Cryptographic algorithm security negotiation method and apparatus, network function, device, storage medium, and computer program product
By negotiating between device and network functions, non-invalid cipher suites and/or cryptographic algorithms are identified and selected, thus addressing the threat posed by quantum computing to existing cryptographic algorithms and achieving communication security in the quantum computing era.
Patent Information
- Application Number
- CN202410903652.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-05
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2044-07-05
AI Technical Summary
Existing cryptographic algorithms are vulnerable to quantum computing attacks and lack sufficient security. The security of post-quantum cryptographic algorithms has not been fully demonstrated and they are at risk of being cracked.
The first device sends a request to the first network function to query whether the cipher suite and/or cryptographic algorithm is invalid, receives and verifies the response returned by the first network function, determines the secure and usable cipher suite and/or cryptographic algorithm, and establishes a communication channel.
It enables flexible and secure cryptographic algorithm negotiation in the era of quantum computing, enhances the security of communication channels, and avoids the use of invalid or insecure cryptographic algorithms.
Smart Images

Figure CN119011130B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and particularly relates to a password algorithm security negotiation method and device, network function, equipment, storage medium and computer program product. BACKGROUND
[0002] With the development of quantum technology, the computing power of computers is significantly improved, which brings great threat to the password system. For example, the password algorithm mechanism used in the transport layer security (TLS) is vulnerable to quantum computing attacks, and the security cannot be guaranteed. In addition, the security of the post-quantum password algorithm has not been fully demonstrated, and there is a risk of being cracked. SUMMARY
[0003] To solve the problems in the related art, the present application provides a password algorithm security negotiation method and device, network function, equipment, storage medium and computer program product.
[0004] The technical scheme of the present application embodiment is implemented as follows:
[0005] The present application embodiment provides a password algorithm security negotiation method applied to a first network function, and the method comprises the following steps.
[0006] Receiving a first request sent by a first device; wherein the first request carries at least an identifier of a password suite and / or a password algorithm, and is used for requesting to query whether the password suite and / or the password algorithm is invalid;
[0007] Returning a first response to the first device; the first response carries first information, and the first information indicates whether the password suite and / or the password algorithm is invalid or not.
[0008] In the above scheme, one password suite contains one or more password algorithms; after receiving the first request sent by the first device, the method further comprises the following steps.
[0009] Determining a first state of the password algorithm, and the first state indicates whether the password algorithm is invalid or not;
[0010] According to the first state of the password algorithm, determining the first information.
[0011] In the above scheme, the first network function supports a first capability and / or a second capability, the first capability is used for determining the password algorithm contained in the password suite, and the second capability is used for querying whether the password algorithm is invalid or not.
[0012] In the above scheme, the first information comprises one or more of the following:
[0013] one or more second information, one second information indicating whether a cipher algorithm included in one cipher suite is invalid, or one second information indicating whether a cipher algorithm is invalid;
[0014] one or more third information, one third information indicating whether a cipher suite is invalid;
[0015] signing.
[0016] In the above scheme, the second information includes a first value, and / or the third information includes a second value; wherein,
[0017] one first value indicating whether a cipher algorithm is invalid, one second value indicating whether a cipher suite is invalid, the second value being obtained by performing an OR operation on the first values of all cipher algorithms included in the cipher suite.
[0018] In the above scheme, the method further includes:
[0019] signing the first digest value using a private key of the first network function to obtain the signature; wherein the first digest value is determined according to all second information, or the first digest value is determined according to all second information and all third information.
[0020] Embodiments of the present application also provide a cipher algorithm security negotiation method, applied to a first device, the method comprising:
[0021] sending a first request to a first network function; the first request carrying at least an identity of a cipher suite and / or a cipher algorithm, for requesting to query whether the cipher suite and / or the cipher algorithm is invalid;
[0022] receiving a first response returned by the first network function; the first response carrying first information, the first information indicating whether the cipher suite and / or the cipher algorithm is invalid or not.
[0023] In the above scheme, after receiving the first response returned by the first network function, the method further includes:
[0024] selecting a cipher suite and / or a cipher algorithm that is not invalid according to the first information.
[0025] In the above scheme, before sending the first request to the first network function, the method further includes:
[0026] receiving a first message sent by a second device; the first message carrying at least the identity of the cipher suite and / or the cipher algorithm;
[0027] generating the first request according to the first message.
[0028] In the scheme, the first information comprises one or more of the following:
[0029] one or more second information, one second information indicating whether a cryptographic algorithm included in one cryptographic suite is invalid, or one second information indicating whether a cryptographic algorithm is invalid;
[0030] one or more third information, one third information indicating whether one cryptographic suite is invalid;
[0031] signature.
[0032] In the scheme, the method further comprises:
[0033] verifying the signature according to the public key of the first network function and a second digest value, wherein the second digest value is determined according to all second information, or the second digest value is determined according to all second information and all third information;
[0034] in the case where the signature verification is passed, selecting an un-invalid cryptographic suite and / or cryptographic algorithm according to the first information.
[0035] Embodiments of the present application also provide a cryptographic algorithm security negotiation device, comprising:
[0036] a first receiving unit configured to receive a first request sent by a first device, wherein the first request carries at least an identifier of a cryptographic suite and / or a cryptographic algorithm, and is used to request to query whether the cryptographic suite and / or the cryptographic algorithm is invalid;
[0037] a first sending unit configured to return a first response to the first device, wherein the first response carries first information, and the first information indicates whether the cryptographic suite and / or the cryptographic algorithm is invalid or un-invalid.
[0038] Embodiments of the present application also provide a cryptographic algorithm security negotiation device, comprising:
[0039] a second sending unit configured to send a first request to a first network function, wherein the first request carries at least an identifier of a cryptographic suite and / or a cryptographic algorithm, and is used to request to query whether the cryptographic suite and / or the cryptographic algorithm is invalid;
[0040] a second receiving unit configured to receive a first response returned by the first network function, wherein the first response carries first information, and the first information indicates whether the cryptographic suite and / or the cryptographic algorithm is invalid or un-invalid.
[0041] Embodiments of the present application also provide a first network function, comprising a first processor and a first communication interface, wherein:
[0042] The first communication interface is configured to receive a first request sent by a first device, and return a first response to the first device, wherein the first request carries at least an identifier of a cipher suite and / or a cipher algorithm, and is used to request to query whether the cipher suite and / or the cipher algorithm is invalid; and the first response carries first information indicating whether the cipher suite and / or the cipher algorithm is invalid.
[0043] The embodiments of the present application further provide a first device, which comprises a second processor and a second memory for storing a computer program capable of being run on the second processor,
[0044] The second communication interface is configured to send a first request to a first network function, and receive a first response returned by the first network function, wherein the first request carries at least an identifier of a cipher suite and / or a cipher algorithm, and is used to request to query whether the cipher suite and / or the cipher algorithm is invalid; and the first response carries first information indicating whether the cipher suite and / or the cipher algorithm is invalid.
[0045] The embodiments of the present application further provide a network function, which comprises a first processor and a first memory for storing a computer program capable of being run on the first processor,
[0046] When the first processor runs the computer program, the steps of any method for the first network function are performed.
[0047] The embodiments of the present application further provide a first device, which comprises a second processor and a second memory for storing a computer program capable of being run on the second processor,
[0048] When the second processor runs the computer program, the steps of any method for the first device are performed.
[0049] The embodiments of the present application further provide a storage medium, which stores a computer program, and when the computer program is run by a processor, the steps of any method for the first network function or the steps of any method for the first device are implemented.
[0050] The embodiments of the present application further provide a computer program product, which comprises a computer program, and when the computer program is run by a processor, the steps of any method are implemented.
