Secure communication method, device and system, terminal and network side equipment
By generating and using security requirements at the terminal, the problems of complex and insufficient security of small data transmission processes are solved, and more efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202311673953.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-07
- Publication Date
- 2025-06-10
AI Technical Summary
The small data transmission process is complicated and cannot guarantee the security of data transmission.
The target wireless signaling is received through the terminal, and the derived algorithm is generated based on the derived information and security requirements, and security operations are performed, such as sending information and receiving information, and security protection and processing are performed.
It reduces the complexity of data transmission, improves the security of interaction between terminals and core network nodes, and reduces data transmission delay.
Smart Images

Figure CN120128916A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technologies, and particularly relates to a secure communication method, apparatus, system, terminal, and network-side device. Background Art
[0002] With the development of communication technologies, in a communication system, to improve the efficiency of data transmission, a terminal can send and receive UE dedicated data with a network-side device without entering a connected state, that is, small data transmission (SDT). Currently, small data transmission mainly includes mobile originated SDT (MO-SDT) transmitted on a physical uplink shared channel (PUSCH) of an uplink message 3 (Msg3) triggered by the terminal or a configured grant (CG), or mobile terminated SDT (MT-SDT) triggered by the downlink. In this way, multiple message interactions between the terminal and the network-side device are still required to complete small data interaction. The interaction process is complex and cannot ensure the security of data transmission. Summary of the Invention
[0003] Embodiments of this application provide a secure communication method, apparatus, system, terminal, and network-side device, which can solve the problems of complex small data transmission process and inability to ensure the security of data transmission.
[0004] In a first aspect, a secure communication method is provided, including:
[0005] A terminal receives a target radio signaling, where the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters. The first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0006] When the first identification information is related to the terminal, the terminal generates a first security requirement based on at least one of first derived information and the security requirement derivation algorithm;
[0007] The terminal performs a first operation based on the first security requirement;
[0008] Wherein, the first operation includes at least one of the following:
[0009] Send the first information to an access network node;
[0010] Send the first information carrying a third security parameter to an access network node;
[0011] Receive second information from the access network node;
[0012] Wherein, the first information or part of the content in the first information is protected based on the first security requirement, and / or, the second information or part of the content in the second information is processed based on the first security requirement;
[0013] The first derived information includes at least one of the following: a core network related key, a non-access stratum (NAS) layer related key, an access network related key, an access stratum (AS) layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter;
[0014] The first security requirement includes at least one of a key and a cipher stream.
[0015] In a second aspect, a secure communication method is provided, which is characterized by including:
[0016] An access network node sends target radio signaling, where the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameter, and second security parameter, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
[0017] In a third aspect, a secure communication method is provided, which is characterized by including:
[0018] An access network node sends target radio signaling, where the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameter, and second security parameter, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0019] A terminal receives the target radio signaling;
[0020] When the first identification information is related to the terminal, the terminal generates a first security requirement based on at least one of first derived information and the security requirement derivation algorithm;
[0021] The terminal performs a first operation based on the first security requirement;
[0022] Wherein, the first operation includes at least one of the following:
[0023] Sending first information to an access network node;
[0024] Sending first information carrying third security parameters to an access network node;
[0025] Receiving second information from an access network node;
[0026] Wherein, the first information or part of the content in the first information is protected based on the first security requirement, and / or, the second information or part of the content in the second information is processed based on the first security requirement;
[0027] The first derived information includes at least one of the following: a core network related key, a non-access stratum (NAS) layer related key, an access network related key, an access stratum (AS) layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameters;
[0028] The first security requirement includes at least one of a key and a cipher stream.
[0029] In a fourth aspect, a secure communication device is provided, which is characterized by comprising:
[0030] A first receiving module, configured to receive a target radio signaling, where the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of a first indication information, a first algorithm information, a first security parameter, and a second security parameter, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0031] A requirement generation module, configured to, when the first identification information is related to the terminal, the terminal generates a first security requirement based on at least one of the first derived information and the security requirement derivation algorithm;
[0032] A first execution module, configured to perform a first operation based on the first security requirement;
[0033] Wherein, the first operation includes at least one of the following:
[0034] Sending first information to an access network node;
[0035] Send a first message carrying a third security parameter to an access network node;
[0036] Receive a second message from the access network node;
[0037] Wherein, the first message or part of the content in the first message is protected based on the first security requirement, and / or, the second message or part of the content in the second message is processed based on the first security requirement;
[0038] The first derived information includes at least one of the following: a core network related key, a non-access stratum NAS layer related key, an access network related key, an access stratum AS layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter;
[0039] The first security requirement includes at least one of a key and a cipher stream.
[0040] In a fifth aspect, a secure communication device is provided, which is characterized by including:
[0041] A first sending module, configured to send a target radio signaling, where the target radio signaling includes a first identification information and a first target information; the first target information includes a first security assistance information, and the first security assistance information includes at least one of a first indication information, a first algorithm information, a first security parameter, and a second security parameter, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
[0042] In a sixth aspect, a secure communication system is provided, which is characterized by including: a terminal and an access network node, wherein,
[0043] The access network node is configured to send a target radio signaling, where the target radio signaling includes a first identification information and a first target information; the first target information includes a first security assistance information, and the first security assistance information includes at least one of a first indication information, a first algorithm information, a first security parameter, and a second security parameter, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0044] The terminal is configured to receive the target radio signaling; when the first identification information is related to the terminal, generate a first security requirement based on at least one of the first derived information and the security requirement derivation algorithm; perform a first operation based on the first security requirement;
[0045] Wherein, the first operation includes at least one of the following:
[0046] Send the first information to the access network node;
[0047] Send the first information carrying the third security parameter to the access network node;
[0048] Receive the second information from the access network node;
[0049] Wherein, the first information or part of the content in the first information is protected based on the first security requirement, and / or, the second information or part of the content in the second information is processed based on the first security requirement;
[0050] The first derived information includes at least one of the following: a core network related key, a non-access stratum (NAS) layer related key, an access network related key, an access stratum (AS) layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter;
[0051] The first security requirement includes at least one of a key and a cipher stream.
[0052] In a seventh aspect, a terminal is provided, which includes a processor and a memory. The memory stores a program or instruction that can run on the processor. When the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.
[0053] In an eighth aspect, a terminal is provided, which includes a processor and a communication interface. The communication interface is used to receive target radio signaling, and the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of a first indication information, a first algorithm information, a first security parameter, and a second security parameter. The first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0054] When the first identification information is related to the terminal, the processor is used to generate a first security requirement by the terminal based on at least one of the first derived information and the security requirement derivation algorithm;
[0055] The communication interface is further used to perform a first operation based on the first security requirement;
[0056] Wherein, the first operation includes at least one of the following:
[0057] Send the first information to the access network node;
[0058] Send the first information carrying the third security parameter to the access network node;
[0059] Receive the second information from the access network node;
[0060] Wherein, the first information or part of the content in the first information is protected based on the first security requirement, and / or, the second information or part of the content in the second information is processed based on the first security requirement;
[0061] The first derived information includes at least one of the following: a core network related key, a non-access stratum (NAS) layer related key, an access network related key, an access stratum (AS) layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter;
[0062] The first security requirement includes at least one of a key and a cipher stream.
[0063] In a ninth aspect, a network-side device is provided. The network-side device includes a processor and a memory. The memory stores a program or instructions that can run on the processor. When the program or instructions are executed by the processor, the steps of the method described in the second aspect are implemented.
[0064] In a tenth aspect, a network-side device is provided, including a processor and a communication interface. The communication interface is used to send target radio signaling, and the target radio signaling includes the first identification information and the first target information; the first target information includes the first security assistance information, and the first security assistance information includes at least one of the first indication information, the first algorithm information, the first security parameter, and the second security parameter. The first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
[0065] In an eleventh aspect, a readable storage medium is provided. The readable storage medium stores a program or instructions. When the program or instructions are executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented.
[0066] In a twelfth aspect, a wireless communication system is provided, including: a terminal and a network-side device. The terminal can be used to execute the steps of the method described in the first aspect, and the network-side device can be used to execute the steps of the method described in the second aspect.
[0067] In a thirteenth aspect, a chip is provided, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is configured to run a program or an instruction to implement the method described in the first aspect or the method described in the second aspect.
[0068] In a fourteenth aspect, a computer program / program product is provided. The computer program / program product is stored in a storage medium and is executed by at least one processor to implement the method described in the first aspect or the method described in the second aspect.
[0069] In the embodiments of the present application, when the terminal is related to the first identification information, the terminal generates a first security requirement based on at least one of the first derived information and the security requirement derivation algorithm; and performs a first operation based on the first security requirement, so that data or signaling can be transmitted in the first interaction information between the terminal and the network-side device in the subsequent process, reducing the complexity of data transmission, and thus reducing the data transmission delay. At the same time, the first security requirement is used to protect at least part of the content of the first information, and the first security requirement is used to perform security processing on at least part of the content of the second information, thereby improving the security of the interaction between the terminal and the core network node. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] Figure 1 is a block diagram of a wireless communication system to which the embodiments of the present application can be applied;
[0071] Figure 2 is one of the flowcharts of the security communication method provided by the embodiments of the present application;
[0072] Figure 3 is another flowchart of the security communication method provided by the embodiments of the present application;
[0073] Figure 4 is a third flowchart of the security communication method provided by the embodiments of the present application;
[0074] Figure 5 is a fourth flowchart of the security communication method provided by the embodiments of the present application;
[0075] Figure 6 is a schematic structural diagram of a security communication device provided by the embodiments of the present application;
[0076] Figure 7 is a schematic structural diagram of another security communication device provided by the embodiments of the present application;
[0077] Figure 8 is a schematic structural diagram of a communication device provided by the embodiments of the present application;
[0078] Figure 9 It is a schematic structural diagram of a terminal provided by an embodiment of the present application;
[0079] Figure 10 It is a schematic structural diagram of a network-side device provided by an embodiment of the present application. Detailed implementation manners
[0080] The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are usually of the same type, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "or" in the present application means at least one of the connected objects. For example, "A or B" covers three scenarios, namely, Scenario 1: including A and not including B; Scenario 2: including B and not including A; Scenario 3: including both A and B. The character " / " generally indicates an "or" relationship between the associated objects before and after.
