Measurement method and related equipment thereof

CN120660320APending Publication Date: 2025-09-16HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380093476.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-02-09
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

The existing technology lacks judgment on the credibility of the terminal hardware device in the end-to-end security verification between the network and the terminal device, resulting in insufficient security.

Method used

Through a measurement method, a symmetric key is used to process random numbers and local measurement information to generate a check value. The terminal and the network element verify whether the check value matches to determine the credibility of the terminal. The method includes the terminal sending measurement information, and the network element receiving and verifying the matching of the check value and the expected check value to ensure that the terminal's trusted measurement result is reliable.

Benefits of technology

It effectively improves the security judgment of terminal equipment, ensures the reliability of the trustworthiness results between the terminal and the network, and enhances end-to-end security verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120660320A_ABST
    Figure CN120660320A_ABST
Patent Text Reader

Abstract

The invention provides a measurement method and related equipment thereof, and by implementing the technical scheme provided by the invention, trusted measurement can be carried out on a terminal. In the measurement method, a first network element receives first measurement information from a terminal. And the first network element obtains a first trusted measurement result of the terminal according to the first measurement information and the first expected information. Visibly, in the measurement method provided by the embodiment of the invention, the first network element obtains the first trusted measurement result of the terminal according to the first expected information and the first measurement information from the terminal, so that trusted measurement of the terminal can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Measurement methods and related equipment Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a measurement method and related equipment. Background Art

[0002] The network's security assessment of terminal devices revolves around the subscriber identity module (SIM) card. Terminal devices are also referred to as user equipment (UE). The basic security logic is that the SIM card and the network share a shared key. Users perform operations on the shared key during network access for authentication and authorization.

[0003] It can be seen that the end-to-end security verification between the network and the UE is a verification from the network end to the SIM card end, but the credibility judgment of the UE hardware device itself is missing.

[0004] Summary of the Invention

[0005] The present application provides a measurement method and related devices, which can perform credibility measurement on a terminal.

[0006] In a first aspect, the present application provides a measurement method, which is applied to a first network element. The first network element is a network element with a trustworthy measurement capability.

[0007] The measurement method includes the following steps: a first network element receives first measurement information from a terminal, and the first network element obtains a first trustworthy measurement result of the terminal according to the first measurement information and first expected information.

[0008] In this solution, the first network element obtains the first trust measurement result of the terminal according to the first expected information and the first measurement information from the terminal, thereby achieving trust measurement of the terminal, that is, determining whether the terminal is trustworthy.

[0009] In one possible implementation of the first aspect, the first measurement information includes a first check value, where the first check value is obtained by processing the first random number and the local measurement information using a symmetric key, where the symmetric key is a key used for trust measurement. The symmetric key means that the terminal and the first network element have the same key used for trust measurement.

[0010] In one possible implementation of the first aspect, the first expected information includes a first expected check value obtained by processing the first random number and the first expected measurement information using a symmetric key. The first expected measurement information is a reference value of the terminal's local measurement information.

[0011] In the present application, a first random number and local measurement information are processed based on a symmetric key to obtain a first verification value, so that the first network element can verify the trustworthiness of the terminal based on the first verification value and the first expected verification value. If the first verification value and the first expected verification value are the same, the terminal is trustworthy; otherwise, the terminal is untrustworthy.

[0012] In combination with a possible implementation of the first aspect, the first measurement information further includes local measurement information of the terminal.

[0013] In combination with a possible implementation of the first aspect, the first expected information further includes first expected metric information.

[0014] In the present application, when the first check value and the first expected check value are the same, and the local measurement information and the first expected measurement information are the same, the first network element can determine that the terminal is trustworthy. Conversely, if the first check value and the first expected check value are different, and / or the local measurement information and the first expected measurement information are different, the terminal is determined to be untrustworthy. The present application performs trustworthy verification by verifying whether the two sets of parameters, namely, the first check value and the first expected check value, and the local measurement information and the first expected measurement information, are the same, thereby ensuring that the trustworthy measurement results of the terminal are more reliable.

[0015] In conjunction with one possible implementation of the first aspect, before the first network element receives the first metric information from the terminal, the method further includes: the first network element receiving a first metric request from a second network element, the first metric request including identification information of the terminal; and the first network element sending a second metric request to the terminal, the second metric request including a first random number, the first random number corresponding to the identification information of the terminal.

[0016] Therefore, in this application, the first network element responds to the first measurement request sent by the second network element and initiates trusted measurement of the terminal. Because the first random number corresponds to the identification information of the terminal, the first network element can obtain the first random number based on the identification information of the terminal. The first network element then sends a second measurement request to the terminal, where the second measurement request includes the first random number. In this way, the terminal can generate a first verification value based on the first random number and local measurement information.

[0017] In combination with a possible implementation of the first aspect, the measurement method further includes the following steps:

[0018] The first network element obtains a first trusted vector corresponding to identification information of the terminal, where the first trusted vector includes first expected information.

[0019] In the present application, the first network element may obtain a first credible vector corresponding to the identification information of the terminal according to the identification information of the terminal, so as to obtain the first expected information.

[0020] In conjunction with a possible implementation of the first aspect, a specific implementation manner in which the first network element obtains the first trusted vector corresponding to the identification information of the terminal includes: the first network element sends a trusted vector request to a third network element, where the trusted vector request includes the identification information of the terminal; and the first network element receives the first trusted vector corresponding to the identification information of the terminal sent by the third network element.

[0021] In this application, the first network element may initiate a trust vector request to the third network element to obtain a first trust vector, wherein the third network element may obtain the first trust vector according to the identification information of the terminal.

[0022] In combination with a possible implementation of the first aspect, another specific implementation manner of the first network element obtaining the first trust vector corresponding to the identification information of the terminal includes: the first network element receiving the first trust vector from the authentication network element.

[0023] In the present application, the authentication network element may send the first trust vector to the first network element, so that the first network element obtains the first trust vector.

[0024] In one possible implementation of the first aspect, the first trust vector further includes a symmetric key. Exemplarily, the first network element may perform key derivation based on the symmetric key. Also exemplarily, the first network element may use the symmetric key to further process the first random number and the first expected metric information to obtain a new check value, and verify the first check value based on the new check value.

[0025] In combination with a possible implementation of the first aspect, the symmetric key is any one of the following:

[0026] Root keys for trustworthy measurements;

[0027] A first derived key, where the first derived key is derived from a root key used for trust measurement;

[0028] A second derived key, the second derived key is derived from the root key used for authentication;

[0029] The third derived key is derived from the authentication key, and the authentication key is derived from the root key used for authentication.

[0030] When the symmetric key is the second derived key or the third derived key, the terminal does not need to set a root key for trust measurement, and can use the root key used for authentication to obtain the second derived key or the third derived key.

[0031] In combination with a possible implementation of the first aspect, the above-mentioned measurement method also includes the following steps: the first network element derives a key based on the symmetric key to obtain a fourth derived key, and the fourth derived key is any one of the following: a first anchor point key; an authentication key.

[0032] In conjunction with one possible implementation of the first aspect, the measurement method further includes the following steps: the first network element sends a second trust vector to the second network element or the first node. The second trust vector includes second expected information; the second trust vector is used by the second network element or the first node to perform trust measurement processing on the terminal, and the second expected information includes a second expected check value.

[0033] In this application, a first network element sends a second trust vector to a second network element or a first node, so that the second network element or the first node can perform trust measurement processing on the terminal according to the second expected information, and the trust measurement capability is deployed on the second network element or the first node. The first node may be an access network device.

[0034] Exemplarily, the second network element or the first node performs trust measurement processing based on the second measurement information and the second expected information of the terminal. The second measurement information includes a second check value, which is obtained by processing the second random number and the local measurement information of the terminal using a fifth derived key, and the fifth derived key is derived from the symmetric key. The second expected check value is obtained by processing the second random number and the second expected measurement information using the fifth derived key, and the second expected measurement information is the same as the first expected measurement information. When the second network element or the first node performs trust measurement processing on the terminal, it can compare the second check value and the second expected check value to see if they are the same. If the two are the same, the terminal is trustworthy; otherwise, the terminal is untrustworthy.

[0035] In combination with a possible implementation of the first aspect, the above-mentioned second expected information also includes second expected measurement information. Exemplarily, the above-mentioned second measurement information also includes local measurement information of the terminal. In the present application, when the second check value and the second expected check value are the same, and the local measurement information and the second expected measurement information are the same, the second network element or the first node determines that the terminal is trustworthy; otherwise, the second check value and the second expected check value are not the same, and / or the local measurement information and the second expected measurement information are not the same, then the terminal is untrustworthy. The present application performs trustworthy verification by verifying whether the two sets of parameters, the second check value and the second expected check value, the local measurement information and the second expected measurement information, are the same, thereby ensuring that the reliability of the trustworthy measurement results of the terminal is higher.

[0036] In this application, similar to the first trust vector, the second trust vector may also include a fifth derived key, so that the second network element or the first node can utilize the fifth derived key. Exemplarily, the second network element or the first node may perform key derivation based on the fifth derived key. In another exemplary embodiment, the second network element or the first node may use the fifth derived key to further process the second random number and the second expected metric information to obtain a new check value, and verify the second check value based on this new check value.

[0037] In combination with a possible implementation manner of the first aspect, the measurement method further includes the following steps: the first network element receives a second trust vector from a third network element.

[0038] In the present application, after determining the second trust vector, the third network element may send the second trust vector to the first network element.

[0039] In conjunction with one possible implementation of the first aspect, the measurement method further includes the following steps: the first network element sends a third trust vector to the second network element or the first node. The third trust vector includes a fifth derived key and the second expected measurement information. The third trust vector is used by the second network element or the first node to perform trust measurement processing on the terminal. The fifth derived key is derived from the symmetric key.

[0040] In the present application, another method for deploying a trusted measurement capability to a second network element or a first node is provided, wherein the first network element sends a third trusted vector to the second network element or the first node, and the second network element or the first node generates a second random number corresponding to the identification information of the terminal, and the second network element or the first node processes the second random number and the second expected measurement information based on a fifth derived key to obtain a second expected verification value. The second network element or the first node can perform trusted measurement on the terminal based on the second expected verification value, or the second network element or the first node performs trusted measurement on the terminal based on the second expected measurement information and the second expected verification value, or the second network element or the first node performs trusted measurement on the terminal based on the second random number, the second expected measurement information and the second expected verification value.

[0041] In combination with a possible implementation manner of the first aspect, the measurement method further includes the following steps: the first network element receives a third trust vector from a third network element.

[0042] In the present application, after determining the third trust vector, the third network element may send the third trust vector to the first network element.

[0043] In combination with a possible implementation of the first aspect, the measurement method further includes the following steps: the first network element sends a first trustworthy measurement result to the terminal.

[0044] In the present application, the first network element feeds back its trustworthiness measurement result to the terminal, so that the terminal obtains its own trustworthiness measurement result.

[0045] In a second aspect, the present application further provides a measurement method, which is applied to a terminal, where the terminal is a device with trusted measurement requirements.

[0046] The measurement method includes the following steps: the terminal determines first measurement information and sends the first measurement information to a first network element.

[0047] In this solution, after determining the first measurement information, the terminal sends it to the first network element so that the first network element obtains the first trusted measurement result of the terminal based on the first expected information and the first measurement information from the terminal, thereby realizing trusted measurement of the terminal, that is, determining whether the terminal is trustworthy.

[0048] In one possible implementation of the second aspect, the first measurement information includes a first check value, obtained by processing the first random number and the local measurement information using a symmetric key, where the symmetric key is a key used for trust measurement. Correspondingly, the first expected information includes a first expected check value. The first network element can verify the trustworthiness of the terminal based on the first check value and the first expected check value. If the first check value and the first expected check value are the same, the terminal is trustworthy; otherwise, the terminal is untrustworthy.

[0049] In conjunction with a possible implementation of the second aspect, the first metric information further includes local metric information of the terminal. Correspondingly, the first expected information further includes first expected metric information.

[0050] The present application performs trust verification by verifying whether the two sets of parameters, namely the first check value and the first expected check value, and the local measurement information and the first expected measurement information, are the same, thereby ensuring that the trust measurement result of the terminal is more reliable.

[0051] In combination with a possible implementation of the second aspect, before the terminal determines the first measurement information, the measurement method further includes: the terminal receiving a second measurement request from the first network element, where the second measurement request includes a first random number.

[0052] In combination with a possible implementation of the second aspect, the symmetric key is any one of the following:

[0053] Root keys for trustworthy measurements;

[0054] A first derived key, where the first derived key is derived from a root key used for trust measurement;

[0055] A second derived key, the second derived key is derived from the root key used for authentication;

[0056] The third derived key is derived from the authentication key.

[0057] In conjunction with a possible implementation of the second aspect, the measurement method further includes the following steps: the terminal receives a first trust measurement result of the terminal from the first network element. The first trust measurement result is obtained based on the first measurement information and the first expected information.

[0058] In one possible implementation of the second aspect, the measurement method further includes the following steps: the terminal sends second measurement information to the second network element or the first node. In this way, the second network element or the first node can perform a credibility measurement on the terminal based on the second measurement information and the second expected information.

[0059] In a third aspect, the present application further provides a measurement method, which is applied to a first network element and a second network element.

[0060] The measurement method includes the following steps: a second network element sends a first measurement request to a first network element, the first measurement request including identification information of a terminal; the first network element receives the first measurement information from the terminal; and the first network element obtains a first trusted measurement result of the terminal based on the first measurement information and first expected information.

[0061] In this application, the first network element responds to the first measurement request sent by the second network element and initiates the trust measurement of the terminal. After the first network element receives the first measurement information of the terminal, the first network element obtains the first trust measurement result of the terminal based on the first expected information and the first measurement information, thereby realizing the trust measurement of the terminal.

[0062] In conjunction with a possible implementation of the third aspect, the first measurement information includes a first check value, which is obtained by processing the first random number and the local measurement information using a symmetric key, where the symmetric key is a key used for trusted measurement. Accordingly, the first expected information includes a first expected check value. In this application, the first network element can verify the trustworthiness of the terminal based on the first check value and the first expected check value. If the first check value and the first expected check value are the same, the terminal is trustworthy; otherwise, the terminal is untrustworthy.

[0063] In conjunction with a possible implementation of the third aspect, the first measurement information further includes local measurement information of the terminal. Correspondingly, the first expected information further includes first expected measurement information. This application performs trustworthy verification by verifying whether the first check value and the first expected check value, and the local measurement information and the first expected measurement information, are identical, thereby ensuring a higher reliability of the trustworthy measurement results of the terminal.

[0064] In combination with a possible implementation of the third aspect, before the first network element receives the first measurement information from the terminal, the above-mentioned measurement method also includes the following steps: the first network element sends a second measurement request to the terminal, the second measurement request includes a first random number, and the first random number corresponds to the identification information of the terminal.

[0065] In combination with a possible implementation of the third aspect, the measurement method further includes the following steps: the first network element obtains a first trust vector corresponding to the identification information of the terminal, where the first trust vector includes the first expected information.

[0066] In combination with a possible implementation of the third aspect, the measurement method further includes the following steps:

[0067] The first network element sends a trusted vector request to the third network element, where the trusted vector request includes identification information of the terminal;

[0068] The third network element sends a first trust vector corresponding to the identification information of the terminal to the first network element.

[0069] In combination with a possible implementation of the third aspect, the measurement method further includes the following steps: the first network element receives a first trust vector from the authentication network element.

