Communication method and communication device

By negotiating and determining the key negotiation algorithm between the verification network element and the communication device, the problem of restricted application scenarios caused by the fixation of the key exchange algorithm in the prior art is solved, and the security and flexibility of key exchange are improved to adapt to diversified network needs.

CN120358491APending Publication Date: 2025-07-22HUAWEI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410095116.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In the prior art, the terminal and the network side use a fixed key exchange algorithm to generate shared keys, resulting in limited application scenarios and unable to adapt to the diversified needs of different security levels, computing complexity and network standards.

Method used

The key negotiation algorithm is determined through verification negotiation between the network element and the communication device, and supports a variety of algorithms such as ECDH, ECDHE, PQC, etc., and flexibly selects the appropriate key negotiation algorithm based on the security level, calculation complexity and device type, and enhances security through post-quantum algorithms.

Benefits of technology

It realizes the flexible choice of key negotiation algorithm, adapts to more application scenarios, improves the security of key exchange and the flexibility of authentication processes, and is suitable for different security levels and network standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358491A_ABST
    Figure CN120358491A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and a communication device, and the method comprises the steps: receiving first indication information from the communication device, and enabling the first indication information to indicate at least one key negotiation algorithm; sending second indication information to the communication device, the second indication information indicating a first key negotiation algorithm, the first key negotiation algorithm being one of the at least one key negotiation algorithm, the first key negotiation algorithm being used to determine a first key, and the first key negotiation algorithm being used to determine a second key; the first key is used for encrypting or decrypting a message transmitted between the communication device and the verification network element. The key agreement algorithm in the authentication process is determined through agreement between the verification network element and the communication device, so that selection of the key agreement algorithm in the authentication process is more flexible, and the method is suitable for more application scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and more particularly, to a communication method and a communication device. Background Art

[0002] In terms of network security, the tasks of the network include: authenticating and authorizing the terminals accessing the network so that the terminals can access the operator network, and then initiating the air interface encryption of the service communication of the terminals. At present, the terminal and the network use the elliptic curve Diffie–Hellman (ECDH) key negotiation to generate a shared key; the terminal transmits the identification information of the terminal based on the shared key so that the network side can obtain the root key corresponding to the identification information of the terminal device, thereby completing the mutual authentication. In the above solution, the network side and the terminal use a fixed key exchange algorithm to generate a shared key, and the application scenarios are limited. Summary of the Invention

[0003] This application provides a communication method and a communication device, which can improve the flexibility of user access to the network.

[0004] In a first aspect, a communication method is provided. This method can be executed by an authentication network element, or can also be executed by a component (such as a chip or a circuit) of the authentication network element. There is no limitation in this regard. For the sake of description, the following takes the execution by the authentication network element as an example for illustration.

[0005] The method includes: receiving first indication information from a communication device, where the first indication information indicates at least one key negotiation algorithm; sending second indication information to the communication device, where the second indication information indicates a first key negotiation algorithm, and the first key negotiation algorithm is one of the at least one key negotiation algorithm, and the first key negotiation algorithm is used to determine a first key, and the first key is used to encrypt or decrypt the messages transmitted between the communication device and the authentication network element.

[0006] Based on the above solution, the authentication network element and the communication device can negotiate to determine the key negotiation algorithm in the authentication process, making the selection of the key negotiation algorithm in the authentication process more flexible and adaptable to more application scenarios. That is, the communication device indicates at least one key negotiation algorithm to the authentication network element, and the authentication network element determines a first key negotiation algorithm from the at least one key negotiation algorithm, and the first key negotiation algorithm is used for the first key.

[0007] In some implementations of the first aspect, the first key negotiation algorithm is determined according to the first information and the first indication information, where the first information includes at least one of the following: the security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.

[0008] Based on the above solution, by determining the first key negotiation algorithm according to the first information, the first key negotiation algorithm can be made applicable to at least one of different security levels, computational complexities, network modes, types of communication devices, and computing powers of communication devices.

[0009] In some implementations of the first aspect, the at least one key negotiation algorithm includes at least one of the following:

[0010] Elliptic Curve Diffie–Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie–Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on post-quantum cryptography (PQC), key negotiation algorithm based on PQC and ECDH, key negotiation algorithm based on PQC and ECDHE, and key negotiation algorithm based on a pre-shared key.

[0011] In some implementations of the first aspect, the first key is determined based on the first key negotiation algorithm.

[0012] In some implementations of the first aspect, the first key negotiation algorithm is the ECDHE key negotiation algorithm. In the ECDHE key negotiation algorithm, the authentication network element receives a first public key from the communication device, and the first public key is the public key in the first temporary public-private key pair generated by the communication device; the authentication network element determines the first key based on the first public key and a second private key, and the second private key is the private key in the second temporary public-private key pair generated by the authentication network element.

[0013] Based on the above solution, the authentication network element and the communication device can negotiate to determine to use the ECDHE key negotiation algorithm. In the ECDHE key negotiation algorithm, the authentication network element and the communication device use the temporary public keys generated by each other to generate the first key, improving the security of key exchange. Secondly, the computational complexity of this key negotiation algorithm is relatively low and can be applicable to communication scenarios with relatively low computational complexity requirements for the key negotiation algorithm and relatively high security requirements.

[0014] In some implementations of the first aspect, the authentication network element sends a second public key to the communication device, where the second public key is the public key in the second temporary public-private key pair. By sending the second public key to the communication device, the communication device can determine the first key based on the second public key.

[0015] In some implementations of the first aspect, the first key negotiation algorithm is the PQC-based key negotiation algorithm. In the PQC-based key negotiation algorithm, the authentication network element receives a third public key from the communication device, where the third public key is the public key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; the authentication network element inputs the third public key into the post-quantum algorithm to generate a ciphertext and the first key.

[0016] Based on the above solution, the authentication network element and the communication device can negotiate and determine to use the PQC-based key negotiation algorithm. In the PQC-based key negotiation algorithm, the authentication network element and the communication device use PQC to generate the first key, which can improve the security of key exchange. This key negotiation algorithm is applicable to communication scenarios with high security requirements.

[0017] In some implementations of the first aspect, the authentication network element sends the ciphertext to the communication device. By sending the ciphertext to the communication device, the communication device can determine the first key based on the ciphertext.

[0018] In some implementations of the first aspect, the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDH. In the key negotiation algorithm based on PQC and ECDH, the authentication network element receives a first public key and a third public key from the communication device. The first public key is the public key in the first temporary public-private key pair generated by the communication device, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; the authentication network element determines a second key based on the first public key and its own private key, and inputs the third public key into the post-quantum algorithm to generate a ciphertext and a third key; the authentication network element determines the first key based on the second key and the third key.

[0019] Based on the above solution, the authentication network element and the communication device can negotiate and determine to use the key negotiation algorithm based on PQC and ECDH. In the key negotiation algorithm based on PQC and ECDH, the authentication network element and the communication device can generate the first key based on the key generated by PQC and the key generated by ECDH, improving the security of key exchange. Compared with the PQC-based key negotiation algorithm, this key negotiation algorithm is applicable to communication scenarios with higher security requirements.

[0020] In certain implementations of the first aspect, the authentication network element sends the public key of the authentication network element and the ciphertext to the communication device, and the public key of the authentication network element and the ciphertext are used by the communication device to determine the first key.

[0021] In certain implementations of the first aspect, the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. In the key negotiation algorithm based on PQC and ECDHE, the authentication network element receives the first public key and the third public key from the communication device. The first public key is the public key in the first temporary public-private key pair generated by the communication device, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm. The authentication network element determines the second key based on the first public key and the second private key. The second private key is the private key in the second temporary public-private key pair generated by the authentication network element, and inputs the third public key into the post-quantum algorithm to generate the ciphertext and the third key. The authentication network element determines the first key based on the second key and the third key.

[0022] Based on the above solution, the authentication network element and the communication device can negotiate and determine to use the key negotiation algorithm based on PQC and ECDHE. In the key negotiation algorithm based on PQC and ECDH, the authentication network element and the communication device can generate the first key based on the key generated by PQC and the key generated by ECDHE, improving the security of key exchange. Among them, ECDHE has forward security. Compared with the key negotiation algorithm based on PQC and ECDH, this key negotiation algorithm is applicable to communication scenarios with higher security requirements.

[0023] In certain implementations of the first aspect, the authentication network element sends the second public key and the ciphertext to the communication device. The second public key is the public key in the second temporary public-private key pair. By sending the second public key and the ciphertext to the communication device, the communication device can determine the first key based on the second public key and the ciphertext.

[0024] In certain implementations of the first aspect, the authentication network element sends the first digital signature to the communication device. The first digital signature is the signature of the private key of the authentication network element on the first message, and the first message includes the messages exchanged between the authentication network element and the communication device. And the authentication network element sends the certificate of the authentication network element to the communication device. The certificate includes the public key of the authentication network element, and the public key of the authentication network element is used by the communication device to verify the first digital signature.

[0025] Exemplarily, the messages that the authentication network element has interacted with the communication device may include the most recent message sent by the authentication network element to the terminal device. For example, the message carrying the first digital signature; or the interacted messages may include all the messages that the authentication network element has interacted with the communication device before sending the most recent message to the communication device (for example, the messages in which the communication device sends the first public key or the third public key to the authentication network element, denoted as message #1, to the message in which the authentication network element sends the first digital signature, denoted as message #2, the interacted messages between the authentication network element and the communication device may include message #1 and message #2). Optionally, before the authentication network element sends the first digital signature to the communication device, the authentication network element may store the messages that have interacted with the communication device.

[0026] Exemplarily, the messages that the authentication network element has interacted with the communication device may also include the message sending the first digital signature. For example, the message sending the first digital signature is a radio resource control (RRC) message or a non-access stratum (NAS) message.

[0027] Based on the above solution, by sending the certificate of the authentication network element and the first digital signature to the communication device, the communication device can authenticate the authentication network element, simplifying the process of the communication device authenticating the authentication network element and saving signaling overhead.

[0028] In some implementation manners of the first aspect, a request message from the communication device is received. The request message is used to request access to the network. The request message includes a first identifier encrypted by the first key. The first identifier has a corresponding relationship with the authentication information of the communication device; the authentication network element obtains the first authentication information in the authentication information according to the first identifier; and authenticates the communication device based on the first authentication information.

[0029] Based on the above solution, the authentication network element obtains the authentication information required by the communication device corresponding to the first identifier based on the first identifier, and authenticates the communication device according to the authentication information, which can improve the flexibility of authenticating the communication device.

[0030] In some implementation manners of the first aspect, before receiving the request message from the communication device, third indication information from the communication device is received. The third indication information indicates at least one authentication method. The authentication information of the communication device indicated by each authentication method in the at least one authentication method is independent of each other; fourth indication information is sent to the communication device. The fourth indication information indicates a first authentication method. The first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.

[0031] Based on the above solution, it is possible to determine the authentication method through negotiation between the verification network element and the communication device, making the selection of the authentication method more flexible and adaptable to more application scenarios, that is, the communication device indicates at least one authentication method to the verification network element, and the verification network element determines the first authentication method from the at least one authentication method.

[0032] In some implementations of the first aspect, the authentication information includes any one of the following information: the credential of the communication device, the cryptographic algorithm; wherein, the credential of the communication device includes the public key of the communication device, and the cryptographic algorithm includes the signature algorithm applicable to the communication device.

[0033] Based on the above solution, by determining the first authentication method according to the third information, the first authentication method can be made applicable to different credentials and cryptographic algorithms of the communication device.

[0034] In some implementations of the first aspect, the types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier includes at least one of the following: the identifier of the first type of the communication device, the identifier of the second type of the communication device, the identifier of the block or the transaction, the virtual identifier of the communication device; wherein, the identifier of the first type has a first corresponding relationship with the root key of the communication device, the identifier of the second type has a second corresponding relationship with at least one credential of the communication device, the identifier of the block or the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the identifier of the second type.

[0035] Based on the above solution, the verification network element can obtain the authentication information of the communication device based on different identifiers, making the authentication process applicable to multiple scenarios. Exemplarily, the identifier of the first type can be compatible with the 5G communication system; compared with the identifier of the first type, the identifier of the second type can be applied to scenarios where high confidentiality requirements for personal information are required; in some scenarios, the communication security can be further enhanced by using the virtual identifier.

[0036] In some implementations of the first aspect, the first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: the issuer of the credential of the communication device, the security level of the credential of the communication device, the cryptographic algorithm corresponding to the credential of the communication device.

[0037] Based on the above solution, the verification network element can make the authentication process more flexible based on at least one of the issuer of the credential of the communication device used in the selected authentication process, the security level of the credential of the communication device, and the cryptographic algorithm corresponding to the credential of the communication device.

[0038] In certain implementations of the first aspect, the first authentication information includes a first credential of the communication device, and the first credential is verified based on the credential of the issuer of the first credential; a second digital signature is received from the communication device, where the second digital signature is a signature of a second message by the private key of the communication device, and the second message includes messages that the communication device has interacted with the verification network element; the second digital signature is verified based on the public key corresponding to the first credential.

[0039] Exemplarily, the messages that the communication device and the verification network element have interacted with can include the most recent message sent by the communication device to the verification network element. For example, the interacted message can include the message carrying the second digital signature; or the interacted message can include the messages after (including) the communication device sends the request message to the verification network element and before the most recent message sent to the verification network element (which can include the most recent message sent to the verification network element). For example, the most recent message sent is the message carrying the second digital signature. Optionally, before the communication device sends the second digital signature to the verification network element, the communication device can store the messages that have interacted with the verification network element.

[0040] Among them, the message carrying the first digital signature can be an RRC message or an NAS message.

[0041] Based on the above solution, the verification network element can verify the communication device by using the first credential to verify the signature of the interacted messages by the communication device; verifying the first credential by the credential of the issuer of the first credential can determine the security of the first credential, thereby enhancing the security of the authentication process.

[0042] In a second aspect, a communication method is provided. This method can be executed by a verification network element, or can also be executed by a component (such as a chip or a circuit) of the verification network element. There is no limitation in this regard. For the sake of description, the following takes the execution by the verification network element as an example for illustration.

[0043] The method includes: receiving a temporary public key from a communication device, where the temporary public key is the public key in a temporary public-private key pair generated by the communication device; authenticating the communication device based on a first key, where the first key is determined based on the temporary public key and a second private key, and the second private key is the private key of the verification network element or the private key in a temporary public-private key pair generated by the verification network element, or the first key is generated by inputting the temporary public key into a post-quantum algorithm.

[0044] Based on the above solution, the authentication network element can authenticate the communication device based on the first key. The first key is determined based on the temporary public key of the communication device and the private key of the authentication network element or the private key in the temporary public-private key pair generated by the authentication network element. Alternatively, the first key is generated by inputting the temporary public key into a post-quantum algorithm, thereby ensuring the security of the first key and enhancing the security of authenticating the communication device based on the first key.

[0045] In some implementations of the second aspect, if the first key is determined based on the temporary public key and the second private key, where the second private key is the private key in the temporary public-private key pair generated by the authentication network element, the authentication network element sends the second public key to the communication device. The second public key includes the public key in the temporary public-private key pair generated by the authentication network element, and the second public key is used by the communication device to determine the first key.

[0046] Based on the above solution, the authentication network element sending the public key in the temporary public-private key pair generated by the authentication network element to the communication device can enable the communication device to determine the first key based on the temporary public key, enhancing the security of the first key determined by the communication device, and thus improving the security of authentication.

[0047] In some implementations of the second aspect, the temporary public key is the third public key, which is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.

[0048] Based on the above solution, by inputting the temporary public key of the communication device into a post-quantum algorithm to obtain the first key, the security of the first key can be enhanced, thereby improving the security of authentication.

[0049] In some implementations of the second aspect, a ciphertext is sent to the communication device, and the ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext is used by the communication device to determine the first key.

[0050] Based on the above solution, by sending the ciphertext to the communication device, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm, the communication device can generate the first key based on the ciphertext, which can enhance the security of the first key, and thus improve the security of authentication.

[0051] In some implementations of the second aspect, the temporary public key includes a first public key and a third public key. The first public key is the public key in a first temporary public-private key pair generated by the communication device, and the third public key is the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm. The first key is determined based on a second key and a third key. The second key is determined according to the second private key and the first public key, and the third key is generated by inputting the third public key into the post-quantum algorithm.

[0052] Based on the above solution, the authentication network element can generate a second key based on the first public key generated by the communication device, and generate a third key according to the third public key generated by the communication device based on the post-quantum algorithm. By generating the first key based on the second key and the third key, the security of the first key can be improved, thereby improving the security of authentication.

[0053] In some implementations of the second aspect, a ciphertext and a second public key are sent to the communication device. The second public key includes the public key of the authentication network element or the public key in a temporary public-private key pair generated by the authentication network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm. The ciphertext and the second public key are used by the communication device to determine the first key.

[0054] Based on the above solution, by sending the ciphertext and the second public key to the communication device, the communication device can generate the first key based on the ciphertext and the second public key, which can improve the security of the first key, thereby improving the security of authentication.

[0055] In some implementations of the second aspect, the temporary public key is sent according to second indication information. The second indication information indicates a first key negotiation algorithm, and the first key negotiation algorithm is one of at least one key negotiation algorithm. Before receiving the temporary public key from the communication device, first indication information from the communication device is received. The first indication information indicates the at least one key negotiation algorithm; and the second indication information is sent to the communication device.

[0056] Based on the above solution, the authentication network element and the communication device can negotiate to determine the key negotiation algorithm in the authentication process, making the selection of the key negotiation algorithm in the authentication process more flexible and adapting to more application scenarios.

[0057] In some implementations of the second aspect, the first key negotiation algorithm is determined according to first information and the first indication information. The first information includes at least one of the following information: the security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.

[0058] Wherein, the at least one key negotiation algorithm refers to the description in the first aspect.

[0059] In some implementations of the second aspect, a first digital signature is sent to the communication device, where the first digital signature is a signature of a first message by the private key of the authentication network element, and the first message includes messages exchanged between the authentication network element and the communication device; a certificate of the authentication network element is sent to the communication device, where the certificate includes the public key of the authentication network element, and the public key of the authentication network element is used by the communication device to verify the first digital signature. Among them, the messages exchanged between the authentication network element and the communication device may refer to the description in the first aspect.

[0060] Based on the above solution, by sending the first digital signature and the certificate of the authentication network element to the communication device, the communication device can verify the first digital signature based on the certificate of the authentication network element, and then verify the authentication network element. This authentication method simplifies the authentication process and can save signaling overhead.

[0061] In some implementations of the second aspect, a request message is received from the communication device, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, and the first identifier has a corresponding relationship with the authentication information of the communication device; the authentication network element obtains the first authentication information in the authentication information according to the first identifier; and authenticates the communication device based on the first authentication information.

[0062] Based on the above solution, the authentication network element obtains the authentication information required by the communication device corresponding to the first identifier based on the first identifier, and authenticates the communication device according to the authentication information, which can improve the flexibility of authenticating the communication device.

[0063] In some implementations of the second aspect, before receiving the request message from the communication device, a third indication information is received from the communication device, where the third indication information indicates at least one authentication method, and the authentication information corresponding to each authentication method in the at least one authentication method is independent of each other; a fourth indication information is sent to the communication device, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication method, and the first authentication method corresponds to the first authentication information.

[0064] Based on the above solution, the authentication method can be determined through negotiation between the authentication network element and the communication device, making the selection of the authentication method more flexible and adaptable to more application scenarios, that is, the communication device indicates at least one authentication method to the authentication network element, and the authentication network element determines the first authentication method from the at least one authentication method.

[0065] In some implementations of the second aspect, the authentication information indicates any one of the following: a credential of the communication device, a cryptographic algorithm; wherein the credential of the communication device includes a public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.

[0066] Based on the above solution, by determining the first authentication method according to the third information, the first authentication method can be made applicable to different credentials and cryptographic algorithms of the communication device.

[0067] In some implementations of the second aspect, the types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier includes at least one of the following: a first type of identifier of the communication device, a second type of identifier of the communication device, an identifier of a block or a transaction, a virtual identifier of the communication device; wherein the first type of identifier has a first corresponding relationship with the root key of the communication device, the second type of identifier has a second corresponding relationship with at least one credential of the communication device, the identifier of the block or the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.