[0081] The term "indication" in the present application can be either a direct indication (or an explicit indication) or an indirect indication (or an implicit indication). Among them, a direct indication can be understood as that the sender clearly informs the receiver of specific information, operations to be performed, or request results, etc. in the sent indication; an indirect indication can be understood as that the receiver determines the corresponding information according to the indication sent by the sender, or makes a judgment and determines the operations to be performed or request results, etc. according to the judgment result.
[0082] It should be noted that the technology described in the embodiments of this application is not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, and can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in the embodiments of this application are often used interchangeably, and the described technology can be used in the above-mentioned systems and radio technologies, as well as in other systems and radio technologies. The following description describes the New Radio (NR) system for example purposes, and the NR term is used in most of the following descriptions, but these technologies can also be applied to systems other than the NR system, such as the 6th Generation (6 th Generation, 6G) communication system.
[0083] Figure 1Block diagram of a wireless communication system to which embodiments of the present application can be applied. The wireless communication system includes a terminal 11 and a network-side device 12. Among them, the terminal 11 can be a mobile phone, a tablet personal computer, a laptop computer, a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device, a flight vehicle, a vehicle user equipment (VUE), a shipborne device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, TVs, washing machines or furniture, etc.), a game console, a personal computer (PC), a teller machine or a self-service machine, etc. Wearable devices include: smart watches, smart bracelets, smart earphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart ankle chains, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle user equipment can also be referred to as a vehicle terminal, a vehicle controller, a vehicle module, a vehicle component, a vehicle chip or a vehicle unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiments of the present application. The network-side device 12 can include an access network system or a core network device. Among them, the access network system can also be referred to as a radio access network (RAN) device, a radio access network function or a radio access network unit. The access network system can include a base station, a wireless local area network (WLAN) access point (AP) or a wireless fidelity (WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), home Node B (HNB), home evolved Node B, Transmission Reception Point (TRP), or some other suitable term in the art. As long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiments of this application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.
[0084] The core network device may include, but is not limited to, at least one of the following: core network node, core network function, Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), etc. It should be noted that in the embodiments of this application, only the core network devices in the NR system are taken as examples for introduction, and the specific types of core network devices are not limited.
[0085] For ease of understanding, some content related to the embodiments of this application is described below:
[0086] I. Small Data Transmission (SDT).
[0087] The characteristics of efficient small data transmission are that for terminals (UEs) in a non-Radio Resource Control (RRC) connected state, it is possible to avoid excessive signaling overhead caused by the resulting RRC state transition and RRC connection establishment process, and the purpose of small data transmission can be achieved through a very simple signaling process. Among them, the non-RRC connected state can include the idle state (IDLE) and the inactive state (INACTIVE).
[0088] The characteristics of the small data transmission scheme are that all the current data radio bearers (DRBs) of the UE are in a suspended state rather than a released state. Therefore, before sending a ResumeRequest message, the UE can first resume the DRB and then piggyback the small data using RRC signaling. At this time, it can transmit data on the DRB just like a UE in the CONNECTED state. Thus, state transition can be avoided, and the purpose of efficient small data transmission can be achieved with relatively small signaling overhead.
[0089] Since small data transmission uses DRB transmission and the access stratum (AS) security has been activated, small data transmission can perform necessary security protection on the data, such as data encryption and integrity protection operations. From a security perspective, since the UE may have moved to another base station in the suspended state, the security key used by the UE to retransmit packets at this time needs to be updated. The update method is to perform the update operation of the next key according to the parameters provided by the network side device to the UE when it enters the suspended state for calculating the next-hop key.
[0090] The data to be transmitted in small data transmission is carried on the dedicated traffic channel (DTCH) and transmitted after being multiplexed with the uplink RRCConnectionResumeRequest message. Similarly, if there is a replied downlink message, it can also be carried on the DTCH and multiplexed with the downlink RRCConnectionRelease message for transmission. The uplink and downlink data are both encrypted, and the encryption operation is performed using the updated next key.
[0091] Optionally, small data can be transmitted on Msg3 PUSCH in a 4-step random access channel (RACH) process. Small data can also be transmitted on MsgA PUSCH in a 2-step RACH process, or on PUSCH resources scheduled by a configured grant (CG) configured in the RRC inactive state. Small data transmission in 2-step RACH and 4-step RACH processes is called RACH based small data transmission, and small data transmission based on PUSCH scheduled by configured grant is called CG based small data transmission.
[0092] 2. Mobile Terminated Early Data Transmission (MT-EDT).
[0093] In the LTE system, the network (NW) carries the MT-EDT trigger message through the paging message, and then the UE initiates the EDT process. After receiving the UE's request message (carrying the MT-EDT cause value), the NW concatenates the RRC response message with the DRB data into a protocol data unit and sends it to the UE, ultimately realizing the reception of downlink services.
[0094] Data transmission in idle or inactive state is a special transmission mechanism, which allows UE to send and receive UE dedicated data (UE dedicate data) with the NW side without entering the connected state. Currently, small data transmission is mainly transmitted in the uplink Msg3 or MO-SDT transmitted on CG PUSCH triggered by the terminal, or MT-SDT triggered by the downlink. There is no corresponding solution for how to transmit data or schedule data transmission in paging messages. To this end, a secure communication method of the present application is proposed, that is, the data or data transmission resources are directly delivered to the UE through the first broadcast signal that the UE can receive, such as paging, thereby reducing the message interaction process.
[0095] The following is a detailed description of the secure communication method provided by the embodiments of the present application through some embodiments and their application scenarios in conjunction with the accompanying drawings.
[0096] Reference Figure 2 , the embodiment of the present application provides a secure communication method, such as Figure 2 As shown, the secure communication method includes:
[0097] Step 201, the terminal receives a target radio signaling, where the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0098] Step 202, when the first identification information is related to the terminal, the terminal generates a first security requirement based on at least one of first derived information and the security requirement derivation algorithm;
[0099] Step 203, the terminal performs a first operation based on the first security requirement;
[0100] Wherein, the first operation includes at least one of the following:
[0101] Sending first information to an access network node;
[0102] Sending first information carrying third security parameters to an access network node;
[0103] Receiving second information from an access network node;
[0104] Wherein, the first information or part of the content in the first information is protected by security based on the first security requirement, and / or, the second information or part of the content in the second information is processed by security based on the first security requirement;
[0105] The first derived information includes at least one of the following: a core network related key, a non-access stratum (NAS) layer related key, an access network related key, an access stratum (AS) layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameters;
[0106] The first security requirement includes at least one of a key and a cipher stream.
[0107] In the embodiments of the present application, the above first identification information can be understood as a target identification or a part of the target identification intercepted, and the target identification can include at least one of a user identification, a group identification, a connection identification, a bearer identification, a thing identification, and an interaction identification.
[0108] Optionally, the terminal being related to the first identification information can be understood as the relevant identification of the terminal being associated with the first identification information. For example, if the target radio signaling includes a user identification, and the user identification included in the target radio signaling is the user identification of the terminal, it can be considered that the terminal is related to the first identification information. In this case, the terminal can perform the above first operation.
[0109] It should be understood that when the terminal is not related to the first identification information, the terminal can discard the received first target information.
[0110] Optionally, the above first indication information can be used to indicate at least one of data transmission and data reception.
[0111] Optionally, when the first security assistance information includes first algorithm information and the first algorithm information includes a full-component derivation algorithm, the terminal can generate a first security component based on the indicated security component derivation algorithm, or can also generate a first security component based on the indicated security component derivation algorithm and other relevant information (such as first derivation information). Optionally, the content in the first derivation information can be agreed upon by the protocol or determined by the terminal, or indicated by the access network node through the first target information. For example, core network-related keys, non-access stratum (NAS) layer-related keys, access network-related keys and access stratum (AS) layer-related keys, keys in the terminal context, information in the terminal core network context, and information in the terminal access network context can be agreed upon by the protocol, and the above-mentioned third security parameter can be determined by the terminal itself.
[0112] Optionally, part or all of the information in the first security assistance information can be used to generate the first security component. When using part of the information in the first security assistance information to generate the first security component, the remaining content can be not used, or used to perform the first operation, such as for security protection or security processing.
[0113] It should be noted that the above target radio signaling can be understood as the radio signaling that the terminal can receive in the idle state or non-active state. Since when the terminal is related to the first identification information, the terminal generates a first security component based on at least one of the first derivation information and the security component derivation algorithm; and performs a first operation based on the first security component, data or signaling transmission can be achieved in the first interaction information between the subsequent terminal and the network-side device, thereby reducing the data transmission delay.
[0114] Optionally, the above KeyStream can be a string generated based on a secret key and other parameters.
[0115] Optionally, the above core network related keys may include a Long Term Key, an Authentication related key (Kausf), a Security and Authentication related key (Kseaf), an AMF key (Kamf), a Mobility Management Entity (MME) key (Kasme), etc.
[0116] NAS layer related keys may include a NAS encryption key (Knas_enc), a NAS integrity key (Knas_int), etc.
