Trusted measurement method, device and system

CN120202465APending Publication Date: 2025-06-24HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101851.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Existing trusted credit methods lack uniformity in network virtualization security in the core network, especially the trusted credit services for terminal devices are not fully covered, and there is a one-to-one correspondence between verifiers and provers in traditional methods. This results in high complexity and high resource consumption.

Method used

By introducing the remote attestation service (RAS network element) to centrally provide measurement results, generate and verify measurement information, it reduces the direct interaction between verifiers and provers, improves efficiency and reduces resource consumption. RAS network elements generate challenge values ​​based on preset cycles or control messages and send them to multiple certifiers, reducing the need for each certifier to generate challenge values ​​and enhancing the credibility of measurement results through signatures.

Benefits of technology

It achieves centralized measurement of multiple provers, reduces complexity and resource consumption, improves the efficiency of trustworthy credit services for various network elements in the network, and enhances the robustness and credibility of measurement results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120202465A_ABST
    Figure CN120202465A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a trusted measurement method, device and system. The method comprises the steps that a remote attestation service (RAS) network element obtains a measurement result of a first remote attestation agent (RAA) network element; the RAS network element receives a first request from a second RAA network element, wherein the first request is used for requesting a measurement result of the first RAA network element; and the RAS network element sends the measurement result of the first RAA network element to the second RAA network element, by adopting the embodiment of the invention, a trusted measurement service can be provided, trusted measurement can be carried out, the resource consumption is low, and the complexity is low.
Need to check novelty before this filing date? Find Prior Art

Description

Trust measurement method, device and system Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a trust measurement method, device, and system. Background Art

[0002] Trusted measurement verifies that a device's hardware and software have not been tampered with by an attacker by checking their measurements. An endorser provides endorsement information, a reference value provider provides reference value information, an attester generates measurement information, and a verifier verifies the measurement information based on the endorsement information and reference value, generating a measurement result. The verifier can then send this measurement result to the relying party.

[0003] When this trusted measurement technology is applied to the core network, the security of core network functions (NFs) is a key consideration due to the necessity of network virtualization security. Because NFs can be deployed in the cloud, the security of the underlying physical devices and virtualization layer will affect NF security. Therefore, the security of the NF's underlying hardware and virtualization layer needs to be measured. However, currently, trusted measurement is limited to the NF and management layers, with no unified trusted measurement service for various network elements, particularly terminal devices.

[0004] Moreover, in this traditional trust measurement method, there is a one-to-one correspondence between the verifier and the prover, and each trust measurement occurs one-to-one. For example, if there are 10 provers and 10 verifiers, and they measure each other, 45 measurements are required, which is highly complex.

[0005] Summary of the Invention

[0006] The present application discloses a trust measurement method, device and system, which can provide trust measurement services and perform trust measurement with low complexity.

[0007] In a first aspect, an embodiment of the present application provides a trusted measurement method, which includes: a remote attestation service (RAS) network element obtains a measurement result of a first remote attestation agent (RAA) network element; the RAS network element receives a first request from a second RAA network element, and the first request is used to request the measurement result of the first RAA network element; the RAS network element sends the measurement result of the first RAA network element to the second RAA network element.

[0008] In the above method, the RAS network element obtains the measurement result of the first RAA network element, and accordingly, after receiving the first request from the second RAA network element, the measurement result is sent to the second RAA network element. The RAS network element can provide trusted measurement services and perform trusted measurement, that is, the RAS network element can provide measurement results in a centralized manner. Compared with the traditional one-to-one correspondence between the prover and the verifier, the verifier sends a challenge value to the prover, the prover generates measurement information based on the challenge value, and sends the measurement information to the verifier, the verifier verifies the measurement information and generates a measurement result. The traditional measurement method has high resource consumption and high complexity. The present application provides trusted measurement services through the RAS network element and centrally provides measurement results. When the second RAA network element needs to use the measurement result of the first RAA network element, it can obtain the measurement result from the RAS network element without initiating the measurement process again, reducing resource consumption and simplifying the implementation process.

[0009] In a possible implementation manner, the RAS network element obtains the measurement result of the first RAA network element, including: the RAS network element generates the measurement result of the first RAA network element.

[0010] In another possible implementation, the method also includes: the RAS network element generates a first challenge value based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; the RAS network element receives measurement information from the first RAA network element, and the measurement information is determined based on the first challenge value; the RAS network element verifies the measurement information.

[0011] In the above method, the RAS network element generates a first challenge value based on a preset period or a first control message. When the first RAA network element is a plurality of provers, the RAS network element can send the first challenge value to the plurality of provers, and the plurality of provers can generate corresponding multiple measurement information based on the first challenge value. Compared with the traditional measurement method, each of the plurality of provers needs to generate a second challenge value. The present application generates a first challenge value by the RAS network element and sends it to the plurality of provers, which can reduce resource consumption.

[0012] In another possible implementation manner, the first control message is sent by a management plane, or is a request message sent by the first RAA network element.

[0013] In yet another possible implementation, the method further includes: if the verification is successful, the RAS network element signing the measurement information and generating a measurement result of the first RAS network element.

[0014] In the above method, the RAS network element signs the measurement information and generates the measurement result, so that the RAS network element can endorse the trustworthy status of the first RAA network element, which is beneficial for nodes using the measurement result to verify the credibility.

[0015] In yet another possible implementation manner, the method further includes: the RAS network element sending the measurement result to the first RAA network element.

[0016] In another possible implementation, the RAS network element obtains the measurement result of the first RAA network element, including: the RAS network element receives the measurement result of the first RAA network element sent by a third RAA network element.

[0017] In the above method, the measurement result of the first RAA network element is received from the third RAA network element by the RAS network element, and the measurement result is verified, so that the measurement result can be more robust and the credibility of the measurement result is enhanced.

[0018] In another possible implementation manner, the RAS network element obtains the measurement result of the first RAA network element, including: the RAS network element receives the measurement result of the first RAA network element sent from a public verifier PVE.

[0019] In the above method, the RAS network element receives the measurement results from the PVE and verifies the measurement results, which can make the measurement results more robust and enhance the credibility of the measurement results. It can enable the PVE to endorse the trustworthy status of the network node, which is beneficial for other nodes to verify the credibility.

[0020] In yet another possible implementation manner, the first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0021] In another possible implementation, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness proof information. The freshness proof information may indicate that the measurement result of the first RAA is time-sensitive. In this way, obtaining expired measurement results that affect the accuracy of the measurement results can be avoided.

[0022] In another possible implementation, the method further includes: the RAS network element obtaining endorsement information and reference value information from a first remote attestation infrastructure RAI network element, wherein the endorsement information and the reference value information are used to verify the measurement information or the measurement result.

[0023] In yet another possible implementation, the method further includes: the RAS network element receiving registered remote attestation capability information from the first RAA network element.

[0024] In the above method, in this way, the RAS network element can have the trustworthy capability of managing network devices.

[0025] In another possible implementation, the method further includes: the RAS network element sending the measurement result to a second RAI network element. The second RAI network element may be a network element with storage functionality, such as a storage system or a database. In this manner, if other network elements in the network need to use the measurement result of the first RAS network element, they can obtain the measurement result from the second RAI network element, eliminating the need to initiate the measurement process again and reducing resource consumption.

[0026] In the second aspect, an embodiment of the present application provides a trusted measurement method, which includes: a first remote attestation agent RAA network element receives a first challenge value, the first challenge value is generated based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; the first RAA network element generates measurement information based on the first challenge value; the first RAA network element sends the measurement information to a remote attestation service RAS network element.

[0027] In the above method, the first RAA network element can be at least one prover. When the first RAA network element is multiple provers, the RAS network element can send the first challenge value to the multiple provers, and the multiple provers can generate corresponding multiple measurement information based on the first challenge value. Compared with the traditional measurement method, each of the multiple provers needs to generate a second challenge value. This application generates the first challenge value by the RAS network element and sends it to the multiple provers, which can reduce resource consumption.

[0028] In a possible implementation manner, the first control message is sent by a management plane, or is a request message sent by the first RAA network element.

[0029] In yet another possible implementation, the method further includes: the first RAA network element receiving the measurement result from the RAS.

[0030] In a third aspect, an embodiment of the present application provides a trusted measurement method, which includes: a second remote attestation agent RAA network element sends a first request to a remote attestation service RAS network element, wherein the first request is used to request the measurement result of the first RAA network element; the second RAA network element receives the measurement result of the first RAA network element from the RAS network element.

[0031] In the above method, a first request is sent to the RAS network element through the second RAA network element. Accordingly, the second RAA network element receives the measurement result of the first RAA network element from the RAS network element, so that the RAS network element can provide trusted measurement services and perform trusted measurement. When the second RAA network element needs to use the measurement result of the first RAA network element, it can obtain the measurement result from the network element that stores the measurement result, thereby eliminating the need to initiate the measurement process again and reducing resource consumption.

[0032] In a possible implementation manner, the first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0033] In another possible implementation, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness proof information. The freshness proof information may indicate that the measurement result of the first RAA is time-sensitive. In this way, obtaining expired measurement results that affect the accuracy of the measurement results can be avoided.

[0034] In a fourth aspect, an embodiment of the present application provides a trusted measurement method, which includes: a third remote attestation agent RAA network element determines the measurement result of a first RAA network element; the third RAA network element sends the measurement result of the first RAA network element to a remote attestation service RAS network element.

[0035] In the above method, the RAS network element can provide a trustworthy measurement service and perform trustworthy measurement through the above manner.

[0036] In a possible implementation, the method further includes: the third RAA network element generating a second challenge value; the third RAA network element receiving measurement information from the first RAA network element, where the measurement information is determined based on the second challenge value; and the third RAA network element verifying the measurement information.

[0037] In a fifth aspect, an embodiment of the present application provides a trusted measurement method, which includes: a public verifier PVE determines a measurement result of a first remote attestation agent RAA network element; and the PVE sends the measurement result of the first RAA network element to a remote attestation service RAS network element.

[0038] In the above method, the RAS network element can provide a trustworthy measurement service and perform trustworthy measurement through the above manner.

[0039] In a sixth aspect, an embodiment of the present application provides a trusted measurement device, comprising: a processing unit and a communication unit, the processing unit being used to obtain the measurement results of a first remote attestation agent RAA network element; the communication unit being used to receive a first request from a second RAA network element, the first request being used to request the measurement results of the first RAA network element; and the communication unit being used to send the measurement results of the first RAA network element to the second RAA network element.

[0040] In a possible implementation manner, the processing unit is configured to generate a measurement result of the first RAA network element.