[0051] In the method, apparatus, network function, device, storage medium, and computer program product for security negotiation of a cryptographic algorithm provided in the embodiments of the present application, a first device sends a first request to a first network function; the first network function receives the first request sent by the first device, and returns a first response to the first device; the first device receives the first response returned by the first network function; wherein the first request carries at least an identifier of a cryptographic suite and / or a cryptographic algorithm, and is used to request to query whether the cryptographic suite and / or the cryptographic algorithm is invalid; the first response carries first information, and the first information indicates whether the cryptographic suite and / or the cryptographic algorithm is invalid. According to the foregoing scheme, the first device determines, through the first network function, whether the cryptographic suite and / or the cryptographic algorithm is invalid, so that the first device can select a cryptographic suite and / or a cryptographic algorithm that is not invalid to establish a communication channel, and implement flexible and secure negotiation of a cryptographic algorithm in the quantum computing era. BRIEF DESCRIPTION OF DRAWINGS
[0052] Figure 1 FIG. 1 is a schematic diagram of an architecture of a related art core network;
[0053] Figure 2 FIG. 2 is a schematic diagram of a process of a method for security negotiation of a cryptographic algorithm according to an embodiment of the present application;
[0054] Figure 3 FIG. 3 is a schematic diagram of an architecture of a core network according to an embodiment of the present application;
[0055] Figure 4 FIG. 4 is a schematic diagram of a structure of a first network function according to an embodiment of the present application;
[0056] Figure 5 FIG. 5 is a schematic diagram of a process of a method for security negotiation of a cryptographic algorithm according to an embodiment of the present application;
[0057] Figure 6 FIG. 6 is a schematic diagram of a process of a method for security negotiation of a cryptographic algorithm according to an embodiment of the present application;
[0058] Figure 7 FIG. 7 is a schematic diagram of a structure of an apparatus for security negotiation of a cryptographic algorithm according to an embodiment of the present application;
[0059] Figure 8 FIG. 8 is a schematic diagram of a structure of an apparatus for security negotiation of a cryptographic algorithm according to an embodiment of the present application;
[0060] Figure 9 FIG. 9 is a schematic diagram of a structure of a first network function according to an embodiment of the present application;
[0061] Figure 10 FIG. 10 is a schematic diagram of a structure of a first device according to an embodiment of the present application. DETAILED DESCRIPTION
[0062] The third generation partnership project (3GPP, 3rd Generation Partnership Project) requires that the communication between network functions (NF, Network Function) of the core network of a communication network and between different network operators complies with the TLS protocol for transmission protection. The core network architecture is shown in Figure 1 Figure 1 Different network functions of the core network communicate through service-based interfaces (SBI) or N32 interfaces, including: network slice selection function (NSSF), network slice-specific authentication and authorization function (NSSAAF), network exposure function (NEF), authentication server function (AUSF), network repository function (NRF), access and mobility management function (AMF), policy control function (PCF), the unified data management (UDM), session management function (SMF), application function (AF), service communication proxy (SCP), network slice admission control function (NSACF), edge application server discovery function (EASDF), security edge protection proxy (SEPP), visitor security edge protection proxy (vSEPP), home security edge protection proxy (hSEPP), public land mobile network (PLMN), home public land mobile network (hPLMN), and short message service function (SMSF).
[0063] With the rapid development of quantum computing, large-scale quantum computers capable of breaking traditional cryptographic algorithms will appear around 2030. Quantum computers can achieve parallel computing based on the characteristics of quantum superposition, and have exponentially higher computing power than traditional computers, which may efficiently solve some "exponential" difficult problems in classical computing mode, thus posing a huge threat to the cryptographic system. For symmetric cryptographic systems, Grover's algorithm can reduce the search complexity in an unordered set to the square root level, theoretically reducing the security strength of symmetric cryptographic algorithms (e.g., block encryption) and hash functions by half. However, by increasing the length of the security parameter, such as doubling the key length of symmetric cryptography or doubling the output length of hash cryptography, the threat of quantum computing can be effectively addressed. For public key cryptographic systems, Shor's algorithm can factor large integers and solve discrete logarithms in polynomial time, which can theoretically completely break the Rivest-Shamir-Adleman (RSA) algorithm and the Elliptic Curve Public Key Cryptography algorithm widely used today. Therefore, the impact of quantum technology development on the cryptographic system is mainly reflected in the public key cryptography field.
[0064] In the public key cryptography field, all mandatory and recommended TLS cipher suites use public key cryptography mechanisms, such as ephemeral Elliptic Curve Diffie-Hellman (ECDHE) and Diffie-Hellman Ephemeral (DHE), for key agreement to achieve secure transmission. Attackers using quantum computers can decrypt, deceive, or tamper with sensitive data communicated through the SBI or N32 interface by using a pre-storage and post-decryption attack method. Sensitive data can include subscription information stored in the UDM, user information provided by the UDM to other network functions (such as AUSF, AMF, SMF, SMSF) upon request, user subscription permanent identifiers (SUPI) and / or user concealed identifiers (SUCI) sent by the UDM service to NF consumers through the interface, access and mobility subscription data, short message service (SMS) subscription data, slice selection subscription data, and location services control (LCS) privacy data.
[0065] In order to cope with the impact of quantum computing on traditional cryptography, western countries such as the United States have already laid out post-quantum cryptography. The National Institute of Standards and Technology (NIST) in the United States has collected post-quantum cryptography algorithm schemes worldwide, and has selected four public key post-quantum cryptography standard algorithms such as CRYSTALS-KYBER. These post-quantum cryptography standard algorithms are likely to be adopted by 3GPP, International Telecommunication Union (ITU), etc. in the future. China has also started research on post-quantum cryptography, and plans to collect in 2024, and it is expected to take more than 5 years to finally publish, therefore, at the present stage, it is necessary to build a flexible and replaceable cryptographic architecture, reserve a replacement mechanism for domestic post-quantum cryptography, and when the domestic post-quantum cryptography standard algorithm is put forward, it can realize smooth migration and strive for the initiative of communication security in the post-quantum era.
[0066] In summary, quantum computing is developing rapidly, and there are problems in the currently used cryptographic algorithm mechanism and the subsequent post-quantum cryptographic algorithm to be introduced: the cryptographic algorithm mechanism used in the current TLS is vulnerable to quantum computing attacks, and the security cannot be guaranteed; the security of the subsequent post-quantum cryptographic algorithm to be introduced has not been fully demonstrated, and it may be cracked at any time.
[0067] Based on this, in various embodiments of the present application, a first device sends a first request to a first network function; the first network function receives the first request sent by the first device, and returns a first response to the first device; the first device receives the first response returned by the first network function; wherein the first request carries at least an identifier of a cryptographic suite and / or a cryptographic algorithm, and is used to request to query whether the cryptographic suite and / or the cryptographic algorithm is invalid; the first response carries first information, and the first information indicates whether the cryptographic suite and / or the cryptographic algorithm is invalid or not. The above scheme determines whether the cryptographic suite and / or the cryptographic algorithm is invalid through the first network function, so as to be able to select a cryptographic suite and / or a cryptographic algorithm that is not invalid to establish a communication channel, and realize flexible and secure cryptographic algorithm negotiation in the quantum computing era.
[0068] The present application will be described in further detail below in conjunction with the accompanying drawings and embodiments.
[0069] The present application provides a cryptographic algorithm security negotiation method, applied to a first network function, which can be understood as a network function with the function of querying whether a cryptographic suite and / or a cryptographic algorithm is invalid. As shown in the figure, the method comprises: Figure 2
[0070] Step 201: receiving a first request sent by a first device.
[0071] The first request carries at least the identifier of the cipher suite and / or the cryptographic algorithm, and is used to request whether the cipher suite and / or the cryptographic algorithm is invalid.
[0072] Here, upon receiving a first request from the first device, the system queries whether the cipher suite and / or cryptographic algorithm carried in the first request is invalid. The first request may carry identifiers of one or more cryptographic algorithms for querying whether one or more cryptographic algorithms are invalid; the first request may carry one or more cipher suites, and a cipher suite may contain one or more cryptographic algorithms. The first request is used to query whether the cipher suite is invalid and / or whether the cryptographic algorithms contained in the cipher suite are invalid.
[0073] It should be noted that the first request may also carry a random number generated by the second device and a protocol version (such as the TLS protocol version). The first device and the second device can also differ depending on the content carried in the first request; for example, if the first request carries one or more cipher suites, the first device can be a TLS server or a device deploying a TLS server, and the second device can be a TLS client or a device deploying a TLS client; as another example, if the first request carries identifiers of multiple cryptographic algorithms, the first device can be the initiator of Internet Protocol Security (IPSec), and the second device can be the responder of IPSec; as yet another example, if the first request carries an identifier of a single cryptographic algorithm, the first device can be an AMF (Anti-Finance cipher), and the second device can be a User Equipment (UE). A cipher suite and / or cryptographic algorithm failure can indicate that the cipher suite and / or cryptographic algorithm is insecure, or that the cryptographic algorithm has been replaced (unavailable) and / or that the cipher suite contains at least one replaced (unavailable) cryptographic algorithm; both cipher suite failure and cryptographic algorithm failure can be represented numerically. For example, a 1 indicates that the cryptographic algorithm is invalid, in an invalid state, unavailable, or insecure; a 0 indicates that the cryptographic algorithm is not invalid or is secure and usable. As another example, a 1 indicates that the cryptographic suite is invalid, unavailable, or insecure, meaning the suite contains at least one invalid, unavailable, or insecure cryptographic algorithm, or at least one cryptographic algorithm in an invalid state; a 0 indicates that the cryptographic suite is not invalid or is secure and usable, meaning all cryptographic algorithms in the suite are valid and secure. In other words, a cryptographic suite is invalid if it contains at least one invalid cryptographic algorithm.
