Communication authentication method, apparatus, terminal, network device, medium and program product
By negotiating security capabilities between terminals and network devices and using the AES-256 algorithm for key enhancement, key information supporting at least 256 bits is generated, solving the problem of quantum computing cracking and improving the security of network information systems.
Patent Information
- Application Number
- CN202411182700.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-27
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2044-08-27
AI Technical Summary
Existing authentication and key negotiation algorithms are vulnerable to being cracked by quantum computing, threatening the security of network information systems.
By negotiating security capabilities between the terminal and network devices, and using the AES-256 algorithm for key enhancement, a second key information supporting at least 256 bits is generated, preventing quantum computing from breaking the code.
It enables secure capability negotiation and instruction between terminals and network devices, and the generated key information can resist quantum computing attacks, thereby improving the security of network information systems.
Smart Images

Figure CN119109574B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a communication authentication method, apparatus, terminal, network equipment, medium, and program product. Background Technology
[0002] With the rapid development of Internet technology, the network security risks of information systems continue to increase, and the threats and challenges are becoming increasingly severe. Cryptographic security is an important foundation of information security and can be used to ensure the data security of network information systems. Cryptographic technology is a core technology and an important means to ensure the security of network information systems.
[0003] Currently, the network authentication and key agreement (AKA) protocol of communication networks is based on the MILENAGE algorithm, which is used to complete the authentication and key negotiation between the Universal Subscriber Identity Module (USIM) and the User Data Management (UDM). The underlying algorithm of the MILENAGE algorithm is AES-128, and the key K shared between USIM and UDM is 128 bits.
[0004] However, with the development of quantum computing technology, traditional cryptographic algorithms face serious security threats. Quantum computers possess powerful computing capabilities, which can significantly reduce the difficulty of breaking symmetric cryptographic algorithms, greatly increasing the risk of AES-128 being cracked. Attackers can obtain the plaintext of the AES-128 algorithm and thus calculate the 128-bit key. Summary of the Invention
[0005] The purpose of this invention is to provide a communication authentication method, device, terminal, network equipment, medium, and program product to solve the problem that existing authentication and key negotiation algorithms are easily cracked by quantum computing.
[0006] To address the aforementioned technical problems, the embodiments of the present invention provide the following technical solutions:
[0007] In a first aspect, embodiments of the present invention provide a communication authentication method applied to a terminal, the method comprising:
[0008] Send a registration request to the network device, the registration request carrying a first security enhancement support bit (SES), the first SES being used to indicate the security capabilities supported by the terminal;
[0009] The network device receives first authentication information, which carries a second SES, and the second SES is used to indicate the security capabilities supported by the first authentication information.
[0010] According to the second SES, the first key information is enhanced with security to obtain the second key information. The first key information is obtained based on the core key K and the random number RAND in the first authentication information. The second key information is used for key derivation.
[0011] Optionally, the method further includes:
[0012] The first SES is generated when the Universal User Identity Module (USIM) on the terminal only supports the first cryptographic algorithm.
[0013] Optionally, the registration request carries a user-hidden identifier (SUCI), the SUCI including the first SES;
[0014] or,
[0015] The registration request carries the first SES through the first interface field.
[0016] Optionally, the authentication management field (AMF) of the first authentication information carries the second SES.
[0017] Optionally, the first key information includes a first encryption key CK and a first integrity protection key IK;
[0018] The second key information includes the second CK and the second IK;
[0019] Based on the second SES, the first key information is enhanced with security to obtain the second key information, including:
[0020] Based on the second SES, the first CK is enhanced with security measures to obtain the second CK;
[0021] The second IK is obtained by enhancing the security of the first IK based on the second SES.
[0022] Optionally, the security enhancement includes at least one of the following:
[0023] Security enhancement is performed based on a first symmetric key, wherein the first symmetric key is obtained when the USIM on the terminal only supports a first cryptographic algorithm. The first symmetric key is generated during the process of encrypting the user permanent identifier SUPI of the USIM to obtain SUCI using a first encryption mechanism. The first encryption mechanism is a key encapsulation-based encryption mechanism.
[0024] Security enhancements are achieved using Key Derivation Functions (KDF).
[0025] Optionally, the second CK supports a key length of at least 256 bits;
[0026] The second IK supports a key length of at least 256 bits.
[0027] Secondly, embodiments of the present invention also provide a communication authentication method applied to a network device, the method comprising:
[0028] The terminal receives a registration request, which carries a SUCI and a first SES, the first SES being used to indicate the security capabilities supported by the terminal.
[0029] Based on the core key K and AMF, first authentication information and third key information are generated. The first authentication information carries a second SES, which is used to indicate the security capabilities supported by the first authentication information.
[0030] Based on the core key K and the first SES, the third key information is enhanced to obtain the fourth key information, which is used for key derivation.
[0031] The first authentication information is sent to the terminal.
[0032] Optionally, the method further includes:
[0033] The first SES is obtained from the SUCI parsing;
[0034] or,
[0035] The first SES is obtained by parsing the first interface field of the registration request.
[0036] Optionally, the AMF of the first authentication information carries the second SES.
[0037] Optionally, based on the core key K and AMF, first authentication information and third key information are generated, including:
[0038] Based on the length of the core key K, determine the corresponding second cryptographic algorithm;
[0039] Using the second cryptographic algorithm, the first authentication information and the third key information are obtained based on the core key K and the AMF.
[0040] Optionally, the third key information includes a third CK and a third IK;
[0041] The fourth key information includes the fourth CK and the fourth IK;
[0042] Based on the core key K and the first SES, the third key information is enhanced to obtain the fourth key information, including:
[0043] Based on the length of the first SES and the core key, the third CK is enhanced with security to obtain the fourth CK;
[0044] Based on the length of the first SES and the core key, the third IK is enhanced with security to obtain the fourth IK.
[0045] Optionally, the security enhancement includes at least one of the following:
[0046] Security enhancement is performed based on a second symmetric key, which is obtained by decrypting the SUCI in the registration request using a first decryption mechanism based on a first SES. The first decryption mechanism is a key-encapsulated decryption mechanism.
[0047] Security enhancements are achieved using KDF.
[0048] Optionally, the fourth CK supports a key length of at least 256 bits;
[0049] The fourth IK supports a key length of at least 256 bits.
[0050] Thirdly, embodiments of the present invention also provide a communication authentication device, the device comprising:
[0051] The first sending module is used to send a registration request to the network device. The registration request carries a first security enhancement support bit (SES), which indicates the security capabilities supported by the terminal.
[0052] A first receiving module is configured to receive first authentication information sent by the network device, wherein the first authentication information carries a second SES and the second SES is used to indicate the security capabilities supported by the first authentication information.
[0053] The first processing module is used to perform security enhancement on the first key information according to the second SES to obtain the second key information. The first key information is obtained based on the core key K and the random number RAND in the first authentication information. The second key information is used for key derivation.
[0054] Fourthly, embodiments of the present invention also provide a communication authentication device, the device comprising:
[0055] The second receiving module is used to receive a registration request sent by the terminal. The registration request carries SUCI and a first SRS. The first SES is used to indicate the security capabilities supported by the terminal.
[0056] The second processing module is used to generate first authentication information and third key information based on the core key K and AMF. The first authentication information carries a second SES, which is used to indicate the security capabilities supported by the first authentication information.
[0057] The third processing module is used to perform security enhancement on the third key information based on the core key K and the first SES to obtain the fourth key information, which is used for key derivation.
[0058] The second sending module is used to send the first authentication information to the terminal.
[0059] Fifthly, embodiments of the present invention also provide a terminal, comprising: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; the processor, when executing the program or instructions, implements the steps of the communication authentication method as described in any one of the first aspects.
[0060] In a sixth aspect, embodiments of the present invention also provide a network device, including: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; when the processor executes the program or instructions, it implements the steps of the communication authentication method as described in any one of the second aspects.
[0061] In a seventh aspect, embodiments of the present invention also provide a readable storage medium having a program or instructions stored thereon, wherein the program or instructions, when executed by a processor, implement the steps of the communication authentication method as described in any one of the first aspects, or implement the steps of the communication authentication method as described in any one of the second aspects.
[0062] Eighthly, embodiments of the present invention also provide a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the communication authentication method as described in any one of the first aspects, or implement the steps of the communication authentication method as described in any one of the second aspects.
