Authentication processing method and device, and related equipment

By acquiring and decrypting SUCI, and using a longer first key to obtain authentication information, the security problem of traditional cryptographic algorithms under the threat of quantum computing is solved, the ability to resist quantum computing is realized, and the security of communication networks is improved.

CN118802297BActive Publication Date: 2026-01-02CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410466115.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-18
Publication Date
2026-01-02
Estimated Expiration
2044-04-18

AI Technical Summary

Technical Problem

Traditional cryptographic algorithms face threats from quantum computing, and AES-128 is easily cracked, reducing the security of communication networks.

Method used

By obtaining the user hidden identifier SUCI and the encapsulated first key sent by the terminal, the user permanent identifier SUPI is decrypted. When USIM does not support the first encryption algorithm, the authentication information is obtained using the first key with a length greater than the USIM key. A quantum-safe encryption algorithm is used for key encapsulation and decapsulation.

Benefits of technology

The authentication process is more secure, resisting quantum computing attacks and improving system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802297B_ABST
    Figure CN118802297B_ABST
Patent Text Reader

Abstract

The application provides an authentication processing method and device and related equipment, and relates to the technical field of communication. The method comprises the following steps: obtaining a user concealed identifier (SUCI) and a packaged first key sent by a terminal; wherein the length of the first key is greater than the length of a second key, and the second key is a key stored in a universal subscriber identity module (USIM); decrypting the SUCI to obtain a user permanent identifier (SUPI); and obtaining authentication information according to the packaged first key in the case that the USIM of the terminal does not support a first encryption algorithm through the SUPI. The scheme of the application achieves the purpose of improving the security of the authentication process.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, in particular to an authentication processing method and device and related equipment. BACKGROUND

[0002] With the rapid development of Internet technology, the network security risks of information systems continue to increase, and the threat challenges are becoming increasingly severe. Password security is an important foundation of information security and can be used to effectively protect the data security of network information systems. Password technology is the core technology and important means to protect network information systems.

[0003] Currently, the network authentication and key agreement (AKA) of the communication network is implemented based on the MILENAGE algorithm, which is used to complete the authentication and key agreement between the universal subscriber identity module (USIM) and the unified data management (UDM). The underlying algorithm of the MILENAGE algorithm is the advanced encryption standard (AES)-128, and the shared key K between the USIM and the UDM is 128 bits.

[0004] However, with the development of quantum computing technology, traditional password algorithms face serious security threats. Quantum computers have powerful computing power, which can greatly reduce the difficulty of breaking symmetric password algorithms, making the risk of breaking AES-128 greatly increased. Attackers can obtain the plaintext of AES-128 to calculate the 128-bit key, thereby reducing the security of the system. SUMMARY

[0005] The purpose of the present application is to provide an authentication processing method, device and related equipment to improve the security of the authentication process.

[0006] To achieve the above purpose, an embodiment of the present application provides an authentication processing method, which is executed by a network side device, comprising:

[0007] Obtaining a user concealed identifier (SUCI) and an encapsulated first key sent by a terminal; wherein the length of the first key is greater than the length of a second key, and the second key is a key stored by a universal subscriber identity module (USIM);

[0008] Decrypting the SUCI to obtain a user permanent identifier (SUPI);

[0009] In a case where it is determined, by the SUPI, that a USIM of the terminal does not support a first encryption algorithm, authentication information is obtained according to the encapsulated first key.

[0010] Optionally, the obtaining of the authentication information according to the encapsulated first key comprises:

[0011] The encapsulated first key is decapsulated to obtain the first key, and the first key and the SUPI are stored in association;

[0012] The authentication information is obtained according to the first key and the second key.

[0013] Optionally, the obtaining of the authentication information according to the first key and the second key comprises:

[0014] First information is obtained according to a second encryption algorithm and the second key;

[0015] Second information is obtained according to a random number in the first information, the first key and the first encryption algorithm;

[0016] Authentication-related information is obtained according to the first information and the second information;

[0017] The authentication information is obtained according to the authentication-related information.

[0018] Optionally, the obtaining of the authentication-related information according to the first information and the second information comprises:

[0019] A fifth key is obtained based on a third key and a fourth key in the second information;

[0020] A third authentication token is obtained based on the fifth key, a first authentication token in the first information and a second authentication token in the second information;

[0021] A third expected response value is obtained based on a first expected response value in the first information and a second expected response value in the second information;

[0022] A seventh key is obtained based on the third key and a sixth key in the first information;

[0023] A ninth key is obtained based on the fourth key and an eighth key in the first information;

[0024] The random number, the third authentication token, the third expected response value, the seventh key and the ninth key are taken as the authentication-related information.

[0025] Optionally, the third authentication token is obtained based on the fifth key, a first authentication token in the first information, and a second authentication token in the second information, and the obtaining the third authentication token comprises:

[0026] concatenating the first authentication token and the second authentication token, and encrypting a concatenation result using the fifth key to obtain the third authentication token; or

[0027] encrypting the first authentication token using the fifth key, and concatenating an encryption result and the second authentication token to obtain the third authentication token.

[0028] Optionally, the authentication information is obtained based on the authentication-related information, and the obtaining the authentication information comprises:

[0029] a tenth key is obtained based on the seventh key and the ninth key;

[0030] a fourth expected response value is obtained based on the third expected response value;

[0031] the random number, the third authentication token, the fourth expected response value, and the ninth key are taken as the authentication information.

[0032] Optionally, after the authentication information is obtained based on the encapsulated first key, the method further comprises:

[0033] the random number and the third authentication token in the authentication information are sent to the terminal.

[0034] Optionally, after the random number and the third authentication token in the authentication information are sent to the terminal, the method further comprises:

[0035] a first response value sent by the terminal is received;

[0036] whether authentication is successful is determined based on the first response value.

[0037] To achieve the above object, an embodiment of the present application provides an authentication processing method, which is executed by a terminal and comprises:

[0038] whether a universal subscriber identity module (USIM) supports a first encryption algorithm is determined;

[0039] in a case where the USIM does not support the first encryption algorithm, a subscriber concealed identifier (SUCI) and an encapsulated first key are sent to a network side device, the first key has a length greater than that of a second key, and the second key is a key stored by the USIM.

[0040] Optionally, before the SUCI and the encapsulated first key are sent to the network side device, the method further comprises:

[0041] obtaining a public key of a home network corresponding to the USIM;

[0042] generating the first key and encapsulating the first key using the public key to obtain the encapsulated first key.

[0043] Optionally, after the sending the SUCI and the encapsulated first key to the network side device, the method further comprises:

[0044] receiving a random number and a third authentication token sent by the network side device;

[0045] obtaining a first authentication token according to the first key, the random number and the third authentication token.

[0046] Optionally, after the obtaining the first authentication token according to the first key, the random number and the third authentication token, the method further comprises:

[0047] verifying according to the first authentication token;

[0048] determining a first response value in case of passing the verification;

[0049] sending the first response value to the network side device.

[0050] Optionally, the obtaining the first authentication token according to the first key, the random number and the third authentication token comprises:

[0051] obtaining second information based on the first key and the random number;

[0052] obtaining a fifth key based on a third key and a fourth key in the second information;

[0053] decrypting the third authentication token using the fifth key to obtain the first authentication token and a fourth authentication token, or determining third information and the fourth authentication token based on the third authentication token and decrypting the third information using the fifth key to obtain the first authentication token.

[0054] Optionally, the method further comprises:

[0055] verifying the fourth authentication token according to a second authentication token in the second information.