[0074] It should be noted that the first network function can be referred to as an algorithm revocation list (ARL), which can be invoked by a network entity or a communication entity (such as a TLS function network element) in a communication network; the ARL can be an independent function network element or network function, and the core network architecture is as shown in Figure 3 FIG. 2, the ARL can also be combined with other network functions, for example, the ARL is combined with the PCF, and the first network function can be understood as a PCF with an algorithm revocation list function.
[0075] Step 202: returning a first response to the first device.
[0076] The first response carries first information, and the first information indicates that the cipher suite and / or the cryptographic algorithm is revoked or not revoked.
[0077] Here, in the case of determining whether the cipher suite and / or the cryptographic algorithm is revoked, the first information is generated according to the determination result; the first response is generated based on the first information, and the first response is sent to the first device, so that the first device can select a secure and available cipher suite or a non-revoked cipher suite according to the first information carried in the first response, establish a secure communication channel between the first device and the second device, and realize communication security.
[0078] Wherein, in the case that the first request carries one or more cryptographic algorithms, the first information indicates that the corresponding one or more cryptographic algorithms are revoked or not revoked, that is, the first information indicates that all the cryptographic algorithms carried in the first request are revoked or not revoked. In the case that the first request carries one or more cipher suites, the first information indicates that the corresponding one or more cipher suites are revoked or not revoked, that is, the first information indicates that all the cipher suites carried in the first request are revoked or not revoked.
[0079] In order to realize flexible and secure cryptographic algorithm negotiation and enhance the security of the communication channel, in an embodiment, one or more cryptographic algorithms are included in one cipher suite; after receiving the first request sent by the first device, the method further comprises:
[0080] determining a first state of the cryptographic algorithm, the first state indicating whether the cryptographic algorithm is revoked;
[0081] determining the first information according to the first state of the cryptographic algorithm.
[0082] Here, in the case of receiving the first request, the first request is parsed to obtain a parsing result. The first state of each cryptographic algorithm included in the parsing result is determined, and the first information is determined according to the first state of each cryptographic algorithm included in the parsing result.
[0083] For example, in the case that the first request carries one or more cipher suites for requesting to query whether the cipher suites are invalid, the parsing result can include the one or more cipher suites and all the cipher algorithms contained in each of the cipher suites. The first network function determines the first status of all the cipher algorithms contained in each of the cipher suites carried by the first request; determines whether each of the cipher suites carried by the first request is invalid according to the first status of all the cipher algorithms contained in each of the cipher suites carried by the first request; determines the first information according to the first status of all the cipher algorithms contained in each of the cipher suites carried by the first request and / or whether each of the cipher suites carried by the first request is invalid; the first information can include the invalid status result of all the cipher suites carried by the first request, the invalid status result can be referred to as a status result or a second status, and the second status indicates that the cipher suite and / or the cipher algorithm is invalid or not invalid; the invalid status result of the cipher suite can be determined according to whether the cipher suite is invalid and / or whether the cipher algorithm contained in the cipher suite is invalid.
[0084] It should be noted that in the case that only one cipher algorithm is included in the cipher suite, whether the cipher algorithm is invalid can be understood as whether the cipher suite is invalid, and the first information can be directly determined according to the first status of the cipher algorithm.
[0085] For another example, in the case that the first request carries the identification of one or more cipher algorithms for requesting to query whether the cipher algorithms are invalid, the parsing result includes the one or more cipher algorithms. The first network function determines the first status of all the cipher algorithms carried by the first request; determines the first information according to the first status of all the cipher algorithms carried by the first request; and the first information can include the invalid status result of all the cipher algorithms carried by the first request; the invalid status result of the cipher algorithm can be determined according to the first status of the cipher algorithm.
[0086] In order to facilitate other functional network elements in the core network to call the first network function, in an embodiment, the first network function supports a first capability and / or a second capability, the first capability is used to determine the cipher algorithm contained in the cipher suite, and the second capability is used to query whether the cipher algorithm is invalid.
[0087] Here, the first network function supports the first capability and / or the second capability, the first capability can be used to determine the cryptographic algorithm included in the cipher suite, and the second capability can be used to query whether the cryptographic algorithm is invalid, i.e., to query the first state of the cryptographic algorithm; for example, the first network function can include a state library, and the second capability can be used to query the first state of the cryptographic algorithm in the state library; for another example, the second capability can be used to query the first state of the cryptographic algorithm in other devices or network functions. The first capability can be understood as a cipher suite state query capability or a cipher suite invalid state query capability, and the second capability can be understood as a cryptographic algorithm state query capability or a cryptographic algorithm invalid state query capability; the first network function can directly invoke the second capability, or can invoke the second capability through the first capability; both the first capability and the second capability are deployed with corresponding capability interfaces for invocation by other functional network elements.
[0088] The state library can also be referred to as a cryptographic algorithm state library, and the state library or other devices or other network functions can store the invalid cryptographic algorithm or the first state of the cryptographic algorithm. The state library can also store and maintain related information of the cryptographic algorithm (such as symmetric cryptographic algorithms, hash cryptographic algorithms, public key cryptography, and post-quantum cryptographic algorithms) that has been verified as insecure, for example, the name, version, and key length of the cryptographic algorithm. In the case where the state library or other devices or other network functions store the invalid cryptographic algorithm, the state library can be queried to determine whether there is a cryptographic algorithm matching the identifier of the cryptographic algorithm carried in the first request, so as to determine the first state corresponding to the identifier of the cryptographic algorithm carried in the first request; or, the state library can be queried to determine whether there is a cryptographic algorithm included in the cipher suite, so as to determine the first state of the cryptographic algorithm included in the cipher suite. In the case where the state library or other devices or other network functions store the first state of the cryptographic algorithm, the state library can be queried to determine whether there is a first state of a cryptographic algorithm matching the identifier of the cryptographic algorithm carried in the first request, so as to determine the first state corresponding to the identifier of the cryptographic algorithm carried in the first request; or, the state library or other devices or other network functions can be queried to determine the first state of the cryptographic algorithm matching the cryptographic algorithm included in the cipher suite, so as to determine the first state of all the cryptographic algorithms included in the cipher suite.
[0089] It should be noted that the first network function can also support a cipher suite parsing capability, so as to be able to parse the cipher suite and determine the cryptographic algorithm included in the cipher suite; the cipher suite parsing capability can be invoked by the first capability. The first network function can also support a cryptographic algorithm state management capability, so as to implement addition, deletion, modification, and query operations on the cryptographic algorithm or related information and the first state of the cryptographic algorithm in the state library, so that the first state of the cryptographic algorithm in real time can be obtained through the state library. The structure of the first network function is as follows: Figure 4indicated by the first information.
[0090] To facilitate the device receiving the first information to learn whether the cipher suite and / or the cipher algorithm is invalid, and to enhance the security of the communication channel, in an embodiment, the first information comprises one or more of the following:
[0091] one or more second information, one second information indicating whether a cipher algorithm included in a cipher suite is invalid, or one second information indicating whether a cipher algorithm is invalid;
[0092] one or more third information, one third information indicating whether a cipher suite is invalid;
[0093] a signature.
[0094] Here, in the case that the first request carries the identification of one or more cipher algorithms, the first information can at least comprise one or more second information, and can further comprise a signature; the number or quantity of the second information is the same as the number or quantity of the cipher algorithms. The signature is used to verify the integrity of the first information.
[0095] In the case that the first request carries one or more cipher suites, the first information at least comprises one or more second information, the number or quantity of the second information is the same as the number or quantity of the cipher algorithms included in the cipher suite; the first information can further comprise one or more third information, and / or a signature.
[0096] In the case that the first information comprises one or more second information, if one second information indicates the first status of a cipher algorithm included in a cipher suite carried by the first request, the first device can determine whether each cipher suite carried by the first request is invalid according to all the second information, so as to select a secure and available or non-invalid cipher suite to establish the communication channel; if one second information indicates the first status of a cipher algorithm, the first device can determine the first status of the cipher algorithm according to the second information, and determine the first status corresponding to the identification of all the cipher algorithms carried by the first request according to all the second information, so as to select a secure and available or non-invalid cipher algorithm for communication, or to establish the communication channel.