[0068] Based on the above solution, the verification network element can obtain the authentication information of the communication device based on different identifiers, which can make the authentication process applicable to multiple scenarios.

[0069] In some implementations of the second aspect, the first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: an issuer of the credential of the communication device, a security level of the credential of the communication device, a cryptographic algorithm corresponding to the credential of the communication device.

[0070] Based on the above solution, the verification network element can make the authentication process more flexible by selecting at least one of the issuer of the credential of the communication device, the security level of the credential of the communication device, and the cryptographic algorithm corresponding to the credential of the communication device used in the authentication process.

[0071] In some implementations of the second aspect, the first authentication information includes a first credential of the communication device, and the first credential is verified based on a credential of the issuer of the first credential; a second digital signature is received from the communication device, the second digital signature is a signature of the communication device on a second message, and the second message includes a message that the communication device has interacted with the verification network element; the second digital signature is verified based on the public key corresponding to the first credential. Among them, the message that the communication device has interacted with the verification network element can refer to the description in the first aspect.

[0072] Based on the above solution, the authentication network element can verify the signature of the messages exchanged by the communication device using the first credential, and verify the communication device; by verifying the first credential through the credential of the issuer of the first credential, the security of the first credential can be determined, thereby enhancing the security of the authentication process.

[0073] In a third aspect, a communication method is provided. This method can be executed by a communication device, or can also be executed by a component (such as a chip or a circuit) of the communication device. There is no limitation in this regard. For the sake of description, the following will take the execution by the communication device as an example for illustration.

[0074] The method includes: sending first indication information to the authentication network element, where the first indication information indicates at least one key negotiation algorithm; receiving second indication information from the authentication network element, where the second indication information indicates a first key negotiation algorithm, and the first key negotiation algorithm is one of the at least one key negotiation algorithm, and the first key negotiation algorithm is used to determine a first key, and the first key is used to encrypt or decrypt the messages transmitted between the communication device and the authentication network element.

[0075] Based on the above solution, the key negotiation algorithm in the authentication process can be determined through negotiation between the authentication network element and the communication device, making the selection of the key negotiation algorithm in the authentication process more flexible and adaptable to more application scenarios. That is, the communication device indicates at least one key negotiation algorithm to the authentication network element, and the authentication network element determines a first key negotiation algorithm from the at least one key negotiation algorithm, and the first key negotiation algorithm is used for the first key.

[0076] In some implementation manners of the third aspect, the first key negotiation algorithm is determined according to the first information and the first indication information, and the first information includes at least one of the following information: the security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.

[0077] Based on the above solution, by determining the first key negotiation algorithm according to the first information, the first key negotiation algorithm can be made applicable to at least one of different security levels, computational complexities, network modes, types of communication devices, and computing powers of communication devices.

[0078] Among them, the at least one key negotiation algorithm refers to the description in the first aspect.

[0079] In some implementation manners of the third aspect, the first key is determined based on the first key negotiation algorithm.

[0080] In some implementations of the third aspect, the first key negotiation algorithm is the ECDHE key negotiation algorithm. In the ECDHE key negotiation algorithm, a second public key from the authentication network element is received, and the second public key is the public key in the second temporary public-private key pair generated by the authentication network element; the first key is determined based on the second public key and the first private key, and the first private key is the private key in the first temporary public-private key pair generated by the communication device.

[0081] Based on the above solution, determining the first key according to the public key in the second temporary public-private key pair generated by the received authentication network element and the private key in the first temporary public-private key pair generated by the communication device can improve the security of the first key, thereby improving the security of authentication.

[0082] In some implementations of the third aspect, a first public key is sent to the authentication network element, and the first public key is the public key in the first temporary public-private key pair, and the first public key is used by the authentication network element to determine the first key.

[0083] In some implementations of the third aspect, the first key negotiation algorithm is the PQC-based key negotiation algorithm. In the PQC-based key negotiation algorithm, a ciphertext from the authentication network element is received, and the ciphertext is generated by the authentication network element based on a post-quantum algorithm; the ciphertext and a third private key are input into the post-quantum algorithm to generate the first key, and the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm.

[0084] Based on the above solution, determining the first key according to the ciphertext generated by the received authentication network element and the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm can improve the security of the first key, thereby improving the security of authentication.

[0085] In some implementations of the third aspect, a third public key is sent to the authentication network element, and the third public key is the public key in the third temporary public-private key pair, and the third public key is used by the authentication network element to determine the first key.

[0086] In some implementations of the third aspect, the first key negotiation algorithm is the PQC- and ECDH-based key negotiation algorithm. In the PQC- and ECDH-based key negotiation algorithm, a ciphertext and the public key of the authentication network element are received, and the ciphertext is generated by the authentication network element based on a post-quantum algorithm; a second key is determined based on the public key of the authentication network element and the first private key, and the first private key is the private key in the first temporary public-private key pair generated by the communication device; the ciphertext and a third private key are input into the post-quantum algorithm to generate a third key, and the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; the first key is determined based on the second key and the third key.

[0087] Based on the above solution, a second key is determined according to the public key of the verification network element received and the private key in the first temporary public-private key pair generated by the communication device, and a third key is determined according to the ciphertext generated by the received verification network element and the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; and the first key is determined according to the second key and the third key, which can improve the security of the first key, thereby improving the security of authentication.

[0088] In some implementations of the third aspect, the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. In the key negotiation algorithm based on PQC and ECDHE, a ciphertext and a second public key from the verification network element are received. The ciphertext is generated by the verification network element based on the post-quantum algorithm, and the second public key is the public key in the second temporary public-private key pair generated by the verification network element; a second key is determined based on the second public key and the first private key, where the first private key is the private key in the first temporary public-private key pair generated by the communication device; the ciphertext and the third private key are input into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; the first key is determined based on the second key and the third key.

[0089] Based on the above solution, a second key is determined according to the public key in the second temporary public-private key pair generated by the received verification network element and the private key in the first temporary public-private key pair generated by the communication device, and a third key is determined according to the ciphertext generated by the received verification network element and the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; and the first key is determined according to the second key and the third key, which can improve the security of the first key, thereby improving the security of authentication.

[0090] In some implementations of the third aspect, a first public key and a third public key are sent to the verification network element. The first public key is the public key in the first temporary public-private key pair, and the third public key is the public key in the third temporary public-private key pair. The first public key and the third public key are used by the verification network element to determine the first key.

[0091] In some implementations of the third aspect, a first digital signature from the verification network element is received. The first digital signature is a signature of the first message by the private key of the verification network element, and the first message includes the messages exchanged between the verification network element and the communication device; a certificate of the verification network element is received from the verification network element, and the certificate includes the public key of the verification network element; the first digital signature is verified based on the public key of the verification network element. Among them, the messages exchanged between the verification network element and the communication device can refer to the description in the first aspect.

[0092] Based on the above solution, by receiving the certificate of the authentication network element and the first digital signature, the communication device can authenticate the authentication network element, simplifying the process of the communication device authenticating the authentication network element and saving signaling overhead.

[0093] In some implementations of the third aspect, a request message is sent to the authentication network element. The request message is used to request access to the network and includes a first identifier encrypted by the first key. The first identifier has a corresponding relationship with the authentication information of the communication device. The authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.

[0094] Based on the above solution, by sending the request message to the authentication network element, the authentication network element can obtain the authentication information required by the communication device corresponding to the first identifier based on the first identifier, and authenticate the communication device according to the authentication information, which can improve the flexibility of authenticating the communication device.

[0095] In some implementations of the third aspect, before sending the request message to the authentication network element, third indication information is sent to the authentication network element. The third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other; fourth indication information from the authentication network element is received. The fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication method, and the first authentication method corresponds to the first authentication information.

[0096] Based on the above solution, the authentication method can be determined through negotiation between the authentication network element and the communication device, making the selection of the authentication method more flexible and adaptable to more application scenarios, that is, the communication device indicates at least one authentication method to the authentication network element, and the authentication network element determines the first authentication method from the at least one authentication method.

[0097] In some implementations of the third aspect, the authentication information includes any one of the following: the credential of the communication device, the cryptographic algorithm; wherein, the credential of the communication device includes the public key of the communication device, and the cryptographic algorithm includes the signature algorithm applicable to the communication device.

[0098] Based on the above solution, by determining the first authentication method according to the third information, the first authentication method can be applicable to different credentials and cryptographic algorithms of the communication device.

[0099] In some implementations of the third aspect, the types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier includes at least one of the following: an identifier of a first type of the communication device, an identifier of a second type of the communication device, an identifier of a block or a transaction, or a virtual identifier of the communication device; wherein, the identifier of the first type has a first correspondence with the root key of the communication device, the identifier of the second type has a second correspondence with at least one credential of the communication device, the identifier of the block or the transaction is used to obtain the second correspondence saved on the blockchain, and the virtual identifier has a correspondence with the identifier of the second type.

[0100] Based on the above solution, the authentication network element can obtain the authentication information of the communication device based on different identifiers, which can make the authentication process applicable to multiple scenarios. Among them, the scenarios applicable to each identifier can refer to the description in the first aspect.

[0101] In some implementations of the third aspect, the first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: the issuer of the credential of the communication device, the security level of the credential of the communication device, or the cryptographic algorithm corresponding to the credential of the communication device.

[0102] Based on the above solution, the authentication network element can be based on at least one of the issuer of the credential of the communication device, the security level of the credential of the communication device, or the cryptographic algorithm corresponding to the credential of the communication device used in the authentication process, making the authentication process more flexible.

[0103] In some implementations of the third aspect, a second digital signature is sent to the authentication network element, and the second digital signature is the signature of the second message by the private key of the communication device. The second message includes the messages interacted between the communication device and the authentication network element, and the second digital signature is used for the authentication network element to authenticate the communication device. Among them, the messages interacted between the communication device and the authentication network element can refer to the description in the first aspect.

[0104] Based on the above solution, by sending the second digital signature to the authentication network element, the authentication network element can verify the communication device by using the first credential to verify the signature of the interacted messages by the communication device, and determine the security of the first credential by verifying the first credential with the credential of the issuer of the first credential, thereby improving the security of the authentication process.

[0105] In the fourth aspect, a communication method is provided. This method can be executed by a communication device, or can also be executed by a component (such as a chip or a circuit) of the communication device, and this is not limited. For the sake of description, the following takes the execution by the communication device as an example for illustration.

[0106] The method includes: sending a temporary public key to the authentication network element, where the temporary public key is the public key in a temporary public-private key pair generated by the communication device, and the temporary public key is used to determine a first key, and the first key is used by the authentication network element to authenticate the communication device; wherein, the first key is determined based on the temporary public key and a second private key, and the second private key is the private key of the authentication network element or the private key in a temporary public-private key pair generated by the authentication network element; or, the first key is generated by inputting the temporary public key into a post-quantum algorithm.

[0107] Based on the above solution, by sending a temporary public key to the authentication network element, the authentication network element can determine a first key based on the temporary public key and authenticate the communication device based on the first key. Among them, the first key is determined based on the temporary public key of the communication device and the private key of the authentication network element or the private key in a temporary public-private key pair generated by the authentication network element, or the first key is generated by inputting the temporary public key into a post-quantum algorithm, thereby ensuring the security of the first key and enhancing the security of authenticating the communication device based on the first key.

[0108] In some implementation manners of the fourth aspect, if the first key is determined based on the temporary public key of the communication device and the private key in a temporary public-private key pair generated by the authentication network element, the method further includes: receiving a second public key from the authentication network element, where the second public key is the public key in a second temporary public-private key pair generated by the authentication network element; determining the first key based on a first private key and the second public key, and the first public key is the private key in the first temporary public-private key pair.

[0109] Based on the above solution, the device can determine the first key based on the temporary public key generated by the authentication network element, enhancing the security of the first key, and thus the security of authentication can be enhanced.

[0110] In some implementation manners of the fourth aspect, the temporary public key is a third public key, and the third public key is the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.

[0111] Based on the above solution, by inputting the temporary public key of the communication device into a post-quantum algorithm to obtain the first key, the security of the first key can be enhanced, and thus the security of authentication can be enhanced.

[0112] In some implementation manners of the fourth aspect, the method further includes: receiving a ciphertext from the authentication network element, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm; inputting the ciphertext and a third private key into the post-quantum algorithm to generate the first key, and the third private key is the private key in the third temporary public-private key pair.

[0113] Based on the above solution, by sending the ciphertext to the communication device and generating the first key by inputting the ciphertext and the third private key into the post-quantum algorithm, the security of the first key can be improved, thereby improving the security of authentication.

[0114] In some implementations of the fourth aspect, the temporary public key includes a first public key and a third public key. The first public key is the public key in the first temporary public-private key pair generated by the communication device, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm. The first key is determined based on a second key and a third key. The second key is determined according to the second private key and the first public key, and the third key is generated by inputting the third public key into the post-quantum algorithm.

[0115] Based on the above solution, by generating the first key based on the second key and the third key, the security of the first key can be improved, thereby improving the security of authentication.

[0116] In some implementations of the fourth aspect, receive the ciphertext and the second public key from the verification network element. The second public key includes the public key of the verification network element or the public key in the temporary public-private key generated by the verification network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm; generate a second key based on the first private key and the second public key, where the first private key is the private key in the first public-private key pair; input the ciphertext and the third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third public-private key pair; determine the first key based on the second key and the third key.

[0117] Based on the above solution, determine the second key according to the public key of the received verification network element or the public key in the temporary public-private key generated by the verification network element, and the private key in the first temporary public-private key pair generated by the communication device, and determine the third key according to the ciphertext received from the verification network element and the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; and determine the first key according to the second key and the third key, which can improve the security of the first key, thereby improving the security of authentication.

[0118] In some implementations of the fourth aspect, the temporary public key is sent according to the second indication information, and the second indication information indicates the first key negotiation algorithm. The first key negotiation algorithm is one of at least one key negotiation algorithm. Before receiving the temporary public key from the communication device, send the first indication information to the verification network element, and the first indication information indicates the at least one key negotiation algorithm; receive the second indication information from the verification network element.

[0119] Based on the above solution, the authentication network element and the communication device can negotiate to determine the key negotiation algorithm in the authentication process, making the selection of the key negotiation algorithm in the authentication process more flexible and adaptable to more application scenarios.

[0120] In some implementation manners of the fourth aspect, the first key negotiation algorithm is determined according to the first information and the first indication information, and the first information includes at least one of the following information: the security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.

[0121] Wherein, the at least one key negotiation algorithm refers to the description in the first aspect.

[0122] In some implementation manners of the fourth aspect, the method further includes: receiving a first digital signature from the authentication network element, where the first digital signature is a signature of the private key of the authentication network element on a first message, and the first message includes messages interacted between the authentication network element and the communication device; receiving a certificate of the authentication network element from the authentication network element, where the certificate includes the public key of the authentication network element; and verifying the first digital signature based on the public key of the authentication network element. Wherein, the messages interacted between the authentication network element and the communication device can refer to the description in the first aspect.

[0123] Based on the above solution, by receiving the first digital signature from the authentication network element and the certificate of the authentication network element, the communication device can verify the first digital signature based on the certificate of the authentication network element, and further verify the authentication network element. This authentication method simplifies the authentication process and can save signaling overhead.

[0124] In some implementation manners of the fourth aspect, a request message is sent to the authentication network element, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the communication device using the first key, and the first identifier has a corresponding relationship with the authentication information of the communication device, and the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.

[0125] Based on the above solution, by sending a request message to the authentication network element, the authentication network element can obtain the authentication information required by the communication device corresponding to the first identifier based on the first identifier, and authenticate the communication device according to the authentication information, which can improve the flexibility of authenticating the communication device.

[0126] In some implementations of the fourth aspect, before sending a request message to the authentication network element, a third indication message is sent to the authentication network element, where the third indication message indicates at least one authentication method, and the authentication information corresponding to each authentication method in the at least one authentication method is independent of each other; a fourth indication message is received from the authentication network element, where the fourth indication message indicates a first authentication method, the first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.

[0127] Based on the above solution, the authentication network element and the communication device can determine the authentication method through negotiation, making the selection of the authentication method more flexible and adaptable to more application scenarios, that is, the communication device indicates at least one authentication method to the authentication network element, and the authentication network element determines the first authentication method from the at least one authentication method.

[0128] In some implementations of the fourth aspect, the authentication information indicates any one of the following information: the credential of the communication device, the cryptographic algorithm; where the credential of the communication device includes the public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.

[0129] Based on the above solution, by determining the first authentication method according to the third information, the first authentication method can be made applicable to different credentials and / or cryptographic algorithms of the communication device.

[0130] In some implementations of the fourth aspect, the types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier includes at least one of the following: the first type of identifier of the communication device, the second type of identifier of the communication device, the identifier of the block or the identifier of the transaction, the virtual identifier of the communication device; where the first type of identifier has a first corresponding relationship with the root key of the communication device, the second type of identifier has a second corresponding relationship with at least one credential of the communication device, the identifier of the block or the identifier of the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.

[0131] Based on the above solution, the authentication information of the communication device can be obtained based on different identifiers, making the authentication process applicable to multiple scenarios. Among them, the scenarios applicable to different types of identifiers can refer to the description in the first aspect.

[0132] In some implementations of the fourth aspect, the first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: the issuer of the credential of the communication device, the security level of the credential of the communication device, the cryptographic algorithm corresponding to the credential of the communication device.

[0133] In some implementations of the fourth aspect, a second digital signature is sent to the authentication network element. The second digital signature is a signature of a second message using the private key of the communication device. The second message includes messages that the communication device has interacted with the authentication network element. The second digital signature is used by the authentication network element to authenticate the communication device. Among them, the messages that the communication device has interacted with the authentication network element can refer to the description in the first aspect.

[0134] Based on the above solution, by sending the second digital signature to the authentication network element, the authentication network element can use the first credential to verify the signature of the messages interacted by the communication device, thereby verifying the communication device; by verifying the first credential through the credential of the issuer of the first credential, the security of the first credential can be determined, thereby enhancing the security of the authentication process.

[0135] In a fifth aspect, a communication device is provided. The communication device can be used as the authentication network element in the first aspect. The communication device can be the authentication network element, or a device in the authentication network element (for example, a chip, or a chip system, or a circuit), or a device that can be used in matching with the authentication network element, or a logical module or software that can implement all or part of the functions of the authentication network element.

[0136] In a possible implementation, the communication device may include modules or units corresponding one by one to the methods / operations / steps / actions described in the first aspect. The module or unit can be a hardware circuit, or software, or a combination of a hardware circuit and software.

[0137] In a possible implementation, the device includes a transceiver unit. The transceiver unit is configured to: receive first indication information from a communication device, the first indication information indicating at least one key negotiation algorithm; send second indication information to the communication device, the second indication information indicating a first key negotiation algorithm, the first key negotiation algorithm being one of the at least one key negotiation algorithms, and the first key negotiation algorithm being used to determine a first key, and the first key being used to encrypt or decrypt messages transmitted between the communication device and the device.

[0138] In some implementations of the fifth aspect, the first key negotiation algorithm is determined according to first information and the first indication information, and the first information refers to the description in the first aspect.

[0139] In some implementations of the fifth aspect, the at least one key negotiation algorithm refers to the description in the first aspect.

[0140] In some implementations of the fifth aspect, the device further includes a processing unit, and the processing unit is configured to determine the first key based on the first key negotiation algorithm.

[0141] In some implementations of the fifth aspect, the first key negotiation algorithm is the ECDHE key negotiation algorithm. In the ECDHE key negotiation algorithm, the transceiver unit is specifically configured to receive a first public key from the communication device, where the first public key is the public key in the first temporary public-private key pair generated by the communication device; the processing unit is specifically configured to determine the first key based on the first public key and a second private key, where the second private key is the private key in the second temporary public-private key pair generated by the device.

[0142] In some implementations of the fifth aspect, the transceiver unit is further configured to send a second public key to the communication device, where the second public key is the public key in the second temporary public-private key pair. By sending the second public key to the communication device, the communication device can determine the first key based on the second public key.

[0143] In some implementations of the fifth aspect, the first key negotiation algorithm is the PQC-based key negotiation algorithm. In the PQC-based key negotiation algorithm, the transceiver unit is specifically configured to receive a third public key from the communication device, where the third public key is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; the processing unit is specifically configured to input the third public key into the post-quantum algorithm to generate a ciphertext and the first key.

