A key agreement method, device, apparatus and storage medium

CN119032582BActive Publication Date: 2026-08-11BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-24
Publication Date
2026-08-11

Smart Images

  • Figure CN119032582B_ABST
    Figure CN119032582B_ABST
Patent Text Reader

Abstract

This disclosure proposes a key negotiation method, apparatus, device, and storage medium. The method includes: receiving a key negotiation request sent by a user equipment (UE), the key negotiation request including: key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key; determining target information based on at least one key identifier and / or at least one key indication information in the key negotiation request, the target information indicating a target key, the target key being a key used to generate the OSCORE master key; and indicating the target key to the UE based on the target information. Embodiments of this disclosure provide a key negotiation method for negotiating between a UE and a first entity which key will be used to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a key negotiation method, apparatus, device and storage medium. Background Technology

[0002] In communication systems, user equipment (UE) and core network equipment typically need to generate their own Object Security for Constrained Representational State Transfer Environments (OSCORE) master secrets so that they can establish an OSCORE secure connection based on the OSCORE master secrets to ensure communication security. Summary of the Invention

[0003] This disclosure proposes a key negotiation method, apparatus, device, and storage medium.

[0004] In a first aspect, embodiments of this disclosure provide a key negotiation method, including:

[0005] The UE receives a key negotiation request, which includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating a restricted representation state transition environment OSCORE master secret.

[0006] Target information is determined based on at least one key identifier and / or at least one key indication information in the key negotiation request, wherein the target information is used to indicate a target key, and the target key is a key used to generate the OSCORE master key;

[0007] The target key is indicated to the UE based on the target information.

[0008] Secondly, embodiments of this disclosure provide a key negotiation method, including:

[0009] Send a key negotiation request to the first entity, the key negotiation request including key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key;

[0010] The target key is determined based on the instructions of the first entity.

[0011] Thirdly, embodiments of this disclosure provide a communication device, including:

[0012] The transceiver module is used to receive a key negotiation request sent by the UE. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating a restricted representation state transition environment object security OSCORE master secret.

[0013] The processing module is configured to determine target information based on at least one key identifier and / or at least one key indication information in the key negotiation request, wherein the target information is used to indicate a target key, and the target key is a key used to generate the OSCORE master key;

[0014] The transceiver module is used to indicate the target key to the UE based on the target information.

[0015] Fourthly, embodiments of this disclosure provide a communication device, including:

[0016] The transceiver module is used to send a key negotiation request to the first entity. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key.

[0017] A processing module is used to determine a target key based on the indication of the first entity.

[0018] Fifthly, embodiments of this disclosure provide a communication device including a processor that, when the processor invokes a computer program in memory, executes the method described in the first or second aspect.

[0019] In a sixth aspect, embodiments of this disclosure provide a communication device including a processor and a memory, the memory storing a computer program; the processor executes the computer program stored in the memory to cause the communication device to perform the method described in the first or second aspect above.

[0020] In a seventh aspect, embodiments of this disclosure provide a communication device including a processor and an interface circuit. The interface circuit is configured to receive code instructions and transmit them to the processor, which is configured to execute the code instructions to cause the device to perform the methods described in the first or second aspect above.

[0021] Eighthly, embodiments of this disclosure provide a communication system that includes the communication devices described in the third to fourth aspects, or the communication devices described in the fifth aspect, or the communication devices described in the sixth aspect, or the communication devices described in the seventh aspect.

[0022] Ninthly, embodiments of this disclosure provide a computer-readable storage medium for storing instructions for use by the network device described above, which, when executed, cause the terminal to perform the method described in the first or second aspect.

[0023] In a tenth aspect, this disclosure also provides a computer program product including a computer program that, when run on a computer, causes the computer to perform the methods described in the first or second aspect above.

[0024] Eleventhly, this disclosure provides a chip system including at least one processor and an interface for supporting network devices in implementing the functions involved in the methods described in the first or second aspect, such as determining or processing at least one of the data and information involved in the aforementioned methods. In one possible design, the chip system further includes a memory for storing computer programs and data necessary for source and slave nodes. The chip system may be composed of chips or may include chips and other discrete devices.

[0025] In a twelfth aspect, this disclosure provides a computer program that, when run on a computer, causes the computer to perform the methods described in the first or second aspect above.

[0026] In a thirteenth aspect, this disclosure provides a communication system, characterized in that it includes a UE and a core network device; wherein the core network device is configured to implement the key negotiation method described in the first aspect above, and the UE is configured to implement the key negotiation method described in the second aspect above.

[0027] In a fourteenth aspect, this disclosure provides a communication method applied to a communication system, the method comprising:

[0028] The UE sends a key negotiation request to the core network equipment. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key.

[0029] The core network device determines the target information based on at least one key identifier and / or at least one key indication information in the key negotiation request. The target information is used to indicate the target key, which is the key used to generate the OSCORE master key.

[0030] The core network equipment indicates the target key to the UE. Attached Figure Description

[0031] The above and / or additional aspects and advantages of this disclosure will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, in which:

[0032] Figure 1 This disclosure provides schematic diagrams of the architecture of some communication systems.

[0033] Figure 2 A schematic flowchart illustrating a key negotiation method provided in another embodiment of this disclosure;

[0034] Figure 3 A schematic flowchart illustrating a key negotiation method provided in yet another embodiment of this disclosure;

[0035] Figure 4 A schematic flowchart illustrating a key negotiation method provided in yet another embodiment of this disclosure;

[0036] Figure 5 A schematic flowchart illustrating a key negotiation method provided in yet another embodiment of this disclosure;

[0037] Figure 6 A schematic flowchart illustrating a key negotiation method provided in yet another embodiment of this disclosure;

[0038] Figure 7 A schematic flowchart illustrating a key negotiation method provided in yet another embodiment of this disclosure;

[0039] Figures 8a-8c A schematic flowchart illustrating a key negotiation method provided in yet another embodiment of this disclosure;

[0040] Figure 9 The following is an interactive flowchart of a key negotiation method provided in another embodiment of this disclosure;

[0041] Figure 10 This is a schematic diagram of the structure of a communication device provided in one embodiment of the present disclosure;

[0042] Figure 11 This is a schematic diagram of the structure of a communication device provided in one embodiment of the present disclosure;

[0043] Figure 12 This is a block diagram of a communication device provided in one embodiment of the present disclosure;

[0044] Figure 13 This is a schematic diagram of the structure of a chip provided in one embodiment of the present disclosure. Detailed Implementation

[0045] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this disclosure as detailed in the appended claims.

[0046] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. The singular forms “a” and “the” as used in this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.

[0047] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of this disclosure, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first information may also be referred to as second information without departing from the scope of embodiments of this disclosure, and similarly, second information may also be referred to as first information. Depending on the context, the words “if” and “suppose” as used herein may be interpreted as “when”, “when”, or “in response to a determination”.

[0048] Embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this disclosure, and should not be construed as limiting this disclosure.

[0049] In related technologies, the OSCORE master key can be generated based on Generic Bootstrapping Architecture (GBA) related keys or Authentication and Key Management for Applications (AKMA) related keys based on 3rd Generation Partnership Project (3GPP) credentials. That is, there can be multiple keys used to generate the OSCORE master key. Therefore, the UE and the core network equipment need to negotiate which key to use to generate the OSCORE master key, which urgently requires a key negotiation method.

[0050] To better understand the key negotiation method disclosed in this disclosure, the communication system to which this disclosure applies will be described first.

[0051] Please see Figure 1 , Figure 1 This is a schematic diagram of the architecture of a communication system provided in an embodiment of the present disclosure. The communication system may include, but is not limited to, at least one core network device and at least one UE. Figure 1 The number and form of devices shown are for illustrative purposes only and do not constitute a limitation on the embodiments of this disclosure. The application may include one or more core network devices, or one or more UEs. Figure 1 The communication system shown is an example consisting of a core network device and a UE.