[0070] In combination with a possible implementation of the third aspect, the symmetric key is any one of the following:

[0071] Root keys for trustworthy measurements;

[0072] A first derived key, where the first derived key is derived from a root key used for trust measurement;

[0073] A second derived key, the second derived key is derived from the root key used for authentication;

[0074] The third derived key is derived from the authentication key.

[0075] In combination with a possible implementation of the third aspect, the above-mentioned measurement method also includes: the first network element derives a key based on the symmetric key to obtain a fourth derived key, and the fourth derived key is any one of the following: a first anchor point key; an authentication key.

[0076] In combination with a possible implementation of the third aspect, the above-mentioned measurement method also includes: the first network element sends a second trust vector to the second network element or the first node, and the second trust vector includes second expected information; the second trust vector is used by the second network element or the first node to perform trust measurement processing on the terminal, and the second expected information includes a second expected verification value.

[0077] In combination with a possible implementation manner of the third aspect, the measurement method further includes: the third network element sending the second trust vector to the first network element.

[0078] In one possible implementation of the third aspect, the measurement method further includes: the first network element sending a third trust vector to the second network element or the first node, the third trust vector including a fifth derived key and the second expected measurement information; the third trust vector being used by the second network element or the first node to perform trust measurement processing on the terminal; the fifth derived key being derived from the symmetric key; the second network element or the first node obtaining a second random number; and the second network element or the first node obtaining a second expected check value based on the fifth derived key, the second random number, and the second expected measurement information.

[0079] In combination with a possible implementation manner of the third aspect, the measurement method further includes: the third network element sending a third trust vector to the first network element.

[0080] In one possible implementation of the third aspect, the measurement method further includes: the second network element or the first node receiving second measurement information of the terminal, and obtaining a second trustworthy measurement result of the terminal based on the second measurement information and the second expected information.

[0081] In combination with a possible implementation manner of the third aspect, the measurement method further includes: the second network element or the first node sending a second trustworthy measurement result to the terminal.

[0082] In combination with a possible implementation of the third aspect, the measurement method further includes: the first network element sending a first trustworthy measurement result to the terminal.

[0083] In a fourth aspect, the present application also provides a measurement method, which is applied to the second node.

[0084] The measurement method includes the following steps: a second node sends a third measurement request to a third node; the second node receives third measurement information from the third node; and the second node obtains a trusted measurement result of the third node based on the third measurement information and third expected information.

[0085] In this solution, the second node initiates a trust measurement of the third node, and performs a trust measurement on the third node based on the third expected information and the third measurement information from the third node to obtain a trust measurement result of the third node, that is, to determine whether the third node is trustworthy.

[0086] In combination with a possible implementation of the fourth aspect, the third measurement information includes a third verification value, and the third verification value is obtained by processing the third random number and the local measurement information using a symmetric key, where the symmetric key is a key used for trusted measurement.

[0087] In one possible implementation of the fourth aspect, the third expected information includes a third expected check value. In this application, when the second node performs trust measurement processing on the third node, the third check value and the third expected check value may be compared to determine whether they are the same. If the third node is the same, then the third node is trustworthy; otherwise, the third node is untrustworthy.

[0088] In combination with a possible implementation of the fourth aspect, the third metric information further includes local metric information of the third node.

[0089] In combination with a possible implementation of the fourth aspect, the third expected information further includes third expected metric information.

[0090] In the present application, when the third check value and the third expected check value are the same, and the local measurement information of the third node is the same as the third expected measurement information, the second node determines that the third node is trustworthy. Conversely, if the third check value and the third expected check value are different, and / or the local measurement information of the third node is different from the third expected measurement information, the third node is untrustworthy. The present application performs trustworthy verification by verifying whether the two sets of parameters, namely, the third check value and the third expected check value, and the local measurement information of the third node and the third expected measurement information, are the same, thereby ensuring that the trustworthy measurement result of the third node is more reliable.

[0091] In one possible implementation of the fourth aspect, the measurement method further includes the following steps: the second node sends a trust vector request to a third network element, where the trust vector request includes identification information of the third node; and the second node receives a fourth trust vector from the third network element, where the fourth trust vector includes the third expected information.

[0092] In this solution, the third network element receives the request from the second node, generates a fourth trust vector, and then returns the fourth trust vector to the second node, so that the second node obtains the third expected information.

[0093] In conjunction with a possible implementation of the fourth aspect, the symmetric key is any one of the following:

[0094] Root keys for trustworthy measurements;

[0095] The sixth derived key is derived from the root key used for trust measurement.

[0096] In combination with a possible implementation of the fourth aspect, the measurement method further includes: the second node sending the trustworthy measurement result to the third node.

[0097] In a fifth aspect, the present application also provides a measurement method, which is applied to the third node.

[0098] The measurement method includes the following steps: a third node receives a third measurement request from a second node. The third node sends third measurement information to the second node, the third measurement information including a third check value obtained by processing a third random number and local measurement information using a symmetric key, where the symmetric key is a key used for trusted measurement.

[0099] In this solution, the third node responds to the third measurement request to send third measurement information to the second node, so that the second node performs trust measurement on the third node according to the third expected information and the third measurement information to obtain a trust measurement result of the third node.

[0100] In one possible implementation of the fifth aspect, the third expected information includes a third expected check value. The second node can verify the trustworthiness of the third node based on the third check value and the third expected check value. If the third check value and the third expected check value are the same, the third node is trustworthy; otherwise, the third node is untrustworthy.

[0101] In combination with a possible implementation of the fifth aspect, the above-mentioned third measurement information also includes the local measurement information of the third node. Correspondingly, the above-mentioned third expected information also includes the third expected measurement information. When the third check value and the third expected check value are the same, and the local measurement information of the third node and the third expected measurement information are the same, the second node can determine that the third node is trustworthy. Conversely, if the third check value and the third expected check value are not the same, and / or the local measurement information of the third node and the third expected measurement information are not the same, then it is determined that the third node is untrustworthy. The present application performs trustworthy verification by verifying whether the two sets of parameters, namely, the third check value and the third expected check value, and the local measurement information of the third node and the third expected measurement information, are the same, thereby ensuring that the reliability of the trustworthy measurement result of the third node is higher.

[0102] In conjunction with a possible implementation of the fifth aspect, the symmetric key is any one of the following:

[0103] Root keys for trustworthy measurements;

[0104] The sixth derived key is derived from the root key used for trust measurement.

[0105] In combination with a possible implementation of the fifth aspect, the above measurement method further includes: the third node receiving a trustworthy measurement result of the third node from the second node, where the trustworthy measurement result is obtained based on the third measurement information and the third expected information.

[0106] In a sixth aspect, the present application further provides a measurement method, which is applied to the second node and the third node.

[0107] The measurement method includes the following steps: a second node sends a third measurement request to a third node; the third node sends third measurement information to the second node; and the second node obtains a trusted measurement result of the third node based on the third measurement information and third expected information.

[0108] In one possible implementation of the sixth aspect, the third measurement information includes a third check value, which is obtained by processing a third random number and the local measurement information using a symmetric key, where the symmetric key is a key used for trust measurement. Accordingly, the third expected information includes a third expected check value. The second node can verify the trustworthiness of the third node based on the third check value and the third expected check value. If the third check value and the third expected check value are the same, the third node is trustworthy; otherwise, the third node is untrustworthy.

[0109] In conjunction with a possible implementation of the sixth aspect, the third measurement information further includes local measurement information of the third node. Correspondingly, the third expected information further includes third expected measurement information. This application performs trustworthy verification by verifying whether the third check value and the third expected check value, and the local measurement information of the third node and the third expected measurement information are identical, thereby ensuring a higher reliability of the trustworthy measurement result of the third node.

[0110] In conjunction with one possible implementation of the sixth aspect, the measurement method further includes the following steps: the second node sends a trust vector request to a third network element, where the trust vector request includes identification information of the third node; and the third network element sends a fourth trust vector to the second node, where the fourth trust vector includes the third expected information.

[0111] In combination with a possible implementation of the sixth aspect, the symmetric key is any one of the following:

[0112] Root keys for trustworthy measurements;

[0113] The sixth derived key is derived from the root key used for trust measurement.

[0114] In combination with a possible implementation of the sixth aspect, the measurement method further includes: the third node receiving the trust measurement result from the second node.

[0115] In a seventh aspect, the present application further provides a first network element, comprising a receiving module and a processing module, wherein:

[0116] The receiving module is configured to receive first measurement information from a terminal.

[0117] The processing module is configured to obtain a first trustworthy measurement result of the terminal according to the first measurement information and the first expected information.

[0118] In an eighth aspect, the present application further provides a terminal, including a determination module and a sending module, wherein:

[0119] The determination module is used to determine the first measurement information.

[0120] The sending module is configured to send the first metric information to the first network element.

[0121] In a ninth aspect, the present application further provides a communication system, the system comprising a first network element and a second network element, wherein:

[0122] The second network element is configured to send a first measurement request to the first network element, where the first measurement request includes identification information of the terminal;

[0123] A first network element, configured to receive first metric information from a terminal;

[0124] The first network element is further configured to obtain a first trustworthy measurement result of the terminal according to the first measurement information and the first expected information.

[0125] In a tenth aspect, the present application further provides a second node, comprising a sending module, a receiving module, and a determining module, wherein:

[0126] The sending module is configured to send a third metric request to the third node.

[0127] The receiving module is configured to receive third metric information from a third node.

[0128] The determination module is configured to obtain a trustworthy measurement result of the third node according to the third measurement information and the third expected information.

[0129] In an eleventh aspect, the present application further provides a third node, comprising a receiving module and a sending module, wherein:

[0130] The receiving module is configured to receive a third metric request from the second node.

[0131] A sending module is used to send third measurement information to the second node, where the third measurement information includes a third verification value, and the third verification value is obtained by processing a third random number and local measurement information of the third node using a symmetric key, where the symmetric key is a key used for trusted measurement.

[0132] In a twelfth aspect, the present application further provides a communication system, the system comprising a second node and a third node, wherein:

[0133] The second node is configured to send a third metric request to the third node.

[0134] The third node is configured to send third metric information to the second node.

[0135] The second node is further configured to obtain a trustworthy measurement result of the third node according to the third measurement information and the third expected information.

[0136] In the thirteenth aspect, the present application also provides a communication device, which includes one or more processors and one or more memories; wherein, the one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer program codes, and the computer program codes include computer instructions, and when the one or more processors execute the computer instructions, the communication device executes the method described in any one of the first to sixth aspects.

[0137] In the fourteenth aspect, the present application also provides a computer-readable storage medium, which stores instructions. When the instructions are executed by a processor, the method described in any one of the first to sixth aspects is implemented.

[0138] In the fifteenth aspect, the present application also provides a computer program product, including a computer program, which, when the computer program runs on a processor, implements the method described in any one of the first to sixth aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0139] FIG1 is a schematic diagram of the structure of the certification system architecture provided in an embodiment of the present application;

[0140] FIG2A is a diagram of a network architecture provided by an embodiment of the present application;

[0141] FIG2B is another network architecture diagram provided by an embodiment of the present application;

[0142] FIG2C is a schematic diagram of an authentication process provided in an embodiment of the present application;

[0143] FIG3 is a flow chart of a measurement method provided in an embodiment of the present application;

[0144] FIG4A is a flow chart of a trustworthiness measurement provided by an embodiment of the present application;

[0145] FIG4B is a schematic diagram of a key architecture provided in an embodiment of the present application;

[0146] FIG4C is an interactive flow chart of a measurement method provided in an embodiment of the present application;

[0147] FIG4D is a schematic diagram of another key architecture provided in an embodiment of the present application;

[0148] FIG4E is an interactive flow chart of another measurement method provided in an embodiment of the present application;

[0149] FIG4F is a schematic diagram of another key architecture provided in an embodiment of the present application;

[0150] FIG4G is an interactive flow chart of another measurement method provided in an embodiment of the present application;

[0151] FIG4H is a schematic diagram of another key architecture provided in an embodiment of the present application;

[0152] FIG4I is an interactive flow chart of another measurement method provided in an embodiment of the present application;

[0153] FIG4J is an interactive flow chart of another measurement method provided in an embodiment of the present application;

[0154] FIG4K is an interactive flow chart of another measurement method provided in an embodiment of the present application;

[0155] FIG5 is a flowchart of another measurement method provided in an embodiment of the present application;

[0156] FIG6A is another trust measurement flow chart provided in an embodiment of the present application;

[0157] FIG6B is an interactive flow chart of another measurement method provided in an embodiment of the present application;

[0158] FIG7 is a schematic structural diagram of a first network element provided in an embodiment of the present application;

[0159] FIG8 is a schematic structural diagram of a terminal provided in an embodiment of the present application;

[0160] FIG9 is a schematic structural diagram of a second node provided in an embodiment of the present application;

[0161] FIG10 is a schematic structural diagram of a third node provided in an embodiment of the present application;

[0162] FIG11 is a schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0163] The terms used in the following examples of the present application are for the purpose of describing specific embodiments only and are not intended to limit the present application. As used in the specification and appended claims of the present application, the singular expressions "a," "an," "said," "above," "the," and "this" are intended to include plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in the present application refers to and encompasses any or all possible combinations of one or more of the listed items.

[0164] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of the technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.

[0165] Since the embodiments of the present application involve methods, in order to facilitate understanding, the relevant terms and concepts involved in the embodiments of the present application are first introduced below.

[0166] (1) Trusted Computing

[0167] Trusted computing (TC) is a technology designed to ensure that computers always operate as expected, with "trust" emphasizing that behavioral outcomes are predictable and controllable. Trusted computing is enforced by computer hardware and software. Trust technology for computing systems begins with a root of trust and evolves to trust in the hardware platform, operating system, and applications. The strength of management and authentication at each layer corresponds to the trustworthiness of each layer. Furthermore, trust is extended to the entire computer system, and protective measures are implemented to ensure the integrity of computer resources and expected computer behavior, thereby enhancing the trustworthiness of the computer system.

[0168] Trusted computing encompasses two distinct research areas. One involves leveraging physical, tamper-resistant devices to ensure the trustworthiness of a trusted computing base (TCB), building a trusted computing architecture for computer systems with the TCB as the trust anchor. Physical tamper-resistant devices, such as the Trusted Platform Module (TPM), are chips embedded within computers that provide a root of trust. The other research area involves building isolated computing systems to ensure the trustworthiness of the environment in which sensitive software code runs. This approach has evolved into the development of a general-purpose Trusted Execution Environment (TEE), based on a special security mode within the central processing unit (CPU).

[0169] Types of trusted computing include, but are not limited to, one or more of TPM, trusted cryptography module (TCM), Intel software guard extensions (Intel SGX), and trusted zone.

[0170] (2) Trusted measurement technology

[0171] Trusted measurement technology checks the hardware and software measurement values ​​of the device to ensure that they have not been tampered with by attackers. Figure 1 shows the architecture of the proof system, which includes an endorser, a reference value provider, an attestor, a verifier, and a relying party. Among them, the endorser, the reference value provider, and the attestor provide the verifier with information used to generate trusted measurement results. Among them, the endorser provides the attestor endorsement (attester endorsements), which is a trusted root certificate. The trusted root certificate is used to confirm that the security chip in the attestor is trustworthy. The certificate includes a public key. The reference value provider provides a reference value of the measurement information, that is, the expected measurement information. The reference value of the measurement information is the reference value of the prover's local measurement information. The prover provides local measurement information (evidence) to the verifier.