[0041] In another possible implementation, the processing unit is further used to generate a first challenge value based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; the communication unit is further used to receive measurement information from the first RAA network element, and the measurement information is determined based on the first challenge value; the processing unit is further used to verify the measurement information.

[0042] In another possible implementation manner, the first control message is sent by a management plane, or is a request message sent by the first RAA network element.

[0043] In yet another possible implementation, the processing unit is configured to, if the verification is successful, sign the measurement information and generate a measurement result of the first RAA network element.

[0044] In yet another possible implementation, the communication unit is further configured to send the measurement result to the first RAA network element.

[0045] In yet another possible implementation, the communication unit is further configured to receive a measurement result of the first RAA network element sent from a third RAA network element.

[0046] In yet another possible implementation, the communication unit is further configured to receive a measurement result of the first RAA network element sent from a public verifier PVE.

[0047] In yet another possible implementation manner, the first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0048] In another possible implementation, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness certification information.

[0049] In another possible implementation, the processing unit is further used to obtain endorsement information and reference value information from a first remote attestation infrastructure RAI network element, and the endorsement information and the reference value information are used to verify the measurement information or the measurement result.

[0050] In yet another possible implementation, the communication unit is further configured to receive registered remote attestation capability information from the first RAA network element.

[0051] In yet another possible implementation manner, the communication unit is further configured to send the measurement result to the second RAI network element.

[0052] Regarding the technical effects brought about by the sixth aspect or possible implementation methods, reference may be made to the introduction to the technical effects of the second aspect or corresponding implementation methods.

[0053] In the seventh aspect, an embodiment of the present application provides a trusted measurement device, which includes: a processing unit and a communication unit, the communication unit is used to receive a first challenge value, the first challenge value is generated based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; the processing unit is used to generate measurement information based on the first challenge value; the communication unit is used to send the measurement information to a remote attestation service RAS network element.

[0054] In a possible implementation manner, the first control message is sent by a management plane, or is a request message sent by the first RAA network element.

[0055] In yet another possible implementation, the communication unit is further configured to receive the measurement result from the RAS.

[0056] Regarding the technical effects brought about by the seventh aspect or possible implementation methods, reference may be made to the introduction to the technical effects of the second aspect or corresponding implementation methods.

[0057] In an eighth aspect, an embodiment of the present application provides a trusted measurement device, comprising: a processing unit and a communication unit, the communication unit being used to send a first request to a remote attestation service RAS network element, the first request being used to request the measurement result of the first RAA network element; the communication unit being used to receive the measurement result of the first RAA network element from the RAS network element.

[0058] In a possible implementation manner, the first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0059] In another possible implementation, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness certification information.

[0060] Regarding the technical effects brought about by the eighth aspect or possible implementation methods, please refer to the introduction to the technical effects of the second aspect or corresponding implementation methods.

[0061] In the ninth aspect, an embodiment of the present application provides a trusted measurement device, which includes: a processing unit and a communication unit, the processing unit is used to determine the measurement result of the first RAA network element; the communication unit is used to send the measurement result of the first RAA network element to the remote attestation service RAS network element.

[0062] In one possible implementation, the processing unit is further used to generate a second challenge value; the communication unit is further used to receive measurement information from the first RAA network element, where the measurement information is determined based on the second challenge value; and the processing unit is further used to verify the measurement information.

[0063] Regarding the technical effects brought about by the ninth aspect or possible implementation methods, please refer to the introduction to the technical effects of the second aspect or corresponding implementation methods.

[0064] In the tenth aspect, an embodiment of the present application provides a trusted measurement device, which includes: a processing unit and a communication unit, the processing unit is used to determine the measurement results of a first remote attestation agent RAA network element; the communication unit is used to send the measurement results of the first RAA network element to a remote attestation service RAS network element.

[0065] Regarding the technical effects brought about by the tenth aspect or possible implementation methods, please refer to the introduction to the technical effects of the second aspect or corresponding implementation methods.

[0066] In an eleventh aspect, an embodiment of the present application provides a trust measurement device, comprising at least one processor and a communication interface, wherein the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the first aspect or in a manner that is possible to implement the first aspect.

[0067] In a twelfth aspect, an embodiment of the present application provides a trust measurement device, comprising at least one processor and a communication interface, wherein the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the second aspect or in a possible implementation manner of the second aspect.

[0068] In a thirteenth aspect, an embodiment of the present application provides a trust measurement device, comprising at least one processor and a communication interface, wherein the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the third aspect or in a possible implementation manner of the third aspect.

[0069] In a fourteenth aspect, an embodiment of the present application provides a trust measurement device, comprising at least one processor and a communication interface, wherein the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the fourth aspect or in a possible implementation manner of the fourth aspect.

[0070] In a fifteenth aspect, an embodiment of the present application provides a trust measurement device, comprising at least one processor and a communication interface, wherein the at least one processor is used to call a computer program stored in at least one memory so that the device implements the method described in the fifth aspect or in a possible implementation manner in the fifth aspect.

[0071] Optionally, in any of the above aspects 11 to 15, the processor can be integrated with the memory.

[0072] In a sixteenth aspect, an embodiment of the present application provides a trust measurement system, which includes the apparatus described in the eleventh aspect, the apparatus described in the twelfth aspect, and the apparatus described in the thirteenth aspect.

[0073] In a seventeenth aspect, an embodiment of the present application provides a trust measurement system, which includes the apparatus described in the eleventh aspect, the apparatus described in the thirteenth aspect, and the apparatus described in the fourteenth aspect.

[0074] In an eighteenth aspect, an embodiment of the present application provides a trust measurement system, which includes the device described in the eleventh aspect and the device described in the thirteenth aspect.

[0075] In a nineteenth aspect, an embodiment of the present application provides a trust measurement system, which includes the device described in the eleventh aspect and the device described in the fifteenth aspect.

[0076] In aspect 20, an embodiment of the present application provides a chip system, which includes a logic circuit and an input / output interface, and the logic circuit is used to call a computer program stored in at least one memory to implement the method described in any one of the above aspects.

[0077] In aspect 21, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions. When the computer instructions are executed on a processor, the method described in any one of the above aspects is implemented.

[0078] In aspect 22, an embodiment of the present application provides a computer program product, which, when the computer program code runs on a processor, implements the method described in any one of the above aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0079] FIG1 is a schematic diagram of the structure of a trust measurement system provided in an embodiment of the present application;

[0080] FIG2 is a schematic diagram of a trust metric provided in an embodiment of the present application;

[0081] FIG3 is a schematic diagram of an architecture for NF measurement provided in an embodiment of the present application;

[0082] FIG4 is a schematic diagram of a process of measuring NF by a PACF network element according to an embodiment of the present application;

[0083] FIG5 is a flow chart of a traditional trust measurement method provided in an embodiment of the present application;

[0084] FIG6 is a schematic diagram of a trust measurement method provided in an embodiment of the present application;

[0085] FIG7 is a schematic diagram of another trust measurement method provided in an embodiment of the present application;

[0086] FIG8 is a schematic diagram of another trust measurement method provided in an embodiment of the present application;

[0087] FIG9 is a schematic diagram of another trust measurement method provided in an embodiment of the present application;

[0088] FIG10 is a schematic diagram of another trust measurement method provided in an embodiment of the present application;

[0089] FIG11 is a schematic diagram of another trust measurement method provided in an embodiment of the present application;

[0090] FIG12 is a schematic diagram of another trust measurement method provided in an embodiment of the present application;

[0091] FIG13 is a schematic diagram of a trust measurement device provided in an embodiment of the present application;

[0092] FIG14 is a schematic diagram of another trust measurement device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0093] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application.

[0094] The technical solutions provided in this application can be applied to various communication systems, such as: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, universal mobile telecommunication system (UMTS), world-wide interoperability for microwave access (WiMAX) communication system, fifth generation (5G) mobile communication system or new radio access technology (NR). Among them, the 5G mobile communication system may include non-standalone (NSA) and / or standalone (SA).

[0095] The technical solution provided in this application can also be applied to machine type communication (MTC), long term evolution-machine (LTE-M), device-to-device (D2D) network, machine-to-machine (M2M) network, Internet of Things (IoT) network or other networks. Among them, the IoT network may include, for example, the Internet of Vehicles. Among them, the communication methods in the Internet of Vehicles system are collectively referred to as vehicle to other devices (vehicle to X, V2X, X can represent anything), for example, the V2X may include: vehicle to vehicle (V2V) communication, vehicle to infrastructure (V2I) communication, vehicle to pedestrian (V2P) communication or vehicle to network (V2N) communication, etc. The V2X communication system is a sidelink (SL) transmission technology based on D2D communication.

[0096] The technical solution provided in this application can also be applied to future communication systems, such as the sixth generation mobile communication system, etc. This application does not limit this.

[0097] It should be noted that the terminal device mentioned in this application may include a device that provides voice and / or data connectivity to a user, specifically, a device that provides voice to a user, or a device that provides data connectivity to a user, or a device that provides voice and data connectivity to a user. For example, it may include a handheld device with wireless connection capabilities, or a processing device connected to a wireless modem. The terminal device can communicate with the core network via a radio access network (RAN), exchange voice or data with the RAN, or exchange voice and data with the RAN. The terminal device may include user equipment (UE), wireless terminal device, mobile terminal device, device-to-device (D2D) terminal device, vehicle to everything (V2X) terminal device, machine-to-machine / machine-type communications (M2M / MTC) terminal device, Internet of Things (IoT) terminal device, light terminal device (light UE), reduced capability UE (REDCAP UE), subscriber unit (subscriber unit), subscriber station (subscriber station), mobile station (mobile station), remote station (remote station), access point (AP), remote terminal (remote terminal), access terminal (access terminal), user terminal (user terminal), user agent (user agent), or user device, etc. For example, it may include a mobile phone (or so-called "cellular" phone), a computer with a mobile terminal device, a portable, pocket-sized, handheld, or computer-built-in mobile device, etc. For example, devices such as personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, and personal digital assistants (PDAs). Also included are constrained devices, such as those with low power consumption, limited storage capacity, or limited computing power.Examples include barcodes, radio frequency identification (RFID), sensors, global positioning systems (GPS), laser scanners, and other information sensing devices.

[0098] As an example and not a limitation, in the embodiments of the present application, the terminal device may also be a wearable device. Wearable devices may also be referred to as wearable smart devices or smart wearable devices, etc., which are a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, etc., as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets, smart helmets, and smart jewelry for vital sign monitoring.

