] Unlike the previous embodiment, in this embodiment, the second network element will return the second reception confirmation value it generates to the third network element, and the first reception confirmation value provided by PINE will also be passed to the third network element. The third network element will then compare the first reception confirmation value and the second reception confirmation value to determine whether the PINE has correctly received the operator certificate.

[0329] In some embodiments, when the second network element receives the first reception confirmation value, it will also receive a credential confirmation indicator.

[0330] In some embodiments, generating the second receipt confirmation value includes:

[0331] The second receipt confirmation value is generated based on the operator's public key, the operator's credentials, and the identifier of the PINE.

[0332] There are many ways to generate the first and second reception confirmation values. The above is a specific example. The specific implementation is not limited to the example above. Other methods can be found in the corresponding parts of the foregoing embodiments, which will not be repeated here.

[0333] like Figure 12 As shown, this disclosure provides an information processing method, wherein the method is executed by a third network element, and the method further includes:

[0334] S5110: Receives the fourth request from the second network element;

[0335] S5120: Configure operator credentials for PINE according to the fourth request;

[0336] S5130: The operator credential is sent to the second network element in the fourth response, wherein the operator credential is used to securely process the operator private key corresponding to the operator public key and then issue it to the PINE.

[0337] This third network element can also be a core network element, including but not limited to UDM.

[0338] The PINE may be a device that has at least a pre-configured operator public key; or, the PINE may be a device that has not been configured with default credentials but has a pre-configured operator public key.

[0339] The system receives the fourth request from the second network element and then configures the operator credential for the PINE. Once the operator credential configuration is complete, it is returned to the second network element for security processing.

[0340] This security process includes, but is not limited to: encryption protection and / or integrity protection and / or protection against repeated attacks.

[0341] In this way, the operator credentials issued to PINE are at least protected by the operator's proprietary security measures, thus ensuring the secure issuance of operator credentials.

[0342] In some embodiments, the method further includes:

[0343] Receive the operator's credentials after security processing returned by the second network element;

[0344] Generate a configuration result including the operator credentials after the security processing;

[0345] The configuration result is sent to the third network element.

[0346] The receipt of the operator's certificate after security processing returned by the second network element includes: receiving an encrypted certificate returned by the second network element; or receiving an encrypted certificate, digital signature, and second timestamp sent by the second network element.

[0347] In some embodiments, if a third network element wants the PINE to return a first reception confirmation value indicating that the operator's credentials have been correctly received, it will add a credential response indicator to the digital signature, the encrypted credential, and the second timestamp to form the configuration result. The configuration result is then returned to the second network element for distribution to the PINE.

[0348] If the securely processed operator credential is not returned to the third network element, and the third network element requires the PINE to return a first receipt confirmation value indicating that the operator credential has been correctly received, then the third network element will provide the credential response indicator and the plaintext operator credential to the second network element. In this way, after the second network element generates the encrypted credential, the second timestamp, and the digital signature, it will return the credential response indicator, the encrypted credential, the second timestamp, and the digital signature together in the third response to the first network element, and finally issue it to the PINE.

[0349] In some embodiments, the method further includes:

[0350] Receive the second reception confirmation value generated by the second network element;

[0351] Receive the first reception confirmation value generated by the PINE;

[0352] When the first reception confirmation value and the second reception confirmation value are the same, it is determined that the PINE has correctly received the operator certificate.

[0353] If PINE returns the first reception confirmation value and the third network element performs reception verification, the third network element will first receive the second reception confirmation value from the second network element after the second network element generates the second reception confirmation value. When PINE returns the first reception confirmation value, the third network element will compare the locally stored second reception confirmation value with the first reception confirmation value to determine whether PINE has correctly received the operator's certificate.

[0354] In another embodiment, if the comparison of the first reception confirmation value and the second reception confirmation value is performed by the second network element, the information processing method performed by the third network element further includes: receiving a notification of correct reception of operator credentials sent by the second network element.

[0355] If the third network element receives the notification, it assumes that the PINE has correctly received the operator credentials configured by the third network element; otherwise, it assumes that the PINE has not correctly received the operator credentials.

[0356] In some embodiments, the method further includes:

[0357] Before configuring the operator credentials for the PINE, verify that the PEGC of the PINE connection is valid;

[0358] The step of configuring carrier credentials for PINE according to the fourth request includes:

[0359] When the PEGC is valid, configure the operator credentials for PINE according to the fourth request.

[0360] The fourth request carries at least the identifier of the PEGC. The third network element can determine whether the PEGC of the PINE connection is valid based on the identifier of the PEGC. If it is valid, it will continue to configure the operator certificate for the PINE; otherwise, it will not configure the operator certificate for the PINE.

[0361] Assume that PINE and PEGC have established a secure non-3GPP connection.

[0362] Assume PINE is pre-configured with the operator's public key, instead of the default credentials provided by a third-party AAA server. This operator's public key is the aforementioned operator public key, configured by the operator.

[0363] PEGC has been registered with the 5G core network (5GC). The connection between PEGC and AMF is protected by Non-Access Stratum (NAS) security. (Reference) Figure 13 As shown in the embodiments of this disclosure, an information processing method is provided, which may include:

[0364] 0.PINE securely connects to PEGC via a non-3GPP connection.

[0365] 1. PINE sends a credential configuration request to PEGC, carrying the PINE's identifier, an encrypted random number, a first timestamp, and a public key identifier. For example, PINE sends a request to PEGC for carrier credentials. Specifically, PINE first generates a random number of a predetermined length (e.g., 256 bits). Then, PINE encrypts the random number and the first timestamp (timestamp p1) using a pre-configured carrier public key. The request includes an encryption unit, the PINE's identifier, and the public key identifier of the carrier's public key. The first timestamp can be PINE's encryption timestamp and / or the timestamp of the random number generation. The encryption unit may include at least: a random number encrypted using the carrier's public key and the first timestamp. The PINE's device identifier includes, but is not limited to: PINE's International Mobile Equipment Identity (IMEI) and / or MAC address.

[0366] 2. Upon receiving the request, PEGC sends it to AMF via a NAS message. This NAS message may include: a credential configuration indicator, the PINE's identifier, an encrypted random number and a first timestamp, a public key identifier, and the PEGC's identifier. The credential configuration indicator instructs the PINE to request the configuration of operator credentials. The PEGC's identifier includes, but is not limited to, PEGC's SUCI and / or SUPI.

[0367] 3. The AMF sends a credential configuration indicator, a PINE device identifier, an encrypted random number, an encrypted first timestamp (timestamp p1), the public key identifier of the operator's public key, and the SUCI of the PEGC to the AMF via the credential configuration request service operation. The credential issuance service operation can be a newly defined operation or a reused existing Nausf_UEAU_Authenticate service operation.

[0368] 4. AUSF sends a request to UDM for operator credentials. Before sending the request to UDM, AUSF retrieves the corresponding operator operator private key based on the public key identifier of the operator's public key. Then, AUSF decrypts the encrypted unit in the request for operator credentials. If AUSF detects a replay attack based on timestamp P1 and the random number, it will terminate the certificate issuance process. The certificate configuration request includes a credential configuration indicator (credential configuration request indicator), the PINE identifier, the random number, and the SUCI of the PEGC. The credential issuance service operation can be a newly defined operation or a reused existing Nudm_UEAU_Get response operation.

