Communication method and communication device
The network device receives the key length indication information of the terminal device and determines the appropriate security algorithm based on the key length, which solves the problem of how to negotiate a reasonable security protection algorithm between the terminal device and the network side, and realizes the saving of computing resources and the efficiency of security protection.
Patent Information
- Application Number
- CN202311600455.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-24
- Publication Date
- 2025-05-27
AI Technical Summary
When negotiating security protection algorithms between the terminal device and the network side, how to determine a reasonable security protection algorithm to save computing resources, especially when the key length and supported algorithms are diverse.
The network device receives the key length indication information of the terminal device, determines a suitable security algorithm based on the key length, and transmits messages with the terminal device for security protection. The input key length of the security algorithm is less than or equal to the key length of the terminal device.
It realizes the selection of reasonable security algorithms based on the key length and security capability information of the terminal device, saves computing resources and improves the efficiency of security protection.
Smart Images

Figure CN120050653A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly, to a communication method and a communication device. Background Art
[0002] A terminal device and a network side can negotiate a security protection algorithm for protecting messages transmitted between the terminal device and the network side. For example, the terminal device and the network side can negotiate algorithms required for confidentiality security protection and integrity security protection based on a non-access stratum (NAS) and an access stratum (AS) security mode control procedure (SMC). In the case where a user identity module of the terminal device supports storing keys of multiple lengths and the terminal device supports multiple security protection algorithms, how to determine a reasonable security protection algorithm is an issue that needs to be considered. Summary of the Invention
[0003] This application provides a communication method and a communication device, which can select a reasonable security protection algorithm and save computing resources.
[0004] In a first aspect, a communication method is provided. This method can be executed by a network device or by a component (such as a chip or a circuit) of the network device. This application does not make any limitation in this regard.
[0005] The method includes: The network device receives first indication information indicating the length of a first key, where the first key is a key of the terminal device; the network device determines a first security algorithm based on the length of the first key, and the length of the input key of the first security algorithm is less than or equal to the length of the first key; the network device transmits a message to the terminal device, and the message is a message that is security-protected based on the first security algorithm. Or,
[0006] The method includes: The network device receives first indication information indicating the length of a first key, where the first key is a key of the terminal device; the network device transmits a message to the terminal device, and the message is a message that is security-protected based on the first security algorithm, the first security algorithm is determined based on the length of the first key, and the length of the input key of the first security algorithm is less than or equal to the length of the first key.
[0007] Based on the above solution, the network device can determine a reasonable security algorithm based on the key of the terminal device and save computing resources, where the length of the input key of the security algorithm can be less than or equal to the length of the first key.
[0008] In combination with the first aspect, in some implementations of the first aspect, the network device is a first core network device, and the network device receives the first indication information from a second core network device and / or the terminal device.
[0009] In combination with the first aspect, in some implementations of the first aspect, the network device is an access network device, and the network device receives the first indication information from a first core network device and / or the terminal device.
[0010] In combination with the first aspect, in some implementations of the first aspect, the network device determines the first security algorithm based on the length of the first key, the security capability information of the terminal device, and an algorithm priority list. The security capability information of the terminal device indicates the security algorithms supported by the terminal device, and the algorithm priority list is used to indicate the priorities of the security algorithms supported on the network side.
[0011] In combination with the first aspect, in some implementations of the first aspect, the first security algorithm is one of the security algorithms supported by the terminal device. The length of the input key of the first security algorithm is less than or equal to the length of the first key, and the priority of the first security algorithm is higher than the priority of a second security algorithm in the algorithm priority list. The second security algorithm includes the security algorithms supported by the terminal device other than the first security algorithm whose input key length is less than or equal to the length of the first key.
[0012] In combination with the first aspect, in some implementations of the first aspect, the network device determines the length of the security key according to the first security algorithm. The security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.
[0013] In combination with the first aspect, in some implementations of the first aspect, the network device sends second indication information to the terminal device. The second indication information indicates the length of the first key. The length of the first key is used to determine the length of the key output by the key derivation algorithm, and the output key is used to generate the security key. The security key is the key used by the security algorithm.
[0014] In a second aspect, a communication method is provided. This method can be executed by a terminal device or by components (such as chips or circuits) of the terminal device. This application does not make any limitations in this regard.
[0015] The method includes: sending first indication information to a network device, where the first indication information indicates the length of a first key, the first key being the key of a terminal device, and the length of the first key is used by the first core network device to determine the length of the input key of a first security algorithm, and the length of the input key of the first security algorithm is less than or equal to the length of the first key; and transmitting a message with the network device, where the message is a message that is secured based on the first security algorithm.
[0016] Based on the above solution, by indicating the length of the first key to the network device, the network device can determine a reasonable security algorithm based on the key of the terminal device, saving computing resources, where the length of the input key of the security algorithm can be less than or equal to the length of the first key.
[0017] Combined with the second aspect, in some implementation manners of the second aspect, before sending the first indication information to the network device, obtain the length of the first key from a user identification module.
[0018] Combined with the second aspect, in some implementation manners of the second aspect, before transmitting a message with the network device, determine the length of the key output by a key derivation algorithm according to the length of the first key, where the key output by the key derivation algorithm is used to generate a security key, and the security key is the key used by the first security algorithm.
[0019] In a third aspect, a communication method is provided, which can be executed by a second core network device or by components (such as chips or circuits) of the second core network device, and this application does not make any limitation in this regard.
[0020] The method includes: determining the length of a first key of a terminal device; sending first indication information to a first core network device, where the first indication information indicates the length of the first key, and the length of the first key is used to determine the length of the key input to a first security algorithm, and the length of the input key of the first security algorithm is less than or equal to the length of the first key, and the first security algorithm is used to secure a message transmitted with the terminal device.
[0021] Based on the above solution, by determining and indicating the length of the first key to the network device, the network device can determine a reasonable security algorithm based on the key of the terminal device, saving computing resources, where the length of the input key of the security algorithm can be less than or equal to the length of the first key.
[0022] Combined with the third aspect, in some implementation manners of the third aspect, receive the identification information of the terminal device from the first core network device; determine the length of the first key according to the identification information of the terminal device.
[0023] In combination with a third aspect, in some implementations of the third aspect, the length of the key output by the key derivation algorithm is determined according to the length of the first key, and the output key is used to generate a security key, and the security key is the key used by the security algorithm.
[0024] A fourth aspect provides a communication method, which can be executed by a terminal device or by a component (such as a chip or a circuit) of the terminal device. This application does not make any limitation in this regard.
[0025] The method includes: sending security capability information of the terminal device to a network device, where the security capability information indicates the security algorithms supported by the terminal device, the length of the input key of the security algorithms supported by the terminal device is less than or equal to the length of the first key, and the first key is the key of the terminal device, and the security capability information of the terminal device is used by the first core network device to determine a first security algorithm; and transmitting a message with the network device, where the message is a message protected based on the first security algorithm.
[0026] Based on the above solution, by sending the security capability information of the terminal device to the network device, where the length of the input key of the security algorithms indicated by the security capability information is less than or equal to the length of the first key, the network device can determine a reasonable security algorithm based on the security capability information of the terminal device, saving computing resources.
[0027] In combination with the fourth aspect, in some implementations of the fourth aspect, before sending the security capability information of the terminal device to the network device, the length of the first key is obtained from a user identification module.
[0028] In combination with the fourth aspect, in some implementations of the fourth aspect, before transmitting a message with the network device, the security capability information of the terminal device to be sent to the network device is determined according to the length of the first key and the security capability information configured in the terminal device.
[0029] In combination with the fourth aspect, in some implementations of the fourth aspect, before transmitting a message with the network device, the length of the key output by the key derivation algorithm is determined according to the length of the first key, and the key output by the key derivation algorithm is used to generate a security key, and the security key is the key used by the first security algorithm.
[0030] A fifth aspect provides a communication method, which can be executed by a network device or by a component (such as a chip or a circuit) of the network device. This application does not make any limitation in this regard.
[0031] The method includes: receiving security capability information of a terminal device, where the security capability information indicates security algorithms supported by the terminal device, the length of the input key of the security algorithms supported by the terminal device is less than or equal to the length of a first key, and the first key is the key of the terminal device; and transmitting a message with the terminal device, where the message is a message secured based on a first security algorithm, and the first security algorithm is one of the security algorithms supported by the terminal device.
[0032] Based on the above solution, by sending the security capability information of the terminal device to a network device, where the length of the input key of the security algorithms indicated by the security capability information is less than or equal to the length of the first key, the network device can determine a reasonable security algorithm based on the security capability information of the terminal device, saving computing resources.
[0033] In combination with the fifth aspect, in some implementation manners of the fifth aspect, before transmitting a message with the terminal device, according to the security capability information of the terminal device and an algorithm priority list, the first security algorithm is determined, and the priority of the first security algorithm is higher than that of the security algorithms supported by the terminal device included in the algorithm priority list other than the first security algorithm.
[0034] In combination with the fifth aspect, in some implementation manners of the fifth aspect, according to the first security algorithm, the length of a security key is determined, the security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.
[0035] In a sixth aspect, a communication device is provided. The device includes a transceiver unit and a processing unit. The transceiver unit is configured to receive first indication information indicating the length of a first key, where the first key is the key of a terminal device; the processing unit is configured to determine a first security algorithm based on the length of the first key, where the length of the input key of the first security algorithm is less than or equal to the length of the first key; and the device transmits a message with the terminal device, where the message is a message secured based on the first security algorithm.
[0036] In combination with the sixth aspect, in some implementation manners of the sixth aspect, the device is a first core network device, and the transceiver unit is specifically configured to receive the first indication information from a second core network device and / or the terminal device.
[0037] In combination with the sixth aspect, in some implementation manners of the sixth aspect, the device is an access network device, and the transceiver unit is specifically configured to receive the first indication information from a first core network device and / or the terminal device.
[0038] In combination with the sixth aspect, in some implementations of the sixth aspect, the processing unit is specifically configured to determine the first security algorithm based on the length of the first key, the security capability information of the terminal device, and the algorithm priority list. The security capability information of the terminal device indicates the security algorithms supported by the terminal device, and the algorithm priority list is used to indicate the priorities of the security algorithms supported by the network side.
[0039] In combination with the sixth aspect, in some implementations of the sixth aspect, the first security algorithm is one of the security algorithms supported by the terminal device. The length of the input key of the first security algorithm is less than or equal to the length of the first key, and the priority of the first security algorithm is higher than the priority of the second security algorithm in the algorithm priority list. The second security algorithm includes the security algorithms supported by the terminal device other than the first security algorithm whose input key lengths are less than or equal to the length of the first key.
[0040] In combination with the sixth aspect, in some implementations of the sixth aspect, the processing unit is further configured to determine the length of the security key according to the first security algorithm. The security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.
[0041] In combination with the sixth aspect, in some implementations of the sixth aspect, the transceiver unit is further configured to send second indication information to the terminal device. The second indication information indicates the length of the first key. The length of the first key is used to determine the length of the key output by the key derivation algorithm, and the output key is used to generate the security key. The security key is the key used by the security algorithm.
[0042] In a seventh aspect, a communication device is provided. The device includes a transceiver unit. The transceiver unit is configured to send first indication information to a network device. The first indication information indicates the length of a first key. The first key is the key of the terminal device. The length of the first key is used for the first core network device to determine the length of the input key of the first security algorithm. The length of the input key of the first security algorithm is less than or equal to the length of the first key. The transceiver unit is further configured to transmit a message with the network device. The message is a message that is security protected based on the first security algorithm.
[0043] In combination with the seventh aspect, in some implementations of the seventh aspect, the device further includes a processing unit. The processing unit is configured to obtain the length of the first key from the user identification module before sending the first indication information to the network device.
[0044] In combination with the seventh aspect, in some implementations of the seventh aspect, before transmitting a message with the network device, the processing unit is further configured to determine the length of the key output by the key derivation algorithm according to the length of the first key, where the key output by the key derivation algorithm is used to generate a security key, and the security key is the key used by the first security algorithm.
[0045] In an eighth aspect, a communication device is provided. The device includes a transceiver unit and a processing unit. The processing unit is configured to determine the length of a first key of a terminal device; the transceiver unit is configured to send first indication information to a first core network device, where the first indication information indicates the length of the first key, and the length of the first key is used to determine the length of the key input to a first security algorithm, and the length of the key input to the first security algorithm is less than or equal to the length of the first key, and the first security algorithm is used to perform security protection on messages transmitted with the terminal device.
[0046] In combination with the eighth aspect, in some implementations of the eighth aspect, the transceiver unit is specifically configured to receive identification information of the terminal device from the first core network device; the transceiver unit is further configured to determine the length of the first key according to the identification information of the terminal device.
[0047] In combination with the eighth aspect, in some implementations of the eighth aspect, the processing unit is further configured to determine the length of the key output by the key derivation algorithm according to the length of the first key, where the output key is used to generate a security key, and the security key is the key used by the security algorithm.
[0048] In a ninth aspect, a communication device is provided. The device includes a transceiver unit, and the transceiver unit is configured to send security capability information of the device to a network device, where the security capability information indicates the security algorithms supported by the device, and the length of the key input to the security algorithms supported by the device is less than or equal to the length of a first key, and the first key is the key of the device, and the security capability information of the device is used for the first core network device to determine a first security algorithm; the transceiver unit is configured to transmit a message with the network device, and the message is a message that is secured based on the first security algorithm.
[0049] In combination with the ninth aspect, in some implementations of the ninth aspect, the device further includes a processing unit, and the processing unit is configured to obtain the length of the first key from a user identification module before sending the security capability information of the device to the network device.
[0050] In combination with the ninth aspect, in some implementations of the ninth aspect, the processing unit is further configured to determine the security capability information of the device sent to the network device according to the length of the first key and the security capability information configured in the device before transmitting a message with the network device.
[0051] In combination with the ninth aspect, in some implementations of the ninth aspect, the processing unit is further configured to determine the length of the key output by the key derivation algorithm before transmitting a message to the network device, where the key output by the key derivation algorithm is used to generate a security key, and the security key is the key used by the first security algorithm.