[0172] The prover is a device equipped with trusted computing capabilities. For example, the trusted computing technology is TPM. When the device starts up, the TPM chip in the device obtains measurement values ​​on the system and its software, and securely stores these measurement values ​​(i.e., local measurement information) in its platform configuration register (PCR).

[0173] When the verifier performs a trusted measurement verification on the prover, it first presents a challenge value (such as a random number) to the prover. When the prover receives the request, the TPM chip calculates a digest of the local measurement information and the challenge value, and then signs the digest using its private key. The prover then sends the signature, local measurement information, and its own digital certificate to the verifier.

[0174] After receiving the signature, local measurement information, and the prover's digital certificate, the verifier verifies two things: 1. The prover's identity authenticity, verifying that the digital certificate sent by the prover is the certificate provided by the legitimate TPM manufacturer for the TPM. 2. Verification of the trusted measurement information, comparing the local measurement information with the reference measurement information to verify whether the two are the same. If they are the same, the verification passes. If both of these checks are successful, the verifier can report the prover's measurement results to the relying party. Furthermore, after successful verification, the verifier can use the public key for key derivation.

[0175] The following describes some embodiments, methods, and methods involved in the embodiments of the present application in combination with the above terms.

[0176] The method of the embodiment of the present application can be applied to future communication networks such as the Long Term Evolution (LTE) system, the Long Term Evolution-Advanced (LTE-A) system, the enhanced Long Term Evolution-Advanced (eLTE), the fifth generation (5G) mobile communication system New Radio (NR) system, and the sixth generation (6G) mobile communication system, and can also be extended to similar wireless communication systems such as wireless fidelity (WiFi), worldwide interoperability for microwave access (WIMAX), and cellular systems related to the Third Generation Partnership Project (3GPP).

[0177] Figure 2A is a network architecture applied to an embodiment of the present application. Taking a 5G mobile communication system as an example, each network element that may be involved in the network architecture is explained separately.

[0178] 1. Terminal device: abbreviated as terminal, also known as user equipment (UE), which can include various handheld devices with wireless communication capabilities, vehicle-mounted devices, wearable devices, computing devices, or other processing devices connected to a wireless modem, as well as various forms of terminals, mobile stations (MS), terminals, soft terminals, access terminals, subscriber units, terminal stations, mobile stations, mobile stations (MS), remote stations, remote terminals, mobile devices, terminal agent, terminal devices, etc. For example, water meters, electricity meters, sensors, etc.

[0179] 2. Radio Access Network (RAN): This network consists of multiple RAN nodes and implements radio physical layer functions, resource scheduling and radio resource management, radio access control, and mobility management. The RAN connects to user-plane network elements via the user plane interface (N3) to transmit data to terminal devices. The RAN establishes control-plane signaling connections with access and mobility management network elements via the control plane interface (N2) to implement functions such as radio access bearer control.

[0180] Specifically, it can be used to provide network access functions for authorized terminal devices in a specific area, and can use transmission tunnels of different qualities according to the level of the terminal device, business requirements, etc.

[0181] RAN can manage radio resources, provide access services for terminal devices, and forward control signals and terminal device data between terminal devices and the core network.

[0182] The wireless access network can have any of the following replacement terms: access network equipment, access network (AN), where the access network equipment can be a base station, a further evolved node B (gNB), an evolved node B (eNB), a transmission reception point (TRP), a centralized unit (CU) node, a distributed unit (DU) node, a transmission point (TP), a receiving point (RP), etc., without limitation. In this application, the wireless access network is explained using the access network equipment as an example, and the functions performed by the access network equipment are also applicable to other replacement terms for the wireless access network.

[0183] 3. Access and mobility management functional network element: mainly used for mobility management and access management, etc.

[0184] In a 5G communication system, the access and mobility management function network element may be an access and mobility management function (AMF) network element. In future communication systems, the access and mobility management function network element may still be an AMF network element, or may have other names, which are not limited in this application.

[0185] Among them, AMF is mainly responsible for UE authentication, UE mobility management, network slice selection, session management network element selection and other functions; serves as the anchor point for N1 and N2 signaling connections and provides N1 / N2 session management (SM) message routing for session management network elements; maintains and manages UE status information.

[0186] 4. Session management network element: It is mainly used for session management, allocation and management of Internet protocol (IP) addresses of terminal devices, selection of endpoints for manageable user plane functions, policy control and charging function interfaces, and downlink data notification.

[0187] In a 5G communication system, the session management network element may be a session management function (SMF) network element. In future communication systems, the session management network element may still be an SMF network element, or may have other names, which are not limited in this application.

[0188] Among them, SMF is mainly responsible for all control plane functions of UE session management, including user plane network element selection, IP address allocation, session QoS management, and obtaining policy and charging control (PCC) information (from policy control network element).

[0189] 5. User plane network element: used for packet routing and forwarding, as well as quality of service (QoS) processing of user plane data.

[0190] In a 5G communication system, the user plane network element may be a user plane function (UPF) network element. In future communication systems, the user plane network element may still be a UPF network element, or may have other names, which are not limited in this application.

[0191] Among them, UPF mainly provides business processing functions for the user plane. As the anchor point of the protocol data unit (PDU) session connection, UPF is responsible for data packet filtering, business routing, packet forwarding, anchoring function, rate control, generation of billing information, QoS mapping and execution, uplink identification and routing to the data network, downlink packet caching and notification triggering of downlink data arrival, and connection to the external data network.

[0192] 6. Data management network element: used to process terminal device identification, access authentication, registration and mobility management, etc.

[0193] In a 5G communication system, the data management network element may be a unified data management (UDM) network element. In future communication systems, the data management network element may still be a UDM network element, or may have other names, which are not limited in this application.

[0194] The UDM network element is mainly responsible for managing user data, such as the management of contract information, including obtaining contract information from the data repository and providing it to other network elements (such as AMF); generating 3GPP authentication credentials for the UE; and registering and maintaining the network element currently serving the UE (for example, the AMF represented by AMF ID1 is the UE's current serving AMF).

[0195] 7. Data repository: used to store user data.

[0196] In a 5G communication system, the data repository may be a unified data repository (UDR). In future communication systems, the data repository may still be a UDR, or may have other names, which are not limited in this application.

[0197] UDR is mainly used to store user data, including contract data called by data management network elements, policy information called by policy control network elements, structured data used for capability exposure, and application data called by network exposure function (NEF) network elements.

[0198] 8. Network capability exposure function network element: used to connect the interaction between other internal network elements of the core network and the external application servers of the core network, so as to provide network capability information to the external application servers, or provide information of the external application servers to the core network network elements.

[0199] In a 5G communication system, the network capability exposure network element may be a NEF network element. In future communication systems, the network capability exposure network element may still be a NEF, or may have other names, which are not limited in this application.

[0200] 9. Application service network element: interacts with core network elements to provide some services, for example, interacts with policy control network elements to perform service policy control, interacts with network capability exposure network elements to obtain some network capability information or provide some application information to the network, and provides some data network access point information to the policy control network element to generate corresponding data service routing information.

[0201] In the 5G communication system, the application service network element may be an application service function (AF) network element. In future communication systems, the application service network element may still be an AF network element, or it may have other names, which are not limited in this application. For example, the application service network element may have any of the following replacement words: application server (AS), AF, third party, third-party application, perception application, perception client, application (APP), over the top (OTT) application, etc., where OTT refers to providing various application services to users through the Internet, and OTT applications are applications on the upper layer of the bearer network, such as WeChat, Alipay, Youku, etc.

[0202] 10. Authentication service network element: used to perform security authentication on UE when UE accesses the network.

[0203] In a 5G communication system, the authentication service network element may be an authentication server function (AUSF) network element. In future communication systems, the authentication service network element may still be an AUSF network element, or may have other names, which are not limited in this application. In addition, in this embodiment, the authentication service network element may also be understood as an authentication network element.

[0204] Taking the 5G communication system as an example, for example, AUSF receives the request from AMF to authenticate the UE, requests the key from UDM, and then forwards the key issued by UDM to AMF for authentication processing.

[0205] 11. Network Slice Selection Element: This element is used to select a set of slice instances for the UE, determine the set of AMFs, and allowable NSSAIs for the UE. (NSSAI stands for Network Slice Selection Assistance Information. A network slice is uniquely identified by a single S-NSSAI, while a collection of one or more S-NSSAIs is called NSSAI.)

[0206] In a 5G communication system, the network slice selection network element may be a network slice selection function (NSSF) network element. In future communication systems, the network slice selection network element may still be an NSSF network element, or may have other names, which are not limited in this application.

[0207] 12. Policy control network element: A unified policy framework used to guide network behavior, provide configuration policy information for UE, and provide policy rule information for control plane functional network elements (such as AMF, SMF network elements, etc.).

[0208] In a 5G communication system, the policy control network element may be a policy control function (PCF) network element. In future communication systems, the policy control network element may still be a PCF network element, or may have other names, which are not limited in this application.

[0209] 13. Data network: a network used to provide data transmission.

[0210] In a 5G communication system, the data network may be a data network (DN). In future communication systems, the data network may still be a DN, or may have other names, which are not limited in this application.

[0211] 14. Specific network slice authentication and authorization network element: used to authenticate and authorize specific network slices.

[0212] In a 5G communication system, the specific network slice authentication and authorization network element may be a network slice-specific authentication and authorization function (NSSAAF) network element. In future communication systems, the specific network slice authentication and authorization network element may still be an NSSAAF network element, or may have other names, which are not limited in this application.

[0213] 15. Service communication proxy (SCP): It is used to implement the communication proxy function between network functions (NFs). NFs do not need to communicate directly, but communicate indirectly through SCP. SCP can simplify the networking of signaling routing.

[0214] In future communication systems, the service communication agent may have other names, which are not limited in this application.

[0215] 16. Security Anchor Function (SEAF) network element: This element holds the root key for accessing the network (called the anchor key). Typically, the AMF and SEAF network elements are deployed together. The SEAF is a function provided by the AMF and is responsible for handling authentication in the serving network (i.e., the access network) based on information received from the UE and AUSF.

[0216] It should be noted that the above-mentioned "network element" can be implemented by software. Optionally, the above-mentioned "network element" can also be referred to as a module, etc., which is not particularly limited in this application. Moreover, in this application, for ease of understanding and explanation, the description of "network element" is omitted in some descriptions. For example, the AMF network element is referred to as AMF. In this case, the "AMF" should be understood as the AMF network element or AMF module. The description of the same or similar situations is omitted below.

[0217] The network architecture can also include a Network Repository Function (NRF) element to manage all NF elements that support service-oriented interfaces. These NF elements must first be registered with the NRF. When NFs search for each other, they can find each other by querying the NRF.

[0218] This network architecture also includes operation administration and maintenance (OAM) network elements. Based on the operator's actual network operation needs, OAM network elements divide network management tasks into three categories: operation, administration, and maintenance. Operations primarily involve the analysis, forecasting, planning, and configuration of daily network and service operations; maintenance primarily involves day-to-day operational activities such as testing and fault management of the network and its services.

[0219] Exemplarily, in an embodiment of the present application, the NRF network element and / or the OAM network element may also have a remote measurement function to provide a trusted measurement service. For example, taking the NRF network element as an example, if the access network device has a trusted measurement capability or a measurement information verification capability, the NRF network element may send a measurement request to the access network device, and the NRF receives the measurement information returned by the access network device in response to the measurement request. The NRF network element determines the trusted measurement result of the access network device based on the measurement information and the expected information, and the NRF network element then provides the trusted measurement result to the access network device, that is, whether the access network device is trusted or untrusted.

[0220] For example, in the present application, the network architecture may further include a remote attestation function (RAF) network element, referred to as a measurement network element. The measurement network element is used to provide trusted measurement services. For example, if the UE has a trusted measurement capability or a measurement information verification capability, the UE may request a trusted measurement from the measurement network element, and the measurement network element provides the UE with a trusted measurement result, i.e., whether the UE is trusted or untrusted.

[0221] For example, in the present application, the network architecture may further include a trustworthiness profile management function (TPMF) network element configured to provide the remote measurement function network element with trustworthiness data related to the measured entity, i.e., a trustworthiness vector. The trustworthiness data may include at least one of the following: a random number, a key for trustworthy measurement, or expected measurement information of the measured entity.

[0222] For example, referring to FIG2B , FIG2B is another network architecture diagram provided in an embodiment of the present application. In the present application, the network architecture may also include reference value providers for providing expected measurement information to the TPMF network element. The expected measurement information is a reference value of the local measurement information of the entity with a trusted measurement requirement, that is, the measured entity (e.g., UE, NF, wireless access network, etc.).

[0223] In addition, the network function entity 1 and the network function entity 2 in FIG. 2B are the core network elements shown in FIG. 2A .

[0224] Exemplarily, in a 5G network, the measurement network element or the TPMF network element may be one of the network elements of the 5G core network (5G core, 5GC). Alternatively, the measurement network element or the TPMF network element may also be a non-core network element. Alternatively, the measurement network element and the TPMF network element may be deployed independently, or the measurement network element and the TPMF network element may be deployed in combination. Referring to FIG2B , the measurement network element and the TPMF network element may be deployed in combination as a remote measurement service entity, or the UDM network element and the TPMF network element may be deployed in combination; this application does not impose any special restrictions on this. Exemplarily, in the above description, when two network elements that were originally deployed independently are changed into network elements that are deployed in combination, the interaction process between the two network elements when they were originally deployed independently may be ignored, and the functions implemented by the interaction process between the two network elements may be implemented by the network elements after the combined deployment.

[0225] In FIG. 2A , N1 , N2 , N3 , N4 , and N6 are interface serial numbers.

[0226] It should be understood that the above-mentioned network architecture applied to the embodiments of the present application is only an example of a network architecture described from the perspective of a service-oriented architecture. The network architecture applicable to the embodiments of the present application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of the present application.

[0227] For example, in some network architectures, network functional entities such as AMF, SMF, PCF, UPF and UDM are all called NF network elements; or, in other network architectures, the collection of network elements such as AMF, SMF, PCF, UPF and UDM can be called control plane function (CPF) network elements.

[0228] In this application, the proposed measurement network element can communicate with other network elements, for example, the measurement network element can communicate with RAN, AMF network element, SMF network element, UDM network element and other network elements.

[0229] Next, we will use the network elements in a 5G system as an example to introduce the specific solution details. It is understandable that when this solution is used in an LTE system or future communication systems, the network elements in the solution can be replaced with other network elements with corresponding functions, and this application does not limit this.

[0230] The network's security assessment of the UE revolves around the SIM card. The basic security logic is that the SIM card and the network share a shared key, which is then calculated during user access to the network for authentication and authorization.

[0231] Referring to FIG2C , FIG2C is a schematic diagram of an authentication process provided by an embodiment of the present application. The specific authentication process includes the following steps:

[0232] (1) The UE sends a registration request to the AMF through the access network device. The registration request includes the UE's identification information. The AMF can also be co-located with the SEAF. For example, the UE includes a mobile equipment (ME) and a user service identity module (UMTS Subscriber Module, USIM) card. The USIM card is a type of SIM card. UMTS is the abbreviation for Universal Mobile Telecommunications System.