[0369] 5. UDM's credential configuration authentication, specifically, involves the UDM verifying whether the PEGC is a legitimate gateway based on the PEGC's SUCI. The UDM determines whether the PEGC is a legitimate gateway authorized to request carrier credentials based on the PEGC's subscription information. If the PEGC is an authorized legitimate gateway, the UDM initiates PINE to generate carrier credentials; otherwise, the UDM terminates the PINE's carrier credential configuration.

[0370] 6. UDM credential configuration, specifically, UDM generates carrier credentials for PINE. UDM stores carrier credentials, PEGC's SUCI, and PINE's device identifier.

[0371] 7. UDM sends a credential provision response message to AUSF. This message may include: a credential protection indicator, a credential acknowledgment indicator, a PINE identifier, a random number, and the SUCI of the PEGC. The credential protection request includes the credential protection indicator, so that AUSF, upon receiving the carrier credential provided by UDM, can securely protect the carrier credential.

[0372] Credential protection requests can be delivered via a newly defined service operation or by reusing an existing Nudm_UEAU_Get service operation. A credential protection request instructs the AUSF to perform security protection on carrier credentials. A credential acknowledgment indicator instructs the AUSF to generate a second reception acknowledgment value that is compared with the first reception acknowledgment value from the PINE. Simultaneously, this credential acknowledgment indicator is sent to the PINE to instruct it to return the first reception acknowledgment value upon correctly receiving the carrier credentials.

[0373] 8. Provide the UDM with a Nudm-UEAU-Get request, including: a credential protection response indicator, a PINE identifier, a credential verification message (i.e., a second receipt acknowledgment value), a digital signature (the aforementioned digital signature), encrypted credentials, a second timestamp, and the SUCI of the PEGC. The credential protection response indicator indicates that AUSF has provided security protection for the operator's credentials.

[0374] Specifically, when the credential confirmation indicator indicates that the UDM requires credential confirmation from the PINE, the AUSF uses the operator's public key to encrypt the encrypted credential and the identifier of the PINE to construct a credential verification message (i.e., the aforementioned second receive confirmation value).

[0375] The encrypted credential is obtained by XORing a portion or all of a random number equal to the length of the operator's credential with the operator's credential. For example, if the length of the random number is greater than the length of the operator's credential, the lower len (operator's credential) bits of the random number are XORed with the operator's credential. len (operator's credential) represents the length of the operator's credential.

[0376] AUSF uses the operator's private key to generate a digital signature for the encrypted credentials and timestamp2. AUSF then sends a credential protection response to the UDM. The credential protection response includes the newly generated digital signature, a credential protection response indicator, the device identifier from the PINE, timestamp p2, the encrypted credentials, and the SUPI of the PEGC. The credential protection response indicator shows that AUSF has securely processed the operator's credentials.

[0377] If the UDM requires credential acknowledgment information from the PINE (i.e., the first receive acknowledgment value), the credential protection response also includes a credential verification message. The credential protection response can be delivered via a newly defined service operation or by reusing an existing Nudm_UEAU_Get service operation.

[0378] 9. UDM sends the credential provision response to AUSF. The credential provision response includes a credential provision response indicator, a credential confirmation indicator, the device identifier of the PINE, encrypted credentials, a second timestamp (timestamp p2), a digital signature, and the SUCI of the PEGC. The credential provision response can be delivered via a newly defined service operation or an existing Nudm_UEAU_Get service operation.

[0379] The supply response indicator indicates that operator credentials have been configured for PINE, and requires PINE to return a receipt confirmation value after correctly receiving the operator credentials.

[0380] 10. The AUSF sends the credential configuration response to the AMF. The credential configuration response includes: a credential configuration response indicator, a credential confirmation indicator, the device identifier from the PINE, encrypted credentials, a second timestamp (p2), and a digital signature. The credential configuration response can be delivered via a newly defined service operation or an existing Nudm_UEAU_Get service operation. The credential configuration response indicator indicates that the message is a response to a request for operator credentials.

[0381] 11. AMF sends the credential configuration response to PEGC.

[0382] 12. PEGC sends the credential configuration response to PINE.

[0383] 13. After receiving the credential configuration response, PINE verifies it. Specifically, PINE first verifies the digital signature using the operator's public key. If the verification result of the digital signature indicates that the credential configuration response has been tampered with, the configuration process for the operator's credential is terminated; otherwise, PINE verifies whether the credential configuration response has been subjected to a replay attack based on the second timestamp. If the credential configuration response has not been subjected to a replay attack, PINE obtains the plaintext operator's credential by XORing a random number with the encrypted credential. If a replay attack has occurred, the process is terminated.

[0384] 14. If the credential confirmation indicator indicates that PINE needs to return a first reception confirmation value (or credential verification message) to UEM to confirm the correct credential reception, then PINE will generate the first reception confirmation value based on the PINE's identifier and the plaintext operator credential.

[0385] 15. PEGC sends a credential removal indicator, a PINE identifier, and a first reception acknowledgment value to AMF.

[0386] 16. The AMF provides the PEGC identifier (e.g., SUCI), credential acknowledgment indicator, PINE identifier, and first receive acknowledgment value (i.e., credential acknowledgment information) to the corresponding UDM. The credential acknowledgment information can use newly defined operations or existing Nudm_SDM_Info service operations.

[0387] 17. Credential Confirmation Message Verification: Once the UDM receives the credential confirmation message, it compares the locally stored second confirmation value with the first confirmation value to verify whether the carrier credential has been correctly received. If they match, the carrier credential configuration is successful; otherwise, the configuration fails.

[0388] Assume that PINE establishes a secure, non-3GPP connection with PEGC. Assume that PINE is pre-configured with the operator's public key, rather than using default credentials generated by a third-party AAA server. PEGC is registered with 5GC. The connection between PEGC and AMF is protected by NAS security.

[0389] like Figure 14 As shown, this disclosure provides an information processing method that may include:

[0390] 0.PINE securely connects to PEGC via a non-3GPP connection.

[0391] 1. PINE sends a request for operator credentials to PEGC. Specifically, PINE first generates a random number of a predetermined length (256 bits). Then, PINE uses a pre-configured operator public key to construct an encrypted random number and an encrypted first timestamp (timestamp p1). The request includes: an encrypted unit, PINE's device identifier, and the public key identifier of the operator's public key.

[0392] 2. Upon receiving the request, PEGC sends the request to AMF via a NAS message.

[0393] 3. The AMF sends a credential configuration indicator, a PINE device identifier, an encrypted random number, an encrypted first event stamp (timestamp p1), the public key identifier of the operator's public key, and the SUCI of the PEGC to the AMF via the credential configuration request service operation. The credential configuration request service operation can be a newly defined operation or a reused existing Nausf_UEAU_Authenticate service operation.

