Security activation method, terminal and network side equipment
By introducing a 256-bit security algorithm and negotiating the target security algorithm to generate keys, the problem that the existing 128-bit security algorithm is easily cracked by quantum computers is solved, and communication security is improved.
Patent Information
- Application Number
- CN202410403538.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-03
- Publication Date
- 2025-10-14
AI Technical Summary
The 128-bit security algorithm used in existing mobile communication networks is at risk of being hacked after the emergence of quantum computers, and the performance of the security algorithm needs to be improved.
A 256-bit security algorithm is introduced, and the target security algorithm is negotiated between the terminal and the network-side device to generate a security key and activate the corresponding security protection.
While being compatible with 128-bit security algorithms, it improves communication security and enhances resistance to quantum computer attacks.
Smart Images

Figure CN120786375A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of communication, and particularly relates to a method for activating security, a terminal and a network side device. BACKGROUND
[0002] A 128-bit security algorithm is used in the current mobile communication network, and such a security algorithm may be at risk of being broken after the emergence of a quantum computer. How to improve the security algorithm is a problem to be solved urgently. SUMMARY
[0003] Embodiments of the present application provide a method for activating security, a terminal and a network side device, which can solve the problem of poor performance of a security algorithm in the related art.
[0004] In a first aspect, a method for activating security is provided, which includes: a terminal sending terminal security capability information to a network side device, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; the terminal receiving an identifier of a target security algorithm sent by the network side device, the target security algorithm being one of the security algorithms supported by the terminal; the terminal deriving a security key according to the identifier of the target security algorithm; and the terminal activating security protection with the network side device according to the target security algorithm and the security key.
[0005] In a second aspect, a method for activating security is provided, which includes: an access network device receiving terminal security capability information from a terminal, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; the access network device selecting a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, the target security algorithm being one of the security algorithms supported by the terminal; the access network device deriving a security key according to the identifier of the target security algorithm; the access network device activating security protection with the terminal according to the target security algorithm and the security key; and the access network device sending the identifier of the target security algorithm to the terminal.
[0006] In a third aspect, a method for activating security is provided, including: receiving, by a core network device, terminal security capability information sent by a terminal, the terminal security capability information including an identity of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; selecting, by the core network device, a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, the target security algorithm being one of the security algorithms supported by the terminal; deriving, by the core network device, a security key according to the identity of the target security algorithm; activating, by the core network device, security protection with the terminal according to the target security algorithm and the security key; and sending, by the core network device, the identity of the target security algorithm to the terminal.
[0007] In a fourth aspect, a device for activating security is provided, applied to a terminal, including: a communication module configured to send terminal security capability information to a network side device, the terminal security capability information including an identity of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; the communication module configured to receive an identity of a target security algorithm sent by the network side device, the target security algorithm being one of the security algorithms supported by the terminal; the communication module configured to derive a security key according to the identity of the target security algorithm; and the communication module configured to activate security protection with the network side device according to the target security algorithm and the security key.
[0008] In a fifth aspect, a device for activating security is provided, applied to an access network device, including: a communication module configured to receive terminal security capability information from a terminal, the terminal security capability information including an identity of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; the communication module configured to select a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, the target security algorithm being one of the security algorithms supported by the terminal; the communication module configured to derive a security key according to the identity of the target security algorithm; the communication module configured to activate security protection with the terminal according to the target security algorithm and the security key; and the communication module configured to send the identity of the target security algorithm to the terminal.
[0009] In the sixth aspect, a device for activating security is provided, which is applied to a core network device, including: a communication module for receiving terminal security capability information sent by a terminal, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; the communication module for selecting a target security algorithm based on the terminal security capability information and a preconfigured algorithm priority list, the target security algorithm being one of the security algorithms supported by the terminal; the communication module for deriving a security key based on the identifier of the target security algorithm; the communication module for activating security protection with the terminal based on the target security algorithm and the security key; the communication module for sending the identifier of the target security algorithm to the terminal.
[0010] In a seventh aspect, a terminal is provided, comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.
[0011] In an eighth aspect, a terminal is provided, comprising a processor and a communication interface, wherein the communication interface is used to send terminal security capability information to a network side device, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; receiving an identifier of a target security algorithm sent by the network side device, the target security algorithm being one of the security algorithms supported by the terminal; deriving a security key based on the identifier of the target security algorithm; and activating security protection with the network side device based on the target security algorithm and the security key.
[0012] In the ninth aspect, a network side device (including an access network device or a core network device) is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the second aspect or the third aspect are implemented.
[0013] In a tenth aspect, an access network device is provided, comprising a processor and a communication interface, wherein the communication interface is configured to receive terminal security capability information from a terminal, the terminal security capability information comprising an identity of a security algorithm supported by the terminal, the security algorithm comprising a security algorithm with a packet length of 256 bits; select a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, the target security algorithm being one of the security algorithms supported by the terminal; derive a security key according to the identity of the target security algorithm; activate security protection with the terminal according to the target security algorithm and the security key; and send the identity of the target security algorithm to the terminal.
[0014] In an eleventh aspect, a core network device is provided, comprising a processor and a communication interface, wherein the communication interface is configured to receive terminal security capability information sent by a terminal, the terminal security capability information comprising an identity of a security algorithm supported by the terminal, the security algorithm comprising a security algorithm with a packet length of 256 bits; select a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, the target security algorithm being one of the security algorithms supported by the terminal; derive a security key according to the identity of the target security algorithm; activate security protection with the terminal according to the target security algorithm and the security key; and send the identity of the target security algorithm to the terminal.
[0015] In a twelfth aspect, a readable storage medium is provided, the readable storage medium storing a program or instructions, the program or instructions being executed by a processor to implement the steps of the method according to the first aspect, the second aspect or the third aspect.
[0016] In a thirteenth aspect, a wireless communication system is provided, comprising a terminal and a network side device, the terminal being configured to implement the steps of the method according to the first aspect, and the network side device being configured to implement the steps of the method according to the second aspect or the third aspect.
[0017] In a fourteenth aspect, a chip is provided, the chip comprising a processor and a communication interface, the communication interface being coupled to the processor, the processor being configured to run a program or instructions to implement the steps of the method according to the first aspect, the second aspect or the third aspect.
[0018] In a fifteenth aspect, a computer program / program product is provided, the computer program / program product being stored in a storage medium, the computer program / program product being executed by at least one processor to implement the steps of the method according to the first aspect, the second aspect or the third aspect.
[0019] In an embodiment of the present application, a 256-bit security algorithm is introduced, and the terminal negotiates a target security algorithm with the network side device, so that the terminal can generate a security key according to the target security algorithm, and activate the corresponding security according to the security key and the target security algorithm, thereby improving communication security while ensuring compatibility with the 128-bit security algorithm in the relevant technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 is a schematic diagram of a wireless communication system according to an embodiment of the present application;
[0021] Figure 2 is a schematic flow chart of a method for activating security according to an embodiment of the present application;
[0022] Figure 3 is a schematic flow chart of a method for activating security according to an embodiment of the present application;
[0023] Figure 4 is a schematic flow chart of a method for activating security according to an embodiment of the present application;
[0024] Figure 5 is a schematic flow chart of a method for activating security according to an embodiment of the present application;
[0025] Figure 6 is a schematic structural diagram of a device for activating security according to an embodiment of the present application;
[0026] Figure 7 is a schematic structural diagram of a device for activating security according to an embodiment of the present application;
[0027] Figure 8 is a schematic structural diagram of a device for activating security according to an embodiment of the present application;
[0028] Figure 9 is a structural diagram of a communication device according to an embodiment of the present application;
[0029] Figure 10 is a schematic structural diagram of a terminal according to an embodiment of the present application;
[0030] Figure 11 is a schematic structural diagram of an access network device according to an embodiment of the present application;
[0031] Figure 12 It is a structural diagram of the core network device according to an embodiment of the present application. DETAILED DESCRIPTION
[0032] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.
[0033] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0034] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.
[0035] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for illustrative purposes, and the NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as the 6th generation (6G) system. th Generation, 6G) communication system.
[0036] Figure 1The block diagram of a wireless communication system applicable to the embodiments of the present application is shown. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device (Wearable Device), an aircraft (flight vehicle), a vehicle user equipment (VUE), a ship-borne device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture, etc.), a game console, a personal computer (PC), a teller machine, or a self-service machine, etc., and other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 may include an access network device or a core network device, wherein the access network device may also be called a radio access network (Radio Access Network, RAN) device, a radio access network function or a radio access network unit. The access network device may include a base station, a wireless local area network (Wireless Local Area Network, WLAN) access point (Access Point, AS) or a wireless fidelity (Wireless Fidelity, WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the relevant field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
[0037] It should be noted that in the embodiments of this application, only the core network equipment in the NR system is introduced as an example, and the specific type of the core network equipment is not limited. But not limited to at least one of the following: core network node, core network function, Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized Network Configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), etc. It should be noted that in the embodiments of this application, only the core network equipment in the NR system is introduced as an example, and the specific type of the core network equipment is not limited.
[0038] The main process of the method for activating security provided in the embodiment of the present application is as follows:
[0039] 1.AMF and RAN select the target security algorithm based on the terminal security capability information reported by the terminal and the locally configured algorithm priority list.
[0040] 2.AMF and RAN notify the terminal of the identifier of the target security algorithm through a downlink message.
[0041] 3. The terminal and AMF / RAN can derive security keys based on the target security algorithm.
[0042] 4.AMF, RAN and terminal then use security keys and target security algorithms to enable related (NAS, RRC, UP) security protection.
[0043] The following describes in detail the method for activating security provided by the embodiments of the present application through some embodiments and their application scenarios in conjunction with the accompanying drawings.
[0044] like Figure 2 As shown, an embodiment of the present application provides a method 200 for activating security, which can be executed by a terminal. In other words, the method can be executed by software or hardware installed in the terminal, and the method includes the following steps.
[0045] S202: The terminal sends terminal security capability information to the network side device. The terminal security capability information includes identifiers of security algorithms supported by the terminal. The security algorithms include security algorithms with a packet length of 256 bits.
[0046] The network side devices mentioned in various embodiments of this application may include access network devices and may also include core network devices, such as AMF. In the case where the network side device is an access network device, the terminal may send terminal security capability information to the access network device through the core network device.
[0047] The security algorithms supported by the terminal include security algorithms with a block length of 256 bits, which means that the encrypted data block is grouped into 256 bits, or that an encrypted block is 256 bits, or that the length of the output message authentication code is 256 bits, or that the key length is 256 bits.
[0048] Optionally, the terminal security capability information also includes first indication information, and the first indication information is used to indicate that the terminal supports the authentication encryption mode, wherein the first indication information can be used to indicate that the terminal supports the authentication encryption mode for a specified security algorithm; or, the first indication information can be used to indicate that the terminal supports the authentication encryption mode for all supported security algorithms.
[0049] Optionally, the first indication information may also be an implicit indication. If the terminal supports the encryption algorithm and integrity protection algorithm of the same algorithm at the same time, it may implicitly indicate that the UE supports the authenticated encryption mode, that is, the UE supports the authenticated encryption with associated data (AEAD) mode for the algorithm.
[0050] For example, if the terminal supports both NIA4 and NEA4, that is, the bit corresponding to NIA4 is 1 and the bit corresponding to NEA4 is 1, it means that the terminal supports both the 256-bit AES encryption algorithm and the 256-bit AES integrity protection algorithm. Then, NIA4 and NEA4 can be combined as the first indication information, indicating that the terminal supports the authenticated encryption mode of the 256-bit AES algorithm.
[0051] S204: The terminal receives an identifier of a target security algorithm sent by the network-side device, where the target security algorithm is one of the security algorithms supported by the terminal.
[0052] In this embodiment, the network-side device can select a target security algorithm based on the terminal security capability information and a pre-configured algorithm priority list, and send an identifier of the target security algorithm to the terminal. The target security algorithm may include an encryption algorithm and an integrity protection algorithm. The target security algorithm may use the Authenticated Encryption with Associated Data (AEAD) mode, which is an encryption form that uses a single key to provide both encryption protection and integrity protection.
[0053] Optionally, the algorithm priority list also includes security algorithms using authenticated encryption mode. The network-side device can additionally select whether to use the security algorithm using authenticated encryption mode based on the first indication information in the terminal security capability information. For example, the algorithm priority list is Algorithm 4 with authenticated encryption > Algorithm 4.
