Method for generating application layer key and communication system based on application layer key
Patent Information
- Application Number
- CN202210861319.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-20
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2042-07-20
AI Technical Summary
[0003]例如采用第四代移动通信技术/第五代移动通信技术(4G/5G)融合组网方式,应用客户端不仅需判断当前应用对应终端的驻网类型,还需对接不同驻网类型终端的服务认证功能接口,如GBA(General Bootstrapping Architecture,通用认证机制)和AKMA(Authentication and Key Management for Applications,应用的认证与密钥管理),另外应用服务器也需要分别对接4G网络和5G网络内的相关功能网元,从而提高了应用对接和使用门槛,不利于运营商网络的应用层密钥能力开放
[0040]根据本公开的一个方面,提供一种电子设备,包括:处理器;以及存储器,用于存储所述处理器的可执行指令;其中,所述处理器配置为经由执行所述可执行指令来执行上述任意一项所述的方法。
Smart Images

Figure CN117479155B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communication technology, and more specifically, to a method for generating application layer keys, a communication system based on application layer keys, a computer-readable storage medium, and an electronic device. Background Technology
[0002] Secure channel keys can ensure secure communication between applications and application servers. Currently, mobile network operators use a converged approach. When mobile network operators open their application layer key generation capabilities to applications, the specific implementation methods differ due to the different network access types of the terminals corresponding to the applications.
[0003] For example, when using a converged network of fourth-generation mobile communication technology / fifth-generation mobile communication technology (4G / 5G), the application client not only needs to determine the network type of the terminal corresponding to the current application, but also needs to connect to the service authentication function interfaces of terminals with different network types, such as GBA (General Bootstrapping Architecture) and AKMA (Authentication and Key Management for Applications). In addition, the application server also needs to connect to the relevant functional network elements in the 4G network and the 5G network respectively, thereby increasing the threshold for application connection and use, and hindering the opening of application layer key capabilities of the operator network.
[0004] It should be noted that the information in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention
[0005] The purpose of this disclosure is to provide a method for generating application layer keys, as well as a communication system, computer-readable storage medium, and electronic device based on application layer keys, thereby reducing the application integration threshold under converged networking and improving the convenience of opening up application layer key capabilities in operator mobile networks.
[0006] Other features and advantages of this disclosure will become apparent from the following detailed description, or may be learned in part from practice of this disclosure.
[0007] According to one aspect of this disclosure, a method for generating an application layer key is provided, comprising:
[0008] The terminal-side application layer key service module sends an application layer key session establishment request to the network-side application layer key service network element. The application layer key session establishment request carries the network identification information of the terminal corresponding to the terminal application. The network identification information is used to instruct the application layer key service network element and the target network element corresponding to the target network type to execute the application layer key generation process.
[0009] If the request response information of the application layer key service network element is received, the service authentication module corresponding to the target network type executes the key generation process to determine the application layer key of the target network type.
[0010] In one exemplary embodiment of this disclosure, before the terminal-side application layer key service module sends an application layer key session establishment request to the application layer key service network element, the method further includes:
[0011] The terminal-side application layer key service module receives the application layer key request from the terminal-side application. The application layer key request carries application identification information and the domain name information of the application layer key service network element.
[0012] The application identification information is used to instruct the terminal-side application layer key service module to determine the target network type of the terminal corresponding to the terminal-side application.
[0013] In one exemplary embodiment of this disclosure, the target network type includes at least a first network and a second network, wherein the first network and the second network differ in at least the following ways:
[0014] This is different from the target network element that performs the application layer key generation process in the application layer key service network element;
[0015] This is different from the service authentication module that executes the application layer key generation process in the terminal-side application layer key service module.
[0016] In an exemplary embodiment of this disclosure, if the target network type is a first network, before the terminal-side application layer key service module sends an application layer key session establishment request to the application layer key service network element, the method further includes:
[0017] The terminal-side application layer key service module obtains the first key identifier from the first service authentication module. The first key identifier is generated when the terminal corresponding to the terminal-side application completes the registration master authentication in the first network.
[0018] The application layer key session establishment request also carries the first key identifier and the application identifier information of the terminal-side application.
[0019] In one exemplary embodiment of this disclosure, the step of receiving the request response information from the application layer key service network element and executing a key generation process corresponding to the target network type to determine the application layer key for the target network type includes:
[0020] Send a first key request to the first service authentication module. The first key request carries the first key identifier and the application identifier information.
[0021] The application layer key sent by the first service authentication module is received. The application layer key is obtained by the first service authentication module through a key generation process based on the first key identifier and the application identifier information.
[0022] In an exemplary embodiment of this disclosure, if the target network type is a second network, the step of receiving the request response information from the application layer key service network element and executing a key generation process corresponding to the target network type to determine the application layer key for the target network type includes:
[0023] An authentication request is sent to the second service authentication module to perform authentication and generate the application layer key and the second key identifier. The authentication request carries application identifier information.
[0024] Receive authentication response information sent by the second service authentication module, wherein the authentication response information includes the application layer key and the second key identifier;
[0025] The second key identifier is used to return to the application layer key service network element to instruct the application layer key service network element and the target network element corresponding to the second network to perform a key generation process to obtain the application layer key.
[0026] In one exemplary embodiment of this disclosure, the first network is a 5G network and the second network is a 4G network.
[0027] The first service authentication module of the first network is the AKMA service for identity authentication and key management, and the second service authentication module of the second network is the GBA service for general authentication mechanism.
[0028] According to one aspect of this disclosure, a method for generating an application layer key is provided, comprising:
[0029] The application layer key service network element receives an application layer key session establishment request sent by the terminal-side application layer key service module. The application layer key session establishment request carries the network registration identification information of the terminal corresponding to the terminal-side application. The application layer key service network element performs a key generation process based on the network registration identification information and the target network element corresponding to the target network type to determine the application layer key corresponding to the target network type.