[0394] 4. AUSF sends a request to UDM for operator credentials. Before sending the request to UDM, AUSF retrieves the corresponding operator private key based on the public key identifier of the operator's public key. Then, AUSF uses the operator private key to decrypt the encrypted unit in the request for operator credentials. If AUSF performs replay attack detection based on the first timestamp and random number carried in the request, AUSF terminates the credential issuance process. The request includes: credential configuration indicator, PINE device identifier, random number, and PEGC SUCI. The credential issuance service operation involved in AUSF executing this request can be a newly defined operation or a reused existing Nudm_UEAU_Get service operation.

[0395] 5. Based on the PEGC's SUCI, the UDM first verifies whether the PEGC is a legitimate gateway. For example, based on the PEGC's subscription information, it verifies whether the PEGC is authorized to request carrier credentials as a gateway. If the PEGC is authorized as a gateway to request carrier credentials, the PEGC passes the legitimacy verification, and the UDM initiates the PINE carrier credential configuration; otherwise, the UDM terminates the credential configuration process.

[0396] 6. UDM generates carrier credentials for PINE. UDM stores carrier credentials, PEGC's SUCI, and PINE's device identifier.

[0397] 7. UDM sends a credential provision response message to AUSF. The credential provision response message contains a credential protection request. The credential protection request includes: a credential protection indicator, a credential acknowledgment indicator, the device identifier of the PINE, the carrier credential, and the SUPI of the PEGC. The credential protection request can be delivered via a newly defined service operation or by reusing an existing Nudm_UEAU_Get service operation.

[0398] 8. When the credential confirmation indicator tells the UDM that the PINE operator needs to receive confirmation,

[0399] AUSF uses the operator's public key to encrypt the encryption credential and the PINE identifier to construct the credential verification message (i.e., the aforementioned second receipt confirmation value).

[0400] The encrypted credential is obtained by XORing a portion or all of a random number equal to the length of the operator's credential with the operator's credential. For example, if the length of the random number is greater than the length of the operator's credential, the lower len (operator's credential) bits of the random number are XORed with the operator's credential. len (operator's credential) represents the length of the operator's credential.

[0401] AUSF uses the operator's private key to generate a digital signature for the encrypted credentials and timestamp2. AUSF then sends a credential protection response to the UDM. The credential protection response includes the newly generated digital signature, a credential protection response indicator, the device identifier from the PINE, timestamp p2, the encrypted credentials, and the SUPI of the PEGC. The credential protection response indicator shows that AUSF has securely processed the operator's credentials.

[0402] If the UDM requires credential acknowledgment information from the PINE (i.e., the first receive acknowledgment value), the credential protection response also includes a credential verification message. The credential protection response can be delivered via a newly defined service operation or by reusing an existing Nudm_UEAU_Get service operation.

[0403] 9. AMF sends a credential provision response to PEGC via a NAS message.

[0404] 10. PEGC sends the credentials provision response to PINE.

[0405] 11. Upon receiving a credential provision response, PINE verifies the credential provision response.

[0406] Specifically, PINE first uses the operator's public key to verify the response signature, achieving integrity protection verification. If the integrity protection verification detects that the credential provision response has been tampered with, PINE will terminate the credential configuration process. Otherwise, PINE checks whether the credential provision response has been subjected to a replay attack based on a second timestamp. If the credential provision response has not been subjected to a replay attack, PINE uses a local random number to XOR the encrypted credential, thereby decrypting the encrypted credential to obtain the plaintext operator credential; otherwise, PINE terminates the process.

[0407] 12. If the credential issuance response indicator indicates that the UDM requires a credential acknowledgment message from the PINE, the PINE sends the credential acknowledgment message, the credential acknowledgment indicator, and the PINE's device identifier to the PEGC. The credential acknowledgment message includes: plaintext carrier credentials encrypted with the carrier's public key and the device identifier.

[0408] 13. PEGC sends a credential confirmation message, a credential confirmation indicator, and the device identifier of PINE to AMF.

[0409] 14. The AMF forwards the credential acknowledgment message provided by PEGC to the AUSF. This credential acknowledgment message sent by the AMF includes: the PEGC SUCI, the credential acknowledgment message, the credential acknowledgment indicator, and the PINE device identifier, and is sent to the corresponding AUSF. This message can be delivered through a newly defined service operation, either directly or via the Nausf_UEAU_Authenticate service operation.

[0410] 15. Upon receiving the credential confirmation message, AUSF compares the locally stored credential confirmation message with the credential confirmation message. If they are different, AUSF considers the PINE's carrier credential configuration incorrect; otherwise, AUSF considers the PINE's carrier credential configuration correct.

[0411] 16. AUSF notifies UDM of the credential configuration results.

[0412] like Figure 15 As shown, this disclosure provides an information processing apparatus, wherein the apparatus includes:

[0413] The first sending module 110 is configured to send a first request for operator credentials to the Personal Internet of Things Gateway PEGC based on a pre-configured operator public key.

[0414] The first receiving module 120 is configured to receive a first response based on the first request;

[0415] The first acquisition module 130 is configured to acquire the operator credentials carried in the first response based on the operator's public key.

[0416] This information processing device can be included in the PINE.

[0417] In some embodiments, the first sending module 110, the first receiving module 120, and the first acquiring module 130 may be program modules; after being executed by the processor, the program modules can perform any of the aforementioned operations.

[0418] In other embodiments, the first transmitting module 110, the first receiving module 120, and the first acquiring module 130 may be hardware-software hybrid modules; such hardware-software hybrid modules include, but are not limited to, various programmable arrays; the programmable arrays include, but are not limited to, field-programmable arrays and / or complex programmable arrays.

[0419] In some embodiments, the first transmitting module 110, the first receiving module 120, and the first acquiring module 130 may be pure hardware modules; the pure hardware modules include, but are not limited to, application-specific integrated circuits.

[0420] In some embodiments, the first sending module 110 is configured to encrypt a first random number and a first timestamp using a pre-configured operator public key to obtain encrypted information; and send a first request to the PEGC based on the encrypted information, the public key identifier of the operator public key, and the identifier of the PINE.

[0421] In some embodiments, the encrypted information further includes: a second random number encrypted using the operator's public key;

[0422] The first acquisition module 130 can be specifically configured to use the second random number to perform integrity protection on the encrypted information, the public key identifier of the operator's public key, the integrity protection algorithm identifier, and the identifier of the PINE, and generate a message verification code; and send a first request to the PEGC according to the encrypted information, the public key identifier of the operator's public key, the identifier of the PINE, and the message verification code.

[0423] The first acquisition module 130 is configured to perform signature verification on the first response based on the operator's public key; after the first response passes the signature verification, the first random number is used to decrypt the encrypted credential carried by the first response to obtain the operator credential, wherein the first response carrying the encrypted credential is returned after the encrypted information is successfully decrypted and the encrypted information is verified to be free from replay attack according to the first random number and the first timestamp.

[0424] In some embodiments, the first response further includes: a second timestamp; the method further includes:

[0425] The first determining module is configured to determine whether the first response has been subjected to a replay attack based on the second timestamp.

[0426] The first acquisition module 130 is configured to use the first random number to decrypt the encryption credential and obtain the PINE operator credential when the first response passes the signature verification and it is determined that the first response has not been subjected to a replay attack.