[0054] Optionally, after the terminal sends the terminal security capability information to the network side device, the method further includes: the terminal receiving second indication information, where the second indication information is used to instruct the terminal to use the authentication encryption mode of the target security algorithm.
[0055] S206: The terminal derives a security key according to the identifier of the target security algorithm.
[0056] Optionally, when the packet length of the target security algorithm is 128 bits, the terminal derives a first key of 256 bits in length based on the identifier of the target security algorithm; the terminal obtains the security key of 128 bits in length by inputting the first key into a truncation function. For example, the target security algorithm includes a 128-bit encryption algorithm and a 128-bit integrity protection algorithm. The terminal derives a 256-bit non-access stratum encryption key Knas-enc' based on the identifier of the encryption algorithm and the access and mobility management function key Kamf; derives a 256-bit non-access stratum integrity protection key Knas-int' based on the identifier of the integrity protection algorithm and the access and mobility management function key Kamf; and the terminal then uses the truncation function to truncate the 128-bit Knas-enc' and Knas-int'. For another example, the terminal uses the authentication encryption mode of the target security algorithm, and derives a first key with a length of 256 bits based on the access and mobility management function key Kamf, the authentication encryption algorithm type difference of the target security algorithm, and the algorithm identifier; the terminal obtains the security key with a length of 128 bits by inputting the first key into the truncation function.
[0057] Optionally, when the packet length of the target security algorithm is 256 bits, the terminal derives a first key with a length of 256 bits based on the identifier of the target security algorithm; the terminal skips the truncation function and uses the first key as the security key. For example, the target security algorithm includes a 256-bit encryption algorithm and a 256-bit integrity protection algorithm. The terminal derives a 256-bit non-access stratum encryption key Knas-enc' based on the identifier of the encryption algorithm and the access and mobility management function key Kamf; and derives a 256-bit non-access stratum integrity protection key Knas-int' based on the identifier of the integrity protection algorithm and the access and mobility management function key Kamf. For another example, the terminal uses the authenticated encryption mode of the target security algorithm. The terminal derives a first key with a length of 256 bits based on the access and mobility management function key Kamf, the authentication encryption algorithm type difference of the target security algorithm, and the algorithm identifier.
[0058] S208: The terminal activates security protection with the network-side device according to the target security algorithm and the security key.
[0059] The method for activating security provided in the embodiment of the present application introduces a 256-bit security algorithm on the network side. The terminal negotiates the target security algorithm with the network side device, generates a security key based on the target security algorithm, and activates the corresponding security based on the security key and the target security algorithm to improve communication security.
[0060] The method for activating security provided in the embodiment of the present application, when the 256-bit security algorithm of the authentication encryption mode is introduced on the network side, the terminal can negotiate the security algorithm of the authentication encryption mode with the network side device, generate a security key according to the security algorithm of the authentication encryption mode, and activate the corresponding security according to the security key and the security algorithm of the authentication encryption mode.
[0061] The following will introduce the two cases where the network side equipment is core network equipment and access network equipment respectively.
[0062] Optionally, in one embodiment, the network side device is an AMF; wherein, the terminal sending the terminal security capability information to the network side device includes: the terminal sending a registration request message to the AMF, the registration request message including the terminal security capability information; the terminal receiving the identifier of the target security algorithm sent by the network side device includes: the terminal receiving the non-access stratum security mode command (Non-Access Stratum Security Mode Command, NAS SMC) message sent by the AMF, the NAS SMC message including the identifier of the target security algorithm, and the NAS SMC message is used to activate NAS security.
[0063] In one embodiment, the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the terminal derives a security key according to an identifier of the target security algorithm, including: the terminal deriving a non-access layer encryption key Knas-enc' with a length of 256 bits according to the identifier of the encryption algorithm and the access and mobility management function key Kamf, and the terminal deriving a non-access layer integrity protection key K with a length of 256 bits according to the identifier of the integrity protection algorithm and the access and mobility management function key Kamf. nas-int'; for example, the terminal derives a 256-bit non-access stratum encryption key Knas-enc' based on the encryption algorithm identifier (Alg-ID), the algorithm type distinction of the encryption algorithm (N-NAS-enc-alg), and the access and mobility management function key Kamf; the terminal derives a 256-bit non-access stratum integrity protection key Knas-int' based on the integrity protection algorithm identifier (Alg-ID), the algorithm type distinction of the integrity protection algorithm (N-NAS-int-alg), and the access and mobility management function key Kamf. The terminal activates security protection with the network-side device based on the target security algorithm and the security key, including: the terminal activates NAS encryption with the AMF based on the encryption algorithm and Knas-enc'; the terminal activates NAS integrity protection with the AMF based on the integrity protection algorithm and Knas-int'.
[0064] In one embodiment, after the terminal sends the terminal security capability information to the network side device, the method further includes: the terminal receiving second indication information, where the second indication information is used to instruct the terminal to use the authentication encryption mode of the target security algorithm.
[0065] The second indication information may be received in a NAS SMC message.
[0066] Related technologies for 128-bit security algorithms only consider standalone encryption or integrity protection algorithms, and have not considered the authenticated encryption mode introduced by the 256-bit security algorithm. Negotiating this new mode presents a challenge. Furthermore, since this mode utilizes a single key to provide both confidentiality and integrity, generating the corresponding security key also presents a challenge. The following embodiments address this issue.
[0067] In one embodiment, the terminal derives a security key based on the identifier of the target security algorithm, including: the terminal derives a second key Knas' with a length of 256 bits based on the second indication information, the access and mobility management function key Kamf, the authentication encryption algorithm type difference of the target security algorithm and the algorithm identifier; for example, the terminal sets the algorithm type difference of the target security algorithm to a new value, which is used to indicate the NAS encryption or integrity protection method using the authentication encryption algorithm type, hereinafter referred to as the authentication encryption algorithm type difference, for example, 0x07 is used to indicate the NAS authentication encryption method, which can be expressed as N-NAS-AEAD-alg or N-NAS-AE-alg. Optionally, the terminal sets the algorithm identifier to the selected target security algorithm, for example, the terminal sets the lower 2 bits of the highest reserved 4 bits to 01 (for example, when 5G-NA is 256-NEA4 and 5G-IA is 256-NIA4, it is set to 00010100 (i.e., 0x14), when 5G-NA is 256-NEA5 and 5G-IA is 256-NIA5, it is set to 00010101 (i.e., 0x15), when 5G-NA is 256-NEA6 and 5G-IA is 256-NIA6, it is set to 00010110 (i.e., 0x16)). The terminal derives a single key Knas' based on Kamf, the authentication and encryption algorithm type difference of the target security algorithm, and the algorithm identifier. The terminal activates security protection with the network side device according to the target security algorithm and the security key, including: the terminal activates NAS encryption and integrity protection with the AMF according to the target security algorithm of the authentication and encryption mode and the second key Knas'.
[0068] Among them, the authentication encryption algorithm uses one key to simultaneously provide encryption protection and integrity protection. Therefore, the authentication encryption algorithm type distinction of the target security algorithm and the algorithm type distinction in the related art may be different.
[0069] In one embodiment, the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives a second key Knas' with a length of 256 bits according to the non-access layer encryption key Knas-enc' and the non-access layer integrity protection key Knas-int' based on the second indication information; for example, Knas-enc' is XORed with Knas-int' to obtain Knas', or Knas-enc' and Knas-int' are input into a key derivation function (Key Derivation Function, KDF) to obtain Knas'.
[0070] The terminal activates security protection with the network side device according to the target security algorithm and the security key, including: the terminal activates NAS encryption and integrity protection with the AMF according to the target security algorithm of the authentication encryption mode and the second key Knas'.
[0071] In the above embodiment where the network side device is AMF, the key derivation process, encryption and integrity protection process on the AMF side are similar to those on the terminal side. For details, please refer to Figure 3 and Figure 4 A detailed description of the illustrated embodiment.
[0072] The following describes the case where the network-side device is an access network device.
[0073] Optionally, in one embodiment, the network side device is a RAN; wherein, the terminal sending the terminal security capability information to the network side device includes: the terminal sending the terminal security capability information to the RAN through the AMF; the terminal receiving the identifier of the target security algorithm sent by the network side device includes: the terminal receiving an access stratum security mode command (Access Stratum Security Mode Command, AS SMC) message sent by the RAN, the AS SMC message including the identifier of the target security algorithm, and the AS SMC message being used to activate radio resource control (Radio Resource Control, RRC) security.
[0074] For example, the terminal first sends a registration request message to the AMF, where the registration request message includes the terminal security capability information. The AMF sends an initialization UE context message to the RAN, where the initialization UE context message includes the terminal security capability information.
[0075] In one embodiment, the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives a security key according to the identifier of the encryption algorithm and the access layer key K gNB , derive the wireless access control encryption key Krrc-enc' with a length of 256 bits, and the terminal uses the identifier of the integrity protection algorithm and the access layer key K gNB , derive the 256-bit wireless access control integrity protection key Krrc-int'; for example, the terminal uses the encryption algorithm identifier (Alg-ID), the encryption algorithm type distinction (N-RRC-enc-alg) and the access layer key K gNB, derive the wireless access control encryption key Krrc-enc' with a length of 256 bits; the terminal uses the integrity protection algorithm identifier (Alg-ID), the integrity protection algorithm algorithm type distinction (N-RRC-int-alg) and the access layer key K gNB , deriving a radio access control integrity protection key Krrc-int' with a length of 256 bits. The terminal activates security protection with the network-side device based on the target security algorithm and the security key, including: the terminal activates RRC encryption with the RAN based on the encryption algorithm and Krrc-enc'; the terminal activates RRC integrity protection with the RAN based on the integrity protection algorithm and Krrc-int'.
[0076] In one embodiment, after the terminal sends the terminal security capability information to the network side device, the method further includes: the terminal receiving third indication information, where the third indication information is used to instruct the terminal to use the authentication encryption mode of the target security algorithm.
[0077] The third indication information may be received in an AS SMC message, and the second indication information and the third indication information may be different information.
[0078] In one embodiment, the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives a security key according to the access layer key K based on the third indication information. gNB, the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a third key Krrc' with a length of 256 bits; for example, the terminal sets the authentication encryption algorithm type difference to a new value, such as 0x10 to indicate the RRC authentication encryption method, which can be expressed as N-RRC-AEAD-alg or N-RRC-AE-alg. The terminal sets the algorithm identifier to the selected target security algorithm and sets the lowest 2 bits of the reserved highest 4 bits to 01 (for example, when 5G-NA is 256-NEA4 and 5G-IA is 256-NIA4, it is set to 00010100 (i.e., 0x14); when 5G-NA is 256-NEA5 and 5G-IA is 256-NIA5, it is set to 00010101 (i.e., 0x15); when 5G-NA is 256-NEA6 and 5G-IA is 256-NIA6, it is set to 00010110 (i.e., 0x16)). The terminal derives a single key Krrc' based on the KgNB, the authentication and encryption algorithm type, and the algorithm identifier. Activating, by the terminal, security protection with the network-side device based on the target security algorithm and the security key includes: activating, by the terminal, RRC encryption and integrity protection with the RAN based on the target security algorithm in the authentication and encryption mode and the third key Krrc'.
[0079] Optionally, in one embodiment, the terminal derives a security key based on the identifier of the target security algorithm, including: the terminal derives a third key Krrc' of 256 bits based on the radio access control encryption key Krrc-enc' and the radio access control integrity protection key Krrc-int' based on the third indication information; for example, Krrc' may be obtained by performing an exclusive-OR operation on Krrc-enc' or by inputting Krrc-int' into a key derivation function (KDF) to obtain Krrc'. The terminal activating security protection with the network-side device based on the target security algorithm and the security key includes: the terminal activating RRC encryption and integrity protection with the RAN based on the target security algorithm in the authenticated encryption mode and the third key Krrc'.
[0080] In the above embodiment where the network side device is RAN, the key derivation process, encryption and integrity protection process on the RAN side are similar to those on the terminal side. For details, please refer to Figure 3 and Figure 5 A detailed description of the illustrated embodiment.
