A communication network anonymous authentication method, user equipment, home network and product
By calculating network-side parameter values and encrypting SUPI in 5G communication networks, combined with post-quantum cryptography algorithms, replay attacks can be identified, solving the problem of easy tracking of user location information and achieving effective protection of user privacy.
Patent Information
- Application Number
- CN202410524800.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-29
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2044-04-29
AI Technical Summary
In existing 5G communication networks, user location information is vulnerable to tracking attacks, leading to privacy leaks.
By working together with user equipment and home network, network-side parameter values are calculated using encrypted parameter values to identify replay attacks. SUPI is encrypted using a post-quantum cryptography algorithm to generate SUCI for identity identification transmission. Combined with a general user identity module to verify authentication tokens, the legality and synchronization of authentication data are ensured.
It effectively identifies replay attacks, protects user location information from being tracked, improves the privacy and security of communication networks, and prevents the leakage of user location information.
Smart Images

Figure CN118802305B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and more specifically, to a method for anonymous authentication of communication networks, user equipment, home network, and related products. Background Technology
[0002] With the rapid development of Internet technology, the network security risks of information systems continue to increase, and the threats and challenges are becoming increasingly severe. Cryptographic security is an important foundation of information security and can be used to effectively protect the data security of network information systems. Cryptographic technology is a core technology and an important means to protect network information systems.
[0003] Currently, 5G communication networks use the AKA protocol to complete two-way authentication between terminals and the network. They also encrypt and encapsulate the SUPI (Subscription Permanent Identifier) to generate the SUCI (Subscription Concealed Identifier), which is then used as the identity identifier for transmission over the air interface, thus improving the security of the SUPI at the air interface. However, existing solutions are vulnerable to tracking attacks targeting user location information, leading to the leakage of user location data. Summary of the Invention
[0004] To address the aforementioned issues, this invention proposes an anonymous authentication method, user equipment, home network, and product for communication networks, which can identify tracking attacks targeting user location information and protect the privacy and security of end users.
[0005] This invention provides an anonymous authentication method for communication networks, the method being executed by a user equipment, the method comprising:
[0006] The network-side parameter values are calculated based on the encryption parameter values in the received authentication data.
[0007] Replay attacks are identified based on the magnitude of the network-side parameter values and the locally stored terminal parameter values.
[0008] Preferably, identifying replay attacks based on the magnitude of the network-side parameter values and the locally stored terminal parameter values includes:
[0009] When the network-side parameter value is greater than the terminal parameter value, it is determined that the authentication data is not a replay attack;
[0010] If the network-side parameter value is not greater than the terminal parameter value, the authentication data is determined to be a replay attack.
[0011] Preferably, the network-side parameter values are calculated based on the encryption parameter values in the received authentication data, including:
[0012] The network-side parameter value is obtained by decrypting the encrypted parameter value using a symmetric decryption function and a pre-stored temporary symmetric key; or, the network-side parameter value is obtained by calculating the encrypted parameter value using an XOR function decryption algorithm and a pre-stored temporary symmetric key.
[0013] As a preferred embodiment, the method further includes:
[0014] When the authentication data is determined to be a replay attack, the error parameter value is calculated based on the terminal parameter value, and the message of the error parameter value is identified by the general user identity module. The authentication error message is then fed back to the security anchor function network element of the service network.
[0015] Wherein, the error parameter value RAND-1 = HASH(K_KEM, RAND_UE), HASH() is a hash calculation, K_KEM is a temporary symmetric key, and RAND_UE is the terminal parameter value.
[0016] Preferably, the method further includes:
[0017] When it is determined that the authentication data is not a replay attack, the terminal parameter value is updated with the network-side parameter value, and the real parameter value is calculated based on the updated terminal parameter value.
[0018] Wherein, the actual parameter value RAND-2 = HASH(K_KEM, RAND_UE), HASH() represents hash calculation, K_KEM is the temporary symmetric key, and RAND_UE is the updated terminal parameter value.
[0019] Furthermore, the method also includes:
[0020] The authentication token in the authentication data is verified by the configured general user identity module. When the authentication vector is found to be out of sync with SQN, the AUTS parameter is generated. The AUTS parameter and the encrypted parameter value are sent to the security anchor function network element of the service network so that the security anchor function network element forwards the encrypted parameter value and the AUTS parameter to the home network, thereby completing the legality verification of the encrypted parameter value and the AUTS parameter and the synchronization of the SQN parameter.
[0021] Preferably, the method further includes:
[0022] Read the SUPI of the configured general user identity module, encrypt the SUPI using a key-based encryption mechanism, and obtain the SUCI;
[0023] Set and store the terminal parameter values;
[0024] Save the temporary symmetric key generated during the SUPI encryption process;
[0025] The SUCI is sent to the home network via the security anchor function network element of the serving network through an initialization request message, so that the home network completes the authentication process and returns the authentication data.