[0427] In some embodiments, the apparatus further includes:

[0428] The first generation module is configured to generate a first reception confirmation value indicating that the operator credential has been correctly received using the operator public key when the first response contains a credential confirmation indicator and the operator credential has been correctly received.

[0429] The first sending module 110 is configured to send the first reception confirmation value to the PEGC.

[0430] In some embodiments, the first generation module is configured to generate a first reception confirmation value based on the operator public key, the operator credentials, and the PINE identifier.

[0431] In some embodiments, the first sending module 110 is configured to send the first reception confirmation value and the credential confirmation indicator to the PEGC.

[0432] In some embodiments, the first request includes:

[0433] The public key identifier of the operator's public key;

[0434] The identifier of the PINE.

[0435] like Figure 16 As shown, this disclosure provides an information processing apparatus, wherein the process is executed by a PEGC, and the apparatus includes:

[0436] The second receiving module 210 is configured to receive a first request sent by PINE based on a pre-configured operator public key; wherein the first request is used to request operator credentials.

[0437] The second sending module 220 is configured to send a second request to the first network element according to the first request;

[0438] The second sending module 220 is also configured to receive a second response returned by the first network element based on the second request;

[0439] The second sending module 220 is also configured to send the second response to the PINE as a first response.

[0440] The information processing device may be included in PEGC.

[0441] In some embodiments, the second receiving module 210 and the second sending module 220 may be program modules; after being executed by the processor, the program modules can perform any of the aforementioned operations.

[0442] In other embodiments, the second receiving module 210 and the second transmitting module 220 may be hardware-software hybrid modules; such hardware-software hybrid modules include, but are not limited to, various programmable arrays; the programmable arrays include, but are not limited to, field-programmable arrays and / or complex programmable arrays.

[0443] In some embodiments, the second receiving module 210 and the second transmitting module 220 may be pure hardware modules; the pure hardware modules include, but are not limited to, application-specific integrated circuits.

[0444] In some embodiments, the second request includes the content of the first request, and further includes at least one of the following:

[0445] The credential configuration indicator directs the user to request operator credentials.

[0446] The identifier of the PEGC is used to verify whether the PEGC is valid.

[0447] In some embodiments, the second receiving module 210 is further configured to receive a first receiving confirmation value; wherein the first receiving confirmation value is generated based on the operator's public key, the encryption certificate, and the identifier of the PINE after the PINE has correctly received the operator's certificate;

[0448] The second receiving module 210 is also configured to send the first receiving confirmation value to the first network element.

[0449] like Figure 17 As shown, this disclosure provides an information processing apparatus, wherein the apparatus includes:

[0450] The third receiving module 310 is configured to receive a second request sent by PEGC, wherein the second request is sent based on the first request; the first request is a request sent by PINE based on a pre-configured operator public key and used to apply for operator credentials.

[0451] The third sending module 320 is configured to send a third request to the second network element according to the second request;

[0452] The third receiving module 310 is configured to receive a third response based on a third request;

[0453] The third sending module 320 is configured to send a second response to the PEGC based on the third response.

[0454] The information processing device may be included in a first network element, which includes, but is not limited to, AMF.

[0455] In some embodiments, the third receiving module 310 and the third sending module 320 may be program modules; after being executed by the processor, the program modules can perform any of the aforementioned operations.

[0456] In other embodiments, the third receiving module 310 and the third transmitting module 320 may be hardware-software hybrid modules; such hardware-software hybrid modules include, but are not limited to, various programmable arrays; the programmable arrays include, but are not limited to, field-programmable arrays and / or complex programmable arrays.

[0457] In some embodiments, the third receiving module 310 and the third transmitting module 320 may be pure hardware modules; the pure hardware modules include, but are not limited to, application-specific integrated circuits.

[0458] In some embodiments, the third receiving module 310 is configured to receive a first receiving confirmation value sent by the PEGC; the first receiving confirmation value is generated based on the operator's public key, encryption certificate, and PINE's identifier after the PINE has correctly received the operator's certificate.

[0459] The third sending module 320 is configured to send the first reception confirmation value to the third network element.

[0460] like Figure 18 As shown, this disclosure provides an information processing method, wherein the apparatus includes: a fourth receiving module 410, a fourth sending module 420, a second determining module 430, and a second acquiring module 440;

[0461] The fourth receiving module 410 is configured to receive a third request;

[0462] The second determining module 430 is configured to determine whether to configure operator credentials for PINE based on the result of processing the third request using the operator's private key.

[0463] The fourth sending module 420 is configured to send a fourth request to the third network element when it is determined that operator credentials will be configured for the PINE.

[0464] The fourth receiving module 410 is also configured to receive the operator credentials returned by the fourth request;

[0465] The second acquisition module 440 is configured to use the operator's private key to perform security processing on the operator's credential to obtain the security-processed operator's credential.

[0466] The fourth sending module 420 is further configured to send the securely processed operator credentials to the first network element along with the third response.

[0467] The information processing device may be included in a second network element, the first network element including but not limited to AUSF.

[0468] In some embodiments, the fourth receiving module 410, the fourth sending module 420, the second determining module 430, and the second acquiring module 440 may be program modules; after being executed by the processor, the program modules can perform any of the aforementioned operations.

[0469] In other embodiments, the fourth receiving module 410, the fourth sending module 420, the second determining module 430, and the second acquiring module 440 may be hardware-software hybrid modules; such hardware-software hybrid modules include, but are not limited to, various programmable arrays; the programmable arrays include, but are not limited to, field-programmable arrays and / or complex programmable arrays.

[0470] In some embodiments, the fourth receiving module 410, the fourth sending module 420, the second determining module 430, and the second acquiring module 440 may be pure hardware modules; the pure hardware modules include, but are not limited to, application-specific integrated circuits.

[0471] In some embodiments, the second determining module 430 is configured to determine the operator private key based on the public key identifier of the operator public key carried in the third request;

[0472] Use the operator's private key to decrypt the encrypted information carried in the third request;

[0473] Based on the first random number and first timestamp carried by the encrypted information, determine whether the encrypted information has been subjected to a replay attack;

[0474] When the encrypted information is not subjected to a replay attack, it is determined that the PINE will be configured with operator credentials.

[0475] In some embodiments, the encrypted information further includes: a second random number; the third request further includes a message verification code, and the apparatus further includes:

[0476] The verification module is configured to perform integrity protection verification on the encrypted information, the public key identifier, the integrity protection algorithm identifier, and the PINE identifier of the message based on the message verification code and the second random number;

[0477] The second determining module 430 is configured to determine to configure operator credentials for the PINE when the encrypted information has not been subjected to a replay attack and the integrity protection verification is passed.

[0478] In some embodiments, the second acquisition module 440 is configured to encrypt the operator credential according to a first random number contained in the encrypted information to obtain an encrypted credential.

[0479] The digital signature is obtained by signing the encrypted credential and the second timestamp generated by the encrypted credential using the operator's private key.

[0480] In some embodiments, the second acquisition module 440 is configured to perform a bitwise XOR operation between the first random number and the operator credential to obtain the encrypted credential.