[0030] Send a request response message to the terminal-side application layer key service module to instruct the terminal-side application layer key service module and the service authentication module corresponding to the target network type to execute the key generation process.
[0031] In one exemplary embodiment of this disclosure, the application layer key service network element performs a key generation process based on the network registration identification information and the target network element corresponding to the target network registration type to determine the application layer key corresponding to the target network registration type, including:
[0032] The application layer key service network element sends an application layer key request to the target network element, and the application layer key request carries a key identifier.
[0033] The key identifier is obtained from the terminal-side application layer key service module, and the key identifier is obtained by the terminal-side application layer key service module from the service authentication module;
[0034] Receive the application layer key generated based on the key identifier sent by the target network element.
[0035] According to one aspect of this disclosure, a communication system based on application-layer keys is provided, the communication system comprising at least:
[0036] The terminal-side application layer key service module is used to execute the method for generating application layer keys as described above, generate application layer keys and send them to the terminal-side application.
[0037] An application layer key service network element is used to execute the method for generating an application layer key as described above, determine the application layer key and send it to the network-side server;
[0038] The terminal-side application and the network-side server establish a communication connection based on the application layer key.
[0039] According to one aspect of this disclosure, a computer storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method described in any of the preceding claims.
[0040] According to one aspect of this disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the method described in any of the preceding methods by executing the executable instructions.
[0041] The method for generating application layer keys in the exemplary embodiments of this disclosure adds a terminal-side application layer key service module on the terminal side and an application layer key service network element on the network side. On the terminal side, according to the target network type of the terminal corresponding to the application, a key generation process is executed with the service authentication module corresponding to the target network type to determine the application layer key for the target network type. This avoids application clients having to connect to different service authentication modules separately, thus lowering the application integration threshold. Correspondingly, on the network side, according to the target network type of the terminal corresponding to the application, the application layer key service network element is instructed to execute the application layer key generation process with the target network element corresponding to the target network type. Based on the application layer key service network element on the network side, this also avoids having to connect to target network elements of different network types separately, thus lowering the application integration and usage threshold. Adding an application layer key service module on the terminal side and an application layer key service network element on the network side, for converged network deployment scenarios, the specific implementation method of providing application layer secure channel keys between application clients and servers based on the operator's mobile network through adaptive mobile network varies for different network deployment types. By providing a unified application layer key capability interface to applications on both the terminal and network sides, it is beneficial for applications and application servers to improve the convenience of opening up the operator's mobile network application layer key capabilities, which is of practical significance for attracting more third-party application partners and improving the operator's incremental benefits.
[0042] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0043] The above and other objects, features, and advantages of this disclosure will become readily apparent from the following detailed description of exemplary embodiments, taken in conjunction with the accompanying drawings. Several embodiments of this disclosure are illustrated in the drawings by way of example and not limitation, in which:
[0044] Figure 1 The architecture diagram of the General Authentication Mechanism (GBA) is shown;
[0045] Figure 2 The architecture diagram of AKMA's authentication and key management system is shown.
[0046] Figure 3 An architecture diagram of an application-layer key-based communication system according to an exemplary embodiment of the present disclosure is shown.
[0047] Figure 4A flowchart illustrating a method for generating an application layer key according to an exemplary embodiment of the present disclosure is shown;
[0048] Figure 5 A flowchart illustrating a method for generating an application layer key in an application scenario according to an exemplary embodiment of the present disclosure is shown.
[0049] Figure 6 A flowchart illustrating a method for generating application layer keys in another application scenario according to an exemplary embodiment of this disclosure is shown.
[0050] Figure 7 A flowchart illustrating another method for generating an application layer key according to an exemplary embodiment of this disclosure is shown;
[0051] Figure 8 A schematic diagram of the architecture of an apparatus for generating application layer keys according to an exemplary embodiment of the present disclosure is shown;
[0052] Figure 9 A schematic diagram of the architecture of another apparatus for generating application layer keys according to an exemplary embodiment of the present disclosure is shown;
[0053] Figure 10 A block diagram of an electronic device according to an exemplary embodiment of the present disclosure is shown.
[0054] In the accompanying drawings, the same or corresponding reference numerals indicate the same or corresponding parts. Detailed Implementation
[0055] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of exemplary embodiments to those skilled in the art. The same reference numerals in the drawings denote the same or similar structures, and therefore their detailed description will be omitted.
[0056] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a thorough understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced without one or more of the specific details described, or other methods, components, apparatuses, steps, etc., can be employed. In other instances, well-known structures, methods, apparatuses, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this disclosure.
[0057] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, or in one or more software-hardened modules, or in different network and / or processor devices and / or microcontroller devices.
[0058] In related technologies in this field, application-layer secure channel keys are provided between application clients and servers based on the operator's mobile network, enabling the establishment of a secure channel between the application and the application server for authentication and secure communication. For example, this can be applied to mobile TV establishing Multimedia Broadcast Multicast Services (MBMS) based on broadcast multicast sessions, secure location services based on Secure User Plane Location (SUPL), IoT application access, and mobile terminal application access, etc.
[0059] Currently, mobile networks operated by carriers all adopt a converged networking approach. For different terminal network access types, relevant technologies provide methods for providing application-layer secure channel keys between application clients and servers based on the carrier's mobile network. For example... Figure 1 The diagram illustrates the architecture of the General Authentication Mechanism (GBA). GBA is a lightweight security infrastructure defined by 3GPP (3rd Generation Partnership Project) based on 3G / 4G mobile communication networks. It provides unified security authentication services for application layer services. It utilizes the AKA (Authentication and Key Agreement) authentication mechanism to establish a secure channel key between the application and the application server, and then uses this secure channel key to establish a secure channel between the application and the application server for identity authentication and secure communication.