[0026] Preferably, the method further includes:
[0027] The authentication data is received through the configured general user identity module, and the separation bit of the authentication token AMF field in the authentication data is checked to see if it is 1. The authentication token is verified, and RES is calculated when the authentication token is verified.
[0028] RES* is calculated based on RES, and the AUSF key K is derived from the key negotiation key CK and the integrity key IK. AUSF This leads to the derivation of SEAF's key K. SEAF ;
[0029] The authentication response of the NAS message feeds back RES* to the security anchor function network element of the serving network, so that the security anchor function network element can perform service network authentication based on the encryption parameter value and RES* calculated by RES*, as well as HXRES* sent by the home network, and feed back the service network authentication message to the authentication server function network element of the home network after successful authentication.
[0030] This invention also provides a method for anonymous authentication in a communication network, the method being executed by the home network, the method comprising:
[0031] The unified data management function network element of the home network calculates the real parameter value based on the generated network-side parameter value and the temporary symmetric key, encrypts the real parameter value to obtain the encrypted parameter value, generates an authentication vector based on the encrypted parameter value, and sends the authentication vector to the authentication server function network element of the home network.
[0032] The authentication server function element performs derivation processing on the authentication vector to generate authentication data, and forwards the updated authentication vector to the user equipment through the security anchor function element of the service network, so that the user equipment can perform authentication based on the vector parameters in the authentication vector.
[0033] Preferably, generating the authentication vector based on the encryption parameter value includes:
[0034] The unified data management function network element increments and stores the network-side parameter values; based on the actual parameter values, XRES, key negotiation key CK, and integrity key IK, the AUSF key K is derived through a KDF one-way function. AUSF and XRES*; create a database containing the encrypted parameter values, authentication token, and key K. AUSF And the authentication vector AV of XRES*.
[0035] Preferably, the method further includes:
[0036] The unified data management function network element receives the encrypted parameter value and AUTS parameter forwarded by the security anchor function network element; decrypts the encrypted parameter value using a temporary symmetric key to obtain the network-side parameter value, and calculates the real parameter value based on the network-side parameter value and the temporary symmetric key; verifies the legality of the real parameter value and AUTS parameter, and synchronizes the SQN parameter.
[0037] Preferably, the authentication server functional network element performs derivation processing on the authentication vector to generate authentication data, including:
[0038] The authentication server functional network element receives and stores the AUSF key K of the authentication vector. AUSF And XRES*;
[0039] Calculate HXRES* based on the encryption parameter value and XRES*;
[0040] According to the AUSF key K AUSF Derive the key K of SEAF SEAF ;
[0041] Based on the key K of HXRES* and SEAF SEAF The key K of the AUSF that replaces the authentication vector AUSF And XRES*, update the authentication vector;
[0042] Delete SEAF key K SEAF The updated authentication vector is sent to the security anchor function network element, so that the security anchor function network element forwards authentication data containing encryption parameter values and authentication tokens to the user equipment; the authentication data also includes information for identifying K. AMF And ngKSI with some native security context, as well as ABBA parameters.
[0043] Preferably, the method further includes:
[0044] The authentication server function element receives the service network authentication message sent by the security anchor function element of the service network. Based on the stored XRES* and the RES* in the service network authentication message, it performs home network authentication. Upon successful authentication, it sends a home network authentication message back to the security anchor function element, enabling the security anchor function element to provide ngKSI and K to the AMF. AMF It provides communication services for user equipment.
[0045] This invention also provides a user equipment that sends a method for performing anonymous authentication of a communication network as described in any of the above embodiments.
[0046] This invention also provides a home network for performing the anonymous authentication method for communication networks as described in any of the above embodiments.
[0047] This invention also provides a computer program product, including a computer program / instructions, which, when executed by a processor, implement the steps of the anonymous authentication method for communication networks as described in any of the above embodiments.
