Communication authentication method and related apparatus, storage medium, computer program product
By using PQC_KEM to encrypt SUPI to generate SUCI and storing the encryption key in the user equipment, the security problem of traditional communication authentication algorithms under the threat of quantum computing is solved, the security of communication authentication is improved, and a full-entropy key is generated, reducing the cost of modification.
Patent Information
- Application Number
- CN202410534242.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-29
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2044-04-29
AI Technical Summary
Traditional communication authentication algorithms have low security when facing quantum computing threats. User devices cannot provide sufficient security capabilities, and keys are difficult to calculate with sufficient entropy, making them vulnerable to attacks.
In the user equipment, the user permanent identifier SUPI is encrypted using the key encapsulation mechanism PQC_KEM based on the post-quantum cryptography algorithm, generating the user hidden identifier SUCI, and storing the symmetric encryption key calculated by PQC_KEM. This key is then forwarded to the target network element in the home network through relevant network elements. The authentication token is processed using the symmetric encryption key to generate and verify keys to improve security.
It improves the security of communication authentication, reduces the risk of keys being cracked in the old USIM, and the generated key provides 256-bit security capabilities. It is low-cost to modify and compatible with the original protocol.
Smart Images

Figure CN118802307B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of network security, and in particular to a communication authentication method and related device, storage medium and computer program product. BACKGROUND
[0002] With the rapid development of Internet technology, the network security risks of information systems continue to increase, and the threat challenges are becoming increasingly severe. Password security is an important basis for information security and can be used to effectively protect the data security of network information systems. Password technology is the core technology and important means for protecting network information systems.
[0003] Currently, the network authentication protocol of the communication network is implemented based on a 128-bit communication authentication algorithm, which is used to complete the authentication and key agreement between the Universal Subscriber Identity Module (USIM) and the Unified Data Management (UDM) in the user equipment. The underlying algorithm of the algorithm is AES-128, and the 128-bit key is shared between the USIM and the UDM.
[0004] However, with the development of quantum computing technology, traditional password algorithms face serious security threats. Quantum computers have powerful computing power, which can greatly reduce the difficulty of breaking symmetric password algorithms. User equipment is difficult to provide 256-bit security capabilities and to calculate a sufficient entropy key, and the randomness is insufficient, which is easy to be attacked by attackers, and the security of communication authentication is low. SUMMARY
[0005] Embodiments of the present application provide a communication authentication method and related device, storage medium and computer program product. In the case that the USIM in the user equipment supports a 128-bit communication authentication algorithm, the symmetric encryption key generated based on PQC_KEM calculation is obtained on the user equipment side and the home network side, which is used to protect the security of authentication tokens and other information, and the security of communication authentication is improved.
[0006] The technical solution of the embodiments of the present application is as follows:
[0007] The embodiments of the present application provide a communication authentication method applied to a mobile equipment ME in a user equipment UE, wherein the UE further includes a Universal Subscriber Identity Module (USIM). The method comprises the following steps:
[0008] In the case that the USIM supports a 128-bit communication authentication algorithm, encrypting a user permanent identifier SUPI of the USIM by using a key encapsulation mechanism PQC_KEM based on a post-quantum cryptography algorithm, generating a user concealed identifier SUCI, and saving a symmetric encryption key generated in the PQC_KEM calculation;
[0009] Forwarding the SUCI to a target network element in a home network through a related network element, so that the target network element obtains the symmetric encryption key based on the SUCI, and forwards a first authentication token processed through the related network element to the ME by using the symmetric encryption key.
[0010] In the above method, the forwarding of the SUCI to the target network element in the home network through the related network element comprises:
[0011] In the initialization of the registration request, the SUCI is forwarded to the target network element through the related network element.
[0012] In the above method, after the saving of the symmetric encryption key generated in the PQC_KEM calculation, the method further comprises:
[0013] Receiving a random number and a second authentication token generated by the target network element, and obtaining the first authentication token by using the symmetric encryption key and the second authentication token; wherein the second authentication token is generated by processing the first authentication token by the symmetric encryption key;
[0014] Sending the random number and the first authentication token to the USIM, so that the USIM performs a synchronization authentication based on the first authentication token, and generates a first encryption key and a first integrity key based on the random number and the first authentication token after the synchronization authentication is passed.
[0015] In the above method, further comprising:
[0016] In the case that the USIM synchronization authentication is passed, receiving the first encryption key and the first integrity key sent by the USIM;
[0017] Based on the first encryption key, constructing a second encryption key by using the symmetric encryption key, and based on the first integrity key, constructing a second integrity key;
[0018] The second encryption key and the second integrity key are used for key derivation.
[0019] In the above method, further comprising:
[0020] In the case that the USIM synchronization authentication is not passed, receiving a first re-synchronization authentication token sent by the USIM;
[0021] processing the first re-synchronization authentication token by using the symmetric encryption key to generate a second re-synchronization authentication token;
[0022] forwarding the second re-synchronization authentication token to the target network element through a related network element.
[0023] The embodiment of the present application provides a communication authentication method, which is applied to a target network element in a home network, and the method comprises the following steps:
[0024] receiving a subscriber concealed identifier SUCI generated by a mobile equipment ME in a user equipment UE; the UE further comprises a universal subscriber identity module USIM, the USIM supports a 128-bit communication authentication algorithm, and the SUCI is generated by encrypting a user permanent identifier SUPI of the USIM by using a post-quantum cryptography algorithm PQC_KEM key encapsulation mechanism;
[0025] decrypting the SUCI by using the PQC_KEM, and saving a symmetric encryption key generated in the PQC_KEM calculation;
[0026] forwarding a first authentication token processed by using the symmetric encryption key to the ME through a related network element.