[0117] Access network related keys may include base station keys (such as Kenb, Kgnb, NH, Kenb*, Kgnb*, Ks-enb, Ks-gnb, etc.).
[0118] AS layer related keys may include a signaling encryption key (Krrc_enc), a signaling integrity key (Krrc_int), a data encryption key (Kup_enc), a data integrity key (Kup_int), etc.
[0119] Keys in the terminal context may include any one or at least two combinations of core network related keys, NAS layer related keys at the non-access stratum, access network related keys, and AS layer related keys at the access stratum.
[0120] In the embodiments of the present application, when the terminal is related to the first identification information, the terminal generates a first security requirement based on at least one of the first derived information and the security requirement derivation algorithm; and performs a first operation based on the first security requirement, so that data or signaling transmission can be achieved in the first interaction information between the terminal and the network side device subsequently, thereby reducing the data transmission delay. At the same time, at least part of the content of the first information is protected by the first security requirement, and at least part of the content of the second information is processed by the first security requirement, thereby improving the security of the interaction between the terminal and the core network node.
[0121] It should be noted that before the access network device sends the target radio signaling, the access network node receives third information or target data from the core network node, and the third information includes third identification information and second target information;
[0122] Among them, the third information includes second identification information and second target information; the second target information includes at least one of the following:
[0123] The first security requirement or the second security requirement;
[0124] The first algorithm information;
[0125] The second indication information;
[0126] the second security parameter
[0127] second security assistance information
[0128] Wherein, the first security requirement includes at least one of a secret key and a cipher stream, the second security requirement includes at least one of a secret key and a cipher stream, the second security assistance information includes information in the terminal core network context, the second indication information is used to generate the first indication information, and the second identification information is used to indicate the terminal or is related to the first identification information.
[0129] In an embodiment of the present application, the access network node may obtain or generate the first security requirement based on the second target information, and send the target radio signaling based on the third information.
[0130] For example, in some embodiments, the access network node generates the first security requirement based on at least one of second derived information and the security requirement derivation algorithm. Wherein, the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in the terminal context, at least part of the content of the first security assistance information, at least part of the content of the second security assistance information, the first identification information, and information in the terminal access network context.
[0131] Optionally, the second identification information may be a Globally Unique Temporary Identifier (GUTI), and the first identification information may be an RNTI; or the second identification information is a GUTI and the first identification information is a Short Term Mobile Subscriber Identity (S-TMSI); or both the second identification information and the first identification information are S-TMSI.
[0132] Optionally, the above target data may be understood as data to be transmitted (i.e., small data). In some embodiments, the above third information may further include the above target data.
[0133] Optionally, in some embodiments, the above second information may be encrypted target data (or encrypted data generated based on the target data).
[0134] Optionally, the access network node may further perform at least one of the following:
[0135] Receive first information from the terminal;
[0136] Receive first information carrying a third security parameter from the terminal;
[0137] Send a second piece of information to the terminal;
[0138] Wherein, the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in the terminal context, a second security requirement, information in the terminal access network context, at least some of the content in the first security assistance information, the first identification information, at least some of the content in the second security assistance information, and the third security parameter;
[0139] Wherein, the first piece of information or some of the content in the first piece of information is securely processed based on the first security requirement, and / or, the second piece of information or some of the content in the second piece of information is securely protected based on the first security requirement.
[0140] Optionally, in some embodiments, the above-mentioned third piece of information includes at least one of the following:
[0141] At least one second identification information and at least one second target information;
[0142] At least one pair of second identification information and second target information;
[0143] Wherein, the second target information and the second identification information are in a one-to-one or many-to-one mapping;
[0144] Or, the second identification information and the second target information are in a one-to-zero or one mapping;
[0145] Or, there is a corresponding relationship between K second identification information and all second target information, and K is less than or equal to the number of second identification information included in the third piece of information.
[0146] In the embodiments of the present application, the second target information and the second identification information being in a one-to-one or many-to-one mapping can be understood as: the second target information can have a one-to-one mapping relationship with the second identification information, or a many-to-one mapping relationship. For example, all the second target information and the second identification information are in a one-to-one mapping; or all the second target information and the second identification information are in a many-to-one mapping; or some of the second target information and the second identification information are in a one-to-one mapping, and some of the second target information and the second identification information are in a many-to-one mapping.
[0147] The second identification information and the second target information being in a one-to-zero or one mapping can be understood as: the second identification information can have a one-to-one mapping relationship with the second target information, or a one-to-zero mapping relationship, where the one-to-zero mapping relationship means that there is no second target information mapped to the second identification information. For example, all the second identification information and the second target information are in a one-to-one mapping; or some of the second identification information and the second target information are in a one-to-one mapping, and some of the second identification information and the second target information are in a one-to-zero mapping.
[0148] Optionally, for the case where there is a correspondence between K pieces of second identification information and all second target information, when K is equal to the number of second identification information included in the target radio signaling, it can be understood that all second identification information has mapped second target information; when K is less than the number of second identification information included in the target radio signaling, it can be understood that only some second identification information has mapped second target information, and some second identification information has no mapped second target information. Wherein, the mapping relationship between the second target information and the second identification information may include at least one of the following: one-to-one mapping relationship; one-to-many mapping relationship.
[0149] Optionally, in some embodiments, the second identification information is used to indicate a terminal, or is generated by a terminal identifier, or indicates a group of terminals, or is related to the first identification information.
[0150] It should be noted that, in the embodiments of the present application, the above core network node can be understood or replaced by a device or system with core network functions, that is, it can be called a core network device or a core network system, or it can also be called a core network function. The above access network node can be understood as a device or system with access network functions, that is, it can be called an access network device or a system, or it can also be called a base station or an access network function.
[0151] Optionally, in some embodiments, the method includes at least one of the following:
[0152] The terminal also performs security protection on the first information or part of the content in the first information based on the first calculation parameter;
[0153] The terminal also performs security processing on the second information or part of the content in the second information based on the first calculation parameter;
[0154] Wherein, the first calculation parameter includes at least one of the following:
[0155] Information in the terminal core network context;
[0156] Information in the terminal access network context;
[0157] The first identification information;
[0158] At least part of the content in the first security assistance information;
[0159] The third security parameter.
[0160] In the embodiments of the present application, the terminal further performs security protection on the first information or a part of the first information based on the first calculation parameter, which can be understood as that the terminal performs security protection on the first information or a part of the first information based on the first security requirement and the first calculation parameter.
[0161] The terminal further performs security processing on the second information or a part of the second information based on the first calculation parameter, which can be understood as that the terminal performs security processing on the second information or a part of the second information based on the first security requirement and the first calculation parameter.
[0162] Optionally, at least part of the first security auxiliary information included in the first calculation parameter may be the same as, different from, or partially the same as at least part of the first security auxiliary information included in the first derived information. For example, in some embodiments, the first security auxiliary information includes two parts of information, where one part of the information (such as the first security parameter) is used to perform the first operation, and the other part (such as the second security parameter) is used to generate the security requirement.
[0163] Optionally, the first security parameter is used to represent the counting information of the NAS, such as the number of downlink NAS signaling times, or the number of uplink NAS signaling times, or the number of NAS signaling times (the sum value of the number of downlink NAS signaling times and the number of uplink NAS signaling times); the second security parameter is used to represent the counting information of the access network signaling or the counting information of the data packet. For example, the second security parameter may be the number of downlink access network signaling times, the number of uplink access network signaling times, or the number of access network signaling times (that is, the sum value of the number of downlink access network signaling times and the number of uplink access network signaling times), or may also be the number of downlink data packets, the number of uplink data packets, or the number of data packets (that is, the sum of the number of downlink data packets and the number of uplink data packets). The above third security parameter can be understood as being used to represent the counting information of the access network signaling or the counting information of the data packet. For example, the second security parameter may be the number of downlink access network signaling times, the number of uplink access network signaling times, or the number of access network signaling times (that is, the sum value of the number of downlink access network signaling times and the number of uplink access network signaling times), or may also be the number of downlink data packets, the number of uplink data packets, or the number of data packets (that is, the sum of the number of downlink data packets and the number of uplink data packets). Optionally, in some embodiments, the third security parameter is different from the second security parameter.
[0164] Optionally, in some embodiments, the information in the terminal core network context includes at least one of the following:
[0165] The identification information of the terminal;
[0166] The group identification information of the terminal;
[0167] The counting information of the non-access stratum NAS signaling;
[0168] Counting information of non-access stratum (NAS) uplink signaling
[0169] Counting information of non-access stratum (NAS) downlink signaling
[0170] Counting information of protocol data packets transmitted through NAS
[0171] Counting information of uplink protocol data packets transmitted through NAS
[0172] Counting information of downlink protocol data packets transmitted through NAS
[0173] Or, information in the context of the terminal accessing the network, including at least one of the following:
[0174] Identification information of the terminal
[0175] Group identification information of the terminal
[0176] Counting information of access stratum (AS) signaling
[0177] Counting information of access stratum (AS) uplink signaling
[0178] Counting information of access stratum (AS) downlink signaling
[0179] Counting information of protocol data packets
[0180] Counting information of uplink protocol data packets
[0181] Counting information of downlink protocol data packets
[0182] Optionally, in some embodiments, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
[0183] Optionally, in some embodiments, the target radio signaling includes at least one of the following:
[0184] At least one first identification information and at least one first target information
[0185] At least one pair of first identification information and first target information
[0186] Wherein, the first target information and the first identification information are in a one-to-one or many-to-one mapping;
[0187] Or, the first identification information and the first target information are in a one-to-zero or one mapping;
[0188] Alternatively, there is a correspondence between N pieces of first identification information and all first target information, and N is less than or equal to the number of pieces of first identification information included in the target radio signaling.