[0233] The SIM cards in the embodiments of this application include SIM cards where the network only authenticates the SIM card, USIM cards that use a two-way authentication mechanism, eSIM (embedded SIM) cards, or soft SIM cards. The two-way authentication mechanism means that when a UE accesses a network, not only does the network authenticate the USIM card, but the USIM card also authenticates the network. The first two types of SIM cards are physical cards that are inserted into the terminal's card slot when in use.

[0234] An eSIM card is an electronic SIM card that is downloaded and installed into a device via the internet. Unlike traditional physical SIM cards, eSIM cards abandon the traditional design of removable SIM cards and instead allow the SIM card to be embedded directly into the device as a component, thus replacing the physical SIM card.

[0235] A soft SIM card simply simulates a SIM card through software, and does not use an actual physical SIM card. After the software modifies the baseband, the baseband is redirected to interact directly with the operating system layer.

[0236] The authentication process of the various types of SIM cards mentioned above is the same, and the embodiments of the present application are described using the USIM card as an example.

[0237] (2) AMF initiates an authentication request to AUSF based on the registration request, and the authentication request includes the identification information of the above-mentioned UE.

[0238] (3) AUSF determines the UDM that processes the UE's authentication request, obtains the UE's authentication data, namely the authentication vector (AV), from the UDM, and sends the AV to the AMF. The AV is a parameter group used for authentication, which includes four parameters:

[0239] RAND (Random Challenge), RAND is an unpredictable random number provided by the network to the UE.

[0240] AUTN (Authentication Token) is used to provide information to the UE so that the UE can use it to authenticate the network.

[0241] XRES (Expected Response), where the "X" in XRES stands for "Expected," represents "expected." XRES is the expected UE authentication response parameter, also known as the expected authentication value RES'. It is compared with the UE-generated RES (or RES + RES_EXT) to determine whether authentication is successful.

[0242] KASME is a root key derived from the CK / IK and the Public Land Mobile Network ID (PLMNID) of the Access Security Management Entity (ASME). The encryption key CK and integrity protection key IK are derived from the authentication root key K.

[0243] Specifically, after the AUSF identifies a UDM, it sends an authentication vector request to the UDM, which includes the UE's identification information. The UDM obtains the UE's authentication vector based on the UE's identification information and sends the authentication vector to the AUSF. The AUSF returns the authentication vector to the AMF in an authentication response.

[0244] (4) The AMF sends the authentication vector to the access network device, and the access network device transparently transmits the authentication vector to the UE.

[0245] (5) After receiving the authentication vector, the SIM card uses the parameters in the authentication vector to verify the validity of the core network authentication message, calculates the authentication value RES, and sends RES to the ME.

[0246] (6) The ME returns the RES to the AMF through the access network equipment, and the AMF passes the RES to the AUSF. If it is 5G AKA, the AMF also needs to verify the RES, obtain the UE verification result from the service network perspective, and send it to the AUSF.

[0247] (7) AUSF verifies RES and obtains the UE's authentication result from the perspective of the home network. Specifically, RES is compared with RES'. If the two are the same, authentication succeeds; otherwise, authentication fails.

[0248] (8) AUSF returns the UE authentication result to AMF. AMF sends the UE authentication result to the access network device, and the access network device transparently transmits it to the UE.

[0249] After both the network side and the UE side have completed mutual authentication, key derivation is performed based on the key.

[0250] From the above authentication process, it can be seen that the end-to-end security verification between the network side and the UE side is the verification from the network side to the SIM card side, but the credibility judgment of the UE hardware device itself is missing.

[0251] Therefore, the embodiment of the present application provides a trust measurement method, which can perform trust measurement on a terminal.

[0252] Refer to Figure 3, which is a flow chart of a measurement method provided in an embodiment of the present application. In this embodiment, the measurement method includes the following steps:

[0253] 301. The terminal determines first measurement information.

[0254] 302. The terminal sends first metric information to the first network element.

[0255] Correspondingly, the first network element receives first metric information from the terminal.

[0256] 303. The first network element obtains a first trustworthy measurement result of the terminal according to the first measurement information and the first expected information.

[0257] Specifically, the first credibility measurement result indicates whether the terminal is credible or uncredible.

[0258] In this embodiment, the first network element may determine the first trust measurement result of the terminal according to the first measurement information and the first expected information of the terminal, thereby implementing trust measurement of the terminal, that is, determining whether the terminal is trustworthy.

[0259] In a possible embodiment, referring to FIG3 , the measurement method further includes:

[0260] 304. The first network element sends a first credibility measurement result to the terminal.

[0261] It can be seen that, in this embodiment, the first network element feeds back its credibility measurement result to the terminal, so that the terminal obtains its own credibility measurement result.

[0262] In one possible embodiment, the first measurement information in step 301 includes a first check value, which is obtained by processing the first random number and local measurement information using a symmetric key. The symmetric key is a key used for trust measurement. A symmetric key means that the terminal and the first network element have the same key used for trust measurement. The first network element or the third network element generates a first random number for each trust measurement of the terminal and provides the first random number to the terminal. The manner in which the terminal obtains the first random number can be referred to the relevant description of steps C403, C404, and C405 below and is not further described here.

[0263] The local measurement information refers to information that needs to be measured in the terminal. Exemplarily, the local measurement information includes a quota and / or a measurement log. The measurement log contains measurement process information of the trusted computing platform supported by the terminal. The quota includes a summary of the measurement log, which is obtained by hashing the measurement log.

[0264] The first expected information includes a first expected check value, which is obtained by processing the first random number and the first expected measurement information using a symmetric key. The first network element generates a first random number for each trust measurement of the terminal, or the third network element generates a first random number for each trust measurement of the terminal and provides the first random number to the first network element. The first expected measurement information is a reference value of the local measurement information of the terminal. The first network element obtains the corresponding first expected measurement information based on the identification information of the terminal. For the specific process, refer to the relevant descriptions of the following steps C403, C404 and C405. In step 303, the first network element compares the first expected check value and the first check value to see if they are the same. When the two are the same, the first trust measurement result of the terminal is that the terminal is trustworthy. Otherwise, the first trust measurement result of the terminal is that the terminal is untrustworthy.

[0265] In one possible embodiment, the first measurement information in the above step 301 also includes the local measurement information of the terminal. And the first expected information also includes the first expected measurement information. Exemplarily, in step 303, the first network element compares whether the first expected measurement information and the local measurement information are the same, and compares whether the first expected check value and the first check value are the same. When both are the same, the first trust measurement result of the terminal is that the terminal is trustworthy. Otherwise, the first trust measurement result of the terminal is that the terminal is untrustworthy. The present application performs trust verification by verifying whether the two sets of parameters, the first check value and the first expected check value, and the local measurement information and the first expected measurement information, are the same, which can ensure that the trust measurement result of the terminal is more reliable.

[0266] Exemplarily, the first measurement information may also include a first random number to indicate that the first check value corresponds to the first random number, that is, the first check value is generated based on the first random number. Similarly, the first expected information may also include a first random number to indicate that the first expected check value corresponds to the first random number, that is, the first expected check value is generated based on the first random number. In step 303, the first network element also compares whether the first random number in the first measurement information and the first random number in the first expected information are the same. When all three comparisons are the same, the first trust measurement result of the terminal is that the terminal is trustworthy. Otherwise, the first trust measurement result of the terminal is that the terminal is untrustworthy. The present application performs trust verification by verifying whether the three groups of parameters, namely, the first check value and the first expected check value, the local measurement information and the first expected measurement information, and the first random number in the first measurement information and the first random number in the first expected information, are the same, thereby further improving the credibility of the trust measurement result of the terminal.

[0267] In one possible embodiment, the first measurement information may further include a sequence number corresponding to the first measurement information, where the sequence number is used to identify the first measurement information. Exemplarily, the sequence number may also be set at the same level as the first measurement information. For example, the terminal sends a measurement response message to the first network element, where the measurement response message includes the first measurement information and the sequence number.

[0268] In a possible embodiment, the symmetric key is any one of the following:

[0269] A root key for trust measurement. This means the terminal is pre-installed with a root key specifically for trust measurement. This root key is securely shared with the network side (e.g., the first network element) so that trust measurement can be performed between the first network element and the terminal based on the root key.

[0270] A first derived key. The first derived key is derived from a root key used for trust measurement. Specifically, the terminal is pre-installed with a root key specifically used for trust measurement. This root key is securely shared with the network. Both the terminal and the network derive the first derived key using the same derivation algorithm, enabling trust measurement between the first network element and the terminal based on the first derived key.

[0271] Second derived key. The second derived key is derived from the root key used for authentication. That is, the terminal is pre-installed with a root key specifically used for authentication. This root key is securely shared with the network. The terminal and the network derive the second derived key using the same derivation algorithm, enabling trust between the first network element and the terminal based on the second derived key.

[0272] The third derived key is derived from the authentication key. Based on the authentication key, the terminal and the network derive the third derived key using the same derivation algorithm. The first network element and the terminal perform a trust measurement based on the third derived key.

[0273] In a possible embodiment, the above measurement method further includes:

[0274] The first network element performs key derivation based on the symmetric key to obtain a fourth derived key, where the fourth derived key is any one of the following: a first anchor point key; an authentication key.

[0275] In this embodiment, the first network element can continue to derive the key based on the symmetric key. Exemplarily, the first network element sends the first anchor key to the second network element. In another exemplary embodiment, the first network element sends the authentication key to the authentication network element.

[0276] The following uses the symmetric key as the first derived key as an example to specifically illustrate the measurement method in the embodiment of the present application:

[0277] Refer to Figure 4A, which is a trust measurement flow chart provided by an embodiment of the present application. In this embodiment, the UE is a mobile phone 401 as an example, and the trust measurement technology is a TPM as an example. Among them, the mobile phone 401 includes a SIM card. The SIM card in the embodiment of the present application includes a SIM card, a USIM card, an eSIM card, or a soft SIM card in which the network only performs identity authentication on the SIM card. The root key K for authentication and the root key K for trust measurement are pre-set in the SIM card. TPM During the production phase, the SIM card manufacturer pre-installs the TPM function in the SIM card and transmits the root key K in the SIM card to the SIM card through a secure channel. TPM Update to the operator's resource server 402. In this way, in the subsequent use of the mobile phone 401, the operator network 403 and the mobile phone 401 can communicate based on the root key K TPMSpecifically, the operator network 403 performs remote trust measurement based on the root key K in the resource server 402. TPM Perform key deduction, and mobile phone 401 uses its own root key K TPM Perform key deduction.

[0278] In addition, the root key K in the SIM card is updated to the operator's resource server 402 through a secure channel. In this way, the operator network 403 can authenticate the mobile phone based on the root key K used for authentication. In this embodiment, the specific process of authenticating the mobile phone can be referred to the description of Figure 2C and will not be repeated here.

[0279] Refer to Figure 4B, which is a schematic diagram of a key architecture provided by an embodiment of the present application. Both the network side and the UE side perform key deduction based on the key architecture of Figure 4B. Among them, the local public land mobile network is the Home Public Land Mobile Network, referred to as HPLMN. For example, on the network side, the key K RAF is the key used by the RAF network element, and the key K SEAF The key K is used by SEAF network elements. SEAF is the anchor key, key K AMF-RA The key used by the AMF network element; the key K gNB-RA A key used by access network devices.

[0280] The following describes the UE's trustworthiness measurement process in FIG4A:

[0281] Referring to FIG4C , FIG4C is an interactive flow chart of a measurement method provided in an embodiment of the present application. The measurement method includes the following steps:

[0282] C401. The UE sends a registration request to the second network element. The registration request includes identification information of the UE.

[0283] Specifically, in this embodiment, the second network element may be an AMF, or the second network element may be a network element jointly established by an AMF and a SEAF. Exemplarily, the registration request also includes the trusted measurement technology supported by the UE (i.e., the category of trusted measurement, i.e., the type of trusted computing mentioned above). Another exemplary embodiment includes the above registration request also including the operating system version and / or application (APP) version of the UE. For example, the TPMF network element may obtain a reference value of the local measurement information of the UE, i.e., the first expected measurement information, based on the identification information of the UE, and the operating system version and / or APP version of the UE. Exemplarily, referring to FIG2B , the TPMF network element obtains the first expected measurement information of the UE from the reference value providing entity based on the identification information of the UE, and the operating system version and / or APP version of the UE.

[0284] Furthermore, the UE may send a registration request to the second network element through the access network device.

[0285] The identification information of the above-mentioned UE includes any of the following items: user permanent identification (SUPI) information, user hidden identification (SUCI) information, international mobile subscriber identity (IMSI) information, permanent equipment identifier (PEI) information, international mobile equipment identity (IMEI) information, generic public subscription identifier (GPSI) information, mobile subscriber international ISDN number (MSISDN) information.

[0286] C402. The second network element sends a first measurement request to the first network element, where the first measurement request includes identification information of the UE.

[0287] Correspondingly, the first network element receives the first metric request from the second network element.

[0288] Specifically, the first measurement request is used to trigger the first network element to perform trust measurement processing on the UE. In this embodiment, the first network element may be a RAF network element. The first network element obtains the first trust vector based on the identification information of the UE. A method for the first network element to obtain the first trust vector can refer to steps C403, C404, and C405.

[0289] C403. The first network element sends a trust vector request to the third network element, where the request includes identification information of the UE.

[0290] Specifically, in this embodiment, the third network element may be a TPMF network element. Optionally, the UDM network element and the TPMF network element are deployed together. Alternatively, the TPMF network element and the RAF network element are deployed together.

[0291] C404. The third network element generates a first trusted vector.

[0292] Specifically, if the identification information of the UE is SUCI, the third network element will decrypt the SUCI to obtain the SUPI, and obtain the first expected metric information evidence' and the symmetric key K corresponding to the UE according to the SUPI query. RAF , the symmetric key K RAF The third network element is based on the root key K TPM The third network element uses the symmetric key K RAF The first expected measurement information evidence' and the first random number nonce are processed to generate the first expected check value HMAC'. Exemplarily, the first trusted vector includes the first expected information, and the first expected information includes the first expected check value HMAC'. Exemplarily, the first expected information also includes the first expected measurement information evidence'. Optionally, the first expected information also includes the first random number nonce. For example, the first expected information Xatt' is a combination of the first random number nonce, the first expected measurement information evidence' and the first expected check value HMAC', and Xatt' can be obtained by splicing the first random number nonce, the first expected measurement information evidence' and the first expected check value HMAC' in this order. Exemplarily, the first trusted vector also includes the symmetric key K RAF .

[0293] If the identification information of the UE is not SUCI, the third network element processes the identification information of the UE according to the processing flow of SUPI and also generates a first trust vector.

[0294] The first random number nonce may be a random number generated by a third network element and corresponding to the identification information of the UE, i.e., the third network element generates a first random number for each trust measurement of the UE. The third network element may send the first random number to the UE via the first network element, i.e., in a unicast manner. Specifically, the third network element may carry the first random number in a first trust vector, and when the first network element sends a second measurement request to the UE, the first network element may carry the first random number in the second measurement request. As another example, the third network element may also broadcast the first random number nonce to multiple UEs, where the multiple refers to two or more than two, and the multiple UEs include the UE in this embodiment.

[0295] For example, the first expected check value HMAC is obtained by using the HMAC algorithm and the symmetric key K RAFThe first expected measurement information evidence' and the first random number nonce are processed and generated. Among them, the HMAC algorithm is a method of constructing a message authentication code using a one-way hash function, where the H in HMAC means Hash. The one-way hash function used in HMAC is not limited to one type. Any high-strength one-way hash function can be used for HMAC. If a new one-way hash function is designed in the future, it can also be used. One-way hash functions include MD5 (Message Digest Algorithm 5), SHA (Secure Hash Algorithm)-1, SHA-256, or SHA-384. MD5 is used to encrypt data blocks of different lengths into a 128-bit value. SHA-1 can generate a 160-bit value for data of any length.