[0060] like Figure 1 As shown, the GBA architecture can include at least an HSS (Home Subscriber Server), a BSF (Binding Support Function) network element, a terminal, a USIM card (Universal Subscriber Identity Module), and an application server NAF.
[0061] In this architecture, the BSF serves as the anchor point, obtaining the authentication vector from the HSS to verify the user terminal and generating a shared key together with the HSS using the AKA mechanism. The NAF guides the application through GBA authentication and obtains the shared key from the BSF, generating a secure communication session key between the application and the NAF. The HSS generates the AKA authentication vector and authenticates the terminal and USIM. The terminal is used to install the application client, and the USIM is used to generate the shared key and the application's external key.
[0062] Figure 2 The diagram illustrates the architecture of AKMA (Authentication, Authentication, and Key Management), a lightweight security infrastructure defined by 3GPP for 5G networks. AKMA provides authentication and secure channel key services to the application layer. AKMA does not require additional UE authentication; it only needs to reuse the primary authentication method to authenticate the UE (such as 5G primary authentication). For example, the 5G primary authentication process can be performed during UE registration. Secure channel keys ensure secure communication between the application and the application server.
[0063] like Figure 2 As shown, the AKMA architecture includes at least AF (Application Function), AAnF (AKMA Anchor Function), AUSF (Authentication Server Function), mobile terminal UE, and USIM card. Among these, AF is a third-party application service function, and AAnF is an anchor function deployed in the home network, storing the AKMA anchor key (K) for the AKMA service. AKMA After the UE successfully completes 5G master authentication, the AUSF will send the key to it; AUSF is the authentication server function of the 5G system.
[0064] The basic idea of 5G AKMA consists of two steps: The first step is to perform AKMA anchor key derivation and anchoring after 5G master authentication. After the UE successfully completes 5G master authentication, key K is generated internally by the UE and AUSF. AUSF Then, the UE and AUSF generate the AKMA anchor key K based on the same parameters and algorithm. AKMA The AKMA key identifier A-KID is then used; subsequently, the AUSF registers the anchor key belonging to the UE with the anchor function AAnF.
[0065] The specific calculation method can be: K AKMA =KDF(K AUSFKDF (Key Derivation Function) is an abbreviation for Key Derivation Function, and SUPI (Subscription Permanent Identifier) is the UE's identity identifier.
[0066] The second step is to use the application key K when the application needs to establish a session. AF The derivation and acquisition of the key K. AF Based on K by AAnF AKMA It was derived and sent to AF.
[0067] It is worth noting that the above provides a method for providing application-layer secure channel keys between application clients and servers based on the operator's mobile network. However, the specific implementation methods differ in actual implementation, such as architecture, network environment, scenario, process, and interface. Specifically, the GBA architecture supports two application key generation methods: in-card and out-of-card, while 5G AKMA supports only one application key generation method: out-of-card.
[0068] Currently, mobile networks operated by operators all adopt converged networking methods, such as 4G / 5G converged networking. When operators open their application layer key generation capabilities to applications, application clients not only need to determine the network environment of the current user's terminal, but also need to connect to the terminal's GBA and AKMA function interfaces. Application servers also need to connect to 4G and 5G related function network elements respectively, which increases the threshold for application integration and use, and is not conducive to the opening up of operators' network capabilities.
[0069] Based on this, in the exemplary embodiments of this disclosure, a method for generating application layer keys is first provided. (See reference...) Figure 3 This is an architecture diagram of a communication system based on application layer keys, which is an exemplary embodiment of this disclosure.
[0070] like Figure 3 As shown, a terminal-side application layer key service module 110 is added on the terminal side, and an application layer key service network element 130 is added on the network side. The terminal-side application layer key service module 110 interacts with the terminal-side application 120 to determine the target network type of the terminal, and interacts with the terminal-side service authentication module and the network-side application layer key service network element 130 to provide the application layer key to the terminal-side application 120. Correspondingly, the application layer key service network element 130 interacts with the terminal-side application layer key service module 110 and coordinates with the functional network elements within the network corresponding to the target network type to realize the function of distributing the application layer key to the application.
[0071] The network type of the terminal includes, but is not limited to, 4G, 5G, and 6G networks, and this disclosure does not impose any special restrictions on this. The service authentication module on the terminal side may include a GBA module and an AKMA module, and the functional network elements within the network corresponding to the target network type may include at least BSF, HSS, AAuF, and AUSF.
[0072] It is worth noting that some technical solutions in the embodiments of this disclosure can be based on, for example... Figure 3 The system architecture or its variants are shown in the diagram for specific implementation.
[0073] like Figure 4 A flowchart illustrating a method for generating an application layer key according to an embodiment of this disclosure is shown, applied to a terminal-side application layer key service module on the terminal side. For example... Figure 4 As shown, the method for generating an application layer key according to this embodiment of the disclosure may include steps S410 and S420:
[0074] Step S410: The terminal-side application layer key service module sends an application layer key session establishment request to the network-side application layer key service network element. The application layer key session establishment request carries the network identification information of the terminal corresponding to the terminal application. The network identification information is used to instruct the application layer key service network element and the target network element corresponding to the target network type to execute the application layer key generation process.
[0075] Step S420: If a request response information from an application layer key service network element is received, the service authentication module corresponding to the target network type executes a key generation process to determine the application layer key for the target network type.