[0048] This invention provides a method for anonymous authentication in communication networks, a user equipment, a home network, and a product. It calculates network-side parameter values based on encrypted parameter values in received authentication data; and identifies replay attacks by comparing the network-side parameter values with locally stored terminal parameter values. This solution can identify tracking attacks targeting user location information, protecting the privacy and security of end users. Attached Figure Description
[0049] Figure 1 This is a flowchart illustrating an anonymous authentication method for communication networks provided in an embodiment of the present invention;
[0050] Figure 2 This is a schematic diagram of the interaction process of the anonymous authentication method for communication networks provided in an embodiment of the present invention;
[0051] Figure 3 This is another interactive flow diagram of the anonymous authentication method for communication networks provided in this embodiment of the invention;
[0052] Figure 4 This is another interactive flowchart of the anonymous authentication method for communication networks provided in this embodiment of the invention. Detailed Implementation
[0053] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0054] Currently, 5G communication networks use the AKA protocol to complete two-way authentication between the terminal and the network. At the same time, in order to improve the security of the Subscription Permanent Identifier (SUPI) on the air interface, when the SUPI needs to be transmitted through the air interface, the terminal uses the public key of its home network to encrypt and encapsulate the SUPI using the ECIES (Elliptic Curve Integrated Encryption Scheme) algorithm to generate the SUCI (Subscription Concealed Identifier). The SUCI is then used as the identity identifier for transmission through the air interface, thereby ensuring the privacy and security of the terminal user and preventing attacks such as tracking.
[0055] However, existing technical solutions still face the risk of being tracked and attacked. In the eavesdropping phase, attackers use sniffing tools to eavesdrop on the target UE's area via air interface and save the target UE's authentication data (RAND, AUTN). In the active attack phase, if the attacker wants to determine if the target UE is in a certain area, they broadcast authentication data (RAND, AUTN) through a fake base station in the area where the target UE might appear. UEs receiving authentication requests near the fake base station will process the authentication data. In the eavesdropping phase, attackers use sniffing tools to eavesdrop on the target UE's area via air interface and save the SUCI sent by the target UE during initial registration. In the active attack phase, if the attacker wants to determine if the target UE is in a certain area, they send a strong signal through a fake base station in the area where the target UE might appear, causing nearby UEs to attach to the fake base station and initiate deregistration requests to nearby UEs, causing the UEs to re-initiate registration requests, thus sending SUCI_new to the network side. After receiving SUCI_new, the fake base station replaces SUCI_new with the old SUCI and submits it to nearby normal base stations. After receiving the SUCI, the network side returns an authentication message (RAND, AUTN). The fake base station forwards the authentication message to nearby UEs. UEs near the fake base station that receive the authentication request will process the authentication data. This ultimately leads to the leakage of user location information.
[0056] Given the vulnerability of existing technologies to attacks that could lead to the leakage of user location information, this application provides an anonymous authentication method for communication networks. This method is executed by the user equipment. (See [link to relevant documentation]). Figure 1 This is a flowchart illustrating an anonymous authentication method for communication networks provided in an embodiment of the present invention. The method includes:
[0057] Step S1: Calculate the network-side parameter values based on the encryption parameter values in the received authentication data;
[0058] Step S2: Identify replay attacks based on the magnitude of the network-side parameter values and the locally stored terminal parameter values.
[0059] In a specific implementation of this embodiment, the authentication data in the NAS message sent by the security anchor function network element of the receiving service network is received;
[0060] The encryption parameter value RAND* is obtained from the authentication data, and the network-side parameter value RAND_HN is calculated based on the encryption parameter value in the received authentication data.
[0061] The network-side parameter value RAND_HN is obtained by calculating based on the pre-stored key and the encryption parameter value RAND*.
[0062] It should be noted that the key is generated by the user equipment when sending the SUCI during the main authentication initiation and identity submission process.
[0063] It should be noted that the terminal parameter values stored locally are also generated when SUCI is sent during the main authentication startup and identity submission process.
[0064] Based on the magnitude of the network-side parameter values and the locally stored terminal parameter values, it can be determined whether the authentication data is a replay attack, thereby identifying replay attacks on the authentication data and avoiding the problem of user location information leakage due to replay attacks.
[0065] The key generated by the user equipment during the authentication process can be used to encrypt parameter values and identify replay attacks, thus protecting authentication security.
[0066] In another embodiment of the present invention, when performing replay attack identification, the network side parameter value RAND_HN is calculated based on the encrypted parameter value in the received authentication data, and the size of the network side parameter value RAND_HN and the locally stored terminal parameter value RAND_UE is determined.
[0067] When the network-side parameter value RAND_HN is greater than the terminal parameter value RAND_UE, it indicates that the encryption parameter value in the authentication data is a fresh RAND*, and therefore the authentication data is determined not to be a replay attack.
[0068] When the network-side parameter value RAND_HN is not greater than the terminal parameter value RAND_UE, it indicates that the encrypted parameter value in the authentication data is not a fresh RAND*, and this encrypted parameter value has been used before. Therefore, the authentication data is determined to be a replay attack.
[0069] By comparing the network-side parameter values with the locally stored terminal parameter values, it is possible to determine whether the received authentication data is up-to-date and identify external replay attacks.