[0052] It should be noted that the technical solutions of this disclosure can be applied to various communication systems. For example, Long Term Evolution (LTE) systems, 5th Generation (5G) mobile communication systems, 5G New Radio (NR) systems, or other future new mobile communication systems.

[0053] The core network equipment in this disclosure embodiment can be equipment deployed in the core network. The main functions of the core network equipment are to provide user connectivity, manage users, and carry out service delivery, serving as an interface to the external network. For example, the core network equipment in a 5G NR system may include at least one of the following: Application Function (AF), Network Application Function (NAF), Authentication and Key Management for Applications Anchor Function (AAnF), Bootstrapping Server Functionality (BSF), Access and Mobility Management Function (AMF), User Plane Function (UPF), Session Management Function (SMF), and Mobility Management Entity (MME).

[0054] In this disclosure, the UE can be a user-side entity used to receive or transmit signals, such as a mobile phone. The UE can also be referred to as a terminal, terminal device, mobile station (MS), mobile terminal (MT), etc. The UE can be a car with communication capabilities, a smart car, a mobile phone, a wearable device, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. This disclosure does not limit the specific technology or device form used by the UE.

[0055] It is understood that the communication system described in the embodiments of this disclosure is for the purpose of more clearly illustrating the technical solutions of the embodiments of this disclosure, and does not constitute a limitation on the technical solutions provided in the embodiments of this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this disclosure are also applicable to similar technical problems.

[0056] In addition, the following points are provided to facilitate understanding of the embodiments disclosed herein.

[0057] First, in this disclosure, unless contradictory, each step in any implementation or embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, the solution after removing some steps in a certain implementation or embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain implementation or embodiment can be arbitrarily interchanged. In addition, the optional methods or examples in a certain implementation or embodiment can be arbitrarily combined. Furthermore, the implementations or embodiments can be arbitrarily combined. For example, some or all steps of different implementations or embodiments can be arbitrarily combined, and a certain implementation or embodiment can be arbitrarily combined with the optional methods or examples of other implementations or embodiments.

[0058] Second, regarding the notation “A or B”, “A and / or B”, “at least one of A and B”, “A in one case, B in another case”, “in response to one case A, in response to another case B”, the following at least one scheme may be included depending on the situation: A is performed regardless of B, i.e., A in some embodiments; B is performed regardless of A, i.e., B in some embodiments; A and B are selectively performed, i.e., selected from A and B in some embodiments; A and B are both performed, i.e., A and B in some embodiments.

[0059] Third, each element, each row, or each column in the tables involved in this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0060] Fourth, in some implementations or embodiments, the terms "including A", "containing A", "for indicating A", and "carrying A" in this disclosure can be interpreted as directly carrying A or indirectly indicating A.

[0061] Fifth, in some implementations or embodiments, terms such as “in response to…”, “in the case of…”, “when…”, “when…”, “if…”, etc. in this disclosure can be replaced with each other.

[0062] Figure 2 This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by a first entity, such as... Figure 2 As shown, the key negotiation method may include the following steps:

[0063] Step 201: Receive the key negotiation request sent by the UE.

[0064] Optionally, in one embodiment of this disclosure, the first entity mentioned above may be a core network device. For example, the first entity may be an application function (AF) or a network application function (NAF).

[0065] Optionally, in one embodiment of this disclosure, the aforementioned key negotiation request may be sent via a Constrained Application Protocol (CoAP) request message.

[0066] Optionally, in one embodiment of this disclosure, the key negotiation request may include: key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master secret.

[0067] Optionally, in one embodiment of this disclosure, the aforementioned "at least one key for generating the OSCORE master key" may include at least one of the following:

[0068] GBA related keys;

[0069] AKMA related keys.

[0070] Optionally, the aforementioned GBA-related keys may include a first key and a second key, where the first key may be, for example, Ks_int_NAF, and the second key may be, for example, Ks_ext_NAF.

[0071] Optionally, the aforementioned AKMA-related keys can be, for example, the AKMA application key (AKMAApplicationkey, K...). AF ).

[0072] Optionally, in one embodiment of this disclosure, different UEs may support different keys for generating the OSCORE master key. For example, UE#1 may support generating the OSCORE master key using AKMA-related keys, while UE#2 may support generating the OSCORE master key using the first and second keys from the GBA-related keys. UE#2 may also support generating the OSCORE master key using both AKMA-related keys and the first key from the GBA-related keys. Therefore, in one embodiment of this disclosure, the key negotiation request sent by the UE to the first entity may include key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key. This allows the first entity to determine, based on the at least one key identifier and / or at least one key indication information, which keys the UE supports for generating the OSCORE master key, and ultimately determine which key to use to generate the OSCORE master key.

[0073] Optionally, in one embodiment of this disclosure, the at least one key identifier included in the aforementioned key negotiation request may include at least one of the following:

[0074] The AKMA-related key corresponds to the Authentication and Key Management for Applications Key Identifier (A-KID).

[0075] The bootstrapping transaction identifier (B-TID) corresponding to the GBA-related key.

[0076] Optionally, in one embodiment of this disclosure, the aforementioned A-KID may indicate that the keys supported by the UE for generating the OSCORE master key include: AKMA-related keys. Optionally, in one embodiment of this disclosure, when the UE supports using AKMA-related keys to generate the OSCORE master key, the UE may include the A-KID in the key negotiation request to indicate to the first entity that the UE supports using AKMA-related keys to generate the OSCORE master key.

[0077] Optionally, in one embodiment of this disclosure, the aforementioned B-TID may indicate that the keys supported by the UE for generating the OSCORE master key include: GBA-related keys. Optionally, in one embodiment of this disclosure, when the UE supports using GBA-related keys to generate the OSCORE master key, the UE may include the B-TID in the key negotiation request to indicate to the first entity that the UE supports using GBA-related keys to generate the OSCORE master key.

[0078] It should be noted that, in one embodiment of this disclosure, as described above, there are multiple GBA-related keys (i.e., the first key and the second key mentioned above). Therefore, when the key negotiation request includes B-TID (i.e., when the key negotiation request indicates that the UE supports using GBA-related keys to generate the OSCORE master key), the UE also needs to further indicate to the first entity through the key negotiation request which one or more of the GBA-related keys it specifically supports using to generate the OSCORE master key. Optionally, the UE can indicate to the first entity, through at least one of the following methods, which one or more of the GBA-related keys it specifically supports using to generate the OSCORE master key.

[0079] The first method involves a key negotiation request that includes a B-TID, which may further include a first key hint. The first key hint may include first key indication information corresponding to the first key and / or second key indication information corresponding to the second key.

[0080] Optionally, in one embodiment of this disclosure, the first key indication information may indicate that the keys supported by the UE for generating the OSCORE master key include the first key among the GBA-related keys, and the second key indication information may indicate that the keys supported by the UE for generating the OSCORE master key include the second key among the GBA-related keys.

[0081] Optionally, in one embodiment of this disclosure, when the first key prompt includes first key indication information, it indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys; when the first key prompt includes second key indication information, it indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys; and when the first key prompt includes both first key indication information and second key indication information, it indicates that the key supported by the UE for generating the OSCORE master key includes both the first key and the second key among the GBA-related keys.

[0082] Optionally, in one embodiment of this disclosure, the format of the B-TID including the aforementioned first key hint can be as follows:

[0083]

[0084] Or as shown below:

[0085]

[0086] Optionally, the RAND mentioned above is the authentication random number, the BSF_servers_domain_name mentioned above is the server domain name, and the Key hint mentioned above is the first key hint mentioned above.