[0027] In the above method, the step of forwarding the first authentication token processed by using the symmetric encryption key to the ME through the related network element comprises the following steps:
[0028] generating a first vector based on a 128-bit root authentication key of the USIM, wherein the first vector comprises a random number, an expected authentication response, the first authentication token, a first encryption key and a first integrity key;
[0029] processing the first authentication token by using the symmetric encryption key to generate a second authentication token;
[0030] constructing a second encryption key based on the first encryption key and a second integrity key based on the first integrity key by using the symmetric encryption key; the second encryption key and the second integrity key are used for key derivation;
[0031] constructing an authentication vector based on the random number, the expected authentication response, the second authentication token, the second encryption key and the second integrity key; wherein the authentication vector comprises the random number and the second authentication token;
[0032] forwarding the authentication vector through a related network element, so that the second authentication token in the authentication vector is sent to the ME along with the random number.
[0033] In the above method, after the saving of the symmetric encryption key generated in the PQC_KEM calculation, the method further comprises:
[0034] In the case of receiving the second re-synchronization authentication token generated by the ME, a first re-synchronization authentication token is obtained by using the symmetric encryption key and the second re-synchronization authentication token; wherein the second re-synchronization authentication token is generated by processing the first re-synchronization authentication token by the symmetric encryption key.
[0035] The legality of the first re-synchronization authentication token is verified, and the sequence number is synchronized.
[0036] Embodiments of the present application provide an ME, comprising: a first processor, a first memory and a first communication bus;
[0037] The first communication bus is used to realize the communication connection between the first processor and the first memory.
[0038] The first processor is used to execute one or more computer programs stored in the first memory, so as to realize the communication authentication method applied to the ME.
[0039] Embodiments of the present application provide a target network element, comprising: a second processor, a second memory and a second communication bus;
[0040] The second communication bus is used to realize the communication connection between the second processor and the second memory.
[0041] The second processor is used to execute one or more computer programs stored in the second memory, so as to realize the communication authentication method applied to the target network element.
[0042] Embodiments of the present application provide a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to realize the steps in the above communication authentication method.
[0043] Embodiments of the present application provide a computer program product, comprising a computer program, and the computer program is executed by a processor to realize the steps in the above communication authentication method.
[0044] The embodiment of the application provides a communication authentication method and related device, storage medium and computer program product, and the method applied to the ME comprises the following steps: in the case that the USIM supports a 128-bit communication authentication algorithm, the SUPI of the USIM is encrypted by using PQC_KEM to generate SUCI, and a symmetric encryption key generated in the PQC_KEM calculation is saved; the SUCI is forwarded to a target network element in a home network through a related network element, so that the target network element obtains the symmetric encryption key based on the SUCI, and the first authentication token is processed by using the symmetric encryption key and then forwarded to the ME through the related network element. The technical scheme provided by the embodiment of the application is used for the case that the USIM in the user equipment supports the 128-bit communication authentication algorithm, so that the symmetric encryption key generated in the PQC_KEM calculation is obtained on the user equipment side and the home network side, and is used for protecting the security of the authentication token and other information, thereby improving the security of the communication authentication. BRIEF DESCRIPTION OF DRAWINGS
[0045] Figure 1 A flowchart of a communication authentication method provided by the embodiment of the application Figure One ;
[0046] Figure 2 A flowchart of a communication authentication method provided by the embodiment of the application Figure Two ;
[0047] Figure 3 A flowchart of a main authentication starting and identity submission provided by the embodiment of the application
[0048] Figure 4 A flowchart of a main authentication provided by the embodiment of the application
[0049] Figure 5 An operation process provided by the embodiment of the application Figure One ;
[0050] Figure 6 An operation process provided by the embodiment of the application Figure Two ;
[0051] Figure 7 A flowchart of an authentication synchronization fault recovery provided by the embodiment of the application
[0052] Figure 8 A structure of the ME provided by the embodiment of the application Figure One ;
[0053] Figure 9 A structure of the ME provided by the embodiment of the application Figure Two ;
[0054] Figure 10A structure diagram of a target network element provided for an embodiment of the present application Figure One ;
[0055] Figure 11 A structure diagram of a target network element provided for an embodiment of the present application Figure Two . DETAILED DESCRIPTION
[0056] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.
[0057] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be specifically described below through embodiments and in combination with the accompanying drawings. The following embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments.
[0058] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0059] Explanation and description of related terms in the embodiments of the present application:
[0060] Universal Subscriber Identity Module (USIM): stores root authentication key K and identifier data.
[0061] Mobile Equipment (ME): cooperates with USIM to complete network authentication.
[0062] User Equipment (UE): the general term of ME and USIM.
[0063] Security Anchor Function (SEAF) network element: access network implements authentication of UE.
[0064] Authentication Server Function (AUSF): home network implements authentication of UE.
[0065] Unified Data Management (UDM) / Authentication Credential Repository and Processing Function (ARPF): stores subscription information of a user, a core key K, etc.
[0066] ECIES_KEM (Elliptic Curve Integrate Encrypt Scheme): a key encapsulation mechanism (KEM) scheme based on an elliptic curve defined by 3GPP.