[0056] Optionally, the determining the first response value in case of passing the verification comprises:

[0057] obtaining first information according to a second encryption algorithm and the second key;

[0058] The first response value is obtained based on a first expected response value in the first information and a second expected response value in the second information.

[0059] Optionally, the method further comprises:

[0060] A seventh key is obtained based on a sixth key in the first information and a third key in the second information.

[0061] A ninth key is obtained based on an eighth key in the first information and a fourth key in the second information.

[0062] To achieve the above object, an embodiment of the present application provides an authentication processing device, comprising:

[0063] A first receiving module is configured to acquire a subscriber concealed identifier (SUCI) and a first encapsulated key sent by a terminal; wherein the first key has a length greater than that of a second key, and the second key is a key stored in a universal subscriber identity module (USIM);

[0064] A first processing module is configured to decrypt the SUCI to obtain a subscriber permanent identifier (SUPI);

[0065] A second processing module is configured to obtain authentication information according to the first encapsulated key in a case where it is determined that the USIM of the terminal does not support a first encryption algorithm through the SUPI.

[0066] To achieve the above object, an embodiment of the present application provides an authentication processing device, comprising:

[0067] A third processing module is configured to determine whether a universal subscriber identity module (USIM) supports a first encryption algorithm;

[0068] A first sending module is configured to send a subscriber concealed identifier (SUCI) and a first encapsulated key to a network side device in a case where the USIM does not support the first encryption algorithm; wherein the first key has a length greater than that of a second key, and the second key is a key stored in the USIM.

[0069] To achieve the above object, an embodiment of the present application provides a network side device, comprising a processor and a transceiver,

[0070] The transceiver is configured to acquire a subscriber concealed identifier (SUCI) and a first encapsulated key sent by a terminal; wherein the first key has a length greater than that of a second key, and the second key is a key stored in a universal subscriber identity module (USIM);

[0071] The processor is configured to decrypt the SUCI to obtain a subscriber permanent identifier (SUPI);

[0072] The processor is further configured to obtain authentication information from the encapsulated first key in a case where the USIM of the terminal does not support the first encryption algorithm determined by the SUPI.

[0073] To achieve the above object, embodiments of the present application provide a terminal comprising a processor and a transceiver,

[0074] The processor is configured to determine whether a universal subscriber identity module (USIM) supports a first encryption algorithm.

[0075] The transceiver is configured to send a subscriber concealed identifier (SUCI) and an encapsulated first key to a network side device in a case where the USIM does not support the first encryption algorithm, the first key having a length greater than that of a second key stored in the USIM.

[0076] To achieve the above object, embodiments of the present application provide a communication device comprising a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; the processor implements the authentication processing method as described above when executing the program or instructions.

[0077] To achieve the above object, embodiments of the present application provide a readable storage medium having a program or instructions stored thereon, the program or instructions being executable by a processor to implement the steps of the authentication processing method as described above.

[0078] To achieve the above object, embodiments of the present application provide a computer program product comprising computer instructions, the computer instructions being executable by a processor to implement the steps of the authentication processing method as described above.

[0079] The above technical solutions of the present application have the following advantages:

[0080] The method of the embodiments of the present application obtains the SUCI and the encapsulated first key sent by the terminal, determines whether the USIM of the terminal supports the first encryption algorithm after decrypting the SUCI to obtain the SUPI, and obtains authentication information from the encapsulated first key in a case where the USIM of the terminal does not support the first encryption algorithm. Since the length of the first key is greater than that of the key of the USIM, the obtained authentication information enhances the ability to resist quantum computing and improves the security of the authentication process even if the USIM does not support the first encryption algorithm. BRIEF DESCRIPTION OF DRAWINGS

[0081] Figure 1 Flowchart of the method of the embodiments of the present application applied to a network side device;

[0082] Figure 2An application flowchart of the method of the embodiment of the present application;

[0083] Figure 3 A flowchart of the method of the embodiment of the present application applied to a terminal;

[0084] Figure 4 One of the device module schematic diagrams of the embodiment of the present application;

[0085] Figure 5 The second device module schematic diagram of the embodiment of the present application;

[0086] Figure 6 The structural diagram of the terminal of the embodiment of the present application;

[0087] Figure 7 The structural diagram of the terminal of another embodiment of the present application;

[0088] Figure 8 The structural diagram of the network side device of the embodiment of the present application. DETAILED DESCRIPTION

[0089] To make the technical problems to be solved by the present application, technical solutions and advantages clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.

[0090] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily mean the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner.

[0091] In various embodiments of the present application, it should be understood that the size of the serial number of the following processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0092] In addition, the terms "system" and "network" are often used interchangeably in this document.

[0093] In the embodiments provided in the present application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that the determination of B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0094] For the convenience of understanding, some contents related to the embodiments of the present application are described as follows:

[0095] 1) Universal Subscriber Identity Module (USIM): stores the user's core key and identifier data, etc.

[0096] 2) Mobile Equipment (ME): completes network authentication in cooperation with the USIM.

[0097] 3) User Equipment (UE): the collective term for the ME and the USIM.

[0098] 4) Security Anchor Function (SEAF): implements authentication of the UE by the access network.

[0099] 5) Authentication Server Function (AUSF): implements authentication of the UE by the home network.

[0100] 6) Unified Data Management (UDM) / Home Subscriber Server (HSS): stores the user's subscription information, authentication data, etc.

[0101] 7) Key Encapsulation Mechanism (KEM): C = KEM_ENC(PK, M), encrypts and encapsulates M using the public key PK, and KEM_ENC is a quantum-secure key encapsulation algorithm.

[0102] 8) Key Decapsulation Mechanism: M = KEM_DEC(SK, C), decrypts C using the private key SK to obtain the plaintext M, and KEM_DEC is a quantum-secure key decapsulation algorithm.

[0103] 9) Symmetric Encryption Function: C = E(K, M), symmetrically encrypts M using the symmetric key K, and E is a quantum-secure symmetric encryption algorithm.

[0104] 10) Symmetric Decryption Function: M = D(K, C), symmetrically decrypts C using the symmetric key K, and D is a quantum-secure symmetric decryption algorithm.

[0105] 11) Asymmetric Encryption Function: C = E_PUB(PK, M), asymmetrically encrypts M using the public key PK, and E_PUB is a quantum-secure public key encryption algorithm.

[0106] 12) Asymmetric decryption function: M = D_PUB(SK, C), asymmetrically decrypt C using private key SK, D_PUB is a quantum-secure public-key decryption algorithm.

[0107] 13) Signature function: S = SIGN(K, M), sign M using private key K.

[0108] 14) Verification function: VERIFY(K, M, S), verify S using public key K.

[0109] 15) Digest function: H = HASH(M), compute the digest value of M using a quantum-secure digest algorithm.

[0110] As shown in the following, Figure 1 An authentication processing method according to an embodiment of the present application is executed by a network-side device, and includes:

[0111] Step 11, obtaining a user concealed identifier SUCI and an encapsulated first key sent by a terminal; wherein the length of the first key is greater than the length of a second key, and the second key is a key stored in a universal subscriber identity module (USIM);

[0112] Step 12, decrypting the SUCI to obtain a user permanent identifier SUPI;

[0113] Step 13, in a case where it is determined that the USIM of the terminal does not support a first encryption algorithm through the SUPI, obtaining authentication information according to the encapsulated first key.