[0099] The various terminal devices introduced above, if located on a vehicle (eg, placed in or installed in a vehicle), can be considered as vehicle-mounted terminal devices, which are also called on-board units (OBUs).

[0100] In the embodiment of the present application, the terminal device may further include a relay. Alternatively, it can be understood that anything that can communicate data with a base station can be considered a terminal device.

[0101] In the embodiments of the present application, the device for implementing the function of the terminal device can be a terminal device, or a device capable of supporting the terminal device to implement the function, such as a chip system, which can be installed in the terminal device. In the embodiments of the present application, the chip system can be composed of a chip, or it can include a chip and other discrete devices. In the technical solutions provided in the embodiments of the present application, the technical solutions provided in the embodiments of the present application are described by taking the terminal device as an example in which the device for implementing the function of the terminal is a terminal device.

[0102] It should be noted that the network devices mentioned in this application, for example, include access network (AN) devices, such as base stations (e.g., access points), which may refer to devices in the access network that communicate with wireless terminal devices through one or more cells at the air interface, or, for example, a network device in a vehicle-to-everything (V2X) technology is a road side unit (RSU). The base station can be used to convert received air frames to and from IP packets, acting as a router between the terminal device and the rest of the access network, where the rest of the access network may include an IP network. The RSU can be a fixed infrastructure entity that supports V2X applications and can exchange messages with other entities that support V2X applications. The network device can also coordinate the attribute management of the air interface. For example, the network device may include an evolved base station (NodeB or eNB or e-NodeB, evolutionary Node B) in a long term evolution (LTE) system or long term evolution-advanced (LTE-A), or may also include a next generation node B (gNB) in a fifth generation mobile communication technology (5G) NR system (also referred to as an NR system) or may also include a centralized unit (CU) and a distributed unit (DU) in a cloud radio access network (Cloud RAN) system, but the embodiments of the present application are not limited thereto.

[0103] It should be noted that the core network equipment mentioned in this application, for example, includes access and mobility management function (AMF), user plane function (UPF) or session management function (SMF), etc., and the embodiments of this application are not limited.

[0104] Please refer to Figure 1, which is a structural diagram of a trust measurement system 100 provided in an embodiment of the present application. The trust measurement system 100 includes a remote attestation service (RAS) network element 101, a remote attestation infrastructure (RAI) network element 102, and a remote attestation agency (RAA) network element 103.

[0105] The RAS network element 101 provides security services in the core network, used for trust measurement between nodes. Trust measurement, also known as trust attestation or remote attestation, verifies that the device's hardware and software have not been tampered with by an attacker by checking their measurements. The RAS network element 101 can be an independent network function, network element, or hardware board, or it can be deployed in conjunction with existing network function network elements, etc., which is not limited in this embodiment of the present application.

[0106] The RAS network element 101 can provide a remote attestation service function, that is, a measurement service. For example, a trusted challenge can be initiated, that is, a first challenge value can be generated. The first challenge value can be a public challenge value, which can be generated by the RAS network element 101 based on a preset period or a first control message. The validity period of the first challenge value is a first duration. Endorsement information and reference value information can also be managed. Measurement information can be verified and measurement results can be generated. For example, the RAS network element 101 can receive measurement information from the RAA network element 103, verify the measurement information, and endorse the measurement information to generate a measurement result. Among them, endorsing the measurement information can be understood as signing the measurement information with the private key of the RAS network element 101. The RAS network element 101 can also verify the measurement result, for example, receive the measurement result from the RAA network element 103 and verify the measurement result. It can also receive measurement results from a public verification and endorsement (PVE), where the PVE is a third-party trusted measurement party.

[0107] The RAS network element 101 may further include a trustworthiness profile management function for receiving registered remote attestation capability information from the RAA network element 103 , which can be understood as receiving registered trustworthiness profile information from the RAA network element 103 .

[0108] The RAS network element 101 may include the following interfaces:

[0109] Storage class interface: The registered remote attestation capability information and measurement results of the RAA network element 103 can be sent to the storage module. Optionally, the storage module can be in the RAA network element 102.

[0110] Interface related to basic information: can receive endorsement information and reference value information from the RAI network element 102.

[0111] Interface related to measurement results: can receive measurement results from the PVE, and can also receive measurement information and measurement results from the RAA network element 103.

[0112] Request-response interface: can receive and respond to requests from the RAA network element 103. For example, the RAA network element 103 sends a request message to the RAS network element 101, which is used to request measurement results. Correspondingly, the RAS network element 101 sends a response message to the RAA network element 103, which includes the measurement results.

[0113] Broadcast interface: can generate the first challenge value and broadcast it.

[0114] The RAI network element 102 is used to provide endorsement information, reference values ​​and other information. The RAI network element 102 can be an external entity, for example, an external entity held by an operator / third party. In one example, the RAI network element 102 can be a manufacturer, such as an endorser and a reference value provider; the RAI network element 102 can also be a PVE, that is, a third-party trust measurement party. The RAI network element 102 can also be a distributed ledger attestation chain with a secure storage function. The RAI network element 102 can also be a management and orchestration (MANO) entity for managing extended functions for trust measurement. It should be noted that the RAI network element 102 can also be a network element of the core network, or the RAI network element 102 belongs to the management plane, or the functions of the RAI network element 102 and the RAS network element 101 are merged into one network element, which is not limited in the embodiments of the present application.

[0115] RAI network element 102 has the following functions: It can provide endorsement information for remote trusted proof, where endorsement information refers to the hardware trusted platform and serves as the foundation for the root of trust. It can also provide reference value information for remote trusted proof, which is used to verify the reliability of measurement results. It can also provide a PVE, a third-party trusted measurement provider. The PVE is a measurement function that the core network opens to the outside world through the PVE and can receive measurement results or measurement information from a trusted third party.

[0116] The RAI network element 102 may include the following interfaces:

[0117] Storage class interface: sends endorsement information, reference value information, etc. to the storage module, and accordingly, the storage module can store the endorsement information, reference value information, etc. Optionally, the storage module can be in the RAI network element 102.

[0118] Registration interface: provides endorsement information and reference value information to the RAS network element 101.

[0119] Interface related to measurement results: sends measurement results to RAS network element 101.

[0120] The RAA network element 103 is a node in the network that uses the trusted measurement service. The RAA network element 103 can be a communication entity in the communication network that may have trusted measurement capabilities or measurement information verification capabilities, such as a terminal device, network device, core network device, core network network function (NF) or third-party function (AF), and is not limited in this embodiment of the application. The carrier form can be a hardware security card, a security chip, integrated into a SIM card, or a software module, and is not limited in this embodiment of the application.

[0121] When the RAA network element is a terminal device, NF, or core network device, the architecture shown in Figure 1 can be applied to different scenarios, as follows:

[0122] (1) When the RAA network element 103 is a terminal device, the architecture shown in FIG1 can be applied to the following scenarios:

[0123] Scenario 1: After the core network verifies the trustworthiness of the terminal device, it allows the terminal device to access the network; traditional identity authentication is extended to identity authentication and device authentication.

[0124] Scenario 2: The core network initiates measurement requests to the terminal device based on policies, such as network switching, abnormal behavior, or regular measurement.

[0125] Scenario 3: The terminal device sends measurement results to the core network based on policies, such as access services and network switching.

[0126] (2) When the RAA network element 103 is a NF, the architecture shown in FIG1 can be applied to the following scenarios:

[0127] Scenario 1: When the NF initiates a registration service to the network repository function (NRF) element, a trust measurement is performed between the NF and the NRF.

[0128] Scenario 2: When NFs communicate with each other, trust measurement is performed.

[0129] Scenario 3: When the MANO entity or management plane performs actions such as NF startup and migration, it performs trust measurement on its devices, operating systems, and images.

[0130] (3) When the RAA network element 103 is a core network device, the architecture shown in FIG1 can be applied to the following scenarios:

[0131] Scenario 1: Perform policy-based trust measurement on network devices.

[0132] RAA network element 103 has the following functions:

[0133] When the RAA network element 103 acts as an atester, it may receive the first challenge value or the second challenge value and generate measurement information.

[0134] When the RAA network element 103 acts as a verifier, it can verify the measurement information from the attestor. After the verification is passed, it can endorse the measurement information and generate a measurement result.

[0135] The RAA network element 103 may include the following interfaces:

[0136] Registration interface: can register the remote certification capability information with the RAS network element 101.

[0137] Interface related to the challenge value: can receive the first challenge value or the second challenge value.

[0138] Interface related to measurement information or measurement results: can send measurement information or measurement results to the RAS network element 101.

[0139] Interface related to measurement results: measurement results can be requested from the RAS network element 101.

[0140] Trusted measurement is to check the measurement values ​​of the hardware and software of the device to determine that it has not been tampered with by an attacker. Please refer to Figure 2, which is a schematic diagram of a trusted measurement provided by an embodiment of the present application. Among them, the endorser is used to provide endorsement information, the reference value provider is used to provide reference value information, the certifier is used to generate measurement information, and the verifier verifies the measurement information based on the endorsement information and the reference value and generates a measurement result. Accordingly, the verifier can send the measurement result to the replying party. When the trusted measurement technology is applied to the core network, in order to meet the necessity of network virtualization security, the security issues of the core network network elements (network function, NF) are proposed. Because NF can be deployed in the cloud, the security of the underlying physical equipment and virtualization layer will affect the security of NF. Therefore, it is necessary to measure the security of the underlying hardware and virtualization layer of NF. Please refer to Figure 3, which is a schematic diagram of the architecture for NF measurement provided by an embodiment of the present application. The architecture includes: an attestor, a verifier, a PACF network element, a relying party virtualized network function (relying party VNF) network element, and an untrusted virtualized network function (untrusted VNF) network element. The relying party VNF network element, the untrusted VNF network element, and the PACF network element are located in the virtualized network functions (VNFs) layer. The attestor is located in the network functions virtualization infrastructure (NFVI) layer. The verifier is located in the network functions virtualization management and orchestration (NFV-MANO) layer. Based on the architecture diagram of Figure 3, please refer to Figure 4, which is a flow chart of a PACF network element measuring NFs provided in an embodiment of the present application.

[0141] Step 1: The virtual network element initiates a registration process to the NRF network element and sends the registration materials of the virtual network element.

[0142] Step 2: The NRF network element sends a remote certification request message to the PACF network element.

[0143] The remote certification request message includes registration materials of the virtual network element.

[0144] Step 3: The PACF network element verifies the signature and obtains the measurement results from the verifier.

[0145] The measurement result may also be referred to as a remote verification result.