[0144] In some implementations of the fifth aspect, the transceiver unit is further configured to send the ciphertext to the communication device. By sending the ciphertext to the communication device, the communication device can determine the first key based on the ciphertext.

[0145] In some implementations of the fifth aspect, the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDH. In the key negotiation algorithm based on PQC and ECDH, the transceiver unit is specifically configured to receive a first public key and a third public key from the communication device, where the first public key is the public key in the first temporary public-private key pair generated by the communication device, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; the processing unit is specifically configured to determine a second key based on the first public key and the private key of the device, and input the third public key into the post-quantum algorithm to generate a ciphertext and a third key; the processing unit is further configured to determine the first key based on the second key and the third key.

[0146] In some implementations of the fifth aspect, the transceiver unit is further configured to send the public key of the device and the ciphertext to the communication device, and the public key of the device and the ciphertext are used for the communication device to determine the first key.

[0147] In some implementations of the fifth aspect, the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. In the key negotiation algorithm based on PQC and ECDHE, the transceiver unit is specifically configured to receive a first public key and a third public key from the communication device. The first public key is the public key in the first temporary public-private key pair generated by the communication device, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm. The processing unit is specifically configured to determine a second key based on the first public key and a second private key, where the second private key is the private key in the second temporary public-private key pair generated by the device, and input the third public key into the post-quantum algorithm to generate a ciphertext and a third key. The processing unit is further configured to determine the first key based on the second key and the third key.

[0148] In some implementations of the fifth aspect, the transceiver unit is further configured to send a second public key and the ciphertext to the communication device. The second public key is the public key in the second temporary public-private key pair. By sending the second public key and the ciphertext to the communication device, the communication device can determine the first key based on the second public key and the ciphertext.

[0149] In some implementations of the fifth aspect, the transceiver unit is further configured to send a first digital signature to the communication device. The first digital signature is the signature of the first message by the private key of the device, and the first message includes the messages exchanged between the device and the communication device. The transceiver unit is also configured to send a certificate of the device to the communication device. The certificate includes the public key of the device, and the public key of the device is used by the communication device to verify the first digital signature.

[0150] In some implementations of the fifth aspect, the transceiver unit is further configured to receive a request message from the communication device. The request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key. The first identifier has a corresponding relationship with the authentication information of the communication device. The authentication information corresponding to the first identifier is obtained. The processing unit is further configured to authenticate the communication device based on the first authentication information.

[0151] In some implementations of the fifth aspect, before receiving the request message from the communication device, the transceiver unit is further configured to receive third indication information from the communication device. The third indication information indicates at least one authentication method, and the third information indicated by each authentication method in the at least one authentication method is different. The transceiver unit is further configured to send fourth indication information to the communication device. The fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.

[0152] In some implementations of the fifth aspect, the authentication information refers to the description in the first aspect.

[0153] In some implementations of the fifth aspect, the types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier refers to the description in the first aspect.

[0154] In some implementations of the fifth aspect, the first authentication method is determined according to the second information and the third indication information, and the second information refers to the description in the first aspect.

[0155] In some implementations of the fifth aspect, the first authentication information includes the first credential of the communication device, and the first credential is verified based on the credential of the issuer of the first credential; the transceiver unit is further configured to receive a second digital signature from the communication device, where the second digital signature is a signature of the second message by the private key of the communication device, and the second message includes the messages that the communication device has interacted with the device; the processing unit is further configured to verify the second digital signature based on the public key corresponding to the first credential.

[0156] In a sixth aspect, a communication device is provided. The communication device can be used as the verification network element in the second aspect. The communication device can be a verification network element, or a device in the verification network element (for example, a chip, or a chip system, or a circuit), or a device that can be used in matching with the verification network element, or a logic module or software that can implement all or part of the functions of the verification network element.

[0157] In a possible implementation, the communication device may include modules or units corresponding one by one to the methods / operations / steps / actions described in the second aspect. The modules or units can be hardware circuits, software, or a combination of hardware circuits and software.

[0158] In a possible implementation, the device includes a transceiver unit and a processing unit. The transceiver unit is configured to receive a temporary public key from a first communication device, where the temporary public key is the public key in the temporary public-private key pair generated by the first communication device; the processing unit is configured to authenticate the first communication device based on a first key, where the first key is determined based on the temporary public key and a second private key, and the second private key is the private key of the verification network element or the private key in the temporary public-private key pair generated by the verification network element, or the first key is generated by inputting the temporary public key into a post-quantum algorithm.

[0159] In some implementations of the sixth aspect, if the first key is determined based on the temporary public key and the second private key, and the second private key is the private key in the temporary public-private key pair generated by the verification network element, the transceiver unit is further configured to send a second public key to the first communication device, where the second public key includes the public key in the temporary public-private key pair generated by the verification network element, and the second public key is used for the first communication device to determine the first key.

[0160] In some implementations of the sixth aspect, the temporary public key is a third public key, which is the public key in a third temporary public-private key pair generated by the first communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.

[0161] In some implementations of the sixth aspect, the transceiver unit is further configured to send a ciphertext to the first communication device, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext is used for the first communication device to determine the first key.

[0162] In some implementations of the sixth aspect, the temporary public key includes a first public key and a third public key. The first public key is the public key in a first temporary public-private key pair generated by the first communication device, and the third public key is the public key in a third temporary public-private key pair generated by the first communication device based on a post-quantum algorithm. The first key is determined based on a second key and a third key. The second key is determined according to the second private key and the first public key, and the third key is generated by inputting the third public key into the post-quantum algorithm.

[0163] In some implementations of the sixth aspect, the transceiver unit is further configured to send a ciphertext and a second public key to the first communication device. The second public key includes the public key of the authentication network element or the public key in a temporary public-private key pair generated by the authentication network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext and the second public key are used for the first communication device to determine the first key.

[0164] In some implementations of the sixth aspect, the temporary public key is sent according to second indication information, and the second indication information indicates a first key negotiation algorithm, where the first key negotiation algorithm is one of at least one key negotiation algorithm. Before receiving the temporary public key from the first communication device, the transceiver unit is further configured to receive first indication information from the first communication device, where the first indication information indicates the at least one key negotiation algorithm; the transceiver unit is further configured to send the second indication information to the first communication device.

[0165] In some implementations of the sixth aspect, the first key negotiation algorithm is determined according to first information and the first indication information, where the first information refers to the description in the second aspect.

[0166] Wherein, the at least one key negotiation algorithm refers to the description in the first aspect.

[0167] In some implementations of the sixth aspect, the transceiver unit is further configured to: send a first digital signature to the first communication device, where the first digital signature is a signature of a first message using the private key of the authentication network element, and the first message includes messages exchanged between the authentication network element and the first communication device; send a certificate of the authentication network element to the first communication device, where the certificate includes a public key of the authentication network element, and the public key of the authentication network element is used by the first communication device to verify the first digital signature.

[0168] In some implementations of the sixth aspect, the transceiver unit is further configured to receive a request message from the first communication device, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first communication device using the first key, and the first identifier has a corresponding relationship with the authentication information of the first communication device; the processing unit is further configured to decrypt the encrypted first identifier based on the first key; obtain the first authentication information in the authentication information according to the first identifier; the processing unit is further configured to authenticate the first communication device based on the first authentication information.

[0169] In some implementations of the sixth aspect, before receiving the request message from the first communication device, the transceiver unit is further configured to receive third indication information from the first communication device, where the third indication information indicates at least one authentication method, and the authentication information corresponding to each authentication method in the at least one authentication method is independent of each other; the transceiver unit is further configured to send fourth indication information to the first communication device, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.

[0170] In some implementations of the sixth aspect, the authentication information refers to the description in the second aspect.

[0171] In some implementations of the sixth aspect, the types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier may refer to the description in the second aspect.

[0172] In some implementations of the sixth aspect, the first authentication method is determined according to the second information and the third indication information, and the second information refers to the description in the second aspect.

[0173] In some implementations of the sixth aspect, the first authentication information includes a first credential of the first communication device, and the first credential is verified based on the credential of the issuer of the first credential; the transceiver unit is further configured to receive a second digital signature from the first communication device, where the second digital signature is a signature of a second message by the first communication device, and the second message includes messages exchanged between the first communication device and the authentication network element; the processing unit is further configured to verify the second digital signature based on the public key corresponding to the first credential.

[0174] In a seventh aspect, a communication device is provided. The communication device can be used in the communication device of the third aspect. The communication device can be a terminal device, or a device in the terminal device (for example, a chip, or a chip system, or a circuit), or a device that can be used in combination with the terminal device, or a logical module or software that can implement all or part of the functions of the terminal device.

[0175] In a possible implementation, the communication device may include modules or units corresponding one by one to the methods / operations / steps / actions described in the third aspect. The modules or units can be hardware circuits, software, or a combination of hardware circuits and software.

[0176] In a possible implementation, the device includes a transceiver unit. The transceiver unit is configured to send a first indication message to an authentication network element. The first indication message indicates at least one key negotiation algorithm. The transceiver unit is further configured to receive a second indication message from the authentication network element. The second indication message indicates a first key negotiation algorithm. The first key negotiation algorithm is one of the at least one key negotiation algorithms. The first key negotiation algorithm is used to determine a first key. The first key is used to encrypt or decrypt messages transmitted between the communication device and the authentication network element.

[0177] In some implementation manners of the seventh aspect, the first key negotiation algorithm is determined according to the first information and the first indication message. The first information includes at least one of the following information: the security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.

[0178] Among them, the at least one key negotiation algorithm refers to the description in the first aspect.

[0179] In some implementation manners of the seventh aspect, the device further includes a processing unit. The processing unit is configured to determine the first key based on the first key negotiation algorithm.

[0180] In some implementation manners of the seventh aspect, the first key negotiation algorithm is the ECDHE key negotiation algorithm. In the ECDHE key negotiation algorithm, the transceiver unit is further configured to receive a second public key from the authentication network element. The second public key is the public key in the second temporary public-private key pair generated by the authentication network element. The processing unit is specifically configured to determine the first key based on the second public key and a first private key. The first private key is the private key in the first temporary public-private key pair generated by the communication device.

[0181] In some implementations of the seventh aspect, the transceiver unit is further configured to send a first public key to the authentication network element, where the first public key is the public key in the first temporary public-private key pair, and the first public key is used by the authentication network element to determine the first key.

[0182] In some implementations of the seventh aspect, the first key negotiation algorithm is the PQC-based key negotiation algorithm. In the PQC-based key negotiation algorithm, the transceiver unit is further configured to receive a ciphertext from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm; the processing unit is further configured to input the ciphertext and a third private key into the post-quantum algorithm to generate the first key, where the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm.

[0183] In some implementations of the seventh aspect, the transceiver unit is further configured to send a third public key to the authentication network element, where the third public key is the public key in the third temporary public-private key pair, and the third public key is used by the authentication network element to determine the first key.

[0184] In some implementations of the seventh aspect, the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDH. In the key negotiation algorithm based on PQC and ECDH, the transceiver unit is further configured to receive a ciphertext and the public key of the authentication network element from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm; the processing unit is further configured to determine a second key based on the public key of the authentication network element and a first private key, where the first private key is the private key in the first temporary public-private key pair generated by the communication device; input the ciphertext and a third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; the processing unit is further configured to determine the first key based on the second key and the third key.

[0185] In some implementations of the seventh aspect, the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. In the key negotiation algorithm based on PQC and ECDHE, the transceiver unit is further configured to receive a ciphertext and a second public key from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm, and the second public key is the public key in the second temporary public-private key pair generated by the authentication network element; the processing unit is further configured to determine a second key based on the second public key and a first private key, where the first private key is the private key in the first temporary public-private key pair generated by the communication device; the processing unit is further configured to input the ciphertext and a third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; determine the first key based on the second key and the third key.

[0186] In some implementations of the seventh aspect, the transceiver unit is further configured to send a first public key and a third public key to the authentication network element, where the first public key is the public key in the first temporary public-private key pair, the third public key is the public key in the third temporary public-private key pair, and the first public key and the third public key are used by the authentication network element to determine the first key.

[0187] In some implementations of the seventh aspect, the transceiver unit is further configured to: receive a first digital signature from the authentication network element, where the first digital signature is a signature of a first message by the private key of the authentication network element, and the first message includes messages exchanged between the authentication network element and the communication device; receive a certificate of the authentication network element from the authentication network element, where the certificate includes the public key of the authentication network element; and the processing unit is further configured to verify the first digital signature based on the public key of the authentication network element.

[0188] In some implementations of the seventh aspect, the transceiver unit is further configured to send a request message to the authentication network element, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, where the first identifier has a corresponding relationship with the authentication information of the communication device, and the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.

[0189] In some implementations of the seventh aspect, before sending the request message to the authentication network element, the transceiver unit is further configured to: send third indication information to the authentication network element, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other; receive fourth indication information from the authentication network element, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.

[0190] Wherein, the authentication information refers to the description in the third aspect.

[0191] In some implementations of the seventh aspect, the types of the first identifier indicated by each authentication method in the at least one authentication method are different, and several types of the first identifier refer to the description in the third aspect.

[0192] In some implementations of the seventh aspect, the first authentication method is determined according to the second information and the third indication information. The second information refers to the description in the third aspect.

[0193] In some implementations of the seventh aspect, the transceiver unit is further configured to: send a second digital signature to the authentication network element, where the second digital signature is a signature of a second message by the private key of the communication device, and the second message includes messages exchanged between the communication device and the authentication network element, and the second digital signature is used by the authentication network element to authenticate the communication device.

[0194] In an eighth aspect, a communication device is provided. This communication device can be used in the communication device of the fourth aspect. This communication device can be a terminal device, or a device in the terminal device (for example, a chip, or a chip system, or a circuit), or a device that can be used in matching with the terminal device, or a logic module or software that can implement all or part of the functions of the terminal device.

[0195] In a possible implementation, the communication device may include modules or units corresponding one by one to the methods / operations / steps / actions described in the fourth aspect. The module or unit can be a hardware circuit, or software, or a combination of a hardware circuit and software.

[0196] In a possible implementation, the device includes a transceiver unit, and the transceiver unit is configured to: send a temporary public key to the authentication network element, where the temporary public key is the public key in the temporary public-private key pair generated by the communication device, and the temporary public key is used to determine a first key, and the first key is used for the authentication network element to authenticate the communication device; wherein, the first key is determined based on the temporary public key and a second private key, and the second private key is the private key of the authentication network element or the private key in the temporary public-private key pair generated by the authentication network element; or, the first key is generated by inputting the temporary public key into a post-quantum algorithm.

[0197] In some implementation manners of the eighth aspect, if the first key is determined based on the temporary public key of the communication device and the private key in the temporary public-private key pair generated by the authentication network element, the transceiver unit is further configured to: receive a second public key from the authentication network element, where the second public key is the public key in the second temporary public-private key pair generated by the authentication network element; the device further includes a processing unit, and the processing unit is configured to determine the first key based on a first private key and the second public key, and the first public key is the private key in the first temporary public-private key pair.

[0198] In some implementation manners of the eighth aspect, the temporary public key is a third public key, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.

[0199] In some implementation manners of the eighth aspect, the transceiver unit is further configured to receive a ciphertext from the authentication network element, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm; the processing unit is further configured to input the ciphertext and a third private key into the post-quantum algorithm to generate the first key, and the third private key is the private key in the third temporary public-private key pair.

[0200] In some implementations of the eighth aspect, the temporary public key includes a first public key and a third public key. The first public key is the public key in the first temporary public-private key pair generated by the communication device. The third public key is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm. The first key is determined based on a second key and a third key. The second key is determined according to the second private key and the first public key. The third key is generated by inputting the third public key into the post-quantum algorithm.

[0201] In some implementations of the eighth aspect, the transceiver unit is further configured to receive a ciphertext and a second public key from the authentication network element. The second public key includes the public key of the authentication network element or the public key in the temporary public-private key generated by the authentication network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm. The processing unit is further configured to: generate a second key based on the first private key and the second public key, where the first private key is the private key in the first public-private key pair; input the ciphertext and the third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third public-private key pair; determine the first key based on the second key and the third key.

[0202] In some implementations of the eighth aspect, the temporary public key is sent according to second indication information, and the second indication information indicates a first key negotiation algorithm. The first key negotiation algorithm is one of at least one key negotiation algorithm. Before receiving the temporary public key from the communication device, the transceiver unit is further configured to: send first indication information to the authentication network element, where the first indication information indicates the at least one key negotiation algorithm; receive the second indication information from the authentication network element.

[0203] In some implementations of the eighth aspect, the first key negotiation algorithm is determined according to first information and the first indication information, and the first information refers to the description in the fourth aspect.

[0204] Wherein, the at least one key negotiation algorithm refers to the description in the first aspect.

[0205] In some implementations of the eighth aspect, the transceiver unit is further configured to: receive a first digital signature from the authentication network element, where the first digital signature is the signature of the first message by the private key of the authentication network element, and the first message includes the messages interacted between the authentication network element and the communication device; receive the certificate of the authentication network element from the authentication network element, where the certificate includes the public key of the authentication network element; the processing unit is further configured to: verify the first digital signature based on the public key of the authentication network element.

[0206] In some implementations of the eighth aspect, the transceiver unit is further configured to: send a request message to the authentication network element, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the communication device using the first key. The first identifier has a corresponding relationship with the authentication information of the communication device, and the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.

[0207] In some implementations of the eighth aspect, before sending the request message to the authentication network element, the transceiver unit is further configured to: send third indication information to the authentication network element, where the third indication information indicates at least one authentication method, and the authentication information corresponding to each authentication method in the at least one authentication method is independent of each other; receive fourth indication information from the authentication network element, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.

[0208] Wherein, the authentication information refers to the description in the fourth aspect.

[0209] In some implementations of the eighth aspect, the types of the first identifier indicated by each authentication method in the at least one authentication method are different, and several types of the first identifier refer to the description in the fourth aspect.

[0210] In some implementations of the eighth aspect, the first authentication method is determined according to second information and the third indication information, and the second information refers to the description in the fourth aspect.

[0211] In some implementations of the eighth aspect, the transceiver unit is further configured to: send a second digital signature to the authentication network element, where the second digital signature is a signature of the second message by the private key of the communication device, and the second message includes messages interacted between the communication device and the authentication network element, and the second digital signature is used for the authentication network element to authenticate the communication device.

[0212] The ninth aspect provides a communication device, which includes a processor. The processor is configured to enable the device to implement any one of the first aspect to the fourth aspect, and the method in any possible implementation manner of the first aspect to the fourth aspect by executing computer programs (or computer-executable instructions) stored in a memory, and / or through logic circuits.

[0213] Optionally, the device further includes a memory, and the memory may be deployed separately or centrally with the processor.

[0214] Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface. The communication interface may be a transceiver or an input / output interface.

[0215] In one implementation, the device is a verification network element, or a chip configured in the verification network element, and can also be a logic module or software that can implement all or part of the functions of the verification network element. When the device is a chip, the communication interface can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processor can also be embodied as a processing circuit or logic circuit.

[0216] In another implementation, the device is a terminal device, or a chip configured in the terminal device, and can also be a logic module or software that can implement all or part of the functions of the terminal device. When the device is a chip, the communication interface can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processor can also be embodied as a processing circuit or logic circuit.

[0217] Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0218] In a specific implementation process, the above-mentioned processor can be one or more chips, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be transistors, gate circuits, flip-flops, and various logic circuits, etc. The input signal received by the input circuit can be, but is not limited to, the signal received and input by the receiver, and the signal output by the output circuit can be, but is not limited to, the signal output to the transmitter and transmitted by the transmitter. Moreover, the input circuit and the output circuit can be the same circuit, which serves as the input circuit and the output circuit at different times respectively. The embodiments of the present application do not limit the specific implementation manners of the processor and various circuits.

[0219] In a tenth aspect, a chip system is provided. The processor is used to execute the computer program or instruction in the memory, so that the chip system implements any one of the first to fourth aspects above, and the methods in any possible implementation manner of the first to fourth aspects.

[0220] In an eleventh aspect, a communication system is provided, including at least one of a verification network element and a terminal device. The verification network element is used to execute the first and second aspects above, and the methods in any possible implementation manner of the first and second aspects; the terminal device is used to execute the third and fourth aspects above, and the methods in any possible implementation manner of the third and fourth aspects.