[0076] According to the method for generating application layer keys according to embodiments of this disclosure, a terminal-side application layer key service module is added to the terminal side, and an application layer key service network element is added to the network side. On the terminal side, based on the target network type of the terminal corresponding to the application, a key generation process is executed with the service authentication module corresponding to the target network type to determine the application layer key for that target network type. This avoids application clients having to connect to different service authentication modules separately, lowering the application integration threshold. Correspondingly, on the network side, based on the target network type of the terminal corresponding to the application, the application layer key service network element is instructed to execute the application layer key generation process with the target network element corresponding to the target network type. Based on the application layer key service network element on the network side, this also avoids having to connect to target network elements of different network types separately, thus lowering the application integration and usage threshold. Adding an application layer key service module on the terminal side and an application layer key service network element on the network side, for converged network deployment scenarios, the specific implementation method of providing application layer secure channel keys between application clients and servers based on the operator's mobile network varies for different network deployment types. By providing a unified application layer key capability interface to applications on both the terminal and network sides, it is of practical significance to improve the convenience of opening up the operator's mobile network application layer key capabilities between applications and application servers, attract more third-party application partners for operators, and improve the incremental benefits for operators.
[0077] The following is combined Figure 4 The method for generating application layer keys according to embodiments of this disclosure will be described in detail.
[0078] In step S410, the terminal-side application layer key service module sends an application layer key session establishment request to the network-side application layer key service network element. The application layer key session establishment request carries the network identification information of the terminal corresponding to the terminal application. The network identification information is used to instruct the application layer key service network element and the target network element corresponding to the target network type to execute the application layer key generation process.
[0079] In the exemplary embodiments of this disclosure, the terminal-side application layer key service module can be called by the terminal-side application, such as the terminal-side application layer key SDK (Software Development Kit), which can be deployed on the operating system of the terminal corresponding to the terminal-side application. This disclosure does not impose any special limitations on this.
[0080] The network access identification information reflects the target network type of the terminal application. The target network type includes at least a first network and a second network, such as a 4G network, a 5G network, and may also include a 6G network. Different target network types for terminal applications require at least the following differences between them:
[0081] 1) It is different from the target network element that performs the application layer key generation process from the application layer key service network element.
[0082] Taking 4G and 5G networks as examples, the target network element performing the application layer key generation process with the application layer key service network element in a 4G network may include the BSF (Browser Serving Element), while the target network element performing the application layer key generation process with the application layer key service network element in a 5G network may include ANSF (AnF), AUSF (Australian Serving Element), etc. It is worth noting that the target network elements included in different networks may not be completely identical; for example, 4G and 5G networks may also include the same target network element, HSS (Hardware Service Element).
[0083] 2) It is different from the service authentication module that executes the application layer key generation process in the terminal-side application layer key service module.
[0084] Taking 4G and 5G networks as examples, in 4G networks, the service authentication module that performs the application layer key generation process with the terminal-side application layer key service module can be a GBA module, while in 5G networks, the service authentication module that performs the application layer key generation process with the terminal-side application layer key service module can be an AKMA module.
[0085] Although a terminal-side application layer key service module is added on the terminal side and an application layer key service network element is added on the network side, the processing flow of the existing architecture can continue to be used for modules or network elements that have repeated steps with the GBA and AKMA architectures.
[0086] In one exemplary embodiment, before the terminal-side application layer key service module sends an application layer key session establishment request to the application layer key service network element, it first receives the application layer key request from the terminal-side application, wherein the application layer key request carries application identification information and the domain name information of the application layer key service network element.
[0087] Application identification information can instruct the terminal-side application layer key service module to determine the target network type of the terminal corresponding to the application. In other words, when the terminal-side application layer key service module receives an application layer key request from the terminal-side application, it can determine the current network type (target network type) of the terminal corresponding to the application. For example, the terminal corresponding to the application can be determined based on the application identification information, and then the current network type of the corresponding terminal can be determined, such as 4G, 5G, or 6G network, etc., thereby adaptively selecting different processing procedures for generating application layer keys based on the current network type.
[0088] The network identification information is also used to instruct the application layer key service network element to interact with the target network element corresponding to the target network type, execute the application layer key generation process, and generate the application layer key. For example, when the network identification information is the identification information of a 4G network, the application layer key service network element can interact with the BSF to obtain the application layer key from the BSF, where the application layer key is generated by the BSF. As another example, when the network identification information is the identification information of a 5G network, the application layer key service network element can initiate an application layer key request to the AAnF of the 5GC (5G Core Network) based on the 5G network identification information, so that the AAnF can deduce the application layer key and return it to the application layer key service network element. Of course, if the current network identification is the identification information of another network, such as the identification information of a 6G network, the functional network element that interacts with the application layer key service network element can be determined according to the specific situation of the 6G network.
[0089] In step S420, if a request response information from an application layer key service network element is received, the service authentication module corresponding to the target network type executes a key generation process to determine the application layer key for the target network type.
[0090] In an exemplary embodiment of this disclosure, if the terminal-side application layer key service module receives the request response information from the application layer key service network element, the terminal-side application layer key service module can perform a key generation process with the service authentication module corresponding to the target network type to determine the application layer key for the target network type.
[0091] In actual implementation, if the target network type is a 4G network, the terminal-side application layer key service module can perform an application layer key generation process with the GBA module to obtain the application layer key; if the target network type is a 5G network, the terminal-side application layer key service module can perform an application layer key generation process with the AKMA module to obtain the application layer key.
[0092] It should be noted that the process of application layer key generation performed by the GBA module or AKMA module in this embodiment can be combined with... Figure 1 or Figure 2 The corresponding service key generation process is the same.
[0093] According to an exemplary embodiment of this disclosure, if the target network type of the terminal application is a first network, the terminal application layer key service module can obtain a first key identifier from the first service authentication module before sending an application layer key session establishment request to the application layer key service network element. The first key identifier is generated when the terminal corresponding to the terminal application completes the registration master authentication in the first network.