[0189] In the embodiments of the present application, the one-to-one or many-to-one mapping between the first target information and the first identification information can be understood as: the first target information can have a one-to-one mapping relationship with the first identification information, or a many-to-one mapping relationship. For example, all the first target information and the first identification information are in a one-to-one mapping; or all the first target information and the first identification information are in a many-to-one mapping; or some of the first target information and the first identification information are in a one-to-one mapping, and some of the first target information and the first identification information are in a many-to-one mapping.
[0190] The one-to-zero or one mapping between the first identification information and the first target information can be understood as: the first identification information can have a one-to-one mapping relationship with the first target information, or a one-to-zero mapping relationship, where the one-to-zero mapping relationship means that there is no first target information mapped to the first identification information. For example, all the first identification information and the first target information are in a one-to-one mapping; or some of the first identification information and the first target information are in a one-to-one mapping, and some of the first identification information and the first target information are in a one-to-zero mapping.
[0191] Optionally, for the case where there is a correspondence between N pieces of first identification information and all first target information, when N is equal to the number of pieces of first identification information included in the target radio signaling, it can be understood that there is first target information mapped to all the first identification information; when N is less than the number of pieces of first identification information included in the target radio signaling, it can be understood that only some of the first identification information has first target information mapped thereto, and some of the first identification information has no first target information mapped thereto. Among them, the mapping relationship between the first target information and the first identification information can include at least one of the following: a one-to-one mapping relationship; a many-to-one mapping relationship.
[0192] Optionally, in some embodiments, the terminal is in an idle state or a non-active state, or is in an idle state or a non-active state before sending the first information, or is in an idle state or a non-active state before receiving the second information.
[0193] In the embodiments of the present application, the idle state includes two cases: the core network idle state and the radio idle state. The core network idle state refers to a state of a terminal in which the core network cannot directly send NAS messages targeted at the terminal (paging must be performed first), or the terminal cannot directly send NAS messages to the core network (corresponding sending resources must be obtained first). It can also be said that there is no NAS connection between the terminal and the core network. The radio idle state means that the terminal has no resources to send signaling to the base station to establish a radio point-to-point connection between the terminal and the base station (there are dedicated radio resources of the terminal for receiving and transmitting information, including dedicated scrambling code resources, such as Radio Network Temporary Identifier (RNTI)). The inactive state refers to a state of a terminal in which the terminal is not in the core network idle state, there is a connection or tunnel for the terminal between the core network and the base station, but there is no radio point-to-point connection between the terminal and the base station. The state of the terminal can also be defined using other names. There are other behaviors between the terminal and the base station. For example, there is a radio point-to-point connection between the terminal and the base station, but the core network cannot directly send NAS messages targeted at the terminal. This state may use a new name, but still corresponds to the description of the idle state (i.e., the core network idle state) of the present application. For example, the terminal is not in the core network idle state (it can directly send NAS messages targeted at the terminal), there is a radio point-to-point connection between the terminal and the base station, but there is no connection for the terminal between the core network and the base station (for example, uplink or downlink NAS messages are identified by the UE ID as the source or target, rather than by the Tunnel endpoint identifier (TEID)). This state can be defined using other names, but still corresponds to the description of the inactive state of the present application. For example, there is a NAS connection, but the connection from the terminal to the base station and then to the core network is incomplete.
[0194] Optionally, in the embodiments of the present application, after the terminal enters the inactive state and before receiving the target radio signaling, the terminal does not send information to the access network system.
[0195] Optionally, in some embodiments, before the terminal receives the target radio signaling, the method further includes:
[0196] The terminal sends second algorithm information to the network side, and the second algorithm information is used to indicate at least one of the following: the algorithms supported by the terminal, the algorithms used by the terminal;
[0197] Wherein, the algorithms include at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
[0198] In the embodiments of the present application, the terminal sending the second algorithm information to the network side can be understood as the terminal sending a NAS message to a core network node, and the NAS message may include the above-mentioned second algorithm information. Further, when the access network node forwards the NAS message to the core network node, it may carry at least one of the algorithms supported by the access network node and the algorithms used by the access network node.
[0199] Optionally, after receiving the second algorithm information, the core network node may indicate the first algorithm information to the access network node.
[0200] Optionally, in some embodiments, the first identification information indicates a terminal, or is generated from the terminal identification, or indicates a group of terminals.
[0201] In the embodiments of the present application, in the case where the first identification information is generated from the terminal identification, different terminal identifications may generate the same first identification information. For example, the terminal identifications of a group of terminals may generate the same first identification information.
[0202] Optionally, in some embodiments, the target radio signaling includes any one of broadcast signaling, paging signaling, wireless short message, and system message;
[0203] Alternatively, the target radio signaling is sent through at least one of a paging channel (PCH), a multicast channel (MCH), a broadcast channel (BCH), and a downlink shared channel (DL-SCH);
[0204] Alternatively, the target radio signaling is sent through at least one of a physical downlink control channel (PDCCH), a physical downlink shared channel (PDSCH), a physical broadcast channel (PBCH), and a physical multicast channel (PMCH).
[0205] In the embodiments of the present application, the above-mentioned target radio signaling may be a paging message in a new format sent through the PCH (i.e., a paging message containing resource information), may be a signaling sent in the PCH, the target radio signaling includes a traditional paging message (i.e., a paging message not containing resource information), and resource information, may also be a traditional paging message sent in the PCH, and resource information is sent through the PDCCH, or may be a traditional paging message.
[0206] Optionally, the above-mentioned wireless short message may be understood as a short message (Short Message) involved in the radio signaling, rather than a short message involved in the Short Messaging / Message Service (SMS).
[0207] Optionally, in some embodiments, before the terminal performs the first operation, the terminal performs a random access process, a RACH process, or a PRACH process.
[0208] In the embodiments of the present application, the above-mentioned first operation may be performed after the random access process is completed, or may be performed during the execution of the random access process. The random access process may be a two-step random access process or a four-step random access process, which is not further limited herein.
[0209] To better understand the present application, the following will be described in detail through some examples.
[0210] Embodiment 1, when the terminal is in the idle state, the interaction process is as Figure 3 shown, specifically including the following steps:
[0211] Step 31, the terminal sends a NAS message to the core network. When the access network node forwards the NAS message to the core network node, it carries the algorithm indication information supported by the terminal (i.e., the second algorithm information), and may further carry the algorithm indication information supported by the access network node. The core network node optionally saves the algorithm indication information supported by the terminal, or the algorithm indication information supported by the terminal and the access network node.
[0212] Step 32, the core network node sends Information 1 to the access network node, for example, it may be sent through a Paging message or an incentive message.
[0213] Among them, Information 1 includes a first user identifier and security elements (including at least one of a secret key and a cipher stream), and the security elements may be generated based on at least one of a key, a first user identifier, and a first security parameter in the terminal core network context. Optionally, Information 1 may further include at least one of a first security parameter and an algorithm indication, and the algorithm indication is used to indicate the first algorithm information.
[0214] Optionally, at least some of the information other than the first user identifier in Information 1 may be associated with the first user identifier, so that other information associated with multiple first user identifiers can be carried. Of course, in other embodiments, at least some of the information other than the first user identifier in Information 1 may also be set to be associated with the first user identifier.
[0215] Step 33, the access network node broadcasts Information 2 through the air interface, for example, by sending it through a Paging message, a system message, or an incentive message, etc. Or Information 2 is sent in the first message sent to the terminal.
[0216] This Information 2 includes the first user identifier or the second user identifier and at least one of the following: an algorithm indication, a first security parameter, a second security parameter, and an indication information (for indicating at least one of performing data transmission and data reception).
[0217] Optionally, the second user identifier may be generated based on the first user identifier. For example, the first user identifier is a user identifier assigned by the core network node (such as TMSI), and the second user identifier is a user identifier assigned by the access network node (such as RNTI), or the first user identifier is a user identifier assigned by the access network node, and the second user identifier is a user identifier assigned by the core network node.
[0218] Optionally, the other information in the above Information 2 other than the user identifier (the first user identifier or the second user identifier) may be associated with the user identifier, so that other information associated with multiple user identifiers can be carried. Of course, in other embodiments, the other information in the above Information 2 other than the user identifier may be irrelevant to the user identifier.
[0219] It should be noted that, except for the user identifier, the other information in the above Information 2 is carried by the message carrying Information 2, and the other information may be carried in the message or in the signaling carrying the message (such as RLC layer signaling, MAC layer signaling). For example, the other information except the user identifier may be carried in the broadcast message, the signaling carrying the broadcast message, the first message sent by the access network node to the terminal, and / or the signaling carrying the first message respectively.
[0220] Step 34, the terminal performs a random access process to access the access network node.
[0221] Step 35, the terminal may generate new security elements based on the key in the terminal core network uplink text (such as using the corresponding key and the agreed parameters and / or the information sent by the received access network node), and the security elements include a key or a cipher stream. When sending a message to the access network node, perform at least one of the following:
[0222] Encrypt the message using a key or cipher stream (encrypt using the key and a predefined or indicated algorithm, or perform an exclusive OR operation based on the cipher stream). When the security requirements include a key, at least one of the received user identifier, the user identifier obtained based on the received user identifier (such as obtaining the TMSI from the received RNTI, or vice versa), the first security parameter, and the second security parameter may also be used to perform the above encryption operation (i.e., the relevant parameters are also used as input parameters during encryption);
[0223] When the security requirements include a key, perform an integrity protection operation on the message and / or the encrypted message (calculate the MAC value using the key and a predefined or indicated algorithm). The integrity protection operation may also be performed using at least one of the received user identifier, the user identifier obtained based on the received user identifier, the first security parameter 1, and the second security parameter (i.e., the relevant parameters are also used as input during the calculation of the MAC value).