[0081] Since the RAN has both RRC and UP protection, and 5G uses the same security algorithms for RRC and UP, but encryption and integrity protection are mandatory for RRC, but optional for UP, if RRC uses an algorithm in authenticated encryption mode and UP does not have encryption and / or integrity protection enabled, inconsistencies in the RRC and UP security algorithms may occur. The following embodiments can address this issue.
[0082] Optionally, in one embodiment, the method further includes: the terminal receiving an RRC reconfiguration message, the RRC reconfiguration message including a user plane UP security activation indication, the UP security activation indication being used to indicate: whether to enable user plane encryption and whether to enable user plane integrity protection.
[0083] The UP security activation indication is generated based on the UP security policy. For example, the SMF sends the UP security policy to the RAN via the AMF. The UP security policy includes the UP encryption policy and the UP integrity protection policy. The UP encryption policy indicates whether the RAN should enable user plane confidentiality protection, while the UP integrity protection policy indicates whether the RAN should enable user plane integrity protection. There are three options: required, preferred, and not needed.
[0084] When the UP encryption policy indicates that it must be enabled, the UP security activation indication is to enable user plane encryption.
[0085] When the UP encryption policy indication is not enabled, the UP security activation indication is to disable user plane encryption.
[0086] When the UP encryption policy indicates that it is recommended to enable, the RAN can decide whether to enable user plane encryption, that is, the UP security activation indication is whether to enable or not enable user plane encryption.
[0087] When the UP integrity protection policy indicates that it must be enabled, the UP security activation indication is to enable user plane integrity protection.
[0088] When the UP integrity protection policy indication is not enabled, the UP security activation indication is to disable the user plane integrity protection policy.
[0089] When the UP integrity protection policy indicates that it is recommended to be enabled, the RAN can decide whether to enable the user plane integrity protection policy, that is, whether the UP security activation indication is to enable or not enable the user plane integrity protection policy.
[0090] It should be noted that the UP key mentioned later can be generated after receiving the AS SMC and before receiving the RRC reconfiguration message; it can also be generated after receiving the RRC reconfiguration message.
[0091] In one embodiment, the UP security activation indication is used to indicate the activation of user plane encryption and the activation of user plane integrity protection, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives a security key according to the identifier of the encryption algorithm and the access layer key K gNB , derive the user plane encryption key Kup-enc' of length 256 bits, and the terminal uses the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; for example, the terminal derives a user plane encryption key Kup-enc' with a length of 256 bits based on the identifier (Alg-ID) of the encryption algorithm, the algorithm type distinction (N-UP-enc-alg) of the encryption algorithm, and the access layer key KgNB, and the terminal derives a user plane integrity protection key Kup-int' with a length of 256 bits based on the identifier (Alg-ID) of the integrity protection algorithm, the algorithm type distinction (N-UP-int-alg) of the integrity protection algorithm, and the access layer key KgNB. The terminal activates security protection with the network-side device based on the target security algorithm and the security key, including: the terminal activates user plane encryption with the RAN based on the encryption algorithm and Kup-enc'; the terminal activates user plane integrity protection with the RAN based on the integrity protection algorithm and Kup-int'.
[0092] In one embodiment, the UP security activation indication is used to indicate the opening of user plane encryption and the opening of user plane integrity protection, and the target security algorithm used by the RRC uses the authenticated encryption mode; the terminal derives the security key according to the identifier of the target security algorithm, including: the terminal derives the security key according to the access layer key K gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a fourth key Kup' with a length of 256 bits; the terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: the terminal activates user plane encryption and user plane integrity protection with the RAN according to the target security algorithm in the authentication encryption mode and the fourth key Kup'.
[0093] In this embodiment, the terminal may determine, through the third indication information, that the target security algorithm used by the RRC uses an authenticated encryption mode.
[0094] In one embodiment, the UP security activation indication is used to indicate the activation of user plane encryption and user plane integrity protection, and the target security algorithm used by the RRC uses an authenticated encryption mode; the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives a single fourth key Kup' with a length of 256 bits according to the user plane encryption key Kup-enc' and the user plane integrity protection key Kup-int'; the terminal activates security protection with the network side device according to the target security algorithm and the security key, including: the terminal activates user plane encryption and user plane integrity protection with the RAN according to the target security algorithm in the authenticated encryption mode and the fourth key Kup'.
[0095] In one embodiment, the UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits; the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives a security key according to the identifier of the encryption algorithm and the access layer key K gNB , deriving a user plane encryption key Kup-enc' with a length of 256 bits; the terminal activating security protection with the network side device according to the target security algorithm and the security key, including: the terminal activating user plane encryption with the RAN according to the encryption algorithm and the Kup-enc'.
[0096] In one embodiment, the UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives the security key according to the identifier of the target security algorithm in the authenticated encryption mode and the access layer key K gNB , deriving a user plane encryption key Kup-enc' with a length of 256 bits; the terminal activating security protection with the network side device according to the target security algorithm and the security key, including: the terminal activating user plane encryption with the RAN according to the target security algorithm in authenticated encryption mode and the user plane encryption key Kup-enc'.
[0097] For example, if RRC uses the 256-bit AES authenticated encryption mode, the terminal activates user plane encryption with the RAN according to the 256-bit AES encryption algorithm.
[0098] In one embodiment, the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm includes an integrity protection algorithm with a packet length of 256 bits; the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives a security key according to the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the terminal activating security protection with the network side device according to the target security algorithm and the security key, including: the terminal activating user plane integrity protection with the RAN according to the integrity protection algorithm and the Kup-int'.
[0099] In one embodiment, the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; the terminal derives a security key according to the identifier of the target security algorithm, including: the terminal derives the security key according to the identifier of the target security algorithm in the authenticated encryption mode and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the terminal activating security protection with the network side device according to the target security algorithm and the security key, including: the terminal activating user plane integrity protection with the RAN according to the target security algorithm in authenticated encryption mode and the user plane integrity protection key Kup-int'.
[0100] For example, if RRC uses the 256-bit SNOW 5G authentication encryption mode, the terminal activates user plane integrity protection with the RAN according to the 256-bit SNOW 5G integrity protection algorithm.
[0101] In one embodiment, the identifier of the target security algorithm used for UP key derivation and UP security protection is obtained by the terminal according to the AS SMC message or the RRC reconfiguration message. The RAN may indicate the target security algorithm to the terminal through the AS SMC message, and the target security algorithm may be used for deriving RRC keys and RRC security protection; and also for UP key derivation and UP security protection; or the RAN may indicate the target security algorithm to the terminal through the AS SMC message, and the target security algorithm may be used for deriving RRC keys and RRC security protection; and the RAN may indicate the target security algorithm to the terminal through the RRC reconfiguration message, and the target security algorithm may be used for UP key derivation and UP security protection, wherein the target security algorithm indicated by the AS SMC message may be the same as or different from the target security algorithm indicated by the RRC reconfiguration message.
[0102] In one example, the identifier of the target security algorithm used for UP key derivation and UP security protection is obtained by the terminal according to the RRC reconfiguration message. This embodiment indicates the corresponding target security algorithm through the AS SMC message and the RRC reconfiguration message respectively, and can decouple the target security algorithm related to RRC security protection and user plane protection, and the encryption method is more flexible.
[0103] In one embodiment, in an embodiment in which the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, or in an embodiment in which the UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, the method further includes at least one of the following: 1) the terminal enables RRC encryption according to the radio access control encryption key Krrc-enc' and the encryption algorithm corresponding to the target security algorithm in the authentication encryption mode; 2) the terminal enables RRC integrity protection according to the radio access control integrity protection key Krrc-int' and the integrity protection algorithm corresponding to the target security algorithm in the authentication encryption mode.
[0104] To illustrate the method for activating security provided by the embodiment of the present application in detail, a specific embodiment will be described below. Figure 3 As shown, this embodiment includes the following steps. Figure 3 The relevant description can be used as Figure 2 Further explanation of the steps involved.
[0105] Step 1: The UE sends a Registration Request message to the AMF. The Registration Request message includes the UE security capabilities, which indicate the security algorithms supported by the UE and include both a 128-bit algorithm identifier and a 256-bit algorithm identifier. The UE security capabilities may include NR UE security capabilities, LTE UE security capabilities, etc.
[0106] The NR UE security capabilities are shown in Table 1.
[0107] Among them, 5G-EA0 can indicate a null encryption algorithm, and 5G-IA0 can indicate a null integrity algorithm.
[0108] 5G-EA1 can indicate the 128-bit SNOW-3G encryption algorithm, and 5G-IA1 can indicate the 128-bit SNOW-3G integrity algorithm.
[0109] 5G-EA2 can indicate the 128-bit AES encryption algorithm, and 5G-IA2 can indicate the 128-bit AES integrity algorithm.
[0110] 5G-EA3 can indicate the 128-bit ZUC encryption algorithm, and 5G-IA3 can indicate the 128-bit ZUC integrity algorithm.
[0111] 5G-EA4 can indicate the 256-bit SNOW-5G encryption algorithm, and 5G-IA4 can indicate the 256-bit SNOW-5G integrity algorithm.
[0112] 5G-EA5 can indicate the 256-bit AES encryption algorithm, and 5G-IA5 can indicate the 256-bit AES integrity algorithm.
[0113] 5G-EA6 can indicate the 256-bit ZUC encryption algorithm, and 5G-IA6 can indicate the 256-bit ZUC integrity algorithm.
[0114] Table 1 UE security capability information element
[0115]
[0116] Optionally, if the NEA and the corresponding NIA appear at the same time, it may implicitly indicate that the UE supports the authenticated encryption mode, that is, the UE supports the authenticated encryption with associated data (AEAD) mode for the algorithm, which is an encryption form that uses a single key to achieve both confidentiality and integrity.
[0117] Optionally, an additional authentication encryption mode support indication (e.g., the three reserved bits in byte 7) may be introduced into the UE security capability to indicate whether the UE supports the authentication encryption mode for a certain algorithm, such as whether the UE supports the authentication encryption mode for NEA4 (i.e., SNOW-5G). For example, the eighth bit of byte 7 is named NEC4 to represent the authentication encryption algorithm of SNOW 5G, the seventh bit of byte 7 is named NEC5 to represent the authentication encryption algorithm of AES, and the sixth bit of byte 7 is named NEC6 to represent the authentication encryption algorithm of ZUC.
[0118] Optionally, an additional authentication encryption mode support indication (such as the reserved 1 bit in byte 7 above) can be introduced into the UE security capability to indicate whether the UE supports authentication encryption mode for all algorithms, such as whether it supports authentication encryption mode of SNOW-5G, AES, and ZUC.
[0119] Step 2: AMF and UE perform the main authentication process. After completing the main authentication process, both UE and AMF obtain the key Kamf.
[0120] For example, the main authentication process performed by the AMF and the UE may refer to Section 6.1 of 3GPP TS 33.501.
[0121] Step 3: AMF selects a security algorithm based on the UE security capabilities and the pre-configured algorithm priority list (assuming a 256-bit algorithm (e.g. 5G-EA4 / 5G-IA4, 5G-EA5 / 5G-IA5, 5G-EA6 / 5G-IA6)) is selected.
[0122] Optionally, the algorithm priority list also includes security algorithms using authenticated encryption mode. The AMF then needs to select whether to use the security algorithm in authenticated encryption mode based on the authenticated encryption mode indication or implicit indication in the UE security capability. For example, the algorithm priority list is Algorithm 4 with authenticated encryption > Algorithm 4.
[0123] For example, if the UE security capability supports algorithms 1, 2, 3, and 4, the authenticated encryption mode of algorithm 3 and the authenticated encryption mode of algorithm 4, and the algorithm priority list is authenticated encryption mode of algorithm 4 > authenticated encryption mode of algorithm 4 > authenticated encryption mode of algorithm 3 > 2 > 1, then the AMF will ultimately select the authenticated encryption mode of algorithm 4.
[0124] Step 4: If the AMF selects a 256-bit encryption algorithm and a 256-bit integrity protection algorithm, the AMF derives the 256-bit keys Knas-enc' and Knas-int' from Kamf and skips using the truncation function. The truncation function directly takes the most significant 128 bits of the 256-bit input as output.