[0146] Step 4: The PACF network element sends a response message to the NRF network element.

[0147] The response message includes signature information and measurement results.

[0148] Step 5: The NRF network element confirms the measurement results and stores the registration materials of the virtual network element.

[0149] Step 6: The NRF network element sends a registration request reply message to the virtual network element.

[0150] The PACF network element-to-NF measurement in FIG4 is a traditional measurement method. FIG5 is a flow chart of a traditional trust measurement method provided in an embodiment of the present application. Traditional trust measurements are all point-to-point measurements, also known as single-point measurements or direct measurements, where the verifier and the attestor are in a one-to-one relationship. The specific process is as follows:

[0151] Step 1: The verifier sends a challenge value to the attester.

[0152] The challenge value is a random number.

[0153] Step 2: The attester generates measurement information based on the challenge value and sends it to the verifier.

[0154] Step 3: The verifier verifies the measurement information and generates measurement results.

[0155] Among them, the verifier verifies the measurement information in order to judge the credibility of the attester.

[0156] Among them, in this single-point measurement, the verifier needs to have the ability to verify the measurement information. And it needs to establish direct communication with the attester. Since the verifier (verifier) ​​and the certifier (attester) are in a one-to-one correspondence, each trust measurement occurs one-to-one. For example, if there are 10 attester and 10 verifier, if they measure each other, they need to measure 45 times, and the computational complexity is high. In Figure 4, the trust measurement technology is used to perform trust measurement on the underlying facilities of the NF, thereby ensuring the security of the NF. However, at present, the trust measurement only stays at the NF level and the management level. There is no unified trust measurement service for various network elements, especially terminal devices. Therefore, in order to solve the above problems, the embodiment of the present application proposes the following solution.

[0157] Please refer to FIG6 , which shows a trust measurement method provided by an embodiment of the present application. The method includes but is not limited to the following steps:

[0158] Step S601: The RAS network element obtains the measurement result of the first RAA network element.

[0159] The RAS network element obtains the measurement results of the first RAA network element in the following three ways:

[0160] Method A: The RAS network element generates the measurement result of the first RAA network element.

[0161] Among them, the process of the RAS network element generating the measurement result of the first RAA network element is as follows: the RAS network element generates a first challenge value based on a preset period or a first control message, and sends it to the first RAA network element. Correspondingly, the first RAA network element generates measurement information based on the first challenge value and sends it to the RAS network element. The RAS network element verifies the measurement information. If the verification is successful, the RAS network element signs the measurement information and generates the measurement result of the first RAA network element.

[0162] The preset period may be specified by the protocol or determined by the RAS network element, and is not limited in the embodiments of the present application. The first control message is sent by the management plane, or is a request message sent by the first RAA network element, or is a request message sent by any other RAA network element other than the first RAA network element.

[0163] The first challenge value may also be referred to as a public challenge value or a public random number. The validity period of the first challenge value is a first duration, which may be specified by the protocol or determined by the RAS network element, and is not limited in the embodiments of the present application. For example, the preset period may be every 10 seconds, for example, the first duration may be 30 seconds.

[0164] Among them, the first RAA network element can be one or more attesters. When the first RAA network element is multiple attesters, the RAS network element can send the first challenge value to the multiple attesters, and the multiple attesters can generate corresponding multiple measurement information based on the first challenge value. Compared with the traditional measurement method, each of the multiple attesters needs to generate a second challenge value. This application generates the first challenge value through the RAS network element and sends it to the multiple attesters, which can reduce resource consumption.

[0165] Among them, the RAS network element can generate a first challenge value based on a preset period or a first control message and according to a first preset rule. The first preset rule can be specified by the protocol or determined by the RAS network element, and is not limited in the embodiment of the present application. For example, the preset period is every 10 seconds, the first preset rule is a first random number generation function, and the RAS network element can generate a first challenge value every 10 seconds according to the first random number generation function. After the RAS network element generates the first challenge value, it can broadcast the first challenge value, that is, the first challenge value can be carried in a broadcast message, and the broadcast message can be a radio resource control (RRC) message RRC, a media access control (MAC) control element (CE) message, or a downlink control message (DCI), and is not limited in the embodiment of the present application. Accordingly, the first RAA network element can receive a broadcast message sent by the RAS network element, and the broadcast message carries the first challenge value.

[0166] Of course, the RAS network element can actively generate the first challenge value by itself, that is, it can be understood that the RAS network element does not generate the first challenge value based on a preset period or the first control message, and this embodiment of the present application does not limit this.

[0167] The measurement information includes identity credibility information and device credibility information. The identity credibility information is used to verify the credibility of the identity of the first RAA network element, and the device credibility information is used to verify the credibility of the device of the first RAA network element. The first RAA network element can generate measurement information based on the first challenge value as follows: the first RAA network element can generate a measurement log based on the measurement process information of the supported trusted computing platform, and then calculate the generated measurement information using a summary of the measurement log and the first challenge value.

[0168] Optionally, before the RAS network element generates the first challenge value based on a preset period or the first control message, the RAS network element may receive remote attestation capability information registered from the first RAS network element. In this way, the RAS network element can have the trustworthy capability of managing network devices.

[0169] Optionally, before the RAS network element generates the first challenge value based on a preset period or the first control message, the RAS network element may receive endorsement information and reference value information from the first RAI network element.

[0170] The RAS network element may obtain endorsement information and reference value information from the first RAI network element, and verify the measurement information based on the endorsement information and reference value information. The endorsement information is provided by an endorser, such as a chip manufacturer, and the reference value information is provided by a reference value provider, such as a device manufacturer. The RAS network element signing the measurement information may refer to the RAS network element signing the measurement information with the RAS network element's signature information, thereby generating a measurement result. Optionally, the RAS network element's signature information may be the RAS network element's private key. That is, the measurement result includes the measurement information + the RAS network element's signature information.

[0171] For example, the first RAA network element is a terminal device, and the measurement information includes identity credibility information and device credibility information, specifically measurement information = certificate 1 + hash 1, where certificate 1 represents identity credibility information and hash 1 represents device credibility information. The RAS network element verifies the measurement information based on endorsement information and reference value information, as follows: First, the RAS network element verifies whether the chip in the terminal device is a legitimate chip. The RAS network element can obtain a certificate issued to the chip of the terminal device from the chip manufacturer (for example, Intel), for example, certificate 2. Certificate 2 is endorsement information, and the chip manufacturer is the endorser. Then, the RAS network element compares certificate 1 and certificate 2. If they are the same, it is determined that the chip in the terminal device is a legitimate chip, that is, the terminal device is a legitimate user. Then, after the RAS network element determines that the terminal device is a legitimate user, it determines whether Hash 1 is authentic information, that is, whether it is trusted startup information. The RAS network element can obtain the hash value of the terminal device when it is trusted startup from the device manufacturer of the terminal device, such as Hash 2, where Hash 2 is reference value information and the device manufacturer is the reference value information provider. The RAS network element then compares Hash 1 with Hash 2. If they are the same, it determines that the terminal device is trusted. The RAS network element determines that the terminal device is trusted by performing a trustworthy measurement on the identity and device of the terminal device.

[0172] In a possible implementation manner, after the RAS network element obtains the measurement result of the first RAA network element, the RAS network element may send the measurement result to the first RAA network element.

[0173] In another possible implementation, after the RAS network element obtains the measurement results of the first RAA network element, the RAS network element may send the measurement results to the second RAI network element. Accordingly, the second RAI network element may store the measurement results. The second RAI network element may be a network element with storage capabilities, such as a storage system or database, and is not limited in this embodiment of the present application. In this way, when a network element in the network needs to use the measurement results, it can obtain the measurement results from the second RAI network element without having to initiate the measurement process again, thereby reducing resource consumption.

[0174] In the above-mentioned method A, the first RAA network element can be one or more RAA network elements, such as one or more provers. For example, the first RAA network element is 10 provers. The 10 provers can generate corresponding 10 measurement information. The RAA network element can verify the 10 measurement information separately, for a total of 10 times, and generate corresponding 10 measurement results. Compared with the traditional trusted measurement method, 10 provers need to establish a one-to-one relationship with 10 verifiers and measure 45 times, which can greatly reduce the complexity. Furthermore, if other network elements in the network need to use the 10 measurement results, they can obtain the measurement results from the network element that stores the measurement results, thereby eliminating the need to initiate 10 measurement processes and reducing resource consumption.

[0175] Mode B: The RAS network element receives the measurement result of the first RAA network element sent by the third RAA network element.

[0176] Among them, the process of determining the measurement result of the first RAA network element is as follows: the third RAA network element generates a second challenge value and sends the second challenge value to the first RAA network element. Accordingly, the first RAA network element generates measurement information based on the second challenge value and sends the measurement information to the third RAA network element. After the third RAA network element receives the measurement information from the first RAA network element, it verifies the measurement information. If the verification is successful, the third RAA network element signs the measurement information and generates the measurement result of the first RAA network element. Accordingly, the third RAA network element sends the measurement result of the first RAA network element to the RAS network element.

[0177] Optionally, the third RAA network element may be a verifier. The second challenge value may also be referred to as an independent challenge value, an independent random number. The third RAA network element may generate a second challenge value based on a second preset rule, which may be specified by the protocol or determined by the third RAA network element, and is not limited in this embodiment of the present application. After the third RAA network element generates the second challenge value, it may send the second challenge value to one or more first RAA network elements, which may be an attester.

[0178] Optionally, before the third RAA network element generates the second challenge value, the RAS network element may receive remote attestation capability information registered from the first RAA network element. In this way, the RAS network element can have the trustworthy capability of managing network devices.

[0179] Optionally, before the third RAA network element generates the second challenge value, the RAS network element may receive endorsement information and reference value information from the first RAI network element.

[0180] The measurement information includes identity credibility information and device credibility information. The identity credibility information is used to verify the credibility of the identity of the first RAA network element, and the device credibility information is used to verify the credibility of the device of the first RAA network element. The first RAA network element generates measurement information based on the second challenge value as follows: the first RAA network element may generate a measurement log based on the measurement process information of the supported trusted computing platform, and then calculate the generated measurement information using a summary of the measurement log and the second challenge value.

[0181] Specifically, the third RAA network element can verify the measurement information based on the endorsement information and the reference value information. The sources of the endorsement information and the reference value information are as follows: The first way: the third RAA network element receives the endorsement information (endorsement) and the reference value (reference value) information from the RAS network element, that is, the RAS network element obtains the endorsement information and the reference value information from the first RAI network element, and then the RAS network element sends the endorsement information and the reference value information to the third RAA network element. Accordingly, the third RAA network element receives the endorsement information and the reference value information from the RAS network element. The second way: the third RAA network element receives the endorsement information and the reference value information from the first RAI network element.