[0114] In this way, according to the above steps, the network-side device can obtain the SUCI and the encapsulated first key sent by the terminal, obtain the SUPI after decrypting the SUCI, determine whether the USIM of the terminal supports the first encryption algorithm through the SUPI, and thus obtain the authentication information from the encapsulated first key in a case where the USIM of the terminal does not support the first encryption algorithm. Since the length of the first key is greater than the length of the key of the USIM, the obtained authentication information enhances the ability to resist quantum computing even if the USIM does not support the first encryption algorithm, and improves the security of the authentication process.

[0115] Optionally, the network-side device is a UDM or a HSS.

[0116] In this embodiment, the first encryption algorithm is implemented based on a key with the same length as the first key. For example, the length of the second key is 128 bits, the length of the first key is 256 bits, and the first encryption algorithm needs to be implemented based on a 256-bit key, such as the MILENAGE-256 algorithm.

[0117] Optionally, in this embodiment, the terminal determines whether the USIM supports the first encryption algorithm, and sends the SUCI and the encapsulated first key in the case that the USIM does not support the first encryption algorithm. Specifically, the terminal sends an Initial Registration Request message carrying the SUCI and the encapsulated first key. Correspondingly, the network-side device obtains the SUCI and the encapsulated first key by receiving the Initial Registration Request message or a message forwarded by another device. For example, the UDM receives an authentication request (Nudm_Authenticate_Get Request) message sent by the AUSF, and the message carries the SUCI and the encapsulated first key.

[0118] In this embodiment, determining whether the USIM supports the first encryption algorithm can also be understood as checking whether the USIM is a new card. When the USIM is a new card, the USIM supports the first encryption algorithm.

[0119] Optionally, before the terminal sends the SUCI and the encapsulated first key, the terminal obtains the public key of the home network corresponding to the USIM, generates the first key, and encapsulates the first key using the public key to obtain the encapsulated first key.

[0120] That is, for the USIM that does not support the first encryption algorithm, the terminal can encapsulate the generated first key using the public key PK_HN of the home network. The terminal reads the home network information on the card and obtains the PK_HN. The way to obtain the PK_HN includes reading the PK_HN from the card or obtaining it from the home network operator. In addition, the encapsulation of the generated first key K_ME using the PK_HN can use a secure public key algorithm such as the PQC algorithm, and for the encapsulated first key K_ME_ENC, K_ME_ENC = KEM_ENC(PK_HN, K_ME).

[0121] In this embodiment, K_ME can be a randomly generated secure key, such as a 256-bit key.

[0122] Optionally, in this embodiment, after the SUCI is decrypted to obtain the SUPI, the network-side device such as the UDM can determine whether the USIM supports the first encryption algorithm according to the subscription data of the corresponding USIM queried according to the SUPI.

[0123] Optionally, in this embodiment, the authentication information obtained according to the encapsulated first key includes:

[0124] decapsulate the first key to obtain the first key, and store the first key and the SUPI in association;

[0125] obtain the authentication information according to the first key and the second key.

[0126] That is, after K_ME is obtained by decapsulating K_ME_ENC, K_ME is stored locally and associated with the SUPI. And the authentication information is obtained using K_ME and the second key K_USIM.

[0127] Wherein, the decapsulation of K_ME_ENC can be implemented by KEM_DEC and the home network private key SK_HN, that is, K_ME = KEM_DEC (SK_HN, K_ME_ENC).

[0128] Optionally, the obtaining the authentication information according to the first key and the second key comprises:

[0129] obtaining first information according to a second encryption algorithm and the second key;

[0130] obtaining second information according to the first encryption algorithm, the first key and a random number in the first information;

[0131] obtaining authentication-related information according to the first information and the second information;

[0132] obtaining the authentication information according to the authentication-related information.

[0133] Here, the second encryption algorithm is implemented based on a key with the same length as the second key. For example, the length of the second key is 128 bits, the length of the first key is 256 bits, and the second encryption algorithm needs to be implemented based on a 128-bit key, such as MILENAGE-128 algorithm.

[0134] Optionally, K_USIM is input to the second encryption algorithm, and the first information AV_USIM calculated includes: a random number RAND, a first authentication token AUTN_USIM, a first expected response value XRES_USIM, a sixth key CK_USIM, and an eighth key IK_USIM. That is, AV_USIM = (RAND, AUTN_USIM, XRES_USIM, CK_USIM, IK_USIM).

[0135] Optionally, the RAND in the K_ME and the AV_USIM is input into a first encryption algorithm, and second information AV_ME calculated and obtained includes: the RAND, a second authentication token AUTN_ME, a second expected response value XRES_ME, a third key CK_ME, and a fourth key IK_ME. That is, AV_ME=(RAND, AUTN_ME, XRES_ME, CK_ME, IK_ME).

[0136] Optionally, in the embodiment, the authentication-related information is obtained according to the first information and the second information, including:

[0137] The fifth key is obtained based on the third key and the fourth key in the second information.

[0138] The third authentication token is obtained based on the fifth key, the first authentication token in the first information, and the second authentication token in the second information.

[0139] The third expected response value is obtained based on the first expected response value in the first information and the second expected response value in the second information.

[0140] The seventh key is obtained based on the third key and the sixth key in the first information.

[0141] The ninth key is obtained based on the fourth key and the eighth key in the first information.

[0142] The random number, the third authentication token, the third expected response value, the seventh key, and the ninth key are taken as the authentication-related information.

[0143] The fifth key AUTN_USIM_ENC_K is an AUTN_USIM protection key. Optionally, the AUTN_USIM_ENC_K is calculated based on the CK_ME and the IK_ME by using a one-way function (f function), that is, AUTN_USIM_ENC_K=f(CK_ME, IK_ME). If the length of the second key is 128 bits and the length of the first key is 256 bits, the AUTN_USIM_ENC_K is a 256-bit AUTN_USIM protection key, and the one-way function used can be a 256-bit digest function HASH or a key derivation function (KDF).

[0144] Optionally, the third authentication token is obtained based on the fifth key, the first authentication token in the first information, and the second authentication token in the second information, including:

[0145] concatenate the first authentication token and the second authentication token, and encrypt the concatenated result using the fifth key to obtain the third authentication token; or

[0146] encrypt the first authentication token using the fifth key, and concatenate the encrypted result and the second authentication token to obtain the third authentication token.

[0147] That is, for the third authentication token AUTN_ENC, AUTN_ENC=E(AUTN_USIM_ENC_K, AUTN_USIM||AUTN_ME), or AUTN_ENC=E(AUTN_USIM_ENC_K, AUTN_USIM)||AUTN_ME, in this way, encryption and integrity protection of AUTN_USIM are realized.

[0148] Optionally, the third expected response value is obtained based on a first expected response value in the first information and a second expected response value in the second information, and the obtaining comprises:

[0149] concatenating the first expected response value and the second expected response value, and obtaining a digest of the concatenated result as the third expected response value.

[0150] Here, the digest of the concatenated result can be obtained by using a digest function, that is, for the third expected response value XRES, XRES=HASH(XRES_USIM||XRES_ME).

[0151] Similarly to the third expected response value, the seventh key and the ninth key can also be obtained by concatenating first and then obtaining a digest, that is, for the seventh key CK, CK=HASH(CK_USIM||CK_ME); and for the ninth key IK, IK=HASH(IK_USIM||IK_ME).

[0152] In this way, the authentication-related information AV(RAND, AUTN, XRES, CK, IK) can be constructed. Then, the authentication information is further obtained based on the authentication-related information AV(RAND, AUTN, XRES, CK, IK).