[0052] The tenth aspect provides a communication device, which includes a transceiver unit and a processing unit. The transceiver unit is configured to receive the security capability information of the terminal device, where the security capability information indicates the security algorithms supported by the terminal device, and the length of the input key of the security algorithms supported by the terminal device is less than or equal to the length of the first key, and the first key is the key of the terminal device; the transceiver unit is further configured to transmit a message to the terminal device, and the message is a message protected by the first security algorithm, and the first security algorithm is one of the security algorithms supported by the terminal device.
[0053] In combination with the tenth aspect, in some implementations of the tenth aspect, the device further includes a processing unit, and the processing unit is configured to determine the first security algorithm according to the security capability information of the terminal device and the algorithm priority list before transmitting a message to the terminal device, and the priority of the first security algorithm is higher than that of the security algorithms supported by the terminal device included in the algorithm priority list except the first security algorithm.
[0054] In combination with the tenth aspect, in some implementations of the tenth aspect, the processing unit is further configured to determine the length of the security key according to the first security algorithm, where the security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.
[0055] The eleventh aspect provides a communication device, including a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the first aspect, the fifth aspect, and any possible implementation manners of the first aspect and the fifth aspect. Optionally, the communication device further includes a memory. Optionally, the communication device further includes a communication interface, and the processor is coupled to the communication interface.
[0056] In one implementation, the communication device is a network device. When the communication device is a network device, the communication interface can be a transceiver, or an input / output interface.
[0057] In another implementation, the communication device is a chip configured in a network device. When the communication device is a chip configured in a network device, the communication interface can be an input / output interface.
[0058] Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.
[0059] In a twelfth aspect, a communication device is provided, including a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the above second aspect, fourth aspect, and any possible implementation manners of the second aspect and the fourth aspect. Optionally, the communication device further includes a memory. Optionally, the communication device further includes a communication interface, and the processor is coupled to the communication interface.
[0060] In one implementation manner, the communication device is a terminal device. When the communication device is a terminal device, the communication interface can be a transceiver or an input / output interface.
[0061] In another implementation manner, the communication device is a chip configured in a terminal device. When the communication device is a chip configured in a terminal device, the communication interface can be an input / output interface.
[0062] In a thirteenth aspect, a communication device is provided, including a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the above third aspect and any possible implementation manners of the third aspect. Optionally, the communication device further includes a memory. Optionally, the communication device further includes a communication interface, and the processor is coupled to the communication interface.
[0063] In one implementation manner, the communication device is a second core network device. When the communication device is a second core network device, the communication interface can be a transceiver or an input / output interface.
[0064] In another implementation manner, the communication device is a chip configured in a second core network device. When the communication device is a chip configured in a second core network device, the communication interface can be an input / output interface.
[0065] In a fourteenth aspect, a processor is provided, including: an input circuit, an output circuit, and a processing circuit. The processing circuit is used to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor executes the methods in any possible implementation manners of the first aspect to the fifth aspect.
[0066] In a specific implementation process, the above-mentioned processor can be one or more chips. The input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be transistors, gate circuits, flip-flops, and various logic circuits, etc. The input signal received by the input circuit can be received and input by a receiver, and the signal output by the output circuit can be output to a transmitter and transmitted by the transmitter. Moreover, the input circuit and the output circuit can be the same circuit, which is used as the input circuit and the output circuit at different times respectively. The embodiments of the present application do not limit the specific implementation manners of the processor and various circuits.
[0067] In a fifteenth aspect, a processing device is provided, including a processor and a memory. The processor is configured to read instructions stored in the memory, and can receive signals through a receiver and transmit signals through a transmitter to execute the method in any one of the possible implementation manners of the first aspect to the fifth aspect.
[0068] Optionally, there may be one or more processors, and there may be one or more memories.
[0069] Optionally, the memory may be integrated with the processor or separately provided from the processor.
[0070] In a specific implementation process, the memory may be a non-transitory memory, such as a read only memory (ROM). This memory may be integrated with the processor on the same chip or separately provided on different chips. The embodiments of the present application do not limit the type of the memory and the setting manner of the memory and the processor.
[0071] It should be understood that relevant data interaction processes, such as sending indication information, may be a process of outputting indication information from the processor, and receiving capability information may be a process of the processor receiving input capability information. Specifically, the data output by the processor may be output to the transmitter, and the input data received by the processor may come from the receiver. Among them, the transmitter and the receiver may be collectively referred to as a transceiver.
[0072] The processing device in the above fifteenth aspect may be one or more chips. The processor in the processing device may be implemented by hardware or by software. When implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor may be a general-purpose processor, which is implemented by reading software code stored in the memory. The memory may be integrated in the processor or may exist independently outside the processor.
[0073] In a sixteenth aspect, a computer program product is provided. The computer program product includes: a computer program (which may also be referred to as code or instruction). When the computer program is run, it causes a computer to execute the method in any one of the possible implementation manners of the first aspect to the fifth aspect.
[0074] In a seventeenth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program (which may also be referred to as code or instruction). When it runs on a computer, it causes the method in any one of the possible implementation manners of the first aspect to the fifth aspect to be executed.
[0075] In an eighteenth aspect, a communication system is provided, including at least one of the foregoing terminal device, network device, and second core network device. Description of the Drawings
[0076] Figure 1 It is a schematic diagram of a network architecture 100.
[0077] Figure 2 It is a schematic diagram of a key architecture.
[0078] Figure 3 It is a schematic flowchart of a NAS SMC process.
[0079] Figure 4 It is a schematic flowchart of an AS SMC process.
[0080] Figure 5 It is a schematic flowchart of a communication method 500 provided by this application.
[0081] Figure 6 It is a schematic flowchart of a communication method 600 provided by this application.
[0082] Figure 7 It is a schematic flowchart of a communication method 700 provided by this application.
[0083] Figure 8 It is a schematic flowchart of a communication method 800 provided by this application.
[0084] Figure 9 It is a schematic flowchart of a communication method 800 provided by this application.
[0085] Figure 10 It is a schematic block diagram of a communication device 10 provided by an embodiment of this application.
[0086] Figure 11 It is a schematic diagram of another communication device 20 provided by an embodiment of this application.
[0087] Figure 12 It is a schematic diagram of a chip system 30 provided by an embodiment of this application. Detailed Embodiments
[0088] Next, the technical solutions in this application will be described with reference to the accompanying drawings.
[0089] The technical solutions provided by this application can be applied to various communication systems, such as: New Radio (NR) systems, Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, etc. The technical solutions provided by this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0090] In a communication system, the part operated by an operator can be called a Public Land Mobile Network (PLMN), or an operator network, etc. A PLMN is a network established and operated by a government or its approved operator for the purpose of providing public land mobile communication services, mainly a public network where a Mobile Network Operator (MNO) provides mobile broadband access services for users. In the embodiments of this application, the PLMN described specifically can be a network that meets the requirements of the 3GPP standard, abbreviated as a 3GPP network. A 3GPP network generally includes but is not limited to a 5G network, a fourth-generation mobile communication (4G) network, and other future communication systems, such as a sixth-generation (6G) network, etc. This technical solution is also applicable to a Stand-alone Non-Public Network (SNPN).
[0091] For ease of description, in the embodiments of this application, the PLMN or the 5G network will be taken as an example for illustration.
[0092] Figure 1 It is a schematic diagram of a network architecture 100. Taking the 5G network architecture based on the service-based architecture in the non-roaming scenario defined in the 3GPP standardization process as an example. As shown in the figure, this network architecture can include three parts, namely the terminal device part, the DN, and the operator network PLMN part. The functions of the network elements in each part will be briefly described below.
[0093] The terminal device part may include a terminal device 110, which may also be referred to as a user equipment (UE). The terminal device 110 in this application is a device with wireless transceiver functions and can communicate with one or more core network (CN) devices via an access network device (or also referred to as an access device) in a radio access network (RAN) 140. The terminal device 110 may also be referred to as an access terminal, a terminal, a user unit, a user station, a mobile station, a mobile device, a remote station, a remote terminal, a mobile device, a user terminal, a user agent, or a user device, etc. The terminal device 110 may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on water (such as a ship, etc.); it can also be deployed in the air (such as an airplane, a balloon, a satellite, etc.). The terminal device 110 may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smart phone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), etc. Alternatively, the terminal device 110 may also be a handheld device with wireless communication functions, a computing device, or other devices connected to a wireless modem, a vehicle-mounted device, a wearable device, a drone device, or a terminal in the Internet of Things, the Internet of Vehicles, any form of terminal in a 5G network and future networks, a relay user equipment, or a terminal in a future evolved 6G network, etc. Among them, the relay user equipment may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. The terminal device here refers to a 3GPP terminal. The embodiments of this application do not limit the type or category of the terminal device. For ease of description, the following examples in this application will use UE to refer to the terminal device for illustration.
[0094] The PLMN part of the operator network may include, but is not limited to, the (radio) access network ((R)AN) 120 and the core network (CN) part.
[0095] (R)AN 120 can be regarded as a sub-network of the operator network and is an implementation system between the service nodes and the terminal device 110 in the operator network. For the terminal device 110 to access the operator network, it first passes through (R)AN 120 and then can be connected to the service nodes of the operator network through (R)AN 120. The access network device (RAN device) in the embodiments of the present application is a device that provides wireless communication functions for the terminal device 110 and can also be called a network device. The RAN device includes, but is not limited to: the next generation node base station (gNB) in the 5G system, the evolved node B (eNB) in the long term evolution (LTE), the radio network controller (RNC), the node B (NB), the base station controller (BSC), the base transceiver station (BTS), the home base station (for example, home evolved node B, or home node B, HNB), the base band unit (BBU), the transmitting and receiving point (TRP), the transmitting point (TP), the pico base station device, the mobile switching center, or the network device in the future network, etc. In systems using different radio access technologies, the names of the devices with the functions of the access network devices may be different. For the convenience of description, in all embodiments of the present application, the above-mentioned device that provides wireless communication functions for the terminal device 110 is collectively referred to as the access network device or simply as RAN or AN. It should be understood that the specific types of the access network devices are not limited herein.
[0096] The CN part may include but is not limited to the following NFs: User Plane Function (UPF) 130, Network Exposure Function (NEF) 131, Network Function Repository Function (NRF) 132, Policy Control Function (PCF) 133, Unified Data Management (UDM) 134, Unified Data Repository (UDR) 135, Network Data Analytics Function (NWDAF) 136, Authentication Server Function (AUSF) 137, Access and Mobility Management Function (AMF) 138, Session Management Function (SMF) 139.
[0097] A data network DN 140, which can also be referred to as a packet data network (PDN), is generally a network outside the operator's network, such as a third-party network. Of course, in some implementation manners, the DN can also be deployed by the operator, that is, the DN belongs to a part of the PLMN. This application does not limit whether the DN belongs to the PLMN. The operator network PLMN can access multiple data networks DN 140, and various services can be deployed on the data network DN 140 to provide services such as data and / or voice for the terminal device 110. For example, the data network DN 140 can be a private network of a smart factory. The sensors installed in the workshop of the smart factory can be the terminal device 110. A control server for the sensors is deployed in the data network DN 140, and the control server can provide services for the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions, etc. Another example is that the data network DN 140 can be an internal office network of a company. The mobile phones or computers of the company's employees can be the terminal device 110, and the mobile phones or computers of the employees can access information, data resources, etc. on the company's internal office network. The terminal device 110 can establish a connection with the operator network through an interface provided by the operator network (such as N1, etc.) and use services such as data and / or voice provided by the operator network. The terminal device 110 can also access the data network DN 140 through the operator network and use operator services and / or services provided by a third party deployed on the data network DN 140.
[0098] The NF functions included in the CN are further briefly described below.
[0099] 1. The UPF 130 is a gateway provided by the operator and is the gateway for communication between the operator network and the data network DN 140. The UPF 130 includes functions related to the user plane such as packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, lawful interception, uplink packet detection, and downlink packet storage.
[0100] 2. The NEF 131 is a control plane function provided by the operator, mainly enabling third parties to use services provided by the network, supporting the network to open its capabilities, events, and data analysis, equipping security information for the PLMN from external applications, converting information exchanged inside and outside the PLMN, providing an API interface for the operator network to open to the outside world, and providing the interaction between an external server and the internal operator network.
[0101] 3. NRF 132 is a control plane function provided by the operator and can be used to maintain real-time information about network functions and services in the network. For example, it supports network service discovery, maintains services supported by the NF configuration data (NF profile) of the NF instance, supports service discovery of the service communication proxy (SCP), maintains the SCP configuration data (SCP profile) of the SCP instance, sends notifications about newly registered, deregistered, and updated NFs and SCPs, and maintains the health status of the running NFs and SCPs.
[0102] 4. PCF 133 is a control plane function provided by the operator. It supports a unified policy framework to govern network behavior, provides policy rules and subscription information related to policy decisions to other control functions, etc.
[0103] 5. UDM 134 is a control plane function provided by the operator and is responsible for storing information such as the subscriber permanent identifier (SUPI) of the subscribed users in the operator network, the generic public subscription identifier (GPSI) of the subscribed users, and the credential.
[0104] Among them, confidentiality protection is performed on the SUPI during the transmission process, and the SUPI with confidentiality protection is called the subscription concealed identifier (SUCI). The information stored by the UDM 134 can be used for the authentication and authorization of the terminal device 110 to access the operator network. Among them, the subscribed users of the above operator network can specifically be users who use the services provided by the operator network. For example, users who use the subscriber identity module (SIM) card of China Telecom, or users who use the SIM card of China Mobile, etc. The credential of the above subscribed users can be a long-term key stored in the SIM card or a small file stored with information related to the encryption of the SIM card, etc., for authentication and / or authorization. It should be noted that information related to verification / authentication, authorization such as the permanent identifier, credential, security context, authentication data (cookie), and token are not distinguished or restricted for the sake of convenience of description in the embodiments of the present application.
[0105] 6. UDR 135 is a control plane function provided by the operator and provides functions for the UDM to store and obtain subscription data, provides functions for the PCF to store and obtain policy data, and stores and obtains the NF group ID information of users, etc.