[0067] Post Quantum Cryptography (PQC_KEM): a KEM scheme based on a post-quantum public key cryptography technology.
[0068] Key encapsulation mechanism (KEM): C = KEM_ENC (PK, M), encrypts and encapsulates M using a public key PK, and KEM_ENC is a quantum-safe key encapsulation algorithm.
[0069] The embodiment of the application provides a communication authentication method applied to an ME in a UE. Figure 1 The embodiment of the application provides a communication authentication method applied to an ME in a UE. Figure One As shown in the embodiment of the application, the communication authentication method applied to the ME mainly comprises the following steps: Figure 1
[0070] S101, in the case where a 128-bit communication authentication algorithm is supported by a USIM, a user permanent identifier SUPI of the USIM is encrypted by using a post-quantum cryptography algorithm-based key encapsulation mechanism PQC_KEM, a user concealed identifier SUCI is generated, and a symmetric encryption key generated in PQC_KEM calculation is saved.
[0071] In the embodiment of the application, in the case where a 128-bit communication authentication algorithm is supported by a USIM, a user permanent identifier (SUPI) of the USIM is encrypted by using PQC_KEM, a user concealed identifier (SUCI) is generated, and a symmetric encryption key generated in PQC_KEM calculation is saved.
[0072] It can be understood that in the embodiments of the present application, the ME can check whether the USIM supports the 256-bit communication authentication algorithm, if the USIM does not support the 256-bit communication authentication algorithm, supports the 128-bit communication authentication algorithm, then encrypts the SUPI by using the PQC_KEM to obtain the SUCI, and secretly saves the symmetric encryption key generated in the PQC_KEM calculation process, that is, K_KEM (the recommended length is at least 256 bits). Wherein, since the ECIES_KEM is realized based on the elliptic curve and cannot resist quantum attacks, the encryption can be performed by using the PQC_KEM.
[0073] S102, forwarding the SUCI to the target network element in the home network through the related network element, so that the target network element obtains the symmetric encryption key based on the SUCI, and forwards the first authentication token processed by using the symmetric encryption key to the ME through the related network element.
[0074] In the embodiments of the present application, after obtaining the SUCI, the ME can forward it to the target network element in the home network through the related network element.
[0075] In the embodiments of the present application, the ME forwards the SUCI to the target network element in the home network through the related network element, comprising: forwarding the SUCI to the target network element through the related network element when initializing the registration request.
[0076] It should be noted that in the embodiments of the present application, the target network element can be UDM / ARPF, which is not limited in the embodiments of the present application.
[0077] It should be noted that in the embodiments of the present application, the first authentication token is AUTN, and the ME forwards the SUCI to the target network element through the related network element, based on which the target network element can obtain the symmetric encryption key K_KEM based on the SUIC, so that the ME can be provided with the AUTN processed by using K_KEM. Since it is transmitted after being processed by K_KEM, it is actually protected for AUTN, thereby improving the security of communication authentication.
[0078] In the embodiments of the present application, after the ME saves the symmetric encryption key generated in the PQC_KEM calculation, the following steps can also be performed: receiving a random number and a second authentication token generated by the target network element, and obtaining a first authentication token by using the symmetric encryption key and the second authentication token; wherein the second authentication token is generated by processing the first authentication token by the symmetric encryption key; sending the random number and the first authentication token to the USIM, so that the USIM performs synchronous authentication based on the first authentication token, to generate a first encryption key and a first integrity key based on the random number and the first authentication token after the synchronous authentication is passed.
[0079] It should be noted that in the embodiments of the present application, the first authentication token is AUTN, the second authentication token is AUTN*, and AUTN* is AUTN generated by K_KEM. The specific processing manner can be that AUTN is encrypted by using K_KEM to obtain AUTN*, or AUTN* can be obtained by other manners, for example, AUTN* = AUTN xor K_KEM, and the embodiments of the present application are not limited thereto. Since the ME stores K_KEM, based thereon, the ME can obtain AUTN by using K_KEM and AUTN*.
[0080] It should be noted that in the embodiments of the present application, when the ME receives AUTN*, the ME can also receive a random number RAND. After the ME obtains AUTN by using K_KEM and AUTN*, the ME can send AUTN and RAND to the USIM, for the USIM to perform synchronization authentication and key generation after the synchronization authentication is passed. Wherein, the first encryption key generated by the USIM based on AUTN and RAND after the synchronization authentication is passed based on AUTN is CK, and the first integrity key is IK.
[0081] In the embodiments of the present application, the ME can further perform the following steps: in the case that the USIM synchronization authentication is passed, receiving the first encryption key and the first integrity key sent by the USIM; constructing a second encryption key based on the first encryption key and a second integrity key based on the first integrity key by using the symmetric encryption key; wherein the second encryption key and the second integrity key are used for key derivation.
[0082] It should be noted that in the embodiments of the present application, the ME can receive CK and IK sent by the USIM after the USIM synchronization authentication is passed, and further, construct keys based on CK and IK by using K_KEM for key derivation. Specifically, the second encryption key constructed by the ME based on CK by using K_KEM is CK_EXT, CK_EXT = HASH(K_KEM||CK) takes the lower 128 bits, the second integrity key constructed by the ME based on IK by using K_KEM is IK_EXT = HASH(K_KEM||IK) takes the lower 128 bits, of course, the above construction manner is only one optional construction manner, other construction manners can also be used in combination with actual requirements and application scenarios, and the embodiments of the present application are not limited thereto.