[0063] The beneficial effects of the above-described technical solution of the present invention are as follows:
[0064] The communication authentication method provided by this invention involves a terminal receiving a registration request sent by a network device. This registration request carries a first Security Authentication Element (SES) indicating the security capabilities supported by the terminal, enabling the network device to obtain the security capabilities supported by the terminal based on the first SES. The terminal also receives first authentication information sent by the network device, which carries a second SES. Based on the second SES, the terminal obtains the security capabilities supported by the first authentication information sent by the network device, thereby achieving negotiation and indication of security capabilities between the terminal and the network device. Furthermore, based on the second SES, the terminal performs security enhancement on the first key information to obtain second key information. Because the key information is enhanced, it can be prevented from being cracked by quantum computing. Attached Figure Description
[0065] Figure 1 A flowchart illustrating a communication authentication method applied to a terminal, as provided in an embodiment of the present invention;
[0066] Figure 2 A schematic diagram of the SUCI format provided in an embodiment of the present invention;
[0067] Figure 3 A flowchart of a communication authentication method for network devices provided in an embodiment of the present invention;
[0068] Figure 4 A flowchart illustrating the identity submission process between a terminal and a network device, provided in this embodiment of the invention.
[0069] Figure 5 The main authentication flowchart provided for embodiments of the present invention;
[0070] Figure 6 This is one of the structural schematic diagrams of the communication authentication device provided in the embodiments of the present invention;
[0071] Figure 7 This is a second schematic diagram of the communication authentication device provided in an embodiment of the present invention;
[0072] Figure 8 This is a schematic diagram of the terminal structure provided in an embodiment of the present invention;
[0073] Figure 9 This is a schematic diagram of the structure of a network device provided in an embodiment of the present invention. Detailed Implementation
[0074] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0075] To address the problem that existing authentication and key negotiation algorithms are easily cracked by quantum computing, this invention provides a method, apparatus, device, storage medium, and program product for secure capability negotiation.
[0076] like Figure 1 As shown, this embodiment of the invention provides a security capability negotiation method applied to a terminal, the method comprising:
[0077] Step 101: Send a registration request to the network device. The registration request carries a first Security Enhancement Support (SES) bit, which indicates the security capabilities supported by the terminal.
[0078] It should be noted that the terminal (i.e., user equipment, UE) provided in this embodiment of the invention is a collective term for mobile equipment (ME) and USIM. USIM stores data such as the user's core key K and identifier. ME and USIM work together to complete network authentication.
[0079] It is understood that the security capability negotiation method for terminals provided in this embodiment of the invention is executed by the ME.
[0080] In this embodiment, the terminal is a terminal that supports enhanced security capabilities. Enhanced security capabilities refer to the replacement of the ME (Mechanical Encryption) on the terminal side with one supporting the AES-128 algorithm (supporting the Advanced Encryption Standard (AES) algorithm with a key length of 128 bits) to one supporting the AES-256 algorithm (supporting the AES algorithm with a key length of 256 bits) to counter quantum attacks. In other words, the security capabilities supported by the terminal can be understood as whether the terminal supports enhanced security capabilities, specifically whether it supports the AES algorithm (or encryption mechanism) with a key length of 256 bits.
[0081] In this step, the ME that supports enhanced security capabilities writes the first SES into the registration request. The first SES is used to indicate whether the ME supports enhanced security capabilities. This registration request is an Initial Registration Request. Through the registration request, the first SES is synchronized to the network device. The network device knows whether the ME supports enhanced security capabilities based on the first SES.
[0082] The registration request also carries a Subscription Concealed Identifier (SUCI).
[0083] In this embodiment, the network device is a Home Network (HN) or a UDM network element within the HN.
[0084] Step 102: Receive first authentication information sent by the network device. The first authentication information carries a second SES, which is used to indicate the security capabilities supported by the first authentication information.
[0085] The first authentication information includes the following authentication parameters: Authentication Token (AUTN) and Random Challenge (RAND).
[0086] The security capabilities supported by the first authentication information can be understood as whether the first authentication information or the authentication parameters in the first authentication information support enhanced security capabilities, that is, whether the key length of the authentication information or the key parameters in the authentication information is 256 bits.
[0087] In this step, after receiving the registration request, if the registration request contains a first SES set to 1, the UDM generates a second SES and stores this second SES in the first authentication information, setting it to 1. That is, the UDM receives the first authentication information sent by the network device, which carries the second SES. This second SES is used to indicate whether the first authentication information supports enhanced security capabilities.
[0088] Specifically, based on the registration request, the UDM decrypts the Subscription Permanent Identifier (SUPI) from the SUCI in the registration request and creates the first authentication vector (AV), namely the 5G HE AV. This first authentication vector includes AUTN, RAND, expected response (XRES), and security key K. AUSF .
[0089] It is understandable that AUTN and RAND in the first authentication vector are AUTN and RAND in the first authentication information, respectively.
[0090] It should also be noted that if there is no first SES with a value of 1 in the registration request, the network device will not perform any additional processing.
[0091] Subsequently, UDM will include AUTN, RAND, expected response XRES*, and K. AUSF The first authentication vector 5G HE AV is sent to the Authentication Server Function (AUSF).
[0092] Specifically, the UDM returns the requested 5G HE AV to AUSF in the Nudm_UEAuthentication_Get Response message and indicates that the 5G HE AV is used for 5G AKA. If the Nudm_UEAuthentication_Get Request contains SUCI, the UDM will include SUPI in the Nudm_UEAuthentication_Get Response.
[0093] AUSF should temporarily store XRES* and the received SUCI or SUPI. AUSF can store K. AUSF .
[0094] AUSF should generate a 5G AV based on the 5G HE AV received from UDM / ARPF. Calculate HXRES* (the hash value of the expected response) from RAND and XRES*, and from K... AUSF Derivation of anchor key K SEAF Then use HXRES* and K SEAF Replace XRES* and K in 5GHE AV respectively AUSF .
[0095] Then AUSF should remove K. SEAF The authentication vector 5G SE AV (RAND, AUTN, HXRES*) is sent to the Secure Anchor Function (SEAF) via the Nausf_UEAuthentication_Authenticate response.
[0096] SEAF should send RAND and AUTN to the UE via a Non-Access Stratum (NAS) message (Auth-Req). It is understood that this NAS message includes the first authentication information (RAND and AUTN). This message should also contain information used by the UE and the Authentication Management Field (AMF) to identify K. AMF In addition to the ngKSI with some native security context, the message should also include the anti-bidding down between architectures (ABBA) parameter.
[0097] ME should forward the RAND and AUTN from the NAS message (Auth-Req) to USIM.
[0098] Upon receiving RAND and AUTN, USIM should check whether AUTN has been accepted to verify that the authentication vector is up-to-date. If the verification is successful (it is up-to-date), USIM should calculate the response (RES) and return RES, the cipher key (CK), and the integrity key (IK) to ME.
[0099] Among them, SEAF (Security Anchor Function) authenticates the UE when accessing the network. AUSF (Authentication Server Function) authenticates the UE through the home network.
[0100] The above steps enable the negotiation and instruction of security capabilities between terminals and network devices.
[0101] Following this step, the terminal obtains the second SES from the first authentication information.
[0102] Step 103: Based on the second SES, perform security enhancement on the first key information to obtain the second key information. The first key information is obtained based on the core key K and the random number RAND in the first authentication information. The second key information is used for key derivation.
[0103] The first key information includes a first CK and a first IK, wherein the first CK is the CK returned by the USIM to the ME, and the first IK is the IK returned by the USIM to the ME.
[0104] In this step, if the terminal receives a second SES with a value of 1, then the first CK and the first IK are respectively subjected to security enhancement (or security enhancement processing or security enhancement) to obtain the second key information, which includes the second CK (CK*) and the second IK (IK*). The key lengths supported by CK* and IK* are at least 256 bits to prevent cracking by quantum computing. This second key information is used for key derivation at subsequent levels.
[0105] It should be noted that in the identity submission process between the terminal and the network device, when the network device (or the network side) requires the UE to send a SUCI for network authentication, specifically, the UE sends an initial registration request (i.e., a registration request) to the network side. The ME reads the Subscription Permanent Identifier (SUPI) from the USIM, encrypts the SUPI using a key-encapsulation mechanism encryption (KEM_ENC) to obtain the SUCI, and sends the initial registration request carrying the SUCI to the UDM in the home network through the relevant network element.
[0106] In KEM_ENC: The input is a public key PK and a message M. A temporary symmetric key sk is generated using a key-encapsulation mechanism (KEM). Then, M is protected, and the ciphertext C is output. The KEM technology can employ traditional public-key cryptography algorithms such as Elliptic Curve Cryptography (ECC), asymmetric encryption algorithms (Ron Rivest, Adi Shamir, Leonard Adleman, RSA), or post-quantum cryptography (PQC). Elliptic Curve Integrated Encryption Scheme (ECIES) encryption is one implementation of KEM_ENC.