[0106] 7. NWDAF 136 is a control plane function provided by the operator. Its main function is to collect data from NFs, external application functions (AFs), and operations, administration, and maintenance (OAM) systems, etc., and provide NWDAF service registration, data opening, and data analysis for NFs and AFs. In this application, NWDAF is mainly responsible for data analysis related to security. Therefore, in this application, NWDAF can also be understood as a network element with security analysis capabilities. The network element with security analysis capabilities being called NWDAF is just an example. There may be other network element names in the future, and this application does not limit this.
[0107] 8. AUSF 137 is a control plane function provided by the operator and is usually used for primary authentication, that is, the authentication between the terminal device 110 (subscribed user) and the operator network. After receiving the authentication request initiated by the subscribed user, AUSF 137 can authenticate and / or authorize the subscribed user through the authentication information and / or authorization information stored in UDM 134, or generate the authentication and / or authorization information of the subscribed user through UDM 134. AUSF 137 can feedback the authentication information and / or authorization information to the subscribed user.
[0108] 9. AMF 138 is a control plane network function provided by the operator network and is responsible for the access control and mobility management of the terminal device 110 accessing the operator network. For example, it includes functions such as mobile status management, allocating user temporary identity identifiers, authenticating and authorizing users, etc.
[0109] AMF 138 is used to establish a non-access stratum (NAS) connection with the UE and has the same 5G NAS security context as the UE. The 5G NAS security context can include K AMF , NAS layer keys and their same key identification information, UE security capability, as well as the uplink NAS COUNT value and the downlink NAS COUNT value. The NAS layer keys include the NAS confidentiality protection key and the NAS integrity security protection key, which are used for the confidentiality security protection and integrity security protection of NAS messages respectively.
[0110] 10. The SMF 139 is a control plane network function provided by the operator network and is responsible for managing the PDU session of the terminal device 110. The PDU session is a channel for transmitting PDUs, and the terminal device needs to transmit PDUs with the data network DN 140 through the PDU session. The SMF 139 is responsible for establishing, maintaining, deleting, etc. of the PDU session. The SMF 139 includes session management (such as session establishment, modification, and release, including the tunnel maintenance between the user plane function UPF 130 and the (R)AN 120), selection and control of the UPF 130, service and session continuity (SSC) mode selection, roaming, and other session-related functions.
[0111] 11. The AF 141 is a control plane network function provided by the operator network, used to provide application layer information, and can interact with the policy framework through the network exposure function network element or directly with the policy framework for policy decision requests, etc. It can be located within the operator network or outside the operator network.
[0112] It can be understood that the above network elements or functions can be either physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (such as a cloud platform). Simply put, an NF can be implemented by hardware or by software.
[0113] Figure 1 Among Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nausf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface sequence numbers. Exemplarily, the meanings of the above interface sequence numbers can be referred to the meanings defined in the 3GPP standard protocol, and this application does not limit the meanings of the above interface sequence numbers. It should be noted that the interface names between the various network functions in the figure are only examples. In specific implementations, the interface names of this system architecture may also be other names, and this application does not make any limitations in this regard. In addition, the names of the messages (or signaling) transmitted between the above network elements are also only examples and do not impose any limitations on the functions of the messages themselves.
[0114] For the convenience of description, in the embodiments of this application, the network functions (such as NEF 131... SMF139) are collectively / abbreviated as NF, that is, the NF described later in the embodiments of this application can be replaced by any network function. Additionally, Figure 1 only some network functions are schematically described, and the NF described later is not limited to Figure 1 the network functions shown in
[0115] It should be understood that the network architecture applied to the embodiments of the present application described above is only described from the perspective of the service-based architecture. The network architecture applicable to the embodiments of the present application is not limited thereto, and any network architecture capable of implementing the functions of the above-mentioned network elements is applicable to the embodiments of the present application.
[0116] It should also be understood that the AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown in the figure can be understood as network elements in the core network for implementing different functions. For example, they can be combined into network slices as needed. These core network elements can be individual devices or integrated into the same device to implement different functions. The present application does not limit the specific form of the above-mentioned network elements.
[0117] It should also be understood that the above naming is only defined for the convenience of distinguishing different functions and should not constitute any limitation to the present application. The present application does not exclude the possibility of using other naming in 5G networks and future other networks. For example, in 6G networks, some or all of the above-mentioned network elements may continue to use the terms in 5G, or other names may be used.
[0118] For the convenience of understanding the embodiments of the present application, some basic concepts related to the present application are briefly described.
[0119] 1. Key architecture
[0120] In the 5G system (5G system, 5GS), taking the 5G authentication key agreement protocol (5G authentication and key agreement, 5G AKA) as an example, the key architecture generated by the key hierarchy is as Figure 2 shown. Among them, the keys related to authentication can include K, CK (cipher Key), IK (integrity Key), and the key hierarchy includes the following keys in sequence: AUSF key (K AUS F), anchor key (K SEA F), AMF key (K AMF ), NAS signaling key (K NASint , K NASenc ), non-3GPP access key (K N3IWF ), NG-RAN key (K gNB ), keys transmitted in the user plane (K UPint , K UPenc ), RRC signaling key (K RRCint , K RRCenc ).
[0121] Specifically, in 5GS, security-related network elements (or network elements with root keys) include the UDM, AMF, AUSF, Authentication Credential Repository and Processing Function (ARPF) network element, and Security Anchor Function (SEAF) network element. Among them, the ARPF is mainly used to store the user's root key and relevant subscribed data for authentication, and calculate 5G authentication and authorization vectors, etc. The SEAF is mainly used to derive the lower-layer NAS and AS keys based on the anchor key, and compare the authentication results.
[0122] The above-mentioned keys are described as follows:
[0123] (1) K AUSF : K in the home network AUSF is derived from CK and IK by the mobile equipment (ME) and ARPF. K AUSF . K AUSF is received from the ARPF as part of the 5G home environment authentication vector (HEAV).
[0124] (2) K SEAF : is the anchor key derived by the ME and AUSF from K AUSF . K AUSF is provided by the AUSF to the SEAF in the serving network.
[0125] (3) K AMF : K AMF in the serving network is the key derived by the ME and SEAF from K SEAF . K AMF is further derived by the ME and the source AMF during the execution of horizontal key derivation.
[0126] (4) NAS signaling key: K NASint is the key derived by the ME and AMF from K AMF , and this key is used to protect NAS signaling using a specific integrity algorithm. K NASenc is the key derived by the ME and AMF from K AMF for protecting NAS signaling using a specific encryption algorithm.
[0127] (5) K N3IWF : K N3IWF is the key derived by the ME and AMF from K AMF for non-3GPP access. KN3IWF Not forwarded between N3IWFs.
[0128] (6)K gNB : K gNB is a key derived by the ME and the AMF from K AMF K is further derived by the ME and the source gNB when performing horizontal or vertical key derivation. gNB Not forwarded between N3IWFs.
[0129] (7)Key for user plane UP transmission: K UPint is a key derived by the ME and the gNB from K gNB This key is used to protect the user plane data between the ME and the gNB using a specific integrity algorithm. K UPenc is a key derived by the ME and the gNB from K gNB This key is used to protect the data transmitted on the UP using a specific encryption algorithm.
[0130] (8)Key for RRC signaling: K RRCint is a key derived by the ME and the gNB from K gNB This key is used to protect the RRC signaling using a specific integrity algorithm. K RRCen c is a key derived by the ME and the gNB from K gNB This key is used to protect the RRC signaling using a specific encryption algorithm.
[0131] It should be understood that when deriving a new key from a key, a key derivation function (KDF) can be used for derivation. A key derivation function refers to using a pseudorandom function to derive one or more keys from a master key. The key derivation function can have the ability to extend the key to a longer key or obtain a key in the required format.
[0132] Exemplarily, CK and IK can be derived based on a random number (RAND), an authentication token (AUTH), and K. Among them, the network side will send RAND and AUTH to the UE in plain text. That is, except for K, other inputs for calculating CK and IK are sent in plain text.
[0133] In addition, two algorithms can be used at the bottom layer of the f1 - f5 algorithms: the MILENAGE algorithm and the Tuak algorithm.
[0134] Among them, the Tuak algorithm supports 128 bits and 256 bits, that is, the input key K can be 128 bits or 256 bits, and the output CK and IK can be 128 bits or 256 bits; currently, the MILENAGE algorithm supports 128 bits, that is, the input key K is 128 bits, and the output CK and IK are 128 bits; in the R19 phase, it may be upgraded to 256 bits, that is, the MILENAGE algorithm can support the input K to be 256 bits, and the output CK and IK are also 256 bits.
[0135] According to the security principle, since the keys used for communication between the UE and the network side are all derived from the long-term key, and no other unknown random factors are introduced in the entire derivation process, when the long-term key of the UE is 128 bits, the overall security strength it can provide is at most 128-bit security strength, and it cannot provide 256-bit security strength. After deriving the corresponding key using the above key derivation method, it can be used to protect the corresponding NAS, RRC, and user plane (UP) data.
[0136] 2. NAS security context:
[0137] Exemplarily, from the perspective of completeness, the NAS security context can be divided into a full NAS security context and a partial NAS security context.
[0138] Among them, the partial NAS security context includes: K AMF and its associated key identifier (ngKSI), UE security capability, uplink NAS counter value, and downlink NAS counter value. Compared with the partial NAS security context, the full NAS security context also includes an integrity security protection key and a confidentiality security protection (or encryption security protection) key, as well as the selected integrity security protection algorithm and confidentiality security protection algorithm.
[0139] Exemplarily, from the perspective of the source, the NAS security context can be divided into a native NAS security context and a mapped NAS security context.
[0140] Among them, the K in the native NAS security context AMF is generated by performing the primary authentication process and is identified by the native ngKSI; the K in the mapped NAS security context AMF is generated by other keys during the interaction process between different generations of networks (such as generated by the 4G key during the interaction process from 4G to 5G), and is identified by the mapped ngKSI.
[0141] Exemplarily, from a state perspective, the NAS security context can be divided into current and non-current. The current NAS security context refers to the security context that has been recently activated; the non-current NAS security context refers to the security context that is not in use.
[0142] As can be seen from the above, the specific types of NAS security context can include mapped, fully native, or partially native security contexts. The state can be current or non-current. Exemplarily, after the UE and the core network complete the primary authentication, a partially native context is generated, and the state is non-current. The AMF initiates a NAS security mode control (SMC) process to the UE. After the NAS SMC is successful, a fully native NAS context is generated, and the state is current.
[0143] 3. Security Algorithm Selection Process
[0144] In the following process, the network side or the UE side selects security algorithms for confidentiality security protection and / or integrity security protection.
[0145] 1) Initial NAS Security Context Establishment
[0146] Exemplarily, each AMF can provide a list of allowed algorithm priorities through network management configuration. The algorithm priority list can include algorithms for NAS integrity security protection (denoted as NAS integrity protection algorithms) and algorithms for NAS confidentiality security protection (NAS encryption algorithms). The algorithms in these lists can be sorted according to the priorities determined by the operator.
[0147] To establish the NAS security context, the AMF can select a NAS encryption algorithm and a NAS integrity protection algorithm. Then, the AMF can initiate a NAS security mode command (SMC) process and include the selected algorithms and the UE security capabilities in the message sent to the UE. For example, the AMF can select a NAS encryption algorithm and a NAS integrity protection algorithm with higher priorities that also exist in the UE security capabilities according to the ordered list.
[0148] Optionally, during an N2 handover or a mobility registration update, the AMF serving the UE may change, which may cause a change in the security algorithms used to establish NAS security. In this case, the target AMF indicates to the UE (e.g., using a NAS container) the security algorithms selected during the N2 handover and the mobility registration update (using NAS SMC).
[0149] 2) Initial AS Security Context Establishment
[0150] Exemplarily, each RAN node can be configured by network management to provide a list of allowed algorithm priorities. The algorithm priority list can include algorithms for AS integrity security protection (denoted as AS integrity protection algorithms) and algorithms for AS confidentiality security protection (AS encryption algorithms). When establishing an AS security context in the RAN node, the AMF can send the UE security capabilities to the RAN node. The RAN node selects the AS encryption algorithm and AS integrity protection algorithm with the highest priority from its configured list and that also exist in the UE security capabilities. The algorithms selected by the RAN node can be indicated to the UE in the ASSMC procedure. The AS encryption algorithm selected by the RAN node can be used for the encryption of the user plane and RRC signaling (when activated), and the selected AS integrity protection algorithm can be used for the integrity protection of the user plane and RRC signaling (when activated).
[0151] 3) Xn handover
[0152] When an Xn handover occurs between the source RAN node (gNB / ng-eNB) and the target RAN node (gNB / ng-eNB), the source RAN node can send (e.g., via a handover request message) the encryption and integrity protection algorithms used by the source cell, as well as the UE security capabilities, to the target RAN node; the target RAN node can also select the algorithm with a higher priority from the received UE security capabilities according to the locally configured algorithm priority list. If the algorithm selected by the target RAN node is different from the algorithm selected by the source RAN node, the target RAN node can indicate the algorithm selected by the target RAN node to the UE in the handover command message. If the UE does not receive an indication of the integrity and encryption algorithms, it continues to use the same algorithms as before the handover.
[0153] When an Xn handover occurs between an ng-eNB and a gNB, the selected algorithm in the target RAN node notifies the UE in the handover command. Exemplarily, in the path-switch message, the target RAN node may send the UE security capabilities received from the source RAN node to the AMF; the AMF verifies whether the UE security capabilities received from the target RAN node match the UE security capabilities locally stored in the AMF. If they do not match, the AMF may send its locally stored UE security capabilities to the target RAN node in the path-switch confirmation message. If the target RAN node receives the UE security capabilities from the AMF in the path-switch confirmation message, then the target RAN node may update the UE's AS security context with the UE security capabilities. The target RAN node may select the algorithm with the highest priority from the algorithm priority list according to the locally configured algorithm priority list and the UE security capabilities. If the algorithm selected by the target RAN node is different from the algorithm used by the source RAN node, the target RAN node initiates an intra-cell handover process and indicates the selected algorithm in the cell handover procedure.