[0087] Optionally, the "CBOR Array" mentioned above can be used to describe how to read B-TID. For example, in the B-TID mentioned above, CBOR Array can indicate that the text before the colon in each line of B-TID represents the item recorded in that line (for example, the recorded item can be RAND, BSF_servers_domain_nam, or Key hint), and the text after the colon represents the specific parameter corresponding to that item. Among them, tstr and bstr mentioned above are used to indicate the recording format of the specific parameter. For example, tstr (textstring) indicates that it is recorded in text format, and bstr (byte string) indicates that it is recorded in byte format.

[0088] Therefore, the first entity can determine which one or more of the GBA-related keys the UE supports using to generate the OSCORE master key by identifying the key hint in the B-TID. Optionally, when the key hint in the B-TID includes first key indication information, it indicates that the UE supports using the first key among the GBA-related keys to generate the OSCORE master key; when the key hint in the B-TID includes second key indication information, it indicates that the UE supports using the second key among the GBA-related keys to generate the OSCORE master key; and when the key hint in the B-TID includes both first and second key indication information, it indicates that the UE supports using both the first and second keys among the GBA-related keys to generate the OSCORE master key.

[0089] The second method involves including a B-TID in the key negotiation request. This key negotiation request may also include a first key hint. For a detailed introduction to the first key hint, please refer to the content of the first method mentioned above.

[0090] Optionally, the second method differs from the first method in that the first method includes the first key hint in the B-TID, while the second method does not include the first key hint in the B-TID, but includes it in the key negotiation request.

[0091] Optionally, in one embodiment of this disclosure, the format of the key negotiation request including the aforementioned first key hint can be as follows:

[0092]

[0093] Alternatively, it can be expressed in the following format:

[0094]

[0095] Optionally, when the first key hint is not included in the B-TID but is included in the key negotiation request, the format of the aforementioned B-TID in the key negotiation request can be:

[0096]

[0097] Optionally, the "N1, NAF-SID, OSC-INP" parameters in this key negotiation request are existing parameters and will not be described in detail. Also, the "Key hint" in this key negotiation request is the aforementioned first key hint. For information on "CBOR Array" and other parameters, please refer to the description of the first method.

[0098] Optionally, the first entity can determine which one or more of the GBA-related keys the UE supports using to generate the OSCORE master key by recognizing the key hint in the key negotiation request. Optionally, when the key hint in the key negotiation request includes first key indication information, it indicates that the UE supports using the first key among the GBA-related keys to generate the OSCORE master key; when the key hint in the key negotiation request includes second key indication information, it indicates that the UE supports using the second key among the GBA-related keys to generate the OSCORE master key; when the key hint in the key negotiation request includes both first key indication information and second key indication information, it indicates that the UE supports using both the first key and the second key among the GBA-related keys to generate the OSCORE master key.

[0099] As can be seen from the above, when the key negotiation request sent by the UE to the first entity includes B-TID (that is, the key negotiation request indicates that the UE supports using GBA-related keys to generate the OSCORE master key), the UE can carry the first key hint through the two methods mentioned above, so as to use the first key hint to further indicate to the first entity which one or more of the GBA-related keys the UE specifically supports using to generate the OSCORE master key.

[0100] Optionally, in one embodiment of this disclosure, the aforementioned key negotiation request may be triggered by the UE and sent to the first entity, or it may be triggered by the CoAP client in the UE and sent to the first entity. The CoAP client may be located in the UE's Universal Integrated Circuit Card (UICC) or in the UE's mobile equipment (ME).

[0101] Optionally, the above-mentioned "the UE triggers the sending of the key negotiation request" can be understood as: the UE decides to send the key negotiation request to the first entity. For example, the UE may decide to use its own transmission module to send the key negotiation request to the first entity, or the UE may instruct the CoAP client to send the key negotiation request to the first entity. For example, the UE may send an instruction to the CoAP client, which instructs the CoAP client to send the key negotiation request to the first entity.

[0102] Optionally, the above-mentioned "the CoAP client triggers the sending of the key negotiation request" can be understood as: the CoAP client decides to send the key negotiation request to the first entity. For example, the CoAP client may decide to send the key negotiation request to the first entity itself, or the CoAP client may instruct the UE's transmission module to send the key negotiation request to the first entity. For example, the CoAP client may send an instruction to the UE's transmission module, which instructs the UE's transmission module to send the key negotiation request to the first entity.

[0103] It should be noted that in one embodiment of this disclosure, the content that the key negotiation request can include will be different when the triggering method of the key negotiation request is different, and when the key negotiation request is triggered and sent by the UE's CoAP client, the content that the key negotiation request can include will also be different if the location of the CoAP client in the UE is different.

[0104] Optionally, regarding the scenario where "the key negotiation request is triggered by the UE's CoAP client," in one embodiment of this disclosure, when the CoAP client is located in the UE's UICC, the key negotiation request triggered by the CoAP client may include at least one of A-TID, B-TID, and first key indication information (i.e., the key indication information corresponding to Ks_int_NAF), but cannot include second key indication information (i.e., the key indication information corresponding to Ks_ext_NAF). When the CoAP client is located in the UE's ME, the key negotiation request triggered by the CoAP client may include at least one of A-TID, B-TID, and second key indication information (i.e., the key indication information corresponding to Ks_ext_NAF), but cannot include first key indication information (i.e., the key indication information corresponding to Ks_int_NAF).

[0105] The following explains why "when the CoAP client is located in the UICC of the UE, the key negotiation request triggered by the CoAP client cannot include the second key indication information, and when the CoAP client is located in the ME of the UE, the key negotiation request triggered by the CoAP client cannot include the first key indication information".

[0106] Optionally, since the UICC is used to derive Ks_int_NAF (i.e., the aforementioned first key) and cannot derive Ks_ext_NAF (i.e., the aforementioned second key), when the CoAP client is located in the UICC, the CoAP client cannot obtain the second key, and therefore the key negotiation request triggered by the CoAP client cannot include the second key indication information corresponding to the second key. Similarly, since the ME is used to derive Ks_ext_NAF (i.e., the aforementioned second key) and cannot derive Ks_int_NAF (i.e., the aforementioned first key), when the CoAP client is located in the ME, the CoAP client cannot obtain the first key, and therefore the key negotiation request triggered by the CoAP client cannot include the first key indication information corresponding to the first key.

[0107] Optionally, for the case where "the key negotiation request is triggered by the UE", the key negotiation request triggered by the UE may include at least one of A-TID, B-TID, first key indication information (i.e., the key indication information corresponding to Ks_int_NAF), and second key indication information (i.e., the key indication information corresponding to Ks_ext_NAF).

[0108] The following explains why "when a key negotiation request is triggered by the UE, the key negotiation request sent by the UE can include both the first key indication information and the second key indication information".

[0109] Optionally, since the UE includes the aforementioned UICC and ME, the UE can obtain the first key derived from the UICC and the second key derived from the ME. Therefore, the key negotiation request triggered by the UE can include both the first key indication information corresponding to the first key and the second key indication information corresponding to the second key.

[0110] Step 202: Determine the target information based on at least one key identifier and / or at least one key indication information in the key negotiation request.

[0111] Optionally, in one embodiment of this disclosure, the target information may be used to indicate a target key, which may be a key determined by the first entity for generating the OSCORE master key. Optionally, the target key may be one of at least one key indicated by the key negotiation request. Furthermore, the target information may be a key identifier and / or key indication information corresponding to the target key.

[0112] Optionally, in one embodiment of this disclosure, the method by which the first entity determines the target information based on at least one key identifier and / or at least one key indication information in the key negotiation request may include the following steps:

[0113] The first step is to select a target key from at least one key indicated in the key negotiation request, based on the capabilities of the first entity and / or the local priority policy.