[0094] The first network can be a 5G network, and the corresponding first service authentication module is the AKMA module. The AKMA module does not require additional UE authentication; it only needs to reuse the 5G master authentication to authenticate the UE. The first key identifier is generated by the terminal application when the terminal completes the master authentication on the first network. For example, the 5G master authentication process is performed during UE registration, and the secure channel key provides a guarantee for secure communication between the terminal application and the application server.
[0095] In addition, the application layer key session establishment request also carries the first key identifier and the application identifier information of the terminal-side application.
[0096] Furthermore, if the terminal-side application layer key service module receives the request response information from the application layer key service network element, the service authentication module corresponding to the target network type executes the key generation process to determine the application layer key for the target network type, which may include the following steps:
[0097] Send a first key request to the first service authentication module, wherein the first key request carries first key identifier and application identifier information, and receive an application layer key sent by the first service authentication module, wherein the application layer key is obtained by the first service authentication module based on the first key identifier and application identifier information by performing a key generation process.
[0098] Figure 5 A flowchart illustrating a method for generating an application layer key according to an exemplary embodiment of this disclosure is shown. The first network is a 5G network, the first service authentication module is an AKMA module, and the target network elements include at least AAnF, AUSF, and HSS.
[0099] Taking the application layer key service module as an example, which is used by operators to provide application layer key capabilities to third-party applications (APPs), and the terminal-side application layer key service module is the terminal-side application layer key SDK, combined with Figure 5 The method for generating application layer keys according to exemplary embodiments of the present disclosure will be described in detail.
[0100] Step S510: The application (APP) accesses the application server.
[0101] Step S520: Application server response: Requests the generation of an application layer key, and the response information carries the domain name information of the application layer key service network element.
[0102] Step S530: The application (APP) calls the terminal application layer key SDK to initiate an application layer key request, carrying the application ID and the domain name information of the application layer key service network element.
[0103] Step S540: The terminal application layer key SDK determines the target network type of the terminal corresponding to the application (APP). Specifically, the terminal corresponding to the application (APP) can be obtained based on the application identifier information, thereby determining the target network type of the corresponding terminal.
[0104] Step S550: If the target network type is determined to be the first network (5G network), the terminal application layer key SDK interacts with the terminal AKMA module to obtain the A-KID identifier, i.e., the AKMA key identifier, i.e., the first key identifier. This first key identifier is generated by the UE during 5G network registration and primary authentication (see 3GPP TS 33.535), and will not be elaborated further in this disclosure.
[0105] Step S560: The terminal-side application layer key SDK initiates an application layer key session establishment request to the application layer key service network element. The application layer key session establishment request carries information such as the network resident identification information, the first key identifier, and the application ID.
[0106] Step S570: The application layer key service network element initiates an application layer key request to the 5G network's AAnF based on the network registration identifier information to execute the application layer key generation process.
[0107] Step S580: AAnF queries the local key identifier (A-KID) based on the first key identifier (A-KID) to retrieve the K key synchronized by AAnF during the UE's 5G network registration master authentication. AKMA .
[0108] Step S590: AAnF based on K AKMA The application layer key is derived from parameters such as the application ID and returned to the application layer key service network element.
[0109] Step S5100: The application layer key service network element returns application layer key session establishment response information to the terminal-side application layer key SDK.
[0110] Step S5110: After receiving the application layer key session establishment response information, the terminal-side application layer key SDK requests the application layer key from the terminal AKMA module, carrying the A-KID and application ID identifier, which is used to execute the key generation process and determine the application layer key.
[0111] Step S5120: The terminal AKMA module queries the K generated by the UE during the 5G network registration master authentication based on the A-KID locally. AKMA The application layer key is derived using the same parameters and algorithm as AAnF.
[0112] Step S5130: The terminal AKMA function module sends the application layer key to the terminal-side application layer key SDK.
[0113] Step S5140: The terminal-side application layer key SDK sends the application layer key and A-KID to the application APP.
[0114] Step S5150: The application APP sends the A-KID to the application server to report the result of generating the application layer key.
[0115] Step S5160: The application server, carrying the A-KID, requests the application layer key from the application layer key service network element to obtain the application layer key;
[0116] Step S5170: The application (APP) establishes secure communication with the application server based on the application layer key.
[0117] As can be seen from the above, by adding a terminal-side application layer key service module on the terminal side and an application layer key service network element on the network side, and by using the terminal-side application layer key service module to determine that the target network status of the terminal corresponding to the terminal application is a 5G network, mobile network adaptation can be performed on both the terminal side and the network side, and application layer key generation processes adapted to 5G networks can be executed respectively.
[0118] In an exemplary embodiment of this disclosure, if the target network type is a second network, and if the request response information of the application layer key service network element is received, the service authentication module corresponding to the target network type executes a key generation process to determine the application layer key of the target network type, which may further include the following steps:
[0119] An authentication request is sent to the second service authentication module so that the second service authentication module can perform authentication and generate an application layer key and a second key identifier. The authentication request carries application identifier information.
[0120] Receive authentication response information sent by the second service authentication module. The authentication response information includes the application layer key and the second key identifier.
[0121] The second key identifier is used to return to the application layer key service network element to instruct the application layer key service network element and the target network element corresponding to the second network to perform the key generation process and obtain the application layer key.
[0122] The second network can be a 4G network, and the second service authentication module can be a GBA module. Figure 6 A flowchart illustrating another method for generating application layer keys according to an exemplary embodiment of this disclosure is shown. The second network is a 4G network, the second service authentication module is a GBA module, and the target network elements include at least BSF and HSS.
[0123] Taking the application layer key service module as an example, which is used by operators to provide application layer key capabilities to third-party applications (APPs), and the terminal-side application layer key service module is the terminal-side application layer key SDK, combined with Figure 6Another method for generating application layer keys, as exemplified in this disclosure, will be described in detail.