[0154] 4) N2 Handover
[0155] When an N2 handover occurs between the source RAN node and the target RAN node, the target AMF may send the UE security capabilities to the target RAN node in the NGAP handover request message. The target RAN node selects the algorithm with a higher priority from the UE security capabilities according to the locally configured algorithm priority list. If the algorithm selected by the target RAN node is different from the algorithm used by the source RAN node, the target RAN node may indicate the selected algorithm to the UE in the handover command message. If the UE does not receive any selection of integrity and encryption algorithms, it will continue to use the same algorithms as before the handover.
[0156] For N2 handover, the source RAN node may send the AS algorithms used in the source cell to the target RAN node. The AS algorithms used in the source cell are provided to the target RAN node so that the target RAN node can use these algorithms in the potential RRC connection reestablishment process.
[0157] 5) Migration from RRC_INACTIVE state to RRC_CONNECTED state
[0158] When transitioning from the RRC_INACTIVE state to the RRC_CONNECTED state, the source RAN node may send the UE security capabilities and the encryption and integrity protection algorithms used in the source cell to the target RAN node in the Xn-AP Retrieve UE Context Response message. The target RAN node may check whether it supports the received encryption and integrity algorithms. For example, the target RAN node should check the received algorithms against its locally configured algorithm priority list. If the target RAN node selects the same security algorithm, the target RAN node should use the selected algorithm to derive the RRC integrity and RRC encryption keys to protect the RRC Resume message and send it to the UE on SRB1.
[0159] If the target RAN node does not support the received algorithms, or if the target RAN node prefers to use different algorithms, the target RAN node sends an RRC Setup message on SRB0 to continue the RRC connection establishment. Then, the UE performs NAS-based RRC resume and negotiates suitable algorithms with the target RAN node through the AS SMC process.
[0160] 4. Security activation process
[0161] 1) NAS security mode command (SMC) process:
[0162] Exemplarily, the functions of the NAS SMC process mainly include the following:
[0163] (1) After the primary authentication is completed, the AMF initiates a NAS SMC message to transform a partial native context into a complete native context for subsequent use.
[0164] (2) Change the NAS security algorithm in the in-use NAS security context. For example, in scenarios where the AMF changes (such as N2 handover or mobility registration and other scenarios where the AMF changes), it is necessary to change the NAS security algorithm in the in-use NAS security context.
[0165] (3) Change the uplink NAS count value in the most recent NAS security mode complete (SMP) message to refresh K gNB .
[0166] (4) Send the selected EPS NAS security algorithm to the UE.
[0167] For ease of understanding, in combination with Figure 3 The NAS SMC process is introduced in detail.
[0168] Figure 3 It is a schematic flowchart of a NAS SMC process, including the following steps:
[0169] S310, the AMF configures a list of algorithm priorities allowed to be used.
[0170] Exemplarily, a NAS integrity security protection algorithm priority list is configured on the AMF (for example, the NAS integrity security protection algorithms configured on the AMF include the AES128 integrity security protection algorithm, the SNOW128 integrity security protection algorithm, the ZUC128 integrity security protection algorithm, the null integrity security protection algorithm, etc.), and a NAS confidentiality security protection algorithm priority list (for example, the NAS confidentiality security protection algorithms configured on the AMF include the ZU128C confidentiality security protection algorithm, the AES128 confidentiality security protection algorithm, the SNOW128 confidentiality security protection algorithm, the null integrity security protection algorithm, etc.).
[0171] Among them, the priorities of the multiple configured integrity security protection algorithms are sorted from high to low. For example, they can be the AES128 integrity security protection algorithm, the SNOW128 integrity security protection algorithm, the ZUC128 integrity security protection algorithm, and the null integrity security protection algorithm; the priorities of the multiple configured confidentiality security protection algorithms are sorted from high to low as the ZUC128 confidentiality security protection algorithm, the AES128 confidentiality security protection algorithm, the SNOW128 confidentiality security protection algorithm, and the null integrity security protection algorithm.
[0172] The AMF obtains the UE security capabilities, and based on the UE security capabilities and the algorithm priority list, selects the NAS integrity security protection algorithm and the NAS confidentiality security protection algorithm.
[0173] Among them, the UE security capabilities include the integrity security protection algorithm and the confidentiality security protection algorithm supported by the UE. The AMF selects the algorithm with the highest priority among those supported by the UE security capabilities from its algorithm priority list. For example, if the UE security capabilities include the supported NAS integrity security protection algorithms as the AES128 integrity security protection algorithm and the SNOW128 integrity security protection algorithm, then the integrity security protection algorithm selected by the AMF is the AES128 integrity security protection algorithm; also for example, if the UE security capabilities include the supported NAS confidentiality security protection algorithms as the AES128 confidentiality security protection algorithm and the ZUC128 confidentiality security protection algorithm, then the confidentiality security protection algorithm selected by the AMF is the ZUC128 confidentiality security protection algorithm.
[0174] S320, the AMF activates the NAS integrity security protection.
[0175] Before sending the NAS SMC message, the AMF activates NAS integrity security protection.
[0176] Exemplarily, the AMF calculates the integrity security protection key K NASint . Further, the AMF performs integrity security protection calculation on the NAS SMC message and obtains the NAS MAC. Exemplarily, the key for calculating the NAS MAC is K NASint , the input parameters are the bearer identifier, the direction parameter, the value of the counter, and the cells in the NAS SMC message to be protected, and the security protection algorithm used is the selected integrity security protection algorithm.
[0177] Among them, the bearer identifier is used to distinguish different bearers. Exemplarily, in a 3GPP connection, the bearer identifier can be "0x01", and in a non-3GPP connection, the bearer identifier can be "0x02"; the direction parameter is used to distinguish between uplink messages and downlink messages. Exemplarily, in an uplink message, the value of the direction parameter is 0, and in a downlink message, the value of the direction parameter is 1; the value of the counter is used as a freshness parameter to prevent replay attacks; the cells in the NAS SMC message to be protected can be the selected EPS security protection algorithm, the international mobile station equipment identity and software version (IMEISV) request indication, etc.;
[0178] It should be noted that the NAS SMC message is subject to integrity security protection and not confidentiality security protection. Because the UE side needs to use the parameters in the message (such as ngKSI, etc.) to obtain the key and algorithm for integrity verification.
[0179] S330, the AMF sends the NAS SMC message to the UE.
[0180] The NAS SMC message includes but is not limited to the selected confidentiality security protection algorithm, the selected integrity security protection algorithm, ngKSI, the replayed UE security capabilities, K AMF change indication, etc. Among them, the selected confidentiality algorithm and the selected integrity security protection algorithm are part of the NAS security context and are used for the UE and the AMF side to negotiate the security protection algorithm for subsequent security protection. ngKSI is used to identify K AMF . The replayed UE security capabilities are used to verify whether the security capabilities have been tampered with, that is, to prevent downgrade attacks, K AMF The change indication is used to indicate that the UE calculates a new K AMF .
[0181] The NAS SMC message includes a "security header type" cell, which is used to indicate the protection method of the NAS message. When the NAS message is a NAS SMC message, the value of this cell is 0011, which is used to identify the use of the 5G NAS security context for integrity security protection;
[0182] It should be noted that the confidentiality security protection algorithm and integrity security protection algorithm carried in the NAS SMC message will be part of the security context later.
[0183] S340, the AMF activates the confidentiality protection of the uplink NAS message.
[0184] After sending the NAS SMC message, the AMF activates the decryption confidentiality protection of the uplink NAS message (e.g., decryption).
[0185] S350, the UE verifies the NAS SMC message.
[0186] Exemplarily, the UE obtains the corresponding K according to ngKSI NASint , and performs integrity verification according to the integrity security protection algorithm carried in the message. In the case of successful integrity verification, the UE activates the integrity security protection and confidentiality security protection of the uplink NAS message, and the decryption operation of the downlink message.
[0187] S360, the UE sends a NAS SMP message to the AMF.
[0188] In the case of successful verification in step S350, the UE sends a NAS SMP message to the AMF, and this message is protected by integrity security protection and confidentiality security protection. Exemplarily, the integrity security protection key is K NASint , the integrity security protection algorithm is the selected integrity security protection algorithm carried in step S330, and the confidentiality security protection key is K NASenc , and the confidentiality security protection algorithm is the selected confidentiality security protection algorithm carried in step S330. Among them, NAS MAC is used for integrity security protection; the AMF receives the NAS SMP message and performs decryption and integrity verification on this message;
[0189] When the NAS message is a NAS SMP message, the value of this cell is 0100, which is used to identify the use of the 5G NAS security context for confidentiality and integrity security protection.
[0190] S370, the AMF activates the confidentiality protection of the NAS downlink message.
[0191] After receiving the NAS SMP message, the AMF activates the confidentiality protection of the NAS downlink message (e.g., encryption).
[0192] It should be noted that in the existing security mechanisms, confidentiality security protection and integrity security protection are independent of each other, that is, both the keys and algorithms are isolated.
[0193] 2) AS SMC process:
[0194] Exemplarily, the function of the AS SMC process is mainly to perform algorithm negotiation for radio resource control (RRC) and user plane (UP), and security activation of RRC. The RRC reconfiguration message is mainly used for security activation of UP.
[0195] For ease of understanding, combined with Figure 4 introduce the AS SMC process in detail.
[0196] Figure 4 is a schematic flowchart of an AS SMC process, including the following steps:
[0197] S410, the access network device configures a list of allowed algorithm priorities.
[0198] Exemplarily, an AS integrity security protection algorithm priority list is configured on the access network device (for example, the AS integrity security protection algorithms configured on the access network device include AES integrity security protection algorithm, SNOW integrity security protection algorithm, ZUC integrity security protection algorithm, null integrity security protection algorithm, etc. Among them, the priorities of the configured multiple integrity security protection algorithms are sorted from high to low as AES integrity security protection algorithm, SNOW integrity security protection algorithm, ZUC integrity security protection algorithm, null integrity security protection algorithm), and an AS confidentiality security protection algorithm priority list (for example, the AS confidentiality security protection algorithms configured on the access network device include ZUC confidentiality security protection algorithm, AES confidentiality security protection algorithm, SNOW confidentiality security protection algorithm, null integrity security protection algorithm. Among them, the priorities of the configured multiple confidentiality security protection algorithms are sorted from high to low as ZUC confidentiality security protection algorithm, AES confidentiality security protection algorithm, SNOW confidentiality security protection algorithm, null integrity security protection algorithm).
[0199] The access network device receives the UE security capabilities, and selects the AS integrity security protection algorithm and the AS confidentiality security protection algorithm according to the UE security capabilities and the algorithm priority list.
[0200] For example, if the UE security capabilities include the supported AS integrity protection algorithms as the AES integrity protection algorithm and the SNOW integrity protection algorithm, the integrity protection algorithm selected by the access network device is the AES integrity protection algorithm; also for example, if the UE security capabilities include the supported AS confidentiality protection algorithms as the AES confidentiality protection algorithm and the ZUC confidentiality protection algorithm, the confidentiality protection algorithm selected by the access network device is the ZUC confidentiality protection algorithm.
[0201] S420, Activate RRC integrity protection.
[0202] Before sending the AS SMC message, the access network device activates RRC integrity protection.
[0203] Exemplarily, the access network device performs integrity protection calculation on the AS SMC message and obtains the MAC-I. Exemplarily, the input key for the AS MAC calculation is K RRCint , the input parameters are the bearer identifier, direction parameter, counter value, etc., and the protection algorithm used is the selected integrity protection algorithm.
[0204] Among them, the bearer identifier is used to distinguish different bearers. Exemplarily, in a 3GPP connection, the bearer identifier can be "0x01", and in a non-3GPP connection, the bearer identifier can be "0x02"; the direction parameter is used to distinguish whether it is an uplink message or a downlink message. Exemplarily, in an uplink message, the value of the direction parameter is 0, and in a downlink message, the value of the direction parameter is 1; the value of the counter is used as a freshness parameter to prevent replay attacks.
[0205] It should be noted that only integrity protection is performed on the AS SMC message, and no confidentiality protection is performed. Because the UE side needs to use the parameters in the message (such as ngKSI, etc.) to obtain the key and algorithm for integrity verification.
[0206] S430, The access network device sends the AS SMC message to the UE.
[0207] The AS SMC message includes, but is not limited to, the selected confidentiality protection algorithm and the selected integrity protection algorithm. Among them, the selected confidentiality protection algorithm and the selected integrity protection algorithm are part of the AS security context and are used for the UE and the access network device side to negotiate the security protection algorithms for subsequent security protection.
[0208] It should be noted that the security protection algorithms for RRC messages and UP messages can be unified, that is, the selected confidentiality security protection algorithm and the selected integrity security protection algorithm are applicable to the security protection of both RRC messages and UP messages; the security protection algorithms for RRC messages and UP messages can be independent, that is, the message includes the selected RRC confidentiality security protection algorithm, the selected RRC integrity security protection algorithm, the selected UP confidentiality security protection algorithm, and the selected UP integrity security protection algorithm.
[0209] S440, the access network device activates the confidentiality protection of the uplink RRC message.
[0210] After sending the AS SMC message, the access network device activates the decryption protection (e.g., decryption) of the uplink RRC message.
[0211] S450, the UE verifies the AS SMC message.
[0212] Exemplarily, the UE obtains the corresponding K RRCint , and performs integrity verification according to the integrity security protection algorithm carried in the message. In the case of successful integrity verification, the UE activates the integrity security protection and confidentiality security protection of the uplink RRC message, and the decryption operation of the downlink message.
[0213] S460, the UE sends an AS SMP message to the access network device.
[0214] In the case of successful verification in step S450, the UE sends an AS SMP message to the access network device. This message is protected by integrity security protection and confidentiality security protection. Exemplarily, the integrity security protection key is K RRCint , the integrity security protection algorithm is the selected integrity security protection algorithm carried in the AS SMC message in step S430, and the confidentiality security protection key is K RRCenc , and the confidentiality security protection algorithm is the selected confidentiality security protection algorithm carried in the AS SMC message in step S430.
[0215] S470, the UE activates the confidentiality of the RRC uplink message.