[0097] In the case that the first information comprises one or more third information, the first information or the third information indicates that the cipher suite carried by the first request is invalid or non-invalid, and the first device can directly select a secure and available or non-invalid cipher suite to establish the communication channel according to the first information or the third information.
[0098] In a case that the first information comprises one or more second information and one or more third information, the first information indicates the first status of the cipher suite carried by the first request and the cipher algorithms included in the cipher suite, and the first device can select the cipher suite that is safe available or not invalid according to the first information, and determine the cipher algorithm that is invalid, or determine the cipher algorithm that is not invalid or safe available.
[0099] It should be noted that the third information corresponds to the cipher suite carried in the first request one by one; one third information corresponds to one or more second information; the second information corresponding to the third information corresponds to the cipher algorithm included in the third information one by one.
[0100] In order to enhance the security of the communication channel, in an embodiment, the second information comprises a first value, and / or the third information comprises a second value; wherein,
[0101] One first value indicates whether a cipher algorithm is invalid, and one second value indicates whether a cipher suite is invalid, and the second value is obtained by performing an OR operation on the first values of all cipher algorithms included in the cipher suite.
[0102] Here, one second information contains one first value, and one first value represents the first status of a cipher algorithm as invalid or not invalid, and the value of the first value can be 1 or 0; one third information contains one second value, and one second value represents that a cipher suite is not invalid or that the cipher suite includes an invalid cipher algorithm, and the value of the second value can be 1 or 0. The second value representing that the cipher suite is invalid (such as the second value corresponding to the cipher suite is 1) can be understood as that the cipher suite includes at least one invalid or unavailable or unsafe cipher algorithm (such as the cipher suite includes at least one cipher algorithm corresponding to the first value of 1); the second value representing that the cipher suite is not invalid (such as the second value corresponding to the cipher suite is 0) can be understood as that all the cipher algorithms included in the cipher suite are not invalid and are safe available (such as all the cipher algorithms included in the cipher suite correspond to the first value of 0).
[0103] In order to facilitate the device receiving the first information to verify the integrity of the first information, the first information includes a signature. Based on this, in an embodiment, the method further comprises:
[0104] The first digest value is signed using the private key of the first network function to obtain the signature; wherein, the first digest value is determined according to all the second information, or the first digest value is determined according to all the second information and all the third information.
[0105] Here, in the case that the first request carries the identification of one or more cryptographic algorithms but does not carry the cipher suite, the first digest value is determined according to all the second information, the first digest value is signed by using the private key of the first network function to obtain the signature included in the first information.
[0106] In the case that the first request carries one or more cipher suites or the first request carries one or more cipher suites and the identification of cryptographic algorithms, the first digest value is determined according to all the second information and all the third information; the first digest value is signed by using the private key of the first network function to obtain the signature included in the first information; all the second information refers to the second information corresponding to all the cryptographic algorithms in all the cipher suites carried by the first request, and all the third information refers to the third information corresponding to all the cipher suites carried by the first request. The algorithm used to determine the first digest value can be a secure available or unexpired cryptographic hash algorithm, which is also called a digest algorithm; the algorithm used to sign the first digest value by using the private key of the first network function can be a secure available or unexpired signature algorithm; the cryptographic hash algorithm and the signature algorithm used by the first network function can be agreed by the first network function and the first device, or can be determined according to the second information.
[0107] The embodiments of the present application also provide a cryptographic algorithm security negotiation method applied to a first device, the first device can be a server or a device deploying a server, for example, a TLS server and an IPSec server (initiator), and can also be a network function having a communication channel establishment function, for example, an AMF, as shown in FIG. 1, the method comprises the following steps. Figure 5
[0108] Step 501: sending a first request to a first network function.
[0109] The first request at least carries the identification of a cipher suite and / or a cryptographic algorithm, and is used to request whether the cipher suite and / or the cryptographic algorithm are expired.
[0110] In order to enable the first device to establish a communication channel with a second device, in an embodiment, before the first request is sent to the first network function, the method further comprises the following steps.
[0111] receiving a first message sent by the second device; the first message at least carries the identification of the cipher suite and / or the cryptographic algorithm;
[0112] generating the first request according to the first message.
[0113] Here, the first device, in a case where the first message sent by the second device is received, parses the first message to obtain fourth information, the fourth information at least including identification of a cipher suite and / or a cryptographic algorithm; generates a first request according to the fourth information, and sends the first request to the first network function to request to query whether the cipher suite and / or the cryptographic algorithm is invalid.
[0114] The fourth information can further include a protocol version (such as a TLS protocol version) and a random number generated by the second device. In a case where the first device is a TLS server or a device deploying a TLS server, the second device can be a TLS client or a device deploying a TLS client, and the communication channel can be a TLS channel, and the first message can be a Client Hello message. The first message can carry identification of one or more cipher suites and / or cryptographic algorithms, or carry a list of cipher suites and / or a list of identification of cryptographic algorithms. The identification of the cipher suite and / or the cryptographic algorithm carried by the first message is identification of a cipher suite and / or a cryptographic algorithm supported by the second device, which is used by the first device to establish the communication channel. The identification of the cipher suite and / or the cryptographic algorithm carried by the first request is the identification of the cipher suite and / or the cryptographic algorithm carried by the first message.
[0115] Step 502: receiving a first response returned by the first network function.
[0116] The first response carries first information, the first information indicating that the cipher suite and / or the cryptographic algorithm is invalid or not invalid.
[0117] In an embodiment, after the first response returned by the first network function is received, the method further includes:
[0118] Selecting a secure cipher suite and / or a cryptographic algorithm according to the first information.
[0119] Here, in a case where the first information indicates that the cryptographic algorithm is invalid or not invalid, and the first request at least carries identification of the cryptographic algorithm, it is determined according to the first information whether the cryptographic algorithm corresponding to the identification of the cryptographic algorithm carried by the first request is invalid, and a secure available or not invalid cryptographic algorithm is selected for communication or establishment of the communication channel.
[0120] In a case where the first information indicates that the cryptographic algorithm is invalid or not invalid, and the first request at least carries the cipher suite, it is determined according to the first information whether each cipher suite carried by the first request is invalid, a secure available or not invalid cipher suite is selected to establish the communication channel, and an invalid or insecure or unavailable cryptographic algorithm is determined to avoid using the invalid or insecure or unavailable cryptographic algorithm for communication or establishment of the communication channel.
[0121] In a case where the first information indicates that the cipher suite is invalid or not invalid, a secure available or not invalid cipher suite is directly selected according to the first information to establish the communication channel.
[0122] In a case where the first information indicates that the cipher suite and the cipher algorithm are invalid or not invalid, a secure available or not invalid cipher suite is directly selected according to the first information to establish the communication channel, and a result of invalidity or insecurity or unavailability of the cipher algorithm is determined according to the first information, or a result of invalidity or non-validity of the cipher suite is verified in combination with a result of invalidity or non-validity of the cipher algorithm included in the cipher suite.
[0123] It should be noted that the cipher suite and / or the cipher algorithm indicated by the first information correspond one by one to the cipher suite and / or the cipher algorithm carried by the first request; the first information indicating that the cipher suite is invalid can be understood as that the cipher suite includes at least one invalid cipher algorithm; and the first information indicating that the cipher suite is not invalid can be understood as that all the cipher algorithms included in the cipher suite are not invalid and are secure available.
[0124] Before the first device selects the cipher suite and / or the cipher algorithm for establishing the secure communication channel, the first network function can be used to confirm whether the cipher suite and / or the cipher algorithm supported by the second device is invalid, so that the secure available or not invalid cipher suite and / or the cipher algorithm is selected for subsequent interaction (such as key negotiation, certificate authentication and communication encryption) with the second device, which can avoid using the invalid or insecure or unavailable cipher algorithm, flexibly cope with the security risk of the cipher algorithm being cracked, and realize the communication network elastic security in the quantum computing era.
[0125] In order to confirm the integrity of the first information and enable the secure available or not invalid cipher suite to be selected according to the first information to establish the communication channel, in an embodiment, the first information includes one or more of the following:
[0126] One or more second information, one second information indicating whether a cipher algorithm included in one cipher suite is invalid, or one second information indicating whether the cipher algorithm is invalid;
[0127] One or more third information, one third information indicating whether one cipher suite is invalid;
[0128] A signature.
[0129] Here, in the case that the first information includes one or more second information, if one second information indicates whether a cipher algorithm included in one cipher suite carried by the first request is invalid, whether each cipher suite carried by the first request is invalid can be determined according to all the second information included in the first information, so that a cipher suite that is safe to use or not invalid is selected to establish a communication channel; if one second information indicates whether a cipher algorithm is invalid, whether the cipher algorithm is invalid can be determined according to the second information, and whether all the cipher algorithms corresponding to the cipher algorithm identifiers included in the first request are invalid can be determined according to all the second information included in the first information, so that a cipher algorithm that is safe to use or not invalid is selected for communication or to establish a communication channel.