[0224] The access network node may generate new security requirements based on the security requirements received from the core network node (such as using the corresponding key and predefined parameters and / or information sent by the access network node to the terminal). When the access network node receives a message sent by the terminal, it may correspondingly generate new security requirements based on the security requirements received from the core network node corresponding to the identification information of the message. When receiving a message sent by the terminal, perform at least one of the following:
[0225] Decrypt the signaling or some signaling cells in the signaling based on the key or cipher stream in the security requirements or the new security requirements;
[0226] Perform integrity protection verification on the entire signaling (the entire encrypted signaling), the decrypted (plaintext) signaling, some signaling cells in the signaling (encrypted signaling cells), and / or some decrypted signaling cells in the signaling (plaintext signaling cells) based on the key pair in the security requirements or the new security requirements (calculate the target MAC value using the key and a predefined or indicated algorithm and compare the received MAC value).
[0227] Optionally, the above integrity protection verification and / or decryption operation may also be performed using at least one of the sent user identifier, the user identifier obtained based on the sent user identifier, the first security parameter, the second security parameter, and the third security parameter (i.e., the corresponding parameters are also used as input during the calculation of the target MAC value and / or during the decryption process).
[0228] At this point, the security activation between the terminal and the access network node is completed, and subsequent message and data interactions can be protected.
[0229] It should be noted that after step 33, the core network node may send a new user identifier to the terminal through the access network node for use in the next execution of step 33 and subsequent operations, so as to update the security parameters.
[0230] Referring to Figure 4 , an embodiment of the present application further provides a secure communication method, as Figure 4 shown, the method includes:
[0231] Step 401, the access network node sends a target radio signaling, the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters, and the first algorithm information includes at least one of the following: security requirement derivation algorithm, confidentiality algorithm, and integrity algorithm.
[0232] Optionally, before the access network node sends the target radio signaling, the method further includes:
[0233] The access network node receives third information or target data from the core network node;
[0234] Wherein, the third information includes second identification information and second target information; the second target information includes at least one of the following:
[0235] First security requirement or second security requirement;
[0236] The first algorithm information;
[0237] Second indication information;
[0238] The second security parameter;
[0239] Second security assistance information;
[0240] Wherein, the first security requirement includes at least one of a secret key and a cipher stream, the second security requirement includes at least one of a secret key and a cipher stream, the second security assistance information includes information in the terminal core network context, the second indication information is used to generate the first indication information, and the second identification information is used to indicate the terminal or is related to the first identification information.
[0241] Optionally, the third information includes at least one of the following:
[0242] At least one second identification information and at least one second target information;
[0243] At least one pair of second identification information and second target information;
[0244] Wherein, the second target information and the second identification information are in a one-to-one or many-to-one mapping;
[0245] Alternatively, the second identification information and the second target information are in a one-to-zero or one mapping;
[0246] Alternatively, there is a corresponding relationship between K pieces of second identification information and all second target information, and K is less than or equal to the number of second identification information.
[0247] Optionally, the method further includes:
[0248] The access network node performs a second operation, and the second operation includes at least one of the following:
[0249] Generating a first security requirement based on at least one of the second derived information and the security requirement derivation algorithm;
[0250] Receiving first information from the terminal;
[0251] Receiving first information carrying a third security parameter from the terminal;
[0252] Sending second information to the terminal;
[0253] Wherein, the second derived information includes at least one of the following: an access network-related key, an AS layer-related key, a key in the terminal context, a second security requirement, information in the terminal access network context, at least part of the first security assistance information, the first identification information, at least part of the second security assistance information, and the third security parameter;
[0254] Wherein, the first information or part of the first information is securely processed based on the first security requirement, and / or, the second information or part of the second information is securely protected based on the first security requirement.
[0255] Optionally, the method includes at least one of the following:
[0256] The access network node further securely processes the first information or part of the first information based on a first calculation parameter;
[0257] The access network node further securely protects the second information or part of the second information based on a first calculation parameter;
[0258] Wherein, the first calculation parameter includes at least one of the following:
[0259] Information in the terminal access network context;
[0260] The first identification information;
[0261] At least part of the content in the first security assistance information;
[0262] At least part of the content in the second security assistance information;
[0263] The first indication information;
[0264] The first algorithm information;
[0265] The third security parameter.
[0266] Optionally, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
[0267] Optionally, the target radio signaling includes at least one of the following:
[0268] At least one first identification information and at least one first target information;
[0269] At least one pair of first identification information and first target information;
[0270] Wherein, the first target information and the first identification information are in a one-to-one or many-to-one mapping;
[0271] Or, the first identification information and the first target information are in a one-to-zero or one mapping;
[0272] Or, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the number of first identification information.
[0273] Optionally, the target radio signaling is any one of broadcast signaling, paging signaling, wireless short message, and system message;
[0274] Or, the target radio signaling is sent through at least one of PCH, MCH, BCH, and DL-SCH;
[0275] Or, the target radio signaling is sent through at least one of PDCCH, PDSCH, PBCH, and PMCH.
[0276] Optionally, the first identification information indicates a terminal, or is generated by the terminal identification, or indicates a group of terminals.
[0277] Optionally, after the access network node sends the target radio signaling, the access network node and the terminal perform a random access procedure, a RACH procedure, or a PRACH procedure.
[0278] Referring to Figure 5 , the embodiment of the present application also provides a secure communication method, as Figure 5 shown, the method includes:
[0279] Step 501, the access network node sends a target radio signaling, where the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0280] Step 502, the terminal receives the target radio signaling;
[0281] Step 503, when the first identification information is related to the terminal, the terminal generates a first security requirement based on at least one of first derived information and the security requirement derivation algorithm;
[0282] Step 504, the terminal performs a first operation based on the first security requirement;
[0283] Among them, the first operation includes at least one of the following:
[0284] Sending first information to the access network node;
[0285] Sending first information carrying third security parameters to the access network node;
[0286] Receiving second information from the access network node;
[0287] Among them, the first information or part of the content in the first information is protected by security based on the first security requirement, and / or, the second information or part of the content in the second information is processed by security based on the first security requirement;
[0288] The first derived information includes at least one of the following: a core network related key, a non-access stratum NAS layer related key, an access network related key, an access stratum AS layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter;
[0289] The first security requirement includes at least one of a key and a cipher stream.
[0290] Optionally, before the access network node sends the target radio signaling, the method further includes:
[0291] The core network node sends third information or target data to the access network node, and the third information includes second identification information and second target information;
[0292] The access network node obtains or generates the first security requirement based on the second target information, and sends the target radio signaling based on the third information;
[0293] Wherein, the second target information includes at least one of the following: the first security requirement or the second security requirement, the first algorithm information, the second security parameter, and the second security auxiliary information; the first algorithm information includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0294] Wherein, the second security auxiliary information includes information in the terminal core network context, the second security requirement includes at least one of a secret key and a cipher stream, the second identification information indicates a terminal, or is generated from the terminal identification, or indicates a group of terminals, or is related to the first identification information.
[0295] Optionally, the access network node generating the first security requirement based on the second target information includes:
[0296] The access network node generates the first security requirement based on at least one of the second derived information and the security requirement derivation algorithm;
[0297] Wherein, the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in the terminal context, at least part of the first security auxiliary information, at least part of the second security auxiliary information, the first identification information, the first algorithm information, information in the terminal access network context, and the third security parameter.
[0298] Optionally, the method further includes:
[0299] The core network node generates the first security requirement or the second security requirement based on at least one of the third derived information and the security requirement derivation algorithm;
[0300] Wherein, the third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in the terminal context, the second security parameter, and at least part of the second security auxiliary information.
[0301] In the embodiments of the present application, the above terminal may also execute each step of the terminal in the above Figure 2 embodiment, and the above access network node may also execute each step of the access network node in the above Figure 4 embodiment. For details, reference may be made to the description of the above embodiment. To avoid repetition, it will not be elaborated here.
[0302] The security communication method provided by the embodiments of this application may be executed by a security communication device or a security communication system. In the embodiments of this application, taking the method of a security communication device executing the security communication method as an example, the security communication device and the security communication system provided by the embodiments of this application are described.
[0303] Referring to Figure 6 , the embodiments of this application also provide a security communication device. As Figure 6 shown, the security communication device 600 includes:
[0304] A first receiving module 601, configured to receive a target radio signaling, where the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters; the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0305] A requirement generation module 602, configured to, when the first identification information is related to the terminal, the terminal generates a first security requirement based on at least one of first derivation information and the security requirement derivation algorithm;
[0306] A first execution module 603, configured to perform a first operation based on the first security requirement;
[0307] Wherein, the first operation includes at least one of the following:
[0308] Sending first information to an access network node;
[0309] Sending first information carrying third security parameters to an access network node;
[0310] Receiving second information from an access network node;
[0311] Wherein, the first information or part of the content in the first information is protected by security based on the first security requirement, and / or, the second information or part of the content in the second information is processed by security based on the first security requirement;
[0312] The first derivation information includes at least one of the following: a core network related key, a non-access stratum NAS layer related key, an access network related key, an access stratum AS layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter;
[0313] The first security requirement includes at least one of a key and a cipher stream.
[0314] Optionally, the first execution module 603 is further configured to perform at least one of the following:
[0315] Also perform security protection on the first information or a part of the first information based on the first calculation parameter;
[0316] Also perform security processing on the second information or a part of the second information based on the first calculation parameter;
[0317] Wherein, the first calculation parameter includes at least one of the following:
[0318] Information in the terminal core network context;
[0319] Information in the terminal access network context;
[0320] The first identification information;
[0321] At least part of the first security auxiliary information;
[0322] The third security parameter.