[0083] In the embodiments of the present application, the ME can further perform the following steps: in the case that the USIM synchronization authentication is not passed, receiving the first resynchronization authentication token sent by the USIM; processing the first resynchronization authentication token by using the symmetric encryption key to generate a second resynchronization authentication token; and forwarding the second resynchronization authentication token to the target network element through the related network element.
[0084] It should be noted that in the embodiments of the present application, the ME can receive the first re-synchronization authentication token, i.e. AUTS, sent after the USIM synchronization authentication fails, process the AUTS by using K_KEM, generate a second re-synchronization authentication token, i.e. AUTS*, and then instruct the target network element, so as to realize the protection of the transmission of AUTS and improve the security.
[0085] Figure 2 A flowchart of a communication authentication method provided in the embodiments of the present application Figure Two As shown in Figure 2 , the communication authentication method applied to the target network element in the home network mainly includes the following steps:
[0086] S201, receiving a user hidden identifier SUCI generated by a mobile device ME in a user equipment UE; the UE further includes a universal subscriber identity module USIM, the USIM supports a 128-bit communication authentication algorithm, and the SUCI is generated by encrypting a user permanent identifier SUPI of the USIM by using a post-quantum cryptography algorithm-based key encapsulation mechanism PQC_KEM.
[0087] In the embodiments of the present application, the target network element can receive the SUCI generated by the ME, and the explanation of the SUCI is described in detail in the related content in the above-mentioned ME side method, which is not repeated here.
[0088] S202, decrypting the SUCI by using the PQC_KEM, and saving a symmetric encryption key generated in the PQC_KEM calculation.
[0089] In the embodiments of the present application, after obtaining the SUCI, the target network element can decrypt the SUCI by using the PQC_KEM, and can obtain a symmetric encryption key, i.e. K_KEM, in the PQC_KEM calculation, so as to save the K_KEM for subsequent steps.
[0090] S203, forwarding a first authentication token processed by using the symmetric encryption key to the ME through a related network element.
[0091] In the embodiments of the present application, the target network element can forward the first authentication token, i.e. AUTN, processed by using the K_KEM to the ME through a related network element, so as to realize the protection of the AUTN and improve the security of the communication authentication.
[0092] In the embodiments of the present application, the target network element forwards the first authentication token processed by the related network element to the ME by using the symmetric encryption key, including: generating a first vector based on a 128-bit root authentication key of the USIM, the first vector containing a random number, an expected authentication response, the first authentication token, a first encryption key and a first integrity key; processing the first authentication token by using the symmetric encryption key to generate a second authentication token; constructing a second encryption key based on the first encryption key and a second integrity key based on the first integrity key by using the symmetric encryption key; the second encryption key and the second integrity key are used for key derivation; constructing an authentication vector based on the random number, the expected authentication response, the second authentication token, the second encryption key and the second integrity key; wherein the authentication vector contains the random number and the second authentication token; forwarding the authentication vector through the related network element, so that the second authentication token in the authentication vector is sent to the ME along with the random number.
[0093] It should be noted that, in the embodiments of the present application, similar to the method on the ME side, the target network element can also construct CK_EXT based on CK by using K_KEM, CK_EXT = HASH (K_KEM||CK) taking the lower 128 bits, and construct IK_EXT based on IK by using K_KEM, IK_EXT = HASH (K_KEM||IK) taking the lower 128 bits. Of course, the above construction method is only one optional construction method, and other construction methods can also be used in combination with actual needs and application scenarios, and the embodiments of the present application are not limited.
[0094] It should be noted that, in the embodiments of the present application, the target network element can construct an authentication vector based on RAND, XRES, AUTN*, CK_EXT and IK_EXT, wherein XRES is an expected authentication response. Specifically, in the 5G authentication and key agreement authentication scenario, a 5G home environment authentication vector (5G HE AV) can be constructed, containing RAND, AUTN*, K AUSF and XRES*, wherein K AUSF = KDF (K AUSF _ID, CK_EXT||IK_EXT), and XRES* = KDF (RAND, XRES, CK_EXT||IK_EXT).
[0095] In the embodiments of the present application, after the target network element saves the symmetric encryption key generated in the PQC_KEM calculation, the following steps can also be performed: in the case of receiving the second resynchronization authentication token generated by the ME, the second resynchronization authentication token is decrypted by using the symmetric encryption key to obtain the first resynchronization authentication token; wherein the second resynchronization authentication token is generated by processing the first resynchronization authentication token by the symmetric encryption key; verifying the legality of the first resynchronization authentication token and synchronizing the sequence number.
[0096] It should be noted that in the embodiments of the present application, if the USIM synchronization authentication fails, the target network element can receive AUTS* corresponding to the ME side method, and since AUTS* is generated by processing AUTS using K_KEM, the target network element can obtain AUTS using K_KEM and AUTS* to perform authentication synchronization fault recovery.
[0097] The following mainly illustrates the related content in the above communication authentication method from the aspects of main authentication initiation and identity submission process, main authentication process, and authentication synchronization fault recovery process, in combination with the 5G authentication and key agreement (AKA) scenario. The interaction process of the UE USIM and ME, the home network (HM) UDM / ARPF, and the service network (SN) SEAF are involved.