[0481] In some embodiments, the apparatus further includes:

[0482] The stop module is configured to stop the operator credential configuration of the PINE when the encrypted information is subjected to a replay attack; and / or to stop the operator credential configuration of the PINE when the integrity protection verification fails.

[0483] In some embodiments, the fourth sending module 420 is configured to send the securely processed operator credentials to the third network element;

[0484] The fourth receiving module 410 is also configured to receive the configuration result provided by the third network element based on the operator credential after the security processing;

[0485] The fourth sending module 420 is also configured to send a third response containing the configuration result to the first network element.

[0486] In some embodiments, the fourth sending module 420 is configured to send a third response containing the securely processed operator credential to the first network element after generating the securely processed operator credential.

[0487] In some embodiments, the apparatus further includes:

[0488] The second generation module is configured to generate a second receipt confirmation value;

[0489] The fourth receiving module 410 is configured to receive the first receiving confirmation value sent by the first network element;

[0490] The device further includes:

[0491] The third confirmation module is configured to determine that the PINE has correctly received the operator certificate when the second reception confirmation value is the same as the first reception confirmation value.

[0492] The fourth sending module 420 is configured to send a notification to the third network element that the operator certificate has been correctly received.

[0493] In some embodiments, the apparatus further includes:

[0494] The second generation module is configured to generate a second receipt confirmation value;

[0495] The fourth sending module 420 is further configured to provide the second received value along with the securely processed operator credential to the third network element;

[0496] The fourth receiving module 410 is configured to receive the first receiving confirmation value sent by the first network element;

[0497] The fourth sending module 420 is configured to send the first reception confirmation value to the third network element, wherein the first reception confirmation value is used by the third network element and the second reception confirmation value to determine whether the PINE has correctly received the operator certificate.

[0498] In some embodiments, the second generation module is configured to generate the second receipt confirmation value based on the operator public key, the operator credentials, and the identifier of the PINE.

[0499] like Figure 19 As shown in the figure, this disclosure provides an information processing apparatus, wherein the apparatus further includes:

[0500] The fifth receiving module 510 is configured to receive the fourth request from the second network element;

[0501] Configuration module 520 is configured to configure operator credentials for PINE according to the fourth request, wherein PINE is a device that has not been configured with default credentials but has been pre-configured with an operator public key;

[0502] The fifth sending module 530 is configured to send the operator credential along with the fourth response to the second network element, wherein the operator credential is used to securely process the operator private key corresponding to the operator public key before being issued to the PINE.

[0503] The information processing device may be included in a third network element, which includes, but is not limited to, UDM.

[0504] In some embodiments, the fifth receiving module 510, the configuration module 520, the second determining module, and the fifth sending module 530 may be program modules; after being executed by the processor, the program modules can perform any of the aforementioned operations.

[0505] In other embodiments, the fifth receiving module 510, the configuration module 520, the second determining module, and the fifth sending module 530 may be hardware-software hybrid modules; such hardware-software hybrid modules include, but are not limited to, various programmable arrays; the programmable arrays include, but are not limited to, field-programmable arrays and / or complex programmable arrays.

[0506] In some embodiments, the fifth receiving module 510, the configuration module 520, the second determining module, and the fifth sending module 530 may be pure hardware modules; the pure hardware modules include, but are not limited to, application-specific integrated circuits.

[0507] In some embodiments, the fifth receiving module 510 is configured to receive the operator credential after security processing returned by the second network element;

[0508] The device further includes:

[0509] The third generation module is configured to generate a configuration result including the operator credentials after the security processing.

[0510] The fifth sending module 530 is configured to send the configuration result to the second network element.

[0511] In some embodiments, the fifth receiving module 510 is configured to receive a second receiving confirmation value generated by the second network element;

[0512] The fifth receiving module 510 is configured to receive the first receiving confirmation value generated by the PINE;

[0513] The device further includes:

[0514] The fourth determining module is configured to determine that the PINE has correctly received the operator's credentials when the first receiving confirmation value and the second receiving confirmation value are the same.

[0515] In some embodiments, the fifth receiving module 510 is configured to receive a notification of correct receipt of operator credentials sent by the second network element.

[0516] In some embodiments, the apparatus further includes:

[0517] The verification module is configured to verify the validity of the PEGC of the PINE connection before configuring the operator credentials for the PINE.

[0518] The configuration module 520 is also configured to configure operator credentials for PINE according to the fourth request when the PEGC is valid.

[0519] This disclosure provides a communication device, including:

[0520] Memory used to store processor-executable instructions;

[0521] The processor is connected to the memory separately;

[0522] The processor is configured to execute the information processing method provided by any of the aforementioned technical solutions.

[0523] The processor may include various types of storage media, which are non-transitory computer storage media that can continue to store information after the communication device loses power.

[0524] Here, the communication device includes a PINE or a network element, which can be any one of the aforementioned first to third network elements.

[0525] The processor can be connected to the memory via a bus or similar means to read executable programs stored in the memory, for example, such as... Figures 2 to 14 At least one of the methods shown.

[0526] Figure 20 This is a block diagram illustrating a communication device 800 according to an exemplary embodiment. For example, the communication device 800 may be the aforementioned PINE and / or PEGC, and may specifically be a mobile phone, computer, digital broadcast user equipment, messaging device, game console, tablet device, medical device, fitness equipment, personal digital assistant, etc.

[0527] Reference Figure 20 The communication device 800 may include one or more of the following components: processing component 802, memory 804, power supply component 806, multimedia component 808, audio component 810, input / output (I / O) interface 812, sensor component 814, and communication component 816.

[0528] Processing component 802 typically controls the overall operation of communication device 800, such as operations associated with display, telephone calls, data communication, camera operation, and recording operations. Processing component 802 may include one or more processors 820 to execute instructions to generate all or part of the steps of the methods described above. Furthermore, processing component 802 may include one or more modules to facilitate interaction between processing component 802 and other components. For example, processing component 802 may include a multimedia module to facilitate interaction between multimedia component 808 and processing component 802.

[0529] Memory 804 is configured to store various types of data to support the operation of communication device 800. Examples of this data include instructions for any application or method operating on communication device 800, contact data, phonebook data, messages, pictures, videos, etc. Memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0530] Power supply component 806 provides power to various components of communication device 800. Power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to communication device 800.

[0531] Multimedia component 808 includes a screen that provides an output interface between the communication device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 808 includes a front-facing camera and / or a rear-facing camera. When the communication device 800 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0532] Audio component 810 is configured to output and / or input audio signals. For example, audio component 810 includes a microphone (MIC) configured to receive external audio signals when communication device 800 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 804 or transmitted via communication component 816. In some embodiments, audio component 810 also includes a speaker for outputting audio signals.

[0533] I / O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.

[0534] Sensor assembly 814 includes one or more sensors for providing status assessments of various aspects of the communication device 800. For example, sensor assembly 814 can detect the on / off state of the device 800, the relative positioning of components such as the display and keypad of the communication device 800, changes in the position of the communication device 800 or a component of the communication device 800, the presence or absence of user contact with the communication device 800, the orientation or acceleration / deceleration of the communication device 800, and temperature changes of the communication device 800. Sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 814 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 814 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.