[0182] Among them, the process in which the third RAA network element can verify the measurement information based on the endorsement information and the reference value information can refer to the RAS network element verifying the measurement information based on the endorsement information and the reference value information in method A, which will not be repeated here.

[0183] The third RAA network element verifies the measurement information. If the verification passes, the third RAA network element signs the measurement information and generates a measurement result for the first RAA network element. The third RAA network element signing the measurement information may mean that the third RAA network element signs the measurement information using its signature information, thereby generating the measurement result. Optionally, the signature information of the RAA network element may be the private key of the third RAA network element. That is, the measurement result includes the measurement information and the signature information of the third RAA network element.

[0184] In one possible implementation, after the RAS network element receives the measurement result of the first RAA network element from the third RAA network element, the RAS network element verifies the measurement result of the first RAA network element. Specifically, the RAS network element can verify the measurement result based on the endorsement information and the reference value information. If the verification is successful, the RAS network element can sign the measurement result with the signature information of the RAS network element, that is, generate a new measurement result, and the new measurement result includes the measurement information + the signature information of the third RAA network element + the signature information of the RAS network element. By signing the measurement information and generating the measurement result by the RAS network element, the RAS network element can endorse the trusted status of the first RAA network element, which is beneficial for the node using the measurement result to verify the credibility. Optionally, the RAS network element can send the new measurement result to the second RAI network element. The second RAI network element can be a network element with a storage function, such as a storage system, a database, etc., which is not limited in the embodiment of the present application. Accordingly, if other network elements in the network need to use the measurement results of the first RAA network element, they can obtain the measurement results from the storage of the second RAA network element, thereby eliminating the need to initiate the measurement process again and reducing resource consumption. The measurement results that appear in the following steps S602-S605 are the new measurement results, that is, the measurement results signed by the RAS network element.

[0185] In the above-described method B, the RAS network element receives the measurement results of the first RAA network element from the third RAA network element and verifies the measurement results, which can make the measurement results more robust and enhance the credibility of the measurement results. Furthermore, if other network elements in the network need to use the measurement results of the first RAA network element, they can obtain the measurement results from the network element that stores the measurement results, eliminating the need to initiate the measurement process again and reducing resource consumption.

[0186] Mode C: The RAS network element receives the measurement result of the first RAA network element sent by the PVE.

[0187] The process of determining the measurement result of the first RAA network element is as follows: the first RAA network element generates measurement information and sends the measurement information to the PVE. Accordingly, the measurement information is verified. If the verification is successful, the PVE signs the measurement information and generates a measurement result.

[0188] The generation of the measurement information may include the following three situations:

[0189] Case 1: The measurement information is determined based on the first challenge value of the RAS network element. After the RAS network element generates the first challenge value, it sends the first challenge value to the first RAA network element. Correspondingly, the first RAA network element receives the first challenge value from the RAS network element and determines the measurement information based on the first challenge value. Among them, the first challenge value is a public challenge value. The RAS network element generates the first challenge value based on a preset period or a first control message. The validity period of the first challenge value is the first duration. For details, please refer to step S601, which will not be repeated here.

[0190] Case 2: The measurement information is determined based on the second challenge value of the third RAA network element. After the third RAA network element generates the second challenge value, the third RAA network element can be a verifier. The third RAA network element sends the second challenge value to the first RAA network element. In response, the first RAA network element receives the second challenge value from the third RAA network element and determines the measurement information based on the second challenge value. The second challenge value is an independent challenge value. For details, please refer to step S701 and will not be repeated here.

[0191] Case 3: The measurement information is determined based on the challenge value of the PVE. After the PVE generates the challenge value of the PVE, it sends the challenge value of the PVE to the first RAA network element. Correspondingly, the first RAA network element receives the challenge value of the PVE from the PVE and generates measurement information based on the challenge value of the PVE. The challenge value of the PVE may be generated by the PVE based on a third preset rule. The third preset rule may be agreed upon by the protocol or determined by the PVE, and is not limited in this embodiment of the present application.

[0192] It should be noted that the number of PVEs can be multiple, and the first RAA network element can send the measurement information of the first RAA network element to multiple PVEs. Accordingly, the multiple PVEs verify the measurement information. In this way, credibility can be enhanced. The process in which the PVE can verify the measurement information based on the endorsement information and the reference value information can refer to the RAS network element verifying the measurement information based on the endorsement information and the reference value information in step S607, which will not be repeated here. The sources of the endorsement information and the reference value information are as follows: The first way: the PVE receives the endorsement information and the reference value information from the RAS network element, that is, the RAS network element obtains the endorsement information and the reference value information from the first RAI network element, and then the RAS network element sends the endorsement information and the reference value information to the PVE. Accordingly, the PVE receives the endorsement information and the reference value information from the RAS network element. The second way: the PVE receives the endorsement information and the reference value information from the first RAI network element.

[0193] Optionally, in approach C, the PVE may be a hardware provider, an operating system provider, an application provider, or a trusted certification authority (CA). The first RAA network element may be a terminal device, a hardware platform, or an application, which is not limited in this embodiment of the present application.

[0194] In the above-described method C, the RAS network element receives the measurement results of the first RAA network element from the PVE and verifies the measurement results, which can make the measurement results more robust and enhance the credibility of the measurement results. Furthermore, if other network elements in the network need to use the measurement results of the first RAA network element, they can obtain the measurement results from the network element that stores the measurement results, eliminating the need to initiate the measurement process again and reducing resource consumption.

[0195] Step S602: The second RAA network element sends a first request to the RAS network element.

[0196] The first request is used to request the measurement result of the first RAA network element. Optionally, the first request may include but is not limited to one or more of the following: a subscription permanent identifier (SUPI), a public key (PK), or an international mobile equipment identity (IMEI).

[0197] Step S603: The RAS network element receives the first request from the second RAS network element.

[0198] Step S604: The RAS network element sends the measurement result of the first RAA network element to the second RAA network element.

[0199] Optionally, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature) or freshness proof information. The verification type information may mean that the measurement information is generated based on the first challenge value or based on the second challenge value. The verifier list information may include a verifier list, for example, the verifier list includes verifier 1, verifier 2 and verifier 3. The random number may be the first challenge value or the second challenge value. When the measurement information is generated based on the first challenge value, the random number is the first challenge value; when the measurement information is generated based on the second challenge value, the random number is the second challenge value. The signature information may be the private key of the RAS network element. The freshness proof information can be understood as the result that the time calculated for the measurement result of the first RAA is time-sensitive. In this way, it is possible to avoid obtaining expired measurement results, thereby affecting the accuracy of the measurement results.

[0200] Step S605: The second RAA network element receives the measurement result of the first RAA network element from the RAS network element.

[0201] After the second RAA network element receives the measurement result of the first RAA network element, since the measurement result of the first RAA network element is authenticated by the RAS network element, if the second RAA network element considers the RAS network element to be credible, then the measurement result of the first RAA network element is considered to be credible.

[0202] In the method shown in Figure 6, the RAS network element obtains the measurement result of the first RAA network element, and accordingly, after receiving the first request from the second RAA network element, the measurement result is sent to the second RAA network element. The RAS network element can provide trusted measurement services and perform trusted measurement, that is, the RAS network element can provide measurement results in a centralized manner. Compared with the traditional one-to-one correspondence between the prover and the verifier, the verifier sends a challenge value to the prover, the prover generates measurement information based on the challenge value, and sends the measurement information to the verifier, the verifier verifies the measurement information and generates a measurement result. The traditional measurement method has high resource consumption and complex processes. The present application provides trusted measurement services through the RAS network element and centrally provides measurement results. When the second RAA network element needs to use the measurement result of the first RAA network element, it can obtain the measurement result from the RAS network element without initiating a measurement process, reducing resource consumption and simplifying the implementation process.

[0203] Please refer to FIG. 7 , which illustrates a trust measurement method provided by an embodiment of the present application. In the method shown in FIG. 7 , the first RAA network element and the second RAA network element may be a terminal device, a base station, an edge server, a core network element, or an application function entity. The RAS network element may be a core network element. The method includes but is not limited to the following steps:

[0204] Step S701: The RAS network element generates a first challenge value based on a preset period or a first control message.

[0205] The preset period may be specified by the protocol or determined by the RAS network element, and is not limited in this embodiment of the present application. The first control message is sent by the management plane, or is a request message sent by the first RAA network element, or may be a request message sent by any other RAA network element other than the first RAA network element. For example, the first RAA network element may be an attester, and the third RAA network element may be a verifier.

[0206] The validity period of the first challenge value is the first duration, and specific details may refer to the relevant description in method A of step S601.

[0207] The RAS network element may generate the first challenge value based on a preset period or a first control message and according to a first preset rule. For details, please refer to the relevant description in Method A of step S601.

[0208] Of course, the RAS network element can actively generate the first challenge value by itself, that is, it can be understood that the RAS network element does not generate the first challenge value based on a preset period or the first control message, and this embodiment of the present application does not limit this.

[0209] Optionally, before the RAS network element generates the first challenge value based on a preset period or the first control message, the RAS network element may receive remote attestation capability information registered from the first RAS network element.

[0210] Optionally, before the RAS network element generates the first challenge value based on a preset period or the first control message, the RAS network element may receive endorsement information and reference value information from the first RAI network element.

[0211] Step S702: The first RAA network element receives a first challenge value.

[0212] Step S703: The first RAA network element generates measurement information according to the first challenge value.

[0213] Specifically, the measurement information includes identity credibility information and device credibility information. For details, please refer to the relevant description in method A of step S601.

[0214] Step S704: The first RAA network element sends measurement information to the RAS network element.

[0215] Step S705: The RAS network element receives the measurement information from the first RAA network element.

[0216] Step S706: The RAS network element obtains the measurement result of the first RAA network element.

[0217] The RAS network element obtaining the measurement result of the first RAA network element may include the RAS network element generating the measurement result of the first RAA network element. For details, refer to the relevant description in the method A of step S601.

[0218] In a possible implementation manner, after the RAS network element obtains the measurement result of the first RAA network element, the RAS network element may send the measurement result to the first RAA network element.

[0219] In another possible implementation, after the RAS network element obtains the measurement result of the first RAA network element, the RAS network element may send the measurement result to a second RAI network element. The second RAI network element may be a network element with a storage function, such as a storage system or a database, which is not limited in this embodiment of the present application.