[0070] In another embodiment provided by the present invention, the following scheme is specifically adopted when calculating the network-side parameter values in step S1:
[0071] The encrypted parameter value is calculated using a symmetric decryption function and a pre-stored temporary symmetric key to obtain the network-side parameter value. Specifically, the user terminal decrypts the encrypted parameter value RAND* using the temporary symmetric key K_KEM to obtain the network-side parameter value RAND_HN, where RAND_HN = D(K_KEM, RAND*).
[0072] Among them, the symmetric encryption function is: C = E(K, M), which uses the symmetric key K to symmetrically encrypt M, and E is a quantum-safe symmetric encryption algorithm.
[0073] Symmetric decryption function: M = D(K, C), which uses the symmetric key K to symmetrically decrypt C, and D is a quantum-safe symmetric decryption algorithm.
[0074] Other algorithms can also be used for encryption and decryption calculations. For example, during encryption, the encryption parameter value RAND* = K_KEM, xor RAND_HN. During decryption, a symmetric decryption function and a pre-stored temporary symmetric key are used to decrypt the encryption parameter value to obtain the network-side parameter value.
[0075] When decrypting, a decryption algorithm corresponding to the encryption algorithm is used. The encryption and decryption algorithm disclosed in this application is only a preferred implementation method. In specific implementation, other encryption and decryption algorithms may be used.
[0076] This application uses a temporary symmetric key for encryption and decryption to ensure the security of authentication data.
[0077] In another embodiment of the invention, after identifying a replay attack, the user equipment further updates the parameter values based on the identification result, specifically including the following steps:
[0078] When the authentication data is determined to be a replay attack, an error parameter value is calculated based on the terminal parameter value. The error parameter value RAND-1 = HASH(K_KEM, RAND_UE), where HASH() is a hash calculation, K_KEM is a temporary symmetric key, and RAND_UE is the terminal parameter value. It is recommended that RAND be 128 bits long, where K_KEM and RAND_UE can be combined using the same combination method as the network-side HN before hash calculation.
[0079] It should be noted that when a replay impact is detected, there are theoretically an infinite number of ways to generate an error parameter value. As long as any value other than the true parameter value is generated, it can be used as an error parameter value. For example, any value other than the true parameter value can be randomly generated as the error parameter value.
[0080] The message that identifies the incorrect parameter value through the general user identity module is fed back to the security anchor function network element of the service network, so that the service network forwards the authentication error message to the home network, and the home network recognizes this replay attack.
[0081] After a replay attack is detected, the error parameter value is calculated to enable the home network to identify the replay attack, thereby achieving the same level of network-side attack identification and preventing home network data leakage.
[0082] In another embodiment of the present invention, after identifying a replay attack, the user equipment further updates the parameter values based on the identification result, specifically including the following steps:
[0083] When it is determined that the authentication data is not a replay attack, the terminal parameter value is updated with the network-side parameter value. Specifically, the ME-side RAND parameter value RAND_UE = RAND_HN is set, and the real parameter value is calculated based on the updated terminal parameter value. The real parameter value RAND-2 = HASH(K_KEM, RAND_UE), where HASH() represents hash calculation, K_KEM is the temporary symmetric key, and RAND_UE is the updated terminal parameter value. It is recommended that the length of RAND be 128 bits, where K_KEM and RAND_UE can be combined using the same combination method as the network-side HN before hash calculation.
[0084] When the authentication data is determined not to be a replay attack, the terminal's parameter values are updated based on the received authentication data to ensure that the terminal parameter values stored in the user device are up-to-date, thus avoiding misidentification of replay attacks due to outdated terminal parameter values.
[0085] In yet another embodiment provided by the present invention, see Figure 2This is a schematic diagram of the interaction process of the anonymous authentication method for communication networks provided in the embodiments of the present invention; the method further includes that the mobile device ME of the user equipment UE completes the replay impulse detection and terminal parameter value update, and sends the updated real parameter value RAND and the authentication token AUTN in the authentication data to the general user identity module USIM;
[0086] The Universal User Identity Module (USIM) generates an SQN (Synchronization Issue) when verifying the AUTN. When the authentication vector is found to be out of sync with the SQN, the USIM generates AUTS parameters.
[0087] The generated AUTS parameters are returned to the mobile device ME, which then sends the AUTS parameters to the Security Anchor Function (SEAF) element of the serving network SN.
[0088] The Security Anchor Function (SEAF) of the Serving Network (SN) sends the parameter values RAND and AUTS to the Unified Data Management (UDM) of the Home Network (HN) via the Syn_failure error message. At this time, the uploaded parameter value RAND is actually the encrypted parameter value RAND*.
[0089] The UDM of the unified data management network element belonging to the network HN verifies the validity of the AUTS parameter and synchronizes the SQN parameter.