[0114] Optionally, in one embodiment of this disclosure, the capabilities of the first entity described above can be used to indicate: the key supported by the first entity for generating the OSCORE master key.

[0115] Optionally, in one embodiment of this disclosure, the keys supported by the first entity can be determined from at least one key indicated in the key negotiation request based on the capabilities of the first entity. When the number of keys supported by the first entity is one, that single key can be directly determined as the target key. When the number of keys supported by the first entity is multiple, a key can be selected as the target key from these multiple keys based on the first entity's local policy. Optionally, the local policy can be a local priority policy (i.e., selection based on key usage priority) or a random selection policy. That is, in one embodiment of this disclosure, the first entity can select a key as the target key from the multiple keys based on the usage priorities of different keys. Optionally, the usage priorities of different keys can be configured by other core network devices, or they can be agreed upon by a protocol. Alternatively, in another embodiment of this disclosure, the first entity can also randomly select a key from the multiple keys as the target key.

[0116] For example, suppose the key negotiation request received by the first entity includes: A-KID, B-TID, first key indication information, and second key indication information. Then, the key negotiation request indicates at least one key: an AKMA-related key, a first key, and a second key. If the first entity supports two keys for generating the OSCORE master key: an AKMA-related key and a first key, then the first entity needs to select one of these two keys as the target key. The first entity can select the key with higher priority from the AKMA-related key and the first key based on key usage priority. For example, if the key usage priority is: the AKMA-related key has a higher priority than the GBA-related key, and among the GBA-related keys, the first key has a higher priority than the second key, then the first entity can select the AKMA-related key with higher priority as the target key. Alternatively, the first entity may randomly select one of the AKMA-related keys and the first key as the target key, for example, it may randomly select the AKMA-related key as the target key.

[0117] The second step is to determine the key identifier and / or key indication information corresponding to the selected target key as the target information mentioned above.

[0118] Optionally, in one embodiment of this disclosure, when the target key selected by the first entity is an AKMA-related key, the key identifier "A-KID" corresponding to the AKMA-related key can be determined as the target information; when the target key selected by the first entity is a first key, the key identifier "B-TID" corresponding to the first key and the first key indication information corresponding to the first key can be determined as the target information; when the target key selected by the first entity is a second key, the key identifier "B-TID" corresponding to the second key and the second key indication information corresponding to the second key can be determined as the target information.

[0119] Furthermore, it should be noted that in one embodiment of this disclosure, there may be a situation where "at least one key indicated by the key negotiation request does not include a key supported by the first entity". When this situation occurs, it indicates that the key negotiation between the first entity and the UE has failed. In this case, the target information determined in step 202 can be used to indicate that the key negotiation has failed.

[0120] Step 203: Indicate the target key to the UE based on the target information.

[0121] Optionally, in one embodiment of this disclosure, the above-mentioned "indicating the target key identifier to the UE" may include: sending a key negotiation response to the UE. Optionally, the key negotiation response may be sent via a CoAP response message, and the key negotiation response may include a second key hint, which may be determined based on the target information, and the second key hint may indicate the target key.

[0122] Optionally, the method by which the second key hint indicates the target key may include at least one of the following:

[0123] The second key hint indicates the target key by including target information;

[0124] The second key hint indicates the target key by indicating the target information. Optionally, at least one key identifier and / or at least one key indication information included in the above key negotiation request may correspond to different indices and / or sequence numbers. Based on this, the second key hint can indicate the target information by carrying the index and / or sequence number corresponding to the target information, thereby indicating the target key. For example, suppose that the key negotiation request received by the first entity in step 201 includes: A-KID, B-TID, and first key indication information; wherein the indices of A-KID, B-TID, and first key indication information are index #1, index #2, and index #3, respectively; and suppose that the target information determined by the first entity in step 202 is: B-TID and first key indication information. Then, the second key hint sent by the first entity to the UE in step 203 may carry index #2 and index #3. Thus, based on the second key hint, the UE can know that the target information determined by the first entity is: B-TID and first key indication information, and therefore can know that the target key determined by the first entity is: the first key.

[0125] Optionally, the format of the key negotiation response, which includes the second key hint mentioned above, can be as follows:

[0126]

[0127] Alternatively, it can be expressed in the following format:

[0128]

[0129] Optionally, the "N2, UE-SID" parameters mentioned above in the key negotiation response are existing parameters and will not be described in detail. Also, the "Information about the selected key" mentioned above in the key negotiation request is the aforementioned second key hint. For information on "CBOR Array" and other parameters, please refer to the foregoing content.

[0130] Therefore, in one embodiment of this disclosure, the first entity indicates the target key to the UE through the aforementioned "Information about the selected key" so that the UE can determine the target key based on the first entity's indication and further generate an OSCORE master key based on the target key. This enables the UE to achieve secure communication with the first entity based on the generated OSCORE master key, ensuring the security and stability of wireless communication.

[0131] It should be noted that, in one embodiment of this disclosure, when the first entity determines that key negotiation has failed in step 202, step 203 will not indicate the target key to the UE based on the target information, but will instead indicate key negotiation failure to the UE. Optionally, the first entity may send a key negotiation response to the UE, which may be sent, for example, via a CoAP response message. The key negotiation response may include a second key prompt, which may be used to indicate key negotiation failure and / or the reason for the failure. The format of the key negotiation response can be referred to the following description, where "failure cause" indicates the reason for the key negotiation failure.

[0132]

[0133] Alternatively, it can be expressed in the following format:

[0134]

[0135] For a detailed description of the above parameters, please refer to the foregoing embodiments.

[0136] In summary, in the key negotiation method provided by this disclosure, a first entity receives a key negotiation request sent by a UE. This request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key. Then, the first entity determines target information based on the at least one key identifier and / or at least one key indication information in the key negotiation request. This target information indicates a target key, which is the key selected by the first entity from the keys indicated by the at least one key identifier and / or at least one key indication information in the key negotiation request for generating the OSCORE master key. Furthermore, the first entity also indicates the target key to the UE based on the target information. Therefore, this disclosure provides a key negotiation method for negotiating between the UE and a first entity which key will be used to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key. This enables secure communication between the UE and the first entity based on the OSCORE master key, ensuring the security and stability of wireless communication.

[0137] Figure 3 This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by a first entity, such as... Figure 3 As shown, the key negotiation method may include the following steps:

[0138] Step 301: Obtain the target key based on the target information.

[0139] Optionally, in one embodiment of this disclosure, after the first entity performs the aforementioned step 202 (i.e., after determining the target information), the first entity can obtain the target key corresponding to the target information from other core network devices based on the target information, so as to further generate the aforementioned OSCORE master key based on the target key. Wherein, when the first entity selects different target information, the first entity will obtain the corresponding target key from different core network devices.

[0140] Optionally, in one embodiment of this disclosure, in response to the target information including A-KID, it is indicated that the target key selected by the first entity is: AKMA related key (i.e., K... AF The first entity can obtain the AKMA-related key K from the Authentication and Key Management for Applications Anchor Function (AAnF) based on the target information (i.e., A-KID). AFOptionally, the first entity may send a first request to AAnF, the first request carrying an A-KID, and AAnF may, based on the A-KID in the first request, transfer the corresponding AKMA-related key K. AF Send to the first entity.

[0141] Optionally, in another embodiment of this disclosure, when the target information includes B-TID and first key indication information, it indicates that the target key selected by the first entity is: the first key (i.e., Ks_int_NAF). In this case, the first entity can obtain the first key from the BSF based on the B-TID and the first key indication information. Optionally, the first entity can send a second request to the BSF, the second request carrying the B-TID and the first key indication information, and the BSF can send the first key to the first entity based on the B-TID and the first key indication information in the second request.