[0535] Communication component 816 is configured to facilitate wired or wireless communication between communication device 800 and other devices. Communication device 800 can access wireless networks based on communication standards, such as WiFi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, communication component 816 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 816 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0536] In an exemplary embodiment, the communication device 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.

[0537] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, which can be executed by a processor 820 of a communication device 800 to generate the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0538] like Figure 21As shown in the illustration, one embodiment of this disclosure illustrates the structure of a network element. For example, network element 900 can be provided as a network-side device. This network element can be the aforementioned first network element, second network element, or third network element.

[0539] Reference Figure 21 The network element 900 includes a processing component 922, which further includes one or more processors, and memory resources represented by a memory 932 for storing instructions executable by the processing component 922, such as application programs. The application programs stored in the memory 932 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processing component 922 is configured to execute instructions to perform any of the methods described above applied to the access device, such as... Figures 2 to 14 Any of the methods shown.

[0540] Network element 900 may also include a power supply component 1926 configured to perform power management of network element 900, a wired or wireless network interface 950 configured to connect network element 900 to a network, and an input / output (I / O) interface 958. Network element 900 can operate on an operating system stored in memory 932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or similar.

[0541] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.

[0542] It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. An information processing method, wherein, Performed by a Personal Internet of Things (PINE) unit, the method includes: Based on the pre-configured operator public key, send the first request to the Personal IoT Gateway PEGC to apply for operator credentials; Receive the first response returned based on the first request; The operator credentials carried in the first response are obtained based on the operator's public key.

2. The method according to claim 1, wherein, The first request to send an operator credential to the network element based on the pre-configured operator public key includes: The encrypted information is obtained by encrypting a first random number and a first timestamp using the pre-configured operator public key; A first request is sent to the PEGC based on the encrypted information, the public key identifier of the operator's public key, and the identifier of the PINE.

3. The method according to claim 2, wherein, The encrypted information also includes: a second random number encrypted using the operator's public key; The first request to send an operator credential to the network element based on the pre-configured operator public key includes: The second random number is used to protect the integrity of the encrypted information, the public key identifier of the operator's public key, the integrity protection algorithm identifier, and the identifier of the PINE, and a message verification code is generated; based on the encrypted information, the public key identifier of the operator's public key, the identifier of the PINE, and the message verification code, a first request is sent to the PEGC.

4. The method according to claim 2 or 3, wherein, The first response carries a digital signature; The step of obtaining the operator credentials carried in the first response based on the operator's public key includes: Based on the operator's public key and the digital signature, the first response is verified by signature verification; After the first response passes the signature verification, the encrypted credentials carried in the first response are decrypted using the first random number to obtain the operator credentials.

5. The method according to claim 4, wherein, The first response further includes: a second timestamp; the method further includes: Based on the second timestamp, determine whether the first response has been subjected to a replay attack; The step of decrypting the encrypted credentials carried in the first response using the first random number to obtain the operator credentials after the first response passes the signature verification includes: When the first response passes the signature verification and it is determined that the first response has not been subjected to a replay attack, the first random number is used to decrypt the encrypted credential to obtain the PINE's operator credential.

6. The method according to any one of claims 1 to 3, wherein, The method further includes: When the first response contains a credential confirmation indicator and the operator credential is correctly received, a first reception confirmation value indicating that the operator credential has been correctly received is generated using the operator's public key. The first receipt confirmation value is sent to the PEGC.

7. The method according to claim 6, wherein, The step of generating a first reception confirmation value indicating that the operator credential has been correctly received using the operator's public key includes: A first reception confirmation value is generated based on the operator's public key, the operator's credentials, and the PINE identifier.

8. The method according to claim 6, wherein, Sending the first receipt confirmation value to the PEGC includes: The first receipt confirmation value and the credential confirmation indicator are sent to the PEGC.

9. An information processing method, wherein, Performed by a personal IoT gateway PEGC, the method includes: Receive a first request sent by the Personal Internet of Things Unit (PINE) based on a pre-configured operator public key; wherein the first request is used to request operator credentials; Based on the first request, a second request is sent to the first network element; Receive the second response returned by the first network element based on the second request; The second response is used to send the first response to the PINE.

10. The method according to claim 9, wherein, The second request includes the content of the first request, and also includes at least one of the following: The credential configuration indicator directs the user to request operator credentials. The identifier of the PEGC is used to verify whether the PEGC is valid.

11. The method according to claim 9 or 10, wherein, The method further includes: Receive a first reception confirmation value; wherein the first reception confirmation value is generated by the PINE based on the operator's public key, the encryption certificate, and the identifier of the PINE after the PINE has correctly received the operator's certificate; The first receipt confirmation value is sent to the first network element.

12. An information processing method, wherein, The method, executed by the first network element, includes: Receive a second request sent by the Personal IoT Gateway PEGC, wherein the second request is sent based on the first request; the first request is a request sent by the Personal IoT Unit PINE based on a pre-configured operator public key and used to request operator credentials; Based on the second request, a third request is sent to the second network element; Receive a third response based on the third request; Based on the third response, a second response is sent to the PEGC.

13. The method according to claim 12, wherein, The method further includes: Receive the first reception confirmation value sent by the PEGC; the first reception confirmation value is generated by the PINE based on the operator's public key, the encryption certificate and the PINE's identifier after the PINE has correctly received the operator's certificate; The first receipt confirmation value is sent to the second network element.

14. An information processing method, wherein, The method, executed by the second network element, includes: Receive a third request; the third request is a request sent by the Personal Internet of Things Unit (PINE) to the Personal Internet of Things Gateway (PEGC) based on a pre-configured operator public key and used to request operator credentials. Based on the result of processing the third request using the operator's private key, determine whether to configure operator credentials for PINE. When it is determined that operator credentials will be configured for the PINE, a fourth request is sent to the third network element. Receive the operator credentials returned by the fourth request; The operator credential is processed securely using the operator's private key to obtain a securely processed operator credential. The securely processed operator credentials are sent to the first network element in the third response.

15. The method according to claim 14, wherein, The process of determining whether to configure operator credentials for PINE based on the result of processing a third request using the operator's private key includes: The operator's private key is determined based on the public key identifier of the operator's public key carried in the third request; The operator's private key is used to decrypt the encrypted information carried in the third request to obtain a first random number and a first timestamp; Based on the first random number and the first timestamp, determine whether the encrypted information has been subjected to a replay attack; When the encrypted information is not subjected to a replay attack, it is determined that the PINE will be configured with operator credentials.

16. The method according to claim 15, wherein, The encrypted information further includes: a second random number; the third request further includes a message verification code; the method further includes: The message containing the encrypted information, the public key identifier, the integrity protection algorithm identifier, and the PINE identifier is verified based on the message verification code and the second random number. When the encrypted information is not subjected to a replay attack, determining to configure operator credentials for the PINE includes: When the encrypted information is not subjected to a replay attack and the integrity protection verification is passed, it is determined to configure operator credentials for the PINE.