[0107] KEM (Key Encapsulation Mechanism) mainly includes the following algorithms:
[0108] KeyGen(pp)->(SK, PK): Generates a public-private key pair. The input pp is the public parameter used to generate the key pair, and the output is the generated public-private key pair.
[0109] Encap(PK)->(sk, csk): Generates a temporary symmetric key based on the public key. The input is the public key, and the output is the temporary symmetric key sk and the encrypted sk, i.e., csk.
[0110] Decap(SK, csk)->(sk): Decrypts a temporary symmetric key based on the private key. The input is the private key and csk, and the output is the temporary symmetric key sk.
[0111] Since the USIM card only stores the user's identifier, it will not be actively replaced with a new card that supports 256 bits for a long time. Therefore, there will inevitably be a large number of old USIM cards in the network that have not been upgraded to support AES-256, that is, USIM cards with a core key K of 128 bits.
[0112] In the identity submission process between the terminal and network device, ME uses ECIES to encrypt SUPI to obtain SUCI, where:
[0113] If the SUCI encryption uses an empty scheme, the original protocol will be executed without any additional processing.
[0114] If SUCI encryption uses a non-empty scheme, the following process will be followed:
[0115] When the Universal User Identity Module (USIM) on the terminal only supports the first cryptographic algorithm, the first SES is generated. The first cryptographic algorithm is the MILENAGE-128 algorithm. Also, when the USIM on the terminal only supports the first cryptographic algorithm, a first symmetric key is acquired and stored. This first symmetric key is generated during the process of encrypting the SUPI of the USIM using a first encryption mechanism to obtain the SUCI. This first symmetric key is used for key enhancement expansion in subsequent authentication processes. The first encryption mechanism is KEM_ENC.
[0116] If USIM supports the MILENAGE-256 algorithm, no additional processing is required.
[0117] Specifically, ME checks whether the USIM is an older card that only supports MILENAGE-128:
[0118] If it's an older card that only supports MILENAGE-128:
[0119] Then ME secretly stores the temporary symmetric key sk generated during the encryption process of KEM_ENC (the first encryption mechanism) as K_KEM (i.e., the first symmetric key);
[0120] Additionally, set the Security Enhancement Support bit (SES) (i.e., the first SES), such as setting it to 1.
[0121] If it's an older card that only supports MILENAGE-256:
[0122] No further processing is required.
[0123] It should be noted that the first symmetric key K_KEM can also be derived from sk: for example, K_KEM = KDF(sk, "KEM"). It is recommended that the length of the first symmetric key K_KEM be at least 128 bits, and preferably 256 bits.
[0124] Because SUPI protection uses the ECIES scheme, and ECIES currently employs the elliptic curve cryptography algorithm ECC, which can be replaced by a post-quantum cryptography algorithm (PQC), the KEM_ENC described above can simultaneously support algorithms such as ECIES_KEM or PQC_KEM. To counter quantum attacks, the PQC-based KEM algorithm (i.e., PQC_KEM) is preferred.
[0125] It should be noted that PQC_KEM (Post Quantum Cryptography): is a KEM scheme based on post-quantum public-key cryptography, meaning that the public-key cryptography algorithm in KEM adopts post-quantum public-key cryptography.
[0126] ECIES:
[0127] 5G AKA uses ECIES to encrypt SUPI to generate SUCI, which mainly includes two algorithms:
[0128] ECIES_ENC (encryption): Input public key PK and plaintext M, output C;
[0129] Encap_ECIES(PK): Generate a temporary public-private key pair (eSK, ePK) using KeyGen(pp), generate a temporary symmetric key sk based on PK and eSK, and output (sk, ePK);
[0130] SEnc_ECIES(sk, M): Encrypts and protects the integrity of M using the temporary key sk to obtain C1 and C2, and outputs C = (ePK, C1, C2).
[0131] Optionally, the first SES can be placed in the SUCI, that is, the registration request carries the SUCI, and the SUCI includes the first SES; the first SES can also be carried in a new field in the interface of ME->Secure Anchor Function (SEAF)->Authentication Server Function (AUSF)->UDM, that is, the registration request carries the first SES through the first interface field, and the registration request is sent from ME to SEAF, from SEAF to AUSF, and then from AUSF to UDM.
[0132] SEAF: Access Network authenticates the UE. AUSF: Home Network authenticates the UE.
[0133] Placing the first SES field in the SUCI is the preferred option. If the first SES field is placed in the SUCI, then a new SES field should be added to the SUCI, and the format of the SUCI should be modified as follows: Figure 2 As shown.
[0134] ME faces challenges in the main authentication process between the terminal and network devices:
[0135] In one optional embodiment, the Authentication Management Field (AMF) of the first authentication information carries the second SES. Specifically, the AMF of the AUTN in the first authentication information carries the second SES.
[0136] Specifically, when a network device receives a registration request, it parses the registration request to obtain the first SES. If there is a first SES with a value of 1, the second SES is stored in the reserved bit of the AV's AMF.
[0137] It should be noted that bits 1-7 and bits 8-15 of the AMF are reserved bits, which are 0 by default. You can choose a fixed position to save the second SES.
[0138] If there is no first SES with a value of 1, the network device will not perform any additional processing.
[0139] According to the second SES, before obtaining the first information, the method further includes: [further details to be added].
[0140] ME obtains the second SES from the AMF in the first authentication information. That is, ME obtains the SES (i.e., the second SES) from the AMF field of AV, and the second SES is 1.
[0141] It should be noted that in the original 3GPP protocol, CK and IK are concatenated (i.e., CK||IK) as a 256-bit input to derive keys at various levels, such as K_ausf, K_seaf, K_amf, K_gNB, etc. However, since the core key K is not 256-bit fully entropy, neither CK nor IK is 256-bit fully entropy. Therefore, the series of keys derived from the CK||IK combination are also not 256-bit fully entropy. Consequently, because K is not 256-bit fully entropy, meaning its randomness is insufficient (not 256 bits), it cannot provide 256-bit security capabilities. This leads to a security risk in quantum attack scenarios for the series of keys derived between the ME and the network side.
[0142] Furthermore, based on the second SES, the first key information is enhanced with security to obtain the second key information, including:
[0143] According to the second SES, the first encryption key CK is enhanced with security to obtain the second CK, and according to the second SES, the first integrity protection key CK is enhanced with security to obtain the second IK. That is, when there is a second SES with a value of 1, ME enhances the security of CK and IK respectively.
[0144] The security enhancement includes at least one of the following:
[0145] (1) Security enhancement is performed based on the first symmetric key K_KEM, as follows:
[0146] CK*=HASH(CK||K_KEM), IK*=HASH(IK||K_KEM)
[0147] Wherein, CK is the first CK, CK* is the second CK, IK is the first IK, IK* is the second IK, and K is the core key;
[0148] (2) Security enhancement using Key Derivation Functions (KDF):
[0149] CK*=KDF(K_KEM,CK), IK*=KDF(K_KEM,IK)
[0150] Wherein, CK is the first CK, CK* is the second CK, IK is the first IK, IK* is the second IK, and K_KEM is the first symmetric key.
[0151] It should be noted that the outputs of KDF and HASH are at least 256 bits, meaning that the second CK (CK*) supports a key length of at least 256 bits, and the second IK (IK*) supports a key length of at least 256 bits. CK and K_KEM can be combined using concatenation, XOR, or other methods, and other shared parameter information can also be added. In this embodiment, the lengths of the first CK and the first IK are 128 bits, the length of the first symmetric key K_KEM is at least 128 bits, and the KDF mixed calculation yields 256 bits of CK* and IK*.
[0152] Subsequently, ME derives the keys and parameters for other layers based on the 256-bit secure CK* and IK*. Specifically, it obtains the second response (represented as the second RES or RES*) based on the second CK, the second IK, the first response (denoted as the first RES or RES), and the random number RAND, and obtains the first secure key K based on the second CK and the second IK. AUSF The first security key K AUSF Used for key derivation at subsequent levels. This second response (second RES or RES*) is used for communication authentication.
[0153] The first RES is obtained based on the first authentication information. The first RSE is the RES calculated by the USIM after receiving RAND and AUTN, whereby the USIM checks whether AUTN has been accepted to verify whether the authentication vector is up-to-date. If the verification is successful (it is up-to-date), the first authentication information includes the RAND, and the first information includes the second RES and the first security key K. AUSF .