[0142] Optionally, in another embodiment of this disclosure, when the target information includes B-TID and second key indication information, it indicates that the target key selected by the first entity is the second key (i.e., Ks_ext_NAF). In this case, the first entity can obtain the second key from the BSF based on the B-TID and second key indication information. Optionally, the first entity can send a third request to the BSF, which carries the B-TID and second key indication information. The BSF can then send the second key to the first entity based on the B-TID and second key indication information in the third request.

[0143] Optionally, in one embodiment of this disclosure, the first entity obtains a target key from other core network devices so that the first entity can generate an OSCORE master key based on the target key. This enables the first entity to achieve secure communication with the UE based on the generated OSCORE master key, ensuring the security and stability of wireless communication.

[0144] In summary, the key negotiation method provided in this disclosure provides a key negotiation method for negotiating with a first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0145] Figure 4 This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by a first entity, such as... Figure 4 As shown, the key negotiation method may include the following steps:

[0146] Step 401: In response to a key negotiation request triggered by a CoAP client located in the UE's UICC, the key negotiation request includes at least one of A-KID, B-TID, and first key indication information.

[0147] For a detailed description of step 401, please refer to the foregoing embodiments.

[0148] In summary, the key negotiation method provided in this disclosure provides a key negotiation method for negotiating with a first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0149] Figure 5 This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by a first entity, such as... Figure 5 As shown, the key negotiation method may include the following steps:

[0150] Step 501: In response to a key negotiation request triggered by a CoAP client located in the ME of the UE, the key negotiation request includes at least one of A-KID, B-TID, and second key indication information.

[0151] For a detailed description of step 501, please refer to the foregoing embodiments.

[0152] In summary, the key negotiation method provided in this disclosure provides a key negotiation method for negotiating with a first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0153] Figure 6 This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by a first entity, such as... Figure 6 As shown, the key negotiation method may include the following steps:

[0154] Step 601: Generate the OSCORE master key based on the target key.

[0155] Optionally, in one embodiment of this disclosure, the first entity may derive the OSCORE master key based on the target key, or the first entity may directly set the target key as the OSCORE master key.

[0156] Step 602: Communicate with the UE based on the OSCORE master key.

[0157] In summary, the key negotiation method provided in this disclosure provides a key negotiation method for negotiating with a first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0158] Figure 7 This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by the UE, as follows: Figure 7 As shown, the key negotiation method may include the following steps:

[0159] Step 701: Send a key negotiation request to the first entity. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key.

[0160] Optionally, the at least one key identifier includes at least one of the following:

[0161] The A-KID corresponding to the AKMA-related key, wherein the A-KID indicates that the keys supported by the UE for generating the OSCORE master key include: AKMA-related keys;

[0162] The B-TID corresponding to the GBA-related key indicates that the keys supported by the UE for generating the OSCORE master key include: GBA-related keys.

[0163] Optionally, the GBA-related key includes a first key and a second key, the key negotiation request includes a B-TID, the B-TID further includes a first key hint, the first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key, the first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key in the GBA-related key, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key in the GBA-related key.

[0164] Optionally, the GBA-related key includes a first key and a second key, the key negotiation request includes a B-TID, and the key negotiation request further includes a first key hint, the first key hint including a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key, the first key indication information indicating that the key supported by the UE for generating the OSCORE master key includes the first key in the GBA-related key, and the second key indication information indicating that the key supported by the UE for generating the OSCORE master key includes the second key in the GBA-related key.

[0165] Optionally, the key negotiation request is triggered by the CoAP client in the UE;

[0166] In response to the CoAP client being located in the UICC of the UE, the first key prompt includes first key indication information;

[0167] In response to the CoAP client being located in the ME of the UE, the first key prompt includes second key indication information.

[0168] Optionally, the key negotiation request is sent via a CoAP request message.

[0169] Step 702: Determine the target key based on the instruction of the first entity.

[0170] Optionally, in one embodiment of this disclosure, the above-described determination of the target key based on the indication of the first entity may include:

[0171] The terminal device receives a key negotiation response from the UE, which includes a second key hint indicating a target key; details regarding the second key hint can be found in the description of the above embodiments. Furthermore, the terminal device can determine the target information based on the second key hint, and then generate a corresponding target key based on that target information.

[0172] Optionally, in one embodiment of this disclosure, the UE may also determine that key negotiation has failed based on the indication of the first entity.

[0173] Furthermore, for a detailed description of steps 701-702, please refer to the foregoing embodiments.

[0174] In summary, in the key negotiation method provided by this disclosure, the UE sends a key negotiation request to a first entity. This request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key. Then, based on the indication from the first entity, a target key is determined. This target key is the key selected by the first entity from the keys indicated by at least one key identifier and / or at least one key indication information in the key negotiation request for generating the OSCORE master key. Therefore, this disclosure provides a key negotiation method for the UE and the first entity to negotiate which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key. This enables secure communication between the UE and the first entity based on the OSCORE master key, ensuring the security and stability of wireless communication.

[0175] Figure 8a This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by the UE, as follows: Figure 8a As shown, the key negotiation method may include the following steps:

[0176] Step 801a: Generate the OSCORE master key based on the target key;

[0177] Step 802a: Communicate with the first entity based on the OSCORE master key.

[0178] For a detailed description of steps 801a-802a, please refer to the foregoing embodiments.

[0179] In summary, the key negotiation method provided in this disclosure provides a key negotiation method for negotiating with a first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0180] Figure 8b This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by the UE, as follows: Figure 8b As shown, the key negotiation method may include the following steps:

[0181] Step 801b: In response to a key negotiation request triggered by a CoAP client located in the UE's UICC, the key negotiation request includes at least one of A-KID, B-TID, and first key indication information.

[0182] For a detailed description of step 801b, please refer to the foregoing embodiments.

[0183] In summary, the key negotiation method provided in this disclosure provides a key negotiation method for negotiating with a first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0184] Figure 8c This is a flowchart illustrating a key negotiation method provided in an embodiment of this disclosure. The method is executed by the UE, as follows: Figure 8c As shown, the key negotiation method may include the following steps:

[0185] Step 801c: In response to a key negotiation request triggered by a CoAP client located in the ME of the UE, the key negotiation request includes at least one of A-KID, B-TID, and second key indication information.

[0186] For a detailed description of step 801c, please refer to the foregoing embodiments.

[0187] In summary, the key negotiation method provided in this disclosure provides a key negotiation method for negotiating with a first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0188] Figure 9 An interactive flowchart of a key negotiation method provided in an embodiment of this disclosure is shown below. Figure 9 As shown, the key negotiation method may include the following steps:

[0189] Step 1: The UE or the CoAP client in the UE sends a CoAP request message to the AF or NAF. The CoAP request message includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key.

[0190] Step 2: The AF or NAF determines target information based on at least one key identifier and / or at least one key indication information. This target information is used to indicate a target key or to indicate key negotiation failure. The target key is the key determined by the first entity for generating the OSCORE master key. When the target information is used to indicate a target key, steps 3-4, 5a, and 6-8 can be executed subsequently. When the target information is used to indicate key negotiation failure, step 5b can be executed subsequently.

[0191] Step 3: AF or NAF requests the target key from AAnF or BSF based on the target information.

[0192] Step 4: AF or NAF receives the target key sent by AAnF or BSF.

[0193] Step 5a: The AF or NAF sends a CoAP response message to the UE, which indicates the target key.

[0194] Step 5b: The AF or NAF sends a CoAP response message to the UE, which indicates that key negotiation failed.

[0195] Step 6: The UE determines the target key based on the indication of AF or NAF.