[0323] Optionally, the information in the terminal core network context includes at least one of the following:
[0324] The identification information of the terminal;
[0325] The group identification information of the terminal;
[0326] The counting information of non-access stratum (NAS) signaling;
[0327] The counting information of NAS uplink signaling;
[0328] The counting information of NAS downlink signaling;
[0329] The counting information of protocol data packets transmitted through NAS;
[0330] The counting information of uplink protocol data packets transmitted through NAS;
[0331] The counting information of downlink protocol data packets transmitted through NAS;
[0332] Or, the information in the terminal access network context includes at least one of the following:
[0333] The identification information of the terminal;
[0334] The group identification information of the terminal;
[0335] The counting information of access stratum (AS) signaling;
[0336] Counting information of the access stratum AS uplink signaling;
[0337] Counting information of the access stratum AS downlink signaling;
[0338] Counting information of protocol data packets;
[0339] Counting information of uplink protocol data packets;
[0340] Counting information of downlink protocol data packets.
[0341] Optionally, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
[0342] Optionally, the target radio signaling includes at least one of the following:
[0343] At least one first identification information and at least one first target information;
[0344] At least one pair of first identification information and first target information;
[0345] Wherein, the first target information and the first identification information are in a one-to-one or many-to-one mapping;
[0346] Or, the first identification information and the first target information are in a one-to-zero or one mapping;
[0347] Or, there is a corresponding relationship between N first identification information and all first target information, and N is less than or equal to the number of the first identification information included in the target radio signaling.
[0348] Optionally, the terminal is in an idle state or a non-active state, or is in an idle state or a non-active state before sending the first information, or is in an idle state or a non-active state before receiving the second information.
[0349] Optionally, the security communication device 600 further includes:
[0350] A second sending module, configured to send second algorithm information to the network side, where the second algorithm information is used to indicate at least one of the following: the algorithms supported by the terminal, the algorithms used by the terminal;
[0351] Wherein, the algorithms include at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
[0352] Optionally, the first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.
[0353] Optionally, the target radio signaling is any one of a broadcast signaling, a paging signaling, a wireless short message, and a system message;
[0354] Alternatively, the target radio signaling is sent through at least one of PCH, MCH, BCH, and DL-SCH;
[0355] Alternatively, the target radio signaling is sent through at least one of PDCCH, PDSCH, PBCH, and PMCH.
[0356] Optionally, the first execution module 603 is further configured to perform a random access procedure, a RACH procedure, or a PRACH procedure before performing the first operation.
[0357] Referring to Figure 7 , an embodiment of the present application further provides a secure communication device, as Figure 7 shown, the secure communication device 700 includes:
[0358] A first sending module 701, configured to send target radio signaling, where the target radio signaling includes first identification information and first target information; the first target information includes first security auxiliary information, and the first security auxiliary information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
[0359] Optionally, the secure communication device 700 further includes:
[0360] A second receiving module, configured to receive third information or target data from a core network node;
[0361] Wherein, the third information includes second identification information and second target information; the second target information includes at least one of the following:
[0362] A first security requirement or a second security requirement;
[0363] The first algorithm information;
[0364] Second indication information;
[0365] The second security parameter;
[0366] Second security auxiliary information;
[0367] Wherein, the first security requirement includes at least one of a secret key and a cipher stream, the second security requirement includes at least one of a secret key and a cipher stream, the second security auxiliary information includes information in the terminal core network context, the second indication information is used to generate the first indication information, the second identification information is used to indicate the terminal, or is related to the first identification information.
[0368] Optionally, the third information includes at least one of the following:
[0369] At least one second identification information and at least one second target information;
[0370] At least one pair of second identification information and second target information;
[0371] Wherein, the second target information and the second identification information are in a one-to-one or many-to-one mapping;
[0372] Alternatively, the second identification information and the second target information are in a one-to-zero or one mapping;
[0373] Alternatively, there is a correspondence between K second identification information and all second target information, and K is less than or equal to the number of second identification information.
[0374] Optionally, the secure communication device 700 further includes:
[0375] A second execution module, configured to execute a second operation, where the second operation includes at least one of the following:
[0376] Generate a first security requirement based on at least one of the second derived information and the security requirement derivation algorithm;
[0377] Receive first information from the terminal;
[0378] Receive first information carrying a third security parameter from the terminal;
[0379] Send second information to the terminal;
[0380] Wherein, the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in the terminal context, a second security requirement, information in the terminal access network context, at least part of the first security assistance information, the first identification information, at least part of the second security assistance information, and the third security parameter;
[0381] Wherein, the first information or part of the first information is subjected to security processing based on the first security requirement, and / or, the second information or part of the second information is subjected to security protection based on the first security requirement.
[0382] Optionally, the second execution module is further configured to execute at least one of the following:
[0383] Further perform security processing on the first information or part of the first information based on a first calculation parameter;
[0384] Further perform security protection on the second information or part of the second information based on a first calculation parameter;
[0385] Wherein, the first calculation parameter includes at least one of the following:
[0386] Information in the context of the terminal accessing the network;
[0387] The first identification information;
[0388] At least part of the content in the first security assistance information;
[0389] At least part of the content in the second security assistance information;
[0390] The first indication information;
[0391] The first algorithm information;
[0392] The third security parameter.
[0393] Optionally, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
[0394] Optionally, the target radio signaling includes at least one of the following:
[0395] At least one first identification information and at least one first target information;
[0396] At least one pair of first identification information and first target information;
[0397] Wherein, the first target information and the first identification information are in a one-to-one or many-to-one mapping;
[0398] Or, the first identification information and the first target information are in a one-to-zero or one mapping;
[0399] Or, there is a corresponding relationship between N first identification information and all first target information, and N is less than or equal to the number of first identification information.
[0400] Optionally, the target radio signaling is any one of broadcast signaling, paging signaling, wireless short message, and system message;
[0401] Or, the target radio signaling is sent through at least one of PCH, MCH, BCH, and DL-SCH;
[0402] Or, the target radio signaling is sent through at least one of PDCCH, PDSCH, PBCH, and PMCH.
[0403] Optionally, the first identification information indicates a terminal, or is generated by the terminal identification, or indicates a group of terminals.
[0404] Optionally, after the access network node sends the target radio signaling, the access network node and the terminal perform a random access procedure, a RACH procedure, or a PRACH procedure.
[0405] The secure communication device in the embodiments of the present application may be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal or other devices other than the terminal. Exemplarily, the terminal may include, but is not limited to, the types of the above-listed terminal 11, and other devices may be a server, a Network Attached Storage (NAS), etc., which are not specifically limited in the embodiments of the present application.
[0406] The secure communication device provided in the embodiments of the present application can implement Figures 2 to 4 the various processes implemented by the method embodiments and achieve the same technical effects. To avoid repetition, they will not be elaborated here.
[0407] The embodiments of the present application further provide a secure communication system, which includes: an access network node and a terminal, where
[0408] the access network node is configured to send target radio signaling, and the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0409] the terminal is configured to receive the target radio signaling; when the first identification information is related to the terminal, generate a first security requirement based on at least one of the first derivation information and the security requirement derivation algorithm; and perform a first operation based on the first security requirement;
[0410] where the first operation includes at least one of the following:
[0411] send first information to the access network node;
[0412] send first information carrying third security parameters to the access network node;
[0413] receive second information from the access network node;
[0414] where the first information or part of the content in the first information is protected by security based on the first security requirement, and / or the second information or part of the content in the second information is processed by security based on the first security requirement;
[0415] The first derived information includes at least one of the following: a core network related key, a non-access stratum (NAS) layer related key, an access network related key, an access stratum (AS) layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter;
[0416] The first security requirement includes at least one of a key and a cipher stream.
[0417] Optionally, the secure communication system further includes a core network node, wherein,
[0418] The core network node is configured to send third information or target data to the access network node, and the third information includes second identification information and second target information;
[0419] The access network node is further configured to obtain or generate the first security requirement based on the second target information, and send the target radio signaling based on the third information;
[0420] Wherein, the second target information includes at least one of the following: the first security requirement or the second security requirement, first algorithm information, a second security parameter, and second security assistance information; the first algorithm information includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0421] Wherein, the second security assistance information includes information in the terminal core network context, the second security requirement includes at least one of a secret key and a cipher stream, the second identification information indicates a terminal, or is generated from the terminal identification, or indicates a group of terminals, or is related to the first identification information.
[0422] Optionally, the access network node is specifically configured to generate the first security requirement based on at least one of second derived information and the security requirement derivation algorithm;
[0423] Wherein, the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in the terminal context, at least part of the content in the first security assistance information, at least part of the content in the second security assistance information, the first identification information, the first algorithm information, information in the terminal access network context, and the third security parameter.
[0424] Optionally, the core network node is further configured to generate the first security requirement or the second security requirement based on at least one of third derived information and the security requirement derivation algorithm;
[0425] Wherein, the third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in the terminal context, at least part of the second security parameter, and the second security assistance information.
[0426] As Figure 8 shown, an embodiment of the present application further provides a communication device 800, including a processor 801 and a memory 802. A program or instruction that can run on the processor 801 is stored on the memory 802. When the program or instruction is executed by the processor 801, each step of the above-mentioned security communication method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be elaborated here.
[0427] An embodiment of the present application further provides a terminal, including a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps in the method embodiment as Figure 2 shown. This terminal embodiment corresponds to the above-mentioned terminal-side method embodiment. Each implementation process and implementation manner of the above method embodiment can be applied to this terminal embodiment, and the same technical effect can be achieved. Specifically, Figure 9 is a schematic hardware structure diagram of a terminal for implementing an embodiment of the present application.