[0130] In the case that the first information includes one or more third information, the first information or the third information indicates whether a cipher suite carried by the first request is invalid, and a cipher suite that is safe to use or not invalid can be directly selected according to the first information or the third information to establish a communication channel.
[0131] In the case that the first information includes one or more second information and one or more third information, the first information indicates whether a cipher suite carried by the first request is invalid and whether a cipher algorithm included in the cipher suite is invalid, a cipher suite that is safe to use or not invalid can be selected according to the first information, and an invalid or unsafe or unusable cipher algorithm can be determined to avoid using the invalid or unsafe or unusable cipher algorithm for communication or to establish a communication channel.
[0132] In the above three cases, if the first information further includes a signature, the integrity of the first information can be verified through the signature.
[0133] It should be noted that the third information corresponds to the cipher suites carried by the first request one by one; one third information corresponds to one or more second information; the second information corresponding to the third information corresponds to the cipher algorithms included in the cipher suite corresponding to the third information one by one.
[0134] In order to verify the integrity of the first information, in an embodiment, the method further includes:
[0135] The signature is verified according to the public key of the first network function and a second digest value; wherein the second digest value is determined according to all the second information, or the second digest value is determined according to all the second information and all the third information;
[0136] In the case that the signature verification is passed, a cipher suite and / or a cipher algorithm that is not invalid is selected according to the first information.
[0137] Here, in the case that the first request carries the identification of one or more cryptographic algorithms but does not carry the cipher suite, the second digest value is determined according to all the second information; the signature included in the first information is verified according to the public key of the first network function and the second digest value; in the case that the signature verification is passed, it is indicated that the first information is not lost, modified or damaged, and it can be determined according to all the second information included in the first information whether the cryptographic algorithm corresponding to the identification of all the cryptographic algorithms carried by the first request is invalid, so that a secure and available or non-invalid cryptographic algorithm is selected for communication or a communication channel is established.
[0138] In the case that the first request carries one or more cipher suites or the first request carries one or more cipher suites and the identification of cryptographic algorithms, the second digest value is determined according to all the second information and all the third information; the signature included in the first information is verified according to the public key of the first network function and the second digest value; in the case that the signature verification is passed, it is indicated that the first information is not lost, modified or damaged, and it can be determined according to all the second information or all the third information included in the first information whether each cipher suite carried by the first request is invalid, so that a secure and available or non-invalid cipher suite is selected to establish a secure communication channel; all the second information refers to the second information corresponding to all the cryptographic algorithms in all the cipher suites carried by the first request, and all the third information refers to the third information corresponding to all the cipher suites carried by the first request. The algorithm used to determine the first digest value can be a secure and available or non-invalid cryptographic hash algorithm, which is also called a digest algorithm; the cryptographic hash algorithm used by the first device is the same as the cryptographic hash algorithm used by the first network function, which can be agreed by the first network function and the first device or determined according to the second information; the algorithm used to verify the signature can be a secure and available or non-invalid signature verification algorithm; the signature verification algorithm used by the first device matches the signature algorithm used by the first network function, which can be agreed by the first network function and the first device or determined according to the second information; the public key of the first network function can be securely distributed to each network entity or communication entity (such as a TLS function network element) in the form of a certificate, and each network entity or communication entity includes the second device.
[0139] The present application will be further described in detail below in combination with application examples.
[0140] As shown in Figure 6 The cryptographic algorithm security negotiation method includes the following steps:
[0141] Step 1: The second device sends a first message to the first device.
[0142] Here, before the communication channel is established between the first device and the second device, the second device needs to send a first message to the first device, the first message carrying at least a cipher suite and / or a cryptographic algorithm supported by the second device, so that the first device can select a cipher suite and / or a cryptographic algorithm that is safe to use or not expired from the cipher suite and / or the cryptographic algorithm carried in the first message, thereby establishing the communication channel. In this embodiment, the first message carries at least a cipher suite supported by the second device as an example.
[0143] The first device can be a TLS server, the second device can be a TLS client, and the first message can be a ClientHello message. The following gives an example of the first message:
[0144] GMTLSv1 Record Layer: Handshake Protocol: Client Hello
[0145] Content Type: Handshake (22)
[0146] Version: GMTLS (0x0101)
[0147] Length: 119
[0148] Handshake Protocol: Client Hello
[0149] Handshake Type: Client Hello (1)
[0150] Length: 115
[0151] Version: GMTLS (0x0101)
[0152] Random:
[0153] 537d140186895336d2971947166ab7275b2a9bec326440647776532753fbeaff
[0154] GMT Unix Time: May 22, 2014 05:00:49.000000000 China Standard Time
[0155] Random Bytes:
[0156] 86895336d2971947166ab7275b2a9bec326440647776532753fbeaff
[0157] Session ID Length: 32
[0158] Session ID:
[0159] a1dfad9e4d068fa6be1a33ef47ccf031836abd3417d9edb38ce4c88443945afc
[0160] Cipher Suites Length: 4
[0161] Cipher Suites (2 suites)
[0162] Cipher Suite:
[0163] TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b)
[0164] Cipher Suite:
[0165] TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)
[0166] Compression Methods Length: 1
[0167] Compression Methods (1 method)
[0168] Extensions Length: 38
[0169] Extension: server_name (len=29)
[0170] Extension: heartbeat (len=1)
[0171] [JA3 Fullstring: 257,57363-57395,0-15,,]
[0172] [JA3: 629a53373db50439339cd02aa5fdc72c]
[0173] Step 2: The first device sends a first request to the first network function.
[0174] Here, the first device, upon receiving the first message, parses the first message to obtain fourth information, which can include a cipher suite, a protocol version, and a random number. For example, parsing the above first message example, the protocol version included in the obtained fourth information is TLS protocol version GMTLS (0x0101), the random number is the random number 86895336d2971947166ab7275b2a9bec326440647776532753fbeaff generated by the second device, and the cipher suite has two, which are cipher suite 1 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b) and cipher suite 2 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013).
[0175] The first device generates a first request according to the fourth information, and sends the first request to the first network function; the first request at least carries a cipher suite, for example, the first request carries the cipher suite 1 and the cipher suite 2.
[0176] Step 3: The first network function determines the first state of the cipher algorithm contained in the cipher suite.
[0177] Here, the first network function, in a case of receiving the first request, parses each cipher suite carried by the first request to obtain cipher algorithms contained in all cipher suites carried by the first request. Specifically, each cipher suite carried by the first request can be parsed by invoking a cipher suite parsing capability of the first capability to obtain all cipher algorithms contained in each cipher suite. For example, the cipher algorithms contained in the cipher suite 1 carried by the first request include: a key agreement algorithm ECDHE, a signature algorithm Elliptic Curve Digital Signature Algorithm (ECDSA), a cryptographic hash algorithm Secure Hash Algorithm 256 (SHA256), and a symmetric algorithm and / or a key length and / or a block mode AES_128_GCM used in communication. AES_128_GCM represents that the symmetric algorithm is Advanced Encryption Standard (AES) with a key length of 128 and a block mode of Galois / Counter Mode (GCM). The cipher algorithms contained in the cipher suite 2 carried by the first request include: a key agreement algorithm ECDHE, a signature algorithm RSA, a cryptographic hash algorithm Secure Hash Algorithm 1 (SHA1), and a symmetric algorithm and / or a key length and / or a block mode AES_128_CBC used in communication. AES_128_CBC represents that the symmetric algorithm is Advanced Encryption Standard (AES) with a key length of 128 and a block mode of Cipher Block Chaining (CBC).
[0178] The first network function, in a case of determining the cipher algorithms contained in all cipher suites carried by the first request, determines a first status of all cipher algorithms contained in each cipher suite carried by the first request. Specifically, a second capability can be invoked to query whether the cipher algorithms contained in the cipher suite exist in a status library.