[0196] Step 7: AF or NAF, and UE generate OSCORE master key based on target key.

[0197] Step 8: AF or NAF, and UE communicate based on the OSCORE master key.

[0198] For a detailed description of steps 1-8 above, please refer to the foregoing embodiments.

[0199] Optionally, in one embodiment of this disclosure, steps 3-4 and 5a can be executed simultaneously, or step 5a can be executed first and then steps 3-4, or steps 3-4 can be executed first and then step 5a. This embodiment of the disclosure does not limit this.

[0200] In summary, the key negotiation method provided in this disclosure provides a key negotiation method for negotiating with a first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0201] Optionally, in one embodiment of this disclosure, a communication system is also provided, which may include a UE and a core network device, the core network device including an AF or NAF (i.e., the core network device can be substantially understood as the first entity described above). The core network device is configured to implement the above-described... Figure 2-6 The key negotiation method described in the embodiment, wherein the UE is configured to implement the above... Figure 7-8c The key negotiation method described in the embodiment.

[0202] Optionally, in one embodiment of this disclosure, a key negotiation method is also provided, applied to the above-mentioned communication system, the method including:

[0203] The UE sends a key negotiation request to the core network equipment. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key.

[0204] The core network device determines the target information based on at least one key identifier and / or at least one key indication information in the key negotiation request. The target information is used to indicate the target key, which is the key used to generate the OSCORE master key.

[0205] The core network equipment indicates the target key to the UE.

[0206] For a detailed description of the above methods, please refer to the foregoing embodiments.

[0207] Figure 10 This is a schematic diagram of the structure of a communication device provided in an embodiment of the present disclosure, as shown below. Figure 10 As shown, the device may include:

[0208] The transceiver module is used to receive a key negotiation request sent by the UE. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating a restricted representation state transition environment object security OSCORE master secret.

[0209] The processing module is configured to determine target information based on at least one key identifier and / or at least one key indication information in the key negotiation request, wherein the target information is used to indicate a target key, and the target key is a key used to generate the OSCORE master key;

[0210] The transceiver module is used to indicate the target key to the UE based on the target information.

[0211] In summary, in the communication device provided in this embodiment, a first entity receives a key negotiation request sent by a UE. This key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key. Then, the first entity determines target information based on the at least one key identifier and / or at least one key indication information in the key negotiation request. This target information indicates a target key, which is the key selected by the first entity from the keys indicated by the at least one key identifier and / or at least one key indication information in the key negotiation request for generating the OSCORE master key. Furthermore, the first entity also indicates the target key to the UE based on the target information. Therefore, this embodiment provides a key negotiation method for negotiating between the UE and the first entity which key to use to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key, enabling secure communication between the UE and the first entity based on the OSCORE master key, and ensuring the security and stability of wireless communication.

[0212] Optionally, in one embodiment of this disclosure, the at least one key identifier includes at least one of the following:

[0213] The Application Authentication and Key Management (AKMA) related key corresponds to the Application Authentication and Key Management (AKMA) key identifier A-KID, whereby A-KID indicates that the keys supported by the UE for generating the OSCORE master key include: AKMA related keys;

[0214] The boot transaction identifier B-TID corresponding to the General Boot Architecture (GBA) related key indicates that the keys supported by the UE for generating the OSCORE master key include: GBA related keys.

[0215] Optionally, in one embodiment of this disclosure, the GBA-related key includes a first key and a second key;

[0216] The key negotiation request includes a B-TID, and the B-TID further includes a first key hint. The first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key. The first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys.

[0217] Optionally, in one embodiment of this disclosure, the GBA-related key includes a first key and a second key;

[0218] The key negotiation request includes a B-TID and a first key hint. The first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key. The first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys.

[0219] Optionally, in one embodiment of this disclosure, the key negotiation request is triggered by a CoAP client in the UE;

[0220] In response to the CoAP client being located in the UE's Universal Integrated Circuit Card (UICC), the first key prompt includes first key indication information;

[0221] In response to the CoAP client being located in the UE's mobile device ME, the first key prompt includes second key indication information.

[0222] Optionally, in one embodiment of this disclosure, the processing module is further configured to:

[0223] Based on the capabilities of the first entity and / or local priority policies, a target key is selected from at least one key indicated by the key negotiation request;

[0224] The key identifier and / or key indication information corresponding to the target key are determined as the target information.

[0225] Optionally, in one embodiment of this disclosure, the target information includes an A-KID, which is used to indicate an AKMA-related key; or

[0226] The target information includes B-TID and first key indication information, wherein the target information is used to indicate the first key; or

[0227] The target information includes B-TID and second key indication information, which is used to indicate the second key.

[0228] Optionally, in one embodiment of this disclosure, the apparatus is further configured to:

[0229] Obtain the target key based on the target information;

[0230] The step of obtaining the target key based on the target information includes:

[0231] In response to the target information including A-KID, the AKMA-related key: KAF is obtained from the AKMA anchor function AAnF based on the target information;

[0232] In response to the target information including B-TID and first key indication information, or in response to the target information including B-TID and second key indication information, the first key or the second key is obtained from the bootstrap server function (BSF) based on the target information.

[0233] Optionally, in one embodiment of this disclosure, the transceiver module is further configured to:

[0234] A key negotiation response is sent to the UE, the key negotiation response including a second key hint, the second key hint being determined based on the target information, the second key hint indicating the target key.

[0235] Optionally, in one embodiment of this disclosure, the apparatus is further configured to:

[0236] Generate an OSCORE master key based on the target key;

[0237] The OSCORE master key is used to communicate with the UE.

[0238] Optionally, in one embodiment of this disclosure, the key negotiation request is sent via a CoAP request message.

[0239] Optionally, in one embodiment of this disclosure, the key negotiation response is sent via a CoAP response message.

[0240] Figure 11 This is a schematic diagram of the structure of a communication device provided in an embodiment of the present disclosure, as shown below. Figure 11 As shown, the device may include:

[0241] The transceiver module is used to send a key negotiation request to the first entity. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key.

[0242] A processing module is used to determine a target key based on the indication of the first entity.

[0243] In summary, in the communication device provided in this embodiment, the UE sends a key negotiation request to a first entity. This request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key. Then, based on the indication from the first entity, a target key is determined. This target key is the key selected by the first entity from the keys indicated by at least one key identifier and / or at least one key indication information in the key negotiation request for generating the OSCORE master key. Therefore, this embodiment provides a key negotiation method for negotiating between the UE and the first entity which key will be used to generate the OSCORE master key, thereby ensuring that the UE and the first entity can successfully generate the OSCORE master key. This enables secure communication between the UE and the first entity based on the OSCORE master key, ensuring the security and stability of wireless communication.

[0244] Optionally, in one embodiment of this disclosure, the at least one key identifier includes at least one of the following:

[0245] The A-KID corresponding to the AKMA-related key, wherein the A-KID indicates that the keys supported by the UE for generating the OSCORE master key include: AKMA-related keys;

[0246] The B-TID corresponding to the GBA-related key indicates that the keys supported by the UE for generating the OSCORE master key include: GBA-related keys.

[0247] Optionally, in one embodiment of this disclosure, the GBA-related key includes a first key and a second key;

[0248] The key negotiation request includes a B-TID, and the B-TID further includes a first key hint. The first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key. The first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys.

[0249] Optionally, in one embodiment of this disclosure, the GBA-related key includes a first key and a second key;

[0250] The key negotiation request includes a B-TID and a first key hint. The first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key. The first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys.

[0251] Optionally, in one embodiment of this disclosure, the key negotiation request is triggered by a CoAP client in the UE;

[0252] In response to the CoAP client being located in the UICC of the UE, the first key prompt includes first key indication information;

[0253] In response to the CoAP client being located in the ME of the UE, the first key prompt includes second key indication information.