[0124] Step S610: The terminal-side application layer key SDK initiates an application layer key session establishment request to the application layer key service network element. The application layer key session establishment request carries information such as the network registration identifier and the application ID.
[0125] Step S620: The application layer key service network element returns a request response to the terminal-side application layer key SDK based on the network registration identification information, requesting GBA authentication.
[0126] Step S630: The terminal-side application layer key SDK sends a GBA authentication request to the terminal-side GBA module, carrying information such as the application ID.
[0127] Step S630: The GBA module carries information such as the IMPI identifier and application ID of the IMS private user and interacts with the BSF network element to perform AKA two-way authentication and authorization.
[0128] Step S640: BSF generates a GBA key Ks and a second key identifier (B-TID identifier), and continues to generate an application layer key based on the GBA key Ks, the B-TID identifier and the application ID.
[0129] Step S650: BSF returns a successful authentication response to the GBA module on the terminal side, carrying the B-TID identifier.
[0130] Step S660: The GBA module on the terminal side interacts with the SIM card (Subscriber Identification Module) to generate a GBA key Ks, and then generates an application layer key based on B-TID, Ks, and application ID.
[0131] Step S670: The GBA module on the terminal side returns a GBA authentication response to the application layer key SDK on the terminal side, carrying the application layer key and B-TID identifier.
[0132] Step S680: The terminal-side application layer key SDK returns the GBA authentication result to the application layer key service network element, carrying the B-TID identifier.
[0133] Step S690: The application layer key service network element requests the application layer key from the BSF, carrying the B-TID identifier.
[0134] Step S6100: The application layer key service network element sends an application layer key session establishment response to the terminal-side application layer key SDK.
[0135] Step S6110: The terminal-side application layer key SDK sends an application layer key call response to the application (APP), carrying the application layer key and B-TID identifier.
[0136] Step S6120: The application (APP) sends the application layer key generation result to the application server, carrying the B-TID identifier.
[0137] Step S6130: The application server obtains the application layer key from the application layer key service network element, carrying the B-TID identifier.
[0138] Step S6140: The application (APP) establishes secure communication with the application server based on the application layer key.
[0139] As can be seen from the above, by adding a terminal-side application layer key service module on the terminal side and an application layer key service network element on the network side, and by using the terminal-side application layer key service module to determine that the target network status of the terminal corresponding to the terminal application is a 4G network, mobile network adaptation can be performed on both the terminal side and the network side, and application layer key generation processes adapted to 4G networks can be executed respectively.
[0140] It is worth noting that if the target network status of the terminal corresponding to the terminal application is 6G or other networks, and there is a system architecture or variation of the method for generating application layer keys in the present disclosure, the method for generating application layer keys in the present disclosure can also be used.
[0141] As can be seen from steps S510 to S5170 and steps S610 to S6140, the method for generating application layer keys in this embodiment of the present disclosure adds a terminal-side application key service module on the terminal side and an application layer key service network element on the network side. The terminal-side application key service module determines the target network status of the terminal and can choose to execute steps S510 to S5170 or steps S610 to S6140. This implements adaptive mobile network on the terminal side and network side respectively, provides a unified application layer key capability interface, fully utilizes the operator's mobile network security capabilities, and generates application layer keys through adaptive mobile network. This reduces the application integration threshold, improves the convenience of opening up the operator's mobile network application layer key capabilities, and has practical significance for attracting more third-party application partners and improving the operator's incremental benefits.
[0142] According to exemplary embodiments of this disclosure, a method for generating application layer keys is also provided, applied to an application layer key service network element on the network side. For example... Figure 7 As shown in the flowchart of the method for generating application layer keys according to embodiments of this disclosure, the steps may include:
[0143] Step S710: Receive the application layer key session establishment request sent by the terminal-side application layer key service module. The application layer key session establishment request carries the network registration identification information of the terminal corresponding to the terminal application. The application layer key service network element performs the key generation process according to the network registration identification information and the target network element corresponding to the target network type to determine the application layer key corresponding to the target network type.
[0144] Step S720: Send a request response message to the terminal-side application layer key service module to instruct the terminal-side application layer key service module and the service authentication module corresponding to the target network type to execute the key generation process.
[0145] The application layer key service network element executes a key generation process based on the network registration identification information and the target network element corresponding to the target network registration type to determine the application layer key corresponding to the target network registration type, which may include:
[0146] The application layer key service network element sends an application layer key request to the target network element, wherein the application layer key request carries a key identifier; the key identifier is obtained from the terminal-side application layer key service module, and the key identifier is obtained by the terminal-side application layer key service module from the service authentication module;
[0147] Receive the application layer key generated based on the key identifier sent by the target network element.
[0148] Since the specific details of each step, module (unit) and functional network element of the method for generating application layer keys in the exemplary embodiments of this disclosure have been described in detail in the above inventive embodiments of the method for generating application layer keys, they will not be repeated here.
[0149] According to exemplary embodiments of this disclosure, an apparatus for generating application layer keys is also provided, such as... Figure 8 As shown, the device 800 includes:
[0150] The first request module 810 is used to send an application layer key session establishment request from the terminal-side application layer key service module to the network-side application layer key service network element. The application layer key session establishment request carries the network identification information of the terminal corresponding to the terminal application. The network identification information is used to instruct the application layer key service network element and the target network element corresponding to the target network type to execute the application layer key generation process.
[0151] The first key determination module 820 is used to, upon receiving a request response information from an application layer key service network element, execute a key generation process with the service authentication module corresponding to the target network type to determine the application layer key for the target network type.
[0152] In an exemplary embodiment of this disclosure, the apparatus 800 for generating application layer keys may further include:
[0153] The first receiving module is used to receive an application layer key request from a terminal-side application by the terminal-side application layer key service module. The application layer key request carries application identification information and domain name information of the application layer key service network element. The application identification information is used to instruct the terminal-side application layer key service module to determine the target network type of the terminal corresponding to the terminal-side application.