[0153] Optionally, the authentication information is obtained based on the authentication-related information, and the obtaining comprises:

[0154] a tenth key is obtained based on the seventh key and the ninth key;

[0155] a fourth expected response value is obtained based on the third expected response value;

[0156] the random number, the third authentication token, the fourth expected response value, and the ninth key are taken as the authentication information.

[0157] wherein the tenth key K AUSF is derived from CK and IK by KDF; and the fourth expected response value XRES* is derived from XRES by KDF. In this way, the authentication information comprising RAND, AUTN, XRES* and K AUSF can be obtained.

[0158] In this embodiment, for the system using 5G AKA, the obtained authentication information is 5G HE AV. Correspondingly, the network side device such as UDM can return the requested 5G HE AV to the AUSF in the authentication response (Nudm_UEAuthentication_Get Response) message, and indicate that the 5G HE AV is used for 5G AKA. If the Nudm_UEAuthentication_Get request contains SUCI, the UDM will contain SUPI in the Nudm_UEAuthentication_Get response.

[0159] The AUSF temporarily saves XRES* and the received SUCI or SUPI, and the AUSF can also save K AUSF . The AUSF generates a 5G AV based on the 5G HE AV received from the UDM / ARPF. Specifically, HXRES* is calculated from XRES*, K AUSF is derived from K SEAF , and then HXRES* and K SEAF are used to replace XRES* and K AUSF in the 5G HE AV respectively to obtain the 5G AV. Then the AUSF removes K SEAF , and sends the 5G SE AV (RAND, AUTN, HXRES*) to the SEAF through the authentication (Nausf_UEAuthentication_Authenticate) response. The SEAF sends RAND and AUTN to the UE through a non-access layer (Non Access Stratum, NAS) message (such as Auth-Req), and the message also contains ngKSI used by the UE and the AMF to identify K AMF (namely, the key derived from K SEAF by the ME and the SEAF) and part of the original security context, and the message also includes an Anti-Biddingdown Between Architectures (ABBA) parameter.

[0160] Optionally, in this embodiment, after the authentication information is obtained according to the encapsulated first key, the method further comprises:

[0161] sending the terminal the random number and the third authentication token in the authentication information.

[0162] In this way, the terminal can receive the random number and the third authentication token to perform subsequent authentication.

[0163] Optionally, after receiving the random number and the third authentication token sent by the network side device, the terminal obtains a first authentication token based on the first key, the random number and the third authentication token.

[0164] Optionally, the obtaining of the first authentication token based on the first key, the random number and the third authentication token comprises:

[0165] obtaining second information based on the first key and the random number;

[0166] obtaining a fifth key based on a third key and a fourth key in the second information;

[0167] decrypting the third authentication token using the fifth key to obtain the first authentication token and a fourth authentication token, or determining third information and the fourth authentication token based on the third authentication token and decrypting the third information using the fifth key to obtain the first authentication token.

[0168] In the above method, the terminal can generate AV_ME using the first encryption algorithm based on K_ME and RAND, like the network side device. For example, the ME of the terminal can input the locally saved K_ME and the received RAND into the first encryption algorithm (e.g., MILENAGE-256 algorithm) to calculate AV_ME. Then, AUTN_USIM_ENC_K is obtained based on CK_ME and IK_ME in AV_ME. AUTN_USIM_ENC_K can be obtained by the same way as the network side device, i.e., AUTN_USIM_ENC_K = f(CK_ME, IK_ME). Then, AUTN_USIM and AUTN_ME are obtained by inverse processing according to different generation ways of the third authentication token (concatenation first and then encryption, or encryption first and then concatenation).

[0169] If the third authentication token is generated by concatenating first and then encrypting, the inverse processing is to intercept after decrypting first, and AUTN_ENC is decrypted using AUTN_USIM_ENC_K to obtain the concatenated information of AUTN_USIM and the fourth authentication token AUTN_ME, and AUTN_USIM and AUTN_ME can be intercepted since the length of the authentication token is known; if the third authentication token is generated by encrypting first and then concatenating, the inverse processing is to intercept first and then decrypt, and AUTN_ME and the third information (encrypted AUTN_USIM) are intercepted since the length of the authentication token is known, and the third information is decrypted using AUTN_USIM_ENC_K to obtain AUTN_USIM.

[0170] Optionally, the steps performed by the terminal further include:

[0171] Verifying the fourth authentication token according to the second authentication token in the second information.

[0172] That is, after the terminal obtains the fourth authentication token by the above-mentioned intercepting after decrypting, the terminal can also verify the legality of the fourth authentication token based on K_ME and RAND using the first encryption algorithm. Specifically, after K_ME and RAND are input into the first encryption algorithm (such as MILENAGE-256), the calculated AUTN_ME is compared with the fourth authentication token (AUTN_ME obtained by intercepting after decrypting) for consistency.

[0173] It should be noted that in this embodiment, the ME of the terminal performs the above-mentioned steps to obtain AUTN_USIM, and forwards the received RAND and the obtained AUTN_USIM to the USIM.

[0174] Optionally, after the first authentication token is obtained according to the first key, the random number and the third authentication token, the method further includes:

[0175] Verifying according to the first authentication token;

[0176] Determining a first response value in the case of passing the verification;

[0177] Sending the first response value to the network side device.

[0178] In this way, after the terminal obtains AUTN_USIM based on the received third authentication token, the terminal verifies according to the AUTN_USIM, and determines a first response value RES* in the case of passing the verification, and sends RES* to the network side device.

[0179] The USIM of the terminal performs the above steps, verifies the AUTN USIM, and checks whether the AUTN USIM is accepted. The ME determines a second response value RES in the case of successful verification, and calculates RES* from the RES.

[0180] Optionally, the determining the first response value in the case of successful verification comprises:

[0181] The first information is obtained according to the second encryption algorithm and the second key.

[0182] The first response value is obtained based on a first expected response value in the first information and a second expected response value in the second information.

[0183] That is, the USIM of the terminal inputs the K USIM into the second encryption algorithm to obtain the AV USIM, and then the ME obtains the second response value RES based on the XRES USIM in the AV USIM and the XRES ME in the AV ME. Specifically, the XRES USIM and the XRES ME are concatenated, and then a digest function is used to calculate the concatenation result to obtain the RES, that is, RES = HASH (XRES USIM || XRES ME). In this way, the ME can calculate the RES* from the RES. The USIM sends the XRES USIM, the CK USIM, and the IK USIM in the AV USIM to the ME.

[0184] Optionally, the steps performed by the terminal further comprise:

[0185] The seventh key is obtained based on a sixth key in the first information and a third key in the second information.

[0186] The ninth key is obtained based on an eighth key in the first information and a fourth key in the second information.

[0187] Therefore, the ME calculates the CK from the CK USIM sent by the USIM and the CK ME saved locally, and calculates the IK from the IK USIM sent by the USIM and the IK ME saved locally.

[0188] The terminal determines the seventh key CK and the ninth key IK in the same way as the network side device, that is, CK = HASH (CK USIM || CK ME), and IK = HASH (IK USIM || IK ME).

[0189] Optionally, the ME can derive the K from the CK and the IK AUSF , derive the K AUSF from the K SEAF .