[0154] Furthermore, using RAND, the first RES, CK*, and IK*, K is derived through a one-way KDF function. AUSFAnd RES*, and the keys for subsequent layers, namely the second RES obtained based on the second CK, the second IK, the first actual verification data RES, and the random number RAND, including:
[0155] The second response is obtained based on the second CK, the second IK, the first response, and the random number RAND, using the following formula:
[0156] RES*=KDF(CK*xor IK*, RAND, RES)
[0157] Where RES* represents the second response, RES represents the first response, CK* represents the second CK, and IK* represents the second IK;
[0158] The second response can also be derived using KDF based on the first response, the RAND, the first CK (CK), and the first IK (IK), as shown in the following formula:
[0159] RES*=KDF(CK||IK,RAND,RES)
[0160] Where RES* represents the second response, RES represents the first response, CK represents the first CK, and IK represents the first IK;
[0161] The first security key K is obtained based on the second CK and the second IK. AUSF ,include:
[0162] Based on the second IK(IK*) and the second CK(CK*), the first security key K is derived using KDF. AUSF The specific formula is as follows:
[0163] K AUSF =KDF(CK*xor IK*,SN_name,SQN xor AK).
[0164] Wherein, SN_name is the serial number of the terminal device, SQN is the serial number used to uniquely identify the terminal device, AK is the authentication key (Access Key), CK* is the second CK, and IK* is the second IK.
[0165] The first security key K can also be derived using KDF based on the first CK(CK) and the first IK(IK). AUSF The specific formula is as follows:
[0166] K AUSF =KDF(CK||IK,SN_name,SQN xor AK)
[0167] Wherein, SN_name is the serial number of the terminal device, SQN is the serial number used to uniquely identify the terminal device, AK is the authentication key (Access Key), CK is the first CK, and IK is the first IK.
[0168] The second CK supports a key length of at least 256 bits, and the second IK supports a key length of at least 256 bits.
[0169] That is, ME uses the shared key (first symmetric key) generated or derived in SUCI encryption to perform security enhancement processing on the first CK and the first IK, extending the security of each layer of keys to at least 256 bits.
[0170] like Figure 3 As shown in the figure, this embodiment of the invention provides a security capability negotiation method applied to a network device, the method comprising:
[0171] Step 301: Receive a registration request sent by the terminal, the registration request carrying SUCI and a first SES, the first SES being used to indicate the security capability SUCI supported by the terminal.
[0172] In this embodiment, the terminal is a terminal that supports enhanced security capabilities. Enhanced security capabilities refer to the replacement of the ME (Mechanical Encryption) on the terminal side with one supporting the AES-128 algorithm (supporting the Advanced Encryption Standard (AES) algorithm with a key length of 128 bits) to one supporting the AES-256 algorithm (supporting the AES algorithm with a key length of 256 bits) to counter quantum attacks. In other words, the security capabilities supported by the terminal can be understood as whether the terminal supports enhanced security capabilities, specifically whether it supports the AES algorithm (or encryption mechanism) with a key length of 256 bits.
[0173] In this step, the ME that supports enhanced security capabilities writes the first SES into the registration request. The first SES is used to indicate whether the ME supports enhanced security capabilities. This registration request is an Initial Registration Request. Through the registration request, the first SES is synchronized to the network device. The network device knows whether the ME supports enhanced security capabilities based on the first SES.
[0174] In this embodiment, the network device is a Home Network (HN) or a UDM network element within the HN.
[0175] Step 302: Generate first authentication information and third key information based on the core key K and AMF. The first authentication information carries a second SES, which is used to indicate the security capability SUCI supported by the first authentication information.
[0176] The first authentication information includes AUTN and RAND.
[0177] In this step, after receiving the registration request, if the registration request contains a first SES set to 1, the UDM generates a second SES and stores this second SES in the first authentication information, setting it to 1. That is, the UDM receives the first authentication information sent by the network device, which carries the second SES. This second SES is used to indicate whether the first authentication information supports enhanced security capabilities.
[0178] It should also be noted that if there is no first SES with a value of 1 in the registration request, the network device will not perform any additional processing.
[0179] The third key information includes CK (also known as the third CK) and IK (also known as the third IK). The third CK and the third IK are calculated by UDM based on the core key K of SUPI and AMF. SUPI is obtained by decrypting SUCI.
[0180] Specifically, based on the core key K and AMF of SUPI, the second authentication vector AV is obtained, AV = (RAND, AUTN, XRES, CK (third CK), IK (third IK)), that is, the second authentication vector AV includes the third key information, AUTN, RAND and XRES, and the third key information includes the third CK and the third IK.
[0181] Step 303: Based on the core key K and the first SES, perform security enhancement on the third key information to obtain the fourth key information, which is used for key derivation.
[0182] The fourth key information includes the fourth CK (CK*) and the fourth IK (IK*). The fourth CK and the fourth IK support a key length of at least 256 bits to prevent them from being cracked by quantum computing. CK* and IK* are used for key derivation at subsequent levels.
[0183] Then, the second security key K is obtained based on CK* and IK*. AUSF And, based on CK*, IK*, XRES and RAND, obtain XRES*, and then K AUSFThe third authentication vector 5GHE AV is generated from the AUTN and RAND (i.e., the first authentication information) in the second authentication vector, XRES*, XRES*, and K. This third authentication vector 5GHE AV includes RAND, AUTN, XRES*, and K. AUSF .
[0184] Step 304: Send the first authentication information to the terminal.
[0185] Specifically, the UDM returns the requested 5G HE AV (third authentication vector) to the AUSF in the Nudm_UEAuthentication_Get Response message and indicates that the 5G HE AV is used for 5G AKA. If the Nudm_UEAuthentication_GetRequest contains SUCI, the UDM will include SUPI in the Nudm_UEAuthentication_Get Response.
[0186] AUSF should temporarily store XRES* from the third authentication vector and the received SUCI or SUPI. AUSF may store K from the third authentication vector. AUSF .
[0187] AUSF should generate a 5G AV based on the 5G HE AV received from UDM / ARPF. Calculate HXRES* (the hash value of the expected response) from RAND and XRES*, and from K... AUSF Derivation of anchor key K SEAF Then use HXRES* and K SEAF Replace XRES* and K in 5GHE AV respectively AUSF .
[0188] Then AUSF should remove K. SEAF The authentication vector 5G SE AV (RAND, AUTN, HXRES*) is sent to the Secure Anchor Function (SEAF) via the Nausf_UEAuthentication_Authenticate response.
[0189] SEAF should send RAND and AUTN (i.e., first authentication information) to the UE via a Non-Access Stratum (NAS) message (Auth-Req). This message should also contain information used by the UE and the Authentication Management Field (AMF) to identify K. AMFIn addition to the ngKSI with some native security context, the message should also include the anti-bidding down between architectures (ABBA) parameter.
[0190] ME should forward the RAND and AUTN from the NAS message (Auth-Req) to USIM.
[0191] Upon receiving RAND and AUTN, USIM should check whether AUTN has been accepted to verify that the authentication vector is up-to-date. If the verification is successful (it is up-to-date), USIM should calculate the actual response (user response, RES) and return RES, the encryption key (Cipher Key, CK), and the integrity protection key (Integrity Key, IK) to ME.
[0192] Among them, SEAF (Security Anchor Function) authenticates the UE when accessing the network. AUSF (Authentication Server Function) authenticates the UE through the home network.
[0193] The above steps enable the negotiation and instruction of security capabilities between terminals and network devices.
[0194] Optionally, the method further includes:
[0195] The first SES is obtained by parsing the SUCI in the registration request. That is, the first SES can be placed in the SUCI. The registration request carries the SUCI, and the SUCI includes the first SES. UDM parses the first SES from the SUCI and determines whether there is a first SES with a value of 1.
[0196] or,
[0197] The first SES is obtained by parsing the first interface field of the registration request. That is, the first SES can also be carried in the interface of ME->Secure Anchor Function (SEAF)->Authentication Server Function (AUSF)->UDM. In other words, the registration request carries the first SES through the first interface field. The registration request is sent from ME to SEAF, from SEAF to AUSF, and from AUSF to UDM. UDM parses the first SES from the interface and determines whether there is a first SES with a value of 1.
[0198] The first authentication information includes AUTN, and the AMF of the AUTN carries the second SES.
[0199] Specifically, when a network device receives a registration request, it parses the registration request to obtain the first SES. If there is a first SES with a value of 1, the second SES is stored in the reserved bit of the AV's AMF.
[0200] It should be noted that bits 1-7 and bits 8-15 of the AMF are reserved bits, which are 0 by default. You can choose a fixed position to save the second SES.