[0221] In a twelfth aspect, there is provided a computer-readable storage medium storing a computer program (which may also be referred to as code or instructions). When the computer program runs on a computer, it causes the computer to execute any one of the first aspect and the second aspect above, as well as the methods in any possible implementation manner of the first aspect and the second aspect.

[0222] In a thirteenth aspect, there is provided a computer program product including a computer program (which may also be referred to as code or instructions). When the computer program runs, it causes the computer to execute any one of the first aspect to the fourth aspect above, as well as the methods in any possible implementation manner of the first aspect to the fourth aspect.

[0223] For the beneficial effects brought by the fifth aspect to the thirteenth aspect above, reference may be made to the description of the beneficial effects in the first aspect to the fourth aspect, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0224] Figure 1 It is a schematic diagram of a communication network architecture applicable to an embodiment of the present application.

[0225] Figure 2 It is a schematic diagram of the architecture of a communication system applicable to an embodiment of the present application.

[0226] Figure 3 It is a schematic flowchart of an authentication process based on the EAP-AKA' architecture.

[0227] Figure 4 It is a schematic flowchart of a communication method 400 provided by the present application.

[0228] Figure 5 It is a schematic flowchart of a method for negotiating a key provided by the present application.

[0229] Figure 6 It is a schematic flowchart of a communication method 600 provided by the present application.

[0230] Figure 7 It is a schematic block diagram of a communication device 700 provided by the present application.

[0231] Figure 8 It is a schematic block diagram of a communication device 800 provided by the present application.

[0232] Figure 9 It is a schematic block diagram of a chip system 900 provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0233] Next, the technical solutions in the present application will be described with reference to the accompanying drawings.

[0234] The technical solution of the embodiment of the present application can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD), 5th generation (5G) systems, 6th generation (6G) systems, and other systems evolved after 5G, such as communication systems.

[0235] Figure 1 It is a schematic diagram of a communication network architecture applicable to the embodiment of the present application. As Figure 1 shown, each part involved in this network architecture will be described separately below.

[0236] Terminal equipment 110: The terminal equipment in the embodiment of the present application may refer to a device that provides voice and / or data connectivity to users, or a handheld device with wireless connection functions, or other processing devices connected to a wireless modem.

[0237] A terminal device can also be referred to as a terminal, access terminal, user unit, user equipment (UE), user station, mobile station, mobile unit, remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent, or user device. A terminal device is a device that includes wireless communication capabilities (providing voice / data connectivity to users). For example, a handheld device with wireless connection capabilities, or a vehicle-mounted device, etc. The terminal in the embodiments of this application can be a mobile phone, a tablet (pad), a computer with wireless transceiver functions, a train, an airplane, a mobile internet device (MID), a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a light UE, a reduced capability UE (REDCAP UE), a wireless terminal in industrial control (such as a robot, etc.), a wireless terminal in vehicle networking (such as a vehicle-mounted device, a vehicle equipment, a vehicle-mounted module, a vehicle, a vehicle-mounted chip, an on-board unit (OBU), or a telematics box (T-BOX) in vehicle networking, etc.), a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart city, a wireless terminal in smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication capabilities, a computing device, or other processing devices connected to a wireless modem, a wearable device, a terminal in a 5G network, or a terminal in a network evolved after 5G, etc. It can be understood that all or part of the functions of the terminal device in this application can also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (such as a cloud platform).

[0238] Among them, a wearable device can also be called a wearable intelligent device, which is a general term for devices developed by applying wearable technologies to the intelligent design of daily wear, such as glasses, gloves, watches, clothing, shoes, etc. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. A wearable device is not only a hardware device, but also realizes powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable intelligent devices include those with complete functions and large sizes that can achieve complete or partial functions without relying on a smartphone, such as smart watches or smart glasses, etc., and those that only focus on a certain type of application function and need to cooperate with other devices such as smartphones, such as various smart bracelets and smart jewelry for physical sign monitoring.

[0239] The terminal device of this application can also be a module or unit for implementing terminal functions. For example, a universal integrated circuit card (UICC). It should be understood that the UICC card is only for illustration. In actual implementation, the UICC card can also be replaced by a device with similar functions to the UICC card, such as an embedded universal integrated circuit card (eUICC). In addition, the UICC card can also have other names, such as a blockchain universal integrated circuit card (B-UICC), and this application does not make any restrictions on this.

[0240] (Wireless) Access Network ((R)AN) Node 120: Used to provide network access functions for terminal devices in a specific area, and can use transmission tunnels of different qualities according to the level of the terminal device, service requirements, etc. The RAN node can manage radio resources, provide access services for terminal devices, and then complete the forwarding of control signals and terminal device data between the terminal device and the core network.

[0241] In a possible scenario, the RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), a base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system, etc. The RAN node can be a macro base station, a micro base station or an indoor station, a relay node or a donor node, or a radio controller in a cloud radio access network (CRAN) scenario. Optionally, the RAN node can also be a server, a wearable device, a vehicle or a vehicle-mounted device, etc. For example, the access network device in V2X technology can be a road side unit (RSU). All or part of the functions of the RAN node in this application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform). The RAN node in this application can also be a logical node, a logical module or software that can implement all or part of the RAN node functions.

[0242] In another possible scenario, multiple RAN nodes cooperate to assist a terminal in achieving wireless access, and different RAN nodes respectively implement part of the functions of a base station. For example, the RAN node can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be set separately, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as included in a remote radio unit (RRU), an active antenna unit (AAU) or a remote radio head (RRH).

[0243] In different systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open-radio access network (O-RAN) system, the CU may also be referred to as an open-central unit (O-CU) (open CU); the DU may also be referred to as an open-distributed unit (O-DU) (open DU); the CU-CP may also be referred to as O-CU-CP, the CU-UP may also be referred to as O-CU-UP, and the RU may also be referred to as O-RU. For the sake of description, in this application, the CU, CU-CP, CU-UP, DU, and RU are used as examples for description. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application may be implemented through a software module, a hardware module, or a combination of a software module and a hardware module.

[0244] User plane network element 130: Used for packet routing and forwarding, as well as quality of service (QoS) processing of user plane data, etc.

[0245] In a 5G communication system, this user plane network element may be a user plane function (UPF) network element. In a communication system evolved after 5G, the user plane network element may still be a UPF network element, or it may also have other names, which are not limited in this application.

[0246] Data network (DN) 140: A data network that provides service to users. Generally, the client is located at the UE, and the server is located in the data network. The data network may be a private network, such as a local area network, or an external network not controlled by the operator, such as the Internet, or a dedicated network jointly deployed by the operator, such as a network that provides Internet protocol (IP) multimedia subsystem (IMS) services.

[0247] In a communication system evolved after 5G, the DN in the 5G communication system may be continued to be used, or it is also possible to replace the entity with a similar function with other names, which are not limited in this application.

[0248] Authentication server 150: Used for authentication services, generating keys to implement two-way authentication of terminal devices, and supporting a unified authentication framework.

[0249] In a 5G communication system, the authentication server may be a network element of the authentication server function (AUSF). In a communication system evolved after 5G, the network element of the authentication server function may still be the AUSF network element, or it may have other names, which are not limited in this application.

[0250] Access management network element 160: mainly used for mobility management and access management, etc., such as functions like access authorization / authentication.

[0251] In a 5G communication system, the access management network element may be a network element of the access and mobility management function (AMF). In a communication system evolved after 5G, the access management network element may still be the AMF network element, or it may have other names, which are not limited in this application.

[0252] Session management network element 170: mainly used for session management, allocation and management of the Internet Protocol (IP) address of the terminal device, selection of manageable user plane functions, termination of the policy control and charging function interfaces, and downlink data notification, etc.

[0253] In a 5G communication system, the session management network element may be a network element of the session management function (SMF). In a communication system evolved after 5G, the session management network element may still be the SMF network element, or it may have other names, which are not limited in this application.

[0254] Slice selection network element 180: used to select a group of network slice instances for serving the terminal device and determine a group of access management network elements for serving the terminal device.

[0255] In a 5G communication system, the network exposure network element may be a network element of the network slice selection function (NSSF). In a communication system evolved after 5G, the network exposure network element may still be the NSSF network element, or it may have other names, which are not limited in this application.

[0256] Network exposure network element 190: used to expose network capabilities to third-party applications and can achieve a friendly docking between network capabilities and service requirements.

[0257] In a 5G communication system, the network exposure network element may be a network exposure function (NEF) network element. In a communication system evolved after 5G, the network exposure network element may still be a NEF network element, or may have other names, which are not limited in this application.

[0258] Network repository network element 1100: Used to maintain real-time information of all network function services in the network.

[0259] In a 5G communication system, the network repository network element may be a network repository function (NRF) network element. In a communication system evolved after 5G, the network repository network element may still be an NRF network element, or may have other names, which are not limited in this application.

[0260] Policy control network element 1110: Used for a unified policy framework to guide network behavior, and provides policy rule information, etc. for control plane function network elements (such as AMF, SMF network elements, etc.).

[0261] In a 4G communication system, the policy control network element may be a policy and charging rules function (PCRF) network element. In a 5G communication system, the policy control network element may be a policy control function (PCF) network element. In a communication system evolved after 5G, the policy control network element may still be a PCF network element, or may have other names, which are not limited in this application.

[0262] Data management network element 1120: Used to process terminal device identification, access authentication, registration, and mobility management, etc.

[0263] In a 5G communication system, the data management network element may be a unified data management (UDM) network element. In a communication system evolved after 5G, the unified data management may still be a UDM network element, or may have other names, which are not limited in this application.

[0264] Application network element 1130: Used to perform data routing affected by the application, access the network, and interact with the policy framework for policy control, etc.

[0265] In a 5G communication system, the application network element may be an application function (AF) network element. In a communication system evolved after 5G, the application network element may still be an AF network element, or it may have other names, which are not limited in this application.

[0266] In the above network architecture, it may also include an authentication credential repository and processing function (ARPF) network element, a security anchor function (SEAF) network element, etc. (not shown in the figure). Among them, the ARPF is mainly used to store the user's root key and relevant subscribed data for authentication, and calculate 5G authentication and authorization vectors, etc. The SEAF is mainly used to derive the lower-layer non-access stratum (NAS) and access stratum (AS) keys based on the anchor key, and compare the authentication results.

[0267] In the above network architecture, N1, N2, N3, N4, N6, Nnssf, Nnef, Nnrf, Npcf, Nudm, Naf, Nausf, Namf, and Nsmf are interface sequence numbers. The meanings of the above interface sequence numbers can be referred to the meanings defined in the 3GPP standard protocol, and this application does not limit the meanings of the above interface sequence numbers.

[0268] Exemplarily, the N2 interface is the interface between the RAN and the access management network element, and is used for sending wireless parameters, NAS signaling, etc.; the N3 interface is the interface between the RAN and the user plane function network element, and is used for transmitting user plane data, etc.; the N4 interface is the interface between the session management function network element and the user plane function network element, and is used for transmitting information such as service policies, tunnel identification information of the N3 connection, data caching indication information, and downlink data notification messages. The N6 interface is the interface between the DN and the user plane function network element, and is used for transmitting user plane data, etc.

[0269] Nnssf, Nnef, Nnrf, Npcf, Nudm, Naf, Nausf, Namf, and Nsmf are service-based interfaces, and network elements can interact with each other through service-based interfaces.

[0270] It should be noted that the interface names between the various network functions in the figure are only examples. In specific implementations, the interface names of this system architecture may also be other names, which are not limited in this application. In addition, the names of the messages (or signaling) transmitted between the above network elements are also only examples and do not impose any limitations on the functions of the messages themselves.

[0271] It should be understood that the network architecture applied to the embodiments of the present application is only an example described from the perspectives of traditional point-to-point architectures and service-oriented architectures, and the network architecture applicable to the embodiments of the present application is not limited thereto. Any network architecture capable of implementing the functions of the above-mentioned network elements is applicable to the embodiments of the present application.

[0272] It should be noted that the names of the network elements and interfaces in the present application are only examples. The present application does not exclude the possibility that the network elements may have other names in the future, or the functions of the network elements may be merged. With the evolution of communication systems, any device or network element capable of implementing the functions of the above-mentioned network elements is within the protection scope of the present application.

[0273] It can be understood that the above-mentioned network elements or functions can be either network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). The above-mentioned network elements or functions can be divided into one or more services. Further, there may also be services that exist independently of network functions.

[0274] Figure 2 It is a schematic diagram of the architecture of a communication system applicable to the embodiments of the present application.

[0275] As Figure 2 shown, the communication system includes at least one node (nodes 101a to 101i) and a storage system 102.

[0276] Among them, the storage system 102 may include one or more storage nodes.

[0277] The storage system 102 may include one or more of the following: a blockchain system, a distributed storage system, or a communication system.

[0278] Among them, the blockchain system may include one or more blockchain nodes, that is, the storage nodes corresponding to the blockchain system may be blockchain nodes; the distributed storage system may include one or more distributed storage devices, that is, the storage nodes corresponding to the distributed storage system may be distributed storage devices; the communication system may include communication devices corresponding to the operator, that is, the storage nodes corresponding to the communication system may be communication devices corresponding to the operator.

[0279] It should be understood that the blockchain nodes, the storage devices in the distributed storage system, and the communication devices may be terminal devices or network devices.

[0280] Each of the at least one node (nodes 101a to 101i) can interact with the storage system 102. Optionally, if the at least one node includes multiple nodes, the nodes among the multiple nodes can directly interact with each other. The nodes in the at least one node (nodes 101a to 101i) can include terminal devices and / or network devices. Among them, the terminal device can be a device corresponding to the user; the network device can be a device corresponding to the card merchant or terminal manufacturer, a device corresponding to the trusted third party, an over-the-air card writing server, a device corresponding to the operator, or a device corresponding to the authoritative institution. The terminal manufacturer can also be referred to as the device manufacturer, device provider, etc.

[0281] Among them, the device corresponding to the card merchant or terminal manufacturer can be a device for implementing the business of the card merchant or terminal manufacturer, such as a device for the card merchant or terminal manufacturer to write cards; the device corresponding to the operator is a device for providing the business of the operator, such as the operator's server, the operator's core network element, or an access network device, etc.; the device corresponding to the authoritative institution can be a device for providing the business of the authoritative institution, such as a server belonging to the authoritative institution, or a host, etc.; the device corresponding to the trusted third party can be a device for providing the business of the third-party trusted institution, such as a server belonging to the third-party trusted institution, or a host, etc.

[0282] It can be understood that the card merchant, terminal manufacturer, trusted third party, operator, or authoritative institution are all for illustration purposes. In actual implementation, there may also be other organizations or institutions.

[0283] To facilitate the understanding of the technical solutions of the embodiments of the present application, some terms or concepts that may be involved in the embodiments of the present application are first briefly described.

[0284] 1. Secret key

[0285] A secret key is a parameter that is input in the algorithm for converting plaintext to ciphertext or ciphertext to plaintext.

[0286] 2. Public key and private key

[0287] The public key and private key are a key pair obtained through an algorithm (i.e., a public key and a private key), one of which is made public to the outside world and is called the public key; the other is kept by oneself and is called the private key. The key pair obtained through the algorithm can ensure uniqueness worldwide. When using this key pair, if one key is used to encrypt a piece of data, the other key must be used to decrypt it. For example, if the public key in the key pair is used to encrypt the data, the private key in the key pair needs to be used to decrypt it, and vice versa, otherwise the decryption will not succeed.

[0288] 3. Blockchain (blockchain, BC)

[0289] Transactions in the network are generated and stored in units of blocks, and are linked into a chain structure in chronological order. Confirmed and certified transactions in the network are linked from the first block of the blockchain to the latest block, and the ledger formed by linking multiple blocks together is called the blockchain.

[0290] Blockchain technology realizes a chain data structure formed by connecting data and information blocks in sequence in chronological order, and a distributed storage that is tamper-proof and forgery-proof guaranteed by cryptography. Generally, the data and information in the blockchain can be called "Transactions".

[0291] Blockchain technology is not a single technology, but a system integrating applications of peer-to-peer transmission, consensus mechanism, distributed data storage, and cryptography principles. This system has the technical characteristics of full disclosure and tamper-proofing.

[0292] 1) Peer-to-peer transmission: The nodes participating in the blockchain are independent and peer-to-peer. Data and information synchronization is achieved between nodes through peer-to-peer transmission technology. Nodes can be different physical machines or different instances in the cloud.

[0293] 2) Consensus mechanism: The consensus mechanism of the blockchain refers to the process in which multiple participating nodes reach an agreement on specific data and information through interactions between nodes under preset logical rules. The consensus mechanism needs to rely on a well-designed algorithm, so there are certain differences in the performance of different consensus mechanisms (such as: transaction throughput transactions per second (TPS), latency to reach consensus, computing resources consumed, transmission resources consumed, etc.).

[0294] 3) Distributed data storage: In the blockchain, distributed storage means that each node participating in the blockchain stores independent and complete data, ensuring that the data is fully disclosed among nodes. Different from traditional distributed data storage, traditional distributed data storage divides data into multiple copies for backup or synchronous storage according to certain rules, while blockchain distributed data storage relies on the consensus among peer-to-peer and independent nodes in the blockchain to achieve highly consistent data storage.

[0295] 4) Cryptography principles: The blockchain usually realizes reliable information dissemination, verification, etc. based on asymmetric encryption technology.

[0296] Among them, the concept of "block" is to organize one or more data records in the form of "blocks", and the size of the "block" can be customized according to the actual application scenario; while "chain" is a data structure that connects the "blocks" storing data records in chronological order and with hash technology. In a blockchain, each "block" contains two parts: a "block header" and a "block body", where the "block body" contains the transaction records packed into the "block"; the "block header" contains the root HASH of all transactions in the "block" and the HASH of the previous "block". The data structure of the blockchain ensures the immutability of the data stored on the blockchain.

[0297] 4. Information / Data on the Chain

[0298] Information / data on the chain means that information / data is packed into a block through a consensus mechanism to become a new block and linked to the previous block, becoming immutable information / data on the chain.

[0299] 5. Smart Contract

[0300] A smart contract is a computer protocol designed to spread, verify, or execute a contract in an information-based manner. All users on the blockchain can see smart contracts based on the blockchain. However, this can lead to all vulnerabilities, including security vulnerabilities, being visible and may not be quickly repaired.

[0301] Smart contracts in the blockchain field have the following characteristics:

[0302] The rules are publicly transparent, and the rules and data within the contract are visible to the outside; all transactions are publicly visible, and there will be no false or hidden transactions.

[0303] The blockchain technology has the characteristics of "public transparency" and "immutability" given by smart contracts. Smart contracts allow for trusted transactions without a third party, and these transactions are queryable and irreversible. Smart contracts are based on immutable data and can automatically execute some predefined rules and terms.

[0304] 6. Self-Control Identity (scID)

[0305] The scID can be used to identify the identity information of the first node (e.g., any one of nodes 101a to 101i). The scID can be a decentralized root credential (DRC), a decentralized identity credential (DIC), or a decentralized self-control credential (DSCC). The scID can be generated by the first node or other nodes other than the first node. For example, if the scID is a DRC, the DRC can be generated by other trusted nodes other than the first node; if the scID is a DIC or a DSCC, the DSCC can be generated by the first node.

[0306] The scID can correspond to different business scenarios. For example, in a business scenario with high requirements for personal information confidentiality, the scID can be a DRC, that is, the DRC can be used to complete the business. Another example is that in a scenario with low trust requirements for the first node, the SID can be a DIC or a DSCC, that is, the DIC or the DSCC can be used to complete the business.

[0307] In the current mobile communication network, before the UE accesses the network, the network side authenticates the UE. Exemplarily, the UE and the network use ECDH key negotiation to generate a key k. The principle of ECDH is that the public key of the network is pre-set inside the UE. Before the UE accesses the network, the UE generates a UE temporary public-private key pair; the UE uses the temporary private key of the UE and the public key of the network to calculate and generate the key k; the UE encrypts the subscription permanent identifier (SUPI) using the key k, and forms the ciphertext of the SUPI and the temporary public key of the UE into a subscription concealed identifier (SUCI), and sends it to the network side; the network side calculates the key k using the private key of the network and the temporary public key of the UE. Subsequently, the network side decrypts the SUCI using the key k to obtain the SUPI, and queries the root key corresponding to the SUPI, and performs mutual authentication using the root key (specifically, reference can be made to Figure 3 the description).