[0296] C405. The third network element sends the first trust vector to the first network element.

[0297] Another way for the first network element to obtain the first trust vector is as follows: the first network element executes steps C403, C404, and C405. The difference is that in step C404, the first trust vector generated by the third network element includes the symmetric key K RAF , the first random number nonce and the first expected measurement information evidence', so that the first network element uses the symmetric key K RAF The first expected measurement information evidence' and the first random number nonce are processed to generate a first expected check value HMAC'. Alternatively, the first trust vector generated by the third network element includes the symmetric key K RAF and the first expected measurement information evidence', the first network element then uses the symmetric key K RAF The first expected measurement information evidence' and the first random number nonce are processed to generate a first expected check value HMAC'. At this time, the first random number nonce used by the first network element can be a random number generated by the first network element and corresponding to the identification information of the UE, that is, the first network element generates a first random number for each trusted measurement of the UE. Similarly, the first network element can send the first random number to the UE in a unicast or broadcast manner. When using the unicast method, when the first network element sends the second measurement request to the UE, it can carry the first random number in the second measurement request. When using the broadcast method, the third network element can broadcast the above-mentioned first random number nonce to multiple UEs, where multiple refers to two or more than two, and the multiple UEs include the UE in this embodiment.

[0298] At this time, similarly, the first expected information includes the first expected check value HMAC'. Exemplarily, the first expected information also includes the first expected measurement information evidence'. Optionally, the first expected information also includes the first random number nonce.

[0299] C406. The first network element sends a second measurement request to the UE.

[0300] The second measurement request is used to trigger the UE to generate the first measurement information. Optionally, when the first network element or the third network element provides the first random number to the UE via unicast, the second measurement request includes the first random number. In the embodiment shown in Figure 4C, the first network element sends the second measurement request to the UE via the second network element. Specifically, the first network element sends a first measurement response to the second network element, and the first measurement response carries the first random number nonce. The second network element sends a second measurement request to the UE, and the request carries the first random number nonce. Specifically, triggered by the first measurement response sent by the first network element, the second network element sends the second measurement request to the UE.

[0301] When the first network element or the third network element provides the first random number to the UE by broadcasting, the second measurement request does not need to carry the first random number. The second measurement request only needs to trigger the UE to generate the first measurement information. At this time, the first network element sends the second measurement request to the UE through the second network element.

[0302] C407. The UE determines first metric information.

[0303] Specifically, in this embodiment, the UE uses the symmetric key K RAF The first random number nonce and local measurement information evidence are processed to generate a first check value HMAC. The first measurement information includes the first check value HMAC. Exemplarily, the first measurement information also includes local measurement information evidence. Exemplarily, the first measurement information Xatt is a combination of the local measurement information evidence and the first check value HMAC, and Xatt can be obtained by concatenating the local measurement information evidence and the first check value HMAC in that order. Optionally, the first measurement information also includes the first random number nonce. Exemplarily, the first measurement information Xatt is a combination of the first random number nonce, the local measurement information evidence, and the first check value HMAC, and Xatt can be obtained by concatenating the first random number nonce, the local measurement information evidence, and the first check value HMAC in that order.

[0304] C408. The UE sends first metric information to the first network element.

[0305] Exemplarily, the first expected information also includes a first random number nonce. When the first random number nonce is a random number generated by the third network element and corresponds to the identification information of the UE, the UE sends a second measurement response to the second network element; and the second network element sends the second measurement response to the first network element.

[0306] Specifically, the second measurement response includes the first measurement information Xatt. Optionally, the second measurement response may further include the first random number nonce and / or local measurement information evidence.

[0307] As another example, when the above-mentioned first random number nonce is a public random number broadcast in advance by the first network element to multiple UEs, the UE sends the first measurement information Xatt to the first network element through the second network element. Optionally, when sending the first measurement information Xatt, the UE also carries the first random number nonce and / or local measurement information evidence.

[0308] C409. The first network element compares Xatt and Xatt' to generate a first credibility measurement result. If the two are consistent, the measurement result indicates that the UE is credible; if the two are inconsistent, the measurement result indicates that the UE is uncredible.

[0309] For example, taking the first measurement information Xatt as a combination of the first random number nonce, local measurement information evidence, and the first check value HMAC, when the first network element compares Xatt and Xatt', it can respectively extract the first random number nonce, local measurement information evidence, and the first check value HMAC in Xatt, the first random number nonce, the first expected measurement information evidence', and the first expected check value HMAC' in Xatt; then compare the first random number nonce in Xatt and the first random number nonce in Xatt' to see if they are the same; compare the local measurement information evidence and the first expected measurement information evidence' to see if they are the same; and compare the first check value HMAC and the first expected check value HMAC' to see if they are the same. If the comparison results of all three are the same, it indicates that Xatt and Xatt' are consistent. Otherwise, Xatt and Xatt' are inconsistent.

[0310] As another example, when the first trust vector also includes the symmetric key K RAF When the symmetric key K RAF The first random number nonce and the first expected measurement information evidence' are processed to generate a check value, and the first check value HMAC is verified according to the generated check value.

[0311] C410. The first network element returns the first credibility measurement result to the second network element, and the second network element returns the first credibility measurement result to the UE.

[0312] When the measurement result shows that the UE is trustworthy, the UE side and the network side can continue to use the symmetric key K RAF Perform key derivation. Referring to Figure 4B, the symmetric key K RAF The anchor key K can be further derived SEAF-RA , according to the anchor key K SEAF-RA The key K used by AMF can be further derived AMF-RA , key K AMF-RA The key K used by the access network device (i.e. gNB) can be further derived gNB-RA .

[0313] Exemplarily, when the above-mentioned first random number nonce is a public random number broadcast in advance by the first network element to multiple UEs, the UE can directly report the first measurement information to the first network element without the need for the first network element to send a second measurement request to the UE. Exemplarily, the UE can report the first measurement information to the first network element periodically, or the UE reports the first measurement information to the first network element based on other strategies, such as reporting the first measurement information to the first network element each time the UE is turned on or after the UE requests a certain service. As another example, when the UE reports the first measurement information directly to the first network element, the first network element can perform a trusted measurement based on the first measurement information and the first expected information; or, before the first network element performs a trusted measurement based on the first measurement information and the first expected information, the first network element receives a first measurement request from the second network element, the first measurement request including the identification information of the UE. In this case, the first measurement request is used to trigger the first network element to start the trusted measurement of the UE, that is, the first network element will perform a trusted measurement based on the first measurement information and the first expected information only after receiving the first measurement request.

[0314] The following uses the symmetric key as the second derived key as an example to specifically describe the measurement method in the embodiment of the present application:

[0315] Different from FIG4A , in this embodiment, the SIM chip in the UE is not pre-configured with a root key K for trust measurement. TPM However, the SIM card is still pre-configured with the root key K for authentication. The root key in the SIM card is updated to the operator's resource server through a secure channel. In this way, the operator network can authenticate the mobile phone based on the root key K used for authentication. In this embodiment, the authentication key K used by the authentication network element is derived based on the root key K. AUSF , and a symmetric key K for use by the first network element RAF .

[0316] Referring to Figure 4D, which is a schematic diagram of another key architecture provided in an embodiment of the present application, both the network side and the UE side perform key deduction based on the key architecture of Figure 4D.

[0317] The following describes the UE trust measurement process:

[0318] Referring to FIG4E , FIG4E is an interactive flow chart of another measurement method provided in an embodiment of the present application. The measurement method includes the following steps:

[0319] E401. The UE sends a registration request to the second network element. The request includes identification information of the UE.

[0320] Specifically, the UE and the network perform trusted capability negotiation. The second network element may be an AMF network element, or the second network element may be a network element jointly provided by the AMF and SEAF. The specific description of step E401 refers to the relevant description of step C401 and is not repeated here.

[0321] E402. The second network element sends a first measurement request to the first network element, where the request includes identification information of the UE.

[0322] Specifically, the first network element obtains a corresponding first trust vector based on the UE's identification information. The specific process of the first network element obtaining the corresponding first trust vector based on the UE's identification information can be found in the corresponding description of FIG. 4C , which includes at least two acquisition methods. Furthermore, the second network element sends an authentication request to the authentication network element, and the authentication network element sends an authentication vector request to the third network element. The order in which the first metric request and the authentication request are sent is not particularly limited.

[0323] In this embodiment, the specific process of authenticating the UE can be referred to the description of FIG2C and will not be described in detail here.

[0324] In this embodiment, the first network element may be a RAF network element. The third network element may be a TPMF network element. Optionally, the UDM network element and the TPMF network element are deployed together. Alternatively, the TPMF network element and the RAF network element are deployed together.

[0325] E403: The first network element sends a trust vector request to the third network element, where the request includes the identification information of the UE. The authentication network element sends an authentication vector request to the third network element.

[0326] Likewise, there is no particular restriction on the order in which the trust vector request and the authentication vector request are sent.

[0327] E404: The third network element generates a first trusted vector. The third network element generates an authentication vector.

[0328] The detailed description of step E404 is referred to the description of step C404, which will not be repeated here.RAF It is derived by the third network element based on the root key K used for authentication.

[0329] E405. The third network element sends the first trusted vector to the first network element, and the third network element sends the authentication vector to the authentication network element.

[0330] E406. The first network element sends a second measurement request to the UE, and the authentication network element sends an authentication request to the UE.

[0331] Specifically, the specific process of the first network element sending the second metric request to the UE is described in detail in step C406 and will not be repeated here.

[0332] Exemplarily, when the second network element sends the second measurement request and authentication request to the UE, the request may be split into two separate requests and sent separately. Alternatively, the authentication request may be multiplexed, with the second measurement request carried in the authentication request. Optionally, the authentication request may carry information carried in the second measurement request, such as the first random number.

[0333] E407. The UE determines the first measurement information and the authentication value.

[0334] For the detailed description of step E407, please refer to the relevant description of step C407, which will not be repeated here.

[0335] E408. The UE sends the first measurement information and the authentication value to the first network element.

[0336] For a detailed description of sending the first metric information in step E408, refer to the description of step C408 and are not repeated here. For example, when the UE sends the authentication value to the first network element, the UE specifically sends an authentication response to the second network element, where the authentication response includes the authentication value. The second network element then forwards the authentication response to the first network element.

[0337] E409: The first network element compares Xatt and Xatt' to generate a first trust measurement result. The authentication network element compares RES and RES' to generate an authentication result.

[0338] Specifically, for a detailed description of the first network element comparing Xatt and Xatt' to generate the first trust metric result, reference may be made to the relevant description of step C409, which will not be elaborated here.

[0339] The first network element uses the symmetric key K RAF The first anchor key is derived and sent to the second network element, and the authentication network element authenticates the second network element according to the authentication key K. AUSFA second anchor key is derived and sent to the second network element. Furthermore, the second network element determines a third anchor key, which serves as an anchor point for subsequent key derivations. Optionally, the second network element may use the first anchor key as the third anchor key. Furthermore, the second network element may derive the third anchor key based on the first anchor key and the second anchor key. For example, the third anchor key may be obtained by concatenating the first anchor key and the second anchor key. Alternatively, a portion of the first anchor key and the second anchor key may be concatenated to form the third anchor key. Alternatively, the third anchor key may be obtained by performing an exclusive-OR operation on the first anchor key and the second anchor key.

[0340] The following uses the symmetric key as the third derived key as an example to specifically illustrate the measurement method in the embodiment of the present application:

[0341] Different from FIG4A , in this embodiment, the SIM chip in the UE is not pre-configured with a root key K for trust measurement. TPM However, the SIM card is still pre-configured with the root key K for authentication. The root key in the SIM card is updated to the operator's resource server through a secure channel. In this way, the operator network can authenticate the mobile phone based on the root key K used for authentication. In this embodiment, the authentication key K used by the authentication network element is derived based on the root key K. AUSF After the UE passes the authentication, according to the authentication key K AUSF Derive the symmetric key K for use by the first network element RAF .

[0342] Referring to Figure 4F, which is a schematic diagram of another key architecture provided in an embodiment of the present application, both the network side and the UE side perform key deduction based on the key architecture of Figure 4F.

[0343] The following describes the UE trust measurement process:

[0344] Referring to FIG4G , FIG4G is an interactive flow chart of another measurement method provided in an embodiment of the present application. The measurement method includes the following steps:

[0345] G401. The UE sends a registration request to the second network element, where the request includes identification information of the UE.

[0346] Specifically, trusted capability negotiation is performed between the UE and the network. In this embodiment, the second network element may be an AMF network element, or the second network element may be a network element jointly provided by the AMF and SEAF. The specific description of step G401 refers to the relevant description of step C401 and is not repeated here.

[0347] G402. The second network element sends a first measurement request to the first network element, where the request includes identification information of the UE.

[0348] Specifically, the second network element sends an authentication request to the authentication network element, and the authentication network element sends an authentication vector request to the third network element. The order in which the first metric request and the authentication request are sent is not particularly limited.

[0349] In this embodiment, the specific process of authenticating the UE can be referred to the description of FIG2C and will not be described in detail here. AUSF Derived symmetric key K RAF .

[0350] The first network element obtains the corresponding first trust vector based on the identification information of the UE. The specific process of the first network element obtaining the corresponding first trust vector based on the identification information of the UE can refer to the relevant description corresponding to Figure 4C, including at least two acquisition methods. The difference is that the third network element sends the generated first trust vector to the authentication network element. After the UE is authenticated, the authentication network element sends the first trust vector to the first network element. Optionally, the first trust vector sent to the first network element at this time may include the symmetric key K RAF .

[0351] G403. The first network element sends a second measurement request to the UE.

[0352] For the detailed description of step G403, please refer to the relevant description of step C406, which will not be repeated here.

[0353] G404. UE determines first measurement information.

[0354] The detailed description of step G404 refers to the relevant description of step C407 and will not be repeated here.

[0355] G405. The UE sends first measurement information to the first network element.

[0356] The specific description of step G405 refers to the relevant description of step C408 and is not repeated here.

[0357] G406. The first network element compares Xatt and Xatt' to generate a first trust measurement result.

[0358] Specifically, for a detailed description of the first network element comparing Xatt and Xatt' to generate the first trust metric result, reference may be made to the relevant description of step C409, which will not be elaborated here.

[0359] If Xatt and Xatt' are the same, that is, the first trust metric result indicates that the UE is trustworthy, the first network element uses the symmetric key K RAFA first anchor key is derived, and the first network element sends the first anchor key to the second network element. In addition, the second network element determines a third anchor key. Optionally, the second network element determines the first anchor key as the third anchor key.

[0360] The following describes the derivation of a symmetric key using the fourth derived key as an authentication key as an example:

[0361] Different from FIG4A , in this embodiment, the SIM chip in the UE is not pre-configured with a root key K for trust measurement. TPM However, the SIM card is still pre-configured with a root key K for authentication. The root key in the SIM card is updated to the operator's resource server through a secure channel. In this embodiment, the symmetric key K used by the first network element is derived based on the root key K. RAF After the UE passes the trust measurement, according to the symmetric key K RAF Derive the authentication key K for use by the authentication network element AUSF .