[0098] Figure 3 A process schematic diagram of main authentication initiation and identity submission provided by the embodiments of the present application is shown in FIG. 1. Figure 3 As shown in FIG. 1, the process mainly includes the following steps:
[0099] S1, when the network side needs the ME to send SUCI for network authentication, the ME performs the following steps:
[0100] (1) check whether the USIM is a new card;
[0101] Specifically, the ME checks whether the USIM is a new card supporting MILENAGE-256 (a 256-bit communication authentication algorithm), if not, the USIM supports MILENAGE-128 (a 128-bit communication authentication algorithm), then (2) and (3) are performed;
[0102] (2) encrypt SUPI using PQC_KEM to obtain SUCI;
[0103] (3) save K_KEM generated in PQC_KEM calculation;
[0104] Wherein, the ME encrypts SUPI using PQC_KEM to obtain SUCI, and secretly saves K_KEM (recommended length at least 256 bits) generated in the PQC_KEM calculation process. Since ECIES_KEM is based on an elliptic curve and cannot resist quantum attacks, PQC_KEM can be used to replace it.
[0105] S2, the ME sends an initial registration request (Initial Registration Request) to the SEAF, which carries SUCI.
[0106] S3, SEAF sends Nudm_Authenticate_Get Request to UDM / ARPF, which carries SUCI.
[0107] S4, UDM / ARPF decrypts SUPI through PQC_KEM and secretly saves K_KEM generated in the PQC_KEM calculation process.
[0108] Figure 4 A main authentication process schematic diagram is provided for the embodiments of the present application. As shown in the schematic diagram, the main authentication process mainly includes the following steps: Figure 4
[0109] S1, UDM / ARPF constructs a 5G HE AV: wherein, UDM / ARPF decrypts SUPI from SUCI and creates AV (RAND, AUTN, XRES, CK, IK). Then, UDM / ARPF should derive K AUSF and XRES* based on AV, finally, UDM / ARPF should create a 5G HE AV containing RAND, AUTN, XRES* and K AUSF , which mainly involves:
[0110] (1) AV is calculated based on 128-bit K;
[0111] wherein, UDM / ARPF queries the subscription data of the corresponding USIM according to SUPI, if the USIM is an old card only supporting 128-bit, AV=(RAND, AUTN, XRES, CK, IK) is calculated based on K in USIM using MILENAGE-128 algorithm, see Figure 5 , AUTN:=SQN⊕AK||AMF||MAC; AV:=RAND||XRES||CK||IK||AUTN, wherein, Sequence Number (SQN), Authentication Management Field (AMF) and Message Authentication Code (MAC) are involved.
[0112] (2) AUTN is encrypted to obtain AUTN*;
[0113] wherein, AUTN is encrypted to obtain AUTN*=E(K_KEM, AUTN) using the key K_KEM. It should be noted that the symmetric encryption algorithm E recommended to be used is quantum safe, such as AES-256, the key length is 256 bits, and the block length can be 128 bits, to be compatible with the original protocol.
[0114] (3) Calculate CK_EXT and IK_EXT instead of CK and IK;
[0115] wherein, calculate CK_EXT = HASH(K_KEM||CK) take low 128bit, IK_EXT = HASH(K_KEM||IK) take low 128bit.
[0116] (4) Construct 5G HE AV;
[0117] wherein, replace CK_EXT and IK_EXT with CK and IK respectively, derive K AUSF and XRES* by KDF one-way function, get 5G HE AV containing RAND, AUTN*, XRES* and K AUSF .
[0118] S2, UDM / ARPF sends RAND and RAND to SEAF;
[0119] wherein, UDM / ARPF sends the 5G HE AV constructed above to AUSF, and UDM returns the requested 5G HE AV to AUSF in Nudm_Authenticate_Get Request message; wherein, it is also indicated that the 5G HE AV is used for 5G AKA, and if SUCI is contained in Nudm_UEAuthentication_Get request, UDM will contain SUPI in Nudm_UEAuthentication_Get response.
[0120] Further, AUSF temporarily saves XRES* and received SUCI or SUPI. AUSF can save K AUSF。
[0121] Further, AUSF generates a 5G AV based on the 5G HE AV received from UDM / ARPF. Calculate HXRES* from XRES*, derive K AUSF from K SEAF , and then replace HXRES* and K SEAF in 5G HE AV with XRES* and K AUSF respectively, wherein, K SEAF is a security anchor function key.
[0122] Further, AUSF removes K SEAF , and sends 5G SE AV (RAND, AUTN*, HXRES*) to SEAF through Nausf_UEAuthentication_Authenticate response.
[0123] S3, the SEAF sends RAND and AUTN* to the ME through an Authentication Request message; wherein the message shall also contain the ngKSI of the partial native security context, and the ABBA parameter. AMF
[0124] S4, the ME decrypts AUTN* using K_KEM to obtain AUTN;
[0125] S5, the ME forwards RAND and AUTN to the USIM;
[0126] S6, upon receiving RAND and AUTN, the USIM performs the following steps:
[0127] (1) verifying AUTN, specifically, verifying whether the AUTN is accepted, so as to verify whether the authentication vector is the latest, see Figure 6 , verifying MAC=XMAC, and verifying whether the SQN is in the correct range; if the verification is passed, step (2) is performed;
[0128] (2) calculating the response RES, CK, and IK.
[0129] S7, the USIM sends RES, CK, and IK to the ME.