[0308] Figure 3 It is a schematic flowchart of an authentication process based on the extensible authentication protocol (EAP) AKA'. The authentication process includes the following contents.

[0309] S301, the UDM / ARPF determines an authentication vector (AV).

[0310] After the UDM / ARPF receives the UE ID and the serving network name (SN name) sent by the AUSF, it determines the AV based on the received information. Among them, the five-tuple included in the AV can be: random number for authentication (RAND), authentication token (AUTN), expected response parameter (XRES), cipher key (CK), and integrity key (IK). The generation process of the AV parameters is as Figure 6 shown, and its specific process can refer to the existing process and will not be elaborated here.

[0311] Next, the UDM / ARPF updates the AV according to the SN name and the key derivation function (KDF) algorithm. Specifically, it calculates CK' and IK' according to the SN name and the KDF algorithm, and uses the CK' and IK' to replace the CK and IK in the original AV.

[0312] S302, the UDM / ARPF sends a UE identity authentication response to the AUSF.

[0313] The UE identity authentication response sent by the UDM / ARPF to the AUSF can be Nudm_UEAuthentication_GetResponse. This UE identity authentication response can include the updated authentication vector (denoted as AV'), and the parameters for authentication included in the AV' can be (RAND, AUTN, XRES, CK', IK').

[0314] S303, the AUSF sends a UE identity authentication response to the SEAF.

[0315] Among them, the UE identity authentication response sent by the AUSF to the SEAF can be an EAP request (EAP request) message or an AKA' challenge (AKA'-challenge) message. The EAP-request or AKA'-challenge includes RAND and AUTN.

[0316] S304, the SEAF sends an authentication request to the UE.

[0317] The authentication request sent by the SEAF to the UE can be a forwarded EAP-request or AKA’-challenge received in step S303. The EAP-request or AKA’-challenge includes RAND and AUTN.

[0318] Specifically, the SEAF forwards the EAP-request or AKA’-challenge to the USIM of the UE.

[0319] S305, the UE calculates the authentication response.

[0320] Specifically, after the USIM of the UE receives RAND and AUTN in the EAP-request or AKA’-challenge, it verifies whether AUTN is correct. If it is correct, the USIM calculates the reply RES, CK, IK, and then sends RES, CK, IK to the ME of the UE; the ME then calculates CK’ and IK’ according to the SN name and the KDF algorithm. Among them, CK’ and IK’ can be used by the UE to generate a key corresponding to the key of the AUSF.

[0321] S306, the UE sends the authentication response to the SEAF.

[0322] Among them, the authentication response sent by the UE to the SEAF can be an EAP response (EAP-response) message or an AKA’ challenge (AKA’-challenge) message. The EAP-response and AKA’-challenge include RES.

[0323] S307, the SEAF forwards the message received in step S306 to the AUSF.

[0324] S308, the AUSF verifies the response.

[0325] Among them, the AUSF can compare whether RES is equal to the RES stored by itself. If they are equal, the AUSF verifies that the UE is successful.

[0326] Optionally, the AUSF and the UE can also exchange EAP-request / AKA’ notification (AKA’-notification) messages and EAP-response / AKA’-notification messages through step S309.

[0327] S310, the AUSF sends the UE identity authentication response to the SEAF.

[0328] Among them, the AUSF can generate an extended master session key (EMSK) from CK’ and IK’, and use the first 256 bits (bit) of the EMSK as the key of the AUSF (denoted as K AUSF ), and then derive the key K AUSF of the SEAF according to K SEAF , and send the EAP success message and K SEAF to the SEAF.

[0329] S311, the SEAF sends an N1 message to the UE.

[0330] Among them, the N1 message can be an EAP success message.

[0331] In the above solution, the network side and the terminal use a fixed key exchange algorithm to generate a shared key, and the application scenario is limited. For example, for some low-power terminal devices, the computational complexity of the ECDH key negotiation is relatively high. For another example, the ECDH key negotiation may not meet the application scenarios with high security requirements. Specifically, in the process of ECDH key negotiation, the terminal side uses the fixed public key of the network side to calculate the shared key, so this key negotiation algorithm does not have forward security.

[0332] As the application scenarios of terminals and networks in the mobile communication system (such as different security requirements) increase, how to improve the flexibility of the authentication process of terminals and networks needs to be considered.

[0333] In view of this, the present application proposes a communication method and a communication device, which are beneficial to the improvement or solution of the above problems.

[0334] For the convenience of understanding the embodiments of the present application, the following points are explained.

[0335] First, in the present application, "used to indicate" can be understood as "enable", and "enable" can include direct enabling and indirect enabling. When describing that a certain piece of information is used to enable A, it can include that the information directly enables A or indirectly enables A, and it does not necessarily mean that A is carried in the information.

[0336] The information enabled by information is called the information to be enabled. In the specific implementation process, there are many ways to enable the information to be enabled. For example, but not limited to, the information to be enabled can be directly enabled, such as the information to be enabled itself or the index of the information to be enabled, etc. It is also possible to indirectly enable the information to be enabled by enabling other information, where there is an association relationship between the other information and the information to be enabled. It is also possible to only enable a part of the information to be enabled, while the other parts of the information to be enabled are known or pre-agreed. For example, it is also possible to use the arrangement order of each piece of information pre-agreed (such as protocol regulations) to enable specific information, thereby reducing the enabling overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and uniformly enabled to reduce the enabling overhead caused by enabling the same information separately.

[0337] Second, the first, second, and various numerical numbers (such as "#1", "#2", etc.) shown in this application are only for the convenience of description and are used to distinguish objects, and do not limit the scope of the embodiments of this application. For example, to distinguish different messages, etc., rather than for describing a specific order or sequence. It should be understood that the objects described in this way can be interchanged under appropriate circumstances so as to be able to describe solutions other than the embodiments of this application.

[0338] Third, in this application, "pre-configuration" may include pre-definition. For example, protocol definition. Among them, "pre-definition" can be implemented by pre-saving corresponding codes, tables, or other ways that can be used to indicate relevant information in devices (such as including each network element). This application does not limit its specific implementation method.

[0339] Fourth, the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the front and back associated objects.

[0340] Fifth, in the embodiments of this application, when an information (such as information #1) "includes" another information (such as information #2), it can be understood that the information #2 is explicitly or implicitly carried in the information #1. For example, the information #2 is directly carried in the information #1; also for example, the information #1 carries indication information indicating the information #2, and the receiving end device receiving the information #1 can obtain the information #2 according to the indication information, and the indication information used to indicate the information #2 can be pre-defined or protocol-regulated, or explicitly or implicitly indicated.

[0341] Hereinafter, without loss of generality, taking the interaction between network elements as an example, the communication method provided by the embodiments of this application will be described in detail.

[0342] Figure 4 It is a schematic flowchart of a communication method provided by an embodiment of the present application. As Figure 4 shown in (a) of

[0343] S410, a terminal device (an example of a communication device) and an authentication network element negotiate to determine a first key negotiation algorithm.

[0344] Among them, the authentication network element may be an access network device that provides services for the terminal device, or, in the case of separation of the CU and DU of the access network device, the authentication network element may be the CU of the access network device; or the authentication network element is an edge computing node, such as an edge application server (EAS) deployed in an edge data network (EDN), or the authentication network element is a core network element belonging to Operator #1, such as an AMF, an AUSF, a UDM, etc. The Operator #1 may be the operator with which the terminal device is subscribed or other operators, without limitation.

[0345] The first key negotiation algorithm is one of at least one key negotiation algorithm. The first key negotiation algorithm is used for the terminal device and the authentication network element to subsequently negotiate to determine a first key. The first key can be used to encrypt or decrypt messages transmitted between the terminal device and the authentication network element.

[0346] Exemplarily, the at least one key negotiation algorithm may include at least one of the following algorithms:

[0347] Elliptic Curve Diffie–Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie–Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on post-quantum cryptography (PQC), key negotiation algorithm based on PQC and ECDH, key negotiation algorithm based on PQC and ECDHE, and key negotiation algorithm based on pre-shared key (PSK).

[0348] That is, the first key negotiation algorithm determined by the terminal device and the authentication network element is any one of the above key negotiation algorithms.

[0349] It can be understood that for the at least one key negotiation algorithm, the corresponding security levels and computational complexities of the algorithms are different. For example, the sorting of the corresponding security levels of the algorithms from high to low can be: the key negotiation algorithm based on PQC and ECDHE, the key negotiation algorithm based on PQC and ECDH, the key negotiation algorithm based on PQC, the ECDHE key negotiation algorithm, the ECDH key negotiation algorithm, and the key negotiation algorithm based on PSK. The sorting of the corresponding computational complexities of the algorithms is similar to the sorting of the corresponding security levels of the algorithms.

[0350] Optionally, the at least one key negotiation algorithm can also correspond to different network modes. Or rather, each key negotiation algorithm in the at least one key negotiation algorithm can be applicable to one or more network modes.

[0351] For example, the 5G network can correspond to the ECDH key negotiation algorithm, the ECDHE key negotiation algorithm, and the key negotiation algorithm based on PSK; the network in the communication system evolved after 5G, for example, the 6G network, can correspond to the ECDHE key negotiation algorithm, the key negotiation algorithm based on PQC, the key negotiation algorithm based on PQC and ECDH, and the key negotiation algorithm based on PQC and ECDHE.

[0352] For another example, the 5G network can correspond to the ECDH key negotiation algorithm, the ECDHE key negotiation algorithm, and the key negotiation algorithm based on PSK; the network in the communication system evolved after 5G, for example, the 6G network, can correspond to the key negotiation algorithm based on PQC, the key negotiation algorithm based on PQC and ECDH, and the key negotiation algorithm based on PQC and ECDHE.

[0353] It should be understood that the above corresponding relationship between the key negotiation algorithm and the network mode is only an example, and this application does not limit this.

[0354] Specifically, the terminal device and the authentication network element can negotiate and determine the first key negotiation algorithm in the following manner:

[0355] In the first method, the authentication network element determines the first key negotiation algorithm from the at least one key negotiation algorithm, and the specific process can include S411a and S412a.

[0356] In S411a, the terminal device sends indication information #1 (an example of the first indication information) to the authentication network element. Correspondingly, the authentication network element receives the first indication information from the terminal device.

[0357] The indication information #1 indicates the at least one key negotiation algorithm, or the indication information #1 indicates to determine the first key negotiation algorithm from the at least one key negotiation algorithm.

[0358] Optionally, the indication information #1 may further indicate the determination of the first key negotiation algorithm.

[0359] S412a, the authentication network element sends indication information #2 (an example of the second indication information) to the terminal device. Correspondingly, the terminal device receives the indication information #2 from the authentication network element.

[0360] The indication information #2 indicates the first key negotiation algorithm, and the first key negotiation algorithm is one of the at least one key negotiation algorithm described above.

[0361] Specifically, the authentication network element determines the first key negotiation algorithm from at least one key negotiation algorithm and indicates the first key negotiation algorithm to the terminal device.

[0362] Exemplarily, the authentication network element may determine the first key negotiation algorithm based on the first information and the indication information #1.

[0363] Wherein, the first information may include at least one of the following information: the security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the terminal device, and the computing power of the terminal device.

[0364] Exemplarily, the authentication network element may determine the first key negotiation algorithm based on a certain item in the first information.

[0365] For example, if it is determined that the security level requirement for the current communication between the terminal device and the authentication network element is relatively low, the authentication network element may select a key negotiation algorithm with a relatively low security level, such as the ECDH key negotiation algorithm.

[0366] For another example, if it is determined that the computing power of the terminal device is relatively low, or the terminal device is a low-power terminal device, the authentication network element may select a key exchange algorithm with a relatively low computational complexity, such as the ECDH key negotiation algorithm or the key negotiation algorithm based on PSK.

[0367] For another example, if the current network is a 5G network, the authentication network element may select a key negotiation algorithm corresponding to the 5G network, such as one of the ECDH key negotiation algorithm, the ECDHE key negotiation algorithm, and the key negotiation algorithm based on PSK; if the current network is a network in a communication system evolved after 5G, the authentication network element may select one of the ECDH key negotiation algorithm, the ECDHE key negotiation algorithm, and the key negotiation algorithm based on PQC, the key negotiation algorithm based on PQC and ECDH, and the key negotiation algorithm based on PQC and ECDHE.

[0368] Alternatively, the authentication network element determines the first key negotiation algorithm based on multiple pieces of information in the first information.

[0369] For example, the authentication network element can determine the current network mode, select a key negotiation algorithm suitable for the network mode, and on this basis, select a key negotiation algorithm with a higher security level or a lower computational complexity according to the security level requirements or the computing power of the terminal device. For example, on the basis of determining that the current network is a 5G network, the authentication network element can select the ECDHE key negotiation algorithm with a higher security level to ensure the security of communication; or select the PSK-based key negotiation algorithm with a lower computational complexity to reduce the power consumption of the terminal device.

[0370] In the second method, the terminal device determines the first key negotiation algorithm from at least one key negotiation algorithm and indicates the first key negotiation algorithm to the authentication network element. The specific process may include S411b and S412b.

[0371] S411b, the terminal device sends indication information #3 to the authentication network element. Correspondingly, the authentication network element receives the indication information #3 from the terminal device.

[0372] The indication information #3 indicates the first key negotiation algorithm, or the indication information #3 indicates to confirm whether to use the first key negotiation algorithm.

[0373] Specifically, the terminal device determines the first key negotiation algorithm from at least one key negotiation algorithm and indicates the first key negotiation algorithm to the authentication network element.

[0374] Exemplarily, the terminal device can determine the first key negotiation algorithm from at least one key negotiation algorithm based on the first information. The first information can refer to the description in S411a.

[0375] Specific examples of the terminal device determining the first key negotiation algorithm according to the first information refer to the description in S411a. For example, the terminal device can select a key negotiation algorithm corresponding to the security level according to the security level of the current communication. For another example, the terminal device selects a key negotiation algorithm corresponding to the computing power according to its own computing power or type. For another example, the terminal device selects a key negotiation algorithm corresponding to the network mode according to the network mode.

[0376] Optionally, in S412b, the authentication network element sends message #1 to the terminal device. Correspondingly, the terminal device receives message #1 from the authentication network element.

[0377] The message #1 can be an acknowledgment message or a rejection message. The message #1 is sent according to the indication information #3, that is, the authentication network element determines whether to use the first key negotiation algorithm indicated by the indication information #3. If it is confirmed to use the first key negotiation algorithm, the acknowledgment message can be sent to the terminal device; otherwise, the rejection message is sent to the terminal device.

[0378] For example, when the first key negotiation algorithm selected by the terminal device meets the established security level, network mode, etc. of the network, an acknowledgement message is sent to the terminal device; otherwise, a rejection message may be sent to the terminal device.

[0379] Optionally, if the authentication network element sends a rejection message to the terminal device, the rejection message may also carry the reason for rejection. For example, the reason for rejection may be insufficient security level or non - compliance with the requirements of the network mode, etc. After receiving the rejection message, the terminal device may re - determine the first key negotiation algorithm according to the reason for rejection.

[0380] Optionally, the method further includes:

[0381] S420. The authentication network element and the terminal device determine the first key based on the first key negotiation algorithm.

[0382] Exemplarily, when the first key negotiation algorithm is the ECDH key negotiation algorithm, the terminal device sends the public key (denoted as the first public key) in the first temporary public - private key pair generated by the terminal device to the authentication network element; the authentication network element determines the first key based on the first public key and its own private key.

[0383] Optionally, the authentication network element sends its public key to the terminal device, or the public key of the authentication network element may be pre - set in the terminal device; the terminal device generates the first key according to the private key (denoted as the first private key) in the generated first temporary public - private key pair and the public key of the authentication network element.

[0384] The specific process of the authentication network element and the terminal device generating the first key based on the ECDHE key negotiation algorithm may refer to Figure 5 the description in (a) of

[0385] When the first key negotiation algorithm is the ECDHE key negotiation algorithm, the terminal device sends the first public key in the first temporary public - private key pair generated by the terminal device to the authentication network element; the authentication network element determines the first key based on the first public key and the private key (denoted as the second private key) in the second temporary public - private key pair generated by the authentication network element.

[0386] Optionally, the authentication network element sends the public key (denoted as the second public key) in the second temporary public - private key pair to the terminal device; the terminal device generates the first key based on the second public key and the first private key in the first temporary public - private key pair.

[0387] The specific process of the authentication network element and the terminal device generating the first key based on the ECDHE key negotiation algorithm may refer to Figure 5 the description in (b) of

[0388] When the first key negotiation algorithm is the PQC-based key negotiation algorithm, the terminal device sends the public key in the third temporary public-private key pair generated by the post-quantum algorithm (denoted as the third public key) to the authentication network element; the authentication network element inputs the third public key into the post-quantum algorithm to generate a ciphertext and the first key.

[0389] Optionally, the authentication network element sends the ciphertext to the terminal device; the terminal device inputs the ciphertext and the third private key into the post-quantum algorithm to obtain the first key.

[0390] The specific process of the authentication network element and the terminal device generating the first key according to the PQC-based key negotiation algorithm can refer to Figure 5 the description in (c) of

[0391] When the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDH, the terminal device sends the first public key and the third public key to the authentication network element, and the first public key and the third public key refer to the description in the above text; the authentication network element determines the second key based on the first public key and the private key of the authentication network element, and inputs the third public key into the post-quantum algorithm to generate a ciphertext and the third key; the authentication network element determines the first key based on the second key and the third key.

[0392] Optionally, the authentication network element sends the public key of the authentication network element and the ciphertext to the terminal device; the terminal device generates the second key based on the first private key and the public key of the authentication network element, and inputs the ciphertext and the third private key into the post-quantum algorithm to obtain the third key; the terminal device determines the first key according to the second key and the third key.

[0393] The specific process of the authentication network element and the terminal device generating the first key according to the key negotiation algorithm based on PQC and ECDH can refer to Figure 5 the description in (d) of

[0394] When the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE, the terminal device sends the first public key and the third public key to the authentication network element, and the first public key and the third public key refer to the description in the above text; the authentication network element determines the second key based on the first public key and the second private key, and inputs the third public key into the post-quantum algorithm to generate a ciphertext and the third key, where the second private key refers to the description in the above text; the authentication network element determines the first key based on the second key and the third key.

[0395] Optionally, the authentication network element sends the second public key and the ciphertext to the terminal device; the terminal device generates the second key based on the first private key and the second public key, and inputs the ciphertext and the third private key into the post-quantum algorithm to obtain the third key; the terminal device determines the first key according to the second key and the third key. Wherein, the second public key and the first private key refer to the descriptions in the above text.

[0396] For the specific process of the authentication network element and the terminal device generating the first key according to the key agreement algorithm based on PQC and ECDHE, reference can be made to Figure 5 the description in (e) of

[0397] In the case where the first key agreement algorithm is the key agreement algorithm based on PSK, before key agreement, at least one key is pre-set in the terminal device and the authentication network element, and the at least one key corresponds to at least one identifier one by one, or rather, the corresponding relationship between at least one key and at least one identifier is pre-set in the terminal device and the authentication network element (denoted as correspondence #2). The terminal device sends the identifier corresponding to the first key to the authentication network element, and the first key is one of the at least one key; the authentication network element determines the first key according to the identifier of the first key and the correspondence #2.

[0398] For the specific process of the authentication network element and the terminal device generating the first key according to the key agreement algorithm based on PSK, reference can be made to Figure 5 the description in (f) of

[0399] Optionally, the method further includes: the authentication network element sends the certificate of the authentication network element (or the certificate of the authentication network element is pre-set in the terminal device), and the digital signature of the first message by the private key of the authentication network element (an example of the first digital signature). The first message may include the messages interacted between the authentication network element and the terminal device; the terminal device verifies the first digital signature according to the certificate of the authentication network element, so as to verify the authentication network element.

[0400] Exemplarily, if the certificate of the authentication network element is issued by the operator, or rather, the signature of the certificate of the authentication network element is generated by the private key of the operator, then the terminal device can verify the certificate of the authentication network element based on the certificate of the operator. Further, the terminal device verifies the first digital signature based on the public key in the certificate of the authentication network element, so as to authenticate the authentication network element.