[0428] The terminal 900 includes, but is not limited to, at least some components such as a radio frequency unit 901, a network module 902, an audio output unit 903, an input unit 904, a sensor 905, a display unit 906, a user input unit 907, an interface unit 908, a memory 909, and a processor 910.
[0429] Those skilled in the art can understand that the terminal 900 may further include a power source (such as a battery) for supplying power to each component. The power source can be logically connected to the processor 910 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. Figure 9 The terminal structure shown in
[0430] It should be understood that in the embodiments of the present application, the input unit 904 may include a Graphics Processing Unit (GPU) 9041 and a microphone 9042. The graphics processor 9041 processes the image data of static pictures or videos obtained by an image capturing device (such as a camera) in a video capturing mode or an image capturing mode. The display unit 906 may include a display panel 9061, and the display panel 9061 may be configured in the form of, for example, a liquid crystal display, an organic light emitting diode, etc. The user input unit 907 includes at least one of a touch panel 9071 and other input devices 9072. The touch panel 9071 is also referred to as a touch screen. The touch panel 9071 may include two parts: a touch detection device and a touch controller. The other input devices 9072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated here.
[0431] In the embodiments of the present application, after receiving downlink data from a network side device, the radio frequency unit 901 may transmit it to the processor 910 for processing; in addition, the radio frequency unit 901 may send uplink data to the network side device. Generally, the radio frequency unit 901 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.
[0432] The memory 909 can be used to store software programs or instructions as well as various data. The memory 909 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area may store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 909 may include volatile memory or non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 909 in the embodiments of the present application includes but is not limited to these and any other suitable types of memory.
[0433] The processor 910 may include one or more processing units; optionally, the processor 910 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above modem processor may not be integrated into the processor 910 either.
[0434] Among them, the radio frequency unit 901 is used to receive a target wireless signaling, and the target wireless signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters. The first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm;
[0435] The processor 910 is configured to generate a first security requirement based on at least one of the first derived information and the security requirement derivation algorithm when the first identification information is related to the terminal;
[0436] The radio frequency unit 901 is further configured to perform a first operation based on the first security requirement;
[0437] Wherein, the first operation includes at least one of the following:
[0438] Sending first information to an access network node;
[0439] Sending the first information carrying a third security parameter to an access network node;
[0440] Receiving second information from an access network node;
[0441] Wherein, the first information or part of the content in the first information is protected by security based on the first security requirement, and / or, the second information or part of the content in the second information is processed by security based on the first security requirement;
[0442] The first derived information includes at least one of the following: a core network related key, a non-access stratum NAS layer related key, an access network related key, an access stratum AS layer related key, a key in the terminal context, at least part of the content in the first security auxiliary information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter;
[0443] The first security requirement includes at least one of a key and a cipher stream.
[0444] It can be understood that the implementation processes of the implementation manners mentioned in this embodiment can refer to the relevant descriptions of the method embodiment on the terminal side, and achieve the same or corresponding technical effects. To avoid repetition, they will not be elaborated here.
[0445] This application embodiment further provides a network-side device, including a processor and a communication interface, the communication interface is coupled to the processor, and the processor is configured to run a program or an instruction to implement the steps of the method embodiment as Figure 4 shown. This network-side device embodiment corresponds to the above network-side device method embodiment. Each implementation process and implementation manner of the above method embodiment can be applied to this network-side device embodiment, and the same technical effects can be achieved.
[0446] Specifically, this application embodiment further provides a network-side device. As Figure 10As shown in the figure, the network-side device 1000 includes: an antenna 1001, a radio frequency device 1002, a baseband device 1003, a processor 1004, and a memory 1005. The antenna 1001 is connected to the radio frequency device 1002. In the uplink direction, the radio frequency device 1002 receives information through the antenna 1001 and sends the received information to the baseband device 1003 for processing. In the downlink direction, the baseband device 1003 processes the information to be sent and sends it to the radio frequency device 1002. After processing the received information, the radio frequency device 1002 sends it out through the antenna 1001.
[0447] In the above embodiments, the method executed by the network-side device can be implemented in the baseband device 1003, and the baseband device 1003 includes a baseband processor.
[0448] The baseband device 1003 may include, for example, at least one baseband board, and a plurality of chips are arranged on the baseband board, such as Figure 10 As shown in the figure, one of the chips is, for example, a baseband processor, which is connected to the memory 1005 through a bus interface to call the program in the memory 1005 and execute the operations of the network-side device shown in the above method embodiments.
[0449] The network-side device may further include a network interface 1006, and the interface is, for example, a Common Public Radio Interface (CPRI).
[0450] Specifically, the network-side device 1000 in the embodiments of the present application further includes: instructions or programs stored on the memory 1005 and executable on the processor 1004. The processor 1004 calls the instructions or programs in the memory 1005 to execute Figure 7 the methods executed by the modules shown in the figure and achieve the same technical effects. To avoid repetition, they will not be elaborated here.
[0451] The embodiments of the present application further provide a readable storage medium. Programs or instructions are stored on the readable storage medium. When the programs or instructions are executed by a processor, each process of the above-mentioned security communication method embodiments is implemented, and the same technical effects can be achieved. To avoid repetition, they will not be elaborated here.
[0452] Wherein, the processor is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs, etc. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0453] Another embodiment of the present application further provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is configured to run programs or instructions to implement each process of the above-mentioned embodiment of the security communication method, and can achieve the same technical effects. To avoid repetition, details are not described herein again.
[0454] It should be understood that the chip mentioned in the embodiment of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip.
[0455] Another embodiment of the present application further provides a computer program / program product. The computer program / program product is stored in a storage medium. The computer program / program product is executed by at least one processor to implement each process of the above-mentioned embodiment of the security communication method, and can achieve the same technical effects. To avoid repetition, details are not described herein again.
[0456] The embodiment of the present application further provides a wireless communication system, including: a terminal and a network-side device. The terminal can be used to execute the steps of the security communication method on the terminal side as described above, and the network-side device can be used to execute the steps of the security communication method of the access network node as described above.
[0457] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0458] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general hardware platform, and of course, can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes several instructions for causing a terminal or a network-side device to execute the methods described in various embodiments of the present application.
[0459] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms of implementation manners without departing from the purpose of the present application and the scope protected by the claims. These implementation manners are all within the protection scope of the present application.
Claims
1. A secure communication method, characterized in that, it includes: The terminal receives a target radio signaling, and the target radio signaling includes first identification information and first target information; The first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters. The first algorithm information includes at least one of the following: security requirement derivation algorithm, confidentiality algorithm, and integrity algorithm; When the first identification information is related to the terminal, the terminal generates a first security requirement based on at least one of first derived information and the security requirement derivation algorithm; The terminal performs a first operation based on the first security requirement; Wherein, the first operation includes at least one of the following: Sending first information to an access network node; Sending first information carrying third security parameters to an access network node; Receiving second information from an access network node; Wherein, the first information or part of the content in the first information is protected by security based on the first security requirement, and / or, the second information or part of the content in the second information is processed by security based on the first security requirement; The first derived information includes at least one of the following: core network related key, non-access stratum NAS layer related key, access network related key, access stratum AS layer related key, key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter; The first security requirement includes at least one of a key and a cipher stream.
2. The method according to claim 1, characterized in that, The method includes at least one of the following: The terminal also protects the first information or part of the content in the first information by security based on first calculation parameters; The terminal also processes the second information or part of the content in the second information by security based on first calculation parameters; Wherein, the first calculation parameters include at least one of the following: Information in the terminal core network context; Information in the terminal access network context; The first identification information; At least part of the content in the first security assistance information; The third security parameter.
3. The method according to claim 1 or 2, characterized in that, The information in the terminal core network context includes at least one of the following: Identification information of the terminal; Group identification information of the terminal; Counting information of non-access stratum NAS signaling; Counting information of non-access stratum NAS uplink signaling; Counting information of non-access stratum NAS downlink signaling; Counting information of protocol data packets transmitted through NAS; Counting information of uplink protocol data packets transmitted through NAS; Counting information of downlink protocol data packets transmitted through NAS; Or, the information in the terminal access network context includes at least one of the following: Identification information of the terminal; Group identification information of the terminal; Counting information of access stratum AS signaling; Counting information of access stratum AS uplink signaling; Counting information of access stratum AS downlink signaling; Counting information of protocol data packets Counting information of uplink protocol data packets Counting information of downlink protocol data packets 4. The method according to any one of claims 1 to 3, characterized in that the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
5. The method according to any one of claims 1 to 4, characterized in that the target radio signaling includes at least one of the following: at least one first identification information and at least one first target information; at least one pair of first identification information and first target information; wherein, the first target information and the first identification information are in a one-to-one or many-to-one mapping; alternatively, the first identification information and the first target information are in a one-to-zero or one mapping; alternatively, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the number of the first identification information included in the target radio signaling.
6. The method according to any one of claims 1 to 5, characterized in that the terminal is in an idle state or a non-active state, or is in an idle state or a non-active state before sending the first information, or is in an idle state or a non-active state before receiving the second information.
7. The method according to any one of claims 1 to 6, characterized in that before the terminal receives the target radio signaling, the method further includes: the terminal sends second algorithm information to the network side, and the second algorithm information is used to indicate at least one of the following: the algorithms supported by the terminal, the algorithms used by the terminal; wherein, the algorithms include at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
8. The method according to any one of claims 1 to 7, characterized in that the first identification information indicates a terminal, or is generated from a terminal identifier, or indicates a group of terminals.
9. The method according to any one of claims 1 to 8, characterized in that the target radio signaling is any one of a broadcast signaling, a paging signaling, a wireless short message, and a system message; alternatively, the target radio signaling is sent through at least one of a PCH, an MCH, a BCH, and a DL-SCH; alternatively, the target radio signaling is sent through at least one of a PDCCH, a PDSCH, a PBCH, and a PMCH.