[0090] The user terminal synchronizes the authentication data identified by the user equipment to the home network through the authentication synchronization fault recovery process to perform SQN data recovery.
[0091] In another embodiment of the present invention, before replay attack identification, the user terminal needs to perform a master authentication initiation and identity submission process, see [link to relevant documentation]. Figure 3 This is another interactive flow diagram of the anonymous authentication method for communication networks provided in this embodiment of the invention.
[0092] When the network side requires the user equipment (UE) to send SUCI for network authentication, the UE's mobile device (ME) reads the SUPI configured in the general user identity module, encrypts the SUPI using KEM_ENC to obtain the SUCI, and at the same time, the UE's mobile device (ME) secretly stores the temporary symmetric key K_KEM generated during the KEM_ENC encryption process.
[0093] Set the RAND terminal parameter value on the UE side to RAND_UE = 0, and save the parameter value.
[0094] The User Equipment (UE) sends an Initial Registration Request to the network side, which forwards it through the Security Anchor Function (SEAF) element of the Serving Network (SN) to the Unified Data Management (UDM) element of the Home Network (HN) to complete the authentication process. The UE then feeds back the authentication data to the UE. The user receives the authentication data and uses it to identify replay attacks, thereby improving security.
[0095] Existing technologies generally employ ECIES (Elliptic Curve Integrate Encryption Scheme): 5G AKA uses ECIES to encrypt SUPI to generate SUCI, mainly including two algorithms: ECIES_ENC (encryption): Input public key PK and plaintext M, output C; Encap_ECIES(PK): Generate a temporary public-private key pair (eSK, ePK) using KeyGen(pp), generate a temporary symmetric key sk based on PK and eSK, output (sk, ePK); SEnc_ECIES(sk, M): Encrypt and protect the integrity of M using the temporary key sk to obtain C1 and C2, output C = (ePK, C1, C2). ECIES_DEC (decryption): Input private key SK and ciphertext C, output plaintext M; Decap_ECIES(SK): Generate a temporary key sk based on SK and ePK, output sk; SDec_ECIES(sk, C): Decrypt and verify the integrity of C using the temporary key sk, output M.
[0096] Because ECIES currently uses the elliptic curve cryptography algorithm ECC, which is vulnerable to quantum attacks, this application replaces the ECC algorithm in ECIES with a post-quantum cryptography algorithm (PQC). Therefore, KEM_ENC or KEM_DEC in the scheme description can simultaneously support algorithms such as ECIES_KEM or PQC_KEM, thereby improving encryption security.
[0097] In yet another embodiment provided by the present invention, see Figure 4 This is another interactive flow diagram of the anonymous authentication method for communication networks provided in the embodiments of the present invention.
[0098] After receiving the authentication data, the user equipment (UE) mobile device (ME) decrypts it using the key K_KEM.
[0099] RAND* yields RAND_HN = D(K_KEM, RAND*);
[0100] Determine if RAND_HN is greater than the locally stored RAND_UE;
[0101] If RAND_HN > RAND_UE, it indicates that it is a fresh RAND*, and the RAND parameter value on the ME side is set to RAND_UE = RAND_HN.
[0102] If RAND_HN≤RAND_UE, it means that RAND* is being replayed, and an incorrect RAND is being generated, such as RAND = HASH(K_KEM, RAND_UE), or it is being generated randomly. Since the RAND is incorrect, USIM will return an authentication error MAC_failure in subsequent steps.
[0103] After the User Equipment (ME) forwards RAND and AUTN to the Universal Subscriber Identity Module (USIM), it receives the authentication data through the USIM and checks whether the separation bit of the AMF field in the authentication token AUTN is 1. The ME then verifies the authentication token. For 5G access, the ME should check whether the separation bit of the AUTN's AMF field is set to 1 during authentication. The separation bit is the 0th bit of the AUTN's AMF field. Note: This separation bit in the AUTN's AMF cannot be used for operator-specific purposes.
[0104] When the authentication token is successfully verified, RES is calculated. RES, or response, is a type of data used for authentication, which is calculated by USIM based on RAND and AUTN and returned to ME.
[0105] The response RES* is calculated based on the RES. RES* is a type of data used for 5G authentication, calculated by the ME based on the RES and sent to the network for comparison with the network's RES.
[0106] The AUSF key K is derived from the key negotiation key CK and the integrity key IK. AUSF ,
[0107] The UE should return RES* to the Security Anchor Function (SEAF) element of the serving network SN in the NAS message authentication response.