[0125] For example, in related art, if the AMF selects a 128-bit encryption algorithm, the AMF may input Kamf, the algorithm type distinction (the value of the algorithm type distinction is 0x01, represented as N-NAS-enc-alg), and the algorithm identifier (the identifier of the selected encryption algorithm) into the KDF to obtain a 256-bit output, and then input the output into the truncation function, taking the highest 128 bits of the 256-bit output as the 128-bit NAS encryption key Knas-enc. If the AMF selects a 128-bit integrity protection algorithm, the AMF may input Kamf, the algorithm type distinction (the value of the algorithm type distinction is 0x02, represented as N-NAS-int-alg), and the algorithm identifier (the identifier of the selected integrity protection algorithm) into the KDF to obtain a 256-bit output, and then input the output into the truncation function, taking the highest 128 bits of the 256-bit output as the 128-bit NAS integrity protection key Knas-int'.
[0126] For example, if the AMF selects a 256-bit encryption algorithm, the AMF may input Kamf, the algorithm type distinction (the value of the algorithm type distinction is 0x01, represented as N-NAS-enc-alg) and the algorithm identifier (the identifier of the selected encryption algorithm) into the KDF to obtain a 256-bit output, skip the use of the truncation function, and use the output as the 256-bit NAS encryption key Knas-enc'. If the AMF selects a 256-bit integrity protection algorithm, the AMF may input Kamf, the algorithm type distinction (the value of the algorithm type distinction is 0x02, represented as N-NAS-int-alg) and the algorithm identifier (the identifier of the selected integrity protection algorithm) into the KDF to obtain a 256-bit output, skip the use of the truncation function, and use the output as the 256-bit NAS integrity protection key Knas-int'.
[0127] Among them, when the above algorithm identifier indicates the encryption algorithm, its set value can be 00000001 for 128-NEA1, 00000002 for 128-NEA2, 00000003 for 128-NEA3, 00000004 for 256-NEA4, 00000005 for 256-NEA5, and 00000006 for 256-NEA6.
[0128] Among them, when the above algorithm identifier indicates the integrity protection algorithm, its set value can be 00000001 representing 128-NIA1, 00000002 representing 128-NIA2, 00000003 representing 128-NIA3, 00000004 representing 256-NIA4, 00000005 representing 256-NIA5, and 00000006 representing 256-NIA6.
[0129] It can be seen that after selecting a 256-bit security algorithm, deducing the key and skipping the truncation function can make the generated key meet the key length requirement of the 256-bit algorithm.
[0130] AMF uses Knas-enc' and the selected 256 encryption algorithms to enable NAS encryption, and AMF uses Knas-int' and the selected 256 integrity protection algorithms to enable NAS integrity protection.
[0131] Optionally, if the AMF selects the 256-bit security algorithm in authenticated encryption mode, the AMF derives the 256-bit key Knas' from Kamf in the following two ways:
[0132] Option 1: The AMF derives a new key Knas' directly from Kamf. Optionally, the AMF sets the algorithm type distinction to a new value to indicate the use of a NAS encryption or integrity protection method using an authenticated encryption algorithm type, hereinafter referred to as the authenticated encryption algorithm type distinction. For example, 0x07 is used to indicate the NAS authenticated encryption method, which can be expressed as N-NAS-AEAD-alg or N-NAS-AE-alg. Optionally, the AMF sets the algorithm identifier to the selected algorithm. For example, the AMF sets the lower 2 bits of the reserved 4 most significant bits to 01 (for example, when 5G-NA is 256-NEA4 and 5G-IA is 256-NIA4, it is set to 00010100 (i.e., 0x14); when 5G-NA is 256-NEA5 and 5G-IA is 256-NIA5, it is set to 00010101 (i.e., 0x15); when 5G-NA is 256-NEA6 and 5G-IA is 256-NIA6, it is set to 00010110 (i.e., 0x16)). The AMF derives a single key Knas' based on Kamf, the authentication and encryption algorithm type, and the algorithm identifier.
[0133] Method 2: The AMF generates Knas' from Knas-enc' and Knas-int'. The AMF may XOR Knas-enc' with Knas-int' to obtain Knas'. Alternatively, the AMF may input Knas-enc' and Knas-int' into a Key Derivation Function (KDF) to obtain Knas'.
[0134] AMF can use Knas' and the selected 256-bit algorithm in authenticated encryption mode to enable NAS encryption and integrity protection at the same time.
[0135] By setting the input parameters for deriving 256-bit keys to different values from those for deriving 128-bit keys, the keys used by different algorithms can be isolated from each other, preventing the leakage of a 128-bit key from compromising the security strength of the 256-bit key.
[0136] Step 5: The AMF sends a NAS Security Mode Command (SMC) to the UE. The NAS SMC message includes the selected 256-bit algorithm and, optionally, an authenticated encryption mode indication, indicating whether to use the authenticated encryption mode with the selected 256-bit algorithm.
[0137] One possible approach is that the authentication encryption mode indication is also a security algorithm identifier, and the authentication encryption mode indication can be a value of the selected 256-bit algorithm.
[0138] Step 6: If the selected algorithm is a 256-bit encryption algorithm and a 256-bit integrity protection algorithm, the UE derives the 256-bit keys Knas-enc' and Knas-int' from Kamf based on the selected 256-bit algorithm and skips using the truncation function. (In the related art, if the selected algorithm is a 128-bit encryption algorithm and a 128-bit integrity protection algorithm, the UE first derives the 256-bit keys Knas-enc' and Knas-int' from Kamf and then uses the truncation function to truncate them to 128-bit Knas-enc' and Knas-int'.) The UE uses Knas-enc' and the selected 256-bit encryption algorithm to enable NAS encryption. The UE uses Knas-int' and the selected 256-bit integrity protection algorithm to enable NAS integrity protection.
[0139] Optionally, if the authenticated encryption mode indicates the authenticated encryption mode using the selected algorithm, the UE derives the 256-bit key Knas' from Kamf.
[0140] The UE can use Knas' and the selected 256-bit algorithm in authenticated encryption mode to enable NAS encryption and integrity protection at the same time.
[0141] The UE's key derivation method is the same as that of the AMF, as shown in step 4.
[0142] Step 7: The UE responds to the AMF with NAS Security Mode Complete (SMP).
[0143] Step 8: The AMF also sends an N2 message to the RAN. The N2 message contains the UE security capabilities and KgNB. KgNB is derived from the KgNB.
[0144] Step 9: The RAN selects a security algorithm based on the UE security capabilities and the pre-configured algorithm priority list (assuming a 256-bit algorithm is selected).
[0145] The process of RAN selecting a security algorithm is similar to the process of AMF selecting a security algorithm in step 3.
[0146] Optionally, the algorithm priority list further includes security algorithms using the authenticated encryption mode. The RAN then needs to select whether to use the security algorithm using the authenticated encryption mode based on the authenticated encryption mode indication or implicit indication in the UE security capability.
[0147] Step 10: If the RAN selects a 256-bit encryption algorithm and a 256-bit integrity protection algorithm, the RAN derives the 256-bit keys Krrc-enc' and Krrc-int' from the KgNB and skips using the truncation function. (In related art, if the RAN selects a 128-bit algorithm, the RAN first derives the 256-bit keys Krrc-enc and Krrc-int from the KgNB and then uses the truncation function to truncate them to 128-bit Krrc-enc and Krrc-int.) The RAN uses Krrc-enc' and the selected 256-bit encryption algorithm to enable RRC encryption (i.e., enable SRB encryption protection). The RAN uses Krrc-int' and the selected 256-bit integrity protection algorithm to enable RRC integrity protection (i.e., enable SRB integrity protection).
[0148] For example, in related art, if the RAN selects a 128-bit encryption algorithm, the RAN may input KgNB, the algorithm type distinction (the algorithm type distinction value is 0x03, represented as N-RRC-enc-alg), and the algorithm identifier (the identifier of the selected encryption algorithm) into the KDF to obtain a 256-bit output. This output is then input into a truncation function, and the highest 128 bits of the 256-bit output are taken as the 128-bit RRC encryption key Krrc-enc. If the RAN selects a 128-bit integrity protection algorithm, the RAN may input KgNB, the algorithm type distinction (the algorithm type distinction value is 0x04, represented as N-RRC-int-alg), and the algorithm identifier (the identifier of the selected integrity protection algorithm) into the KDF to obtain a 256-bit output. This output is then input into a truncation function, and the highest 128 bits of the 256-bit output are taken as the 128-bit RRC integrity protection key Krrc-int'.
[0149] For example, if the RAN selects a 256-bit encryption algorithm, the RAN may input KgNB, the algorithm type distinction (the value of the algorithm type distinction is 0x03, represented as N-RRC-enc-alg), and the algorithm identifier (the identifier of the selected encryption algorithm) into the KDF to obtain a 256-bit output, skip the use of the truncation function, and use the output as the 256-bit RRC encryption key Krrc-enc'. If the RAN selects a 256-bit integrity protection algorithm, the RAN may input KgNB, the algorithm type distinction (the value of the algorithm type distinction is 0x04, represented as N-RRC-int-alg), and the algorithm identifier (the identifier of the selected integrity protection algorithm) into the KDF to obtain a 256-bit output, skip the use of the truncation function, and use the output as the 256-bit RRC integrity protection key Krrc-int'.
[0150] Among them, when the above algorithm identifier indicates the encryption algorithm, its set value can be 00000001 for 128-NEA1, 00000002 for 128-NEA2, 00000003 for 128-NEA3, 00000004 for 256-NEA4, 00000005 for 256-NEA5, and 00000006 for 256-NEA6.
[0151] Among them, when the above algorithm identifier indicates the integrity protection algorithm, its set value can be 00000001 representing 128-NIA1, 00000002 representing 128-NIA2, 00000003 representing 128-NIA3, 00000004 representing 256-NIA4, 00000005 representing 256-NIA5, and 00000006 representing 256-NIA6.
[0152] Optionally, if the RAN selects the 256-bit security algorithm in authenticated encryption mode, the RAN derives the 256-bit key Krrc' from the KgNB in the following two ways:
[0153] Method 1: The RAN derives a new key, Krrc', directly from the KgNB. Optionally, the RAN sets the algorithm type distinction to a new value, indicating the RRC encryption or integrity protection method using the authentication encryption algorithm type, hereinafter referred to as the authentication encryption algorithm type distinction. For example, 0x10 is used to indicate the RRC authentication encryption method, which can be expressed as N-RRC-AEAD-alg or N-RRC-AE-alg. Optionally, the RAN sets the algorithm identifier to the selected algorithm and sets the lowest two bits of the reserved highest four bits to 01 (for example, when 5G-NA is 256-NEA4 and 5G-IA is 256-NIA4, it is set to 00010100 (i.e., 0x14); when 5G-NA is 256-NEA5 and 5G-IA is 256-NIA5, it is set to 00010101 (i.e., 0x15); when 5G-NA is 256-NEA6 and 5G-IA is 256-NIA6, it is set to 00010110 (i.e., 0x16)). The RAN derives a single key Krrc' based on the KgNB, the authentication and encryption algorithm type, and the algorithm identifier.
[0154] Method 2: The RAN generates Krrc' from Krrc-enc' and Krrc-int'. The RAN can XOR Krrc-enc' with Krrc-int' to obtain Krrc'. Alternatively, the RAN can input Krrc-enc' and Krrc-int' into a key derivation function (KDF) to obtain Krrc'.
[0155] The RAN can use Krrc' and the selected 256-bit authenticated encryption mode to enable RRC encryption and integrity protection at the same time.
[0156] Step 11: The RAN sends an AS Security Mode Command (SMC) to the UE. The AS SMC message includes the selected 256-bit algorithm and, optionally, an authenticated encryption mode indication, indicating whether to use the authenticated encryption mode of the selected 256-bit algorithm.
[0157] One possible approach is that the authentication encryption mode indication is also a security algorithm identifier, and the authentication encryption mode indication can be a value of the selected 256-bit algorithm.
[0158] Step 12: If the selected algorithm is a 256-bit encryption algorithm and a 256-bit integrity protection algorithm, the UE derives the 256-bit keys Krrc-enc' and Krrc-int' from the KgNB based on the selected 256-bit algorithm and skips using the truncation function. (In the related art, if the selected algorithm is a 128-bit encryption algorithm and a 128-bit integrity protection algorithm, the UE first derives the 256-bit keys Krrc-enc and Krrc-int from the KgNB and then uses the truncation function to truncate them to 128-bit Krrc-enc and Krrc-int.) The UE enables RRC encryption using Krrc-enc' and the selected 256-bit encryption algorithm. The UE enables RRC integrity protection using Krrc-int' and the selected 256-bit integrity protection algorithm.