[0154] In an exemplary embodiment of this disclosure, the target network type includes at least a first network and a second network, and the first network and the second network differ in at least the following ways:
[0155] This is different from the target network element that performs the application layer key generation process in the application layer key service network element;
[0156] This is different from the service authentication module that executes the application layer key generation process in the terminal-side application layer key service module.
[0157] In an exemplary embodiment of this disclosure, the first key determination module 820 is configured to:
[0158] The terminal-side application layer key service module obtains the first key identifier from the first service authentication module. The first key identifier is generated when the terminal corresponding to the terminal-side application completes the registration master authentication in the first network.
[0159] The application layer key session establishment request also carries the first key identifier and the application identifier information of the terminal-side application.
[0160] In an exemplary embodiment of this disclosure, the first key determination module 820 is configured to:
[0161] Send a first key request to the first service authentication module. The first key request carries the first key identifier and the application identifier information.
[0162] The application layer key sent by the first service authentication module is received. The application layer key is obtained by the first service authentication module through a key generation process based on the first key identifier and the application identifier information.
[0163] In an exemplary embodiment of this disclosure, if the target network type is a second network, the first key determination module 820 is configured as follows:
[0164] An authentication request is sent to the second service authentication module to perform authentication and generate the application layer key and the second key identifier. The authentication request carries application identifier information.
[0165] Receive authentication response information sent by the second service authentication module, wherein the authentication response information includes the application layer key and the second key identifier;
[0166] The second key identifier is used to return to the application layer key service network element to instruct the application layer key service network element and the target network element corresponding to the second network to perform a key generation process to obtain the application layer key.
[0167] In an exemplary embodiment of this disclosure, the first network is a 5G network and the second network is a 4G network.
[0168] The first service authentication module of the first network is the AKMA service for identity authentication and key management, and the second service authentication module of the second network is the GBA service for general authentication mechanism.
[0169] According to exemplary embodiments of this disclosure, an apparatus for generating application layer keys is also provided, such as... Figure 9 As shown, the device 900 includes:
[0170] The second request module 910 is used to receive an application layer key session establishment request sent by the terminal-side application layer key service module. The application layer key session establishment request carries the network identification information of the terminal corresponding to the terminal application. The application layer key service network element performs a key generation process according to the network identification information and the target network element corresponding to the target network type to determine the application layer key corresponding to the target network type.
[0171] The second key determination module 920 is used to send a request response information to the terminal-side application layer key service module to instruct the terminal-side application layer key service module and the service authentication module corresponding to the target network type to execute the key generation process.
[0172] In an exemplary embodiment of this disclosure, the second request module 910 may include:
[0173] The request unit is used for the application layer key service network element to send an application layer key request to the target network element. The application layer key request carries a key identifier. The key identifier is obtained from the terminal-side application layer key service module, and the key identifier is obtained by the terminal-side application layer key service module from the service authentication module.
[0174] The receiving unit is configured to receive the application layer key generated based on the key identifier sent by the target network element.
[0175] Since the specific details of the various functional modules (units) of the apparatus for generating application layer keys in the exemplary embodiments of this disclosure have been described in detail in the inventive embodiments of the method for generating application layer keys described above, they will not be repeated here.
[0176] According to exemplary embodiments of this disclosure, a communication system based on application-layer keys is also provided, and so on. Figure 1 As shown, the system 100 includes at least:
[0177] The terminal-side application layer key service module 110 is used to execute any of the above methods for generating application layer keys, generate application layer keys and send them to the terminal-side application 120.
[0178] Application layer key service network element 130 is used to execute the method of generating application layer key according to any of the above claims, determine the application layer key and send it to network side server 140;
[0179] The terminal-side application 120 and the network-side server 140 establish a communication connection based on the application layer key.
[0180] It is worth noting that other modules and network elements of the application layer key-based communication system in this disclosure have been described in the above-mentioned method embodiment section, and will not be repeated here.
[0181] Since the specific details of each network element and functional module (unit) of the communication system based on application layer keys in the exemplary embodiments of this disclosure have been described in detail in the inventive embodiments of the method for generating application layer keys described above, they will not be repeated here.
[0182] It should be noted that although the apparatus for generating application layer keys and several modules or units of the communication system based on application layer keys have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0183] Furthermore, in exemplary embodiments of this disclosure, a computer storage medium capable of implementing the above-described methods is also provided. A program product capable of implementing the methods described in this specification is stored thereon. In some possible embodiments, various aspects of this disclosure can also be implemented as a program product including program code, which, when run on a terminal device, causes the terminal device to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure.
[0184] This disclosure also provides a program product for implementing the above methods, which may employ a portable compact disc read-only memory (CD-ROM) and include program code, and can run on a terminal device, such as a personal computer. However, the program product of this disclosure is not limited thereto. In this document, a readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0185] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0186] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.
[0187] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0188] Program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0189] Furthermore, in exemplary embodiments of this disclosure, an electronic device capable of implementing the above-described methods is also provided. Those skilled in the art will understand that various aspects of this disclosure can be implemented as systems, methods, or program products. Therefore, various aspects of this disclosure can be specifically implemented as entirely hardware embodiments, entirely software embodiments (including firmware, microcode, etc.), or embodiments combining hardware and software aspects, collectively referred to herein as "circuit," "module," or "system."
[0190] The following reference Figure 10 To describe an electronic device 1000 according to such an embodiment of the present disclosure. Figure 10 The electronic device 1000 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.
[0191] like Figure 10 As shown, the electronic device 1000 is manifested in the form of a general-purpose computing device. The components of the electronic device 1000 may include, but are not limited to: at least one processing unit 1010, at least one storage unit 1020, a bus 1030 connecting different system components (including storage unit 1020 and processing unit 1010), and a display unit 1040.