[0108] The Security Anchor Function (SEAF) element should calculate HRES* from RAND and RES*, and compare HRES* and HXRES* for serving network authentication. If the two values match, SEAF should consider authentication successful from the perspective of the serving network. If they do not match, SEAF should consider authentication failed and indicate the failure to AUSF. In this case, the RAND used by SEAF for calculation is actually RAND*.
[0109] The Security Anchor Function (SEAF) element should send the corresponding SUCI or SUPI from the User Terminal (UE) to the Home Network Authentication Server (AUSF) element via the Nausf_UEAuthentication_Authenticate Request message for home network authentication.
[0110] Improve the security of network authentication by providing network authentication services.
[0111] Another embodiment of the present invention provides an anonymous authentication method for a communication network. The method is executed by the Unified Data Management (UDM) function network element and the Authentication Server (AUSF) function network element of the Home Network (HN). For specific execution details, please refer to... Figure 3 :
[0112] The Unified Data Management (UDM) network element of the home network receives the Nudm_Authenticate_Get Request message SUCI sent by the Security Anchor (SEAF) network element of the serving network SN;
[0113] SUPI was decrypted using KEM_DEC.
[0114] After the Unified Data Management (UDM) element of the home network (HN) obtains the SUPI, it creates a 5G HE AV (RAND, AUTN, XRES, CK, IK). For specific creation instructions, please refer to [link / reference needed]. Figure 4 :
[0115] The real parameter value RAND = HASH(K_KEM, RAND_HN) is calculated based on the generated network-side parameter value and the temporary symmetric key. It is recommended that the length of RAND be 128 bits. K_KEM and RAND_HN can be combined in a certain way before hash calculation. For example, K_KEM||RAND_HN or K_KEM xor RAND_HN.
[0116] The calculated value is AV = (RAND, AUTN, XRES, CK, IK);
[0117] The encryption parameter value RAND* = E(K_KEM, RAND_HN) is obtained by encrypting RAND_HN using the key K_KEM. It is recommended that the output block length of the symmetric encryption algorithm E be 128 bits to ensure compatibility with the original protocol.
[0118] Increment and save RAND_HN: RAND_HN = RAND_HN + DELTA, where DELTA can be 1 or any other smaller value.
[0119] An authentication vector is generated based on the encryption parameter value; the authentication vector, which includes the encryption parameter value RAND* and the authentication token AUTN, is sent to the authentication server function element AUSF of the home network.
[0120] The Authentication Server Functional Element (AUSF) performs derivation processing on the authentication vector to generate authentication data, and forwards the updated authentication vector to the User Equipment (UE) through the Security Anchor Functional Element (AEAF) of the serving network. This enables the UE to perform authentication based on the vector parameters in the authentication vector, identify the authentication data encrypted by the home network authentication vector, distinguish this authentication data from the authentication data of replay attacks, and accurately identify replay attacks.
[0121] In another embodiment of the present invention, the Unified Data Management Function (UDM) of the Home Network (HN) generates an authentication vector based on the encryption parameter value, including:
[0122] The Unified Data Management Function (UDM) network element increments and saves the network-side parameter values: RAND_HN = RAND_HN + DELTA, where DELTA can be 1 or any other smaller value.
[0123] The Unified Data Management Function (UDM) network element uses RAND, XRES, key negotiation key CK, and integrity key IK to derive KAUSF and XRES* through the KDF one-way function;
[0124] Create a database containing the encrypted parameter values, authentication token, and key K. AUSF The authentication vector AV of XRES* is sent to the authentication server function element of the home network.
[0125] In yet another embodiment of the present invention, the Unified Data Management Function (UDM) performs a synchronization fault recovery process, see [link to relevant documentation]. Figure 2 :
[0126] After receiving the encrypted parameter value and AUTS parameter forwarded by the security anchor function network element, the Unified Data Management Function Network Element (UDM) decrypts the network-side parameter value RAND_HN and uses the key K_KEM to decrypt RAND* to obtain the network-side parameter value RAND_HN = D(K_KEM, RAND*), and calculates the real RAND = HASH(K_KEM, RAND_HN).
[0127] The Unified Data Management (UDM) function network element verifies the legitimacy of (RAND, AUTS) and synchronizes SQN parameters to complete the synchronization fault recovery process.
[0128] In another embodiment of the present invention, the Authentication Server Functional Element (AUSF) performs derivation processing on the authentication vector to generate authentication data, including:
[0129] The authentication server (AUSF) function element receives and stores the AUSF key K of the authentication vector. AUSF And XRES*;
[0130] The authentication server function element AUSF should generate a 5G AV based on the 5G HE AV received from UDM / ARPF. HXRES* is calculated from RAND and XRES*, and KSEAF is derived from KAUSF. Then, HXRES* and KSEAF in the 5G HE AV are replaced with HXRES* and KSEAF respectively. AUSF .