[0159] Optionally, if the authenticated encryption mode indicates the authenticated encryption mode using the selected algorithm, the UE derives the 256-bit key Krrc' from KgNB.
[0160] The UE can use Krrc' and the selected 256-bit algorithm in authenticated encryption mode to enable RRC encryption and integrity protection at the same time.
[0161] The key derivation method of the UE is the same as that of the RAN, as shown in step 10.
[0162] Step 13: The UE responds to the RAN with a message indicating that the AS security mode is complete (SMP).
[0163] Step 14: The UE sends a PDU session establishment request to the SMF through the AMF to request the establishment of a PDU session.
[0164] Step 15: The SMF sends the UP security policy to the RAN via the AMF. The UP security policy includes the UP encryption policy and the UP integrity protection policy. The UP encryption policy instructs the RAN whether to enable user plane confidentiality protection. The UP integrity protection policy instructs the RAN whether to enable user plane integrity protection. There are three options: required, preferred, and not needed.
[0165] When the UP encryption policy indicates that it must be enabled, the UP security activation indication is to enable user plane encryption.
[0166] When the UP encryption policy indication is not enabled, the UP security activation indication is to disable user plane encryption.
[0167] When the UP encryption policy indicates that it is recommended to enable, the RAN can decide whether to enable user plane encryption, that is, the UP security activation indication is whether to enable or not enable user plane encryption.
[0168] When the UP integrity protection policy indicates that it must be enabled, the UP security activation indication is to enable user plane integrity protection.
[0169] When the UP integrity protection policy indication is not enabled, the UP security activation indication is to disable the user plane integrity protection policy.
[0170] When the UP integrity protection policy indicates that it is recommended to be enabled, the RAN can decide whether to enable the user plane integrity protection policy, that is, whether the UP security activation indication is to enable or not enable the user plane integrity protection policy.
[0171] Step 16: The RAN determines whether to enable user plane protection (confidentiality and integrity protection) based on the UP security policy. There are four possible scenarios: a) both encryption and integrity protection are enabled; b) encryption is enabled but integrity protection is disabled; c) encryption is disabled but integrity protection is enabled; and d) neither encryption nor integrity protection is enabled.
[0172] For case a):
[0173] If the RAN selected a 256-bit encryption algorithm and a 256-bit integrity protection algorithm in step 10, the RAN derives the 256-bit keys Kup-enc' and Kup-int' from the KgNB and skips using the truncation function. (In related art, if the RAN selected a 128-bit algorithm, the RAN first derives the 256-bit keys Kup-enc and Kup-int from the KgNB and then uses the truncation function to truncate them to 128-bit Kup-enc and Kup-int.) The RAN uses Kup-enc' and the selected 256-bit encryption algorithm to enable UP encryption. The RAN uses Kup-int' and the selected 256-bit integrity protection algorithm to enable UP integrity protection.
[0174] For example, in related art, if the RAN selects a 128-bit encryption algorithm, the RAN may input KgNB, the algorithm type distinction (the value of the algorithm type distinction is 0x05, represented as N-UP-enc-alg), and the algorithm identifier (the identifier of the selected encryption algorithm) into the KDF to obtain a 256-bit output. This output is then input into a truncation function, and the highest 128 bits of the 256-bit output are taken as the 128-bit user plane encryption key Kup-enc. If the RAN selects a 128-bit integrity protection algorithm, the RAN may input KgNB, the algorithm type distinction (the value of the algorithm type distinction is 0x06, represented as N-UP-int-alg), and the algorithm identifier (the identifier of the selected integrity protection algorithm) into the KDF to obtain a 256-bit output. This output is then input into a truncation function, and the highest 128 bits of the 256-bit output are taken as the 128-bit user plane integrity protection key Kup-int'.
[0175] For example, if the RAN selects a 256-bit encryption algorithm, the RAN can input KgNB, algorithm type distinction (the value of the algorithm type distinction is 0x05, represented as N-UP-enc-alg), and algorithm identifier (the identifier of the selected encryption algorithm) into the KDF to obtain a 256-bit output, skip the use of the truncation function, and use this output as the 256-bit user plane encryption key Kup-enc'. If the RAN selects a 256-bit integrity protection algorithm, the RAN can input KgNB, algorithm type distinction (the value of the algorithm type distinction is 0x06, represented as N-UP-int-alg), and algorithm identifier (the identifier of the selected integrity protection algorithm) into the KDF to obtain a 256-bit output, skip the use of the truncation function, and use this output as the 256-bit user plane integrity protection key Krrc-int'.
[0176] Among them, when the above algorithm identifier indicates the encryption algorithm, its set value can be 00000001 for 128-NEA1, 00000002 for 128-NEA2, 00000003 for 128-NEA3, 00000004 for 256-NEA4, 00000005 for 256-NEA5, and 00000006 for 256-NEA6.
[0177] Among them, when the above algorithm identifier indicates the integrity protection algorithm, its set value can be 00000001 representing 128-NIA1, 00000002 representing 128-NIA2, 00000003 representing 128-NIA3, 00000004 representing 256-NIA4, 00000005 representing 256-NIA5, and 00000006 representing 256-NIA6.
[0178] Optionally, if the authentication encryption mode is selected in step 10 in the RAN, the RAN derives the 256-bit key Kup' from the KgNB in the following two ways:
[0179] Method 1: The RAN directly derives a new key, Kup', from the KgNB. Optionally, the RAN sets the algorithm type distinction to a new value, indicating the use of an UP encryption or integrity protection method using an authenticated encryption algorithm type, hereinafter referred to as the authenticated encryption algorithm type distinction. For example, 0x11 is used to indicate the UP authenticated encryption method, which can be expressed as N-UP-AEAD-alg or N-UP-AE-alg. Optionally, the RAN sets the algorithm identifier to the selected algorithm and sets the lowest two bits of the reserved highest four bits to 01 (for example, when 5G-NA is 256-NEA4 and 5G-IA is 256-NIA4, the value is set to 00010100 (i.e., 0x14); when 5G-NA is 256-NEA5 and 5G-IA is 256-NIA5, the value is set to 00010101 (i.e., 0x15); and when 5G-NA is 256-NEA6 and 5G-IA is 256-NIA6, the value is set to 00010110 (i.e., 0x16)). The RAN derives a single key Kup' based on KgNB, the authentication and encryption algorithm type, and the algorithm identifier.
[0180] Method 2: The RAN generates Kup' from Kup-enc' and Kup-int'. The RAN can XOR Kup-enc' with Kup-int' to obtain Kup'. Alternatively, the RAN can input Kup-enc' and Kup-int' into a key derivation function (KDF) to obtain Kup'.
[0181] RAN can use Kup' and the selected 256-bit algorithm in authenticated encryption mode to enable UP encryption and integrity protection at the same time.
[0182] It should be noted that the Kup' key derivation step may also be performed first in step 10, and in this case, it may not be performed here.
[0183] For case b):
[0184] Optionally, if the RAN selected a 256-bit encryption algorithm in step 10, the RAN derives the 256-bit key Kup-enc' from the KgNB and skips using the truncation function. (If derivation has already occurred in step 10, this step can be skipped.) The RAN then uses Kup-enc' and the selected 256-bit encryption algorithm to enable UP encryption.
[0185] Optionally, if the RAN selects the 256-bit algorithm in the authenticated encryption mode in step 10, the RAN uses Kup-enc' and the 256-bit encryption algorithm corresponding to the 256-bit algorithm in the authenticated encryption mode to enable UP encryption.
[0186] For example, if the RAN selects the 256-bit ZUC algorithm (denoted as NCA5) in authenticated encryption mode in step 10, the RAN uses Kup-enc' and the 256-bit ZUC encryption algorithm (denoted as NEA5) to enable UP encryption.
[0187] Optionally, the RAN may reselect an encryption algorithm based on the algorithm priority list, but skip the algorithm for authenticated encryption mode, and enable UP encryption using Kup-enc' and the selected 256-bit encryption algorithm.
[0188] Optionally, the RAN may enable RRC encryption based on Krrc-enc' and the 256-bit encryption algorithm corresponding to the 256-bit algorithm in authenticated encryption mode, and enable RRC integrity protection based on Krrc-int' and the 256-bit integrity protection algorithm corresponding to the 256-bit algorithm in authenticated encryption mode. These two keys may be newly generated.
[0189] For case c), the RAN action is similar to case b), except that encryption is changed to integrity protection.
[0190] Optionally, if the RAN selected a 256-bit integrity protection algorithm in step 10, the RAN derives the 256-bit key Kup-int' from the KgNB and skips using the truncation function. (If step 10 has already been derived, this step can be skipped.) The RAN uses Kup-int' and the selected 256-bit integrity protection algorithm to enable UP integrity protection.
[0191] Optionally, if the RAN selects the 256-bit algorithm in the authenticated encryption mode in step 10, the RAN uses Kup-int' and the 256 integrity protection algorithm corresponding to the 256-bit algorithm in the authenticated encryption mode to enable UP integrity protection.
[0192] For example, if the RAN selects the 256-bit ZUC algorithm (denoted as NCA5) in authenticated encryption mode in step 10, the RAN uses Kup-int' and the 256-bit ZUC integrity protection algorithm (denoted as NIA5) to enable UP integrity protection.
[0193] Optionally, the RAN may reselect the integrity protection algorithm based on the algorithm priority list, but skip the algorithm in the authenticated encryption mode, and enable UP integrity protection using Kup-int' and the selected 256 integrity protection algorithms.
[0194] Optionally, the RAN may enable RRC encryption based on Krrc-enc' and the 256-bit encryption algorithm corresponding to the 256-bit algorithm in authenticated encryption mode, and enable RRC integrity protection based on Krrc-int' and the 256-bit integrity protection algorithm corresponding to the 256-bit algorithm in authenticated encryption mode. These two keys may be regenerated.
[0195] For case d), the RAN does not need to perform key derivation and security activation on the UP plane.
[0196] Step 17: The RAN sends an RRC reconfiguration message to the UE, including an UP security activation indication. The UP security activation indication includes an UP cipher activation indication and an UP integrity protection activation indication. The UP cipher activation indication indicates whether the UE has enabled UP security. The UP integrity protection activation indication indicates whether the UE has enabled UP integrity protection. The UP security activation indication can be either explicit or implicit. An explicit indication, for example, uses a single bit, with 1 indicating activation and 0 indicating inactivation. Alternatively, the UP security activation indication can be implicit, with a carry indication indicating activation and an omission indicating inactivation, or vice versa.
[0197] Optionally, the RRC reconfiguration message further includes a selected security algorithm.
[0198] Step 18: The UE determines whether to enable protection (confidentiality and integrity protection) based on the UP security activation indication. There are four possible scenarios: scenario a) both encryption and integrity protection are enabled; scenario b) encryption is enabled but integrity protection is disabled; scenario c) encryption is disabled but integrity protection is enabled; and scenario d) neither encryption nor integrity protection is enabled.
[0199] For case a):
[0200] If the algorithm used in step 12 is a 256-bit encryption algorithm and a 256-bit integrity protection algorithm, the UE derives the 256-bit keys Kup-enc' and Kup-int' from the KgNB based on the selected 256-bit algorithm and skips using the truncation function. The UE uses Kup-enc' and the selected 256-bit encryption algorithm to enable UP encryption. The UE uses Kup-int' and the selected 256-bit integrity protection algorithm to enable UP integrity protection.
[0201] Optionally, if the algorithm used in the authenticated encryption mode is in step 12, the UE derives the 256-bit key Kup' from the KgNB in the same manner as in step 16. The UE can use Kup' and the selected 256-bit authenticated encryption mode to simultaneously enable UP encryption and integrity protection.
[0202] It should be noted that if the Kup' key derivation step can also be performed first in step 12, it may not be performed here.
[0203] For case b):
[0204] Optionally, if the UE uses a 256-bit encryption algorithm in step 12, the UE derives the 256-bit key Kup-enc' from the KgNB and skips using the truncation function. (If step 12 has already been derived, this step can be skipped.) The UE uses Kup-enc' and the selected 256-bit encryption algorithm to enable UP encryption.