[0190] In this embodiment, the terminal sends RES* to the network side device, which can be that the terminal returns RES* to SEAF in the NAS message authentication response. Then, SEAF calculates HRES* from RES* and compares HRES* with HXRES*. If the two values are consistent, SEAF considers the authentication successful from the perspective of the service network; if not, SEAF considers the authentication failed and indicates the failure to AUSF. SEAF sends RES* to AUSF through the Nausf_UEAuthentication_Authenticate Request message, and also sends the corresponding SUCI or SUPI from the UE to AUSF through the Nausf_UEAuthentication_Authenticate Request message. When receiving the Nausf_UEAuthentication_Authenticate Request message containing RES*, AUSF can verify whether the authentication information has expired. If the authentication information has expired, AUSF considers the authentication unsuccessful from the perspective of the home network. AUSF should compare the received RES* with the stored XRES*, and if RES* and XRES* are consistent, AUSF should consider the authentication successful from the perspective of the home network.

[0191] AUSF indicates to SEAF whether the authentication is successful through Nausf_UEAuthentication_Authenticate Response. If the authentication is successful, AUSF sends K SEAF to SEAF through Nausf_UEAuthentication_Authenticate Response. If AUSF receives SUCI from SEAF when starting authentication and the authentication is successful, AUSF should also include SUPI in Nausf_UEAuthentication_Authenticate Response.

[0192] If the authentication is successful, SEAF should receive the key K SEAF from the Nausf_UEAuthentication_Authenticate Response message as an anchor key. Then SEAF should derive K SEAF from K AMF , ABBA parameter and SUPI, and provide ngKSI and K AMF to AMF. If SUCI is used for this authentication, SEAF should only provide ngKSI and K AMF to AMF after receiving the Nausf_UEAuthentication_Authenticate Response message containing SUPI.Before the service network learns the SUPI, the UE is not provided with communication services.

[0193] In the following, the method of the embodiment of the application is described in combination with Figure 2 The method of the embodiment of the application is described in combination with the overall flow of 5G AKA.

[0194] The ME checks whether the USIM is a new card, and if not, obtains the public key PK_HN of the USIM home network. The ME randomly generates a 256-bit K_ME, encapsulates the K_ME as K_ME_ENC, and sends the K_ME_ENC and SUCI to the UDM / HSS through an initialization registration request.

[0195] After the UDM / HSS obtains the K_ME_ENC, the K_ME_ENC is decrypted to obtain the K_ME; the AV_USIM is calculated based on the 128-bit K_USIM; the AV_ME is calculated based on the RAND and the K_ME; the AUTN_USIM_ENC_K is calculated; the AUTN_USIM is encrypted to obtain the AUTN_ENC; and the 5G HE AV is constructed. The terminal is informed of the RAND and the AUTN_ENC through an authentication request.

[0196] After the ME obtains the RAND and the AUTN_ENC, the CK_ME, IK_ME and XRES_ME are calculated based on the K_ME and the RAND; the AUTN_USIM_ENC_K is calculated; the AUTN_USIM is decrypted from the AUTN_ENC based on the AUTN_USIM_ENC_K; and the RAND and the AUTN_USIM are sent to the USIM.

[0197] After the USIM obtains the RAND and the AUTN_USIM, the AUTN_USIM is verified; the XRES_USIM, CK_USIM and IK_USIM are calculated; and the XRES_USIM, CK_USIM and IK_USIM are sent to the ME.

[0198] The ME calculates the RES*, CK and IK based on the received XRES_USIM, CK_USIM and IK_USIM and the locally saved XRES_ME, CK_ME and IK_ME. The terminal sends an authentication response to the UDM / HSS, including the RES*.

[0199] In summary, in the scenario that the first encryption algorithm is not supported by the terminal USIM, the method of the embodiment of the application can complete the authentication based on the provided first key, the length of the first key is greater than the length of the key stored by the USIM, and the security of the system is improved. In addition, since other network elements and related interfaces do not need to be modified, the modification cost is low, and the compatibility with the original protocol is high.

[0200] It should be noted that in the embodiment, it is judged whether the USIM supports the first encryption algorithm, and if the USIM supports the first encryption algorithm, the terminal can directly encrypt and encapsulate the second key, send the encapsulated second key and the SUCI to the network side device, and the network side device and the terminal complete authentication based on the second key.

[0201] It should also be noted that the method of the embodiment of the application is not only applicable to the AKA protocols of 3G, 4G and 5G, but also applicable to the corresponding EAP-AKA. The above embodiment is mainly described with respect to 5G AKA.

[0202] As shown in Figure 3 An authentication processing method according to an embodiment of the application is executed by a terminal and includes:

[0203] Step 31: judging whether a universal subscriber identity module (USIM) supports a first encryption algorithm;

[0204] Step 32: in a case where the USIM does not support the first encryption algorithm, sending a subscriber concealed identifier (SUCI) and an encapsulated first key to a network side device, the first key having a length greater than that of a second key, and the second key being a key stored by the USIM.

[0205] In this way, the network side device can obtain authentication information from the encapsulated first key in a case where the USIM of the terminal does not support the first encryption algorithm, by acquiring the SUCI and the encapsulated first key sent by the terminal, decrypting the SUCI to obtain a SUPI, and determining whether the USIM of the terminal supports the first encryption algorithm based on the SUPI. Since the length of the first key is greater than that of the key of the USIM, the obtained authentication information has enhanced ability to resist quantum computing even if the USIM does not support the first encryption algorithm, and the security of the authentication process is improved.

[0206] Optionally, before the sending of the SUCI and the encapsulated first key to the network side device, the method further includes:

[0207] acquiring a public key of a home network corresponding to the USIM;

[0208] generating the first key and encapsulating the first key using the public key to obtain the encapsulated first key.

[0209] Optionally, after the sending of the SUCI and the encapsulated first key to the network side device, the method further includes:

[0210] receiving a random number and a third authentication token sent by the network side device;

[0211] The first authentication token is obtained according to the first key, the random number and the third authentication token.

[0212] Optionally, after the first authentication token is obtained according to the first key, the random number and the third authentication token, the method further comprises:

[0213] The first authentication token is verified;

[0214] A first response value is determined in a case where the verification is passed;

[0215] The first response value is sent to the network side device.

[0216] Optionally, the first authentication token is obtained according to the first key, the random number and the third authentication token, and the method comprises:

[0217] Second information is obtained based on the first key and the random number;

[0218] A fifth key is obtained based on a third key and a fourth key in the second information;

[0219] The third authentication token is decrypted using the fifth key to obtain the first authentication token and a fourth authentication token, or third information and the fourth authentication token are determined based on the third authentication token, and the third information is decrypted using the fifth key to obtain the first authentication token.

[0220] Optionally, the method further comprises:

[0221] The fourth authentication token is verified according to a second authentication token in the second information.

[0222] Optionally, the first response value is determined in a case where the verification is passed, and the method comprises:

[0223] First information is obtained according to a second encryption algorithm and the second key;

[0224] The first response value is obtained based on a first expected response value in the first information and a second expected response value in the second information.

[0225] Optionally, the method further comprises:

[0226] A seventh key is obtained based on a sixth key in the first information and a third key in the second information;

[0227] A ninth key is obtained based on an eighth key in the first information and a fourth key in the second information.

[0228] It should be noted that the method is implemented in cooperation with the method executed by the network side device, and the implementation mode of the method embodiment is applicable to the method, and the same technical effects can be achieved.

[0229] As shown in Figure 4 An embodiment of the application provides an authentication processing device, comprising:

[0230] The first receiving module 410 is configured to acquire a user concealed identifier SUCI and a packaged first key sent by a terminal; wherein the length of the first key is greater than the length of a second key, and the second key is a key of a universal subscriber identity module USIM;

[0231] The first processing module 420 is configured to decrypt the SUCI to obtain a user permanent identifier SUPI;

[0232] The second processing module 430 is configured to acquire authentication information according to the packaged first key in a case where it is determined that the USIM of the terminal does not support a first encryption algorithm through the SUPI.