[0131] Then AUSF should remove K. SEAF The updated authentication vector is sent to the security anchor function network element, so that the security anchor function network element forwards the authentication data containing the encryption parameter value and authentication token to the user equipment, that is, the 5G SE AV (RAND, AUTN, HXRES*) is sent to the SEAF through the Nausf_UEAuthentication_Authenticate response.
[0132] SEAF should send RAND and AUTN to UE via a NAS message (Auth-Req). This message should also contain ngKSI, which is used by UE and AMF to identify KAMF and part of the native security context, and should also include the ABBA parameter.
[0133] In another embodiment of the present invention, after the Authentication Server Functional Network Element (AUSF) receives the service network authentication message sent by the security anchor functional network element of the service network, that is, when it receives the Nausf_UEAuthentication_Authenticate Request message containing RES*, the AUSF can verify whether the AV has expired. If the AV has expired, the AUSF can consider the authentication unsuccessful from the perspective of the home network. The AUSF should compare the received RES* with the stored XRES*. If RES* and XRES* are consistent, the AUSF should consider the authentication successful from the perspective of the home network.
[0134] AUSF should indicate to SEAF whether authentication was successful via the Nausf_UEAuthentication_Authenticate Response. If authentication is successful, KSEAF should be sent to SEAF via the Nausf_UEAuthentication_Authenticate Response. If AUSF receives SUCI from SEAF upon initiating authentication and authentication is successful, AUSF should also include SUPI in the Nausf_UEAuthentication_Authenticate Response.
[0135] If authentication is successful, SEAF should use the key KSEAF received from the Nausf_UEAuthentication_Authenticate Response message as the anchor key. SEAF should then derive KAMF from KSEAF, the ABBA parameters, and SUPI, and provide ngKSI and KAMF to AMF.
[0136] If SUCI is used for this authentication, SEAF should only provide ngKSI and KAMF to AMF after receiving a Nausf_UEAuthentication_Authenticate Response message containing SUPI; communication services will not be provided to the UE until the serving network is aware of the SUPI.
[0137] This invention also provides a user equipment, which sends a method for executing any of the communication network anonymous authentication methods executed by the user equipment in the above embodiments.
[0138] This invention also provides a home network, which is used to execute any of the communication network anonymity authentication methods executed by the home network in the above embodiments.
[0139] This invention also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of any of the communication network anonymous authentication methods described in the above embodiments.
[0140] It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this invention, and these improvements and modifications are also considered to be within the scope of protection of this invention.
Claims
1. A communication network anonymous authentication method characterized by, The method is executed by a user equipment, and the method comprises: calculating a network-side parameter value according to an encryption parameter value in received authentication data; identifying a replay attack according to the size of the network-side parameter value and a locally stored terminal parameter value; The method further comprises: reading a SUPI of a configured universal subscriber identity module, encrypting the SUPI using an encryption mechanism based on key encapsulation to obtain a SUCI; setting and storing the terminal parameter value of the terminal; saving a temporary symmetric key generated in the SUPI encryption process; sending the SUCI to a home network through a security anchor function network element of a service network through an initialization request message, so that the home network completes an authentication process and feeds back the authentication data.
2. The communication network anonymous authentication method according to claim 1, characterized by, The method further comprises: when the network-side parameter value is greater than the terminal parameter value, determining that the authentication data is not a replay attack; when the network-side parameter value is not greater than the terminal parameter value, determining that the authentication data is a replay attack.
3. The communication network anonymous authentication method according to claim 1, characterized by, The method further comprises: decrypting and calculating the encryption parameter value using a symmetric decryption function and a pre-stored temporary symmetric key to obtain the network-side parameter value; or calculating the encryption parameter value using an exclusive or function decryption algorithm and a pre-stored temporary symmetric key to obtain the network-side parameter value.
4. The communication network anonymous authentication method according to claim 1, characterized by, The method further comprises: when it is determined that the authentication data is a replay attack, calculating an error parameter value according to the terminal parameter value, and feeding back an authentication error message to a security anchor function network element of a service network through a message of a general user identity module identifying an error parameter value; wherein the error parameter value RAND — 1 = HASH(K_KEM, RAND_UE), HASH() is a hash calculation, K_KEM is a temporary symmetric key, and RAND_UE is the terminal parameter value.
5. The communication network anonymous authentication method according to claim 1, characterized by, The method further comprises: when it is determined that the authentication data is not a replay attack, updating the terminal parameter value with the network-side parameter value, and calculating a real parameter value according to the updated terminal parameter value; wherein the real parameter value RAND — 2=HASH(K_KEM, RAND_UE), HASH() denotes a hash calculation, K_KEM is a temporary symmetric key, and RAND_UE is the updated terminal parameter value.