[0201] If there is no first SES with a value of 1, the network device will not perform any additional processing.
[0202] In the identity submission process between the terminal and the network device, the UDM receives a registration request, which includes a SUCI. The UDM uses a first decryption mechanism to decrypt the SUCI to obtain the SUPI. This first decryption mechanism is a key-encapsulated decryption mechanism (KEM_DEC), such as the ECIES algorithm.
[0203] KEM_DEC (Key Encapsulation-Based Decryption Mechanism): Inputting a private key SK and ciphertext C, it uses KEM technology to decrypt and obtain a temporary symmetric key sk. Then, it decrypts the ciphertext C to output the plaintext M. The KEM technology can employ traditional public-key cryptography algorithms such as ECC and RSA, as well as PQC. ECIES decryption is an implementation of KEM_DEC.
[0204] Specifically, UDM decrypts SUPI from SUCI using the KEM_DEC algorithm. UDM parses the first SES from SUCI or the interface, determines whether there is a first SES with a value of 1, and if so, generates and saves the second SES. It also obtains and saves the symmetric key K_KEM generated during the process of decrypting SUCI to obtain SUPI using the first decryption mechanism, which is the second symmetric key.
[0205] It should be noted that the second symmetric key K_KEM can also be derived from sk: for example, K_KEM = KDF(sk, "KEM").
[0206] The second symmetric key is used for key enhancement and expansion in subsequent authentication processes.
[0207] The following is combined Figure 4 The following describes the identity submission process between the terminal and network device provided in this embodiment of the invention:
[0208] ME uses KEM_ENC to encrypt SUPI to obtain SUCI. If the core key K is 128 bits, then K_KEM (the first symmetric key) generated by KEM_ENC is secretly stored, and the first SES bit is set to 1 in SUCI.
[0209] When the network side requires the UE to send SUCI for network authentication, the UE sends an Initial Registration Request to the network side.
[0210] If the UDM receives the Nudm_Authenticate_Get Request and receives the SUCI, it should use KEM_DEC to decrypt the SUCI to obtain the SUPI. If the SUCI contains the first SES which is 1, then the K_KEM (second symmetric key) and the SES (i.e. the second SES) should be secretly saved.
[0211] In the main authentication process:
[0212] In an optional embodiment, first authentication information and second key information are generated based on the SUPI core key and AMF, including:
[0213] Based on the length of the core key K, a corresponding second cryptographic algorithm is determined. That is, UDM selects the appropriate second cryptographic algorithm based on the length of the current SUPI user's core key K. This second cryptographic algorithm is the MILENAGE-256 algorithm.
[0214] If K is 128 bits, then the MILENAGE-128 algorithm is selected;
[0215] If K is 256 bits (or >128 bits), then the MILENAGE-256 algorithm is selected.
[0216] Using the second cryptographic algorithm, based on the core key and the AMF, the first authentication information and the second key information are obtained. That is, using the MILENAGE-256 algorithm or the MILENAGE-128 algorithm, the second authentication vector AV = (RAND, AUTN, XRES, (third CK), IK (third IK)) is calculated based on the core key K and the AMF, etc., where RAND and AUTN are the first authentication information, and CK and IK are the second key information.
[0217] In an optional embodiment, based on the core key K and the first SES, the third key information is enhanced with security to obtain fourth key information, which is used for key derivation and includes:
[0218] Specifically, if the first SES is 1 and the core key K is 128 bits, then the third key information is enhanced with security to obtain the fourth key information.
[0219] According to the AUTN, the RAND, and K AUSFAnd XRES*, to obtain the third authentication vector, the final authentication credential storage and processing function (ARPF) in the UDM or network device should create a vector containing RAND, AUTN, XRES*, and K. AUSF The 5G HE AV (third authentication vector) is sent to the AUSF so that the AUSF can send the AUTN and RAND from the third authentication vector to the terminal.
[0220] Specifically, the UDM returns the requested 5G HE AV (third authentication vector) to the AUSF in the Nudm_UEAuthentication_Get Response message and indicates that the 5G HE AV is used for 5G AKA. If the Nudm_UEAuthentication_GetRequest contains SUCI, the UDM will include SUPI in the Nudm_UEAuthentication_Get Response.
[0221] AUSF should temporarily store XRES* and the received SUCI or SUPI. AUSF can store K. AUSF .
[0222] AUSF should generate a 5G AV (authentication vector) based on the 5G HE AV received from UDM / ARPF. Calculate HXRES* (the hash of the expected response) from RAND and XRES*, and from K... AUSF Derivation of anchor key K SEAF Then use HXRES* and K SEAF Replace XRES* and K in 5G HE AV respectively AUSF .
[0223] Then AUSF should remove K. SEAF The authentication vector 5G SE AV (RAND, AUTN, HXRES*) is sent to the Secure Anchor Function (SEAF) via the Nausf_UEAuthentication_Authenticate response.
[0224] SEAF should send RAND and AUTN to the UE via a Non-Access Stratum (NAS) message (Auth-Req). This message should also contain information used by the UE and the Authentication Management Field (AMF) to identify K. AMFIn addition to the ngKSI with some native security context, the message should also include anti-bidding down between architectures (ABBA) parameters.
[0225] ME should forward the RAND and AUTN from the NAS message (Auth-Req) to USIM.
[0226] Upon receiving RAND and AUTN, USIM should check whether AUTN has been accepted to verify that the authentication vector is up-to-date. If the verification is successful (it is up-to-date), USIM should calculate the actual response (user response, RES) and return RES, the encryption key (Cipher Key, CK), and the integrity protection key (Integrity Key, IK) to ME.
[0227] ARPF stores user subscription information, authentication data K, etc.
[0228] Furthermore, the third key information includes a third CK and a third IK; the fourth key information includes a fourth CK and a fourth IK;
[0229] Based on the core key and the first SES, the third key information is enhanced with security to obtain the fourth key information, including:
[0230] Based on the length of the first SES and the core key K, the third CK is enhanced with security to obtain the fourth CK; and based on the length of the first SES and the core key K, the third IK is enhanced with security to obtain the fourth IK.
[0231] The security enhancement (also known as security enhancement processing) includes at least one of the following:
[0232] (1) Security enhancements are performed based on the second symmetric key, as follows:
[0233] CK*=HASH(CK||K_KEM), IK*=HASH(IK||K_KEM)
[0234] Wherein, CK is the third CK, CK* is the fourth CK, IK is the third IK, IK* is the fourth IK, and K is the core key;
[0235] (2) Security enhancement using KDF:
[0236] CK*=KDF(K_KEM,CK), IK*=KDF(K_KEM,IK)
[0237] Wherein, CK is the third CK, CK* is the fourth CK, IK is the third IK, IK* is the fourth IK, and K_KEM is the second symmetric key.
[0238] It should be noted that the outputs of KDF and HASH are at least 256 bits, meaning that the key length supported by the fourth CK is at least 256 bits, and the key length supported by the fourth IK is at least 256 bits. CK and K_KEM can be combined using concatenation, XOR, or other methods, and other shared parameter information can also be added. In this embodiment, the lengths of the third CK and the third IK are 128 bits, the length of the first symmetric key K_KEM is at least 128 bits, and the KDF mixed calculation yields 256 bits of CK* and IK*.
[0239] It should also be noted that if the core key K is 256 bits (or >128 bits) or there is no first SES with a value of 1, no additional processing is performed.
[0240] Subsequently, UDM uses RAND, XRES, CK*, and IK* to derive K through a one-way KDF function. AUSF And XRES*, specifically:
[0241] The second expected response (i.e., XRES*) is obtained based on the fourth CK, the fourth IK, the first expected response (XRES), and the RAND, and the second security key K is obtained based on the fourth CK and the fourth IK. AUSF The first expected response (which may be denoted as a first XRES or XRES) is generated based on the core key and the AMF; the second expected response (which may be denoted as a second XRES or XRES*) is used for communication authentication, and the second security key K AUSF Used for key derivation.
[0242] The first expected response is XRES in the second authentication vector AV = (RAND, AUTN, XRES, CK (third CK), IK (third IK)).
[0243] Furthermore, based on the first expected response, the RAND, the fourth CK, and the fourth IK, the second expected response is derived using KDF, with the specific formula as follows:
[0244] XRES*=KDF(CK*xor IK*,RAND,XRES).
[0245] Where XRES* is the second expected response, XRES is the first expected response, CK* is the fourth CK, and IK* is the fourth IK.