[0233] The device can acquire the SUCI and the packaged first key sent by the terminal, decrypt the SUCI to obtain the SUPI, and then determine whether the USIM of the terminal supports the first encryption algorithm through the SUPI, so as to acquire the authentication information from the packaged first key in a case where the USIM of the terminal does not support the first encryption algorithm. Since the length of the first key is greater than the length of the key of the USIM, even if the USIM does not support the first encryption algorithm, the obtained authentication information enhances the ability to resist quantum computing and improves the security of the authentication process.

[0234] Optionally, the second processing module is further configured to:

[0235] unpack the packaged first key to obtain the first key, and store the first key and the SUPI in association;

[0236] obtain the authentication information according to the first key and the second key.

[0237] Optionally, the second processing module is further configured to:

[0238] obtain first information according to a second encryption algorithm and the second key;

[0239] obtain second information according to a random number in the first information, the first key, and the first encryption algorithm;

[0240] obtain authentication-related information according to the first information and the second information;

[0241] obtaining the authentication information according to the authentication-related information.

[0242] Optionally, the second processing module is further configured to:

[0243] obtaining a fifth key based on a third key and a fourth key in the second information;

[0244] obtaining a third authentication token based on the fifth key, a first authentication token in the first information, and a second authentication token in the second information;

[0245] obtaining a third expected response value based on a first expected response value in the first information and a second expected response value in the second information;

[0246] obtaining a seventh key based on the third key and a sixth key in the first information;

[0247] obtaining a ninth key based on the fourth key and an eighth key in the first information;

[0248] using the random number, the third authentication token, the third expected response value, the seventh key, and the ninth key as the authentication-related information.

[0249] Optionally, the second processing module is further configured to:

[0250] concatenating the first authentication token and the second authentication token, and encrypting a result of the concatenation using the fifth key to obtain the third authentication token; or

[0251] encrypting the first authentication token using the fifth key, and concatenating a result of the encryption with the second authentication token to obtain the third authentication token.

[0252] Optionally, the second processing module is further configured to:

[0253] obtaining a tenth key based on the seventh key and the ninth key;

[0254] obtaining a fourth expected response value based on the third expected response value;

[0255] using the random number, the third authentication token, the fourth expected response value, and the ninth key as the authentication information.

[0256] Optionally, the apparatus further includes:

[0257] a second sending module configured to send a random number and a third authentication token in the authentication information to the terminal.

[0258] Optionally, the apparatus further includes:

[0259] The second receiving module is configured to receive a first response value sent by the terminal.

[0260] The fourth processing module is configured to determine whether the authentication is successful according to the first response value.

[0261] It should be noted that the device is a device applying the method executed by the network side device, and the implementation manners of the method embodiments are applicable to the device, and the same technical effects can be achieved.

[0262] As shown in Figure 5 An authentication processing device is provided, which includes:

[0263] The third processing module 510 is configured to determine whether a universal subscriber identity module (USIM) supports a first encryption algorithm.

[0264] The first sending module 520 is configured to send a subscriber concealed identifier (SUCI) and an encapsulated first key to a network side device in a case where the USIM does not support the first encryption algorithm, the first key having a length greater than that of a second key stored in the USIM.

[0265] The device enables the network side device to obtain the SUCI and the encapsulated first key sent by the terminal, to obtain the SUPI by decrypting the SUCI, to determine whether the USIM of the terminal supports the first encryption algorithm according to the SUPI, and to obtain the authentication information from the encapsulated first key in a case where the USIM of the terminal does not support the first encryption algorithm. Since the length of the first key is greater than that of the key of the USIM, the obtained authentication information enhances the ability to resist quantum computing and improves the security of the authentication process even if the USIM does not support the first encryption algorithm.

[0266] Optionally, the device further includes:

[0267] The obtaining module is configured to obtain a public key of a home network corresponding to the USIM.

[0268] The fifth processing module is configured to generate the first key and encapsulate the first key using the public key to obtain the encapsulated first key.

[0269] Optionally, the device further includes:

[0270] The third receiving module is configured to receive a random number and a third authentication token sent by the network side device.

[0271] The sixth processing module is configured to obtain a first authentication token according to the first key, the random number and the third authentication token.

[0272] Optionally, the apparatus further comprises:

[0273] a seventh processing module configured to verify according to the first authentication token;

[0274] an eighth processing module configured to determine a first response value in a case of verification passing;

[0275] a third sending module configured to send the first response value to the network side device.

[0276] Optionally, the sixth processing module is further configured to:

[0277] obtain second information based on the first key and the random number;

[0278] obtain a fifth key based on a third key and a fourth key in the second information;

[0279] decrypt the third authentication token using the fifth key to obtain the first authentication token and a fourth authentication token, or determine third information and the fourth authentication token based on the third authentication token, and decrypt the third information using the fifth key to obtain the first authentication token.

[0280] Optionally, the apparatus further comprises:

[0281] a ninth processing module configured to verify the fourth authentication token according to a second authentication token in the second information.

[0282] Optionally, the eighth processing module is further configured to:

[0283] obtain first information according to a second encryption algorithm and the second key;

[0284] obtain the first response value based on a first expected response value in the first information and a second expected response value in the second information.

[0285] Optionally, the apparatus further comprises:

[0286] a tenth processing module configured to obtain a seventh key based on a sixth key in the first information and a third key in the second information;

[0287] an eleventh processing module configured to obtain a ninth key based on an eighth key in the first information and a fourth key in the second information.

[0288] It should be noted that the apparatus is an apparatus applied to the method executed by the terminal, and the implementation manners of the method embodiments are applicable to the apparatus, and the same technical effects can be achieved.

[0289] As Figure 6 shown in FIG. 6, a terminal 600 according to an embodiment of the present application includes a processor 610 and a transceiver 620, wherein

[0290] The processor is configured to determine whether a universal subscriber identity module (USIM) supports a first encryption algorithm.

[0291] The transceiver is configured to send, to a network-side device, a subscriber concealed identifier (SUCI) and an encapsulated first key in a case where the USIM does not support the first encryption algorithm, the first key having a length greater than a length of a second key stored in the USIM.

[0292] Optionally, the processor is further configured to:

[0293] obtain a public key of a home network corresponding to the USIM;

[0294] generate the first key and encapsulate the first key using the public key to obtain the encapsulated first key.

[0295] Optionally, the transceiver is further configured to receive a random number and a third authentication token sent by the network-side device.

[0296] The processor is further configured to obtain a first authentication token based on the first key, the random number, and the third authentication token.

[0297] Optionally, the processor is further configured to perform verification based on the first authentication token and determine a first response value in a case where the verification is passed.

[0298] The transceiver is further configured to send the first response value to the network-side device.

[0299] Optionally, the processor is further configured to:

[0300] obtain second information based on the first key and the random number.

[0301] obtain a fifth key based on a third key and a fourth key in the second information.

[0302] decrypt the third authentication token using the fifth key to obtain the first authentication token and a fourth authentication token, or determine third information and the fourth authentication token based on the third authentication token and decrypt the third information using the fifth key to obtain the first authentication token.

[0303] Optionally, the processor is further configured to:

[0304] verify the fourth authentication token based on a second authentication token in the second information.

[0305] Optionally, the processor is further configured to:

[0306] The first information is obtained based on the second encryption algorithm and the second key;

[0307] The first response value is obtained based on the first expected response value in the first information and the second expected response value in the second information.