[0216] After sending the AS SMP message, the UE activates the confidentiality protection of the RRC uplink message.
[0217] S480, the access network device activates the confidentiality protection of the RRC downlink message.
[0218] After receiving the AS SMP message, the access network device activates the confidentiality of the RRC downlink message (e.g., encryption).
[0219] It should be noted that in the existing security mechanisms, confidentiality security protection and integrity security protection are independent of each other, that is, both the key and the algorithm are isolated.
[0220] Generally speaking, the security algorithm of the 5G mobile communication network is negotiated and selected by the network side (AMF / RAN) based on the UE security capabilities reported by the UE and the capabilities of the network side itself (such as the configured security protection algorithm), and the security algorithm with a higher priority that is supported by both the network side and the UE side is selected. Exemplarily, for the UE side, if the UE supports a 256-bit security algorithm, or rather, the UE security capabilities include a 256-bit security algorithm and the network side also supports a 256-bit security algorithm, then the security algorithm negotiated by the network side and the UE side can be 256 bits. However, in this case, if the long-term key in the user identification module of the UE (for example, the universal subscriber identity module (USIM) card) is 128 bits (for example, in the case where the user replaces the ME but does not replace the USIM card), then the key generated based on this long-term key and the negotiated security algorithm can only support 128-bit security. At this time, using a 256-bit security algorithm may cause waste of computing resources.
[0221] In view of this, the present application provides a communication method, which can enable the network side and the UE to negotiate and determine a reasonable security algorithm, saving the overhead of computing resources.
[0222] For the convenience of understanding the embodiments of the present application, the following points are explained.
[0223] First, in the present application, "for indicating" may include for directly indicating and for indirectly indicating. When describing that a certain indication information is used to indicate A, it may include that the indication information directly indicates A or indirectly indicates A, and does not mean that A must be included in the indication information.
[0224] The information indicated by the indication information is called the information to be indicated. Then, in the specific implementation process, there are many ways to indicate the information to be indicated. The information to be indicated can be sent as a whole, or can be divided into multiple sub-information and sent separately, and the sending periods and / or sending times of these sub-information can be the same or different. The specific sending method is not limited in the present application. Among them, the sending periods and / or sending times of these sub-information can be predefined, such as predefined according to the protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.
[0225] Second, the "at least one" shown in this application means one or more, and "multiple" means two or more. Additionally, in the embodiments of this application, the "first", "second", and various numerical numbers (such as "#1", "#2", etc.) are only for the convenience of description and do not limit the scope of the embodiments of this application. The magnitudes of the serial numbers of the following processes do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic and should not impose any limitation on the implementation process of the embodiments of this application. It should be understood that the objects described in this way can be interchanged under appropriate circumstances so as to describe solutions other than the embodiments of this application. In addition, in the embodiments of this application, the words such as "510" and "520" are only identifiers made for the convenience of description and do not limit the order of execution steps.
[0226] Third, in this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplarily" or "for example" in this application should not be construed as more preferred or more advantageous than other embodiments or design solutions. Rather, the use of words such as "exemplarily" or "for example" is intended to present relevant concepts in a specific manner.
[0227] Fourth, the "storage" involved in the embodiments of this application may refer to storage in one or more memories. The one or more memories may be separately provided or integrated in an encoder, decoder, processor, or communication device. The one or more memories may also have a part separately provided and a part integrated in a decoder, processor, or communication device. The type of memory may be any form of storage medium, and this application does not limit this.
[0228] Fifth, the "protocol" involved in the embodiments of this application may refer to standard protocols in the communication field. For example, it may include LTE protocols, NR protocols, and related protocols applied to future communication systems. This application does not limit this.
[0229] Sixth, in the embodiments of this application, "in... cases", "when...", and "if..." can sometimes be used interchangeably. It should be noted that when not emphasizing their differences, the meanings they convey are the same.
[0230] Seventh, in the embodiments of this application, each term and English abbreviation, such as Radio Resource Control (RRC), etc., are all exemplary examples given for the convenience of description and should not impose any limitation on this application. This application does not exclude the possibility of defining other terms in existing or future protocols that can achieve the same or similar functions.
[0231] Eighth, the term "and / or" in this text is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this text generally indicates that the associated objects before and after are in an "or" relationship.
[0232] It should be understood that the specific structure of the execution entity of the method provided in the embodiments of the present application is not particularly limited by the embodiments shown below. As long as it can communicate according to the method provided in the embodiments of the present application by running a program recorded with the code of the method provided in the embodiments of the present application. For example, the execution entity of the method provided in the embodiments of the present application can be a first core network device, or a functional module in the first core network device that can call and execute the program.
[0233] Figure 5 It is a schematic flowchart of a communication method 500 provided by the present application, and this method can include the following steps.
[0234] S510, the network device receives first indication information.
[0235] Wherein, the first indication information indicates the length of a first key, and the first key is a key of the terminal device. For example, the first key is a long-term key of the terminal device.
[0236] Specifically, the first key can be the long-term key stored in the user identification module of the terminal device. The length of the long-term key is, for example, 128 bits or 256 bits.
[0237] As a possible implementation manner, the network device is a first core network device, and the first core network device can be an AMF. The first core network device can receive the first indication information in the manner shown in S510a or S510b:
[0238] S510a, the second core network device sends the first indication information to the first core network device. Correspondingly, the first core network device receives the first indication information from the second core network device.
[0239] Exemplarily, the second core network device is a UDM. The second core network device receives the identification information of the terminal device from the first core network device. For example, the identification information of the terminal device is a subscription concealed identifier (SUCI); the second core network device decrypts the identification information of the terminal device to obtain the subscriber permanent identifier (SUPI) of the subscribed user of the terminal device, and retrieves the long-term key of the terminal device from the stored keys according to the SUPI of the terminal device, so as to obtain the length of the first key.
[0240] Specifically, the second core network device may send the first indication information to the first core network device during the authentication process of the terminal device. For example, the second core network device sends the first indication information to the third core network device through a first message, so that the third core network device sends the first indication information to the first core network device. Among them, the third core network device may be an authentication server function network element, for example.
[0241] Exemplarily, the second core network device may send the first indication information to the third core network device through a Nudm_UEAuthentication_Get Response message, and the third core network device sends the first indication information to the first core network device through a Nausf_UEAuthentication_Authenticate Response message.
[0242] Alternatively, the second core network device may send the first indication information to the first core network device after the terminal device authentication is successful. The first indication information may be carried in an existing message or a newly defined message, without limitation.
[0243] Exemplarily, the first indication information may be a 1-bit value. For example, when the value of the first indication information is 1, it means that the length of the first key is the first length, for example, 128 bits or 256 bits; when the value of the first indication information is 0 or not carried, it means that the length of the first key is the second length, for example, 256 bits or 128 bits.
[0244] Optionally, after the second core network device determines the length of the first key, the second core network device may further determine the length of the key derivation algorithm according to the length of the first key, and deduce a second key according to the first key and the key derivation algorithm.
[0245] Among them, the length of the output key of the key derivation algorithm is equal to the length of the first key; the second key is used to determine the security key used by the first security algorithm. For example, the second key includes an integrity key (IK) and a cipher key (CK). The first security algorithm can refer to the description in the following text.
[0246] S510b, the terminal device sends the first indication information to the first core network device. Correspondingly, the first core network device receives the first indication information from the terminal device.
[0247] Optionally, before the terminal device sends the first indication information to the first core network device, the terminal device can obtain the length of the first key.
[0248] Exemplarily, the terminal device can obtain the length of the first key from the user identification module. For example, the user identification module has an interface to call the length of the first key. The terminal device can receive the length of the first key by sending a request message for the length of the first key to the user identification module and receiving a response message from the user identification module.
[0249] Specifically, the terminal device can send the first indication information to the first core network device in an uplink NAS message. For example, the terminal device can carry the first indication information in a registration request message sent to the second core network device.
[0250] As another possible implementation, the network device is an access network device. The access network device can receive the first indication information in the manner shown in S510c or S510d:
[0251] S510c, the first core network device sends the first indication information to the access network device. Correspondingly, the access network device receives the first indication information from the first core network device.
[0252] Exemplarily, after receiving the first indication information from the second core network device (S510a) or the terminal device (S510b), the first core network device sends the first indication information to the access network device.
[0253] S510d, the terminal device sends the first indication information to the access network device. Correspondingly, the access network device receives the first indication information from the terminal device.
[0254] Optionally, before the terminal device sends the first indication information to the access network device, the terminal device may obtain the length of the first key. Exemplarily, the terminal device may obtain the length of the first key from the user identity module. For details, reference may be made to the description in S510b.
[0255] S520. The network device determines a first security algorithm based on the length of the first key.
[0256] Wherein, the length of the key used by the first security algorithm is less than or equal to the length of the first key.
[0257] Specifically, if the network device is a first core network device (S520a), the first core network device may determine the first security algorithm based on the length of the first key, the security capability information of the terminal device, and the algorithm priority list.
[0258] The security capability information of the terminal device indicates the security algorithms supported by the terminal device. For example, the security capability information may include a list of security algorithms supported by the terminal device, and the list of security algorithms may include at least one security algorithm supported by the terminal device. The security capability information of the terminal device may refer to the UE security capabilities in S310. The algorithm priority list is used to configure the priorities of the security algorithms supported by the network side. The algorithm priority list may refer to the description in S310.
[0259] Wherein, the first security algorithm determined by the first core network device may be used to perform security protection on NAS messages transmitted between the terminal device and the first core network device. For example, the security algorithm is used to perform security protection on the security mode command message and the security mode completion message transmitted in the NAS SMC process, and NAS messages transmitted after the NAS SMC process.
[0260] The first security algorithm is one of the security algorithms supported by the terminal device, or in other words, the first security algorithm is one of the algorithm list supported by the terminal device. The length of the input key of the first security algorithm is less than or equal to the length of the first key, and the priority of the first security algorithm is higher than the priority of the second security algorithm in the algorithm priority list, where the second security algorithm includes the security algorithms other than the first security algorithm in the list of security algorithms supported by the terminal device and with the length of the input key less than or equal to the length of the first key.
[0261] Exemplarily, the specific manner for the first core network device to determine the first security algorithm based on the length of the first key, the security capability information of the terminal device, and the algorithm priority list is as follows:
[0262] Method 1: The first core network device traverses the algorithm priority list from the highest to the lowest priority. If the security capability information of the terminal device indicates that the terminal device supports the currently traversed security algorithm (denoted as security algorithm #1), and the length of the input key of this security algorithm #1 is less than or equal to the length of the first key, then this security algorithm #1 is determined as the first security algorithm. Otherwise, continue to traverse the algorithm priority list until a security algorithm that meets the above conditions is found.
[0263] Method 2: The first core network device determines the security algorithm (denoted as security algorithm #3) that both the terminal device and the network device support based on the security capability information of the terminal device and the algorithm priority list; the first core network device determines, from this security algorithm #3, the security algorithm with the highest priority and the length of the input key less than or equal to the length of the first key as the first security algorithm.
[0264] Exemplarily, the security algorithms configured in the algorithm priority list include AES256 AEAD algorithm, SNOW256 AEAD algorithm, ZUC256 AEAD algorithm, AES128 encryption algorithm, SNOW128 integrity security protection algorithm, ZUC128 integrity security protection algorithm, and null algorithm, etc. Among them, the priorities of the configured multiple encryption algorithms sorted from the highest to the lowest can be, for example, AES256 AEAD algorithm, SNOW256 AEAD algorithm, ZUC256 AEAD algorithm, AES128 encryption algorithm, null algorithm. The priorities of the configured multiple integrity protection algorithms sorted from the highest to the lowest can be: SNOW128 integrity protection algorithm, ZUC128 integrity security protection algorithm, and null algorithm.
[0265] Similarly, if the network device is an access network device, the access network device can determine the first security algorithm based on the length of the first key, the security capability information of the terminal device, and the algorithm priority list. The security capability information of the terminal device indicates the list of security algorithms supported by the terminal device; the algorithm priority list is used to configure the priorities of the security algorithms supported by the network side. The specific determination method can refer to the method by which the first core network device determines the first security algorithm.
[0266] Among them, the first security algorithm determined by the access network device can be used to perform security protection on the AS messages transmitted between the terminal device and the access network device. For example, this security algorithm is used to perform security protection on the RRC messages (such as, security mode command message, security mode complete message) transmitted in the AS SMC process; also for example, this security algorithm is used to perform security protection on the user plane (UP) messages transmitted after the AS SMC process.
[0267] Optionally, the method further includes: the network device determines the length of the security key according to the length of the first key.
[0268] Wherein, the length of the security key is the same as the length of the input key of the first security algorithm. The security key is the key used by the first security algorithm. That is, based on the security key and the first security algorithm, integrity security protection and confidentiality security protection (encryption) can be performed on the sent message, or integrity verification and decryption can be performed on the received message. The security key can be a key shared between the terminal device and the network device. For example, the security key is a key obtained after derivation and truncation processing of the key generated during the primary authentication process. For example, the security key determined by the first core network device can be K NASint and K NASenc . Or, the security key determined by the access network device is K UPint and K UPenc .
[0269] Specifically, if the selected first security algorithm is 128 bits, the length of the security key is determined to be 128 bits. For example, the first core network device truncates the security key generated according to K AMF to 128 bits, and the specific truncation method can refer to existing related descriptions.
[0270] If the selected security algorithm is 256 bits, the length of the security key is determined to be 256 bits. If the length of the security key generated by the first core network device according to K AMF is 512 bits, the 512-bit key can be truncated to 256 bits.
[0271] Similarly, the access network device truncates the security key generated according to K gNB to 128 bits or truncates it to 256 bits.
[0272] When the network device receives the first indication information from the second core network device, the method further includes: the network device sends second indication information to the terminal device, and the second indication information indicates the length of the first key.
[0273] Optionally, the method further includes: the terminal device uses the length of the first key to determine the length of the key output by the key derivation algorithm, and the key output by the key derivation algorithm is used to generate the security key.
[0274] In one implementation, when the network device is the first core network device, the first core network device sends a non-access stratum security mode command message to the terminal device, and the non-access stratum security mode command message includes the second indication information.