[0246] The second XRES can also be derived using KDF based on the first XRES, the RAND, the third CK (CK), and the third IK (IK), as shown in the following formula:
[0247] XRES*=KDF(CK||IK,RAND,XRES)
[0248] Where XRES* is the second expected response, XRES is the first expected response, CK is the third CK, and IK is the third IK;
[0249] The second security key K is obtained based on the fourth CK and the fourth IK. AUSF ,include:
[0250] Based on the fourth IK(IK*) and the fourth CK(CK*), the second security key K is derived using KDF. AUSF The specific formula is as follows:
[0251] K AUSF =KDF(CK*xor IK*,SN_name,SQN xor AK).
[0252] Wherein, SN_name is the serial number of the terminal device, SQN is the serial number used to uniquely identify the terminal device, AK is the authentication key (Access Key), CK* is the fourth CK, and IK* is the fourth IK.
[0253] The second security key K can also be derived using KDF based on the third CK(CK) and the third IK(IK). AUSF The specific formula is as follows:
[0254] K AUSF =KDF(CK||IK,SN_name,SQN xor AK)
[0255] Wherein, SN_name is the serial number of the terminal device, SQN is the serial number used to uniquely identify the terminal device, AK is the authentication key (Access Key), CK is the third CK, and IK is the third IK.
[0256] The fourth CK supports a key length of at least 256 bits, and the fourth IK supports a key length of at least 256 bits.
[0257] That is, ME uses the shared key (second symmetric key) generated or derived in SUCI decryption to perform security enhancement processing on the third CK and third IK, extending the security of each layer of keys to at least 256 bits.
[0258] The following is combined Figure 5The main authentication process is explained in detail below:
[0259] If the UDM parsing reveals a SES bit of 1 (the first SES), then the AMF in the AUTN is set (i.e., the AMF in the first authentication information is set, which can also be understood as the AMF in the AUTN of the first authentication information carrying the second SES); the MILENAGE (128 / 256) algorithm is selected based on the length of the core key K; the second authentication vector AV = (RAND, AUTN, XRES, CK, IK) is calculated; if the first SES is 1, then CK and IK are enhanced with security based on the second symmetric key K_KEM, CK* = HASH(CK||K_KEM), IK* = HASH(IK||K_KEM); K is then calculated and derived. AUSF , XRES* etc.
[0260] Send 5G HE AV containing RAND, AUTN, XRES*, and KAUSF to SEAF;
[0261] In the Nudm_UEAuthentication_Get Response message, the UDM returns the requested 5G HEAV to the AUSF and indicates that the 5G HEAV is used for 5G AKA. If the Nudm_UEAuthentication_Get request includes SUCI, the UDM will include SUPI in the Nudm_UEAuthentication_Get response;
[0262] AUSF should temporarily store XRES* and the received SUCI or SUPI. AUSF can store K. AUSF .
[0263] AUSF should generate a 5G AV based on the 5G HE AV received from UDM / ARPF. Calculate HXRES* from RAND and XRES*, and from K... AUSF Derivation of K SEAF Then use HXRES* and K SEAF Replace XRES* and K in 5G HE AV respectively AUSF .
[0264] Then AUSF should remove K. SEAF The 5G SEAV(RAND, AUTN, HXRES*) is sent to SEAF via the Nausf_UEAuthentication_Authenticate response.
[0265] SEAF should send RAND and AUTN to UE via a NAS message (Authentication Request, Auth-Req). This message should also contain the identifier used by the UE and AMF to identify K. AMF In addition to ngKSI with some native security context, the message should also include the ABBA parameter.
[0266] ME should forward the RAND and AUTN from the NAS message (Auth-Req) to USIM.
[0267] Upon receiving RAND and AUTN, USIM should check whether AUTN is accepted to verify that the authentication vector is up-to-date. If the verification passes, USIM should calculate the response RES and return RES (first RES), CK (first CK), and IK (first IK) to ME.
[0268] ME should be based on RES to calculate RES* (second RES). ME should derive K from CK||IK. AUSF (First symmetric key).
[0269] Specifically, ME obtains the SES bit (second SES) from the AMF field of AUTN. If SES (second SES) is 1, then based on K_KEM (first symmetric key), security enhancement extensions are performed on CK and IK: CK*(second CK) = HASH(CK||K_KEM), IK*(first IK) = HASH(IK||K_KEM), and the first security key K is calculated and derived. AUSF , second RES (RES*), etc.
[0270] The UE should return RES* to SEAF in the NAS message authentication response.
[0271] SEAF should calculate HRES* based on RAND and RES*, and compare HRES* with HXRES*. If the two values match, SEAF should consider authentication successful from the perspective of the service network. If they do not match, SEAF should consider authentication failed and indicate the failure to AUSF.
[0272] SEAF should send the corresponding SUCI or SUPI from the UE to AUSF via the Nausf_UEAuthentication_AuthenticateRequest message.
[0273] When AUSF receives a Nausf_UEAuthentication_Authenticate Request message containing RES*, it can verify whether the AV has expired. If the AV has expired, AUSF can consider authentication unsuccessful from the home network's perspective. AUSF should compare the received RES* with the stored XRES*. If RES* and XRES* match, AUSF should consider authentication successful from the home network's perspective.
[0274] AUSF should indicate to SEAF whether authentication was successful via the Nausf_UEAuthentication_Authenticate Response. If authentication is successful, the K should be sent via the Nausf_UEAuthentication_Authenticate Response. SEAF Send to SEAF. If AUSF receives SUCI from SEAF during authentication and authentication is successful, AUSF should also include SUPI in the Nausf_UEAuthentication_Authenticate Response.
[0275] If authentication is successful, SEAF should send the key K received from the Nausf_UEAuthentication_Authenticate Response message. SEAF As the anchor key. Then SEAF should be from K. SEAF K is derived from ABBA parameters and SUPI. AMF and provide ngKSI and K to AMF AMF .
[0276] If SUCI is used for this authentication, SEAF should only provide ngKSI and K to AMF after receiving a Nausf_UEAuthentication_Authenticate Response message containing SUCI. AMF The UE will not be provided with communication services until the SUPI is known to the Serving Network.
[0277] like Figure 6 As shown, this embodiment of the invention also provides a communication authentication device, the device comprising:
[0278] The first sending module 601 is used to send a registration request to the network device. The registration request carries a first security enhancement support bit (SES). The first SES is used to indicate the security capabilities supported by the terminal.
[0279] The first receiving module 602 is used to receive the first authentication information sent by the network device. The first authentication information carries a second SES, and the second SES is used to indicate the security capabilities supported by the first authentication information.
[0280] The first processing module 603 is used to perform security enhancement on the first key information according to the second SES to obtain the second key information. The first key information is obtained based on the core key K and the random number RAND in the first authentication information. The second key information is used for key derivation.
[0281] Optionally, the device further includes:
[0282] The first target processing module is used to generate the first SES when the Universal User Identity Module (USIM) on the terminal only supports the first cryptographic algorithm.
[0283] Optionally, the registration request carries a user-hidden identifier (SUCI), the SUCI including the first SES;
[0284] or,
[0285] The registration request carries the first SES through the first interface field.
[0286] Optionally, the authentication management field (AMF) of the first authentication information carries the second SES.
[0287] Optionally, the first key information includes a first encryption key CK and a first integrity protection key IK;
[0288] The second key information includes the second CK and the second IK;
[0289] The first processing module 603 includes:
[0290] The first processing unit is configured to perform security enhancement on the first CK according to the second SES to obtain the second CK;
[0291] The second processing unit is used to perform security enhancement on the first IK according to the second SES to obtain the second IK.
[0292] Optionally, the security enhancement includes at least one of the following:
[0293] Security enhancement is performed based on a first symmetric key, wherein the first symmetric key is obtained when the USIM on the terminal only supports a first cryptographic algorithm. The first symmetric key is generated during the process of encrypting the user permanent identifier SUPI of the USIM to obtain SUCI using a first encryption mechanism. The first encryption mechanism is a key encapsulation-based encryption mechanism.
[0294] Security enhancements are achieved using Key Derivation Functions (KDF).
[0295] Optionally, the second CK supports a key length of at least 256 bits;
[0296] The second IK supports a key length of at least 256 bits.
[0297] It should be noted that the embodiments of the present invention provide Figure 6 The communication authentication device shown is an apparatus capable of executing the above-described communication authentication method applied to a terminal. Therefore, all embodiments of the above-described communication authentication method applied to a terminal are applicable to this apparatus and can achieve the same or similar technical effects.
[0298] like Figure 7 As shown in the illustration, this invention also provides a communication authentication device, the device comprising:
[0299] The second receiving module 701 is used to receive a registration request sent by the terminal. The registration request carries SUCI and a first SES, and the first SES is used to indicate the security capabilities supported by the terminal.