[0130] S8, the ME performs the following steps:
[0131] (1) the ME calculates CK_EXT and IK_EXT instead of CK and IK;
[0132] wherein CK_EXT=HASH(K_KEM||CK) takes the lower 128 bits;
[0133] IK_EXT=HASH(K_KEM||IK) takes the lower 128 bits.
[0134] (2) calculating RES* and other parameters;
[0135] The ME replaces CK and IK with CK_EXT and IK_EXT respectively, calculates RES* from RES through the corresponding derivation function, RES* is the authentication result, and K AUSF is derived from K AUSF , K SEAF is derived from K
[0136] S9, the ME returns RES* to the SEAF in a NAS message authentication response.
[0137] Further, the SEAF shall compute a hash authentication result HRES* from RES* and compare HRES* with a hash expected authentication result HXRES*. If the two values are identical, the SEAF shall consider the authentication successful from the service network perspective. If not, the SEAF shall consider the authentication failed and indicate the failure to the AUSF.
[0138] The SEAF shall send the SUCI or SUPI to the AUSF via the Nausf_UEAuthentication_Authenticate Request message.
[0139] Upon receiving the Nausf_UEAuthentication_Authenticate Request message containing RES*, the AUSF can verify whether the AV has expired. If the AV has expired, the AUSF can consider the authentication unsuccessful from the home network perspective. The AUSF shall compare the received RES* with the stored XRES*. If RES* and XRES* are identical, the AUSF shall consider the authentication successful from the home network perspective.
[0140] The AUSF shall indicate whether the authentication is successful or not to the SEAF via the Nausf_UEAuthentication_Authenticate Response. If the authentication is successful, the K SEAF shall be sent to the SEAF via the Nausf_UEAuthentication_Authenticate Response. If the AUSF receives SUCI from the SEAF when initiating the authentication and the authentication is successful, the AUSF shall also include the SUPI in the Nausf_UEAuthentication_Authenticate Response.
[0141] If the authentication is successful, the SEAF shall take the K SEAF received from the Nausf_UEAuthentication_Authenticate Response message as the anchor key. The SEAF shall then derive K SEAF from K AMF , the ABBA parameter and the SUPI, and provide ngKSI and K AMF to the AMF.
[0142] If SUCI is used for this authentication, the SEAF shall only provide the ngKSI and K to the AMF after receiving the Nausf_UEAuthentication_Authenticate Response message containing the SUPI AMF ; the UE is not provided with communication services until the serving network learns the SUPI.
[0143] Figure 7 A flowchart of an authentication synchronization fault recovery process is provided for the embodiments of the present application. As shown in Figure 7 , the process mainly includes the following steps:
[0144] S1, when the USIM verifies the AUTN to generate a SQN (Sequence Number) synchronization problem, the AUTS is generated.
[0145] S2, the USIM returns the AUTS to the ME.
[0146] S3, the ME encrypts the AUTS to obtain AUTS* using K_KEM.
[0147] S4, the ME sends the AUTS* to the SEAF.
[0148] S5, the SEAF sends the RAND and AUTS* to the UDM / ARPF.
[0149] S6, the UDM / ARPF performs the following steps:
[0150] (1) decrypting the AUTS* to obtain the AUTS;
[0151] (2) verifying the legality of the AUTS and synchronizing the SQN parameter.
[0152] Based on the above, the technical solution provided by the embodiments of the present application has the following advantages: first, the security of the AKA protocol in the new ME+old USIM scenario can be improved, and the risk of K being cracked in the old USIM can be reduced; second, the generated CK_EXT||IK_EXT is a 256bit entropy key, which can provide 256bit security capability; third, compared with the original AKA authentication protocol, only the ME and the target network element (UDM / ARPF) need to be modified, without the need to modify other network elements and related interfaces, the modification cost is low, and the compatibility with the original protocol is high.
[0153] The embodiments of the present application provide an ME. Figure 8 A structure diagram of an ME is provided for the embodiments of the present application Figure One . As shown in Figure 8 , the ME includes:
[0154] The first processing module 801 is configured to, in the case that the USIM supports a 128-bit communication authentication algorithm, encrypt a user permanent identifier SUPI of the USIM by using a key encapsulation mechanism PQC_KEM based on a post-quantum cryptography algorithm, generate a user concealed identifier SUCI, and save a symmetric encryption key generated in the PQC_KEM calculation;
[0155] The first communication module 802 is configured to forward the SUCI to a target network element in a home network through a related network element, so that the target network element obtains the symmetric encryption key based on the SUCI, and forwards a first authentication token processed by using the symmetric encryption key to the ME through the related network element.
[0156] In an embodiment of the present application, the first communication module 802 is configured to, when initializing a registration request, forward the SUCI to the target network element through the related network element.
[0157] In an embodiment of the present application, the first communication module 802 is further configured to receive a random number and a second authentication token generated by the target network element;
[0158] The first processing module 801 is further configured to obtain the first authentication token by using the symmetric encryption key and the second authentication token; wherein the second authentication token is generated by processing the first authentication token by using the symmetric encryption key.
[0159] The first communication module 802 is further configured to send the random number and the first authentication token to the USIM, so that the USIM performs a synchronization authentication based on the first authentication token, and generates a first encryption key and a first integrity key based on the random number and the first authentication token after the synchronization authentication is passed.
[0160] In an embodiment of the present application, the first communication module 802 is further configured to, in the case that the synchronization authentication of the USIM is passed, receive the first encryption key and the first integrity key sent by the USIM;
[0161] The first processing module 801 is further configured to construct a second encryption key based on the first encryption key and a second integrity key based on the first integrity key by using the symmetric encryption key.