[0220] Step S707: The second RAA network element sends a first request to the RAS network element.

[0221] The first request is used to request a measurement result of a first RAA network element.

[0222] Step S708: The RAS network element receives the first request from the second RAS network element.

[0223] Step S709: The RAS network element sends the measurement result of the first RAA network element to the second RAA network element.

[0224] Step S710: The second RAA network element receives the measurement result of the first RAA network element from the RAS network element.

[0225] This step can refer to the description of step S605 and will not be repeated here.

[0226] In the method shown in Figure 7, the first RAA network element can be one or more certifiers. For example, the first RAA network element can be 10 certifiers. These 10 certifiers can generate 10 corresponding measurement information. The RAS network element can verify these 10 measurement information separately, for a total of 10 verifications, and generate 10 corresponding measurement results. Furthermore, if other network elements in the network, such as the second RAA network element, need to use these 10 measurement results, they can obtain them from the RAS network element, thus eliminating the need to initiate 10 measurement processes and reducing resource consumption.

[0227] Please refer to FIG8 , which shows a trust measurement method provided by an embodiment of the present application. In the method shown in FIG8 , the first RAA network element, the second RAA network element, and the third RAA network element can be a terminal device, a base station, an edge server, a core network element, or an application function entity. The RAS network element can be a core network element. The method includes but is not limited to the following steps:

[0228] Step S801: The third RAA network element generates a second challenge value.

[0229] Among them, the third RAA network element can be a verifier. The second challenge value can also be called an independent challenge value, an independent random number. The third RAA network element can generate the second challenge value based on a second preset rule. The second preset rule can be specified by the protocol or determined by the third RAA network element, and is not limited in the embodiment of the present application. After the third RAA network element generates the second challenge value, it can send the second challenge value to one or more first RAA network elements, and the first RAA network element can be an attester.

[0230] Optionally, before the third RAA network element generates the second challenge value, the RAS network element may receive remote attestation capability information registered from the first RAA network element.

[0231] Optionally, before the third RAA network element generates the second challenge value, the RAS network element may receive endorsement information and reference value information from the first RAI network element.

[0232] Step S802: the third RAA network element sends a second challenge value to the first RAA network element.

[0233] Step S803: The first RAA network element receives a second challenge value from the third RAA network element.

[0234] Step S804: The first RAA network element generates measurement information according to the second challenge value.

[0235] The measurement information includes identity credibility information and device credibility information. For details, please refer to the relevant description of method B in step S601.

[0236] Step S805: The first RAA network element sends measurement information to the third RAA network element.

[0237] Step S806: The third RAA network element receives the measurement information from the first RAA network element.

[0238] Step S807: The third RAA network element verifies the measurement information.

[0239] Specifically, the third RAA network element can verify the measurement information based on the endorsement information and reference value information. The endorsement information and reference value information can be obtained in two ways: First, the third RAA network element receives endorsement information and reference value information from the RAS network element. Second, the third RAA network element receives endorsement information and reference value information from the first RAI network element. For details, please refer to the description of Method B in step S601.

[0240] The process in which the third RAA network element can verify the measurement information based on the endorsement information and the reference value information can refer to the process in which the RAS network element verifies the measurement information based on the endorsement information and the reference value information in method A in step S601, which will not be repeated here.

[0241] Step S808: The third RAA network element determines the measurement result of the first RAA network element.

[0242] The third RAA network element verifies the measurement information. If the verification is successful, the third RAA network element signs the measurement information and generates a measurement result of the first RAA network element. For details, please refer to the description of method B in step S601.

[0243] Step S809: the third RAA network element sends the measurement result of the first RAA network element to the RAS network element.

[0244] Step S810: The RAS network element obtains the measurement result of the first RAA network element.

[0245] Specifically, the RAS network element receives the measurement result of the first RAA network element from the third RAA network element. The measurement result includes measurement information and signature information of the third RAA network element. Optionally, the signature information of the third RAA network element may be a private key of the third RAA network element.

[0246] In one possible implementation, after the RAS network element receives the measurement result of the first RAA network element from the third RAA network element, the RAS network element verifies the measurement result of the first RAA network element. Specifically, the RAS network element can verify the measurement result based on the endorsement information and the reference value information. If the verification is successful, the RAS network element can sign the measurement result with the signature information of the RAS network element, that is, generate a new measurement result, and the new measurement result includes the measurement information + the signature information of the third RAA network element + the signature information of the RAS network element. Optionally, the RAS network element can send the new measurement result to the second RAI network element. The second RAI network element can be a network element with a storage function, for example, a storage system, a database, etc., which is not limited in the embodiment of the present application. The measurement result appearing in the following steps S811-S814 refers to the new measurement result, that is, the measurement result signed by the RAS network element.

[0247] Step S811: the second RAA network element sends a first request to the RAS network element.

[0248] The first request is used to request a measurement result of a first RAA network element.

[0249] Step S812: The RAS network element receives the first request from the second RAS network element.

[0250] Step S813: The RAS network element sends the measurement result of the first RAA network element to the second RAA network element.

[0251] Step S814: the second RAA network element receives the measurement result of the first RAA network element from the RAS network element.

[0252] This step can refer to the description of step S605 and will not be repeated here.

[0253] In the method shown in Figure 8, the RAS network element receives the measurement results of the first RAA network element from the third RAA network element and verifies the measurement results, making the measurement results more robust and enhancing the credibility of the measurement results. Furthermore, if other network elements in the network, such as the second RAA network element, need to use the measurement results of the first RAA network element, they can obtain the measurement results from the RAS network element, eliminating the need to initiate the measurement process again and reducing resource consumption.

[0254] Please refer to Figure 9, which shows a trust measurement method provided by an embodiment of the present application. The method shown in Figure 9 is applicable to a scenario in which an authentication server function (AUSF) network element performs access authentication on a terminal device. The first RAA network element may be a terminal device, and the second RAA network element may be an AUSF network element. The method includes but is not limited to the following steps:

[0255] Step S901: The RAS network element obtains the measurement result of the first RAA network element.

[0256] The RAS network element obtains the measurement result of the first RAA network element in the following two ways:

[0257] Method 1: The RAS network element generates a measurement result for the first RAA network element. The RAS network element generates a first challenge value and sends it to the first RAA network element. The first RAA network element generates measurement information based on the first challenge value and sends the measurement information to the RAS network element. In response, the RAS network element verifies the measurement information. If the verification is successful, the RAS network element signs the measurement information and generates a measurement result.

[0258] The second method: The third RAA network element sends the measurement result of the first RAA network element to the RAS network element, wherein the third RAA network element is any one or more RAA network elements other than the first RAA network element and the second RAA network element. The third RAA network element can be a verifier. The third RAA network element generates a second challenge value and sends the second challenge value to the first RAA network element. The first RAA network element generates measurement information based on the second challenge value and sends the measurement information to the third RAA network element. Accordingly, the third RAA network element verifies the measurement information. If the verification is successful, the third RAA network element signs the measurement information and generates a measurement result. Accordingly, the third RAA network element can send the measurement result to the RAS network element.

[0259] Step S902: The second RAA network element sends a first request to the RAS network element.

[0260] The second RAA network element may be a verifier. The first request is used to request the measurement result of the first RAA network element. Optionally, the first request may include but is not limited to one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0261] Step S903: The RAS network element receives the first request from the second RAS network element.

[0262] Step S904: The RAS network element sends the measurement result of the first RAA network element to the second RAA network element.

[0263] The measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness proof information. For details, please refer to the relevant description in step S604, which is not repeated here.

[0264] Step S905: The second RAA network element receives the measurement result of the first RAA network element from the RAS network element.

[0265] For details, please refer to step S605, which will not be repeated here.

[0266] In the method shown in Figure 9, the RAS network element obtains the measurement result of the first RAA network element, and accordingly, after receiving the first request from the second RAA network element, the measurement result is sent to the second RAA network element. The RAS network element can provide trusted measurement services and perform trusted measurement, that is, the RAS network element can provide measurement results in a centralized manner. Compared with the traditional one-to-one correspondence between the prover and the verifier, the verifier sends a challenge value to the prover, the prover generates measurement information based on the challenge value, and sends the measurement information to the verifier, the verifier verifies the measurement information and generates a measurement result. The traditional measurement method has high resource consumption and complex processes. The present application provides trusted measurement services through the RAS network element and centrally provides measurement results. When the second RAA network element needs to use the measurement result of the first RAA network element, it can obtain the measurement result from the RAS network element without initiating a measurement process, reducing resource consumption and simplifying the implementation process.

[0267] Please refer to Figure 10, which shows a trust measurement method provided by an embodiment of the present application. In the method shown in Figure 10, the PVE can be a hardware provider, an operating system provider, an application provider, or a trusted certificate authority (CA), and the first RAA network element can be a terminal device, a hardware platform, or an application. The method includes but is not limited to the following steps:

[0268] Step S1001: The PVE determines a measurement result of a first RAA network element.

[0269] Optionally, the PVE may be a hardware provider, an operating system provider, an application provider, or a trusted certificate authority (CA). The first RAA network element may be a terminal device, a hardware platform, or an application, which is not limited in the embodiment of the present application.

[0270] Specifically, the PVE receives measurement information from the first RAA network element and verifies the measurement information. If the verification is successful, the PVE signs the measurement information and generates a measurement result. The generation of the measurement information may include the following three cases: Case 1: The measurement information is determined based on the first challenge value of the RAS network element. Case 2: The measurement information is determined based on the second challenge value of the third RAA network element. Case 3: The measurement information is determined based on the challenge value of the PVE. For details, please refer to the relevant description of method C in step S601, which will not be repeated here.

[0271] It should be noted that the number of PVEs can be multiple, and the first RAA network element can send the measurement information of the first RAA network element to multiple PVEs. Accordingly, the multiple PVEs verify the measurement information. For details, please refer to the relevant description of method C in step S601, which will not be repeated here.

[0272] Step S1002: The PVE sends the measurement result of the first RAA network element to the RAS network element.

[0273] Step S1003: The RAS network element obtains the measurement result of the first RAA network element.

[0274] The RAS network element obtaining the measurement result of the first RAA network element may include the RAS network element receiving the measurement result of the first RAA network element from the PVE.

[0275] Step S1004: the second RAA network element sends a first request to the RAS network element.

[0276] The first request is used to request a measurement result of a first RAA network element.

[0277] Step S1005: The RAS network element receives the first request from the second RAS network element.

[0278] Step S1006: The RAS network element sends the measurement result of the first RAA network element to the second RAA network element.