[0300] The second processing module 702 is used to generate first authentication information and third key information based on the core key K and AMF. The first authentication information carries a second SES, which is used to indicate the security capabilities supported by the first authentication information.
[0301] The third processing module 703 is used to perform security enhancement on the third key information based on the core key K and the first SES to obtain the fourth key information, which is used for key derivation.
[0302] The second sending module 704 is used to send the first authentication information to the terminal.
[0303] Optionally, the device further includes a second target processing module, the second target processing module being used for:
[0304] The first SES is obtained from the SUCI parsing;
[0305] or,
[0306] The first SES is obtained by parsing the first interface field of the registration request.
[0307] Optionally, the AMF of the first authentication information carries the second SES.
[0308] Optionally, the second processing module 702 includes:
[0309] The third processing unit is used to determine a second cryptographic algorithm corresponding to the length of the core key K.
[0310] The fourth processing unit is used to obtain the first authentication information and the third key information based on the core key K and the AMF using the second cryptographic algorithm.
[0311] Optionally, the third key information includes a third CK and a third IK;
[0312] The fourth key information includes the fourth CK and the fourth IK;
[0313] The third processing module 703 includes:
[0314] The fifth processing unit is used to enhance the security of the third CK based on the length of the first SES and the core key to obtain the fourth CK;
[0315] The sixth processing unit is used to perform security enhancement on the third IK based on the length of the first SES and the core key to obtain the fourth IK.
[0316] Optionally, the security enhancement includes at least one of the following:
[0317] Security enhancement is performed based on a second symmetric key, which is obtained by decrypting the SUCI in the registration request using a first decryption mechanism based on a first SES. The first decryption mechanism is a key-encapsulated decryption mechanism.
[0318] Security enhancements are achieved using KDF.
[0319] Optionally, the fourth CK supports a key length of at least 256 bits;
[0320] The fourth IK supports a key length of at least 256 bits.
[0321] It should be noted that the embodiments of the present invention provide Figure 7 The communication authentication device shown is an apparatus capable of executing the above-described communication authentication method applied to network devices. Therefore, all embodiments of the above-described communication authentication method applied to network devices are applicable to this apparatus and can achieve the same or similar technical effects.
[0322] like Figure 8As shown, this embodiment of the invention also provides a terminal, including: a processor 801; and a memory 803 connected to the processor 801 via a bus interface 802, the memory 803 being used to store programs and data used by the processor 801 when performing operations, and the processor 801 calling and executing the programs and data stored in the memory 803.
[0323] The transceiver 804 is connected to the bus interface 802 and is used to receive and send data under the control of the processor 801. Specifically, the processor 801 is used to read the program in the memory 803, and the transceiver 804 executes the following processes:
[0324] Send a registration request to the network device, the registration request carrying a first security enhancement support bit (SES), the first SES being used to indicate the security capabilities supported by the terminal;
[0325] The network device receives first authentication information, which carries a second SES, and the second SES is used to indicate the security capabilities supported by the first authentication information.
[0326] The processor 801 performs the following procedures:
[0327] According to the second SES, the first key information is enhanced with security to obtain the second key information. The first key information is obtained based on the core key K and the random number RAND in the first authentication information. The second key information is used for key derivation.
[0328] Optionally, the processor 801 is further configured to:
[0329] The first SES is generated when the Universal User Identity Module (USIM) on the terminal only supports the first cryptographic algorithm.
[0330] Optionally, the registration request carries a user-hidden identifier (SUCI), the SUCI including the first SES;
[0331] or,
[0332] The registration request carries the first SES through the first interface field.
[0333] Optionally, the authentication management field (AMF) of the first authentication information carries the second SES.
[0334] Optionally, the first key information includes a first encryption key CK and a first integrity protection key IK;
[0335] The second key information includes the second CK and the second IK;
[0336] The processor 801 is used for:
[0337] Based on the second SES, the first CK is enhanced with security measures to obtain the second CK;
[0338] The second IK is obtained by enhancing the security of the first IK based on the second SES.
[0339] Optionally, the security enhancement includes at least one of the following:
[0340] Security enhancement is performed based on a first symmetric key, wherein the first symmetric key is obtained when the USIM on the terminal only supports a first cryptographic algorithm. The first symmetric key is generated during the process of encrypting the user permanent identifier SUPI of the USIM to obtain SUCI using a first encryption mechanism. The first encryption mechanism is a key encapsulation-based encryption mechanism.
[0341] Security enhancements are achieved using Key Derivation Functions (KDF).
[0342] Optionally, the second CK supports a key length of at least 256 bits;
[0343] The second IK supports a key length of at least 256 bits.
[0344] Among them, Figure 8 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 801) and memory (memory 803). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides a user interface 805. A transceiver 804 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over a transmission medium. Processor 801 is responsible for managing the bus architecture and general processing, and memory 803 may store data used by processor 801 during operation.
[0345] like Figure 9 As shown, this embodiment of the invention also provides a network device, including: a processor 901; and a memory 903 connected to the processor 901 via a bus interface 902, the memory 903 being used to store programs and data used by the processor 901 when performing operations, and the processor 901 calling and executing the programs and data stored in the memory 903.
[0346] The transceiver 904 is connected to the bus interface 902 and is used to receive and send data under the control of the processor 901. Specifically, the processor 901 is used to read the program in the memory 903, and the transceiver 904 executes the following processes:
[0347] The terminal receives a registration request, which carries a SUCI and a first SES, the first SES being used to indicate the security capabilities supported by the terminal.
[0348] The processor 901 performs the following procedures:
[0349] Based on the core key K and AMF, first authentication information and third key information are generated. The first authentication information carries a second SES, which is used to indicate the security capabilities supported by the first authentication information.
[0350] Based on the core key K and the first SES, the third key information is enhanced to obtain the fourth key information, which is used for key derivation.
[0351] The transceiver 904 performs the following process:
[0352] The first authentication information is sent to the terminal.
[0353] Optionally, the processor 901 is configured to:
[0354] The first SES is obtained from the SUCI parsing;
[0355] or,
[0356] The first SES is obtained by parsing the first interface field of the registration request.
[0357] Optionally, the AMF of the first authentication information carries the second SES.
[0358] Optionally, the processor 901 is configured to:
[0359] Based on the length of the core key K, determine the corresponding second cryptographic algorithm;
[0360] Using the second cryptographic algorithm, the first authentication information and the third key information are obtained based on the core key K and the AMF.
[0361] Optionally, the third key information includes a third CK and a third IK;
[0362] The fourth key information includes the fourth CK and the fourth IK;
[0363] The processor 901 is specifically used for:
[0364] Based on the length of the first SES and the core key, the third CK is enhanced with security to obtain the fourth CK;
[0365] Based on the length of the first SES and the core key, the third IK is enhanced with security to obtain the fourth IK.
[0366] Optionally, the security enhancement includes at least one of the following:
[0367] Security enhancement is performed based on a second symmetric key, which is obtained by decrypting the SUCI in the registration request using a first decryption mechanism based on a first SES. The first decryption mechanism is a key-encapsulated decryption mechanism.
[0368] Security enhancements are achieved using KDF.
[0369] Optionally, the fourth CK supports a key length of at least 256 bits;
[0370] The fourth IK supports a key length of at least 256 bits.
[0371] Among them, Figure 9 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 901) and memory (memory 903). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 904 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. Processor 901 is responsible for managing the bus architecture and general processing, and memory 903 can store data used by processor 901 during operation.
[0372] An embodiment of the present invention provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the steps in the communication authentication method described above and achieve the same technical effect. To avoid repetition, further details are omitted here.
[0373] In this embodiment of the invention, the module can be implemented in software so that it can be executed by various types of processors. For example, an identified executable code module may include one or more physical or logical blocks of computer instructions, which may be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but may include different instructions stored in different bits, which, when logically combined, constitute the module and achieve the module's intended purpose.
[0374] In practice, an executable code module can be a single instruction or many instructions, and can even be distributed across multiple different code segments, different programs, and across multiple memory devices. Similarly, operational data can be identified within the module and can be implemented in any suitable form and organized within any suitable type of data structure. This operational data can be collected as a single dataset or distributed across different locations (including different storage devices), and can exist, at least in part, solely as electronic signals within the system or network.
[0375] When a module can be implemented using software, considering the current level of hardware technology, modules that can be implemented in software can be implemented using hardware circuits by those skilled in the art to achieve the corresponding functions, without considering cost. These hardware circuits include conventional very-large-scale integrated circuits (VLSI) or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules can also be implemented using programmable hardware devices, such as field-programmable gate arrays, programmable array logic, and programmable logic devices.