[0205] Optionally, if the UE uses the 256-bit algorithm in the authenticated encryption mode in step 12, the UE uses Kup-enc' and the 256-bit encryption algorithm corresponding to the 256-bit algorithm in the authenticated encryption mode to enable UP encryption.
[0206] Optionally, the UE may generate Kup-enc' according to the security algorithm selected in RRC Reconfiguration and enable UP encryption.
[0207] Optionally, the UE may enable RRC encryption based on Krrc-enc' and the 256-bit encryption algorithm corresponding to the 256-bit algorithm in authenticated encryption mode, and enable RRC integrity protection based on Krrc-int' and the 256-bit integrity protection algorithm corresponding to the 256-bit algorithm in authenticated encryption mode. These two keys may be newly generated.
[0208] For case c), the UE action is similar to that of case b), except that encryption is changed to integrity protection.
[0209] Optionally, if the UE uses a 256-bit integrity protection algorithm in step 12, the UE derives the 256-bit key Kup-int' from the KgNB and skips using the truncation function. (If step 12 has already been derived, this step can be skipped.) The UE uses Kup-int' and the selected 256-bit integrity protection algorithm to enable UP integrity protection.
[0210] Optionally, if the UE uses the 256-bit algorithm in the authenticated encryption mode in step 12, the UE uses Kup-int' and the 256 integrity protection algorithm corresponding to the 256-bit algorithm in the authenticated encryption mode to enable UP integrity protection.
[0211] Optionally, the UE may generate Kup-int' according to the security algorithm selected in RRC Reconfiguration and enable UP integrity protection.
[0212] Optionally, the UE may enable RRC encryption based on Krrc-enc' and the 256-bit encryption algorithm corresponding to the 256-bit algorithm of the authentication encryption mode, and enable RRC integrity protection based on Krrc-int' and the 256-bit integrity protection algorithm corresponding to the 256-bit algorithm of the authentication encryption mode. These two keys may be regenerated.
[0213] For case d), the UE does not need to perform key derivation and security activation of the UP plane.
[0214] Step 19: The UE sends an RRC reconfiguration complete message to the RAN.
[0215] The various embodiments of the present application can be applied to 4G, 5G, and 6G networks, and can also be applied to mobility processes in these networks, such as location update registration, handover, re-establishment, inactive state to active state, dual connectivity, etc. This is because the essence of these processes is that the new network element obtains the security capabilities of the UE from the old network element and then selects a new algorithm based on the algorithm priority list.
[0216] Combination of the above Figure 2 The method for activating security according to the embodiment of the present application is described in detail. Figure 4 and Figure 5 The method for activating security according to another embodiment of the present application is described in detail. It can be understood that the interaction between the network side device and the terminal described in the network side device is the same as Figure 2 The descriptions on the terminal side in the methods shown are the same or corresponding, and to avoid repetition, the relevant descriptions are appropriately omitted.
[0217] Figure 4 This is a flowchart of a method for implementing activation security in an embodiment of the present application, which can be applied to access network equipment. Figure 4As shown, the method 400 includes the following steps.
[0218] S402: The access network device receives terminal security capability information from the terminal, where the terminal security capability information includes identifiers of security algorithms supported by the terminal, and the security algorithms include security algorithms with a packet length of 256 bits.
[0219] S404: The access network device selects a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list. The target security algorithm is one of the security algorithms supported by the terminal.
[0220] Optionally, the algorithm priority list also includes security algorithms using authenticated encryption mode. The access network device then needs to select whether to use the authenticated encryption mode security algorithm based on the authenticated encryption mode indication or implicit indication in the terminal security capability. For example, the algorithm priority list may have authenticated encryption > algorithm 4.
[0221] For example, if the terminal security capability supports algorithms 1, 2, 3, and 4, the authentication and encryption mode of algorithm 3 and the authentication and encryption mode of algorithm 4, and the algorithm priority list is authentication and encryption mode of algorithm 4 > authentication and encryption mode of algorithm 4 > authentication and encryption mode of algorithm 3 > 2 > 1, the access network device ultimately selects authentication and encryption mode of algorithm 4.
[0222] S406: The access network device derives a security key according to the identifier of the target security algorithm.
[0223] S408: The access network device activates security protection with the terminal according to the target security algorithm and the security key.
[0224] S410: The access network device sends the identifier of the target security algorithm to the terminal.
[0225] This embodiment does not limit the order of S410 , which may be after S406 and before S408 , or after S408 .
[0226] In an embodiment of the present application, after a 256-bit security algorithm is introduced on the network side, the terminal negotiates a target security algorithm with the network side device, generates a security key based on the target security algorithm, and activates corresponding security based on the security key and the target security algorithm to improve communication security.
[0227] Optionally, in one embodiment, the access network device derives a security key based on the identifier of the target security algorithm, including: when the packet length of the target security algorithm is 128 bits, the access network device derives a 256-bit first key based on the identifier of the target security algorithm; the access network device obtains the security key by inputting the first key into a truncation function; or, when the packet length of the target security algorithm is 256 bits, the access network device derives a 256-bit first key based on the identifier of the target security algorithm; the access network device skips the truncation function and uses the first key as the security key.
[0228] Optionally, in one embodiment, the terminal security capability information further includes first indication information, and the first indication information is used to indicate that the terminal supports the authentication encryption mode.
[0229] Optionally, in one embodiment, the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the access network device derives a security key according to the identifier of the target security algorithm, including: the access network device derives a security key according to the identifier of the encryption algorithm and the access layer key K gNB , derive the wireless access control encryption key Krrc-enc' with a length of 256 bits, and the access network device uses the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a radio access control integrity protection key Krrc-int' with a length of 256 bits; the access network device activates security protection with the terminal according to the target security algorithm and the security key, including: the access network device activates RRC encryption with the terminal according to the encryption algorithm and the Krrc-enc'; the access network device activates RRC integrity protection with the terminal according to the integrity protection algorithm and the Krrc-int'.
[0230] Optionally, in one embodiment, the algorithm priority list also includes a security algorithm using an authentication encryption mode, and the method also includes: the access network device determines third indication information based on the first indication information in the terminal security capability information, and the third indication information is used to indicate the use of the authentication encryption mode of the target security algorithm; the access network device sends the third indication information to the terminal.
[0231] Optionally, in one embodiment, the access network device derives a security key according to the identifier of the target security algorithm, including: the access network device derives a security key according to the access layer key K gNB, the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a third key Krrc' with a length of 256 bits; the access network device activates security protection with the terminal according to the target security algorithm and the security key, including: the access network device activates RRC encryption and integrity protection with the terminal according to the target security algorithm of the authentication encryption mode and the third key Krrc'.
[0232] Optionally, in one embodiment, the access network device derives a security key based on the identifier of the target security algorithm, including: the access network device derives a third key Krrc' with a length of 256 bits based on the wireless access control encryption key Krrc-enc' and the wireless access control integrity protection key Krrc-int'; the access network device activates security protection with the terminal based on the target security algorithm and the security key, including: the access network device activates RRC encryption and integrity protection with the terminal based on the target security algorithm of the authentication encryption mode and the third key Krrc'.
[0233] Optionally, in one embodiment, the method further includes: the access network device determining a UP security activation indication, where the UP security activation indication is used to indicate whether user plane encryption is enabled and whether user plane integrity protection is enabled. In this embodiment, the access network device may determine the UP security activation indication based on a UP security policy from the SMF.
[0234] Optionally, in one embodiment, the UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the access network device derives a security key according to the identifier of the target security algorithm, including: the access network device derives a security key according to the identifier of the encryption algorithm and the access layer key K gNB , derive the user plane encryption key Kup-enc' of length 256 bits, and the access network device uses the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the access network device activates security protection with the terminal according to the target security algorithm and the security key, including: the access network device activates user plane encryption with the terminal according to the encryption algorithm and Kup-enc'; the access network device activates user plane integrity protection with the terminal according to the integrity protection algorithm and Kup-int'.
[0235] Optionally, in one embodiment, the UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm used by the RRC uses an authenticated encryption mode; the access network device derives a security key according to the identifier of the target security algorithm, including: the access network device derives a security key according to the access layer key K gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a fourth key Kup' with a length of 256 bits; the access network device activates security protection with the terminal according to the target security algorithm and the security key, including: the access network device activates user plane encryption and user plane integrity protection with the terminal according to the target security algorithm in the authentication encryption mode and the fourth key Kup'.
[0236] Optionally, in one embodiment, the UP security activation indication is used to indicate the activation of user plane encryption and the activation of user plane integrity protection, and the target security algorithm used by the RRC uses an authenticated encryption mode; the access network device derives a security key based on the identifier of the target security algorithm, including: the access network device derives a single fourth key Kup' with a length of 256 bits based on the user plane encryption key Kup-enc' and the user plane integrity protection key Kup-int'; the access network device activates security protection with the terminal based on the target security algorithm and the security key, including: the access network device activates user plane encryption and user plane integrity protection with the terminal based on the target security algorithm in the authenticated encryption mode and the fourth key Kup'.
[0237] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits; the access network device derives a security key according to the identifier of the target security algorithm, including: the access network device derives a security key according to the identifier of the encryption algorithm and the access layer key K gNB , deriving a user plane encryption key Kup-enc' with a length of 256 bits; the access network device activates security protection with the terminal according to the target security algorithm and the security key, including: the access network device activates user plane encryption with the terminal according to the encryption algorithm and the Kup-enc'.
[0238] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; the access network device derives a security key according to the identifier of the target security algorithm, including: the access network device derives a security key according to the identifier of the target security algorithm in the authenticated encryption mode and the access layer key K gNB , deriving a user plane encryption key Kup-enc' with a length of 256 bits; the access network device activates security protection with the terminal according to the target security algorithm and the security key, including: the access network device activates user plane encryption with the terminal according to the target security algorithm of the authentication encryption mode and the user plane encryption key Kup-enc'.
[0239] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm includes an integrity protection algorithm with a packet length of 256 bits; the access network device derives a security key according to the identifier of the target security algorithm, including: the access network device derives a security key according to the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the access network device activates security protection with the terminal according to the target security algorithm and the security key, including: the access network device activates user plane integrity protection with the terminal according to the integrity protection algorithm and the Kup-int'.
[0240] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; the access network device derives a security key according to the identifier of the target security algorithm, including: the access network device derives a security key according to the identifier of the target security algorithm in the authenticated encryption mode and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the access network device activates security protection with the terminal according to the target security algorithm and the security key, including: the access network device activates user plane integrity protection with the terminal according to the target security algorithm of the authenticated encryption mode and the user plane integrity protection key Kup-int'.
[0241] Optionally, in an embodiment, the method further comprises at least one of the following: starting RRC encryption by the access network device according to a radio access control encryption key Krrc-enc', an encryption algorithm corresponding to the target security algorithm of the authentication encryption mode; starting RRC integrity protection by the access network device according to a radio access control integrity protection key Krrc-int', an integrity protection algorithm corresponding to the target security algorithm of the authentication encryption mode.
[0242] Figure 5 is a method of activating security implementation flow diagram of the embodiment of the application, which can be applied to a core network device, such as AMF. As shown in the figure, the method 500 comprises the following steps. Figure 5
[0243] S502: The core network device receives terminal security capability information sent by a terminal, wherein the terminal security capability information comprises an identifier of a security algorithm supported by the terminal, and the security algorithm comprises a security algorithm with a packet length of 256 bits.
[0244] S504: The core network device selects a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, and the target security algorithm is one of the security algorithms supported by the terminal.
[0245] Optionally, the algorithm priority list further contains a security algorithm using an authentication encryption mode. Then the core network device needs to additionally select whether to use the security algorithm using the authentication encryption mode according to an authentication encryption mode indication or an implicit indication in the terminal security capability. For example, the algorithm priority list is algorithm 4 authentication encryption > algorithm 4.
[0246] For example, the terminal security capability supports algorithms 1, 2, 3 and 4, the authentication encryption mode of 3, the authentication encryption mode of 4, and the algorithm priority list is algorithm 4 authentication encryption mode > algorithm 4 > 3 authentication encryption mode > 2 > 1. Then the core network device finally selects algorithm 4 authentication encryption mode.
[0247] S506: The core network device derives a security key according to the identifier of the target security algorithm.
[0248] S508: The core network device activates security protection with the terminal according to the target security algorithm and the security key.