[0179] For example, in the case that the cipher algorithm included in the cipher suite exists in the state library, the first state of the cipher algorithm can be represented as 1; in the case that the cipher algorithm included in the cipher suite does not exist in the state library, the first state of the cipher algorithm can be represented as 0; the key agreement algorithm ECDHE, the signature algorithm ECDSA, the cipher hash algorithm SHA256, and the symmetric algorithm and / or the key length and / or the block mode AES_128_GCM used in the communication included in the cipher suite 1 cannot be queried in the state library, that is, the first state of all the cipher algorithms included in the cipher suite 1 is represented as 0 (the corresponding first numerical value is 0); based on this, the first state of all the cipher algorithms included in the cipher suite 1 can be represented as: {Revoked ECDHE , Revoked ECDSA , Revoked AES_128_GCM , Revoked SHA256} = {0, 0, 0, 0}. The key agreement algorithm ECDHE, the signature algorithm RSA, and the symmetric algorithm and / or the key length and / or the block mode AES_128_CBC used in the communication included in the cipher suite 2 cannot be queried in the state library, that is, the first state is represented as 0 (the corresponding first numerical value is 0), and the cipher hash algorithm SHA1 can be queried in the state library, that is, the first state of SHA1 is represented as 1 (the corresponding first numerical value is 1); based on this, the first state of all the cipher algorithms included in the cipher suite 1 can be represented as: {Revoked ECDHE , Revoked RSA , Revoked AES_128_CBC , Revoked SHA1} = {0, 0, 0, 1}.
[0180] Step 4: The first network function determines the first information according to the first state of the cipher algorithm included in the cipher suite.
[0181] Here, the first network function respectively performs or operation on the first numerical value of all the cipher algorithms included in each cipher suite carried by the first request to obtain a second numerical value in the case that the first state of all the cipher algorithms included in each cipher suite carried by the first request is determined, and the second numerical value represents whether each cipher suite carried by the first request is invalid.
[0182] For example, whether the cipher suite 1 is invalid can be determined by the following formula:
[0183] Revoked TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 = Revoked ECDHE | Revoked ECDSA |
[0184] Revoked AES_128_GCMRevoked SHA256 = 0 | 0 | 0 | 0 = 0
[0185] The revocation status result of the cipher suite 1 can be expressed as:
[0186] {Revoked TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 , {Revoked ECDHE , Revoked ECDSA , Revoked AES_128_GCM , Revoked SHA256}} = { 0, { 0, 0, 0, 0}} ;
[0187] Whether the cipher suite 2 is revoked can be determined by the following equation:
[0188] Revoked TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA1 = Revoked ECDHE | Revoked RSA |
[0189] Revoked AES_128_CBC | Revoked SHA1 = 0 | 0 | 0 | 1 = 1
[0190] The revocation status result of the cipher suite 2 can be expressed as:
[0191] {Revoked TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA1 , {Revoked ECDHE , Revoked RSA , Revoked AES_128_CBC , Revoked SHA1}} = { 1, { 0, 0, 0, 1}} ;
[0192] The first information includes the revocation status result of the cipher suite 1 and the cipher suite 2, and the first information can be expressed as:
[0193] { { Revoked TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 , { Revoked ECDHE , Revoked ECDSA , Revoked AES_128_GCM , Revoked SHA256}},
[0194] { Revoked TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA1 , { Revoked ECDHE , Revoked RSA , Revoked AES_128_CBC , Revoked SHA1}}}
[0195] {{0, {0, 0, 0, 0}}, {1, {0, 0, 0, 1}}}.
[0196] Step 5: The first network function returns a first response to the first device.
[0197] Here, the first network function can construct the first response according to the first information, and return the first response to the first device.
[0198] Step 6: The first device selects a non-revoked cipher suite according to the first information.
[0199] Here, in the case that the first device receives the first response returned by the first network function, a non-revoked cipher suite is selected according to the first information carried by the first response. For example, the first information carried by the first response is: {{Revoked TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 , {Revoked ECDHE , Revoked ECDSA , Revoked AES_128_GCM , Revoked SHA256}}, {Revoked TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA1 , {Revoked ECDHE , Revoked RSA , Revoked AES_128_CBC , Revoked SHA1}} = {{0, {0, 0, 0, 0}}, {1, {0, 0, 0, 1}}}, wherein {0, {0, 0, 0, 0}} represents that the cipher suite 1 is safe and available or non-revoked, and all the cipher algorithms contained in the cipher suite 1 are non-revoked, {1, {0, 0, 0, 1}} represents that the cipher algorithm 2 is revoked or unsafe or unavailable, and the revoked or unsafe or unavailable cipher algorithm in the cipher suite 2 is the cipher hash algorithm SHA1, therefore, the non-revoked cipher suite 1 is selected to establish the communication channel.
[0200] In order to implement the method of the first network function side of the embodiments of the present application, the embodiments of the present application further provide a cipher algorithm security negotiation device arranged on the first network function, as shown in Figure 7 , the device comprises:
[0201] A first receiving unit 701 is configured to receive a first request sent by a first device; wherein the first request carries at least an identifier of a cipher suite and / or a cipher algorithm, and is used to request to query whether the cipher suite and / or the cipher algorithm is revoked;
[0202] A first sending unit 702 is configured to return a first response to the first device; the first response carries first information, and the first information indicates whether the cipher suite and / or the cipher algorithm is revoked or non-revoked.
[0203] In an embodiment, one or more cryptographic algorithms are included in one cryptographic suite; the apparatus further includes:
[0204] a first determining unit, configured to determine a first status of the cryptographic algorithm, the first status indicating whether the cryptographic algorithm is invalid;
[0205] a second determining unit, configured to determine the first information according to the first status of the cryptographic algorithm.
[0206] In an embodiment, the first network function supports a first capability and / or a second capability, the first capability being used to determine the cryptographic algorithm included in the cryptographic suite, and the second capability being used to query whether the cryptographic algorithm is invalid.
[0207] In an embodiment, the first information includes one or more of the following:
[0208] one or more second information, one second information indicating whether one cryptographic algorithm included in one cryptographic suite is invalid, or one second information indicating whether one cryptographic algorithm is invalid;
[0209] one or more third information, one third information indicating whether one cryptographic suite is invalid;
[0210] a signature.
[0211] In an embodiment, the second information includes a first value, and / or the third information includes a second value; wherein,
[0212] one first value indicating whether one cryptographic algorithm is invalid, and one second value indicating whether one cryptographic suite is invalid, the second value being obtained by performing an OR operation on the first values of all the cryptographic algorithms included in the cryptographic suite.
[0213] In an embodiment, the apparatus further includes:
[0214] a signing unit, configured to sign the first digest value using a private key of the first network function to obtain the signature; wherein the first digest value is determined according to all the second information, or the first digest value is determined according to all the second information and all the third information.
[0215] In actual application, the first receiving unit 701 and the first sending unit 702 can be realized by a processor in combination with a communication interface in a cryptographic algorithm security negotiation apparatus; the first determining unit, the second determining unit and the signing unit can be realized by a processor in the cryptographic algorithm security negotiation apparatus.
[0216] In order to implement the method of the first device side in the embodiments of the present application, the embodiments of the present application further provide a cryptographic algorithm security negotiation apparatus arranged on a first device, such as Figure 8As shown, the apparatus comprises:
[0217] The second sending unit 801 is configured to send a first request to a first network function, wherein the first request carries at least an identifier of a cipher suite and / or a cipher algorithm, and is used to request to query whether the cipher suite and / or the cipher algorithm is invalid.
[0218] The second receiving unit 802 is configured to receive a first response returned by the first network function, wherein the first response carries first information, and the first information indicates whether the cipher suite and / or the cipher algorithm is invalid.
[0219] In an embodiment, the apparatus further comprises:
[0220] The first selecting unit is configured to select a cipher suite and / or a cipher algorithm that is not invalid according to the first information.
[0221] In an embodiment, the apparatus further comprises:
[0222] The third receiving unit is configured to receive a first message sent by a second device, wherein the first message carries at least an identifier of the cipher suite and / or the cipher algorithm.
[0223] The generating unit is configured to generate the first request according to the first message.
[0224] In an embodiment, the first information comprises one or more of the following:
[0225] One or more second information, one second information indicating whether a cipher algorithm included in a cipher suite is invalid, or one second information indicating whether a cipher algorithm is invalid;
[0226] One or more third information, one third information indicating whether a cipher suite is invalid.
[0227] Signature.
[0228] In an embodiment, the apparatus further comprises:
[0229] The verifying unit is configured to verify the signature according to a public key of the first network function and a second digest value, wherein the second digest value is determined according to all the second information, or the second digest value is determined according to all the second information and all the third information.
[0230] The second selecting unit is configured to select a cipher suite and / or a cipher algorithm that is not invalid according to the first information in a case where the signature is verified.
[0231] In actual application, the second sending unit 801, the second receiving unit 802 and the third receiving unit can be realized by a processor in combination with a communication interface in the password algorithm security negotiation device, and the first selecting unit, the generating unit, the verifying unit and the second selecting unit can be realized by the processor in the password algorithm security negotiation device.