10. The method according to any one of claims 1 to 9, characterized in that before the terminal performs the first operation, the terminal performs a random access procedure, a RACH procedure, or a PRACH procedure.
11. A secure communication method, characterized in that comprises: an access network node sends target radio signaling, and the target radio signaling includes first identification information and first target information; the first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters, and the first algorithm information includes at least one of the following: a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
12. The method according to claim 11, It is characterized in that Before the access network node sends the target radio signaling, the method further includes: The access network node receives third information or target data from the core network node; Wherein, the third information includes second identification information and second target information; The second target information includes at least one of the following: The first security requirement or the second security requirement; The first algorithm information; The second indication information; The second security parameter; The second security auxiliary information; Wherein, the first security requirement includes at least one of a secret key and a cipher stream, the second security requirement includes at least one of a secret key and a cipher stream, the second security auxiliary information includes information in the terminal core network context, the second indication information is used to generate the first indication information, and the second identification information is used to indicate the terminal or is related to the first identification information.
13. According to the method described in claim 12, It is characterized in that The third information includes at least one of the following: At least one second identification information and at least one second target information; At least one pair of second identification information and second target information; Wherein, the second target information and the second identification information are in a one-to-one or many-to-one mapping; Or, the second identification information and the second target information are in a one-to-zero or one mapping; Or, there is a corresponding relationship between K second identification information and all second target information, and K is less than or equal to the number of second identification information.
14. According to the method described in claim 12 or 13, It is characterized in that The method further includes: The access network node performs a second operation, and the second operation includes at least one of the following: Derive the first security requirement based on at least one of the second derived information and the security requirement derivation algorithm; Receive first information from the terminal; Receive first information carrying a third security parameter from the terminal; Send second information to the terminal; Wherein, the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in the terminal context, a second security requirement, information in the terminal access network context, at least part of the first security auxiliary information, the first identification information, at least part of the second security auxiliary information, and the third security parameter; Wherein, the first information or part of the first information is security processed based on the first security requirement, and / or, the second information or part of the second information is security protected based on the first security requirement.
15. According to the method described in claim 14, It is characterized in that The method includes at least one of the following: The access network node further security processes the first information or part of the first information based on a first calculation parameter; The access network node further security protects the second information or part of the second information based on a first calculation parameter; Wherein, the first calculation parameter includes at least one of the following: Information in the terminal access network context; The first identification information; At least part of the first security auxiliary information; At least part of the second security auxiliary information; The first indication information; The first algorithm information; The third security parameter.
16. The method according to claim 14 or 15, wherein, the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
17. The method according to any one of claims 11 to 16, wherein, the target radio signaling includes at least one of the following: at least one first identification information and at least one first target information; at least one pair of first identification information and first target information; wherein, the first target information and the first identification information are in a one-to-one or many-to-one mapping; alternatively, the first identification information and the first target information are in a one-to-zero or one mapping; alternatively, there is a correspondence between N first identification information and all first target information, and N is less than or equal to the number of first identification information.
18. The method according to any one of claims 11 to 17, wherein, the target radio signaling is any one of broadcast signaling, paging signaling, wireless short message, and system message; alternatively, the target radio signaling is sent through at least one of PCH, MCH, BCH, and DL-SCH; alternatively, the target radio signaling is sent through at least one of PDCCH, PDSCH, PBCH, and PMCH.
19. The method according to any one of claims 11 to 18, wherein, the first identification information indicates a terminal, or is generated from a terminal identifier, or indicates a group of terminals.
20. The method according to any one of claims 11 to 19, wherein, after the access network node sends the target radio signaling, the access network node and the terminal perform a random access procedure, a RACH procedure, or a PRACH procedure.
21. A secure communication method, wherein, includes: The access network node sends target radio signaling, and the target radio signaling includes first identification information and first target information; The first target information includes first security auxiliary information, and the first security auxiliary information includes at least one of first indication information, first algorithm information, first security parameter, and second security parameter. The first algorithm information includes at least one of the following: security requirement derivation algorithm, confidentiality algorithm, and integrity algorithm; The terminal receives the target radio signaling; When the first identification information is related to the terminal, the terminal generates a first security requirement based on at least one of first derived information and the security requirement derivation algorithm; The terminal performs a first operation based on the first security requirement; wherein, the first operation includes at least one of the following: Sending a first message to the access network node; Sending a first message carrying a third security parameter to the access network node; Receiving a second message from the access network node; wherein, the first message or a part of the content in the first message is protected based on the first security requirement, and / or, the second message or a part of the content in the second message is processed based on the first security requirement; The first derived information includes at least one of the following: a core network related key, a non-access stratum (NAS) layer related key, an access network related key, an access stratum (AS) layer related key, a key in the terminal context, at least a part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameter; The first security requirement includes at least one of a key and a cipher stream.
22. The method according to claim 21, wherein, before the access network node sends the target radio signaling, the method further includes: a core network node sends third information or target data to the access network node, and the third information includes second identification information and second target information; the access network node obtains or generates the first security requirement based on the second target information, and sends the target radio signaling based on the third information; wherein, the second target information includes at least one of the following: the first security requirement or the second security requirement, first algorithm information, a second security parameter, and second security assistance information; the first algorithm information includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm; wherein, the second security assistance information includes information in the terminal core network context, the second security requirement includes at least one of a secret key and a cipher stream, the second identification information indicates a terminal, or is generated from a terminal identifier, or indicates a group of terminals, or is related to the first identification information.
23. The method according to claim 22, wherein, the access network node generating the first security requirement based on the second target information includes: the access network node generates the first security requirement based on at least one of second derived information and the security requirement derivation algorithm; wherein, the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in the terminal context, at least a part of the content in the first security assistance information, at least a part of the content in the second security assistance information, the first identification information, the first algorithm information, information in the terminal access network context, and the third security parameter.
24. The method according to claim 22, wherein, the method further includes: the core network node generates the first security requirement or the second security requirement based on at least one of third derived information and the security requirement derivation algorithm; wherein, the third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in the terminal context, the second security parameter, and at least a part of the content in the second security assistance information.
25. A secure communication device, applied to a terminal, wherein, it includes: a first receiving module, configured to receive a target radio signaling, where the target radio signaling includes first identification information and first target information; The first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters. The first algorithm information includes at least one of the following: security requirement derivation algorithm, confidentiality algorithm, and integrity algorithm; A requirement generation module, configured to, when the first identification information is related to a terminal, generate a first security requirement by the terminal based on at least one of the first derived information and the security requirement derivation algorithm; A first execution module, configured to perform a first operation based on the first security requirement; Wherein, the first operation includes at least one of the following: Sending first information to an access network node; Sending first information carrying third security parameters to an access network node; Receiving second information from an access network node; Wherein, the first information or part of the content in the first information is protected by security based on the first security requirement, and / or, the second information or part of the content in the second information is processed by security based on the first security requirement; The first derived information includes at least one of the following: a core network related key, a non-access stratum (NAS) layer related key, an access network related key, an access stratum (AS) layer related key, a key in the terminal context, at least part of the content in the first security assistance information, the first identification information, information in the terminal core network context, information in the terminal access network context, and the third security parameters; The first security requirement includes at least one of a key and a cipher stream.
26. The apparatus according to claim 25, characterized in that the first execution module is further configured to perform at least one of the following: Further protecting the first information or part of the content in the first information by security based on first calculation parameters; Further processing the second information or part of the content in the second information by security based on first calculation parameters; Wherein, the first calculation parameters include at least one of the following: Information in the terminal core network context; Information in the terminal access network context; The first identification information; At least part of the content in the first security assistance information; The third security parameters.
27. A secure communication apparatus, applied to an access network node, characterized in that it includes: A first sending module, configured to send target radio signaling, and the target radio signaling includes first identification information and first target information; The first target information includes first security assistance information, and the first security assistance information includes at least one of first indication information, first algorithm information, first security parameters, and second security parameters. The first algorithm information includes at least one of the following: security requirement derivation algorithm, confidentiality algorithm, and integrity algorithm.
28. The apparatus according to claim 27, characterized in that the secure communication apparatus further includes: A second receiving module, configured to receive third information or target data from a core network node; Wherein, the third information includes second identification information and second target information; the second target information includes at least one of the following: A first security requirement or a second security requirement; The first algorithm information; Second indication information; The second security parameter; Second security assistance information; Wherein, the first security requirement includes at least one of a secret key and a cipher stream, the second security requirement includes at least one of a secret key and a cipher stream, the second security assistance information includes information in the terminal core network context, the second indication information is used to generate the first indication information, the second identification information is used to indicate the terminal, or is related to the first identification information.
29. A terminal, Characterized in that, It includes a processor and a memory, the memory stores a program or instructions that can run on the processor, and when the program or instructions are executed by the processor, the steps of the security communication method according to any one of claims 1 to 10 are implemented.
30. A network-side device, Characterized in that, It includes a processor and a memory, the memory stores a program or instructions that can run on the processor, and when the program or instructions are executed by the processor, the steps of the security communication method according to any one of claims 11 to 24 are implemented.
31. A security communication system, Characterized in that, It includes: A network-side device and a terminal, wherein, The network-side device is configured to execute the steps of the security communication method according to any one of claims 11 to 24, and the terminal is configured to execute the steps of the security communication method according to any one of claims 1 to 10.
32. A readable storage medium, Characterized in that, The readable storage medium stores a program or instructions, and when the program or instructions are executed by a processor, the steps of the security communication method according to any one of claims 1 to 24 are implemented.