[0275] In another implementation manner, when the network device is an access network device, the access network device sends an access layer security mode command message to the terminal device, and the access layer security mode command message carries the second indication information.
[0276] Optionally, the method further includes: the terminal device determines the length of the security key according to the first security algorithm, and the length of the security key is the same as the length of the key used by the first security algorithm. Specifically, reference may be made to the manner in which the first core network device determines the length of the security key as described above, and details are not repeated here.
[0277] Optionally, before the network device determines the first security algorithm, it determines that the trigger condition is met. It can be understood that: the network device selects the first security algorithm when the trigger condition is met. Among them, the trigger condition includes but is not limited to: after the primary authentication is completed, the network device determines to initiate the security mode command process; or, the scenario where the network device undergoes a handover; or, the network device determines to change the uplink count value (such as NAS counter rollover, trigger of primary authentication), etc.
[0278] S530, the network device transmits a message to the terminal device.
[0279] Exemplarily, when the network device is the first core network device (S530a), the message may be a security mode command message, a security mode completion message transmitted in the NAS SMC process, and a NAS message transmitted after the NAS SMC process.
[0280] When the network device is an access network device (S530b), the message may be an RRC message (such as a security mode command message, a security mode completion message) transmitted in the AS SMC process; or, a user plane (UP) message transmitted after the AS SMC process.
[0281] Among them, the message is a message that is security protected based on the first security algorithm.
[0282] It should be understood that the security algorithm determined by the network device in the embodiments of the present application may be an authenticated encryption algorithm that can implement both confidentiality security protection and integrity security protection; or it may also be a confidentiality security protection algorithm and an integrity security protection algorithm; or it may also be that an authenticated encryption algorithm is selected, and a confidentiality security protection algorithm and an integrity security protection algorithm are also selected, which is not limited.
[0283] Based on the above solution, the network device can avoid wasting computing resources due to unreasonable selection of the security algorithm by determining the first security algorithm according to the length of the first key. For example, when the key length used by the security algorithm determined by the network device is greater than the length of the first key, the key generated based on the first key and the security algorithm can only support the security of the first key length. At this time, performing security protection based on the security algorithm selected by the network device may cause waste of computing resources.
[0284] Figure 6 It is a schematic flowchart of a communication method 600 provided by this application. This method may include the following steps.
[0285] S610, the terminal device sends the security capability information of the terminal device to the network device. Correspondingly, the network device receives the security capability information of the terminal device.
[0286] Among them, the security capability information of the terminal device indicates a list of security algorithms supported by the terminal device, and the list of security algorithms includes at least one security algorithm supported by the terminal device. The length of the input key of the security algorithm supported by the terminal device is less than or equal to the length of the first key.
[0287] Exemplarily, the terminal device may send the security capability information to the network device in an uplink NAS message. For example, the terminal device may carry the security capability information in a registration request message sent to the network device.
[0288] Among them, the network device may be a first core network device (S610a) or an access network device (S610b). Optionally, the terminal device may also send the security capability information to the first core network device and the access network device at the same time. For example, the terminal device sends the security capability information to the first core network device through the access network device.
[0289] Optionally, before S610, this method further includes S601 and S602:
[0290] S601, the terminal device determines the length of the first key.
[0291] The specific process for the terminal device to determine the length of the first key may refer to the description in S510b.
[0292] S602, the terminal device determines the security capability information reported by the terminal device according to the length of the first key.
[0293] Exemplarily, when the terminal device is configured with the terminal device security capability information (this security capability information can refer to existing descriptions, such as the UE security capability in S310), the terminal device selects, according to the length of the first key, a security algorithm whose input key length in the UE security capability is less than or equal to that of the first key for reporting.
[0294] S620. The network device determines a first security algorithm according to the security capability information of the terminal device.
[0295] Among them, when the network device is the first core network device (S620a), the first security algorithm determined by the first core network device can be used to protect the security of the messages transmitted between the terminal device and the first core network device.
[0296] When the network device is an access network device (S620b), the first security algorithm determined by the access network device can be used to protect the security of the messages transmitted between the terminal device and the access network device.
[0297] Exemplarily, the network device determines the first security algorithm according to the algorithm priority list and the security capability information of the terminal device.
[0298] For example, the network device traverses the algorithm priority list from high to low in priority. If the currently traversed security algorithm #1 exists in the security capability information of the terminal device, then the security algorithm #1 is determined as the first security algorithm. The priority of the security algorithm #1 is higher than the priorities of other security algorithms supported by the terminal device included in the algorithm priority list.
[0299] Optionally, the method further includes:
[0300] S630. The first core network device sends the security capability information of the terminal device to the access network device. Correspondingly, the access network device receives the security capability information of the terminal device from the first core network device.
[0301] That is, when the network device is an access network device, the access network device can also receive the security capability information of the terminal device from the first core network device.
[0302] S640. The network device transmits messages with the terminal device.
[0303] Exemplarily, when the network device is the first core network device (S650a), the message can be a security mode command message, a security mode complete message transmitted in the NAS SMC process, and a NAS message transmitted after the NAS SMC process.
[0304] When the network device is an access network device (S650b), the message may be an RRC message transmitted in the AS SMC process (such as a security mode command message, a security mode completion message); or, a user plane (UP) message transmitted after the AS SMC process.
[0305] Among them, the message is a message protected by security based on the first security algorithm.
[0306] Based on the above solution, the network device determines the first security algorithm through the security capability information of the terminal device reported by the terminal device. Among them, the length of the input key of the security algorithm supported by the terminal device included in the security capability information is less than or equal to the length of the first key, which can avoid wasting computing resources due to unreasonable selection of the security algorithm.
[0307] It should be understood that the above process of determining the communication method is only an example. The embodiments of the present application can also be applied to other scenarios that require determining the security algorithm. For example, in Xn handover and / or N2 handover, the source RAN node can send (for example, through a handover request message) the first indication information and / or the UE security capability (refer to the security capability information of the terminal device in S610) to the target RAN node, so that the target RAN node can select a reasonable security algorithm according to the communication method shown in the embodiments of the present application.
[0308] The following combines Figures 7 to 9 to introduce in detail the communication method provided by the embodiments of the present application.
[0309] Figure 7 It is a schematic flowchart of a communication method provided by the present application. The method may include the following steps.
[0310] S701, the UE sends a registration request message to the AMF through the RAN. Correspondingly, the AMF receives the registration request message from the UE.
[0311] The registration request message includes the identification information of the UE carrying confidentiality protection, the UE security capability information, and other registration information.
[0312] Among them, the identification information of the UE carrying confidentiality protection is, for example, SUCI or 5G globally unique temporary UE identity (5G-GUTI); the UE security capability information indicates the security algorithms supported by the UE.
[0313] S702, the AMF sends the identification information of the UE to the UDM. Correspondingly, the UDM receives the identification information of the UE from the AMF.
[0314] S703, the UDM determines the length of the long-term key K (an example of the first key) according to the identification information of the UE.
[0315] Exemplarily, the UDM decrypts the identification information of the UE protected by confidentiality to obtain the identification information of the UE, for example, obtains the UE's SUPI; the UDM determines the long-term key K according to the UE's SUPI. For example, the long-term key K is the long-term key stored in the UE's USIM card; the UDM retrieves the long-term key K according to the UE's SUPI and determines the length of the UE's long-term key.
[0316] For example, the length of the long-term key is 128 bits or 256 bits.
[0317] S704, the network side and the UE perform the main authentication process.
[0318] Exemplarily, the main authentication process between the network side and the UE can complete the identity authentication of the UE and the network side and derive the keys for each layer.
[0319] For example, in this main authentication process, the UDM can calculate CK and IK according to the long-term key K and the key derivation algorithm (for example, MILENAGE 128 algorithm or MILENAGE 256 algorithm); the UDM calculates Kasuf according to CK and IK, and the AUSF calculates Kseaf according to Kausf; the SEAF calculates K AMF . The specific calculation process can refer to the existing relevant descriptions.
[0320] Optionally, when deriving keys, the UDM can select the length of the input of the key derivation algorithm used according to the length of the long-term key K.
[0321] For example, the UDM can select whether to use the MILENAGE-128 algorithm or the MILENAGE-256 algorithm for f1-f5 calculation according to the length of the long-term key, so as to derive 128-bit or 256-bit IK and CK, and derive 256-bit (corresponding to the length of CK and IK being 128 bits) or 512-bit (corresponding to the length of CK and IK being 256 bits) K AUSF 、K SEAF 、K AMF etc.
[0322] Specifically, when the long-term key is 128 bits, the UDM can select a 128-bit key derivation algorithm and obtain 128-bit CK and IK, so that each network element derives a 256-bit key, such as 256-bit KAUSF , K SEAF , K AMF etc.
[0323] When the long - term key is 256 bits, the UDM can select a 256 - bit key derivation algorithm and obtain 256 - bit CK and IK, so that each network element can derive a 512 - bit key, such as 512 - bit K AUSF , K SEAF , K AMF etc.
[0324] S705, the UDM sends indication information #1 to the AMF. Correspondingly, the AMF receives indication information #1 from the UDM.
[0325] This indication information #1 (an example of the first indication information) indicates the length of the long - term key K.
[0326] For example, this indication information #1 can directly indicate the length of the long - term key; or, this indication information #1 can be a bit, by setting this bit to "0" to indicate that the length of the long - term key is 128 bits; by setting this bit to "1" to indicate that the length of the long - term key is 256. Vice versa.
[0327] Exemplarily, the UDM can send this indication information #1 to the AUSF through the Nudm_UEAuthentication_Get Response message, and the AUSF sends this indication information #1 to the AMF through the Nausf_UEAuthentication_Authenticate Response message.
[0328] Or, after the UE authentication is successful, the UDM sends this indication information #1 to the AMF. This indication information #1 can be carried in an existing message or a newly defined message, without limitation.
[0329] S706, the AMF determines a security algorithm (an example of the first security algorithm) according to the length of the long - term key.
[0330] This security algorithm can refer to the description above. For example, the security algorithm is 128 - EEA1.
[0331] Specifically, the AMF can determine the security algorithm according to the length of the long - term key, the UE's security capability information, and the configured algorithm priority list. The length of the input key of this security algorithm is less than or equal to the length of the long - term key.
[0332] For example, if the length of the long - term key is 128 bits, select the security algorithm with a higher priority from the 128 - bit security algorithms supported by both the UE and the network side.
[0333] If the length of the long-term key is 256 bits, a security algorithm with a higher priority is selected from the 256-bit security algorithms supported by both the UE and the network side.
[0334] If the length of the long-term key is 256 bits, if the UE and / or the network side does not support 256-bit security algorithms, a security algorithm with a higher priority is selected from the 128-bit security algorithms supported by both the UE and the network side.
[0335] S707, the AMF generates a NAS key and determines the length of the NAS key (an example of a security key) according to the selected security algorithm.
[0336] For example, the AMF generates a NAS key according to K AMF The NAS key is K NASint and K NASenc . The length of the NAS key is consistent with the length of the input key of the security algorithm.
[0337] As can be seen from S704, the length of K AMF can be 256 bits or 512 bits, so the NAS key generated according to this K AMF corresponds to 256 bits or 512 bits.
[0338] Specifically, if the length of the input key of the selected security algorithm is 128 bits, it is determined that the length of the NAS key is 128 bits. For example, the AMF truncates the NAS key generated according to K AMF to 128 bits, and the specific truncation method can refer to existing relevant descriptions.
[0339] If the length of the input key of the selected security algorithm is 256 bits, it is determined that the length of the NAS key is 256 bits. If the length of the NAS key generated by the AMF according to K AMF is 512 bits, the 512-bit key can be truncated to 256 bits.
[0340] This method further includes: the AMF sends indication information #2 (an example of the second indication information) indicating the length of the long-term key to the UE, and / or sends indication information #3 indicating the security algorithm.
[0341] In a possible implementation, the AMF sends the indication information #2 and / or indication information #3 to the UE through the NAS SMC procedure. Specifically, reference can be made to S708 to S710.
[0342] In another possible implementation, the AMF sends the indication information #2 and / or indication information #3 to the UE through the AS SMC procedure of the radio access network device RAN. Specifically, reference can be made to S711 to S716.
[0343] S708, the AMF sends the NAS SMC to the UE. Correspondingly, the UE receives the NAS SMC from the AMF.
[0344] This NAS SMC may carry indication information #2, and this indication information #2 indicates the length of the long-term key.
[0345] Optionally, this NAS SMC carries indication information #3, and this indication information #3 indicates the security algorithm selected by the AMF.
[0346] S709, the UE determines the length of the NAS key.
[0347] In a possible implementation, the UE determines the length of the NAS key (an example of a security key) based on the length of the long-term key and the security algorithm.
[0348] For example, the UE may select a key derivation algorithm according to the length of the long-term key (e.g., the MILENAGE-128 algorithm or the MILENAGE-256 algorithm) to obtain CK and IK. For example, if the length of the long-term key is 128 bits, the MILENAGE128 algorithm is selected to derive 128-bit CK and IK; if the length of the long-term key is 256 bits, the MILENAGE-256 algorithm is selected to derive 256-bit CK and IK.
[0349] Furthermore, the UE determines the NAS key based on CK and IK.
[0350] If the length of this CK and IK is 128 bits, the UE derives a NAS key with a length of 256 bits; if the length of this CK and IK is 256 bits, the UE derives a 512-bit NAS key.
[0351] In the case where the UE derives a 256-bit or 512-bit NAS key, if the input of this security algorithm is 128 bits, the UE truncates the derived NAS key to 128 bits.
[0352] In the case where the UE derives a 256-bit NAS key, if the input of this security algorithm is 256 bits, the UE determines that the length of the NAS key is 256 bits.
[0353] In the case where the UE derives a 512-bit NAS key, if the input of this security algorithm is 256 bits, the UE truncates the derived NAS key to 256 bits.
[0354] In another possible implementation, the UE may determine the length of the NAS key according to the length of the input key of the security algorithm.
[0355] Exemplarily, if the indication information #2 is not carried in the NAS SMC, the UE may determine the length of the NAS key according to the length of the input of the security algorithm.