[0232] It should be noted that: the above embodiment provides the password algorithm security negotiation device, and only the division of each program module is used for example description when the password algorithm security negotiation device performs password algorithm security negotiation. In actual application, the above processing can be completed by different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the password algorithm security negotiation device and the password algorithm security negotiation method provided in the above embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
[0233] Based on the hardware implementation of the above program modules, and in order to realize the method of the first network function side in the embodiment of the application, the embodiment of the application further provides a first network function, as shown in the following Figure 9 The first network function 900 includes:
[0234] The first communication interface 901 can interact with other network nodes.
[0235] The first processor 902 is connected with the first communication interface 901 to realize information interaction with other network nodes, and is used to run a computer program to execute the method provided by one or more technical solutions of the first network function side.
[0236] The first memory 903 is used to store a computer program capable of running on the first processor 902.
[0237] Specifically, the first communication interface 901 is used to receive a first request sent by a first device, and is also used to return a first response to the first device; wherein the first request carries at least an identifier of a password suite and / or a password algorithm, and is used to request to query whether the password suite and / or the password algorithm is invalid; the first response carries first information, and the first information indicates whether the password suite and / or the password algorithm is invalid or not.
[0238] In an embodiment, one password suite contains one or more password algorithms; the first processor 902 is used to determine a first state of the password algorithm, and the first state indicates whether the password algorithm is invalid; and the first information is determined according to the first state of the password algorithm.
[0239] In an embodiment, the first network function supports a first capability for determining a cryptographic algorithm included in a cipher suite and / or a second capability for querying whether a cryptographic algorithm is disabled.
[0240] In an embodiment, the first information comprises one or more of:
[0241] one or more second information, one second information indicating whether a cryptographic algorithm included in a cipher suite is disabled, or one second information indicating whether a cryptographic algorithm is disabled;
[0242] one or more third information, one third information indicating whether a cipher suite is disabled;
[0243] a signature.
[0244] In an embodiment, the second information comprises a first value, and / or the third information comprises a second value; wherein,
[0245] one first value indicating whether a cryptographic algorithm is disabled, and one second value indicating whether a cipher suite is disabled, the second value being obtained by performing an OR operation on the first values of all cryptographic algorithms included in the cipher suite.
[0246] In an embodiment, the first processor 902 is further configured to sign the first digest value using a private key of the first network function to obtain the signature; wherein the first digest value is determined according to all second information, or the first digest value is determined according to all second information and all third information.
[0247] It should be noted that the specific processing procedures of the first processor 902 and the first communication interface 901 can be understood with reference to the above method.
[0248] Of course, in actual application, various components in the first network function 900 are coupled together through the bus system 904. It can be understood that the bus system 904 is used to realize the connection and communication between these components. In addition to including a data bus, the bus system 904 also includes a power bus, a control bus and a status signal bus. However, in order to clearly illustrate the application, all kinds of buses are marked as the bus system 904 in the Figure 9 .
[0249] The first memory 903 in the embodiment of the application is used to store various types of data to support the operation of the first network function 900. Examples of these data include: any computer programs used to operate on the first network function 900.
[0250] The method disclosed by the embodiments of the present application can be applied to the first processor 902 or implemented by the first processor 902. The first processor 902 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the first processor 902 or the instruction in the form of software. The first processor 902 described above can be a general processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 902 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the steps of the method, or the hardware and software modules in the decoding processor can be combined to execute the steps of the method. The software module can be located in a storage medium, and the storage medium is located in the first memory 903. The first processor 902 reads the information in the first memory 903 and combines the hardware to complete the steps of the method.
[0251] In the exemplary embodiments, the first network function 900 can be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), field programmable gate arrays (FPGAs), general-purpose processors, controllers, micro controllers (MCUs), microprocessors (Microprocessors), or other electronic elements, for executing the foregoing methods.
[0252] Based on the hardware implementation of the above program module, and in order to implement the method of the first device side in the embodiments of the present application, the embodiments of the present application further provide a first device, as shown in the following table: Figure 10 The first device 1000 includes:
[0253] The second communication interface 1001 can interact with other network nodes.
[0254] The second processor 1002 is connected with the second communication interface 1001 to realize the information interaction with other network nodes, and is used to run the computer program to execute the method provided by one or more technical solutions of the first device side.
[0255] The second memory 1003 is configured to store a computer program capable of running on the second processor 1002.
[0256] Specifically, the second communication interface 1001 is configured to send a first request to a first network function, and receive a first response returned by the first network function; the first request carries at least an identification of a cipher suite and / or a cryptographic algorithm, and is used to request to query whether the cipher suite and / or the cryptographic algorithm is invalid; the first response carries first information, and the first information indicates whether the cipher suite and / or the cryptographic algorithm is invalid.
[0257] In an embodiment, the second processor 1002 is configured to select a cipher suite and / or a cryptographic algorithm that is not invalid according to the first information.
[0258] In an embodiment, the second communication interface 1001 is further configured to receive a first message sent by a second device; the first message carries at least the identification of the cipher suite and / or the cryptographic algorithm.
[0259] The second processor 1002 is further configured to generate the first request according to the first message.
[0260] In an embodiment, the first information includes one or more of the following:
[0261] one or more second information, one second information indicating whether a cryptographic algorithm included in a cipher suite is invalid, or one second information indicating whether a cryptographic algorithm is invalid;
[0262] one or more third information, one third information indicating whether a cipher suite is invalid;
[0263] a signature.
[0264] In an embodiment, the second processor 1002 is further configured to verify the signature according to a public key of the first network function and a second digest value; wherein the second digest value is determined according to all the second information, or the second digest value is determined according to all the second information and all the third information.
[0265] In the case where the signature is verified, a cipher suite and / or a cryptographic algorithm that is not invalid is selected according to the first information.
[0266] It should be noted that the specific processing process of the second processor 1002 and the second communication interface 1001 can be understood with reference to the above method.
[0267] Of course, in actual applications, various components in the first device 1000 are coupled together through the bus system 1004. It can be understood that the bus system 1004 is used to realize the connection and communication between the components. In addition to including a data bus, the bus system 1004 also includes a power supply bus, a control bus, and a status signal bus. However, for the purpose of clear illustration, all the buses are marked as the bus system 1004 in the following description. Figure 10
[0268] The second memory 1003 in the embodiment of the present application is used to store various types of data to support the operation of the first device 1000. Examples of the data include any computer programs used for operation on the first device 1000.
[0269] The method disclosed in the above embodiment of the present application can be applied to or implemented by the second processor 1002. The second processor 1002 can be an integrated circuit chip with a signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware or the instruction in the form of software in the second processor 1002. The second processor 1002 can be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1002 can implement or execute the disclosed methods, steps, and logic block diagrams in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the completion, or the hardware and software modules in the decoding processor are combined to execute the completion. The software module can be located in the storage medium, which is located in the second memory 1003. The second processor 1002 reads the information in the second memory 1003 and combines the hardware to complete the steps of the above method.
[0270] In the exemplary embodiments, the first device 1000 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic elements, for executing the above method.
[0271] It can be understood that the memory (the first memory 903 and the second memory 1003) of the embodiments of the present application can be a volatile memory or a non-volatile memory, and can also include both a volatile memory and a non-volatile memory. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as a static random access memory (SRAM), a synchronous static random access memory (SSRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a sync link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM).The memory described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable type of memory.
[0272] In the example embodiments, the embodiments of the present application also provide a storage medium, i.e., a computer storage medium, specifically a computer readable storage medium, such as a first memory 903 storing a computer program executable by the first processor 902 of the first network function 900 to complete the steps of the aforementioned first network function side method. For example, a second memory 1003 storing a computer program executable by the second processor 1002 of the first device 1000 to complete the steps of the aforementioned first device side method. The computer readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.
[0273] Exemplarily, the embodiments of the present application also provide a computer program product comprising a computer program executable by the first processor 902 of the first network function 900 and the second processor 1002 of the first device 1000 to complete the steps of any of the aforementioned methods.
[0274] It should be noted that "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence; "multiple" means two or more.
[0275] The term "and / or" herein is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and or B, which can represent the three cases of A alone, A and B together, and B alone.
[0276] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0277] The above is only a preferred embodiment of the present application, and is not intended to limit the scope of protection of the present application.