[0254] Optionally, in one embodiment of this disclosure, the apparatus is further configured to:

[0255] Generate an OSCORE master key based on the target key;

[0256] The OSCORE master key is used to communicate with the first entity.

[0257] Optionally, in one embodiment of this disclosure, the key negotiation request is sent via a CoAP request message.

[0258] Optionally, in one embodiment of this disclosure, the processing module is further configured to:

[0259] Receive a key negotiation response sent by the UE, the key negotiation response including a second key hint, the second key hint indicating the target key;

[0260] The target key is determined based on the second key hint.

[0261] Optionally, in one embodiment of this disclosure, the key negotiation response is sent via a CoAP response message.

[0262] Please see Figure 12 , Figure 12This is a schematic diagram of the structure of a communication device 1200 provided in an embodiment of this disclosure. The communication device 1200 can be a base station, a terminal, or a chip, chip system, or processor that supports the base station in implementing the above methods; it can also be a chip, chip system, or processor that supports the terminal in implementing the above methods. This device can be used to implement the methods described in the above method embodiments, and specific details can be found in the descriptions of the above method embodiments.

[0263] The communication device 1200 may include one or more processors 1201. The processor 1201 may be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control the communication device (e.g., base station, baseband chip, terminal, terminal chip, DU or CU, etc.), execute computer programs, and process data from the computer programs.

[0264] Optionally, the communication device 1200 may further include one or more memories 1202, which may store a computer program 1204. The processor 1201 executes the computer program 1204 to cause the communication device 1200 to perform the methods described in the above method embodiments. Optionally, the memory 1202 may also store data. The communication device 1200 and the memory 1202 may be provided separately or integrated together.

[0265] Optionally, the communication device 1200 may also include a transceiver 1205 and an antenna 1206. The transceiver 1205 may be referred to as a transceiver unit, transceiver, or transceiver circuit, etc., and is used to implement the transmission and reception functions. The transceiver 1205 may include a receiver and a transmitter. The receiver may be referred to as a receiver or receiving circuit, etc., and is used to implement the receiving function; the transmitter may be referred to as a transmitter or transmitting circuit, etc., and is used to implement the transmitting function.

[0266] Optionally, the communication device 1200 may further include one or more interface circuits 1207. The interface circuits 1207 are used to receive code instructions and transmit them to the processor 1201. The processor 1201 executes the code instructions to cause the communication device 1200 to perform the methods described in the above method embodiments.

[0267] In one implementation, the processor 1201 may include a transceiver for implementing receiving and transmitting functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing receiving and transmitting functions may be separate or integrated. The aforementioned transceiver circuit, interface, or interface circuit can be used for reading and writing code / data, or it can be used for transmitting or relaying signals.

[0268] In one implementation, processor 1201 may store computer program 1203, which runs on processor 1201 and causes communication device 1200 to perform the methods described in the above method embodiments. Computer program 1203 may be embedded in processor 1201, in which case processor 1201 may be implemented in hardware.

[0269] In one implementation, the communication device 1200 may include circuitry capable of performing the functions of transmitting, receiving, or communicating as described in the foregoing method embodiments. The processor and transceiver described in this disclosure can be implemented on integrated circuits (ICs), analog ICs, radio frequency integrated circuits (RFICs), mixed-signal ICs, application-specific integrated circuits (ASICs), printed circuit boards (PCBs), electronic devices, etc. The processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductors (CMOS), n-metal-oxide-semiconductor (NMOS), positive-channel metal oxide semiconductors (PMOS), bipolar junction transistors (BJTs), bipolar CMOS (BiCMOS), silicon-germanium (SiGe), gallium arsenide (GaAs), etc.

[0270] The communication device described in the above embodiments may be a base station or a terminal, but the scope of the communication device described in this disclosure is not limited thereto, and the structure of the communication device may vary. Figure 12 The communication device may be a standalone device or part of a larger device. For example, the communication device may be:

[0271] (1) Independent integrated circuit IC, or chip, or chip system or subsystem;

[0272] (2) A collection of one or more ICs, optionally including storage components for storing data and computer programs;

[0273] (3) ASIC, such as modem;

[0274] (4) Modules that can be embedded in other devices;

[0275] (5) Receivers, terminals, smart terminals, cellular phones, wireless devices, handheld devices, mobile units, vehicle-mounted devices, base stations, cloud devices, artificial intelligence devices, etc.

[0276] (6) Others, etc.

[0277] For cases where the communication device can be a chip or a chip system, please refer to [link / reference]. Figure 13 The diagram shows the structure of the chip. Figure 13 The chip shown includes a processor 1301 and an interface 1302. There can be one or more processors 1301, and multiple interfaces 1302.

[0278] Optionally, the chip also includes a memory 1303, which is used to store necessary computer programs and data.

[0279] Those skilled in the art will also understand that the various illustrative logical blocks and steps listed in the embodiments of this disclosure can be implemented by electronic hardware, computer software, or a combination of both. Whether such functionality is implemented in hardware or software depends on the specific application and the overall system design requirements. Those skilled in the art can implement the described functionality using various methods for each specific application, but such implementation should not be construed as exceeding the scope of protection of the embodiments of this disclosure.

[0280] This disclosure also provides a readable storage medium having instructions stored thereon that, when executed by a computer, implement the functions of any of the above method embodiments.

[0281] This disclosure also provides a computer program product that, when executed by a computer, implements the functions of any of the above method embodiments.

[0282] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).

[0283] Those skilled in the art will understand that the various numerical designations such as "first," "second," etc., used in this disclosure are merely for the convenience of description and are not intended to limit the scope of the embodiments of this disclosure, nor do they indicate the order of events.

[0284] At least one of the features described in this disclosure can also be described as one or more, and multiple features can be two, three, four or more, and this disclosure does not impose any limitations. In the embodiments of this disclosure, for a technical feature, the technical features in that technical feature are distinguished by "first", "second", "third", "A", "B", "C" and "D", etc., and there is no sequential order or size order among the technical features described by "first", "second", "third", "A", "B", "C" and "D".

[0285] The correspondences shown in the tables of this disclosure can be configured or predefined. The values ​​of the information in each table are merely examples and can be configured to other values; this disclosure is not limiting. When configuring the correspondences between information and parameters, it is not necessarily required to configure all the correspondences shown in each table. For example, the correspondences shown in some rows of the tables in this disclosure may not be configured. Furthermore, appropriate modifications and adjustments can be made based on the above tables, such as splitting, merging, etc. The names of the parameters shown in the headers of the above tables can also use other names that the communication device can understand, and the values ​​or representations of the parameters can also be other values ​​or representations that the communication device can understand. In the implementation of the above tables, other data structures can also be used, such as arrays, queues, containers, stacks, linear lists, pointers, linked lists, trees, graphs, structures, classes, heaps, hash tables, or hash tables, etc.

[0286] The predefined terms in this disclosure can be understood as defined, predefined, stored, pre-stored, pre-negotiated, pre-configured, solidified, or pre-burned.

[0287] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0288] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0289] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.

Claims

1. A key negotiation method, characterized in that, The method is executed by the first entity, and the method includes: The system receives a key negotiation request sent by a user equipment (UE), the key negotiation request including: key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating a restricted representation state transition environment object security OSCORE master secret; Target information is determined based on at least one key identifier and / or at least one key indication information in the key negotiation request, wherein the target information is used to indicate a target key, and the target key is a key used to generate the OSCORE master key; The target key is indicated to the UE based on the target information; The step of determining the target information based on at least one key identifier and / or at least one key indication information in the key negotiation request includes: Based on the capabilities of the first entity and / or local priority policies, a target key is selected from at least one key indicated by the key negotiation request; The key identifier and / or key indication information corresponding to the target key are determined as the target information.