[0249] S510: The core network device sends the identifier of the target security algorithm to the terminal.
[0250] The embodiment does not limit the sequence of S510, which can be after S506 and before S508, or also after S508.
[0251] The method for activating security provided in the embodiment of the present application introduces a 256-bit security algorithm on the network side. The terminal negotiates the target security algorithm with the network side device, generates a security key based on the target security algorithm, and activates the corresponding security based on the security key and the target security algorithm to improve communication security.
[0252] Optionally, in one embodiment, the core network device derives a security key based on the identifier of the target security algorithm, including: when the packet length of the target security algorithm is 128 bits, the core network device derives a 256-bit first key based on the identifier of the target security algorithm; the core network device obtains the security key by inputting the first key into a truncation function; or, when the packet length of the target security algorithm is 256 bits, the core network device derives a 256-bit first key based on the identifier of the target security algorithm; the core network device skips the truncation function and uses the first key as the security key.
[0253] Optionally, in one embodiment, the terminal security capability information further includes first indication information, and the first indication information is used to indicate that the terminal supports the authentication encryption mode.
[0254] Optionally, in one embodiment, the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the core network device derives a security key based on the identifier of the target security algorithm, including: the core network device derives a non-access layer encryption key Knas-enc' with a length of 256 bits based on the identifier of the encryption algorithm and the access and mobility management function key Kamf, and the core network device derives a non-access layer integrity protection key Knas-int' with a length of 256 bits based on the identifier of the integrity protection algorithm and the access and mobility management function key Kamf; the core network device activates security protection with the terminal based on the target security algorithm and the security key, including: the core network device activates NAS encryption with the terminal based on the encryption algorithm and Knas-enc'; the core network device activates NAS integrity protection with the terminal based on the integrity protection algorithm and Knas-int'.
[0255] Optionally, in one embodiment, the algorithm priority list also includes a security algorithm using an authenticated encryption mode, and the method further includes: the core network device determines second indication information based on the first indication information in the terminal security capability information, the second indication information being used to indicate the use of the authenticated encryption mode of the target security algorithm; the core network device sends the second indication information to the terminal.
[0256] Optionally, in one embodiment, the core network device derives a security key based on the identifier of the target security algorithm, including: the core network device derives a second key Knas' with a length of 256 bits based on the access and mobility management function key Kamf, the authentication encryption algorithm type difference of the target security algorithm and the algorithm identifier; the core network device activates security protection with the terminal based on the target security algorithm and the security key, including: the core network device activates NAS encryption and integrity protection with the terminal based on the target security algorithm of the authentication encryption mode and the second key Knas'.
[0257] Optionally, in one embodiment, the core network device derives a security key based on the identifier of the target security algorithm, including: the core network device derives a second key Knas' with a length of 256 bits based on the non-access layer encryption key Knas-enc' and the non-access layer integrity protection key Knas-int'; the core network device activates security protection with the terminal based on the target security algorithm and the security key, including: the core network device activates NAS encryption and integrity protection with the terminal based on the target security algorithm of the authentication encryption mode and the second key Knas'.
[0258] The method for activating security provided in the embodiment of the present application can be executed by a device for activating security. In the embodiment of the present application, the device for activating security provided in the embodiment of the present application is described by taking the method for activating security performed by the device for activating security as an example.
[0259] Figure 6 FIG. 1 is a schematic diagram of a structure of a device for activating security according to an embodiment of the present application, which can be applied to terminals in other embodiments. Figure 6 As shown, the apparatus 600 includes the following modules.
[0260] The communication module 602 is configured to send terminal security capability information to a network-side device, where the terminal security capability information includes identifiers of security algorithms supported by the terminal, and the security algorithms include security algorithms with a packet length of 256 bits.
[0261] The communication module 602 is configured to receive an identifier of a target security algorithm sent by the network-side device, where the target security algorithm is one of the security algorithms supported by the terminal.
[0262] The communication module 602 is configured to derive a security key according to the identifier of the target security algorithm.
[0263] The communication module 602 is configured to activate security protection with the network-side device according to the target security algorithm and the security key.
[0264] In an embodiment of the present application, after a 256-bit security algorithm is introduced on the network side, the terminal negotiates a target security algorithm with the network side device, generates a security key based on the target security algorithm, and activates corresponding security based on the security key and the target security algorithm to improve communication security.
[0265] Optionally, in one embodiment, the communication module 602 is used to derive a 256-bit first key based on the identifier of the target security algorithm when the packet length of the target security algorithm is 128 bits; obtain the security key by inputting the first key into a truncation function; or, the communication module 602 is used to derive a 256-bit first key based on the identifier of the target security algorithm when the packet length of the target security algorithm is 256 bits; skip the truncation function and use the first key as the security key.
[0266] Optionally, in one embodiment, the terminal security capability information further includes first indication information, and the first indication information is used to indicate that the terminal supports the authentication encryption mode.
[0267] Optionally, in one embodiment, the network side device is an AMF; wherein the communication module 602 is used to send a registration request message to the AMF, and the registration request message includes the terminal security capability information; the communication module 602 is used to receive a non-access layer security mode command NAS SMC message sent by the AMF, and the NAS SMC message includes an identifier of the target security algorithm, and the NAS SMC message is used to activate NAS security.
[0268] Optionally, in one embodiment, the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the communication module 602 is used to derive a non-access layer encryption key Knas-enc' with a length of 256 bits according to the identifier of the encryption algorithm and the access and mobility management function key Kamf, and the communication module 602 is used to derive a non-access layer integrity protection key Knas-int' with a length of 256 bits according to the identifier of the integrity protection algorithm and the access and mobility management function key Kamf; the communication module 602 is used to activate NAS encryption with the AMF according to the encryption algorithm and Knas-enc'; and activate NAS integrity protection with the AMF according to the integrity protection algorithm and Knas-int'.
[0269] Optionally, in one embodiment, the communication module 602 is further configured to receive second indication information, where the second indication information is configured to instruct the terminal to use the authentication encryption mode of the target security algorithm.
[0270] Optionally, in one embodiment, the communication module 602 is used to derive a second key Knas' with a length of 256 bits based on the second indication information, the access and mobility management function key Kamf, the authentication encryption algorithm type difference and the algorithm identifier of the target security algorithm; the communication module 602 is used to activate NAS encryption and integrity protection with the AMF according to the target security algorithm of the authentication encryption mode and the second key Knas'.
[0271] Optionally, in one embodiment, the communication module 602 is used to derive a second key Knas' with a length of 256 bits based on the second indication information, the non-access layer encryption key Knas-enc' and the non-access layer integrity protection key Knas-int'; the communication module 602 is used to activate NAS encryption and integrity protection with the AMF according to the target security algorithm of the authenticated encryption mode and the second key Knas'.
[0272] Optionally, in one embodiment, the network side device is a RAN; wherein the communication module 602 is used to send the terminal security capability information to the RAN through the AMF; the communication module 602 is used to receive an access layer security mode command AS SMC message sent by the RAN, the AS SMC message including the identifier of the target security algorithm, and the AS SMC message is used to activate radio resource control RRC security.
[0273] Optionally, in one embodiment, the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the communication module 602 is configured to generate a cipher key according to the identifier of the encryption algorithm and the access layer key K gNB , derive the wireless access control encryption key Krrc-enc' with a length of 256 bits, and, according to the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a radio access control integrity protection key Krrc-int' with a length of 256 bits; the communication module 602 is configured to activate RRC encryption with the RAN according to the encryption algorithm and the Krrc-enc'; and activate RRC integrity protection with the RAN according to the integrity protection algorithm and the Krrc-int'.
[0274] Optionally, in one embodiment, the communication module 602 is further configured to receive third indication information, where the third indication information is configured to instruct the terminal to use the authenticated encryption mode of the target security algorithm.
[0275] Optionally, in one embodiment, the communication module 602 is configured to, based on the third indication information, determine the access layer key K gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm, and derive a third key Krrc' with a length of 256 bits; the communication module 602 is configured to activate RRC encryption and integrity protection with the RAN based on the target security algorithm in the authentication encryption mode and the third key Krrc'.
[0276] Optionally, in one embodiment, the communication module 602 is configured to derive, based on the third indication information, a third key Krrc' having a length of 256 bits according to a radio access control encryption key Krrc-enc' and a radio access control integrity protection key Krrc-int'; and the communication module 602 is configured to activate RRC encryption and integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the third key Krrc'.
[0277] Optionally, in one embodiment, the communication module 602 is further used to receive an RRC reconfiguration message, where the RRC reconfiguration message includes a user plane UP security activation indication, where the UP security activation indication is used to indicate whether user plane encryption is enabled and whether user plane integrity protection is enabled.
[0278] Optionally, in one embodiment, the UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the communication module 602 is used to determine the encryption algorithm according to the identifier of the encryption algorithm and the access layer key K gNB , derive the user plane encryption key Kup-enc' of length 256 bits, and, according to the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the communication module 602 is used to activate user plane encryption with the RAN according to the encryption algorithm and the Kup-enc'; and activate user plane integrity protection with the RAN according to the integrity protection algorithm and the Kup-int'.
[0279] Optionally, in an embodiment, the UP security activation indication is configured to indicate that user plane encryption is turned on and user plane integrity protection is turned on, and the target security algorithm used by the RRC uses an authenticated encryption mode; the communication module 602 is configured to derive a fourth key Kup' with a length of 256 bits according to the target security algorithm of the authenticated encryption mode and the access stratum key K gNB , a difference between authentication encryption algorithm types of the target security algorithm, and an algorithm identifier; the communication module 602 is configured to activate user plane encryption and user plane integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the fourth key Kup'.
[0280] Optionally, in an embodiment, the UP security activation indication is configured to indicate that user plane encryption is turned on and user plane integrity protection is turned on, and the target security algorithm used by the RRC uses an authenticated encryption mode; the communication module 602 is configured to derive a single fourth key Kup' with a length of 256 bits according to a user plane encryption key Kup-enc' and a user plane integrity protection key Kup-int'; the communication module 602 is configured to activate user plane encryption and user plane integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the fourth key Kup'.
[0281] Optionally, in an embodiment, the UP security activation indication is configured to indicate that user plane encryption is turned on and user plane integrity protection is not turned on, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits; the communication module 602 is configured to derive a user plane encryption key Kup-enc' with a length of 256 bits according to an identifier of the encryption algorithm and an access stratum key K gNB ; the communication module 602 is configured to activate user plane encryption with the RAN according to the encryption algorithm and the Kup-enc'.
[0282] Optionally, in an embodiment, the UP security activation indication is configured to indicate that user plane encryption is turned on and user plane integrity protection is not turned on, and the target security algorithm used by the RRC uses an authenticated encryption mode; the communication module 602 is configured to derive a user plane encryption key Kup-enc' with a length of 256 bits according to an identifier of the target security algorithm of the authenticated encryption mode and an access stratum key K gNB ; the communication module 602 is configured to activate user plane encryption with the RAN according to the target security algorithm of the authenticated encryption mode and the user plane encryption key Kup-enc'.
[0283] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm includes an integrity protection algorithm with a packet length of 256 bits; the communication module 602 is used to determine the integrity protection algorithm based on the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the communication module 602 is used to activate user plane integrity protection with the RAN according to the integrity protection algorithm and the Kup-int'.
[0284] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; the communication module 602 is used to identify the target security algorithm in the authenticated encryption mode and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the communication module 602 is used to activate user plane integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the user plane integrity protection key Kup-int'.
[0285] Optionally, in one embodiment, the identifier of the target security algorithm is obtained by the terminal according to the AS SMC message, or according to the RRC reconfiguration message.
[0286] Optionally, in one embodiment, the communication module 602 is further used for at least one of the following: 1) enabling RRC encryption based on the wireless access control encryption key Krrc-enc' and the encryption algorithm corresponding to the target security algorithm of the authentication encryption mode; 2) enabling RRC integrity protection based on the wireless access control integrity protection key Krrc-int' and the integrity protection algorithm corresponding to the target security algorithm of the authentication encryption mode.
[0287] According to the device 600 of the embodiment of the present application, the process of the method 200 corresponding to the embodiment of the present application can be referred to, and the various units / modules in the device 600 and the above-mentioned other operations and / or functions are respectively for implementing the corresponding processes in the method 200, and can achieve the same or equivalent technical effects. For the sake of brevity, they will not be repeated here.