[0308] Optionally, the processor is further configured to:

[0309] Based on the sixth key in the first information and the third key in the second information, the seventh key is obtained;

[0310] Based on the eighth key in the first information and the fourth key in the second information, the ninth key is obtained.

[0311] Another embodiment of the present invention provides a mobile terminal, such as... Figure 7 As shown, it includes a transceiver 710, a processor 700, a memory 720, and a program or instructions stored in the memory 720 and executable on the processor 700; when the processor 700 executes the program or instructions, it implements the authentication processing method applied to the terminal described above.

[0312] The transceiver 710 is used to receive and send data under the control of the processor 700.

[0313] Among them, Figure 7 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 700 and memory represented by memory 720 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 710 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, the user interface 730 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.

[0314] The processor 700 is responsible for managing the bus architecture and general processing, while the memory 720 can store the data used by the processor 700 during operation.

[0315] A network-side device according to an embodiment of the present invention includes a processor and a transceiver.

[0316] The transceiver is configured to obtain a subscriber concealed identifier (SUCI) and a first encapsulated key sent by a terminal, wherein the first key has a length greater than that of a second key, and the second key is a key of a universal subscriber identity module (USIM);

[0317] The processor is configured to decrypt the SUCI to obtain a subscriber permanent identifier (SUPI);

[0318] The processor is further configured to obtain authentication information according to the first encapsulated key in a case where it is determined that the USIM of the terminal does not support a first encryption algorithm through the SUPI.

[0319] Optionally, the processor is further configured to:

[0320] decapsulate the first encapsulated key to obtain the first key, and store the first key and the SUPI in association;

[0321] obtain the authentication information according to the first key and the second key.

[0322] Optionally, the processor is further configured to:

[0323] obtain first information according to a second encryption algorithm and the second key;

[0324] obtain second information according to a random number in the first information, the first key, and the first encryption algorithm;

[0325] obtain authentication-related information according to the first information and the second information;

[0326] obtain the authentication information according to the authentication-related information.

[0327] Optionally, the processor is further configured to:

[0328] obtain a fifth key based on a third key and a fourth key in the second information;

[0329] obtain a third authentication token based on the fifth key, a first authentication token in the first information, and a second authentication token in the second information;

[0330] obtain a third expected response value based on a first expected response value in the first information and a second expected response value in the second information;

[0331] obtain a seventh key based on the third key and a sixth key in the first information;

[0332] obtain a ninth key based on the fourth key and an eighth key in the first information;

[0333] The random number, the third authentication token, the third expected response value, the seventh key and the ninth key are taken as the authentication-related information.

[0334] Optionally, the processor is further configured to:

[0335] The first authentication token is concatenated with the second authentication token, and the concatenated result is encrypted using the fifth key to obtain the third authentication token; or

[0336] The first authentication token is encrypted using the fifth key, and the encrypted result is concatenated with the second authentication token to obtain the third authentication token.

[0337] Optionally, the processor is further configured to:

[0338] A tenth key is obtained based on the seventh key and the ninth key;

[0339] A fourth expected response value is obtained based on the third expected response value;

[0340] The random number, the third authentication token, the fourth expected response value and the ninth key are taken as the authentication information.

[0341] Optionally, the transceiver is configured to:

[0342] The transceiver is configured to send the random number and the third authentication token in the authentication information to the terminal.

[0343] Optionally, the transceiver is configured to receive the first response value sent by the terminal.

[0344] The processor is further configured to determine whether the authentication is successful according to the first response value.

[0345] Another embodiment of the network side device of the application, as shown in Figure 8 The network side device comprises a transceiver 810, a processor 800, a memory 820, and a program or instruction stored in the memory 820 and executable on the processor 800; and the processor 800 implements the above-mentioned authentication processing method applied to the network side device when executing the program or instruction.

[0346] The transceiver 810 is configured to receive and send data under the control of the processor 800.

[0347] In the above-mentioned authentication processing method applied to the network side device, the first authentication token is concatenated with the second authentication token, and the concatenated result is encrypted using the fifth key to obtain the third authentication token; or Figure 8In particular embodiments, the bus architecture can include any number of interconnecting buses and bridges, depending on the specific application of the processor 800 and the overall design constraints. The bus architecture can link together various circuits including the one or more processors represented by the processor 800, and the memory represented by the memory 820. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and thus, not described further. The bus interface provides an interface to the transceiver 810, which can be a plurality of elements including a transmitter and a receiver, providing a means for communicating with various other apparatus over a transmission medium. The processor 800 is responsible for managing the bus architecture and general processing, with the memory 820 storing data used by the processor 800 in its execution.

[0348] A readable storage medium of an embodiment of the present application, which stores a program or instruction, when executed by a processor, implements the steps in the authentication processing method as described above, and can achieve the same technical effects. To avoid repetition, this will not be described further.

[0349] The processor is the processor in the terminal or network side device described in the above embodiments. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (Read-Only Memory, ROM for short), a random access memory (Random Access Memory, RAM for short), a magnetic disk or an optical disk, etc.

[0350] The embodiment of the present application also provides a computer program product, which includes computer instructions, when executed by a processor, implements various processes of the method embodiment shown in the above Figure 1 Or Figure 3 The same technical effects can be achieved, and to avoid repetition, this will not be described further.

[0351] It should be further noted that the terminal described in the specification includes but is not limited to a smart phone, a tablet computer, etc., and many functional components described are referred to as modules, in order to more particularly emphasize the independence of their implementation.

[0352] In the embodiment of the present application, the module can be implemented by software, so as to be executed by various types of processors. For example, an identified executable code module can include one or more physical or logical blocks of computer instructions, which can be constructed as objects, processes or functions, for example. However, the executable code of the identified module need not be physically located together, but can include different instructions stored in different locations which, when combined logically, constitute the module and achieve the specified purpose of the module.

[0353] Indeed, a module of executable code can be a single instruction, or many instructions, and can even be distributed over several different code segments, among different programs, and across several memory devices. Similarly, operational data can be identified within the module and can be

[0354] To the extent that the module can be implemented utilizing software, the module can be stored in a non-transitory computer-readable medium or memory at a location within or outside of a computing device at the time of actual use or can be stored and transported within a computing device at or outside of the time of actual use. An implementation of a module can be realized in a centralized fashion in which the module is stored on one computing device and executed thereon or a decentralized fashion where the module is stored and executed acrossthe multiple computing devices.

[0355] The foregoing exemplary embodiments have been described in some detail constituting certain examples of the present application. Many variations and modifications of the embodiments described herein can be made by those skilled in the art without departing from the intended scope of the application as defined by the appended claims. Accordingly, the application is not limited to the examples described herein, but is intended to embrace all within the scope of the appended claims. Furthermore, the terms and expressions employed herein have been used as terms of description and not of limitation, and there is no intention in the use of such terms and expressions of excluding any equivalents of the features shown and described or portions thereof. It is recognized that various modifications are possible within the scope of the application, and the inventive subject matter is to be understood as not limited to the examples described or referenced herein but encompass a complete range of equivalents. Various references have been mentioned throughout this detailed description that can be consulted for additional aspects and features relating to the present application. Any and all such references are incorporated by reference in their entirety.

[0356] The preferred embodiments of the application have been described above with the understanding that variations and modifications will occur to those skilled in the art in view of these preferred embodiments. Therefore, to the extent that the present application includes such modifications and variations, it is the intention that such modifications and variations be included within the scope of the application.