[0192] The storage unit stores program code that can be executed by the processing unit 1010, causing the processing unit 1010 to perform the steps described in the "Exemplary Methods" section above according to various exemplary embodiments of this disclosure.
[0193] Storage unit 1020 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 1021 and / or a cache memory unit 1022, and may further include a read-only memory unit (ROM) 1023.
[0194] Storage unit 1020 may also include a program / utility 1024 having a set (at least one) program module 1025, such program module 1025 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.
[0195] Bus 1030 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the multiple bus structures.
[0196] Electronic device 1000 can also communicate with one or more external devices 1100 (e.g., keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with electronic device 1000, and / or any device that enables electronic device 1000 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 1050. Furthermore, electronic device 1000 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1060. As shown, network adapter 1060 communicates with other modules of electronic device 1000 via bus 1030. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1000, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0197] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0198] Furthermore, the above figures are merely illustrative of the processes included in the method according to exemplary embodiments of this disclosure and are not intended to be limiting. It is readily understood that the processes shown in the above figures do not indicate or limit the temporal order of these processes. Additionally, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.
[0199] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.
Claims
1. A method for generating application layer keys, characterized in that, The terminal-side application layer key service module, applied to the terminal side, includes: Send an application layer key session establishment request to the application layer key service network element on the network side. The application layer key session establishment request carries the network identification information of the terminal corresponding to the terminal application on the terminal side. The network identification information is used to instruct the application layer key service network element and the target network element corresponding to the target network type to execute the application layer key generation process. If a request response is received from the application layer key service network element, the service authentication module corresponding to the target network type executes a key generation process to determine the application layer key for the target network type.
2. The method according to claim 1, characterized in that, Before the terminal-side application layer key service module sends an application layer key session establishment request to the application layer key service network element, the method further includes: The terminal-side application layer key service module receives the application layer key request from the terminal-side application. The application layer key request carries application identification information and the domain name information of the application layer key service network element. The application identification information is used to instruct the terminal-side application layer key service module to determine the target network type of the terminal corresponding to the terminal-side application.
3. The method according to claim 1, characterized in that, The target network type includes at least a first network and a second network, and the first network and the second network differ in at least the following ways: This is different from the target network element that performs the application layer key generation process in the application layer key service network element; This is different from the service authentication module that executes the application layer key generation process in the terminal-side application layer key service module.
4. The method according to claim 3, characterized in that, If the target network type is a first network, before the terminal-side application layer key service module sends an application layer key session establishment request to the application layer key service network element, the method further includes: The terminal-side application layer key service module obtains the first key identifier from the first service authentication module. The first key identifier is generated when the terminal corresponding to the terminal-side application completes the registration master authentication in the first network. The application layer key session establishment request also carries the first key identifier and the application identifier information of the terminal-side application.
5. The method according to claim 4, characterized in that, If the request response information of the application layer key service network element is received, the service authentication module corresponding to the target network type executes a key generation process to determine the application layer key of the target network type, including: Send a first key request to the first service authentication module. The first key request carries the first key identifier and the application identifier information. The application layer key sent by the first service authentication module is received. The application layer key is obtained by the first service authentication module through a key generation process based on the first key identifier and the application identifier information.
6. The method according to claim 3, characterized in that, If the target network type is a second network, and the service authentication module corresponding to the target network type executes a key generation process to determine the application layer key for the target network type, including: An authentication request is sent to the second service authentication module to perform authentication and generate the application layer key and the second key identifier. The authentication request carries application identifier information. Receive authentication response information sent by the second service authentication module, wherein the authentication response information includes the application layer key and the second key identifier; The second key identifier is used to return to the application layer key service network element to instruct the application layer key service network element and the target network element corresponding to the second network to perform a key generation process to obtain the application layer key.
7. The method according to any one of claims 3 to 6, characterized in that, The first network is a 5G network, and the second network is a 4G network. The first service authentication module of the first network is the AKMA service for identity authentication and key management, and the second service authentication module of the second network is the GBA service for general authentication mechanism.
8. A method for generating an application layer key, characterized in that, Application-layer key service network elements applied on the network side include: The application layer key service network element receives an application layer key session establishment request sent by the terminal-side application layer key service module. The application layer key session establishment request carries the network registration identification information of the terminal corresponding to the terminal-side application. The application layer key service network element performs a key generation process based on the network registration identification information and the target network element corresponding to the target network type to determine the application layer key corresponding to the target network type. Send a request response message to the terminal-side application layer key service module to instruct the terminal-side application layer key service module and the service authentication module corresponding to the target network type to execute the key generation process.
9. The method according to claim 8, characterized in that, The application layer key service network element performs a key generation process based on the network registration identification information and the target network element corresponding to the target network registration type to determine the application layer key corresponding to the target network registration type, including: The application layer key service network element sends an application layer key request to the target network element. The application layer key request carries a key identifier. The key identifier is obtained from the terminal-side application layer key service module. The key identifier is obtained by the terminal-side application layer key service module from the service authentication module. Receive the application layer key generated based on the key identifier sent by the target network element.
10. A communication system based on application-layer keys, characterized in that, The communication system includes at least: A terminal-side application layer key service module is used to execute the method for generating an application layer key as described in any one of claims 1 to 7, generate an application layer key and send it to the terminal-side application; An application layer key service network element is used to execute the method for generating an application layer key as described in claim 8 or 9, determine the application layer key, and send it to the network-side server. The terminal-side application and the network-side server establish a communication connection based on the application layer key.
Citation Information
Patent Citations
Key generation method, device and equipment and computer readable storage medium
CN113543127A
Key distribution method, system and related equipment
CN114339745A