6. The communication network anonymous authentication method according to claim 5, characterized by, The method further comprises: verifying an authentication token in the authentication data through a configured general user identity module, generating an AUTS parameter when it is identified that the authentication vector and the SQN are not synchronized, and sending the AUTS parameter and the encryption parameter value to a security anchor function network element of a service network, so that the security anchor function network element forwards the encryption parameter value and the AUTS parameter to a home network to complete legality verification of the encryption parameter value and the AUTS parameter and synchronization of the SQN parameter.
7. The communication network anonymous authentication method according to claim 1, characterized by, The method further comprises: receiving the authentication data through a configured general user identity module, checking whether an authentication token AMF field separation bit in the authentication data is 1, verifying the authentication token, and calculating RES when the authentication token verification is passed; The RES is calculated according to RES*, and the key K of the SEAF is derived according to the key agreement key CK and the integrity key IK AUSF , and further the key K of the SEAF SEAF ; feeding back RES* to a security anchor function network element of a service network through an authentication response of a NAS message, so that the security anchor function network element performs service network authentication according to HRES* calculated from the encryption parameter value and RES*, and HXRES* sent by the home network, and feeds back a service network authentication message to an authentication server function network element of the home network after the authentication is successful.
8. A communication network anonymous authentication method characterized by, The method is executed by a home network, and the method comprises: The unified data management function network element of the home network calculates a real parameter value according to the generated network-side parameter value, encrypts the real parameter value to obtain an encrypted parameter value, generates an authentication vector according to the encrypted parameter value, and sends the authentication vector to an authentication server function network element of the home network; The authentication server function network element performs derivation processing on the authentication vector, generates authentication data, and forwards the updated authentication vector to a user equipment through a security anchor function network element of a service network, so that the user equipment performs authentication according to a vector parameter in the authentication vector.
9. The communication network anonymous authentication method according to claim 8, characterized by, The generating of the authentication vector according to the encrypted parameter value comprises: The unified data management function network element increments and saves the network side parameter value; derives the key K of the AUSF through the KDF one-way function according to the real parameter value, the XRES, the key negotiation key CK and the integrity key IK AUSF and XRES*; creates an authentication vector AV containing the encryption parameter value, the authentication token, the key K AUSF and XRES*.
10. The communication network anonymous authentication method according to claim 8, characterized by, The method further comprises: The unified data management function network element receives the encrypted parameter value and the AUTS parameter forwarded by the security anchor function network element, decrypts the encrypted parameter value by using a temporary symmetric key to obtain the network-side parameter value, calculates a real parameter value according to the network-side parameter value and the temporary symmetric key, verifies the legitimacy of the real parameter value and the AUTS parameter, and synchronizes the SQN parameter.
11. The communication network anonymous authentication method according to claim 8, characterized by, The derivation processing of the authentication vector by the authentication server function network element to generate authentication data comprises: The authentication server function network element receives and saves the key K of the AUSF of the authentication vector AUSF and XRES*; calculating HXRES* according to the encrypted parameter value and XRES*; Key K of the SEAF is derived from the key K of the AUSF AUSF Key K of the SEAF is derived from the key K of the AUSF SEAF ; According to the HXRES* and the SEAF key K SEAF Replacing the AUSF's key K of the authentication vector AUSF And XRES*, updating the authentication vector; Delete SEAF key K SEAF The updated authentication vector is sent to the security anchor function network element, so that the security anchor function network element forwards authentication data containing encryption parameter values and authentication tokens to the user equipment; the authentication data also includes information for identifying K. AMF And ngKSI with some native security context, as well as ABBA parameters.
12. The communication network anonymous authentication method according to claim 8, characterized by, The method further comprises: The authentication server function network element receives a service network authentication message sent by the security anchor function network element of the service network, performs home network authentication according to the stored XRES* and RES* in the service network authentication message, and feeds back a home network authentication message to the security anchor function network element after successful authentication, so that the security anchor function network element provides ngKSI and K to the AMF AMF , and provides communication services for the user equipment.
13. A user equipment, comprising: The user equipment sends a communication network anonymous authentication method as claimed in any one of claims 1 to 7.
14. A home network, characterized by The home network is configured to execute a communication network anonymous authentication method as claimed in any one of claims 8 to 12.
15. A computer program product comprising computer programs / instructions, characterized in that, The computer program / instruction is executed by a processor to implement the steps of the communication network anonymous authentication method as claimed in any one of claims 1 to 12.
Citation Information
Patent Citations
Internet-of things-oriented equipment anonymous identity authentication method and system
CN112953727A
Information processing method, device and equipment
CN113141327A