2. The method as described in claim 1, characterized in that, The at least one key identifier includes at least one of the following: The Application Authentication and Key Management (AKMA) related key corresponds to the Application Authentication and Key Management (AKMA) key identifier A-KID, whereby A-KID indicates that the keys supported by the UE for generating the OSCORE master key include: AKMA related keys; The boot transaction identifier B-TID corresponding to the General Boot Architecture (GBA) related key indicates that the keys supported by the UE for generating the OSCORE master key include: GBA related keys.

3. The method as described in claim 2, characterized in that, The GBA-related keys include a first key and a second key; The key negotiation request includes a B-TID, and the B-TID further includes a first key hint. The first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key. The first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys.

4. The method as described in claim 2, characterized in that, The GBA-related keys include a first key and a second key; The key negotiation request includes a B-TID and a first key hint. The first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key. The first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys.

5. The method as described in claim 3 or 4, characterized in that, The key negotiation request is triggered and sent by the CoAP client in the UE; In response to the CoAP client being located in the UE's Universal Integrated Circuit Card (UICC), the first key prompt includes first key indication information; In response to the CoAP client being located in the UE's mobile device ME, the first key prompt includes second key indication information.

6. The method as described in claim 1, characterized in that, The target information includes A-KID, which is used to indicate the AKMA-related key; or The target information includes B-TID and first key indication information, wherein the target information is used to indicate the first key; or The target information includes B-TID and second key indication information, which is used to indicate the second key.

7. The method as described in claim 2, characterized in that, The method further includes: Obtain the target key based on the target information; The step of obtaining the target key based on the target information includes: In response to the target information including A-KID, the AKMA-related key K is obtained from the AKMA anchor function AAnF based on the target information. AF ; In response to the target information including B-TID and first key indication information, or in response to the target information including B-TID and second key indication information, the first key or the second key is obtained from the bootstrap server function (BSF) based on the target information.

8. The method as described in claim 2, characterized in that, The step of instructing the UE with the target key based on the target information includes: A key negotiation response is sent to the UE, the key negotiation response including a second key hint, the second key hint being determined based on the target information, the second key hint indicating the target key.

9. The method as described in claim 7, characterized in that, The method further includes: Generate an OSCORE master key based on the target key; The OSCORE master key is used to communicate with the UE.

10. The method as described in claim 1, characterized in that, The key negotiation request is sent via a CoAP request message.

11. The method as described in claim 8, characterized in that, The key negotiation response is sent via a CoAP response message.

12. A key negotiation method, characterized in that, The method is executed by the UE, and the method includes: Send a key negotiation request to the first entity, the key negotiation request including key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key; The target key is determined based on the instructions of the first entity; The target key is indicated by the first entity based on target information, which includes a key identifier and / or key indication information corresponding to the target key. The target key is selected by the first entity from at least one key indicated by the key negotiation request based on the capabilities of the first entity and / or local priority policies.

13. The method as described in claim 12, characterized in that, The at least one key identifier includes at least one of the following: The A-KID corresponding to the AKMA-related key, wherein the A-KID indicates that the keys supported by the UE for generating the OSCORE master key include: AKMA-related keys; The B-TID corresponding to the GBA-related key indicates that the keys supported by the UE for generating the OSCORE master key include: GBA-related keys.

14. The method as described in claim 13, characterized in that, The GBA-related keys include a first key and a second key; The key negotiation request includes a B-TID, and the B-TID further includes a first key hint. The first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key. The first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys.

15. The method as described in claim 13, characterized in that, The GBA-related keys include a first key and a second key; The key negotiation request includes a B-TID and a first key hint. The first key hint includes a first key indication information corresponding to the first key and / or a second key indication information corresponding to the second key. The first key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the first key among the GBA-related keys, and the second key indication information indicates that the key supported by the UE for generating the OSCORE master key includes the second key among the GBA-related keys.

16. The method as described in claim 14 or 15, characterized in that, The key negotiation request is triggered and sent by the CoAP client in the UE; In response to the CoAP client being located in the UICC of the UE, the first key prompt includes first key indication information; In response to the CoAP client being located in the ME of the UE, the first key prompt includes second key indication information.

17. The method as described in claim 12, characterized in that, The method further includes: Generate an OSCORE master key based on the target key; The OSCORE master key is used to communicate with the first entity.

18. The method as described in claim 12, characterized in that, The key negotiation request is sent via a CoAP request message.

19. The method as described in claim 12, characterized in that, The determination of the target key based on the indication of the first entity includes: Receive a key negotiation response sent by the first entity, the key negotiation response including a second key hint indicating the target key; The target key is determined based on the second key hint.

20. The method as described in claim 19, characterized in that, The key negotiation response is sent via a CoAP response message.

21. A communication device, the device being applied in a first entity, comprising: The transceiver module is used to receive a key negotiation request sent by the UE. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating a restricted representation state transition environment OSCORE master secret. The processing module is configured to determine target information based on at least one key identifier and / or at least one key indication information in the key negotiation request, wherein the target information is used to indicate a target key, and the target key is a key used to generate the OSCORE master key; The transceiver module is used to indicate the target key to the UE based on the target information; The processing module is further configured to: Based on the capabilities of the first entity and / or local priority policies, a target key is selected from at least one key indicated by the key negotiation request; The key identifier and / or key indication information corresponding to the target key are determined as the target information.

22. A communication device, comprising: The transceiver module is used to send a key negotiation request to the first entity. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key. A processing module is used to determine a target key based on the indication of the first entity; The target key is indicated by the first entity based on target information, which includes a key identifier and / or key indication information corresponding to the target key. The target key is selected by the first entity from at least one key indicated by the key negotiation request based on the capabilities of the first entity and / or local priority policies.

23. A communication device, characterized in that, The device includes a processor and a memory, wherein the memory stores a computer program, and the processor executes the computer program stored in the memory to cause the device to perform the method as claimed in any one of claims 1 to 11, or the processor executes the computer program stored in the memory to cause the device to perform the method as claimed in any one of claims 12 to 20.

24. A communication device, characterized in that, include: Processor and interface circuitry, among which The interface circuit is used to receive code instructions and transmit them to the processor; The processor is configured to execute the code instructions to perform the method as claimed in any one of claims 1 to 11, or to execute the code instructions to perform the method as claimed in any one of claims 12 to 20.

25. A communication system, characterized in that, It includes a UE and a core network device; wherein the core network device is configured to implement the key negotiation method according to any one of claims 1 to 11, and the UE is configured to implement the key negotiation method according to any one of claims 12 to 20.

26. A communication method, characterized in that, Applied to a communication system, the method includes: The UE sends a key negotiation request to the core network equipment. The key negotiation request includes key identifiers and / or key indication information corresponding to at least one key supported by the UE for generating the OSCORE master key. The core network device determines the target information based on at least one key identifier and / or at least one key indication information in the key negotiation request. The target information is used to indicate the target key, which is the key used to generate the OSCORE master key. The core network device indicates the target key to the UE; The step of determining the target information based on at least one key identifier and / or at least one key indication information in the key negotiation request includes: Based on the capabilities of the core network equipment and / or local priority policies, a target key is selected from at least one key indicated in the key negotiation request; The key identifier and / or key indication information corresponding to the target key are determined as the target information.

27. A computer-readable storage medium for storing instructions that, when executed, cause the method of any one of claims 1 to 11 to be implemented, or, when executed, cause the method of any one of claims 12 to 20 to be implemented.

Citation Information

Patent Citations

  • Key determination method and device

    CN114726520A