[0279] Step S1007: the second RAA network element receives the measurement result of the first RAA network element from the RAS network element.

[0280] For details, please refer to step S605, which will not be repeated here.

[0281] In the method shown in Figure 10, the RAS network element receives the measurement results of the first RAA network element from the PVE and verifies the measurement results, making the measurement results more robust and enhancing the credibility of the measurement results. Furthermore, if other network elements in the network, such as the second RAA network element, need to use the measurement results of the first RAA network element, they can obtain the measurement results from the RAS network element, eliminating the need to initiate the measurement process again and reducing resource consumption.

[0282] Please refer to FIG. 11 , which illustrates a trust measurement method provided in an embodiment of the present application. In the method described in FIG. 11 , the first RAA network element may be a terminal device or a network device, such as a base station or a core network element, and the RAS network element may be a core network element. The method includes but is not limited to the following steps:

[0283] Step S1101: The first RAA network element triggers itself to generate measurement information based on time or policy.

[0284] The first RAA network element is an attestor. The first RAA network element self-triggering the generation of measurement information based on time may include the first RAA network element self-triggering the generation of measurement information based on a first duration, for example, the first RAA network element self-triggering the generation of measurement information every T minutes, where T is greater than 0. The first RAA network element self-triggering the generation of measurement information based on policy may include the first RAA network element moving, i.e., the first RAA network element's network changing, such as network handover, which triggers the generation of measurement information.

[0285] Step S1102: The first RAA network element sends measurement information to the RAS network element.

[0286] Step S1103: The RAS network element receives measurement information from the first RAA network element.

[0287] Step S1104: The RAS network element verifies the measurement information and generates a measurement result of the first RAS network element.

[0288] Specifically, the RAS network element may verify the measurement information and generate a measurement result based on the endorsement information and the reference value information. For details, please refer to the relevant description in step S601, which will not be repeated here.

[0289] Step S1105: The RAS network element sends the measurement result to the first RAA network element.

[0290] Step S1106: The first RAA network element receives the measurement result from the RAS network element.

[0291] In the method shown in FIG11 , the above-mentioned manner enables the RAS network element to provide a trust measurement service and perform trust measurement.

[0292] Please refer to Figure 12, which shows a trust measurement method provided by an embodiment of the present application. In the method shown in Figure 12, the first RAA network element is a terminal device, and correspondingly, the third RAA network element is an AUSF network element or a network device, such as a base station; the first RAA network element is a network device, and correspondingly, the third RAA network element is a terminal device; the first RAA network element is a core network element, and correspondingly, the third RAA network element is a MAMO, core network element, or NRF network element; the method includes but is not limited to the following steps:

[0293] Step S1201: the third RAA network element sends a first message to the first RAA network element.

[0294] The first message is used to request the measurement result of the first RAA network element. The first RAA network element is an attester, and the third RAA network element is a verifier.

[0295] Step S1202: The first RAA network element receives a first message from a third RAA network element.

[0296] Step S1203: The first RAA network element sends a second message to the third RAA network element.

[0297] The second message includes the measurement result.

[0298] Step S1204: the third RAA network element receives the second message from the first RAA network element (RAS network element).

[0299] In the method shown in FIG12 , the RAS network element can provide a trust measurement service and perform trust measurement through the above-mentioned manner.

[0300] The above describes in detail the method of the embodiment of the present application, and the following provides an apparatus of the embodiment of the present application.

[0301] Please refer to Figure 13, which is a schematic diagram of the structure of a trust measurement device 1300 provided in an embodiment of the present application. The trust measurement device 1300 includes a processing unit 1301 and a communication unit 1302, wherein each unit is described in detail as follows. The processing unit 1301 is used to obtain the measurement result of the first remote attestation agent RAA network element; the communication unit 1302 is used to receive a first request from a second RAA network element, the first request being used to request the measurement result of the first RAA network element; and the communication unit 1302 is used to send the measurement result of the first RAA network element to the second RAA network element.

[0302] In a possible implementation, the processing unit 1301 is configured to generate a measurement result of the first RAA network element.

[0303] In another possible implementation, the processing unit 1301 is further used to generate a first challenge value based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; the communication unit 1302 is further used to receive measurement information from the first RAA network element, and the measurement information is determined based on the first challenge value; the processing unit 1301 is also used to verify the measurement information.

[0304] In another possible implementation manner, the first control message is sent by a management plane, or is a request message sent by the first RAA network element.

[0305] In yet another possible implementation, the processing unit 1301 is configured to, if the verification is successful, sign the measurement information and generate a measurement result of the first RAA network element.

[0306] In yet another possible implementation, the communication unit 1302 is further configured to send the measurement result to the first RAA network element.

[0307] In yet another possible implementation, the communication unit 1302 is further configured to receive a measurement result of the first RAA network element sent from a third RAA network element.

[0308] In yet another possible implementation, the communication unit 1302 is further configured to receive a measurement result of the first RAA network element sent from a public verifier PVE.

[0309] In yet another possible implementation manner, the first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0310] In another possible implementation, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness certification information.

[0311] In another possible implementation, the processing unit 1301 is further used to obtain endorsement information and reference value information from a first remote attestation infrastructure RAI network element, and the endorsement information and the reference value information are used to verify the measurement information or the measurement result.

[0312] In yet another possible implementation, the communication unit 1302 is further configured to receive registered remote attestation capability information from the first RAA network element.

[0313] In yet another possible implementation, the communication unit 1302 is further configured to send the measurement result to the second RAI network element.

[0314] It should be noted that the implementation and beneficial effects of each unit may also correspond to the corresponding description of the method embodiment shown in Figures 6, 7, 8, 9, 10, 11 or 12.

[0315] Optionally, a detailed description of each unit in the trust measurement device 1300 may be as follows: the communication unit 1302 is configured to receive a first challenge value, where the first challenge value is generated based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; the processing unit 1301 is configured to generate measurement information based on the first challenge value; and the communication unit 1302 is configured to send the measurement information to a remote attestation service (RAS) network element.

[0316] In a possible implementation manner, the first control message is sent by a management plane, or is a request message sent by the first RAA network element.

[0317] In yet another possible implementation, the communication unit 1302 is further configured to receive the measurement result from the RAS.

[0318] It should be noted that the implementation and beneficial effects of each unit may also correspond to the corresponding description of the method embodiment shown in FIG. 6 or FIG. 7 .

[0319] Optionally, a detailed description of each unit in the trusted measurement device 1300 may also be as follows: the communication unit 1302 is configured to send a first request to a remote attestation service (RAS) network element, where the first request is used to request a measurement result of the first RAA network element; and the communication unit 1302 is configured to receive the measurement result of the first RAA network element from the RAS network element.

[0320] In a possible implementation manner, the first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0321] In another possible implementation, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness certification information.

[0322] It should be noted that the implementation and beneficial effects of each unit may also correspond to the corresponding description of the method embodiment shown in Figures 6, 7, 8, 9, 10, 11 or 12.

[0323] Optionally, the detailed description of each unit in the trust measurement device 1300 may also be as follows: The processing unit 1301 is configured to determine the measurement result of the first RAA network element; and the communication unit 1302 is configured to send the measurement result of the first RAA network element to the remote attestation service RAS network element.

[0324] In one possible implementation, the processing unit 1301 is further used to generate a second challenge value; the communication unit 1302 is further used to receive measurement information from the first RAA network element, where the measurement information is determined based on the second challenge value; and the processing unit 1301 is further used to verify the measurement information.

[0325] It should be noted that the implementation and beneficial effects of each unit may also correspond to the corresponding description of the method embodiment shown in FIG. 6 or FIG. 8 .

[0326] Optionally, the detailed description of each unit in the trust measurement device 1300 may also be as follows: The processing unit 1301 is used to determine the measurement result of the first remote attestation agent RAA network element; the communication unit 1302 is used to send the measurement result of the first RAA network element to the remote attestation service RAS network element.

[0327] It should be noted that the implementation and beneficial effects of each unit may also correspond to the corresponding description of the method embodiment shown in Figure 6 or Figure 10.

[0328] Please refer to Figure 14, which shows a trust measurement device 1400 provided in an embodiment of the present application. The trust measurement device 1400 includes at least one processor 1401 and a communication interface 1403, and optionally also includes a memory 1402. The processor 1401, the memory 1402, and the communication interface 1403 are interconnected via a bus 1404. Optionally, the at least one processor 1401 and the memory 1402 may be integrated together.

[0329] Memory 1402 includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM). Memory 1402 is used for storing computer programs and data. Communication interface 1403 is used to receive and send data.

[0330] The processor 1401 may be one or more central processing units (CPUs). When the processor 1401 is a CPU, the CPU may be a single-core CPU or a multi-core CPU.

[0331] The processor 1401 in the trusted measurement device 1400 is used to call the computer program stored in the memory 1402 to perform the following operations: obtain the measurement results of the first remote attestation agent RAA network element; receive a first request from the second RAA network element through the communication interface 1403, and the first request is used to request the measurement results of the first RAA network element; send the measurement results of the first RAA network element to the second RAA network element through the communication interface 1403.

[0332] In a possible implementation, the processor 1401 is configured to generate a measurement result of the first RAA network element.

[0333] In another possible implementation, the processor 1401 is further used to generate a first challenge value based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; the processor 1401 is further used to receive measurement information from the first RAA network element through the communication interface 1403, and the measurement information is determined based on the first challenge value; the processor 1401 is also used to verify the measurement information.

[0334] In another possible implementation manner, the first control message is sent by a management plane, or is a request message sent by the first RAA network element.

[0335] In yet another possible implementation, the processor 1401 is configured to, if the verification passes, sign the measurement information and generate a measurement result of the first RAA network element.

[0336] In yet another possible implementation, the processor 1401 is further configured to send the measurement result to the first RAA network element through the communication interface 1403 .

[0337] In yet another possible implementation, the processor 1401 is further configured to receive, through the communication interface 1403 , a measurement result of the first RAA network element sent from a third RAA network element.

[0338] In yet another possible implementation, the processor 1401 is further configured to receive, through the communication interface 1403 , a measurement result of the first RAA network element sent from a public verifier PVE.

[0339] In yet another possible implementation manner, the first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0340] In another possible implementation, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness certification information.

[0341] In another possible implementation, the processor 1401 is further used to obtain endorsement information and reference value information from a first remote attestation infrastructure RAI network element, and the endorsement information and the reference value information are used to verify the measurement information or the measurement result.

[0342] In yet another possible implementation, the processor 1401 is further configured to receive registered remote attestation capability information from the first RAA network element through the communication interface 1403 .