[0356] This implementation method can be applied to the scenario where the UE and the network side derive keys based on a fixed key derivation algorithm. For example, the NAS key derived by the UE based on the fixed key derivation algorithm is 256 bits or 512 bits.
[0357] In this case, if the length of the input of the security algorithm is 128 bits, the length of the NAS key is determined to be 128 bits; if the length of the input of the security algorithm is 256 bits, the length of the NAS key is determined to be 256 bits.
[0358] S710, the UE sends the NAS SMP to the AMF. Correspondingly, the AMF receives the NAS SMP from the UE.
[0359] S711, the AMF sends the first information to the RAN. Correspondingly, the RAN receives the first information from the AMF.
[0360] The first information may include the security capability information of the UE and the indication information #2. Alternatively, the security capability information of the UE and the indication information #2 may be carried in different messages, which is not limited.
[0361] It should be understood that the AMF may send the first information to the RAN in multiple processes. Specifically, reference may be made to the aforementioned security algorithm selection process.
[0362] S712, the RAN determines the security algorithm according to the length of the long-term key.
[0363] The specific determination method may refer to the description in S706. The length of the input of the security algorithm selected by the RAN may be 128 bits or 256 bits.
[0364] S713, the RAN generates an AS key (an example of a security key) and determines the length of the AS key according to the selected security algorithm.
[0365] The length of this AS key (for example, K RRCint and K RRCenc ) is consistent with the length of the security algorithm.
[0366] Specifically, if the selected security algorithm is 128 bits, the length of the AS key is determined to be 128 bits. For example, the RAN will truncate the AS key generated according to K gNB to 128 bits.
[0367] If the selected security algorithm is 256 bits, the length of the AS key is determined to be 256 bits. If the AMF will generate the AS key according to K gNBIf the length of the generated AS key is 512 bits, the 512-bit key can be truncated to 256 bits.
[0368] S714. The RAN sends the AS SMC to the UE. Correspondingly, the UE receives the AS SMC from the RAN.
[0369] The AS SMC may carry indication information #2, and the indication information #2 indicates the length of the long-term key.
[0370] Optionally, the AS SMC carries indication information indicating the security algorithm selected by the RAN.
[0371] S715. The UE determines the length of the AS key (an example of a security key).
[0372] For example, the AS key is K UPint and K UPenc .
[0373] Exemplarily, the UE determines the length of the AS key according to the length of the long-term key and the security algorithm.
[0374] Alternatively, the UE may determine the length of the AS key according to the length of the input of the security algorithm.
[0375] The specific determination method may refer to the description in S709. The length of the AS key may be 128 bits or 256 bits.
[0376] S716. The UE sends the AS SMP to the RAN. Correspondingly, the RAN receives the AS SMP from the UE.
[0377] Figure 8 It is a schematic flowchart of a communication method provided by this application. The method includes the following steps.
[0378] S801. The UE obtains the length of the long-term key.
[0379] Specifically, the long-term key may refer to the description in S701.
[0380] Exemplarily, the UE obtains the length of the long-term key from the USIM card. For example, the UE sends a request message to the USIM card, and the request message is used to request the length of the long-term key. In response to the request message, the USIM card sends the length of the long-term key to the UE. It can be understood that a dedicated interface is enabled in the USIM card to respond to the UE's request for the key length. Exemplarily, the request may be sent after PIN authentication.
[0381] Or, the length of the long-term key is saved in the UE. For example, the UE includes through Figure 7The length of the long-term key obtained by the method shown. If the UE does not detect a USIM card replacement, the UE saves the information on the length of the long-term key.
[0382] Alternatively, the UE obtains the length of the long-term key from a network device or an access network device. Exemplarily, for the case where indication information #2 is carried, reference can be made to steps S711 - S714.
[0383] S802. The UE determines the UE's security capability information (denoted as security capability information #1) according to the length of the long-term key.
[0384] The security capability information of the UE indicates the security algorithms supported by the UE. Among them, the length of the input key of the security algorithms supported by the UE is less than or equal to the length of the key of this length.
[0385] For example, the UE can determine the security capability information #1 according to the configured UE security capability information. The security algorithms supported by the UE indicated by the security capability information #1 are the security algorithms among the security algorithms supported by the terminal device indicated by the configured UE security capability information whose input key length is less than or equal to the length of the first key.
[0386] S803. The UE sends a registration request message to the AMF through the RAN. Correspondingly, the AMF receives the registration request message from the UE.
[0387] This registration request can refer to the description in S701.
[0388] This registration request carries the UE's security capability information (security capability information #1).
[0389] For example, if the length of the long-term key is 128 bits, the UE only reports the security algorithms with an input of 128 through the security capability information.
[0390] If the length of the long-term key is 256 bits, the UE reports the security algorithms with an input of 128 bits and / or 256 bits through the security capability information.
[0391] S804. The AMF sends the UE's identification information to the UDM. Correspondingly, the UDM receives the UE's identification information from the AMF.
[0392] S805. The UDM determines the length of the long-term key according to the UE's identification information.
[0393] This step can refer to the description in S703.
[0394] For example, the length of the long-term key is 128 bits or 256 bits.
[0395] In S806, the network side and the UE perform the primary authentication process.
[0396] Exemplarily, the primary authentication process between the network side and the UE can complete the identity authentication of the UE and the network side and derive the keys for each layer.
[0397] Optionally, when deriving keys, the UDM can select the length of the input of the key derivation algorithm used according to the length of the long-term key K.
[0398] Specifically, when the long-term key is 128 bits, the UDM can select a 128-bit key derivation algorithm and obtain 128-bit CK and IK, so that each network element can derive a 256-bit key, such as 256-bit K AUSF 、K SEAF 、K AMF and so on.
[0399] When the long-term key is 256 bits, the UDM can select a 256-bit key derivation algorithm and obtain 256-bit CK and IK, so that each network element can derive a 512-bit key, such as 512-bit K AUSF 、K SEAF 、K AMF and so on.
[0400] In S807, the AMF determines the security algorithm according to the UE's security capability information and the configured algorithm priority list.
[0401] For example, the AMF selects the security algorithm with a higher priority from the security algorithms supported by both the UE and the network side.
[0402] In S808, the AMF generates a NAS key (an example of a security key) and determines the length of the NAS key according to the selected security algorithm.
[0403] For example, the AMF generates a NAS key according to K AMF For example, this NAS key is K NASint and K NASenc . The length of this NAS key is consistent with the length of the security algorithm.
[0404] This step can specifically refer to the description in S707.
[0405] Optionally, this method further includes:
[0406] In S809, the AMF and the UE execute the NAS SMC process. Specifically, it can refer to the description in Figure 4 .
[0407] Optionally, this method further includes S810 to S813:
[0408] S810. The AMF sends the security capability information of the UE to the RAN. Correspondingly, the RAN receives the security capability information of the UE from the AMF.
[0409] S811. The RAN determines the security algorithm according to the security capability information of the UE and the configured algorithm priority list.
[0410] This step can refer to the description in S807.
[0411] S812. The RAN generates an AS key (an example of a security key) and determines the length of the AS key according to the selected security algorithm.
[0412] This step can refer to the description in S713.
[0413] S813. The RAN and the UE execute the AS SMC process. Specifically, it can refer to the existing relevant descriptions.
[0414] This step can refer to the existing relevant descriptions.
[0415] Figure 9 It is a schematic flowchart of a communication method provided by this application. The method includes the following steps.
[0416] S901. The UE obtains the length of the long-term key.
[0417] Specifically, this long-term key can refer to the description in S801.
[0418] Exemplarily, the UE obtains the length of this long-term key from the USIM card. This step can specifically refer to S801.
[0419] S902. The UE sends a registration request message to the AMF through the RAN. Correspondingly, the AMF receives the registration request message from the UE.
[0420] This registration request can refer to the description in S701.
[0421] This registration request carries indication information #2 and the security capability information of the UE.
[0422] Among them, this indication information #2 indicates the length of this long-term key. Optionally, this indication information #2 can be encrypted. By encrypting the indication information #2, the length information of the long-term key can be protected. The specific encryption method can be to encrypt with the network-side public key of the encrypted SUPI (if there is no previous security context), or to encrypt with the previous NAS key (if there is a previous security context). This security capability information of the UE indicates the security algorithms supported by the UE.
[0423] S903. The AMF sends the identification information of the UE and indication information #2 to the UDM. Correspondingly, the UDM receives the identification information of the UE and indication information #2 from the AMF.
[0424] S904. The UDM determines the length of the long-term key based on the identification information of the UE.
[0425] This step can refer to the description in S805.
[0426] For example, the length of this long-term key is 128 bits or 256 bits.
[0427] In a possible implementation, the UDM decrypts the indication information #2, obtains the length of the long-term key sent by the UE, and compares it with the length of the long-term key retrieved through the identification information of the UE. If the two lengths are different, an error message is sent and the subsequent steps are not executed.
[0428] S905. The network side and the UE perform the mutual authentication process.
[0429] Exemplarily, the mutual authentication process between the network side and the UE can complete the authentication of the identities of the UE and the network side and derive the keys for each layer.
[0430] Optionally, when deriving the key, the UDM can select the input length of the key derivation algorithm according to the length of the long-term key K.
[0431] S906. The UDM sends indication information #1 to the AMF. Correspondingly, the AMF receives indication information #1 from the UDM.
[0432] This indication information #1 indicates the length of the long-term key K.
[0433] S907. The AMF determines the length of the long-term key.
[0434] Exemplarily, the AMF can compare the length of the long-term key in indication information #2 with that in indication information #1.
[0435] It should be noted that when the long-term key is encrypted with the NAS key, the AMF can compare the length of the long-term key in indication information #4 with that in indication information #1; when the long-term key is encrypted with the home network public key, the UDM decryption and comparison need to be performed through the relevant steps in S904.
[0436] If the length of the long-term key indicated by indication information #2 is the same as the length of the long-term key indicated by indication information #1, it is determined that the length of the long-term key is the length of the long-term key indicated by indication information #1 or indication information #2.
[0437] If the length of the long-term key indicated by the indication information #2 is inconsistent with the length of the long-term key indicated by the indication information #1, an error is reported and the subsequent steps are not executed.
[0438] S908. The AMF determines the security algorithm based on the length of the long-term key.
[0439] Specifically, the AMF can determine the security algorithm based on the length of the long-term key, the UE's security capability information, and the configured algorithm priority list. This step can refer to the description in S706.
[0440] S909. The AMF generates the NAS key and determines the length of the NAS key according to the selected security algorithm.
[0441] This step can refer to the description in S707.
[0442] S910. The AMF sends the NAS SMC to the UE. Correspondingly, the UE receives the NAS SMC from the AMF.
[0443] This step can refer to the existing relevant descriptions
[0444] S911. The UE determines the length of the NAS key.
[0445] Exemplarily, the UE determines the length of the NAS key according to the length of the long-term key obtained in S901 and the security algorithm. Specifically, it can refer to the first possible implementation method in S709.
[0446] In another possible implementation method, the UE can determine the length of the NAS key according to the length of the input of the security algorithm. Specifically, it can refer to the second possible implementation method in S709.
[0447] S912. The UE sends the NAS SMP to the AMF. Correspondingly, the AMF receives the NAS SMP from the UE.
[0448] Or,
[0449] S913. The AMF sends the first information to the RAN. Correspondingly, the RAN receives the first information from the AMF.
[0450] The first information may include the UE's security capability information and the indication information #5, and the indication information #5 indicates the length of the long-term key.
[0451] S914. The RAN determines the security algorithm based on the length of the long-term key.
[0452] The specific determination method can refer to the description in S706. The length of the input of the security algorithm selected by the RAN can be 128 bits or 256 bits.
[0453] S915. The RAN generates an AS key (an example of a security key) and determines the length of the AS key according to the selected security algorithm.
[0454] This AS key (for example, K RRCint and K RRCenc ) has a length consistent with that of the security algorithm.
[0455] Specifically, if the selected security algorithm is 128 bits, the length of the AS key is determined to be 128 bits. For example, the RAN truncates the AS key generated according to K gNB to 128 bits.
[0456] If the selected security algorithm is 256 bits, the length of the AS key is determined to be 256 bits. If the length of the AS key generated by the AMF according to K gNB is 512 bits, the 512-bit key can be truncated to 256 bits.
[0457] S916. The RAN sends the AS SMC to the UE. Correspondingly, the UE receives the AS SMC from the RAN.
[0458] This step can refer to existing relevant descriptions.
[0459] S917. The UE determines the length of the AS key.
[0460] For example, this AS key is K UPint and K UPenc .
[0461] Exemplarily, the UE determines the length of the AS key according to the length of the long-term key obtained in S901 and the security algorithm.
[0462] Alternatively, the UE can determine the length of the AS key according to the length of the input of the security algorithm.
[0463] The specific determination method can refer to the description in S709. The length of this AS key can be 128 bits or 256 bits.
[0464] S918. The UE sends the AS SMP to the RAN. Correspondingly, the RAN receives the AS SMP from the UE.
[0465] It should be understood that the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.
[0466] It should also be understood that in various embodiments of the present application, if there is no special description and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0467] It should also be understood that in some of the above embodiments, the devices in the existing network architecture are mainly used as examples for illustrative purposes (such as network devices, terminal devices, etc.). It should be understood that the specific forms of the devices are not limited in the embodiments of the present application. For example, devices that can achieve the same functions in the future are applicable to the embodiments of the present application.
[0468] It can be understood that in each of the above method embodiments, the methods and operations implemented by the devices (such as core network devices, access network devices, and terminal devices) can also be implemented by components of the devices (such as chips or circuits).
[0469] Above, in combination with Figures 5 to 9 The communication method provided by the embodiments of the present application has been described in detail. The above communication method is mainly introduced from the perspective of the interaction between core network devices (such as the first core network device and the second core network device), access network devices, and terminal devices. It can be understood that in order to implement the above functions, the core network devices, access network devices, and terminal devices include the corresponding hardware structures and / or software modules for executing each function.