[0362] Referring to Figure 4H, which is a schematic diagram of another key architecture provided in an embodiment of the present application, both the network side and the UE side perform key deduction based on the key architecture of Figure 4H.

[0363] The following describes the UE trust measurement process:

[0364] Referring to FIG4I , FIG4I is an interactive flow chart of another measurement method provided in an embodiment of the present application. The measurement method includes the following steps:

[0365] I401. The UE sends a registration request to the second network element, where the request includes identification information of the UE.

[0366] In this embodiment, the second network element can be an AMF network element, or the second network element can be a network element jointly established by AMF and SEAF.

[0367] I402. The second network element sends a first measurement request to the first network element, where the request includes identification information of the UE.

[0368] Specifically, the second network element sends an authentication request to the authentication network element, and the authentication network element sends an authentication vector request to the third network element. The order in which the first metric request and the authentication request are sent is not particularly limited.

[0369] The first network element obtains the corresponding first trust vector based on the UE's identification information. The specific process for the first network element to obtain the corresponding first trust vector based on the UE's identification information can be found in the corresponding description of FIG. 4C , including at least two acquisition methods. Furthermore, the third network element transmits the generated authentication vector and the first trust vector to the first network element.

[0370] I403. The first network element sends a second measurement request to the UE.

[0371] I404. UE determines first measurement information.

[0372] I405. The UE sends first measurement information to the first network element.

[0373] For the detailed description of step I405, please refer to the relevant description of step C408, which will not be repeated here.

[0374] I406, the first network element compares Xatt and Xatt' to generate a first trust measurement result. If Xatt and Xatt' are the same, that is, the first trust measurement result indicates that the UE is trustworthy, the first network element then uses the symmetric key K RAF Derive the authentication key K AUSF .

[0375] For the detailed description of steps I403 to I406, please refer to the relevant description of steps C407 to C409, which will not be repeated here.

[0376] I407. The first network element sends the authentication vector and authentication key to the authentication network element.

[0377] I408. The authentication network element authenticates the UE.

[0378] In this embodiment, the specific process of the authentication network element authenticating the UE can be referred to the description of FIG2C , which will not be repeated here.

[0379] I409, the authentication network element compares RES and RES'. If the comparison is the same, the authentication network element uses the authentication key K AUSF A third anchor key is derived and sent to the second network element.

[0380] In a possible embodiment, the above measurement method further includes:

[0381] The first network element sends a second trust vector to the second network element or the first node. The second trust vector includes second expected information; the second trust vector is used by the second network element or the first node to perform trust measurement processing on the terminal, and the second expected information includes a second expected check value.

[0382] In this embodiment, the first network element sends a second trust vector to the second network element or the first node to deliver the trust measurement capability to the second network element or the first node. Optionally, the second network element or the first node can initiate trust measurement for the UE periodically or based on other policies to prevent tampering of the UE's local measurement information.

[0383] The first node may be an access network device. Alternatively, this embodiment may be independent of the method shown in FIG3 , that is, independent of the UE's first trustworthiness measurement result. After the second network element or the first node obtains the second trustworthiness vector, it may initiate a trustworthiness measurement on the UE based on actual circumstances. Furthermore, if the first trustworthiness measurement result indicates that the UE is trustworthy, the first network element may send the second trustworthiness vector to the second network element or the first node.

[0384] The second network element or the first node performs a similar trust measurement process on the UE as the first network element, including the second network element or the first node receiving second measurement information of the UE and obtaining a second trust measurement result of the terminal based on the second measurement information and the second expected information. Optionally, the second network element or the first node may send the second trust measurement result to the UE.

[0385] Exemplarily, the second network element or the first node performs trust measurement processing based on the second measurement information and the second expected information of the terminal. The second measurement information includes a second verification value, and the second verification value is obtained by processing the second random number and the local measurement information of the terminal using the fifth derived key. The fifth derived key is derived from the above-mentioned symmetric key. The specific method for obtaining the second verification value refers to the method for obtaining the first verification value, which will not be repeated here. The second expected verification value is obtained by processing the second random number and the second expected measurement information using the fifth derived key. The second expected measurement information is the same as the first expected measurement information. When the second network element or the first node performs trust measurement processing on the terminal, it can compare whether the second verification value and the second expected verification value are the same. If the two are the same, the terminal is trustworthy. Otherwise, the terminal is untrustworthy.

[0386] Exemplarily, the second expected information also includes second expected measurement information. Exemplarily, the above-mentioned second measurement information also includes local measurement information of the terminal. In the present application, when the second check value and the second expected check value are the same, and the local measurement information and the second expected measurement information are the same, the second network element or the first node determines that the terminal is trustworthy. Conversely, the second check value and the second expected check value are not the same, and / or the local measurement information and the second expected measurement information are not the same, then the terminal is untrustworthy. The present application performs trustworthy verification by verifying whether the two sets of parameters, the second check value and the second expected check value, the local measurement information and the second expected measurement information, are the same, thereby ensuring that the reliability of the trustworthy measurement results of the terminal is higher.

[0387] Exemplarily, the second trust vector further includes a fifth derived key.

[0388] Specifically, the fifth derived key is a key derived by the network for use by the second network element or the first node. The UE also derives the fifth derived key from the symmetric key using the same key derivation algorithm as the network. The UE and the second network element or the first node can establish a trustworthiness measure based on the fifth derived key. The fifth derived key for use by the first node is derived from the fifth derived key for use by the second network element, and the fifth derived key for use by the second network element is derived from the symmetric key.

[0389] In this embodiment, when the first network element has not completed the first trust measurement of the UE, the second network element or the first node may request the third network element through the first network element to obtain the second trust vector, or the second network element or the first node may directly request the third network element to obtain the second trust vector.

[0390] Optionally, after the first network element completes the initial trust measurement of the UE, the first network element may also directly derive a fifth derived key based on the symmetric key. Further optionally, since the first expected measurement information is the second expected measurement information, the first network element may generate a second random number, and then process the second expected measurement information and the second random number based on the fifth derived key to obtain a second expected check value. In this way, the first network element can obtain a second trust vector.

[0391] Similar to the first random number, the second random number may be a random number generated by the first network element or the third network element and corresponding to the identification information of the UE, that is, the first network element or the third network element generates a second random number for each trust measurement of the UE. The first network element or the third network element provides the second random number to the UE via unicast or broadcast.

[0392] Optionally, when verifying the second expected verification value, the second network element or the first node may process the second random number and the second expected measurement information according to the fifth derived key to obtain the second expected verification value, and then verify the second verification value according to the second expected verification value.

[0393] Exemplarily, the second measurement information may further include a second random number to indicate that the second check value corresponds to the second random number, i.e., the second check value is generated based on the second random number. Similarly, the second expected information may further include a second random number to indicate that the second expected check value corresponds to the second random number, i.e., the second expected check value is generated based on the second random number. By comparing the second random number in the second measurement information and the second random number in the second expected information to determine whether they are the same, it can be confirmed whether the second measurement information and the second expected information correspond to each other. Furthermore, when the second random number in the second measurement information and the second random number in the second expected information are the same, the second check value and the second expected check value are the same, and the local measurement information and the second expected measurement information are the same, the second network element or the first node determines that the terminal is trustworthy; otherwise, the terminal is untrustworthy. This application performs trustworthy verification by verifying whether three sets of parameters, namely, the second check value and the second expected check value, the local measurement information and the second expected measurement information, and the second random number in the second measurement information and the second random number in the second expected information, are the same, thereby further improving the credibility of the terminal's trustworthy measurement results.

[0394] In a possible embodiment, the above measurement method further includes:

[0395] The first network element receives a second trust vector from a third network element.

[0396] In this embodiment, when the first network element has not completed the first trust measurement of the UE, the first network element may request the second trust vector from the third network element. After generating the second trust vector, the third network element sends the second trust vector to the first network element.

[0397] The following takes the first node as an access network device as an example to specifically describe a process in which the first node performs a trust measurement on the UE based on the second trust vector:

[0398] In this embodiment, the same as FIG4A is that the root key K for authentication and the root key K for trust measurement are preset in the SIM card of the UE. TPM During the production phase, the SIM card manufacturer pre-installs the TPM function in the SIM card and transmits the root key K in the SIM card to the SIM card through a secure channel. TPM Update to the operator's resource server 402.

[0399] Referring to Figure 4B, in this embodiment, both the network side and the UE side perform key derivation based on the key architecture of Figure 4B. AMF-RA Derive the key K used by the access network device gNB-RA .

[0400] The following describes the UE trust measurement process:

[0401] Referring to FIG4J , FIG4J is an interactive flow chart of another measurement method provided in an embodiment of the present application. The measurement method includes the following steps:

[0402] J401. The first network element sends a trust vector request to the third network element. The request includes identification information of the UE.

[0403] Specifically, the above-mentioned trusted vector request is used to request a fifth trusted vector, and the fifth trusted vector includes the key K AMF-RA , the second expected measurement information and the second expected check value. In this embodiment, the first network element obtains the fifth trust vector from the third network element as an example. At this time, the third network element performs key derivation to obtain the key K AMF-RA , and use the key K AMF-RA The second expected measurement information and the second random number are processed to obtain a second expected verification value. The second random number can be a random number generated by a third network element and corresponding to the identification information of the UE, or the second random number is a public random number broadcast in advance by the third network element to multiple UEs. Multiple refers to two or more than two, and multiple UEs include the UE in this embodiment.

[0404] The third network element returns the fifth trust vector to the first network element.

[0405] In this embodiment, the first network element may be a RAF network element, and the third network element may be a TPMF network element. Optionally, the UDM network element and the TPMF network element are deployed together. Alternatively, the TPMF network element and the RAF network element are deployed together.

[0406] J402. The first network element sends the fifth trust vector to the AMF network element.

[0407] Among them, the AMF network element obtains the second trusted vector based on the fifth trusted vector.

[0408] Specifically, the AMF network element uses the key K AMF-RA Derived key K gNB-RA The second trusted vector includes the second expected information. Furthermore, the second trusted vector may also include the key K gNB-RA .

[0409] J403. The AMF network element sends the second trust vector to the first node. The first node is an access network device.

[0410] J404. The first node sends a fourth metric request to the UE.

[0411] Specifically, the fourth metric request is used to trigger the UE to determine the second metric information. The first node may periodically send the fourth metric request to the UE, or the first node may send the fourth metric request to the UE based on other policies, such as sending the fourth metric request to the UE after receiving a registration request from the UE or after the UE requests a service.

[0412] When the second random number is a random number generated by the third network element and corresponding to the identification information of the UE, the fourth metric request includes the second random number. However, when the second random number is a common random number pre-broadcasted by the third network element to multiple UEs, the UE has the second random number, and the fourth metric request does not need to carry the second random number, and is only used to trigger the UE to determine the second metric information.

[0413] J405. The UE determines the second measurement information.

[0414] Specifically, the UE side also derives the key K gNB-RA , UE based on the key K gNB-RA The local measurement information and the second random number are processed to obtain a second verification value. Similar to the first measurement information, the second measurement information includes a second verification value. In another exemplary embodiment, the second measurement information also includes local measurement information. In an exemplary embodiment, the second measurement information is a combination of the local measurement information and the second verification value, and the second measurement information can be obtained by splicing the local measurement information and the second verification value in the order of the local measurement information and the second verification value. Optionally, the second measurement information also includes a second random number. In an exemplary embodiment, the second measurement information is a combination of the second random number, the local measurement information, and the second verification value, and the second measurement information can be obtained by splicing the second random number, the local measurement information, and the second verification value in the order of the second random number, the local measurement information, and the second verification value.

[0415] J406. The UE sends a fourth metric response to the first node. The fourth metric response includes the second metric information. Optionally, the fourth metric response may also include a second random number and / or local metric information.

[0416] J407. The first node determines a second trustworthy measurement result according to the second measurement information and the second expected information.

[0417] The specific description of step J407 refers to the description of step C409 and is not repeated here.

[0418] J408. The first node feeds back the second trust metric result to the UE.

[0419] Optionally, the first node feeds back the second credibility measurement result to the first network element.

[0420] Specifically, the first node feeds back the second trusted measurement result to the first network element through the AMF, so that the first network element learns the trusted measurement result of the first node for the UE, and the first node endorses the local measurement information of the UE.

[0421] Referring to Figure 4J , when the second network element performs a trust measurement on the UE based on the second trust vector, taking the second network element as the AMF as an example, the fifth trust vector is the second trust vector. After the AMF network element receives the second trust vector, the AMF network element directly sends a fourth measurement request to the UE via the access network device. The UE returns a fourth measurement response to the AMF network element, and the AMF network element obtains the second trust measurement result based on the fourth measurement response.

[0422] In a possible embodiment, the above measurement method further includes:

[0423] The first network element sends a third trust vector to the second network element or the first node. The third trust vector includes a fifth derived key and the second expected measurement information. The third trust vector is used by the second network element or the first node to perform trust measurement processing on the terminal. The fifth derived key is derived from the symmetric key.

[0424] In this embodiment, the first network element sends a third trust vector to the second network element or the first node to send the trust measurement capability to the second network element or the first node. Optionally, the second network element or the first node can start the trust measurement of the UE periodically or according to other policies to prevent the local measurement information of the UE from being tampered with. The second expected measurement information is the above-mentioned first expected measurement information. Different from the embodiment corresponding to the above-mentioned second trust vector, in this embodiment, the second network element or the first node generates a second random number corresponding to the identification information of the UE, and the second network element or the first node processes the second random number and the second expected measurement information based on the fifth derived key to obtain a second expected verification value. The second network element or the first node can perform trust measurement on the UE based on the second random number, the second expected measurement information and the second expected verification value to obtain the second trust measurement result of the UE. For the relevant detailed description in this embodiment, please refer to the embodiment corresponding to the above-mentioned second trust vector.

[0425] Optionally, this embodiment can be independent of the method shown in FIG. 3 , that is, it can be independent of the first trust metric result of the UE. After the second network element or the first node obtains the third trust vector, it can initiate a trust metric on the UE based on actual conditions. Optionally, if the first trust metric result indicates that the UE is trustworthy, the first network element sends the third trust vector to the second network element or the first node.

[0426] Specifically, the fifth derived key is a key derived by the network for use by the second network element or the first node. The UE also derives the fifth derived key from the symmetric key using the same key derivation algorithm as the network. The UE and the second network element or the first node can perform a trust measurement based on the fifth derived key.

[0427] In this embodiment, when the first network element has not completed the first trust measurement of the UE, the second network element or the first node may request the third network element through the first network element to obtain the third trust vector, or the second network element or the first node may directly request the third network element to obtain the third trust vector.

[0428] Optionally, after the first network element completes the initial trust measurement of the UE, the first network element may also directly derive a fifth derived key based on the symmetric key. Further optionally, since the first expected measurement information is the second expected measurement information, the first network element may generate a second random number, and then process the second expected measurement information and the second random number based on the fifth derived key to obtain a second expected check value. In this way, the first network element can obtain a third trust vector.

[0429] The second network element or the first node performs a similar trust measurement process on the UE as the first network element, including the second network element or the first node receiving second measurement information of the UE and obtaining a second trust measurement result of the terminal based on the second measurement information and the second expected information. Optionally, the second network element or the first node may send the second trust measurement result to the UE.

[0430] In a possible embodiment, the above measurement method further includes:

[0431] The first network element receives a third trust vector from a third network element.