[0162] The second encryption key and the second integrity key are used for key derivation.
[0163] In an embodiment of the present application, the first communication module 802 is further configured to, in the case that the synchronization authentication of the USIM is not passed, receive a first re-synchronization authentication token sent by the USIM;
[0164] The first processing module 801 is further configured to process the first resynchronization authentication token by using the symmetric encryption key to generate a second resynchronization authentication token.
[0165] The first communication module 802 is further configured to forward the second resynchronization authentication token to the target network element through a related network element.
[0166] Figure 9 A structure of an ME provided by an embodiment of the present application Figure Two As shown in Figure 9 , the ME includes a first processor 901, a first memory 902, and a first communication bus 903.
[0167] The first communication bus 903 is configured to realize a communication connection between the first processor 901 and the first memory 902.
[0168] The first processor 901 is configured to execute one or more computer programs stored in the first memory 902 to realize a communication authentication method applied to the ME.
[0169] An embodiment of the present application provides a target network element. Figure 10 A structure of a target network element provided by an embodiment of the present application Figure One As shown in Figure 10 , the target network element includes:
[0170] A second communication module 1001 is configured to receive a subscriber concealed identifier SUCI generated by a mobile equipment ME in a user equipment UE; the UE further includes a universal subscriber identity module USIM, the USIM supports a 128-bit communication authentication algorithm, and the SUCI is generated by encrypting a user permanent identifier SUPI of the USIM by using a post-quantum cryptography algorithm-based key encapsulation mechanism PQC_KEM;
[0171] A second processing module 1002 is configured to decrypt the SUCI by using the PQC_KEM, save a symmetric encryption key generated in the PQC_KEM calculation, and forward a first authentication token processed by using the symmetric encryption key to the ME through a related network element by using the second communication module 1001.
[0172] In an embodiment of the present application, the second processing module 10012 is configured to generate a first vector based on the 128-bit root authentication key of the USIM, wherein the first vector comprises a random number, an expected authentication response, the first authentication token, a first encryption key and a first integrity key; generate a second authentication token by processing the first authentication token using the symmetric encryption key; construct a second encryption key based on the first encryption key and a second integrity key based on the first integrity key using the symmetric encryption key; the second encryption key and the second integrity key are used for key derivation; and construct an authentication vector based on the random number, the expected authentication response, the second authentication token, the second encryption key and the second integrity key; wherein the authentication vector comprises the random number and the second authentication token.
[0173] The second communication module 1001 is configured to forward the authentication vector through a related network element, so that the second authentication token in the authentication vector is sent to the ME together with the random number.
[0174] In an embodiment of the present application, the second processing module 1002 is further configured to, in a case where the second communication module 1001 receives a second resynchronization authentication token generated by the ME, obtain a first resynchronization authentication token using the symmetric encryption key and the second resynchronization authentication token; wherein the second resynchronization authentication token is generated by processing the first resynchronization authentication token using the symmetric encryption key; verify the legality of the first resynchronization authentication token, and synchronize a sequence number.
[0175] Figure 11 A structure of a target network element provided in an embodiment of the present application Figure Two As shown in Figure 11 , the target network element comprises a second processor 1101, a second memory 1102 and a second communication bus 1103.
[0176] The second communication bus 1103 is configured to realize the communication connection between the second processor 1101 and the second memory 1102.
[0177] The second processor 1101 is configured to execute one or more computer programs stored in the second memory 1102, so as to realize the communication authentication method applied to the target network element.
[0178] An embodiment of the present application provides a computer program product, comprising a computer program, characterized in that the computer program realizes the steps in the above communication authentication method when executed by a processor.
[0179] The embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to realize the steps in the communication authentication method. The computer readable storage medium can be a volatile memory (volatile memory), such as a random access memory (Random-Access Memory, RAM); or a non-volatile memory (non-volatile memory), such as a read-only memory (Read-Only Memory, ROM), a flash memory, a hard disk (Hard Disk Drive, HDD) or a solid state disk (Solid-State Drive, SSD); and can also be a respective device including one or any combination of the above memories, such as a mobile phone, a computer, a tablet device, a personal digital assistant, etc.
[0180] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt a computer program product implemented on one or more computer usable storage media (including but not limited to magnetic disk storage and optical storage) containing computer usable program codes.
[0181] The present application is described with reference to the implementation flowcharts and / or block diagrams of the method, device (system), and computer program product according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram and the combination of the flows and / or blocks in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the functions specified in the flowchart and / or block diagram. Figure One The functions specified in one or more flows and / or blocks Figure One The functions specified in one or more flows and / or blocks
[0182] These computer program instructions can also be stored in a computer readable storage medium that can guide the computer or other programmable data processing devices to work in a specific way, so that the instructions stored in the computer readable storage medium produce a manufactured product including instruction devices, which implement the functions specified in the flowchart and / or block diagram. Figure One The functions specified in one or more flows and / or blocks Figure One The functions specified in one or more flows and / or blocks
[0183] These computer program instructions can also be loaded into a computer or other programmable data processing devices, so that a series of operational steps are generated to realize the computer-implemented processes, and the instructions executed on the computer or other programmable devices provide the functions specified in the flowchart Figure One or multiple flows and / or blocks Figure One or multiple blocks or steps of the functions specified in the flowchart
[0184] The above description is merely one specific implementation of the present application, but the protection scope of the present application is not limited thereto, any changes or replacements easily thought of by those skilled in the art within the technical range disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method of authenticating a communication, characterized by, A method applied to a mobile equipment ME in a user equipment UE, the UE further comprising a universal subscriber identity module USIM, the method comprising: In a case that the USIM supports a 128-bit communication authentication algorithm, encrypting a user permanent identifier SUPI of the USIM by a post-quantum cryptography algorithm based key encapsulation mechanism PQC_KEM, generating a user concealed identifier SUCI, and saving a symmetric encryption key generated in the PQC_KEM calculation; forwarding the SUCI to a target network element in a home network through a related network element, so that the target network element obtains the symmetric encryption key based on the SUCI, and forwards a first authentication token processed through the related network element to the ME by using the symmetric encryption key.