[0343] In yet another possible implementation, the processor 1401 is further configured to send the measurement result to the second RAI network element through the communication interface 1403 .

[0344] It should be noted that the implementation and beneficial effects of each operation may also correspond to the corresponding description of the method embodiment with reference to Figures 6, 7, 8, 9, 10, 11 or 12.

[0345] The processor 1401 in the trusted measurement device 1400 is used to call the computer program stored in the memory 1402, and perform the following operations: receiving a first challenge value through the communication interface 1403, the first challenge value being generated based on a preset period or a first control message, and the validity period of the first challenge value being a first duration; generating measurement information based on the first challenge value; and sending the measurement information to a remote attestation service RAS network element through the communication interface 1403.

[0346] In a possible implementation manner, the first control message is sent by a management plane, or is a request message sent by the first RAA network element.

[0347] In yet another possible implementation, the processor 1401 is further configured to receive the measurement result from the RAS through the communication interface 1403 .

[0348] It should be noted that the implementation and beneficial effects of each operation may also correspond to the corresponding description of the method embodiment shown in FIG. 6 or FIG. 7 .

[0349] The processor 1401 in the trusted measurement device 1400 is used to call the computer program stored in the memory 1402 and perform the following operations: sending a first request to the remote attestation service RAS network element through the communication interface 1403, wherein the first request is used to request the measurement result of the first RAA network element; and receiving the measurement result of the first RAA network element from the RAS network element through the communication interface 1403.

[0350] In a possible implementation manner, the first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

[0351] In another possible implementation, the measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature), or freshness certification information.

[0352] It should be noted that the implementation and beneficial effects of each operation may also correspond to the corresponding description of the method embodiment shown in Figures 6, 7, 8, 9, 10, 11 or 12.

[0353] The processor 1401 in the trust measurement device 1400 is used to call the computer program stored in the memory 1402 to perform the following operations: determine the measurement result of the first RAA network element; and send the measurement result of the first RAA network element to the remote attestation service RAS network element through the communication interface 1403.

[0354] In one possible implementation, the processor 1401 is further used to generate a second challenge value; the processor 1401 is further used to receive measurement information from the first RAA network element through the communication interface 1403, where the measurement information is determined based on the second challenge value; the processor 1401 is further used to verify the measurement information.

[0355] It should be noted that the implementation and beneficial effects of each operation may also correspond to the corresponding description of the method embodiment shown in FIG. 6 or FIG. 8 .

[0356] The processor 1401 in the trust measurement device 1400 is used to call the computer program stored in the memory 1402 to perform the following operations: determine the measurement result of the first remote attestation agent RAA network element; and send the measurement result of the first RAA network element to the remote attestation service RAS network element through the communication interface 1403.

[0357] It should be noted that the implementation and beneficial effects of each operation may also correspond to the corresponding description of the method embodiment shown in FIG. 6 or FIG. 10 .

[0358] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0359] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a base station or a terminal. Of course, the processor and the storage medium can also exist in a base station or a terminal as discrete components.

[0360] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.

[0361] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0362] In the description of this application, words such as "first", "second", "S601", or "S602" are only used to distinguish the description and facilitate the context. Different sequence numbers themselves do not have specific technical meanings and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying the order of execution of operations. The execution order of each process should be determined by its function and internal logic.

[0363] In this application, the term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. A and B can be singular or plural. Additionally, the character " / " in this document indicates that the related objects are in an "or" relationship.

[0364] In this application, "transmission" may include the following three situations: sending of data, receiving of data, or sending of data and receiving of data. In this application, "data" may include business data and / or signaling data.

[0365] In this application, the terms "comprise" or "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process / method comprising a series of steps, or a system / product / apparatus comprising a series of units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to these processes / methods / products / apparatus.

[0366] In the description of this application, unless otherwise specified, the number of nouns refers to "singular or plural," that is, "one or more." "At least one" means one or more. "Including at least one of the following: A, B, C" means that it may include A, or include B, or include C, or include A and B, or include A and C, or include B and C, or include A, B, and C. A, B, and C can be single or plural.

Claims

1. A credibility measurement method, characterized in that: include: The remote attestation service RAS network element obtains the measurement result of the first remote attestation agent RAA network element; The RAS network element receives a first request from a second RAA network element, where the first request is used to request a measurement result of the first RAA network element; The RAS network element sends the measurement result of the first RAA network element to the second RAA network element.

2. The method according to claim 1, characterized in that The RAS network element obtains the measurement result of the first RAA network element, including: The RAS network element generates a measurement result of the first RAA network element.

3. The method according to claim 2, characterized in that The method further comprises: The RAS network element generates a first challenge value based on a preset period or a first control message, where the validity period of the first challenge value is a first duration; The RAS network element receives measurement information from the first RAA network element, where the measurement information is determined based on the first challenge value; The RAS network element verifies the measurement information.

4. The method according to claim 3, characterized in that The first control message is sent by a management plane, or is a request message sent by the first RAA network element.

5. The method according to claim 3 or 4, further comprising: If the verification is successful, the RAS network element signs the measurement information and generates a measurement result of the first RAS network element.

6. The method according to any one of claims 2 to 5, characterized in that: The method further comprises: The RAS network element sends the measurement result to the first RAA network element.

7. The method according to claim 1, characterized in that The RAS network element obtains the measurement result of the first RAA network element, including: The RAS network element receives the measurement result of the first RAA network element sent by the third RAA network element.

8. The method according to claim 1, characterized in that The RAS network element obtains the measurement result of the first RAA network element, including: The RAS network element receives the measurement result of the first RAS network element sent from a public verifier PVE.

9. The method according to claim 1, characterized in that The first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

10. The method according to claim 9, characterized in that The measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature) or freshness certification information.

11. The method according to any one of claims 1 to 10, characterized in that The method further comprises: The RAS network element obtains endorsement information and reference value information from a first remote attestation infrastructure (RAI) network element, where the endorsement information and the reference value information are used to verify the measurement information or the measurement result.

12. The method according to any one of claims 1 to 11, characterized in that The method further comprises: The RAS network element receives the registered remote attestation capability information from the first RAA network element.

13. The method according to any one of claims 1 to 12, characterized in that The method further comprises: The RAS network element sends the measurement result to the second RAI network element.

14. A credibility measurement method, characterized in that: include: The first remote attestation agent RAA network element receives a first challenge value, where the first challenge value is generated based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; The first RAA network element generates measurement information according to the first challenge value; The first RAA network element sends the measurement information to a remote attestation service (RAS) network element.

15. The method according to claim 14, characterized in that The first control message is sent by a management plane, or is a request message sent by the first RAA network element.

16. The method according to claim 14 or 15, characterized in that The method further comprises: The first RAA network element receives the measurement result from the RAS.

17. A trust measurement device, characterized in that: The device comprises a processing unit and a communication unit, The processing unit is configured to obtain a measurement result of the first remote attestation agent RAA network element; The communication unit is configured to receive a first request from a second RAA network element, where the first request is used to request a measurement result of the first RAA network element; The communication unit is configured to send the measurement result of the first RAA network element to the second RAA network element.

18. The device according to claim 17, characterized in that The processing unit is configured to generate a measurement result of the first RAA network element.

19. The device according to claim 18, characterized in that The processing unit is further configured to generate a first challenge value based on a preset period or a first control message, wherein the validity period of the first challenge value is a first duration; The communication unit is further configured to receive measurement information from the first RAA network element, where the measurement information is determined based on the first challenge value; The processing unit is further configured to verify the measurement information.

20. The device according to claim 19, characterized in that The first control message is sent by a management plane, or is a request message sent by the first RAA network element.

21. The device according to claim 19 or 20, characterized in that The processing unit is configured to sign the measurement information and generate a measurement result of the first RAA network element if the verification is successful.

22. The device according to any one of claims 18 to 21, characterized in that The communication unit is further configured to send the measurement result to the first RAA network element.

23. The device according to claim 17, wherein The communication unit is further configured to receive a measurement result of the first RAA network element sent from a third RAA network element.

24. The device according to claim 17, wherein The communication unit is further configured to receive a measurement result of the first RAA network element sent from a public verifier PVE.

25. The device according to claim 17, wherein The first request includes one or more of the following: a user permanent identifier SUPI, a public key PK, or an international mobile equipment identity IMEI.

26. The device according to claim 25, characterized in that The measurement result of the first RAA network element includes one or more of the following: measurement information (evidence), verification type information, verifier list information (verifier list), random number (nonce), signature information (signature) or freshness certification information.

27. The device according to any one of claims 17 to 26, characterized in that The processing unit is further configured to obtain endorsement information and reference value information from a first remote attestation infrastructure (RAI) network element, where the endorsement information and the reference value information are used to verify the measurement information or the measurement result.

28. The device according to any one of claims 17 to 27, characterized in that The communication unit is further configured to receive registered remote attestation capability information from the first RAA network element.

29. The device according to any one of claims 17 to 28, characterized in that The communication unit is further configured to send the measurement result to the second RAI network element.

30. A trust measurement device, characterized in that: The device comprises a processing unit and a communication unit, The communication unit is configured to receive a first challenge value, where the first challenge value is generated based on a preset period or a first control message, and the validity period of the first challenge value is a first duration; the processing unit being configured to generate measurement information according to the first challenge value; The communication unit is configured to send the measurement information to a remote attestation service (RAS) network element.

31. The device according to claim 30, characterized in that The first control message is sent by a management plane, or is a request message sent by the first RAA network element.

32. The device according to claim 30 or 31, characterized in that The communication unit is further configured to receive the measurement result from the RAS.

33. A trust measurement device, characterized in that: The device includes at least one processor and a communication interface, wherein the at least one processor is configured to call a computer program stored in at least one memory, so that the device implements the method according to any one of claims 1 to 13.

34. A trust measurement device, characterized in that: The device includes at least one processor and a communication interface, wherein the at least one processor is configured to call a computer program stored in at least one memory, so that the device implements the method according to any one of claims 14 to 16.

35. A trust measurement system, characterized in that The system comprises the apparatus of claim 33 and the apparatus of claim 34.

36. A chip system, characterized in that: The chip system includes a logic circuit and an input / output interface, and the logic circuit is used to call a computer program stored in at least one memory to implement the method according to any one of claims 1 to 16.

37. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and when the computer instructions are executed on a processor, the method according to any one of claims 1 to 16 is implemented.

38. A computer program product, characterized in that When the computer program product is run on a processor, the method according to any one of claims 1 to 16 is implemented.