[0432] In this embodiment, when the first network element has not completed the first trust measurement of the UE, the first network element may request a third trust vector from the third network element. After generating the third trust vector, the third network element sends the third trust vector to the first network element.

[0433] The following takes the first node as an access network device as an example to specifically describe a process in which the first node performs a trust measurement on the UE based on the third trust vector:

[0434] In this embodiment, the same as FIG4A is that the root key K for authentication and the root key K for trust measurement are preset in the SIM card of the UE. TPM During the production phase, the SIM card manufacturer pre-installs the TPM function in the SIM card and transmits the root key K in the SIM card to the SIM card through a secure channel. TPM Update to the operator's resource server 402.

[0435] Referring to Figure 4B, in this embodiment, both the network side and the UE side perform key derivation based on the key architecture of Figure 4B. AMF-RA Derive the key K used by the access network device gNB-RA .

[0436] The following describes the UE trust measurement process:

[0437] Referring to FIG4K , FIG4K is an interactive flow chart of another measurement method provided in an embodiment of the present application. The measurement method includes the following steps:

[0438] K401. The first network element sends a trust vector request to the third network element, where the request includes identification information of the UE.

[0439] Specifically, the above-mentioned trusted vector request is used to request a sixth trusted vector, and the sixth trusted vector includes the key K AMF-RA In this embodiment, the first network element obtains the sixth trust vector from the third network element as an example. At this time, the third network element performs key derivation to obtain the key K AMF-RA The third network element returns the sixth trust vector to the first network element.

[0440] In this embodiment, the first network element may be a RAF network element, and the third network element may be a TPMF network element. Optionally, the UDM network element and the TPMF network element are deployed together. Alternatively, the TPMF network element and the RAF network element are deployed together.

[0441] K402. The first network element sends the sixth trust vector to the AMF network element.

[0442] K403. The AMF network element sends a third trust vector to the first node. The first node is an access network device.

[0443] The AMF network element obtains the third trust vector based on the sixth trust vector. Specifically, the AMF network element obtains the third trust vector based on the key K AMF-RA Derived key K gNB-RA , the third trusted vector includes the key K gNB-RA and second expected measurement information.

[0444] K404. The first node sends a fourth metric request to the UE.

[0445] Specifically, the fourth metric request is used to trigger the UE to determine the second metric information, and the fourth metric request includes a second random number. The first node generates a second random number corresponding to the identification information of the UE. The first node generates a second random number based on the key K gNB-RAThe second random number and the second expected metric information are processed to obtain a second expected check value. The first node may periodically send the fourth metric request to the UE, or the first node may send the fourth metric request to the UE based on other policies, such as after receiving a registration request from the UE or after the UE requests a service.

[0446] K405. UE determines the second measurement information.

[0447] K406. The UE sends a fourth metric response to the first node. The fourth metric response includes the second metric information. Optionally, the fourth metric response may also include a second random number and / or local metric information.

[0448] K407. The first node determines a second trustworthy measurement result based on the second measurement information and the second expected information.

[0449] The detailed description of step K407 refers to the description of step C409 and will not be repeated here.

[0450] K408. The first node feeds back the second trust metric result to the UE.

[0451] Optionally, the first node feeds back the second credibility measurement result to the first network element.

[0452] Referring to Figure 4K , when the first node and AMF network element in Figure 4K are replaced by an AMF network element, the sixth trust vector becomes the third trust vector. After the AMF network element receives the third trust vector, the AMF network element directly sends a fourth metric request to the UE through the access network device. The subsequent processing flow is the same as when the first node is an access network device and is not further described here.

[0453] The embodiment of the present application further provides a measurement method for performing a credibility measurement on a third node. The third node may be an access network device or a core network element.

[0454] Referring to FIG5 , FIG5 is a flow chart of another measurement method provided in an embodiment of the present application. The measurement method includes the following steps:

[0455] 501. The second node sends a third metric request to the third node.

[0456] Accordingly, the third node receives the third metric request from the second node.

[0457] Specifically, the third metric request is used to trigger the third node to determine the third metric information.

[0458] The second node can be a RAF network element, an OAM network element, or an NRF network element. If the second node is a RAF network element, and the third node is a core network element, the third node refers to the core network element other than the RAF network element. If the second node is an OAM network element, and the third node is a core network element, the third node refers to the core network element other than the OAM network element. If the second node is an NRF network element, and the third node is a core network element, the third node refers to the core network element other than the NRF network element.

[0459] 502. The third node determines third metric information. The third node determines the third metric information in response to a third metric request.

[0460] 503. The third node sends third metric information to the second node.

[0461] Accordingly, the second node receives third metric information from the third node;

[0462] 504. The second node obtains a trustworthy measurement result of the third node according to the third measurement information and the third expected information.

[0463] Specifically, the trust metric result indicates whether the third node is trustworthy or untrustworthy.

[0464] In this embodiment, the second node may determine the trustworthiness measurement result of the third node according to the third measurement information and the third expected information of the third node, thereby implementing trustworthiness measurement of the third node.

[0465] In a possible embodiment, referring to FIG5 , the measurement method further includes:

[0466] 505. The second node sends the trust measurement result to the third node.

[0467] Accordingly, the third node receives the trust measurement result of the third node from the second node.

[0468] It can be seen that in this embodiment, the second node feeds back its trustworthiness measurement result to the third node, so that the third node obtains its own trustworthiness measurement result.

[0469] In one possible embodiment, the third metric information in step 502 includes a third check value, which is obtained by processing the third random number and the local metric information using a symmetric key. The symmetric key is a key used for trust measurement, and a symmetric key means that the second node and the third node have the same key used for trust measurement. The third expected information includes a third expected check value. In step 504, the second node compares the third expected check value with the third check value to see if they are identical. If the two compare identically, the trust measurement result for the third node is that the third node is trustworthy. Otherwise, the trust measurement result for the third node is that the third node is untrustworthy.

[0470] In one possible embodiment, the third measurement information in the above step 502 also includes the local measurement information of the third node. And the third expected information also includes the third expected measurement information. In step 504, the second node compares whether the third expected measurement information and the local measurement information of the third node are the same, and compares whether the third expected check value and the third check value are the same. When both are compared and are the same, the trust measurement result of the third node is that the third node is trustworthy. Otherwise, the trust measurement result of the third node is that the third node is untrustworthy. The present application performs trust verification by verifying whether the two sets of parameters, the third check value and the third expected check value, and the local measurement information of the third node and the third expected measurement information, are the same, so as to ensure that the trust measurement result of the third node is more reliable.

[0471] Exemplarily, the third measurement information may also include a third random number to indicate that the third check value corresponds to the third random number. Similarly, the third expected information may also include a third random number to indicate that the third expected measurement information and the third expected check value correspond to the third random number. In step 504, the second node also compares whether the third random number in the third measurement information and the third random number in the third expected information are the same. When all three comparisons are the same, the trust measurement result of the third node is that the third node is trustworthy. Otherwise, the trust measurement result of the third node is that the third node is untrustworthy. The present application performs trust verification by verifying whether the three groups of parameters, namely, the third check value and the third expected check value, the local measurement information of the third node and the third expected measurement information, and the third random number in the third measurement information and the third random number in the third expected information, are the same, thereby further improving the credibility of the trust measurement result of the third node.

[0472] In a possible embodiment, the symmetric key is any one of the following:

[0473] A root key for trust measurement is pre-installed on the third node, specifically for trust measurement. The root key is securely shared with the network side, so that the third node and the second node can perform trust measurement based on the root key.

[0474] The sixth derived key is derived from the root key used for trust measurement. Specifically, the third node is pre-installed with a root key specifically used for trust measurement. This root key is securely shared with the network. The terminal and the network (e.g., the second node or third network element) derive the sixth derived key using the same derivation algorithm, enabling trust measurement between the third node and the second node based on the sixth derived key.

[0475] In one possible embodiment, in the above-mentioned measurement method, the second node can be co-located with a third network element, where the third network element is a TPMF network element. Optionally, the UDM network element and the TPMF network element are deployed in combination. Furthermore, optionally, the TPMF network element and the RAF network element are deployed in combination. In this case, the second node stores the third expected measurement information of the third node. The second node can generate a third random number and then process the third random number and the third expected measurement information based on a symmetric key to obtain a third expected check value. In this way, the second node can obtain the third expected information and, based on actual needs, initiate trusted measurement of the third node, namely, send a third measurement request to the third node, where the third measurement request includes the third random number.

[0476] In a possible embodiment, when the second node and the third network element are deployed separately, the measurement method further includes the following steps:

[0477] The second node sends a trust vector request to the third network element, where the trust vector request includes identification information of the third node.

[0478] The second node receives a fourth trust vector from a third network element, where the fourth trust vector includes third expected information.

[0479] Specifically, the third network element may be a TPMF network element. Optionally, the UDM network element and the TPMF network element are deployed together. Furthermore, optionally, the TPMF network element and the RAF network element are deployed together. Exemplarily, the third network element stores third expected metric information of a third node. The third network element may generate a third random number and then process the third random number and the third expected metric information according to a symmetric key to obtain a third expected check value. The third expected information includes the third expected check value. Optionally, the third expected information also includes the third expected metric information. Furthermore, optionally, the third expected information also includes the third random number. Furthermore, illustratively, the fourth trust vector may also include the aforementioned symmetric key.

[0480] The following uses the second node as an OAM network element and the third node as an access network device as an example to specifically explain the process of the OAM network element performing trust measurement on the access network device:

[0481] Refer to Figure 6A, which is another trust measurement flow chart provided by an embodiment of the present application. Similar to the UE, the security chip takes the TPM chip as an example. During the production stage of the access network device 601, the TPM function and the root key for trust measurement are pre-installed in the access network device, and the root key is updated to the operator's resource server 602 through a secure channel. In this way, in the subsequent use of the access network device 601, the operator network 603 and the access network device 601 can perform remote trust measurement based on the root key. Alternatively, the operator network 603 performs key deduction based on the root key K in the resource server 602 to obtain the sixth derived key, and the access network device 601 performs key deduction based on the root key in itself to obtain the sixth derived key, and the operator network 603 and the access network device 601 can perform remote trust measurement based on the sixth derived key.

[0482] The following is a detailed description of the trust measurement process of access network equipment.

[0483] Referring to FIG6B , FIG6B is an interactive flow chart of another measurement method provided in an embodiment of the present application. The measurement method includes the following steps:

[0484] B601. The OAM network element sends a trust vector request to a third network element. The request includes identification information of the OAM network element.

[0485] B602. The third network element obtains a fourth trust vector according to the identification information of the OAM network element.

[0486] Specifically, take the fourth trusted vector including the third expected information, and the third expected information including the third random number, the third expected measurement information, and the third expected verification value as an example.

[0487] B603. The third network element sends the fourth trust vector to the OAM network element.

[0488] B604. The OAM network element sends a third measurement request to the access network device, where the request includes a third random number.

[0489] B605. The access network device determines the third measurement information.

[0490] Exemplarily, the third measurement information includes a third random number, local measurement information of the access network device, and a third check value.

[0491] B606. The access network device sends a third metric response to the OAM network element. The response includes third metric information.

[0492] B607. The OAM network element compares the third measurement information with the third expected information to obtain a reliable measurement result of the access network device.

[0493] For example, the OAM network element compares the third random number in the third measurement information with the third random number in the third expected information to see if they are the same, compares the third expected measurement information with the local measurement information of the access network device to see if they are the same, and compares the third expected check value with the third check value to see if they are the same. If all three are the same, the trust measurement result of the access network device is that the access network device is trustworthy. Otherwise, the trust measurement result of the access network device is that the access network device is untrustworthy.

[0494] B608. The OAM network element returns the trust measurement result to the access network device.

[0495] Figures 7, 8, 9, and 10 are schematic diagrams of the structures of possible devices provided in embodiments of the present application. These devices can be used to implement the functions of the first network element, terminal, second node, and third node in the above-mentioned method embodiments, thereby also achieving the beneficial effects possessed by the above-mentioned method embodiments. In the embodiments of the present application, the device can be the first network element, terminal, second node, and third node, and can also be a module (such as a chip) applied to the first network element, terminal, second node, and third node.

[0496] As shown in Figure 7, Figure 7 is a schematic diagram of the structure of a first network element provided in an embodiment of the present application. The first network element 700 includes a receiving module 701 and a processing module 702. The first network element 700 is used to implement the functions of the first network element in the method embodiment shown in Figure 3 above. Alternatively, the first network element 700 may include a module for implementing any function or operation of the first network element in the method embodiment shown in Figure 3 above, and the module may be implemented in whole or in part by software, hardware, firmware, or any combination thereof.

[0497] When the first network element 700 is used to implement the functions of the first network element in the method embodiment shown in FIG3 , the receiving module 701 is configured to receive first measurement information from a terminal, and the processing module 702 is configured to obtain a first trustworthy measurement result of the terminal based on the first measurement information and the first expected information.

[0498] As shown in Figure 8, Figure 8 is a schematic diagram of the structure of a terminal provided in an embodiment of the present application. Terminal 800 includes a determination module 801 and a sending module 802. Terminal 800 is configured to implement the functions of the terminal in the method embodiment shown in Figure 3 above. Alternatively, terminal 800 may include a module for implementing any function or operation of the terminal in the method embodiment shown in Figure 3 above. This module may be implemented in whole or in part through software, hardware, firmware, or any combination thereof.

[0499] When the terminal 800 is used to implement the functions of the terminal in the method embodiment shown in FIG3 , the determining module 801 is configured to determine first metric information, and the sending module 802 is configured to send the first metric information to a first network element.

[0500] Illustratively, an embodiment of the present application further provides a communication system, the system including a first network element and a second network element as shown in FIG7 , wherein:

[0501] The second network element is configured to send a first measurement request to the first network element, where the first measurement request includes identification information of the terminal.

[0502] The first network element 700 is configured to receive first metric information from a terminal.

[0503] The first network element 700 is further configured to obtain a first trustworthy measurement result of the terminal according to the first measurement information and the first expected information.

[0504] As shown in Figure 9, Figure 9 is a schematic diagram of the structure of a second node provided in an embodiment of the present application. Second node 900 includes a sending module 901, a receiving module 902, and a determining module 903. Second node 900 is used to implement the functions of the second node in the method embodiment shown in Figure 5 above. Alternatively, second node 900 may include a module for implementing any function or operation of the second node in the method embodiment shown in Figure 5 above. This module may be implemented in whole or in part via software, hardware, firmware, or any combination thereof.

[0505] When the second node 900 is used to implement the functions of the second node in the method embodiment shown in FIG5 , a sending module 901 is configured to send a third metric request to a third node. A receiving module 902 is configured to receive third metric information from the third node. A determining module 903 is configured to obtain a trustworthy metric result for the third node based on the third metric information and third expected information.

[0506] As shown in Figure 10, Figure 10 is a schematic diagram of the structure of a third node provided in an embodiment of the present application. The third node 1000 includes a receiving module 1001 and a sending module 1002. The third node 1000 is configured to implement the functions of the third node in the method embodiment shown in Figure 5 above. Alternatively, the third node 1000 may include a module for implementing any function or operation of the third node in the method embodiment shown in Figure 5 above. The module may be implemented in whole or in part via software, hardware, firmware, or any combination thereof.

[0507] When the third node 1000 is used to implement the functions of the third node in the method embodiment shown in FIG5 , the receiving module 1001 is configured to receive a third metric request from the second node. The sending module 1002 is configured to send third metric information to the second node. The third metric information includes a third check value obtained by processing a third random number and local metric information of the third node using a symmetric key used for trustworthy measurement.