2. The method of claim 1, wherein, The forwarding of the SUCI to the target network element in the home network through the related network element comprises: forwarding the SUCI to the target network element through the related network element when initializing a registration request.
3. The method of claim 1, wherein, After the saving of the symmetric encryption key generated in the PQC_KEM calculation, the method further comprises: receiving a random number and a second authentication token generated by the target network element, and obtaining the first authentication token by using the symmetric encryption key and the second authentication token; wherein the second authentication token is generated by processing the first authentication token by the symmetric encryption key; sending the random number and the first authentication token to the USIM, so that the USIM performs a synchronization authentication based on the first authentication token, and generates a first encryption key and a first integrity key based on the random number and the first authentication token after the synchronization authentication is passed.
4. The method of claim 3, wherein, The method further comprises: in a case that the USIM synchronization authentication is passed, receiving the first encryption key and the first integrity key sent by the USIM; constructing a second encryption key based on the first encryption key and a second integrity key based on the first integrity key by using the symmetric encryption key; wherein the second encryption key and the second integrity key are used for key derivation.
5. The method of claim 3, wherein, The method further comprises: in a case that the USIM synchronization authentication is not passed, receiving a first re-synchronization authentication token sent by the USIM; processing the first re-synchronization authentication token by using the symmetric encryption key to generate a second re-synchronization authentication token; forwarding the second re-synchronization authentication token to the target network element through the related network element.
6. A method of authenticating a communication, characterized by, A method applied to a target network element in a home network, the method comprising: receiving a user concealed identifier SUCI generated by a mobile equipment ME in a user equipment UE; the UE further comprising a universal subscriber identity module USIM, the USIM supporting a 128-bit communication authentication algorithm, and the SUCI being generated by encrypting a user permanent identifier SUPI of the USIM by a post-quantum cryptography algorithm based key encapsulation mechanism PQC_KEM; decrypting the SUCI by using the PQC_KEM, and saving a symmetric encryption key generated in the PQC_KEM calculation; forwarding a first authentication token processed through a related network element to the ME by using the symmetric encryption key. The method further comprises: in a case that the USIM synchronization authentication is passed, receiving the first encryption key and the first integrity key sent by the USIM; constructing a second encryption key based on the first encryption key and a second integrity key based on the first integrity key by using the symmetric encryption key; wherein the second encryption key and the second integrity key are used for key derivation. The method further comprises: in a case that the USIM synchronization authentication is not passed, receiving a first re-synchronization authentication token sent by the USIM; processing the first re-synchronization authentication token by using the symmetric encryption key to generate a second re-synchronization authentication token; forwarding the second re-synchronization authentication token to the target network element through the related network element.
7. The method of claim 6, wherein, The first authentication token is processed by using the symmetric encryption key, and is forwarded to the ME through a related network element. A first vector is generated based on a 128-bit root authentication key of the USIM, and the first vector includes a random number, an expected authentication response, the first authentication token, a first encryption key, and a first integrity key; The first authentication token is processed by using the symmetric encryption key to generate a second authentication token; The second encryption key and the second integrity key are used for key derivation. The authentication vector is forwarded through a related network element, so that the second authentication token in the authentication vector is sent to the ME along with the random number. After the symmetric encryption key generated in the PQC_KEM calculation is saved, the method further includes:
8. The method of claim 6, wherein, In a case where the second resynchronization authentication token generated by the ME is received, a first resynchronization authentication token is obtained by using the symmetric encryption key and the second resynchronization authentication token; the second resynchronization authentication token is the first resynchronization authentication token processed by using the symmetric encryption key to generate; The legality of the first resynchronization authentication token is verified, and a sequence number is synchronized. The method comprises:
9. An ME, characterized in that, a first processor, a first memory, and a first communication bus; The first communication bus is used to realize the communication connection between the first processor and the first memory; The first processor is used to execute one or more computer programs stored in the first memory, so as to realize the communication authentication method in any one of claims 1-5. The method comprises:
10. A target network element, characterized by a second processor, a second memory, and a second communication bus; The second communication bus is used to realize the communication connection between the second processor and the second memory; The second processor is used to execute one or more computer programs stored in the second memory, so as to realize the communication authentication method in any one of claims 6-8. The computer program is executed by the processor to realize the communication authentication method in any one of claims 1-8.
11. A computer readable storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to realize the communication authentication method in any one of claims 1-8.
12. A computer program product comprising a computer program, characterized in that,
Citation Information
Patent Citations
Network access authentication method and its USIM card
CN101132649A
Secret key determination method and device
CN111641498A