Claims

1. An authentication processing method characterized by comprising: Perfromed by a network side device, comprising: obtaining a user concealed identifier SUCI and an encapsulated first key sent by a terminal; wherein, the length of the first key is greater than the length of a second key, and the second key is a key stored in a universal subscriber identity module USIM; decrypting the SUCI to obtain a user permanent identifier SUPI; in a case where it is determined through the SUPI that the USIM of the terminal does not support a first encryption algorithm, decapsulating the encapsulated first key to obtain the first key, and obtaining authentication information according to the first key and the second key.

2. The method of claim 1, wherein, Further comprising: storing the first key and the SUPI in association.

3. The method of claim 1, wherein, The obtaining of the authentication information according to the first key and the second key comprises: obtaining first information according to a second encryption algorithm and the second key; obtaining second information according to a random number in the first information, the first key and the first encryption algorithm; obtaining authentication related information according to the first information and the second information; obtaining the authentication information according to the authentication related information.

4. The method of claim 3, wherein, The obtaining of the authentication related information according to the first information and the second information comprises: obtaining a fifth key based on a third key and a fourth key in the second information; obtaining a third authentication token based on the fifth key, a first authentication token in the first information and a second authentication token in the second information; obtaining a third expected response value based on a first expected response value in the first information and a second expected response value in the second information; obtaining a seventh key based on the third key and a sixth key in the first information; obtaining a ninth key based on the fourth key and an eighth key in the first information; taking the random number, the third authentication token, the third expected response value, the seventh key and the ninth key as the authentication related information.

5. The method of claim 4, wherein, The obtaining of the third authentication token based on the fifth key, the first authentication token in the first information and the second authentication token in the second information comprises: concatenating the first authentication token and the second authentication token, and encrypting the concatenated result using the fifth key to obtain the third authentication token; or encrypting the first authentication token using the fifth key, and concatenating the encrypted result and the second authentication token to obtain the third authentication token.

6. The method according to claim 4 or 5, characterized in that, The obtaining of the authentication information according to the authentication related information comprises: obtaining a tenth key based on the seventh key and the ninth key; obtaining a fourth expected response value based on the third expected response value; taking the random number, the third authentication token, the fourth expected response value and the ninth key as the authentication information.

7. The method of claim 1, wherein, After the obtaining of the authentication information according to the first key and the second key, further comprising: sending a random number and a third authentication token in the authentication information to the terminal.

8. The method of claim 7, wherein, After the sending of the random number and the third authentication token in the authentication information to the terminal, further comprising: receiving a first response value sent by the terminal; According to the first response value, it is determined whether the authentication is successful.

9. An authentication processing method characterized by comprising: Performs by a terminal, comprising: Determining whether a universal subscriber identity module (USIM) supports a first encryption algorithm; In the case that the USIM does not support the first encryption algorithm, sending a subscriber concealed identifier (SUCI) and an encapsulated first key to a network side device, the first key having a length greater than that of a second key, the second key being a key stored by the USIM; The SUCI is used by the network side device to obtain a SUPI, and the SUPI is used by the network side device to determine whether the USIM supports the first encryption algorithm.

10. The method of claim 9, wherein, Before the sending of the SUCI and the encapsulated first key to the network side device, further comprising: Obtaining a public key of a home network corresponding to the USIM; Generating the first key and encapsulating the first key using the public key to obtain the encapsulated first key.

11. The method of claim 9, wherein, After the sending of the SUCI and the encapsulated first key to the network side device, further comprising: Receiving a random number and a third authentication token sent by the network side device; Obtaining a first authentication token according to the first key, the random number and the third authentication token.

12. The method of claim 11, wherein, After the obtaining of the first authentication token according to the first key, the random number and the third authentication token, further comprising: Verifying according to the first authentication token; Determining a first response value in the case that the verification is passed; Sending the first response value to the network side device.

13. The method of claim 11, wherein, The obtaining of the first authentication token according to the first key, the random number and the third authentication token comprises: Obtaining second information based on the first key and the random number; Obtaining a fifth key based on third and fourth keys in the second information; Decrypting the third authentication token using the fifth key to obtain the first authentication token and a fourth authentication token, or determining third information and the fourth authentication token based on the third authentication token and decrypting the third information using the fifth key to obtain the first authentication token.

14. The method of claim 13, wherein, Further comprising: Verifying the fourth authentication token according to a second authentication token in the second information.

15. The method of claim 12, wherein, The determining of the first response value in the case that the verification is passed comprises: Obtaining first information according to a second encryption algorithm and the second key; Obtaining the first response value based on a first expected response value in the first information and a second expected response value in second information.

16. The method of claim 12, wherein, Further comprising: Obtaining a seventh key based on a sixth key in first information and a third key in second information; Obtaining a ninth key based on an eighth key in the first information and a fourth key in the second information.

17. An authentication processing apparatus characterized by comprising: Comprising: A first receiving module, configured to obtain a subscriber concealed identifier (SUCI) and an encapsulated first key sent by a terminal; wherein the first key has a length greater than that of a second key, and the second key is a key stored by a universal subscriber identity module (USIM); A first processing module, configured to decrypt the SUCI to obtain a subscriber permanent identifier (SUPI); The second processing module is configured to, in a case where it is determined by the SUPI that the USIM of the terminal does not support the first encryption algorithm, unpack the packaged first key to obtain the first key, and obtain authentication information according to the first key and the second key.

18. An authentication processing apparatus characterized by comprising: Comprise: The third processing module is configured to determine whether the USIM supports the first encryption algorithm. The first sending module is configured to, in a case where the USIM does not support the first encryption algorithm, send a SUCI and a packaged first key to a network side device, the first key having a length greater than that of a second key, and the second key being a key stored by the USIM. The SUCI is used by the network side device to decrypt to obtain a SUPI, and the SUPI is used by the network side device to determine whether the USIM supports the first encryption algorithm.

19. A network-side device, comprising: Comprise a processor and a transceiver, The transceiver is configured to acquire a SUCI and a packaged first key sent by a terminal, the first key having a length greater than that of a second key, and the second key being a key stored by a USIM. The processor is configured to decrypt the SUCI to obtain a SUPI. The processor is further configured to, in a case where it is determined by the SUPI that the USIM of the terminal does not support the first encryption algorithm, unpack the packaged first key to obtain the first key, and obtain authentication information according to the first key and the second key.

20. A terminal, characterized by Comprise a processor and a transceiver, The processor is configured to determine whether a USIM supports a first encryption algorithm. The transceiver is configured to, in a case where the USIM does not support the first encryption algorithm, send a SUCI and a packaged first key to a network side device, the first key having a length greater than that of a second key, and the second key being a key stored by the USIM. The SUCI is used by the network side device to decrypt to obtain a SUPI, and the SUPI is used by the network side device to determine whether the USIM supports the first encryption algorithm.

21. A communication device comprising: A transceiver, a processor, a memory, and a program or instructions stored on the memory and executable on the processor; characterized by, the processor implements the authentication processing method of any one of claims 1-8, or the authentication processing method of any one of claims 9-16 when executing the program or instructions.

22. A readable storage medium, on which a program or instructions are stored, characterized in that, The program or instructions are executed by the processor to implement the steps of the authentication processing method of any one of claims 1-8, or the authentication processing method of any one of claims 9-16.

23. A computer program product, characterised in that, Comprise computer instructions, the computer instructions are executed by the processor to implement the steps of the authentication processing method of any one of claims 1-8, or the authentication processing method of any one of claims 9-16.

Citation Information

Patent Citations

  • 5G-AKA authentication method, unified data management network element and user equipment

    CN111770496A

  • Registration and security enhancement for WTRU with multiple usim

    CN114342436A