[0401] For example, the terminal device may pre-set the certificate of the operator, or receive the certificate of the operator from the authentication network element, and the certificate of the operator includes the public key of the operator; the terminal device may use the public key in the certificate of the operator to verify the signature of the certificate of the authentication network element by the private key of the operator; and then verify the first digital signature based on the public key of the authentication network element. If the above processes are all verified successfully, it means that the authentication of the terminal device to the authentication network element is successful.

[0402] Alternatively, the terminal device may verify the first digital signature based on the public key in the certificate of the authentication network element, thereby authenticating the authentication network element.

[0403] It should be understood that the authentication network element sending the certificate of the authentication network element and / or the first digital signature to the terminal device may be during the key negotiation process. For example, when the authentication network element sends the public key or the second public key or the ciphertext of the authentication network element to the terminal device, it sends the certificate of the authentication network element and / or the first digital signature to the terminal device at the same time. Alternatively, it may also be independent of the key negotiation process, which is not limited in this application.

[0404] Wherein, the certificate of the authentication network element may include the identifier of the authentication network element, the public key of the authentication network element, information about the issuer of the certificate, such as the identifier of the issuer, the signature of the issuer, etc., and information about the certificate, such as the validity period of the certificate, the version number, etc.

[0405] It should be understood that if the certificate of the authentication network element is pre - installed in the terminal device, the step of the authentication network element sending the certificate of the authentication network element to the terminal device may not be executed.

[0406] It should be understood that the certificate of the authentication network element and the first digital signature may be carried in the same message for sending, or sent separately, which is not limited. For example, it is sent through an RRC message or an NAS message, or other downlink signaling, which is not limited.

[0407] Optionally, the method further includes:

[0408] S430, the terminal device and the authentication network element negotiate to determine a first authentication method.

[0409] The first authentication method is one of at least one authentication method. The authentication information corresponding to each authentication method in the at least one authentication method is independent of each other. For example, the authentication information corresponding to each authentication method is different, and / or the authentication process corresponding to each authentication method is different.

[0410] Exemplarily, the authentication information may include at least one of the following information: the credential of the terminal device, and the cryptographic algorithm.

[0411] Wherein, the credential of the terminal device may include at least one verifiable credential (VC) or at least one verifiable attestation (VA) of the terminal device. The credential information corresponding to different credentials is different. The credential information may include information about the issuer of the credential, the public key of the terminal device, the valid time of the credential, etc.

[0412] The information of the issuer of the certificate may include the public key of the certificate issuer, the identifier and / or name of the certificate issuer. For example, the certificate issuer may be different operators, card providers, terminal manufacturers, authoritative institutions, third-party trusted institutions, or over-the-air writing card servers, etc.

[0413] Among them, the cryptographic algorithm may also be referred to as a cryptographic suite. The cryptographic algorithm includes at least one of the following: key length, encryption algorithm, decryption algorithm, signature algorithm, or public parameters, etc.

[0414] Alternatively, the authentication information may include the root key of the terminal device, the authentication vector (AV) of the terminal device, or the address of the smart contract. Among them, the authentication vector is determined according to the root key of the terminal device; the address of the smart contract can be used to obtain the authentication vector of the terminal device saved on the smart contract. For example, the authentication vector may be an extensible authentication protocol - authentication and key agreement (EAP - AKA) AV, or a 5G home environment authentication vector (5G HE AV).

[0415] It should be understood that the above authentication vectors are only examples, and the present application is not limited thereto.

[0416] Optionally, the types of the first identifiers indicated by each authentication method in the at least one authentication method are different.

[0417] Among them, the first identifier has a corresponding relationship with the authentication information of the terminal device (denoted as corresponding relationship #1), and the first identifier can be used to obtain the authentication information of the terminal device.

[0418] Exemplarily, the corresponding relationship #1 can be saved in a storage system, for example, the storage system 102 described above. Specifically, it can be saved in the corresponding storage node of the storage system. For example, if the storage system is a blockchain system, the storage node may be a blockchain node. For example, the corresponding relationship can be stored on the blockchain node in the form of a block or a transaction, that is, the information is uploaded to the chain; if the storage system is a distributed storage system, the storage node may be a node in the distributed storage system. In some possible scenarios, the distributed storage node may be a blockchain node; if the storage system is a communication system, the storage node may be a communication device in the communication system, such as a functional network element capable of saving the subscription data of the terminal device.

[0419] The type of the first identifier can be any one of the following, or rather, the first identifier can include identifiers of any of the following types: identifiers of the first type, identifiers of the second type, identifiers of a block or a transaction, and pseudo identifiers.

[0420] Among them, the identifiers of the first type include but are not limited to the following identifiers:

[0421] Subscription Permanent Identifier (SUPI), Subscription Concealed Identifier (SUCI), Generic Public Subscription Identifier (GPSI), Permanent Equipment Identifier (PEI), or Mobile Subscriber International ISDN / PSTN Number (MSISDN), where ISDN is the Integrated Service Digital Network and PSTN is the Public Switched Telephone Network, etc.

[0422] The identifier of the second type is the scID of the terminal device, and the identifier of the second type can be DRC, DIC, or DSCC.

[0423] Among them, the identifier of the first type can be understood as an identifier assigned by the network side or the access network side to the terminal device, or a permanent identifier of the terminal device. The identifier of the first type is universal and can be applied to the authentication of terminal devices in 5G communication systems or communication systems before 5G; the identifier of the second type can be generated by the terminal device or other trusted nodes other than the terminal device (for example, the storage node shown in Figure 2 . Compared with the identifier of the first type, the generation of the identifier of the second type is more flexible. Secondly, the identifier of the second type can be applied to service scenarios with high requirements for personal information confidentiality.

[0424] The identifier of the block or the transaction can be used to obtain the corresponding relationship #1 stored on the blockchain. In other words, when the first identifier is the identifier of the block or the transaction, the corresponding relationship #1 stored on the blockchain can be obtained through the first identifier.

[0425] The virtual identifier has a corresponding relationship with the identifier of the second type. That is, when the first identifier is a virtual identifier, the identifier of the second type is determined through the corresponding relationship between the virtual identifier and the identifier of the second type. Compared with directly using the identifier of the second type, the use of a virtual identifier can further enhance the security of communication.

[0426] Specifically, the terminal device and the authentication network element can negotiate and determine the first authentication method in the following manner:

[0427] Method 1: The authentication network element determines the first authentication method from the at least one authentication method. The specific process may include S431a and S432a.

[0428] S431a: The terminal device sends indication information #4 (an example of the third indication information) to the authentication network element. Correspondingly, the authentication network element receives the indication information #4 from the terminal device.

[0429] The indication information #4 can indicate at least one authentication method. Or rather, the indication information #4 can indicate to determine the first authentication method from the at least one authentication method.

[0430] Alternatively, the indication information #4 indicates to determine the first authentication method.

[0431] S432a: The authentication network element sends indication information #5 (an example of the fourth indication information) to the terminal device. Correspondingly, the terminal device receives the indication information #5 from the authentication network element.

[0432] Among them, the indication information #5 indicates the first authentication method.

[0433] Specifically, the authentication network element can determine the first authentication method from at least one authentication method based on the second information.

[0434] Among them, the second information may include at least one of the following information: information of the issuer of the credential, security level of the credential, security level of the cryptographic algorithm, computational complexity of the cryptographic algorithm.

[0435] For example, if the credentials of the terminal device include credentials issued by a card merchant and credentials issued by an operator. The authentication network element can select the credentials issued by the operator to which the network accessed this time belongs for verification. That is, the first authentication method can correspond to the credentials issued by the operator to which the network accessed this time belongs.

[0436] For another example, if the terminal device has two types of certificates, one is a post-quantum certificate and the other is a non-post-quantum certificate (such as Rivest-Shamir-Adleman (RSA) certificate, Elliptic Curve Digital Signature Algorithm (ECDSA) certificate), the authentication network element can select the certificate with a higher security level based on the security level of the certificate (for example, the post-quantum certificate). That is, this first authentication method can correspond to the post-quantum certificate of the terminal device.

[0437] Method 2: The terminal device determines the first authentication method from the at least one authentication method and indicates the first authentication method to the authentication network element. The specific determination method can include S431b and S432b:

[0438] S431b: The terminal device sends indication information #6 to the authentication network element. Correspondingly, the authentication network element receives the indication information #6 from the terminal device.

[0439] The indication information #6 indicates the first authentication method, or the indication information #6 indicates to confirm whether to use the first authentication method.

[0440] Specifically, the terminal device determines the first authentication method from the at least one authentication method according to the second information and sends the indication information #6 to the authentication network element.

[0441] For a specific example of how the terminal device determines the first authentication method according to the second information, refer to the description in S432a.

[0442] Optionally, in S432b, the authentication network element sends message #2 to the terminal device. Correspondingly, the terminal device receives message #2 from the authentication network element.

[0443] The message #2 can be an acknowledgment message or a rejection message. The message #2 is sent according to the indication information #6, that is, the authentication network element determines whether to use the first authentication method indicated by the indication information #6. If it is confirmed to use the first authentication method, the acknowledgment message can be sent to the terminal device; otherwise, the rejection message is sent to the terminal device.

[0444] For example, when the second information corresponding to the first authentication method selected by the terminal device meets the established requirements of the network (such as the issuer of the required credential, the security level of the required credential, etc.), an acknowledgment message is sent to the terminal device; otherwise, a rejection message can be sent to the terminal device.

[0445] Optionally, if the authentication network element sends a rejection message to the terminal device, the rejection message may also carry the reason for rejection. For example, the reason for rejection may be that the security level of the credential is insufficient, or it is not the issuer of the required credential, etc. After receiving the rejection message, the terminal device may re-determine the first authentication method according to the reason for rejection.

[0446] It should be understood that this application does not limit the timing of determining the execution of the authentication method, that is, it does not limit the execution timing of S430. For example, S430 may be executed before or after S410.

[0447] Optionally, the method further includes:

[0448] S440, the terminal device sends a request message to the authentication network element. Correspondingly, the authentication network element receives the request message from the terminal device.

[0449] Wherein, the request message is used to request access to the network, and the request message includes the first identifier encrypted by the first key (that is, the key determined by the terminal device according to the first key negotiation algorithm).

[0450] Exemplarily, the format of the request message may be as Figure 4 shown in (b) of. The request message may include a plaintext part and a ciphertext part.

[0451] Among them, the plaintext part may carry the type of the first identifier. The type of the first identifier may be any one of the above-mentioned first type, second type, or the type of virtual identifier. It can be understood that the type of the first identifier can be determined by the first authentication method; the network identifier (for example, the network identifier is the identifier of the terminal device's subscribed operator); the public key on the network side (or the identifier of the public key on the network side), that is, the public key of the verification network element used by the terminal device. For example, the public key of the verification network element is the public key of the verification network element used by the terminal device in the ECDH key negotiation algorithm, ECDHE key negotiation algorithm, key negotiation algorithm based on PQC and ECDH, and key negotiation algorithm based on PQC and ECDHE; the temporary public key of the terminal device. For example, the temporary public key is the temporary public key used by the terminal device in the ECDH key negotiation algorithm, ECDHE key negotiation algorithm, key negotiation algorithm based on PQC, key negotiation algorithm based on PQC and ECDH, and key negotiation algorithm based on PQC and ECDHE (for example, the first public key or the third public key), or the temporary public key is the key pre-set on the terminal device side in the key negotiation algorithm based on PSK. Optionally, the plaintext part further includes the identifier of the blockchain. That is, when the authentication information of the terminal device is stored on the blockchain and there are multiple blockchains, the identifier of the blockchain is used to identify the blockchain where the authentication information of the current terminal device is located. The ciphertext part of the request message may include the encrypted first identifier. Optionally, the ciphertext part may further include a session identifier for identifying this key negotiation.

[0452] Optionally, the terminal device sends a second digital signature to the verification network element. The second digital signature is the signature of the private key of the terminal device on the second message or the hash value of the second message. Among them, the second message may include the messages exchanged between the terminal device and the verification network element.

[0453] Exemplarily, the messages exchanged between the terminal device and the verification network element may include the most recent message sent by the terminal device to the verification network element. For example, the exchanged message may include the message carrying the second digital signature; or the exchanged message may include the messages after the terminal device sends the request message to the verification network element (including the request message) and before the most recent message sent to the verification network element (which may include the most recent message sent to the verification network element). For example, the most recent message sent is the message carrying the second digital signature. Optionally, before the terminal device sends the second digital signature to the verification network element, the terminal device may store the messages exchanged with the verification network element.

[0454] Among them, the message carrying the first digital signature may be an RRC message or an NAS message.

[0455] Exemplarily, the terminal device may determine the private key of the terminal device corresponding to the first authentication method according to the first authentication method, and use the private key to sign the second message or the hash value of the second message. The terminal device may also determine the signature algorithm used for the signature according to the first authentication method.

[0456] The second digital signature may be carried in the request message or other uplink messages, which is not limited.

[0457] S450, the authentication network element obtains the first authentication information of the terminal device according to the first identifier.

[0458] Specifically, after receiving the request message from the terminal device, the authentication network element may decrypt to obtain the first identifier based on the first key (i.e., the key determined by the authentication network element according to the first key negotiation algorithm), and obtain the first authentication information of the terminal device according to the first identifier.

[0459] Exemplarily, if the first identifier is an identifier of the first type, the authentication network element may obtain the root key of the terminal device or the authentication vector of the terminal device based on the user permanent identifier. That is, the first authentication information may include the root key or authentication vector of the terminal device.

[0460] If the first identifier is an identifier of the second type, the authentication network element obtains the first credential of the terminal device according to the identifier of the second type and the corresponding relationship #1, where the first credential is one of at least one credential of the terminal device. Exemplarily, the authentication network element may determine the first credential from the at least one credential based on the first authentication method. That is, the first authentication information may include the first credential.

[0461] If the first identifier is an identifier of a block or a transaction, the authentication network element obtains the corresponding relationship #1 saved on the blockchain based on the identifier of the block or the transaction, and selects the first credential from at least one credential of the terminal device. Exemplarily, the authentication network element may determine the first credential from the at least one credential based on the first authentication method. That is, the first authentication information may include the first credential.

[0462] If the first identifier is a virtual identifier, the authentication network element determines the identifier of the second type according to the virtual identifier and the corresponding relationship between the virtual identifier and the identifier of the second type; further, the authentication network element obtains the first credential according to the identifier of the second type and the corresponding relationship #1. Exemplarily, the authentication network element may determine the first credential from the at least one credential based on the first authentication method. That is, the first authentication information may include the first credential.

[0463] S460, the authentication network element authenticates the communication device based on the first authentication information.

[0464] In a possible implementation, the authentication network element authenticates the terminal device based on the root key or authentication vector of the terminal device.

[0465] For example, the authentication network element may generate an authentication vector based on the root key; the authentication network element sends some parameters in the authentication vector to the terminal device so that the terminal device determines other parameters in the authentication vector; the authentication network element may compare the other parameters in the saved authentication vector with the other parameters determined by the terminal device, thereby determining whether the authentication of the terminal device is successful.

[0466] In another possible implementation, the authentication network element authenticates the terminal device based on the first credential.

[0467] Exemplarily, the authentication network element may verify the first credential based on the credential of the first credential issuer (including the public key of the credential issuer), that is, verify the signature of the first credential issuer on the first credential through the public key of the first credential issuer; if the verification is successful, further, the authentication network element verifies the second digital signature based on the public key corresponding to the first credential, thereby determining whether the authentication of the terminal device is successful.

[0468] Optionally, the authentication network element may directly verify the second digital signature based on the public key corresponding to the first credential, thereby determining whether the authentication of the terminal device is successful.

[0469] The following is combined with Figure 5 When introducing that the first key negotiation algorithm is different algorithms, the specific determination method of the first key is described. It should be understood that the present application does not limit the specific names of the following algorithms.

[0470] Figure 5 As shown in (a) of Figure 5 As shown in (a) of

[0471] S501a, the terminal device sends a first public key to the authentication network element. Correspondingly, the authentication network element receives the first public key from the communication device.

[0472] Exemplarily, the terminal device generates a temporary public-private key pair (denoted as the first temporary public-private key pair), and the terminal device sends the public key in the first temporary public-private key pair to the authentication network element. That is, the first public key is the public key in the first temporary public-private key pair.

[0473] For example, the terminal device may generate a random number (denoted as random number #1) as the private key (denoted as the first private key) in the first public-private key pair, and generate the public key in the first public-private key pair based on the elliptic curve algorithm, that is, the first public key.

[0474] Exemplarily, the first public key may be carried in Message #1, which may be an RRC message, an NAS message, or other uplink signaling, and the present application does not make any limitation.

[0475] Optionally, the terminal device sends Identification #1 to the authentication network element. Identification #1 is used to identify this key exchange, or in other words, Identification #1 can be used as the unique identifier for this key exchange process.

[0476] Exemplarily, Identification #1 may be carried in Message #1 together with the first public key, or sent separately, and the present application does not make any limitation.

[0477] S502 a. The authentication network element determines the first key based on the first public key and the private key of the authentication network element (denoted as Private Key #1).

[0478] Exemplarily, Private Key #1 may be the private key of the authentication network element. The public key of the authentication network element corresponding to Private Key #1 (denoted as Public Key #1) may be pre - configured in the terminal device. Public Key #1 is the public key of the authentication network element pre - configured in the terminal device.

[0479] Optionally, the authentication network element sends the certificate of the authentication network element to the terminal device. Exemplarily, the certificate of the authentication network element may refer to the description in S420.

[0480] Optionally, the certificate of the authentication network element may also be pre - configured in the terminal device. It should be understood that if the certificate of the authentication network element is pre - configured in the terminal device, the step of the authentication network element sending the certificate of the authentication network element to the terminal device may not be executed.

[0481] Optionally, S503a. The authentication network element sends a first digital signature to the terminal device.

[0482] The first digital signature is the digital signature of the first message using the private key of the authentication network element. The first message may include the messages exchanged between the authentication network element and the terminal device. For example, the message #1.

[0483] Among them, the certificate of the authentication network element and the signature of the first message using the private key of the authentication network element may be carried in Message #2 together, or sent separately, without any limitation. Message #2 may be an RRC message, an NAS message, or other downlink signaling, without any limitation.

[0484] S504 a. The terminal device determines the first key based on Public Key #1 and the first private key.

[0485] Optionally, S505a. The terminal device verifies the first digital signature based on the public key of the authentication network element, thereby authenticating the authentication network element.

[0486] Based on the above solution, the use of the ECDH key negotiation algorithm can reduce the computational complexity in the key negotiation process. That is, the first key is generated by the terminal device using the public key of the authentication network element and the private key in the temporary public-private key pair generated by the terminal device, and the authentication network element generates the first key based on the private key of the authentication network element and the temporary public key generated by the terminal device, which can reduce the computational complexity.

[0487] Figure 5 As shown in (b) of, the method for determining the first key based on the ECDHE key negotiation algorithm is that the first key negotiation algorithm is the ECDHE key negotiation algorithm. As Figure 5 shown in (b) of, determining the first key based on the first key negotiation algorithm may include the following steps:

[0488] S501b, the terminal device sends a first public key to the authentication network element. Correspondingly, the authentication network element receives the first public key from the communication device.

[0489] For the specific implementation of this step, reference may be made to the description of S501a.

[0490] S502b, the authentication network element determines the first key based on the first public key and the second private key.

[0491] Exemplarily, the authentication network element generates a temporary public-private key pair (denoted as the second temporary public-private key pair), and the second private key is the private key in the second public-private key pair; the authentication network element calculates the first key based on the first public key and the second private key.

[0492] For example, the authentication network element may generate a random number (denoted as random number #2) as the private key in the second public-private key pair, that is, the second private key, and generate the public key (denoted as the second public key) in the second public-private key pair based on the elliptic curve algorithm.

[0493] S503b, the authentication network element sends the second public key to the terminal device. Correspondingly, the terminal device receives the second public key from the authentication network element.

[0494] Exemplarily, the second public key may be carried in message #3, and message #3 may be an NAS message, an RRC message, or other downlink signaling, without limitation.

[0495] Optionally, the authentication network element sends the certificate of the authentication network element to the terminal device. The certificate of the authentication network element may refer to the description in S502a.

[0496] Optionally, the authentication network element sends the digital signature of the private key of the authentication network element on the first message to the terminal device. The first message may include the messages interacted between the authentication network element and the terminal device. For example, the message #1 and / or message #3.