Claims
1. A cryptographic algorithm security negotiation method, characterized by, The method is applied to a first network function, the first network function supports a first capability and / or a second capability, the first capability is used to determine a cipher algorithm included in a cipher suite, and the second capability is used to query whether the cipher algorithm is invalid; and the method comprises the following steps: receiving a first request sent by a first device; wherein the first request carries at least a cipher suite, and is used to request to query whether the cipher suite and / or the cipher algorithm is invalid; returning a first response to the first device; the first response carries first information, the first information indicates whether the cipher suite and / or the cipher algorithm is invalid or not invalid; the first information comprises one or more second information, one or more third information and a signature; one second information indicates whether one cipher algorithm included in one cipher suite is invalid, or one second information indicates whether one cipher algorithm is invalid; the second information comprises a first value, and one first value indicates whether one cipher algorithm is invalid; one third information indicates whether one cipher suite is invalid; the third information comprises a second value, and one second value indicates whether one cipher suite is invalid, and the second value is obtained by performing an or operation on the first values of all the cipher algorithms included in the cipher suite.
2. The method of claim 1, wherein, One cipher suite includes one or more cipher algorithms; after the step of receiving the first request sent by the first device, the method further comprises the following steps: determining a first state of the cipher algorithm, the first state indicating whether the cipher algorithm is invalid; determining the first information according to the first state of the cipher algorithm.
3. The method of claim 1, wherein, The method further comprises the following steps: signing the first digest value using a private key of the first network function to obtain the signature; wherein the first digest value is determined according to all the second information, or the first digest value is determined according to all the second information and all the third information.
4. A cryptographic algorithm security negotiation method, characterized by, The method is applied to a first device, and comprises the following steps: sending a first request to a first network function; the first request carries at least a cipher suite, and is used to request to query whether the cipher suite and / or the cipher algorithm is invalid; the first network function supports a first capability and / or a second capability, the first capability is used to determine a cipher algorithm included in a cipher suite, and the second capability is used to query whether the cipher algorithm is invalid; receiving a first response returned by the first network function; the first response carries first information, the first information indicates whether the cipher suite and / or the cipher algorithm is invalid or not invalid; the first information comprises one or more second information, one or more third information and a signature; one second information indicates whether one cipher algorithm included in one cipher suite is invalid, or one second information indicates whether one cipher algorithm is invalid; the second information comprises a first value, and one first value indicates whether one cipher algorithm is invalid; one third information indicates whether one cipher suite is invalid; the third information comprises a second value, and one second value indicates whether one cipher suite is invalid, and the second value is obtained by performing an or operation on the first values of all the cipher algorithms included in the cipher suite.
5. The method of claim 4, wherein, After the step of receiving the first response returned by the first network function, the method further comprises the following steps: select, according to the first information, a non-failed cipher suite and / or a non-failed cryptographic algorithm.
6. The method of claim 4, wherein, Before the first request is sent to the first network function, the method further includes: receiving a first message sent by a second device, the first message carrying at least an identifier of the cipher suite and / or the cryptographic algorithm; generating the first request according to the first message.
7. The method of claim 4, wherein, The method further includes: verifying the signature according to a public key of the first network function and a second digest value, wherein the second digest value is determined according to all the second information, or the second digest value is determined according to all the second information and all the third information; selecting, in a case where the signature is verified, a non-failed cipher suite and / or a non-failed cryptographic algorithm according to the first information.
8. A cryptographic algorithm security negotiation apparatus characterized by comprising: The method is applied to a first network function supporting a first capability and / or a second capability, the first capability being used to determine a cryptographic algorithm included in a cipher suite, and the second capability being used to query whether the cryptographic algorithm is failed; and the method includes: a first receiving unit configured to receive a first request sent by a first device, wherein the first request carries at least a cipher suite and is used to request querying whether the cipher suite and / or a cryptographic algorithm is failed; a first sending unit configured to return a first response to the first device, wherein the first response carries first information indicating whether the cipher suite and / or the cryptographic algorithm is failed or not, and the first information includes one or more of one or more second information, one or more third information and a signature; one second information indicates whether one cryptographic algorithm included in one cipher suite is failed, or one second information indicates whether one cryptographic algorithm is failed; the second information includes a first value, and one first value indicates whether one cryptographic algorithm is failed; one third information indicates whether one cipher suite is failed; the third information includes a second value, and one second value indicates whether one cipher suite is failed, and the second value is obtained by performing an OR operation on first values of all cryptographic algorithms included in the cipher suite.
9. A cryptographic algorithm security negotiation apparatus characterized by comprising: The method includes: a second sending unit configured to send a first request to a first network function; the first request carries at least a cipher suite and is used to request querying whether the cipher suite and / or a cryptographic algorithm is failed; and the first network function supports a first capability and / or a second capability, the first capability being used to determine a cryptographic algorithm included in a cipher suite, and the second capability being used to query whether the cryptographic algorithm is failed; a second receiving unit configured to receive a first response returned by the first network function; and the first response carries first information indicating whether the cipher suite and / or the cryptographic algorithm is failed or not, and the first information includes one or more of one or more second information, one or more third information and a signature; one second information indicates whether one cryptographic algorithm included in one cipher suite is failed, or one second information indicates whether one cryptographic algorithm is failed; the second information includes a first value, and one first value indicates whether one cryptographic algorithm is failed; one third information indicates whether one cipher suite is failed; the third information includes a second value, and one second value indicates whether one cipher suite is failed, and the second value is obtained by performing an OR operation on first values of all cryptographic algorithms included in the cipher suite. The first response carries first information, the first information indicates that a cipher suite and / or a cipher algorithm is invalid or is not invalid; the first information includes one or more second information, one or more third information and a signature; one second information indicates whether a cipher algorithm included in one cipher suite is invalid, or one second information indicates whether a cipher algorithm is invalid; the second information includes a first value, one first value indicates whether a cipher algorithm is invalid; one third information indicates whether one cipher suite is invalid; the third information includes a second value, one second value indicates whether one cipher suite is invalid, and the second value is obtained by performing an OR operation on the first values of all cipher algorithms included in the cipher suite.
10. A first network function, characterized by, The first network function supports a first capability and / or a second capability, the first capability is used to determine a cipher algorithm included in a cipher suite, and the second capability is used to query whether the cipher algorithm is invalid; the first network function includes a first processor and a first communication interface; wherein, The first communication interface is configured to receive a first request sent by a first device, and is further configured to return a first response to the first device; wherein the first request at least carries a cipher suite, and is used to request to query whether the cipher suite and / or a cipher algorithm is invalid; the first response carries first information, the first information indicates that the cipher suite and / or the cipher algorithm is invalid or is not invalid; the first information includes one or more second information, one or more third information and a signature; one second information indicates whether a cipher algorithm included in one cipher suite is invalid, or one second information indicates whether a cipher algorithm is invalid; the second information includes a first value, one first value indicates whether a cipher algorithm is invalid; one third information indicates whether one cipher suite is invalid; the third information includes a second value, one second value indicates whether one cipher suite is invalid, and the second value is obtained by performing an OR operation on the first values of all cipher algorithms included in the cipher suite.
11. A first device, comprising: The first network function includes: A second processor and a second communication interface; wherein The second communication interface is configured to send a first request to the first network function. Also for receiving a first response returned by the first network function; the first request carries at least a cipher suite, for requesting to query whether a cipher suite and / or a cipher algorithm is invalid; the first response carries first information, the first information indicating whether the cipher suite and / or the cipher algorithm is invalid or not invalid; the first network function supports a first capability and / or a second capability, the first capability being used for determining a cipher algorithm contained in a cipher suite, and the second capability being used for querying whether the cipher algorithm is invalid; the first information comprises one or more of one or more second information, one or more third information and a signature; one second information indicates whether a cipher algorithm contained in a cipher suite is invalid, or one second information indicates whether a cipher algorithm is invalid; the second information comprises a first value, one first value indicating whether a cipher algorithm is invalid; one third information indicates whether a cipher suite is invalid; the third information comprises a second value, one second value indicating whether a cipher suite is invalid, and the second value being obtained by performing an OR operation on first values of all cipher algorithms contained in the cipher suite.
12. A network function, characterized by, comprising a first processor and a first memory for storing a computer program capable of running on the first processor, wherein the first processor, when running the computer program, is configured to perform the steps of the method of any one of claims 1 to 3.
13. A first device, comprising: comprising a second processor and a second memory for storing a computer program capable of running on the second processor, wherein the second processor, when running the computer program, is configured to perform the steps of the method of any one of claims 4 to 7.
14. A storage medium having stored thereon a computer program, characterized in that The computer program, when executed by a processor, implements the steps of the method of any one of claims 1 to 3, or implements the steps of the method of any one of claims 4 to 7.
15. A computer program product comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Access authentication method and device, equipment and storage medium
CN114245377A
Encryption transmission method, device and system, electronic equipment and storage medium
CN117834125A