[0508] Illustratively, an embodiment of the present application further provides a communication system, which includes the second node shown in FIG. 9 and the third node shown in FIG. 10 .

[0509] FIG11 is a schematic structural diagram of a communication device provided in an embodiment of the present application.

[0510] The communication device 1100 includes a memory 1101, a processor 1102, a communication interface 1104, and a bus 1103. The memory 1101, the processor 1102, and the communication interface 1104 are connected to each other via the bus 1103. There may be one or more memories 1101 and one or more processors 1102.

[0511] Exemplarily, the communication device 1100 may be a chip or a chip system.

[0512] The memory 1101 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1101 may store a program. When the program stored in the memory 1101 is executed by the processor 1102, the processor 1102 is configured to execute the various steps of the measurement method described in any of the above embodiments.

[0513] The processor 1102 can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), a graphics processing unit (GPU) or one or more integrated circuits to execute relevant programs to implement the measurement method described in any of the above embodiments.

[0514] The processor 1102 may also be an integrated circuit chip with signal processing capabilities. During implementation, the various steps of the measurement method described in any embodiment of the present application may be completed by hardware integrated logic circuits or software instructions in the processor 1102. The aforementioned processor 1102 may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present application may be implemented or executed. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the measurement method described in any embodiment of the present application may be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or the like. The storage medium is located in the memory 1101 , and the processor 1102 reads the information in the memory 1101 and completes the measurement method described in any of the above embodiments in combination with its hardware.

[0515] The communication interface 1104 uses a transceiver device such as, but not limited to, a transceiver to implement communication between the communication device 1100 and other devices or a communication network. For example, the communication device 1100 can obtain second data through the communication interface 1104.

[0516] The bus 1103 may include a path for transmitting information between various components of the communication device 1100 (eg, the memory 1101 , the processor 1102 , and the communication interface 1104 ).

[0517] It should be noted that although the communication device 1100 shown in FIG11 only shows a memory, a processor, and a communication interface, during specific implementation, those skilled in the art will understand that the communication device 1100 also includes other components necessary for normal operation. Furthermore, those skilled in the art will understand that, depending on specific needs, the communication device 1100 may also include hardware components that implement other additional functions. Furthermore, those skilled in the art will understand that the communication device 1100 may only include the components necessary to implement the embodiments of the present application, and does not necessarily need to include all of the components shown in FIG11.

[0518] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0519] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0520] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0521] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk).

[0522] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A measurement method, characterized in that The method comprises: The first network element receives first metric information from the terminal; The first network element obtains a first trusted measurement result of the terminal according to the first measurement information and the first expected information.

2. The method according to claim 1, characterized in that The first measurement information includes a first verification value, where the first verification value is obtained by processing a first random number and local measurement information of the terminal using a symmetric key, where the symmetric key is a key used for trusted measurement.

3. The method according to claim 2, characterized in that The first metric information also includes the local metric information.

4. The method according to any one of claims 1 to 3, characterized in that: The first expected information includes a first expected check value.

5. The method according to claim 4, characterized in that The first expected information also includes first expected metric information.

6. The method according to any one of claims 2 to 5, characterized in that: Before the first network element receives the first metric information from the terminal, the method further includes: The first network element receives a first measurement request from a second network element, where the first measurement request includes identification information of the terminal; The first network element sends a second metric request to the terminal, where the second metric request includes the first random number, and the first random number corresponds to identification information of the terminal.

7. The method according to any one of claims 2 to 6, characterized in that: The method further comprises: The first network element obtains a first trusted vector corresponding to the identification information of the terminal, where the first trusted vector includes the first expected information.

8. The method according to claim 7, characterized in that The first network element obtains a first trusted vector corresponding to the identification information of the terminal, including: The first network element sends a trusted vector request to a third network element, where the trusted vector request includes identification information of the terminal; The first network element receives the first trusted vector corresponding to the identification information of the terminal and sent by the third network element.

9. The method according to claim 7, characterized in that: The first network element obtains a first trusted vector corresponding to the identification information of the terminal, including: The first network element receives the first trusted vector from an authentication network element.

10. The method according to any one of claims 7 to 9, characterized in that: The first trust vector also includes the symmetric key.

11. The method according to any one of claims 2 to 10, characterized in that: The symmetric key is any of the following: Root keys for trusted measurements; A first derived key, wherein the first derived key is derived from a root key used for trust measurement; a second derived key, wherein the second derived key is derived from a root key used for authentication; A third derived key, wherein the third derived key is derived from the authentication key.

12. The method according to any one of claims 2 to 11, characterized in that The method further comprises: The first network element performs key derivation according to the symmetric key to obtain a fourth derived key, where the fourth derived key is any one of the following: a first anchor point key; an authentication key.

13. The method according to any one of claims 2 to 12, characterized in that: The method further comprises: The first network element sends a second trusted vector to the second network element or the first node, where the second trusted vector includes second expected information; the second trusted vector is used by the second network element or the first node to perform trusted measurement processing on the terminal, where the second expected information includes a second expected verification value.

14. The method according to claim 13, characterized in that The second trust vector further includes a fifth derived key, where the fifth derived key is derived from the symmetric key.

15. The method according to claim 13 or 14, characterized in that The method further comprises: The first network element receives the second trusted vector from a third network element.

16. The method according to any one of claims 2 to 12, characterized in that The method further comprises: The first network element sends a third trusted vector to the second network element or the first node, where the third trusted vector includes a fifth derived key and second expected measurement information, and the third trusted vector is used by the second network element or the first node to perform trusted measurement processing on the terminal, and the fifth derived key is derived from the symmetric key.

17. The method according to claim 16, characterized in that The method further comprises: The first network element receives the third trusted vector from a third network element.

18. The method according to any one of claims 1 to 17, characterized in that The method further comprises: The first network element sends the first trust metric result to the terminal.

19. A measurement method, characterized in that The method comprises: The terminal determines first metric information; The terminal sends the first metric information to the first network element.

20. The method according to claim 19, characterized in that The first measurement information includes a first verification value, where the first verification value is obtained by processing a first random number and local measurement information of the terminal using a symmetric key, where the symmetric key is a key used for trusted measurement.

21. The method according to claim 20, characterized in that The first metric information also includes the local metric information.

22. The method according to claim 20 or 21, characterized in that Before the terminal determines the first metric information, the method further includes: The terminal receives a second metric request from the first network element, where the second metric request includes the first random number.

23. The method according to any one of claims 20 to 22, characterized in that The symmetric key is any of the following: Root keys for trusted measurements; A first derived key, wherein the first derived key is derived from a root key used for trust measurement; a second derived key, wherein the second derived key is derived from a root key used for authentication; A third derived key, wherein the third derived key is derived from the authentication key.

24. The method according to any one of claims 19 to 23, characterized in that The method further comprises: The terminal receives a first trustworthy measurement result of the terminal from the first network element, where the first trustworthy measurement result is obtained according to the first measurement information and first expected information.

25. The method according to claim 24, characterized in that The first expected information includes a first expected check value.

26. The method according to claim 25, characterized in that The first expected information also includes first expected metric information.

27. The method according to any one of claims 19 to 26, characterized in that The method further comprises: The terminal sends second metric information to the second network element or the first node.

28. A measurement method, characterized in that The method comprises: The second network element sends a first measurement request to the first network element, where the first measurement request includes identification information of the terminal; The first network element receives first metric information from the terminal; The first network element obtains a first trusted measurement result of the terminal according to the first measurement information and the first expected information.

29. The method according to claim 28, characterized in that The first measurement information includes a first verification value, where the first verification value is obtained by processing a first random number and local measurement information of the terminal using a symmetric key, where the symmetric key is a key used for trusted measurement.

30. The method according to claim 29, characterized in that The first metric information also includes the local metric information.

31. The method according to claim 29 or 30, characterized in that Before the first network element receives the first metric information from the terminal, the method further includes: The first network element sends a second metric request to the terminal, where the second metric request includes the first random number, and the first random number corresponds to identification information of the terminal.

32. The method according to any one of claims 28 to 31, characterized in that The method further comprises the following steps: The first network element obtains a first trusted vector corresponding to the identification information of the terminal, where the first trusted vector includes the first expected information.

33. The method according to claim 32, characterized in that The method further comprises: The first network element sends a trusted vector request to a third network element, where the trusted vector request includes identification information of the terminal; The third network element sends the first trusted vector corresponding to the identification information of the terminal to the first network element.

34. The method according to claim 32, characterized in that The method further comprises: The first network element receives the first trusted vector from an authentication network element.

35. The method according to any one of claims 29 to 34, characterized in that The symmetric key is any of the following: Root keys for trusted measurements; A first derived key, wherein the first derived key is derived from a root key used for trust measurement; a second derived key, wherein the second derived key is derived from a root key used for authentication; A third derived key, wherein the third derived key is derived from the authentication key.

36. The method according to any one of claims 29 to 35, characterized in that The method further comprises: The first network element performs key derivation according to the symmetric key to obtain a fourth derived key, where the fourth derived key is any one of the following: a first anchor point key; an authentication key.

37. The method according to any one of claims 29 to 36, characterized in that The method further comprises: The first network element sends a second trusted vector to the second network element or the first node, where the second trusted vector includes second expected information; the second trusted vector is used by the second network element or the first node to perform trusted measurement processing on the terminal, where the second expected information includes a second expected verification value.

38. The method according to claim 37, characterized in that The method further comprises: The third network element sends the second trusted vector to the first network element.

39. The method according to any one of claims 29 to 36, characterized in that The method further comprises: The first network element sends a third trusted vector to the second network element or the first node, where the third trusted vector includes a fifth derived key and second expected measurement information, where the third trusted vector is used by the second network element or the first node to perform trusted measurement processing on the terminal, and the fifth derived key is derived from the symmetric key; The second network element or the first node obtains a second random number; The second network element or the first node generates a random number according to the fifth derived key, the second random number, and the second expected The measurement information obtains a second expected check value.

40. The method according to claim 39, characterized in that The method further comprises: The third network element sends the third trusted vector to the first network element.

41. The method according to any one of claims 37 to 40, characterized in that The method further comprises: The second network element or the first node receives second metric information of the terminal; The second network element or the first node obtains a second trusted measurement result of the terminal according to the second measurement information and the second expected information.

42. The method according to any one of claims 28 to 41, characterized in that The method further comprises: The first network element sends the first trust metric result to the terminal.

43. A measurement method, characterized in that The method comprises: The second node sends a third metric request to the third node; The second node receives third metric information from the third node; The second node obtains a trustworthy measurement result of the third node according to the third measurement information and the third expected information.

44. The method according to claim 43, characterized in that The third measurement information includes a third verification value, where the third verification value is obtained by processing a third random number and local measurement information of the third node using a symmetric key, and the symmetric key is a key used for trusted measurement.

45. The method according to claim 44, characterized in that The third metric information also includes the local metric information.

46. ​​The method according to any one of claims 43 to 45, characterized in that The third expected information includes a third expected check value.

47. The method according to claim 46, characterized in that The third expected information also includes third expected metric information.

48. The method according to claim 43, characterized in that The method further comprises: The second node sends a trusted vector request to a third network element, where the trusted vector request includes identification information of the third node; The second node receives a fourth trusted vector from the third network element, where the fourth trusted vector includes the third expected information.

49. The method according to any one of claims 44 to 48, characterized in that The symmetric key is any of the following: Root keys for trusted measurements; A sixth derived key is derived from the root key used for trust measurement.

50. The method according to any one of claims 43 to 49, characterized in that The method further comprises: The second node sends the trust measurement result to the third node.

51. A measurement method, characterized in that The method comprises: The third node receives a third metric request from the second node; The third node sends third measurement information to the second node; the third measurement information includes a third verification value, and the third verification value is obtained by processing a third random number and local measurement information of the third node using a symmetric key, and the symmetric key is a key used for trusted measurement.

52. The method according to claim 51, characterized in that The third metric information also includes the local metric information.

53. The method according to claim 51 or 52, characterized in that The symmetric key is any of the following: Root keys for trusted measurements; A sixth derived key is derived from the root key used for trust measurement.

54. The method according to any one of claims 51 to 53, characterized in that The method further comprises: The third node receives a trustworthy measurement result of the third node from the second node, where the trustworthy measurement result is obtained according to the third measurement information and third expected information.

55. The method according to claim 54, characterized in that The third expected information includes a third expected check value.

56. The method according to claim 55, characterized in that The third expected information also includes third expected metric information.

57. A measurement method, characterized in that The method comprises: The second node sends a third metric request to the third node; The third node sends third metric information to the second node; The second node obtains a trustworthy measurement result of the third node according to the third measurement information and the third expected information.

58. The method according to claim 57, characterized in that The third measurement information includes a third verification value, where the third verification value is obtained by processing a third random number and local measurement information of the third node using a symmetric key, and the symmetric key is a key used for trusted measurement.

59. The method according to claim 57 or 58, characterized in that The third expected information includes a third expected check value.

60. The method according to claim 59, characterized in that The method further comprises: The second node sends a trusted vector request to a third network element, wherein the trusted vector request includes a tag of the third node. Knowledge information; The third network element sends a fourth trusted vector to the second node, where the fourth trusted vector includes the third expected information.

61. The method according to any one of claims 58 to 60, characterized in that The symmetric key is any of the following: Root keys for trusted measurements; A sixth derived key is derived from the root key used for trust measurement.

62. The method according to any one of claims 57 to 61, characterized in that The method further comprises: The third node receives the trust metric result from the second node.

63. A first network element, characterized in that: include: A receiving module, configured to receive first metric information from a terminal; The processing module is used to obtain a first trustworthy measurement result of the terminal according to the first measurement information and the first expected information.

64. A terminal, characterized in that: include: A determination module, configured to determine first measurement information; A sending module is used to send the first measurement information to the first network element.

65. A communication system, characterized in that: The system comprises a first network element and a second network element, wherein: The second network element is configured to send a first measurement request to the first network element, where the first measurement request includes identification information of the terminal; The first network element is used to receive first metric information from the terminal; The first network element is further configured to obtain a first trusted measurement result of the terminal according to the first measurement information and the first expected information.

66. A second node, characterized in that: include: A sending module, used for sending a third metric request to a third node; A receiving module, configured to receive third metric information from the third node; The determination module is used to obtain a trustworthy measurement result of the third node according to the third measurement information and the third expected information.

67. A third node, characterized in that: include: A receiving module, configured to receive a third metric request from a second node; A sending module is used to send third measurement information to the second node, where the third measurement information includes a third verification value, where the third verification value is obtained by processing a third random number and local measurement information of the third node using a symmetric key, where the symmetric key is a key used for trusted measurement.

68. A communication system, characterized in that: The system comprises a second node and a third node, wherein: The second node is used to send a third metric request to the third node; The third node is used to send third metric information to the second node; The second node is further configured to obtain a trusted measurement result of the third node according to the third measurement information and the third expected information.

69. A communication device, characterized in that: The communication device includes one or more processors and one or more memories; wherein the one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer program codes, and the computer program codes include computer instructions, and when the one or more processors execute the computer instructions, the communication device executes the method described in any one of claims 1 to 62.

70. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed by a processor, the method described in any one of claims 1 to 62 is implemented.

71. A computer program product, characterized in that The invention comprises a computer program which, when executed on a processor, implements the method according to any one of claims 1 to 62.