[0497] S504b, the terminal device determines a first key based on the second public key and the first private key.

[0498] That is, the terminal device calculates the first key based on the public key in the temporary public-private key pair generated by the received authentication network element and the private key in the temporary public-private key pair generated by the terminal device.

[0499] Optionally, the terminal device authenticates the first digital signature based on the certificate of the authentication network element, thereby authenticating the authentication network element.

[0500] Based on the above solution, by using the ECDHE key negotiation algorithm, the authentication network element and the terminal device use the temporary public keys generated by each other to generate the first key, improving the security of key exchange. Secondly, the computational complexity of this key negotiation algorithm is relatively low, and it can be applied to communication scenarios with relatively low computational complexity requirements for key negotiation algorithms and high security requirements. At the same time, this key negotiation algorithm can be compatible with 5G communication systems or communication systems before 5G.

[0501] Figure 5 As shown in (c) of [], the method for determining the first key based on the PQC-based key negotiation algorithm is that the first key negotiation algorithm is a PQC-based key negotiation algorithm. As Figure 5 As shown in (c) of [], determining the first key based on the PQC-based key negotiation algorithm may include the following steps:

[0502] S501c, the terminal device sends a third public key to the authentication network element. Correspondingly, the authentication network element receives the third public key from the terminal device.

[0503] Exemplarily, the terminal device generates a temporary public-private key pair (denoted as the third temporary public-private key pair) based on a post-quantum algorithm, and the terminal device sends the public key in the third temporary public-private key pair to the authentication network element. That is, the third public key is the public key in the third temporary public-private key pair.

[0504] Exemplarily, the third public key may be carried in message #3, and message #3 may be an RRC message, an NAS message, or other uplink signaling, which is not limited in this application.

[0505] Optionally, the terminal device sends identification #1 to the authentication network element. Identification #1 is used to identify this key exchange. Exemplarily, identification #1 may be carried in message #1 together with the first public key, or sent separately, which is not limited in this application.

[0506] S502c, the authentication network element generates a ciphertext and the first key based on the post-quantum algorithm and the third public key.

[0507] Exemplarily, the authentication network element uses the third public key as the input of the post-quantum algorithm to obtain the ciphertext and the first key. In the specific calculation process, the authentication network element randomly selects an m, encrypts m to obtain the ciphertext, and performs a hash operation on the ciphertext and the random number to obtain the first key.

[0508] S503c, the authentication network element sends the ciphertext to the terminal device. Correspondingly, the terminal device receives the ciphertext from the authentication network element.

[0509] Exemplarily, the ciphertext can be carried in Message #4, and Message #4 can be a NAS message, an RRC message, or other downlink signaling, without limitation.

[0510] Optionally, the authentication network element sends the certificate of the authentication network element to the terminal device. The certificate of the authentication network element can be used by the terminal device to authenticate the authentication network element. Alternatively, the certificate of the authentication network element can also be pre-configured in the terminal device. The certificate can refer to Figure 5 the description in S3 of (b) of

[0511] Optionally, the authentication network element sends the digital signature of the private key of the authentication network element on the first message to the terminal device. The first message can include the messages interacted between the authentication network element and the terminal device. For example, the message #1.

[0512] Among them, the certificate of the authentication network element and the signature of the private key of the authentication network element on the first message can be carried in Message #4 at the same time, or sent separately, without limitation.

[0513] S504c, the terminal device generates the first key based on the ciphertext and the post-quantum algorithm.

[0514] Exemplarily, the terminal device uses the ciphertext and the private key in the third temporary public-private key (denoted as the third private key) as the input of the post-quantum algorithm to calculate and obtain the first key.

[0515] Optionally, the terminal device authenticates the authentication network element by verifying the first digital signature based on the certificate of the authentication network element.

[0516] Based on the above solution, by using the key agreement algorithm based on PQC, the authentication network element and the terminal device can use PQC to generate the first key, which can improve the security of key exchange. The key agreement algorithm is applicable to communication scenarios with high security requirements.

[0517] Figure 5 The method shown in (d) of Figure 5As shown in (d) of [description], the key negotiation algorithm based on PQC and ECDHE may include the following steps:

[0518] S501d, the terminal device sends the first public key and the third public key to the authentication network element. Correspondingly, the authentication network element receives the first public key and the third public key from the terminal device.

[0519] Exemplarily, the first public key is the public key in the first temporary public-private key pair; the third public key is the public key in the third temporary public-private key pair.

[0520] Among them, the first temporary public-private key pair is the public key in the temporary public-private key pair generated by the terminal device based on the elliptic curve algorithm, and specifically, it can refer to the first public key in S501b; the third public key is the public key in the temporary public-private key pair generated by the terminal device based on the post-quantum algorithm, and specifically, it can refer to the third public key in S501c.

[0521] S502d, the authentication network element generates a second key based on the first public key and the private key of the authentication network element, and generates a third key based on the third public key.

[0522] The public key of the authentication network element corresponding to the private key of the authentication network element (denoted as public key #1) can be pre-set in the terminal device.

[0523] The authentication network element uses the third public key as the input of the post-quantum algorithm to obtain the ciphertext and the third key. Specifically, it can refer to the description of generating the first key based on the third public key in S502c.

[0524] S503d, the authentication network element generates the first key based on the second key and the third key.

[0525] S504d, the authentication network element sends the ciphertext to the terminal device. Correspondingly, the terminal device receives the ciphertext from the authentication network element.

[0526] This step can refer to the description in S503c.

[0527] Optionally, if the public key #1 is not pre-set in the terminal device, the authentication network element sends the public key #1 to the terminal device.

[0528] Optionally, the authentication network element sends the certificate of the authentication network element to the terminal device. The certificate of the authentication network element can be used by the terminal device to verify the authentication network element. Alternatively, the certificate of the authentication network element can also be pre-set in the terminal device. The certificate can refer to Figure 5 the description in S3 of (a) of [description].

[0529] Optionally, the authentication network element sends the digital signature of the private key of the authentication network element on the first message. The first message may include the messages interacted between the authentication network element and the terminal device.

[0530] In S505d, the terminal device generates a first key based on the ciphertext and a post-quantum algorithm.

[0531] Exemplarily, the terminal device generates the second key based on the first private key and the public key of the authentication network element, i.e., public key #1. The first private key is the private key in the first temporary public-private key pair.

[0532] The terminal device uses the ciphertext and the third private key as the input of the post-quantum algorithm to calculate the third key. Further, the terminal device generates the first key based on the second key and the third key.

[0533] Optionally, the terminal device authenticates the authentication network element by verifying the first digital signature based on the certificate of the authentication network element.

[0534] Based on the above solution, by using the key agreement algorithm based on PQC and ECDH, the authentication network element and the communication device can generate the first key based on the key generated by PQC and the key generated by ECDH. Compared with the key agreement algorithm based on PQC, the security of key exchange is further improved. This key agreement algorithm is applicable to communication scenarios with higher security requirements.

[0535] Figure 5 As shown in (e), the method for determining the first key by the key agreement algorithm based on PQC and ECDHE (or the key agreement algorithm integrating PQC and ECDHE) is presented, i.e., the first key agreement algorithm is the key agreement algorithm based on PQC and ECDHE. As Figure 5 As shown in (d), the key agreement algorithm based on PQC and ECDHE may include the following steps:

[0536] S501e, the terminal device sends the first public key and the third public key to the authentication network element. Correspondingly, the authentication network element receives the first public key and the third public key from the terminal device.

[0537] This step can refer to S501d.

[0538] S502e, the authentication network element generates a second key based on the first public key and the second private key, and generates a third key based on the third public key.

[0539] The second private key can be the private key in the temporary public-private key pair generated by the authentication network element.

[0540] The specific process of the authentication network element generating the third key based on the third public key can refer to the description of generating the first key based on the third public key in S502c.

[0541] S503e, the authentication network element generates the first key based on the second key and the third key.

[0542] In S504e, the authentication network element sends the ciphertext and the second public key to the terminal device. Correspondingly, the terminal device receives the ciphertext and the second public key from the authentication network element.

[0543] The second public key may be the public key in the temporary public-private key pair generated by the authentication network element.

[0544] Optionally, the authentication network element sends the certificate of the authentication network element to the terminal device. The certificate of the authentication network element can be used by the terminal device to authenticate the authentication network element. Alternatively, the certificate of the authentication network element can also be pre-set in the terminal device. The certificate can refer to Figure 5 the description in S3 of (a) in

[0545] Optionally, the authentication network element sends the digital signature of the private key of the authentication network element on the first message (an example of the first digital signature) to the terminal device. The first message may include the messages that the authentication network element has interacted with the terminal device.

[0546] In S505e, the terminal device generates a first key based on the ciphertext and the post-quantum algorithm.

[0547] Exemplarily, the terminal device generates the second key based on the first private key and the second public key. The first private key is the private key in the first temporary public-private key pair.

[0548] The terminal device takes the ciphertext and the third private key as the input of the post-quantum algorithm, and calculates the third key. Further, the terminal device generates the first key based on the second key and the third key.

[0549] Optionally, the terminal device authenticates the authentication network element by verifying the first digital signature based on the certificate of the authentication network element.

[0550] Based on the above solution, by using the key negotiation algorithm based on PQC and ECDHE, the authentication network element and the terminal device can generate the first key based on the key generated by PQC and the key generated by ECDHE. Among them, ECDHE has forward security. Compared with the key negotiation algorithms based on PQC and ECDH, this key negotiation algorithm can be applied to communication scenarios with higher security requirements.

[0551] Figure 5 The method shown in (f) of

[0552] Exemplarily, when the terminal device signs a contract with the operator, the operator node can write the corresponding relationship #2 into the terminal device by over-the-air card writing.

[0553] S501 f, the terminal device sends the identifier #1 to the authentication network element. Correspondingly, the authentication network element receives the identifier #1 from the terminal device.

[0554] The identifier #1 is one of the at least one identifier, and the identifier #1 is used to identify one of the at least one keys (denoted as key k). It can be understood that the key k is the first key determined by the terminal device.

[0555] S502 f, the authentication network element determines the first key based on the identifier #1 and the corresponding relationship #1.

[0556] Exemplarily, the authentication network element can query the key corresponding to the identifier #1 from the corresponding relationship #1 based on the identifier #1, that is, the authentication network element determines the first key.

[0557] Based on the above solution, by using the key negotiation algorithm based on PSK, the authentication network element and the terminal device can use the pre-set key to generate the first key. The computational complexity of this key negotiation algorithm is relatively low and can be applied to communication scenarios with relatively low computational complexity of the key negotiation algorithm.

[0558] Figure 6 It is a schematic flowchart of a communication method provided by an embodiment of the present application. The method may include the following steps.

[0559] S610, the terminal device (an example of the terminal device) sends a temporary public key to the authentication network element. Correspondingly, the authentication network element receives the temporary public key from the terminal device.

[0560] Wherein, the temporary public key is the public key in the temporary public-private key pair generated by the terminal device. The temporary public-private key pair may include a first temporary public-private key pair and / or a third temporary public-private key pair, respectively referring to the descriptions in S501b and S501c. Correspondingly, the temporary public key may include a first public key and / or a third public key, respectively referring to the above descriptions.

[0561] Optionally, the method further includes: the authentication network element determines the first key based on the temporary public key. The authentication network element determining the first key based on the temporary public key may include the following examples:

[0562] Example #1, the temporary public key is the first public key, and the authentication network element determines the first key based on the ECDH key negotiation algorithm.

[0563] In this example, the authentication network element determines the first key based on the first public key and the private key of the authentication network element.

[0564] Optionally, the authentication network element sends the public key of the authentication network element to the terminal device; the terminal device determines the first key according to the first private key and the public key of the authentication network element, where the first private key is the private key in the first temporary public-private key pair.

[0565] The specific process of the authentication network element and the terminal device determining the first key can refer to Figure 5 the description in (a) of

[0566] Example #2, where the temporary public key is the first public key, and the authentication network element determines the first key based on the ECDHE key negotiation algorithm.

[0567] In this example, the authentication network element determines the first key based on the first public key and the private key in the second temporary public-private key pair generated by the authentication network element.

[0568] Optionally, the authentication network element sends the second public key to the terminal device, where the second public key is the public key in the second temporary public-private key pair; the terminal device determines the first key according to the second public key.

[0569] The specific process of the authentication network element and the terminal device determining the first key can refer to Figure 5 the description in (b) of

[0570] Example #3, where the temporary public key is the third public key, and the authentication network element determines the first key based on the PQC key negotiation algorithm.

[0571] In this example, the authentication network element inputs the third public key into the post-quantum algorithm to generate a ciphertext and the first key.

[0572] Optionally, the authentication network element sends the ciphertext to the terminal device; the terminal device obtains the first key by inputting the third private key and the ciphertext into the post-quantum algorithm.

[0573] The specific process of the authentication network element and the terminal device determining the first key can refer to Figure 5 the description in (c) of

[0574] Example #4, where the temporary public key includes the first public key and the third public key, and the authentication network element determines the first key based on the PQC and ECDH key negotiation algorithms.

[0575] In this example, the authentication network element determines the second key based on the first public key and the private key of the authentication network element, and inputs the third public key into the post-quantum algorithm to generate a ciphertext and the third key; the authentication network element determines the first key based on the second key and the third key.

[0576] Optionally, the authentication network element sends the public key of the authentication network element and the ciphertext to the terminal device; the terminal device may generate the second key according to the public key of the authentication network element and the first private key (refer to the description in the above text), and input the third private key (refer to the description in the above text) and the ciphertext into the post-quantum algorithm to obtain the third key; the terminal device determines the first key according to the second key and the third key.

[0577] For the specific process of the authentication network element and the terminal device to determine the first key, reference can be made to Figure 5 the description in (d) of

[0578] Example #5, the ephemeral public key includes the first public key and the third public key, and the authentication network element determines the first key based on PQC and the ECDHE key negotiation algorithm.

[0579] In this example, the authentication network element determines the second key based on the first public key and the second private key, and inputs the third public key into the post-quantum algorithm to generate the ciphertext and the third key, where the second private key refers to the description in the above text; the authentication network element determines the first key based on the second key and the third key.

[0580] Optionally, the authentication network element sends the second public key and the ciphertext to the terminal device; the terminal device may generate the second key according to the second public key and the first private key (refer to the description in the above text), and input the third private key (refer to the description in the above text) and the ciphertext into the post-quantum algorithm to obtain the third key; the terminal device determines the first key according to the second key and the third key.

[0581] For the specific process of the authentication network element and the terminal device to determine the first key, reference can be made to Figure 5 the description in (e) of

[0582] Optionally, the terminal device indicates to the authentication network element the identifier corresponding to the key k (an example of the first key), where the key k is one of at least one key pre-configured in the terminal device, and there is a corresponding relationship (denoted as corresponding relationship #2) between the at least one key and at least one identifier; the authentication network element determines the first key based on the psk key negotiation algorithm. Specifically, the corresponding relationship #2 may be pre-configured in the authentication network element; the authentication network element determines the first key according to the identifier of the key k and the corresponding relationship #2. For the specific process, reference can be made to Figure 5 the description in (f) of

[0583] Exemplarily, the terminal device may determine to send the ephemeral public key according to the second indication information. Wherein, the second indication information comes from the authentication network element; the second indication information indicates the first key negotiation algorithm, and the first key negotiation algorithm is one of at least one key negotiation algorithm. The at least one key negotiation algorithm refers to the description in S410.

[0584] Specifically, the terminal device and the authentication network element can negotiate and determine the first key negotiation algorithm. That is, during the negotiation of the first key negotiation algorithm, the terminal device receives the second indication information from the authentication network element. The specific process of the terminal device and the authentication network element negotiating and determining the first key negotiation algorithm refers to the description in S410 and will not be elaborated here.

[0585] S620. The authentication network element authenticates the terminal device based on the first key.

[0586] Specifically, the authentication network element receives a request message from the terminal device. The request message is used to request access to the network and includes a first identifier encrypted by the terminal device using the first key. The authentication network element decrypts the encrypted first identifier based on the first key and obtains first authentication information according to the first identifier. The authentication network element authenticates the terminal device based on the first authentication information.

[0587] The specific implementation of the above steps can refer to the description in S440 to S460 and will not be elaborated here.

[0588] Among them, the first authentication information is the authentication information corresponding to the first authentication method. Before sending the request message to the authentication network element, the terminal device and the authentication network element negotiate and determine the first authentication method. The specific process can refer to the description in S430.

[0589] Exemplarily, the first authentication information includes a first credential of the terminal device. The authentication network element authenticates the terminal device based on the first credential. The specific manner in which the authentication network element authenticates the terminal device based on the first credential refers to the description in S460.

[0590] Optionally, the method further includes S630 and S640:

[0591] S630. The authentication network element sends a first digital signature to the terminal device. Correspondingly, the terminal device receives the first digital signature from the authentication network element.

[0592] The first digital signature is a signature of the first message using the private key of the authentication network element. The first message includes the messages exchanged between the authentication network element and the terminal device.

[0593] Optionally, if the terminal device does not pre-store the certificate of the authentication network element, the authentication network element sends the certificate of the authentication network element to the terminal device. The certificate includes the public key of the authentication network element, and the public key of the authentication network element is used by the terminal device to verify the first digital signature.

[0594] It should be understood that the authentication network element sending the certificate of the authentication network element and / or the first digital signature to the terminal device may be during the key negotiation process. For example, when the authentication network element sends the public key or the second public key of the authentication network element or the ciphertext to the terminal device, the certificate of the authentication network element and / or the first digital signature are sent to the terminal device. Alternatively, it may also be independent of the key negotiation process, which is not limited in this application.

[0595] S640. The terminal device verifies the first digital signature according to the certificate of the authentication network element.

[0596] That is, the terminal device verifies the first digital signature according to the certificate of the authentication network element, thereby verifying the authentication network element. The process of the terminal device verifying the authentication network element may refer to the description in S420.

[0597] Above, in combination with Figures 4 to 6 The communication method provided by the embodiments of this application has been described in detail. It should be understood that the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.

[0598] It should also be understood that in each embodiment of this application, without special instructions and logical conflicts, the terms and / or descriptions between different embodiments are consistent and can be mutually referred to. The technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

[0599] It can be understood that in the above method embodiments, the methods and operations implemented by the devices (such as the above-mentioned authentication network element and terminal device, etc.) can also be implemented by components of the devices (such as chips or circuits).

[0600] The above communication method has been introduced mainly from the perspective of the interaction between each network element. It can be understood that each network element includes the corresponding hardware structure and / or software module for implementing the above functions.

[0601] Below, in combination with Figures 7 to 9 The communication device provided by the embodiments of this application will be described in detail. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, the content not described in detail can be referred to the above method embodiments. For the sake of brevity, it will not be repeated here.

[0602] Figure 7 The schematic diagram of a communication device 700 provided by the embodiments of this application is shown.

[0603] The device 700 includes an interface unit 710. The interface unit 710 can be used to implement corresponding communication functions. The interface unit 710 can also be referred to as a communication interface, a communication unit, or a transceiver unit.

[0604] Optionally, the apparatus 700 may further include a processing unit 720, which may be used for data processing.

[0605] Optionally, the apparatus 700 further includes a storage unit, which may be used for storing instructions and / or data. The processing unit 720 may read the instructions and / or data in the storage unit so that the apparatus implements the actions of different devices in the foregoing method embodiments.

[0606] In a possible design, the apparatus 700 may be the authentication network element in the foregoing embodiments, or a component (such as a chip) of the authentication network element. The apparatus 700 may implement the steps or processes corresponding to the authentication network element in the foregoing method embodiments. Among them, the interface unit 710 may be used to perform the operations related to the transceiver of the authentication network element in the foregoing method embodiments; the processing unit 720 may be used to perform the operations related to the processing of the authentication network element in the foregoing method embodiments.

[0607] In another possible design, the apparatus 700 may be the terminal device in the foregoing embodiments, or a component (such as a chip) of the terminal device. The apparatus 700 may implement the steps or processes corresponding to the terminal device in the foregoing method embodiments. Among them, the interface unit 710 may be used to perform the operations related to the transceiver of the terminal device in the foregoing method embodiments; the processing unit 720 may be used to perform the operations related to the processing of the terminal device in the foregoing method embodiments.