17. The method according to any one of claims 14 to 16, wherein, The step of using the operator's private key to perform secure processing on the operator's credentials to obtain the securely processed operator's credentials includes: The operator's certificate is encrypted using the first random number contained in the encrypted information to obtain the encrypted certificate; The digital signature is obtained by signing the encrypted credential and the second timestamp generated by the encrypted credential using the operator's private key.

18. The method according to claim 17, wherein, The step of encrypting the operator credential based on the first random number contained in the encrypted information to obtain the encrypted credential includes: The first random number is XORed with the operator's certificate to obtain the encrypted certificate.

19. The method of claim 16, wherein, The method further includes: When the encrypted information is subjected to a replay attack, the operator credential configuration of the PINE is stopped; And / or, If the integrity protection verification fails, stop the operator credential configuration of the PINE.

20. The method according to any one of claims 14 to 16, wherein, The method further includes: The securely processed operator credentials are sent to the third network element; The step of sending the securely processed operator credentials to the first network element via the third response includes: Receive the configuration result provided by the third network element based on the operator credentials after the security processing; Send a third response containing the configuration result to the first network element.

21. The method according to any one of claims 14 to 16, wherein, The step of sending the securely processed operator credentials to the first network element via the third response includes: After generating the securely processed operator credential, a third response containing the securely processed operator credential is sent to the first network element.

22. The method according to claim 21, wherein, The method further includes: Generate a second confirmation value; Receive the first reception confirmation value sent by the first network element; When the second reception confirmation value is the same as the first reception confirmation value, it is determined that the PINE has correctly received the operator certificate; Send a notification to the third network element that the operator's certificate has been correctly received.

23. The method according to claim 21, wherein, The method further includes: A second reception confirmation value is generated, and the second reception value is provided to the third network element along with the securely processed operator credential. Receive the first reception confirmation value sent by the first network element; The first reception confirmation value is sent to the third network element, wherein the first reception confirmation value is used by the third network element and the second reception confirmation value to determine whether the PINE has correctly received the operator certificate.

24. The method according to claim 22 or 23, wherein, The generation of the second reception confirmation value includes: The second receipt confirmation value is generated based on the operator's public key, the operator's credentials, and the identifier of the PINE.

25. An information processing method, wherein, The method is executed by a third network element and further includes: Receive the fourth request from the second network element; the fourth request is a request sent by the Personal Internet of Things Unit (PINE) to the Personal Internet of Things Gateway (PEGC) based on a pre-configured operator public key and used to apply for operator credentials. Configure the operator credentials for the PINE according to the fourth request, wherein the PINE is a device that has not been configured with default credentials but has been pre-configured with the operator's public key; The operator credentials are carried in the fourth response and sent to the second network element. The operator credentials are used to securely process the operator private key corresponding to the operator public key before being issued to the PINE.

26. The method according to claim 25, wherein, The method further includes: Receive the operator's credentials after security processing returned by the second network element; Generate a configuration result including the operator credentials after the security processing; The configuration result is sent to the second network element.

27. The method according to claim 25 or 26, wherein, The method further includes: Receive the second reception confirmation value generated by the second network element; Receive the first reception confirmation value generated by the PINE; When the first reception confirmation value and the second reception confirmation value are the same, it is determined that the PINE has correctly received the operator certificate.

28. The method according to claim 25 or 26, wherein, The method further includes: Receive the operator credentials reception notification sent by the second network element.

29. The method according to claim 25 or 26, wherein, The method further includes: Before configuring the operator credentials for the PINE, verify that the PEGC of the PINE connection is valid; The step of configuring carrier credentials for PINE according to the fourth request includes: When the PEGC is valid, configure the operator credentials for PINE according to the fourth request.

30. An information processing apparatus, wherein, The device is applied to a Personal Internet of Things (PINE) unit and includes: The first sending module is configured to send a first request for operator credentials to the Personal IoT Gateway PEGC based on a pre-configured operator public key. The first receiving module is configured to receive a first response based on the first request; The first acquisition module is configured to acquire the operator credentials carried in the first response based on the operator's public key.

31. The apparatus according to claim 30, wherein, The first sending module is configured to encrypt a first random number and a first timestamp using a pre-configured operator public key to obtain encrypted information; and to send a first request to the PEGC based on the encrypted information, the public key identifier of the operator public key, and the identifier of the PINE.

32. The apparatus according to claim 31, wherein, The first acquisition module is further configured to use a second random number to perform integrity protection on the encrypted information, the public key identifier of the operator's public key, the integrity protection algorithm identifier, and the identifier of the PINE, and generate a message verification code; and send a first request to the PEGC based on the encrypted information, the public key identifier of the operator's public key, the identifier of the PINE, and the message verification code.

33. The apparatus according to claim 31 or 32, wherein, The first response carries a digital signature; The first acquisition module is configured to perform signature verification on the first response based on the operator's public key; after the first response passes the signature verification, the first random number is used to decrypt the encrypted credential carried by the first response to obtain the operator credential, wherein the first response carrying the encrypted credential is returned after the encrypted information is successfully decrypted and the encrypted information is verified to be free from replay attacks based on the first random number and the first timestamp.

34. The apparatus according to claim 33, wherein, The first response further includes: a second timestamp; the device further includes: The first determining module is configured to determine whether the first response has been subjected to a replay attack based on the second timestamp. The first acquisition module is configured to use the first random number to decrypt the encryption credential and obtain the PINE operator credential when the first response passes the signature verification and it is determined that the first response has not been subjected to a replay attack.

35. The apparatus according to any one of claims 30 to 32, wherein, The device further includes: The first generation module is configured to generate a first reception confirmation value indicating that the operator credential has been correctly received using the operator public key when the first response contains a credential confirmation indicator and the operator credential has been correctly received. The first sending module is configured to send the first reception confirmation value to the PEGC.

36. The apparatus according to claim 35, wherein, The first generation module is configured to generate a first reception confirmation value based on the operator's public key, the operator's credentials, and the PINE identifier.

37. The apparatus according to claim 36, wherein, The first sending module is configured to send the first reception confirmation value and the credential confirmation indicator to the PEGC.

38. An information processing apparatus, wherein, The device is applied to a Personal Internet of Things (PEGC) gateway and includes: The second receiving module is configured to receive a first request sent by the Personal Internet of Things Unit (PINE) based on a pre-configured operator public key; wherein the first request is used to request operator credentials. The second sending module is configured to send a second request to the first network element based on the first request; The second sending module is also configured to receive a second response returned by the first network element based on the second request; The second sending module is also configured to send the second response to the PINE as a first response.

39. The apparatus according to claim 38, wherein, The second request includes the content of the first request, and also includes at least one of the following: The credential configuration indicator directs the user to request operator credentials. The identifier of the PEGC is used to verify whether the PEGC is valid.

40. The apparatus according to claim 38 or 39, wherein, The second receiving module is further configured to receive a first receiving confirmation value; wherein the first receiving confirmation value is generated by the PINE based on the operator's public key, the encryption certificate, and the identifier of the PINE after the PINE has correctly received the operator's certificate; The second receiving module is also configured to send the first receiving confirmation value to the first network element.