[0376] The exemplary embodiments described above are with reference to the accompanying drawings. Many different forms and embodiments are feasible without departing from the spirit and teachings of the invention. Therefore, the invention should not be construed as limiting the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided to make the invention complete and convey the scope of the invention to those skilled in the art. In these drawings, component dimensions and relative dimensions may be exaggerated for clarity. The terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. As used herein, unless clearly indicated otherwise, the singular forms “a,” “an,” and “the” are intended to include all such forms. It will be further understood that the terms “comprising” and / or “including”, when used in this specification, indicate the presence of the stated features, integers, steps, operations, components, and / or elements, but do not exclude the presence or addition of one or more other features, integers, steps, operations, components, and / or groups thereof. Unless otherwise indicated, when stated, a range of values includes the upper and lower limits of the range and any subranges in between.
[0377] A specific embodiment of the present invention also provides a computer program product, including computer instructions, which, when executed by a processor, implement the above-described functionality. Figure 1 or Figure 3 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0378] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A communication authentication method characterized by, Applied to a terminal, the method comprises: sending a registration request to a network device, the registration request carrying a first security enhancement support bit SES, the first SES being used to indicate a security capability supported by the terminal; receiving first authentication information sent by the network device, the first authentication information carrying a second SES, the second SES being used to indicate a security capability supported by the first authentication information; performing security enhancement on first key information according to the second SES to obtain second key information, the first key information being obtained according to a core key K and a random number RAND in the first authentication information, the second key information being used for key derivation; wherein the first key information comprises a first encryption key CK and a first integrity protection key IK; the second key information comprises a second CK and a second IK; performing security enhancement on the first key information according to the second SES to obtain the second key information, comprising: performing security enhancement on the first CK according to the second SES to obtain the second CK; performing security enhancement on the first IK according to the second SES to obtain the second IK; wherein the security enhancement comprises at least one of the following: performing security enhancement according to a first symmetric key, wherein the first symmetric key is obtained in a case where a universal subscriber identity module USIM on the terminal only supports a first cryptographic algorithm, the first symmetric key being generated in a process of encrypting a user permanent identity SUPI of the USIM to obtain a subscriber concealed identity SUCI by using a first encryption mechanism, the first encryption mechanism being a key encapsulation-based encryption mechanism; performing security enhancement by using a key derivation function KDF.
2. The method of claim 1, wherein, The method further comprises: generating the first SES in a case where the USIM on the terminal only supports the first cryptographic algorithm.
3. The method of claim 1, wherein, The registration request carries the SUCI, and the SUCI comprises the first SES. Or, the registration request carries the first SES through a first interface field.
4. The method of claim 1, wherein, The second SES is carried in an authentication management field AMF of the first authentication information.
5. The method of claim 1, wherein, The second CK supports a key length of at least 256 bits; the second IK supports a key length of at least 256 bits.
6. A communication authentication method characterized by, Applied to a network device, the method comprises: receiving a registration request sent by a terminal, the registration request carrying a SUCI and a first SES, the first SES being used to indicate a security capability supported by the terminal; generating first authentication information and third key information according to a core key K and an AMF, the first authentication information carrying a second SES, the second SES being used to indicate a security capability supported by the first authentication information; performing security enhancement on the third key information according to the core key K and the first SES to obtain fourth key information, the fourth key information being used for key derivation; sending the first authentication information to the terminal; wherein the third key information comprises a third CK and a third IK; the fourth key information comprises a fourth CK and a fourth IK; According to the core key K and the first SES, the third key information is securely enhanced to obtain fourth key information, including: According to the first SES and the length of the core key, the third CK is securely enhanced to obtain the fourth CK; According to the first SES and the length of the core key, the third IK is securely enhanced to obtain the fourth IK; The secure enhancement includes at least one of the following: According to the second symmetric key, the secure enhancement is performed, and the second symmetric key is obtained by decrypting the SUCI in the registration request by using a first decryption mechanism according to the first SES, and the first decryption mechanism is a decryption mechanism based on key encapsulation; The secure enhancement is performed by using KDF.
7. The method of claim 6, wherein, The method further includes: The first SES is parsed from the SUCI; Or, The first SES is parsed from the first interface field of the registration request.
8. The method of claim 6, wherein, The second SES is carried in the AMF of the first authentication information.
9. The method of claim 6, wherein, According to the core key K and the AMF, the first authentication information and the third key information are generated, including: According to the length of the core key K, a second cryptographic algorithm corresponding in length is determined; According to the core key K and the AMF, the first authentication information and the third key information are obtained by using the second cryptographic algorithm.
10. The method of claim 6, wherein, The fourth CK supports a key length of at least 256 bits; The fourth IK supports a key length of at least 256 bits.
11. A communication authentication apparatus characterized by comprising: The apparatus includes: The first sending module is configured to send a registration request to a network device, and the registration request carries a first security enhancement support bit SES, and the first SES is used to indicate the security capability supported by the terminal; The first receiving module is configured to receive first authentication information sent by the network device, and the first authentication information carries a second SES, and the second SES is used to indicate the security capability supported by the first authentication information; The first processing module is configured to securely enhance first key information according to the second SES to obtain second key information, and the first key information is obtained according to a core key K and a random number RAND in the first authentication information, and the second key information is used for key derivation; The first key information includes a first encryption key CK and a first integrity protection key IK; The second key information includes a second CK and a second IK; The first processing module includes: The first processing unit is configured to securely enhance the first CK according to the second SES to obtain the second CK; The second processing unit is configured to securely enhance the first IK according to the second SES to obtain the second IK; The secure enhancement includes at least one of the following: The security enhancement is performed according to a first symmetric key, wherein the first symmetric key is obtained in a case where a USIM on the terminal only supports a first cryptographic algorithm, the first symmetric key is generated in a process of encrypting a Subscriber Permanent Identity (SUPI) of the USIM to obtain a Subscription Concealed Identifier (SUCI) by using a first encryption mechanism, and the first encryption mechanism is a key encapsulation-based encryption mechanism; The security enhancement is performed by using a key derivation function (KDF).
12. A communication authentication apparatus characterized by comprising: The apparatus comprises: The second receiving module is configured to receive a registration request sent by a terminal, wherein the registration request carries a SUCI and a first SES, and the first SES is used to indicate security capabilities supported by the terminal. The second processing module is configured to generate first authentication information and third key information according to a core key K and an AMF, wherein the first authentication information carries a second SES, and the second SES is used to indicate security capabilities supported by the first authentication information. The third processing module is configured to perform security enhancement on the third key information according to the core key K and the first SES to obtain fourth key information, wherein the fourth key information is used for key derivation. The second sending module is configured to send the first authentication information to the terminal. The third key information comprises a third CK and a third IK. The fourth key information comprises a fourth CK and a fourth IK. The third processing module comprises: The fifth processing unit is configured to perform security enhancement on the third CK according to the first SES and the length of the core key to obtain the fourth CK. The sixth processing unit is configured to perform security enhancement on the third IK according to the first SES and the length of the core key to obtain the fourth IK. The security enhancement comprises at least one of the following: The security enhancement is performed according to a second symmetric key, wherein the second symmetric key is obtained by decrypting the SUCI in the registration request according to the first SES by using a first decryption mechanism, and the first decryption mechanism is a key encapsulation-based decryption mechanism. The security enhancement is performed by using a KDF.
13. A terminal comprising: The transceiver, the processor, the memory, and the program or instructions stored on the memory and executable on the processor; characterized in that the processor implements the steps in the communication authentication method of any one of claims 1 to 5 when executing the program or instructions.
14. A network device comprising: The transceiver, the processor, the memory, and the program or instructions stored on the memory and executable on the processor; characterized in that the processor implements the steps in the communication authentication method of any one of claims 6 to 10 when executing the program or instructions.
15. A readable storage medium, having stored thereon a program or instructions, characterized in that, The program or instructions are executed by the processor to implement the steps in the communication authentication method of any one of claims 1 to 5, or implement the steps in the communication authentication method of any one of claims 6 to 10.
16. A computer program product, characterised in that, The program or instructions are executed by the processor to implement the steps in the communication authentication method of any one of claims 1 to 5, or implement the steps in the communication authentication method of any one of claims 6 to 10.
Citation Information
Patent Citations
Edge computing node identity authentication method based on AES algorithm
CN108173882A
Method for negotiating security capability of 5G mobile communication network
CN111787532A