[0470] Those skilled in the art should be able to realize that, in combination with the units and algorithm steps of the examples described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0471] The following in combination with Figures 10 to 12 The communication device provided by the present application will be described in detail. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, the content not described in detail can be referred to the above method embodiments, and for the sake of brevity, some content will not be repeated.
[0472] The embodiments of the present application can divide the functional modules of the transmitting device or the receiving device according to the above method examples. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. It should be noted that the division of modules in the embodiments of the present application is illustrative, only a logical function division, and there can be other division methods in actual implementation. The following will take the example of dividing each functional module corresponding to each function for illustration.
[0473] Figure 10 FIG. 4 is a schematic block diagram of a communication device 10 provided by an embodiment of the present application. The device 10 includes a transceiver module 11 and a processing module 12. The transceiver module 11 can implement corresponding communication functions. The processing module 12 is used for data processing. Or rather, the transceiver module 11 is used to perform operations related to reception and transmission, and the processing module 12 is used to perform other operations except reception and transmission. The transceiver module 11 can also be referred to as a communication interface or a communication unit.
[0474] Optionally, the device 10 may further include a storage module 13. The storage module 13 can be used to store instructions and / or data. The processing module 12 can read the instructions and / or data in the storage module so that the device can implement the actions of the device in the foregoing method embodiments.
[0475] In one design, the device 10 can correspond to the core network device (for example, the first core network device or the second core network device) in the foregoing method embodiment, or a component (such as a chip) of the core network device.
[0476] The device 10 can implement the steps or processes performed by the core network device corresponding to the foregoing method embodiment. Among them, the transceiver module 11 can be used to perform the operations related to reception and transmission of the core network device in the foregoing method embodiment, and the processing module 12 can be used to perform the operations related to processing of the core network device in the foregoing method embodiment.
[0477] It should be understood that the specific processes of each unit performing the above corresponding steps have been described in detail in the foregoing method embodiments. For the sake of brevity, they will not be repeated here.
[0478] In another design, the device 10 can correspond to the access network device in the foregoing method embodiment, or a component (such as a chip) of the access network device.
[0479] The device 10 can implement the steps or processes corresponding to those executed by the access network device in the above method embodiments. Among them, the transceiver module 11 can be used to perform the operations related to the transceiver of the access network device in the above method embodiments, and the processing module 12 can be used to perform the operations related to the processing of the access network device in the above method embodiments.
[0480] It should be understood that the specific processes of each unit executing the above corresponding steps have been described in detail in the above method embodiments. For the sake of brevity, they will not be repeated here.
[0481] In another design, the device 10 can correspond to the terminal device in the above method embodiments, or a component (such as a chip) of the terminal device.
[0482] The device 10 can implement the steps or processes corresponding to those executed by the terminal device in the above method embodiments. Among them, the transceiver module 11 can be used to perform the operations related to the transceiver of the terminal device in the above method embodiments, and the processing module 12 can be used to perform the operations related to the processing of the terminal device in the above method embodiments.
[0483] It should be understood that the specific processes of each unit executing the above corresponding steps have been described in detail in the above method embodiments. For the sake of brevity, they will not be repeated here.
[0484] It should also be understood that the device 10 is embodied in the form of functional modules here. The term "module" here can refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a dedicated processor or a group of processors, etc.) for executing one or more software or firmware programs, and a memory, a combined logic circuit and / or other suitable components supporting the described functions. In an alternative example, those skilled in the art can understand that the device 10 can specifically be the access and mobility management network element or the data management network element in the above embodiments, which can be used to execute each process and / or step corresponding to the access and mobility management network element or the data management network element in the above method embodiments; or, the device 10 can specifically be the access network device in the above embodiments, which can be used to execute each process and / or step corresponding to the access network device in the above method embodiments. To avoid repetition, they will not be repeated here; or, the device 10 can specifically be the terminal device in the above embodiments, which can be used to execute each process and / or step corresponding to the terminal device in the above method embodiments. To avoid repetition, they will not be repeated here.
[0485] The device 10 in each of the above solutions has the function of implementing the corresponding steps performed by the devices (such as core network devices, access network devices, and terminal devices) in the above methods. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions; for example, the transceiver module can be replaced by a transceiver (for example, the sending unit in the transceiver module can be replaced by a transmitter, and the receiving unit in the transceiver module can be replaced by a receiver), and other units, such as the processing module, can be replaced by a processor to respectively perform the transceiver operations and related processing operations in each method embodiment.
[0486] In addition, the above transceiver module 11 can also be a transceiver circuit (for example, it can include a receiving circuit and a sending circuit), and the processing module can be a processing circuit.
[0487] Figure 11 It is a schematic diagram of another communication device 20 provided by an embodiment of the present application. The device 20 includes a processor 21, and the processor 21 is used to execute the computer program or instruction stored in the memory 22, or read the data / signaling stored in the memory 22 to execute the methods in the above method embodiments. Optionally, the processor 21 is one or more.
[0488] Optionally, as Figure 11 shown, the device 20 further includes a memory 22, and the memory 22 is used to store computer programs or instructions and / or data. The memory 22 can be integrated with the processor 21 or can be separately provided. Optionally, the memory 22 is one or more.
[0489] Optionally, as Figure 11 shown, the device 20 further includes a transceiver 23, and the transceiver 23 is used for receiving and / or sending signals. For example, the processor 21 is used to control the transceiver 23 to receive and / or send signals.
[0490] As a solution, the device 20 is used to implement the operations performed by the access network device in the above method embodiments.
[0491] As another solution, the device 20 is used to implement the operations performed by the core network device in the above method embodiments.
[0492] As another solution, the device 20 is used to implement the operations performed by the terminal device in the above method embodiments.
[0493] It should be understood that the processor mentioned in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0494] It should also be understood that the memory mentioned in the embodiments of the present application may be volatile memory and / or non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), or flash memory. The volatile memory may be a random access memory (RAM). For example, the RAM may be used as an external cache. By way of example and not limitation, the RAM includes the following various forms: static random access memory (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0495] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) may be integrated in the processor.
[0496] It should also be noted that the memory described herein is intended to include, but not be limited to, these and any other suitable types of memory.
[0497] Figure 12 This is a schematic diagram of a chip system 30 provided by an embodiment of the present application. The chip system 30 (or may also be referred to as a processing system) includes a logic circuit 31 and an input / output interface 32.
[0498] Among them, the logic circuit 31 can be a processing circuit in the chip system 30. The logic circuit 31 can be coupled to a storage unit to call instructions in the storage unit, enabling the chip system 30 to implement the methods and functions of the embodiments of the present application. The input / output interface 32 can be an input / output circuit in the chip system 30, outputting the information processed by the chip system 30, or inputting the data or signaling information to be processed into the chip system 30 for processing.
[0499] As a solution, the chip system 30 is used to implement the operations performed by the core network device, access network device, and terminal device in the above method embodiments.
[0500] For example, the logic circuit 31 is used to implement the processing-related operations performed by the core network device, access network device, and terminal device in the above method embodiments; the input / output interface 32 is used to implement the sending and / or receiving-related operations performed by the core network device, access network device, and terminal device in the above method embodiments.
[0501] The embodiment of the present application also provides a computer-readable storage medium, on which computer instructions for implementing the methods performed by the core network device, access network device, and terminal device in the above method embodiments are stored.
[0502] For example, when the computer program is executed by a computer, the computer can implement the methods performed by the core network device, access network device, and terminal device in the above method embodiments.
[0503] The embodiment of the present application also provides a computer program product, including instructions, which when executed by a computer, implement the methods performed by the core network device, access network device, and terminal device in the above method embodiments.
[0504] The embodiment of the present application also provides a communication system, including the aforementioned core network device, access network device, and terminal device.
[0505] The explanations and beneficial effects of the relevant content in any of the above-mentioned devices can refer to the corresponding method embodiments provided above, and will not be elaborated here.
[0506] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0507] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD), etc.). For example, the aforementioned available media include, but are not limited to: USB flash drives, external hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs and other media that can store program codes.
[0508] As described above, this is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A communication method, characterized in that, it includes: The network device receives first indication information, where the first indication information indicates the length of a first key, and the first key is the key of the terminal device; The network device determines a first security algorithm based on the length of the first key, and the length of the input key of the first security algorithm is less than or equal to the length of the first key; The network device transmits a message to the terminal device, and the message is a message that is securely protected based on the first security algorithm.
2. The method according to claim 1, characterized in that, The network device is a first core network device, and the network device receiving the first indication information includes: The network device receives the first indication information from a second core network device and / or the terminal device.
3. The method according to claim 1, characterized in that, The network device is an access network device, and the network device receiving the first indication information includes: The network device receives the first indication information from a first core network device and / or the terminal device.
4. The method according to any one of claims 1 to 3, characterized in that, The network device determining the first security algorithm based on the length of the first key includes: The network device determines the first security algorithm based on the length of the first key, the security capability information of the terminal device, and an algorithm priority list. The security capability information of the terminal device indicates the security algorithms supported by the terminal device, and the algorithm priority list is used to indicate the priorities of the security algorithms supported by the network side.
5. The method according to claim 4, characterized in that, The first security algorithm is one of the security algorithms supported by the terminal device, and the priority of the first security algorithm is higher than the priority of a second security algorithm in the algorithm priority list. The second security algorithm includes the security algorithms supported by the terminal device other than the first security algorithm and having an input key length less than or equal to the length of the first key.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: The network device determines the length of a security key according to the first security algorithm. The security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.
7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: The network device sends second indication information to the terminal device. The second indication information indicates the length of the first key, and the length of the first key is used to determine the length of the key output by a key derivation algorithm. The output key is used to generate a security key, and the security key is the key used by the security algorithm.
8. A communication method, characterized in that, it includes: Send first indication information to a network device, where the first indication information indicates the length of a first key, the first key being a key of a terminal device, and the length of the first key being used by a first core network device to determine the length of an input key of a first security algorithm, the length of the input key of the first security algorithm being less than or equal to the length of the first key; Transmit a message with the network device, the message being a message that is security protected based on the first security algorithm.
9. The method according to claim 8, wherein, before sending the first indication information to the network device, the method further includes: Obtain the length of the first key from a user identification module.
10. The method according to claim 8 or 9, wherein, before transmitting a message with the network device, the method further includes: Determine the length of a key output by a key derivation algorithm according to the length of the first key, the key output by the key derivation algorithm being used to generate a security key, the security key being the key used by the first security algorithm.
11. A communication method, wherein, includes: Determine the length of a first key of a terminal device; Send first indication information to a first core network device, the first indication information indicating the length of the first key, the length of the first key being used to determine the length of an input key of a first security algorithm, the length of the input key of the first security algorithm being less than or equal to the length of the first key, the first security algorithm being used to security protect a message transmitted with the terminal device.
12. The method according to claim 11, wherein, the determining the length of the first key of the terminal device includes: Receive identification information of the terminal device from the first core network device; Determine the length of the first key according to the identification information of the terminal device.
13. The method according to claim 11 or 12, wherein, the method further includes: Determine the length of a key output by a key derivation algorithm according to the length of the first key, the output key being used to generate a security key, the security key being the key used by the security algorithm.
14. A communication method, wherein, includes: Send security capability information of a terminal device to a network device, the security capability information indicating a security algorithm supported by the terminal device, the length of an input key of the security algorithm supported by the terminal device being less than or equal to the length of a first key, the first key being a key of the terminal device, the security capability information of the terminal device being used by the first core network device to determine a first security algorithm; Transmit a message with the network device, the message being a message that is security protected based on the first security algorithm.
15. The method according to claim 14, wherein, before sending the security capability information of the terminal device to the network device, the method further includes: Obtain the length of the first key from a user identification module.
16. The method according to claim 14 or 15, wherein, before transmitting a message with the network device, the method further includes: Determine the security capability information of the terminal device to be sent to the network device according to the length of the first key and the security capability information configured in the terminal device.
17. The method according to any one of claims 14 to 16, wherein, before transmitting a message with the network device, the method further includes: Determine the length of the key output by the key derivation algorithm according to the length of the first key, and the key output by the key derivation algorithm is used to generate a security key, and the security key is the key used by the first security algorithm.
18. A communication method, wherein, includes: Receive the security capability information of the terminal device, where the security capability information indicates the security algorithms supported by the terminal device, and the length of the input key of the security algorithms supported by the terminal device is less than or equal to the length of the first key, and the first key is the key of the terminal device; Transmit a message with the terminal device, and the message is a message that is secure protected based on the first security algorithm, and the first security algorithm is one of the security algorithms supported by the terminal device.
19. The method according to claim 18, wherein, before transmitting a message with the terminal device, the method further includes: Determine the first security algorithm according to the security capability information of the terminal device and the algorithm priority list, and the priority of the first security algorithm is higher than that of the security algorithms supported by the terminal device other than the first security algorithm included in the algorithm priority list.
20. The method according to claim 18 or 19, wherein, the method further includes: Determine the length of the security key according to the first security algorithm, where the security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.
21. A communication device, wherein, includes: One or more functional modules for performing the method according to any one of claims 1 to 7, or one or more functional modules for performing the method according to any one of claims 8 to 10, or one or more functional modules for performing the method according to any one of claims 11 to 13, or one or more functional modules for performing the method according to any one of claims 14 to 17, or one or more functional modules for performing the method according to any one of claims 18 to 20.
22. A communication device, wherein, includes: A processor for executing a computer program stored in a memory, so that the device executes the method according to any one of claims 1 to 7, or so that the device executes the method according to any one of claims 8 to 10, or for executing the method according to any one of claims 11 to 13, or for executing the method according to any one of claims 14 to 17, or for executing the method according to any one of claims 18 to 20.
23. A computer-readable storage medium, wherein, includes: The computer-readable storage medium stores a computer program; when the computer program runs on a computer, the computer is caused to execute the method according to any one of claims 1 to 20.
24. A chip, characterized in that the chip is installed in a communication device, the chip includes a processor and a communication interface, and when the processor reads and runs instructions through the communication interface, the communication device is caused to execute the method according to any one of claims 1 to 20.
Citation Information
Cited By
Communication method and communication apparatus
EP4808176A1
Communication method and communication apparatus
WO2025108327A1
Access stratum security
WO2026118473A1