41. An information processing apparatus, wherein, The device includes: The third receiving module is configured to receive a second request sent by the Personal IoT Gateway (PEGC), wherein the second request is sent based on the first request; the first request is a request sent by the Personal IoT Unit (PINE) based on a pre-configured operator public key and used to request operator credentials. The third sending module is configured to send a third request to the second network element based on the second request; The third receiving module is configured to receive a third response based on a third request; The third sending module is configured to send a second response to the PEGC based on the third response.

42. The apparatus according to claim 41, wherein, The third receiving module is configured to receive a first receiving confirmation value sent by the PEGC; the first receiving confirmation value is generated by the PINE based on the operator's public key, the encryption certificate, and the PINE's identifier after the PINE has correctly received the operator's certificate. The third sending module is configured to send the first reception confirmation value to the second network element.

43. An information processing apparatus, wherein, The device includes: a fourth receiving module, a fourth transmitting module, a second determining module, and a second acquiring module; The fourth receiving module is configured to receive a third request; the third request is a request sent by the Personal Internet of Things Unit (PINE) to the Personal Internet of Things Gateway (PEGC) based on a pre-configured operator public key and used to apply for operator credentials. The second determining module is configured to determine whether to configure operator credentials for PINE based on the result of processing the third request using the operator's private key. The fourth sending module is configured to send a fourth request to the third network element when it is determined that operator credentials will be configured for the PINE. The fourth receiving module is also configured to receive the operator credentials returned by the fourth request; The second acquisition module is configured to use the operator's private key to perform security processing on the operator's credentials to obtain the security-processed operator's credentials; The fourth sending module is also configured to send the securely processed operator credentials in the third response to the first network element.

44. The apparatus according to claim 43, wherein, The second determining module is configured to determine the operator's private key based on the public key identifier of the operator's public key carried in the third request; Use the operator's private key to decrypt the encrypted information carried in the third request; Based on the first random number and first timestamp carried by the encrypted information, determine whether the encrypted information has been subjected to a replay attack; When the encrypted information is not subjected to a replay attack, it is determined that the PINE will be configured with operator credentials.

45. The apparatus according to claim 44, wherein, The encrypted information further includes: a second random number; the third request further includes a message verification code; the device further includes: The verification module is configured to perform integrity protection verification on the encrypted information, the public key identifier, the integrity protection algorithm identifier, and the PINE identifier of the message based on the message verification code and the second random number; The second determining module is configured to determine to configure operator credentials for the PINE when the encrypted information has not been subjected to a replay attack and the integrity protection verification is passed.

46. ​​The apparatus according to any one of claims 43 to 45, wherein, The second acquisition module is configured to encrypt the operator credential based on a first random number contained in the encrypted information to obtain an encrypted credential; and to sign the encrypted credential and a second timestamp generated by the encrypted credential using the operator's private key to obtain a digital signature.

47. The apparatus according to claim 46, wherein, The second acquisition module is configured to perform a bitwise XOR operation between the first random number and the operator credential to obtain the encrypted credential.

48. The apparatus according to claim 44, wherein, The device further includes: The stop module is configured to stop the operator credential configuration of the PINE when the encrypted information is subjected to a replay attack; and / or to stop the operator credential configuration of the PINE when the integrity protection verification fails.

49. The apparatus according to any one of claims 43 to 45, wherein, The fourth sending module is configured to send the securely processed operator credentials to the third network element; The fourth receiving module is also configured to receive the configuration result provided by the third network element based on the operator credential after the security processing; The fourth sending module is also configured to send a third response containing the configuration result to the first network element.

50. The apparatus according to any one of claims 43 to 45, wherein, The fourth sending module is configured to send a third response containing the securely processed operator credential to the first network element after generating the securely processed operator credential.

51. The apparatus according to any one of claims 43 to 45, wherein, The device further includes: The second generation module is configured to generate a second receipt confirmation value; The fourth receiving module is configured to receive the first receiving confirmation value sent by the first network element; The device further includes: The third confirmation module is configured to determine that the PINE has correctly received the operator certificate when the second reception confirmation value is the same as the first reception confirmation value. The fourth sending module is configured to send a notification to the third network element that the operator certificate has been correctly received.

52. The apparatus according to any one of claims 43 to 45, wherein, The device further includes: The second generation module is configured to generate a second receipt confirmation value; The fourth sending module is further configured to provide the second received value along with the securely processed operator credential to the third network element; The fourth receiving module is configured to receive the first receiving confirmation value sent by the first network element; The fourth sending module is configured to send the first reception confirmation value to the third network element, wherein the first reception confirmation value is used by the third network element and the second reception confirmation value to determine whether the PINE has correctly received the operator certificate.

53. The apparatus according to claim 52, wherein, The second generation module is configured to generate the second receipt confirmation value based on the operator's public key, the operator's credentials, and the identifier of the PINE.

54. An information processing apparatus, wherein, The device includes: The fifth receiving module is configured to receive the fourth request from the second network element; the fourth request is a request sent by the Personal Internet of Things Unit (PINE) to the Personal Internet of Things Gateway (PEGC) based on a pre-configured operator public key and used to apply for operator credentials. The configuration module is configured to configure operator credentials for the PINE according to the fourth request, wherein the PINE is a device that has not been configured with default credentials but has been pre-configured with an operator public key; The fifth sending module is configured to send the operator credential along with the fourth response to the second network element, wherein the operator credential is used to securely process the operator private key corresponding to the operator public key before issuing it to the PINE.

55. The apparatus according to claim 54, wherein, The fifth receiving module is configured to receive the operator's credentials after security processing returned by the second network element; The device further includes: The third generation module is configured to generate a configuration result including the operator credentials after the security processing. The fifth sending module is configured to send the configuration result to the second network element.

56. The apparatus according to claim 54 or 55, wherein, The fifth receiving module is configured to receive the second receiving confirmation value generated by the second network element; The fifth receiving module is configured to receive the first receiving confirmation value generated by the PINE; The device further includes: The fourth determining module is configured to determine that the PINE has correctly received the operator's credentials when the first receiving confirmation value and the second receiving confirmation value are the same.

57. The apparatus according to claim 54 or 55, wherein, The fifth receiving module is configured to receive the operator credential correct reception notification sent by the second network element.

58. The apparatus according to claim 54 or 55, wherein, The device further includes: The verification module is configured to verify the validity of the PEGC of the PINE connection before configuring the operator credentials for the PINE. The configuration module is also configured to configure operator credentials for PINE according to the fourth request when the PEGC is valid.

59. A communication device comprising a processor, a transceiver, a memory, and an executable program stored in the memory and executable by the processor, wherein, When the processor runs the executable program, it performs the method provided as claimed in any one of claims 1 to 8, 9 to 11, 12 to 13, 14 to 24, or 25 to 29.

60. A computer storage medium storing an executable program; the executable program, when executed by a processor, is capable of implementing the method provided in any one of claims 1 to 8, 9 to 11, 12 to 13, 14 to 24, or 25 to 29.

Citation Information

Patent Citations

  • System, apparatus and method for managing lifecycle of secure publish-subscribe system

    CN107637038A

  • 5G communication information encryption and decryption method and device and storage medium

    CN111065092A