[0608] Figure 8 It is a schematic block diagram of a communication apparatus 800 provided by an embodiment of the present application.

[0609] The apparatus 800 includes a processor 810, and the processor 810 is coupled to a memory 820. Optionally, a memory 820 is further included. The memory 820 is used for storing computer programs or instructions and / or data, and the processor 810 is used to execute the computer programs or instructions stored in the memory 820, or read the data stored in the memory 820 to execute the methods in the foregoing method embodiments.

[0610] Optionally, the processor 810 is one or more.

[0611] Optionally, the memory 820 is one or more.

[0612] Optionally, the memory 820 is integrated with the processor 810 or is separately provided.

[0613] Optionally, as Figure 8As shown, the device 800 further includes a communication interface 830, which is used for receiving and / or transmitting signals. For example, the processor 810 is used to control the communication interface 830 to receive and / or transmit signals.

[0614] Exemplarily, the communication interface 830 may be a transceiver, a circuit, a bus, a module or other types of communication interfaces. The communication interface 830 may also be referred to as an interface.

[0615] As a solution, the device 800 is used to implement the operations performed by the authentication network element in the above method embodiments.

[0616] For example, the processor 810 is used to execute the computer programs or instructions stored in the memory 820 to implement the relevant operations of the authentication network element in the above method embodiments.

[0617] As another solution, the device 800 is used to implement the operations performed by the terminal device in the above method embodiments.

[0618] For example, the processor 810 is used to execute the computer programs or instructions stored in the memory 820 to implement the relevant operations of the terminal device in the above method embodiments.

[0619] In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 810 or the instructions in software form. The method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware processor, or executed and completed by the combination of the hardware and software modules in the processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 820, and the processor 810 reads the information in the memory 820 and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0620] It should be understood that in the embodiments of the present application, the processor may be one or more integrated circuits, which are used to execute relevant programs to execute the method embodiments of the present application.

[0621] A processor (e.g., processor 810) may include one or more processors and be implemented as a combination of computing devices. The processor may respectively include one or more of the following: microprocessor, microcontroller, digital signal processor (DSP), digital signal processing device (DSPD), application specific integrated circuit (ASIC), field programmable gate array (FPGA), programmable logic device (PLD), gated logic, transistor logic, discrete hardware circuits, processing circuits, or other suitable hardware, firmware, and / or a combination of hardware and software for performing the various functions described in the present disclosure. The processor may be a general-purpose processor or a special-purpose processor. For example, processor 810 may be a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data. The central processing unit may be used to cause the device to execute software programs and process the data in the software programs. In addition, a part of the processor may also include non-volatile random access memory. For example, the processor may also store information about the device type.

[0622] The programs in this application are generally used to represent software. Non-limiting examples of software include: program code, programs, subroutines, instructions, instruction sets, code, code segments, software modules, application programs, or software applications, etc. The programs may run in a processor and / or a computer so that the device performs the various functions and / or processes described in this application.

[0623] A memory (e.g., memory 820) can store data required by a processor (e.g., processor 810) when executing software. The memory can be implemented using any suitable storage technology. For example, the memory can be any available storage medium accessible to the processor and / or computer. Non-limiting examples of storage media include: random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM), removable media, optical disc memory, magnetic disk storage media, magnetic storage devices, flash memory, registers, status memory, remotely mounted memory, local or remote memory components, or any other medium capable of carrying or storing software, data, or information and accessible by the processor / computer. It should be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0624] The memory (e.g., memory 820) and the processor (e.g., processor 810) can be separately provided or integrated together. The memory can be used to connect to the processor so that the processor can read information from the memory, store and / or write information in the memory. The memory can be integrated in the processor. The memory and the processor can be provided in an integrated circuit (e.g., the integrated circuit can be provided in a UE or other network node).

[0625] Figure 9 FIG. 7 is a schematic block diagram of a chip system 900 provided by an embodiment of the present application. The chip system 900 (or can also be referred to as a processing system) includes a logic circuit 910 and an input / output interface 920.

[0626] Among them, the logic circuit 910 can be the processing circuit in the chip system 900. The logic circuit 910 can be coupled to the storage unit and call the instructions in the storage unit, enabling the chip system 900 to implement the methods and functions of the embodiments of the present application. The input / output interface 920 can be the input / output circuit in the chip system 900, outputting the information processed by the chip system 900 or inputting the data or signaling information to be processed into the chip system 900 for processing.

[0627] As a solution, the chip system 900 is used to implement the operations performed by the verification network element in the above method embodiments.

[0628] For example, the logic circuit 910 is used to implement the operations related to processing performed by the verification network element in the above method embodiments; the input / output interface 920 is used to implement the operations related to sending and / or receiving performed by the verification network element in the above method embodiments.

[0629] As another solution, the chip system 900 is used to implement the operations performed by the terminal device in the above method embodiments.

[0630] For example, the logic circuit 910 is used to implement the operations related to processing performed by the terminal device in the above method embodiments; the input / output interface 920 is used to implement the operations related to sending and / or receiving performed by the terminal device in the above method embodiments.

[0631] The embodiments of the present application further provide a computer-readable storage medium, on which computer instructions for implementing the methods performed by the communication device (such as the verification network element, the terminal device) in the above method embodiments are stored.

[0632] The embodiments of the present application further provide a computer program product, including instructions, which when executed by a computer, implement the methods performed by the communication device (such as the verification network element, the terminal device) in the above method embodiments.

[0633] The embodiments of the present application further provide a communication system, which includes at least one of the verification network element, the terminal device, etc. in the above embodiments.

[0634] The explanations and beneficial effects of the relevant content in any of the above provided devices can refer to the corresponding method embodiments provided above, and will not be elaborated here.

[0635] In the above embodiments, if there is no special explanation and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

[0636] In the embodiments of the present application, words such as "exemplarily" and "for example" are used to give examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner.

[0637] It should be understood that the "embodiments" mentioned throughout the specification mean that specific features, structures or characteristics related to the embodiments are included in at least one embodiment of the present application. Therefore, the various embodiments throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner.

[0638] It should be understood that in the various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution is prior or posterior. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The names of all nodes and messages in the present application are only names set for the convenience of description in the present application, and their names in the actual network may be different. It should not be understood that the present application limits the names of various nodes and messages. On the contrary, any name having the same or similar function as the nodes or messages used in the present application is regarded as a method or equivalent replacement of the present application and is within the protection scope of the present application.

[0639] It should also be understood that in the present application, "when", "if", and "in case" all mean that the network element will perform corresponding processing under certain objective circumstances, which does not limit the time, and it is not required that the network element must have a judgment action when implemented, nor does it mean that there are other limitations.

[0640] It should be noted that in the embodiments of the present application, "predetermined", "preconfigured", etc. can be implemented by pre-saving corresponding codes, tables or other means that can be used to indicate relevant information in a device (such as a terminal device). The present application does not limit its specific implementation manner. For example, the preset rules, preset constants, etc. in the embodiments of the present application.

[0641] In addition, the terms "system" and "network" are often used interchangeably in this document.

[0642] The term "at least one of..." or "at least one kind of..." in this document means all or any combination of the listed items. For example, "at least one of A, B, and C" can represent: A exists alone, B exists alone, C exists alone, A and B exist simultaneously, B and C exist simultaneously, and A, B, and C exist simultaneously, these six situations. "At least one" in this document means one or more. "Multiple" means two or more.

[0643] It should be understood that in the embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean determining B only according to A, and B can also be determined according to A and / or other information.

[0644] In addition, "of", "corresponding", "corresponding", and "associated" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, their intended meanings are the same. The terms "comprise", "include", "have" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0645] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0646] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0647] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling, direct coupling, or communication connection can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.

[0648] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0649] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, may exist separately physically for each unit, or two or more units may be integrated into one unit.

[0650] If the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0651] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method, characterized in that, Applied to an authentication network element, the method includes: Receiving first indication information from a communication device, the first indication information indicating at least one key negotiation algorithm; Sending second indication information to the communication device, the second indication information indicating a first key negotiation algorithm, the first key negotiation algorithm being one of the at least one key negotiation algorithm, the first key negotiation algorithm being used to determine a first key, and the first key being used to encrypt or decrypt messages transmitted between the communication device and the authentication network element.

2. The method according to claim 1, wherein The first key negotiation algorithm is determined according to first information, and the first information includes at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.

3. The method according to claim 1 or 2, characterized in that, The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, Post-Quantum Cryptography (PQC)-based key negotiation algorithm, PQC and ECDH-based key negotiation algorithm, PQC and ECDHE-based key negotiation algorithm, and pre-shared key-based key negotiation algorithm.

4. The method according to claim 3, wherein The method further includes: Determining the first key based on the first key negotiation algorithm.

5. The method according to claim 4, characterized in that, The first key negotiation algorithm is the ECDHE key negotiation algorithm, and determining the first key based on the first key negotiation algorithm includes: Receiving a first public key from the communication device, the first public key being the public key in a first ephemeral public-private key pair generated by the communication device; Determining the first key based on the first public key and a second private key, the second private key being the private key in a second ephemeral public-private key pair generated by the authentication network element.

6. The method according to claim 5, characterized in that, The method further includes: Sending a second public key to the communication device, the second public key being the public key in the second ephemeral public-private key pair, and the second public key being used by the communication device to determine the first key.

7. The method according to claim 4, characterized in that, The first key negotiation algorithm is the PQC-based key negotiation algorithm, and determining the first key based on the first key negotiation algorithm includes: Receiving a third public key from the communication device, the third public key being the public key in a third ephemeral public-private key pair generated by the communication device based on a post-quantum algorithm; Inputting the third public key into the post-quantum algorithm to generate a ciphertext and the first key.

8. The method according to claim 7, characterized in that, The method further includes: Sending the ciphertext to the communication device, and the ciphertext being used by the communication device to determine the first key.

9. The method according to claim 4, wherein The first key negotiation algorithm is the PQC and ECDH-based key negotiation algorithm, and determining the first key based on the first key negotiation algorithm includes: Receive a first public key and a third public key from the communication device, where the first public key is the public key in a first temporary public-private key pair generated by the communication device, and the third public key is the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; Determine a second key based on the first public key and the private key of the authentication network element; Input the third public key into the post-quantum algorithm to generate a ciphertext and a third key; Determine the first key based on the second key and the third key.

10. The method according to claim 9, wherein The method further includes: Send the public key of the authentication network element and the ciphertext to the communication device, where the public key of the authentication network element and the ciphertext are used by the communication device to determine the first key.

11. The method according to claim 4, characterized in that, The first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. Determining the first key based on the first key negotiation algorithm includes: Receive a first public key and a third public key from the communication device, where the first public key is the public key in a first temporary public-private key pair generated by the communication device, and the third public key is the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; Determine a second key based on the first public key and a second private key, where the second private key is the private key in a second temporary public-private key pair generated by the authentication network element; Input the third public key into the post-quantum algorithm to generate a ciphertext and a third key; Determine the first key based on the second key and the third key.

12. The method according to claim 11, wherein The method further includes: Send a second public key and the ciphertext to the communication device, where the second public key is the public key in the second temporary public-private key pair, and the second public key and the ciphertext are used by the communication device to determine the first key.

13. The method according to any one of claims 1 to 12, characterized in that, The method further includes: Send a first digital signature to the communication device, where the first digital signature is a signature of a first message by the private key of the authentication network element, and the first message includes messages exchanged between the authentication network element and the communication device; Send a certificate of the authentication network element to the communication device, where the certificate includes the public key of the authentication network element, and the public key of the authentication network element is used by the communication device to verify the first digital signature.

14. The method according to any one of claims 1 to 13, characterized in that, The method further includes: Receive a request message from the communication device, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, and the first identifier has a corresponding relationship with the authentication information of the communication device; Obtain first authentication information in the authentication information according to the first identifier; Authenticate the communication device based on the first authentication information.

15. The method according to claim 14, wherein Before receiving the request message from the communication device, the method further includes: Receive third indication information from the communication device, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other; Send fourth indication information to the communication device, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.

16. The method according to claim 14 or 15, characterized in that, The authentication information includes any one of the following information: The certificate of the communication device, cryptographic algorithms; Wherein, the certificate of the communication device includes the public key of the communication device, and the cryptographic algorithms include signature algorithms applicable to the communication device.

17. The method according to claim 15 or 16, characterized in that, The types of the first identifiers indicated by each of the at least one authentication method are different, and the first identifier includes at least one of the following: The first type of identifier of the communication device, the second type of identifier of the communication device, the identifier of a block or a transaction, the virtual identifier of the communication device; Wherein, the first type of identifier has a first corresponding relationship with the root key of the communication device, the second type of identifier has a second corresponding relationship with at least one certificate of the communication device, the identifier of the block or the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.

18. The method according to any one of claims 15 to 17, characterized in that The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the certificate of the communication device, the security level of the certificate of the communication device, the cryptographic algorithm corresponding to the certificate of the communication device.

19. The method according to any one of claims 14 to 18, characterized in that, The first authentication information includes the first certificate of the communication device, and authenticating the communication device based on the first authentication information includes: Verifying the first certificate based on the certificate of the issuer of the first certificate; Receiving a second digital signature from the communication device, where the second digital signature is a signature of a second message by the private key of the communication device, and the second message includes the messages interacted between the communication device and the verification network element; Verifying the second digital signature based on the public key corresponding to the first certificate.

20. A communication method, characterized in that, Applied to a communication device, the method includes: Sending first indication information to a verification network element, where the first indication information indicates at least one key negotiation algorithm; Receiving second indication information from the verification network element, where the second indication information indicates a first key negotiation algorithm, and the first key negotiation algorithm is one of the at least one key negotiation algorithm, and the first key negotiation algorithm is used to determine a first key, and the first key is used to encrypt or decrypt the messages transmitted between the communication device and the verification network element.

21. The method according to claim 20, wherein The first key negotiation algorithm is determined according to the first information and the first indication information, and the first information includes at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, the computing power of the communication device.

22. The method according to claim 20 or 21, characterized in that The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key agreement algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key agreement algorithm, key agreement algorithm based on Post-Quantum Cryptography (PQC), key agreement algorithm based on Post-Quantum Cryptography (PQC) and Elliptic Curve Diffie-Hellman (ECDH), key agreement algorithm based on Post-Quantum Cryptography (PQC) and Ephemeral Elliptic Curve Diffie-Hellman (ECDHE), and key agreement algorithm based on a pre-shared key.

23. The method according to claim 22, characterized in that, The method further includes: Determining the first key based on the first key agreement algorithm.

24. The method according to claim 23, characterized in that, The first key agreement algorithm is the ECDHE key agreement algorithm. Determining the first key based on the first key agreement algorithm includes: Receiving a second public key from the authentication network element, where the second public key is the public key in a second ephemeral public-private key pair generated by the authentication network element; Determining the first key based on the second public key and a first private key, where the first private key is the private key in a first ephemeral public-private key pair generated by the communication device.

25. The method according to claim 22 or 23, characterized in that, Before determining the first key based on the first key agreement algorithm, the method further includes: Sending a first public key to the authentication network element, where the first public key is the public key in a first ephemeral public-private key pair generated by the communication device, and the first public key is used by the authentication network element to determine the first key.

26. The method according to claim 23, wherein The first key agreement algorithm is the key agreement algorithm based on PQC. Determining the first key based on the first key agreement algorithm includes: Receiving a ciphertext from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm; Inputting the ciphertext and a third private key into the post-quantum algorithm to generate the first key, where the third private key is the private key in a third ephemeral public-private key pair generated by the communication device based on the post-quantum algorithm.

27. The method according to claim 26, wherein Before determining the first key based on the first key agreement algorithm, the method further includes: Sending a third public key to the authentication network element, where the third public key is the public key in the third ephemeral public-private key pair, and the third public key is used by the authentication network element to determine the first key.

28. The method according to claim 23, wherein The first key agreement algorithm is the key agreement algorithm based on PQC and ECDH. Determining the first key based on the first key agreement algorithm includes: Receiving a ciphertext and the public key of the authentication network element from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm; Determining a second key based on the public key of the authentication network element and a first private key, where the first private key is the private key in a first ephemeral public-private key pair generated by the communication device; Inputting the ciphertext and a third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in a third ephemeral public-private key pair generated by the communication device based on the post-quantum algorithm; Determining the first key based on the second key and the third key.

29. The method according to claim 23, wherein The first key agreement algorithm is the key agreement algorithm based on PQC and ECDHE. Determining the first key based on the first key agreement algorithm includes: Receive the ciphertext and the second public key from the verification network element, where the ciphertext is generated by the verification network element based on a post-quantum algorithm, and the second public key is the public key in the second temporary public-private key pair generated by the verification network element; Determine a second key based on the second public key and the first private key, where the first private key is the private key in the first temporary public-private key pair generated by the communication device; Input the ciphertext and the third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; Determine the first key based on the second key and the third key.

30. The method according to claim 28 or 29, characterized in that, Before determining the first key based on the first key negotiation algorithm, the method further includes: Send a first public key and a third public key to the verification network element, where the first public key is the public key in the first temporary public-private key pair, and the third public key is the public key in the third temporary public-private key pair, and the first public key and the third public key are used by the verification network element to determine the first key.

31. The method according to any one of claims 20 to 30, characterized in that The method further includes: Receive a first digital signature from the verification network element, where the first digital signature is the signature of the first message by the private key of the verification network element, and the first message includes the messages interacted between the verification network element and the communication device; Receive the certificate of the verification network element from the verification network element, where the certificate includes the public key of the verification network element; Verify the first digital signature based on the public key of the verification network element.

32. The method according to any one of claims 20 to 31, characterized in that, The method further includes: Send a request message to the verification network element, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, and the first identifier has a corresponding relationship with the authentication information of the communication device, and the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.

33. The method according to claim 32, wherein Before sending the request message to the verification network element, the method further includes: Send third indication information to the verification network element, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other; Receive fourth indication information from the verification network element, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication method, and the first authentication method corresponds to the first authentication information.

34. The method according to claim 32 or 33, characterized in that, The authentication information includes any one of the following information: The credential of the communication device, the cryptographic algorithm; Wherein, the credential of the communication device includes the public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.

35. The method according to claim 33 or 34, characterized in that, The type of the first identifier indicated by each authentication method in the at least one authentication method is different, and the first identifier includes at least one of the following: The first type of identifier of the communication device, the second type of identifier of the communication device, the identifier of the block or the transaction, the virtual identifier of the communication device; Among them, the identifier of the first type has a first corresponding relationship with the root key of the communication device, the identifier of the second type has a second corresponding relationship with at least one credential of the communication device, the identifier of the block or the identifier of the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the identifier of the second type.

36. The method according to any one of claims 33 to 35, characterized in that, The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the credential of the communication device, the security level of the credential of the communication device, the cryptographic algorithm corresponding to the credential of the communication device.

37. The method according to any one of claims 32 to 36, characterized in that The method further includes: Sending a second digital signature to the verification network element, where the second digital signature is a signature of the second message by the private key of the communication device, the second message includes the messages interacted between the communication device and the verification network element, and the second digital signature is used for the verification network element to authenticate the communication device.

38. A communication device, characterized in that, The device is used to execute the method according to any one of claims 1 to 37.

39. A communication device, characterized in that, Including: A processor, which is used to make the device execute the method according to any one of claims 1 to 37 by executing the computer program stored in the memory and / or through logic circuits.

40. The device according to claim 39, wherein, The device further includes the memory.

41. A communication device, characterized in that, Including: A processor and a communication interface; Among them, the communication interface is used to receive code instructions and transmit them to the processor, and the processor is used to make the device execute the method according to any one of claims 1 to 37 by executing the computer program stored in the memory and / or through logic circuits.

42. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a computer program or instruction, and when the computer program or instruction runs on a computer, it makes the computer execute the method according to any one of claims 1 to 37.

43. A computer program product, characterized in that, The computer program product includes a computer program or instruction, and when the computer program or instruction runs on a computer, it makes the computer execute the method according to any one of claims 1 to 37.

44. A communication system, characterized in that, Including an authentication entity and a first terminal device, the authentication entity is used to execute the method according to any one of claims 1 to 19, and the first terminal device is used to execute the method according to any one of claims 20 to 37.

Citation Information

Cited By

  • Communication method and communication apparatus

    WO2025157070A1