[0288] The device for activating security in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or chip. The electronic device can be a terminal, or it can be other devices other than a terminal. For example, the terminal can include but is not limited to the types of terminals 11 listed above, and other devices can be servers, network attached storage (NAS), etc., which are not specifically limited in the embodiments of the present application.
[0289] Figure 7 FIG. 1 is a schematic diagram of the structure of a device for activating security according to an embodiment of the present application, which can be applied to access network devices in other embodiments. Figure 7 As shown, the apparatus 700 includes the following modules.
[0290] The communication module 702 is configured to receive terminal security capability information from a terminal, where the terminal security capability information includes an identifier of a security algorithm supported by the terminal, and the security algorithm includes a security algorithm with a packet length of 256 bits.
[0291] The communication module 702 is configured to select a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, where the target security algorithm is one of the security algorithms supported by the terminal.
[0292] The communication module 702 is configured to derive a security key according to the identifier of the target security algorithm.
[0293] The communication module 702 is configured to activate security protection with the terminal according to the target security algorithm and the security key.
[0294] The communication module 702 is configured to send the identifier of the target security algorithm to the terminal.
[0295] The device for activating security provided in the embodiment of the present application introduces a 256-bit security algorithm on the network side. The terminal negotiates the target security algorithm with the network side device, generates a security key based on the target security algorithm, and activates the corresponding security based on the security key and the target security algorithm to improve communication security.
[0296] Optionally, in one embodiment, the communication module 702 is used to derive a 256-bit first key based on the identifier of the target security algorithm when the packet length of the target security algorithm is 128 bits; obtain the security key by inputting the first key into a truncation function; or, the communication module 702 is used to derive a 256-bit first key based on the identifier of the target security algorithm when the packet length of the target security algorithm is 256 bits; skip the truncation function and use the first key as the security key.
[0297] Optionally, in one embodiment, the terminal security capability information further includes first indication information, and the first indication information is used to indicate that the terminal supports the authentication encryption mode.
[0298] Optionally, in one embodiment, the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the communication module 702 is configured to generate a corresponding encryption algorithm based on the identifier of the encryption algorithm and the access layer key K gNB , derive the wireless access control encryption key Krrc-enc' with a length of 256 bits, and, according to the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a radio access control integrity protection key Krrc-int' with a length of 256 bits; the communication module 702 is used to activate RRC encryption with the terminal according to the encryption algorithm and the Krrc-enc'; and activate RRC integrity protection with the terminal according to the integrity protection algorithm and the Krrc-int'.
[0299] Optionally, in one embodiment, the algorithm priority list also includes a security algorithm using an authenticated encryption mode, and the communication module 702 is further used to determine third indication information based on the first indication information in the terminal security capability information, wherein the third indication information is used to indicate the use of the authenticated encryption mode of the target security algorithm; and send the third indication information to the terminal.
[0300] Optionally, in one embodiment, the communication module 702 is configured to: gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a third key Krrc' with a length of 256 bits; the communication module 702 is used to activate RRC encryption and integrity protection with the terminal according to the target security algorithm of the authentication encryption mode and the third key Krrc'.
[0301] Optionally, in one embodiment, the communication module 702 is used to derive a third key Krrc' with a length of 256 bits based on the wireless access control encryption key Krrc-enc' and the wireless access control integrity protection key Krrc-int'; the communication module 702 is used to activate RRC encryption and integrity protection with the terminal based on the target security algorithm of the authenticated encryption mode and the third key Krrc'.
[0302] Optionally, in one embodiment, the communication module 702 is further configured to determine a UP security activation indication, where the UP security activation indication is configured to indicate whether user plane encryption is enabled and whether user plane integrity protection is enabled.
[0303] Optionally, in one embodiment, the UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the communication module 702 is used to generate a 256-bit encryption key according to the identifier of the encryption algorithm and the access layer key K gNB , derive the user plane encryption key Kup-enc' of length 256 bits, and, according to the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the communication module 702 is used to activate user plane encryption with the terminal according to the encryption algorithm and the Kup-enc'; and activate user plane integrity protection with the terminal according to the integrity protection algorithm and the Kup-int'.
[0304] Optionally, in one embodiment, the UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm used by the RRC uses an authenticated encryption mode; the communication module 702 is used to determine the authentication mode according to the access layer key K gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a fourth key Kup' with a length of 256 bits; the communication module 702 is used to activate user plane encryption and user plane integrity protection with the terminal according to the target security algorithm of the authentication encryption mode and the fourth key Kup'.
[0305] Optionally, in one embodiment, the UP security activation indication is used to indicate the activation of user plane encryption and the activation of user plane integrity protection, and the target security algorithm used by the RRC uses an authenticated encryption mode; the communication module 702 is used to derive a single fourth key Kup' with a length of 256 bits based on the user plane encryption key Kup-enc' and the user plane integrity protection key Kup-int'; the communication module 702 is used to activate user plane encryption and user plane integrity protection with the terminal based on the target security algorithm of the authenticated encryption mode and the fourth key Kup'.
[0306] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits; the communication module 702 is used to generate an encryption algorithm based on the identifier of the encryption algorithm and the access layer key K gNB , deriving a user plane encryption key Kup-enc' with a length of 256 bits; the communication module 702 is used to activate user plane encryption with the terminal according to the encryption algorithm and the Kup-enc'.
[0307] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; the communication module 702 is used to identify the target security algorithm in the authenticated encryption mode and the access layer key K gNB , deriving a user plane encryption key Kup-enc' with a length of 256 bits; the communication module 702 is used to activate user plane encryption with the terminal according to the target security algorithm of the authentication encryption mode and the user plane encryption key Kup-enc'.
[0308] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm includes an integrity protection algorithm with a packet length of 256 bits; the communication module 702 is used to determine the integrity protection algorithm based on the identifier of the integrity protection algorithm and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the communication module 702 is used to activate user plane integrity protection with the terminal according to the integrity protection algorithm and the Kup-int'.
[0309] Optionally, in one embodiment, the UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; the communication module 702 is used to identify the target security algorithm in the authenticated encryption mode and the access layer key K gNB , deriving a user plane integrity protection key Kup-int' with a length of 256 bits; the communication module 702 is used to activate user plane integrity protection with the terminal according to the target security algorithm of the authenticated encryption mode and the user plane integrity protection key Kup-int'.
[0310] Optionally, in one embodiment, the communication module 702 is further used for at least one of the following: enabling RRC encryption according to the wireless access control encryption key Krrc-enc' and the encryption algorithm corresponding to the target security algorithm of the authentication encryption mode; enabling RRC integrity protection according to the wireless access control integrity protection key Krrc-int' and the integrity protection algorithm corresponding to the target security algorithm of the authentication encryption mode.
[0311] According to the device 700 of the embodiment of the present application, the process of the method 400 corresponding to the embodiment of the present application can be referred to, and the various units / modules in the device 700 and the above-mentioned other operations and / or functions are respectively for implementing the corresponding processes in the method 400, and can achieve the same or equivalent technical effects. For the sake of brevity, they will not be repeated here.
[0312] Figure 8 This is a schematic diagram of the structure of the device for activating security according to an embodiment of the present application, which can be applied to the core network equipment in other embodiments. Figure 8 As shown, the apparatus 800 includes the following modules.
[0313] The communication module 802 is configured to receive terminal security capability information sent by a terminal, where the terminal security capability information includes an identifier of a security algorithm supported by the terminal, and the security algorithm includes a security algorithm with a packet length of 256 bits.
[0314] The communication module 802 is configured to select a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, where the target security algorithm is one of the security algorithms supported by the terminal.
[0315] The communication module 802 is configured to derive a security key according to the identifier of the target security algorithm.
[0316] The communication module 802 is configured to activate security protection with the terminal according to the target security algorithm and the security key.
[0317] The communication module 802 is configured to send the identifier of the target security algorithm to the terminal.
[0318] The device for activating security provided in the embodiment of the present application introduces a 256-bit security algorithm on the network side. The terminal negotiates the target security algorithm with the network side device, generates a security key based on the target security algorithm, and activates the corresponding security based on the security key and the target security algorithm to improve communication security.
[0319] Optionally, in one embodiment, the communication module 802 is used to derive a 256-bit first key based on the identifier of the target security algorithm when the packet length of the target security algorithm is 128 bits; obtain the security key by inputting the first key into a truncation function; or, the communication module 802 is used to derive a 256-bit first key based on the identifier of the target security algorithm when the packet length of the target security algorithm is 256 bits; skip the truncation function and use the first key as the security key.
[0320] Optionally, in one embodiment, the terminal security capability information further includes first indication information, and the first indication information is used to indicate that the terminal supports the authentication encryption mode.
[0321] Optionally, in one embodiment, the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; the communication module 802 is used to derive a non-access stratum encryption key Knas-enc' with a length of 256 bits based on the identifier of the encryption algorithm and the access and mobility management function key Kamf, and to derive a non-access stratum integrity protection key Knas-int' with a length of 256 bits based on the identifier of the integrity protection algorithm and the access and mobility management function key Kamf; the communication module 802 is used to activate NAS encryption with the terminal based on the encryption algorithm and the Knas-enc'; and activate NAS integrity protection with the terminal based on the integrity protection algorithm and the Knas-int'.
[0322] Optionally, in one embodiment, the algorithm priority list also includes a security algorithm using an authenticated encryption mode, and the communication module 802 is further used to determine second indication information based on the first indication information in the terminal security capability information, wherein the second indication information is used to indicate the use of the authenticated encryption mode of the target security algorithm; and send the second indication information to the terminal.
[0323] Optionally, in one embodiment, the communication module 802 is used to derive a second key Knas' with a length of 256 bits based on the access and mobility management function key Kamf, the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm; the communication module 802 is used to activate NAS encryption and integrity protection with the terminal based on the target security algorithm of the authentication encryption mode and the second key Knas'.
[0324] Optionally, in one embodiment, the communication module 802 is used to derive a second key Knas' with a length of 256 bits based on the non-access layer encryption key Knas-enc' and the non-access layer integrity protection key Knas-int'; the communication module 802 is used to activate NAS encryption and integrity protection with the terminal based on the target security algorithm of the authenticated encryption mode and the second key Knas'.
[0325] According to the device 800 of the embodiment of the present application, the process of the method 500 corresponding to the embodiment of the present application can be referred to, and the various units / modules in the device 800 and the above-mentioned other operations and / or functions are respectively for implementing the corresponding processes in the method 500, and can achieve the same or equivalent technical effects. For the sake of brevity, they will not be repeated here.
[0326] The activation security device provided in the embodiment of the present application can achieve Figures 2 to 5 The various processes implemented by the method embodiment achieve the same technical effect and are not described here again to avoid repetition.
[0327] Alternatively, as Figure 9 As shown, an embodiment of the present application further provides a communication device 900, including a processor 901 and a memory 902, wherein the memory 902 stores a program or instruction that can be run on the processor 901. For example, when the communication device 900 is a terminal, the program or instruction, when executed by the processor 901, implements the various steps of the above-mentioned method embodiment for activating security, and can achieve the same technical effect. When the communication device 900 is a network-side device, the program or instruction, when executed by the processor 901, implements the various steps of the above-mentioned method embodiment for activating security, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0328] An embodiment of the present application also provides a terminal, including a processor and a communication interface, wherein the communication interface is used to send terminal security capability information to a network side device, wherein the terminal security capability information includes an identifier of a security algorithm supported by the terminal, and the security algorithm includes a security algorithm with a packet length of 256 bits; receiving an identifier of a target security algorithm sent by the network side device, wherein the target security algorithm is one of the security algorithms supported by the terminal; deriving a security key based on the identifier of the target security algorithm; activating security protection with the network side device based on the target security algorithm and the security key. This terminal embodiment corresponds to the above-mentioned terminal side method embodiment, and each implementation process and implementation method of the above-mentioned method embodiment can be applied to this terminal embodiment and can achieve the same technical effect. Specifically, Figure 10 A schematic diagram of the hardware structure of a terminal for implementing an embodiment of the present application.
[0329] The terminal 1000 includes but is not limited to: a radio frequency unit 1001, a network module 1002, an audio output unit 1003, an input unit 1004, a sensor 1005, a display unit 1006, a user input unit 1007, an interface unit 1008, a memory 1009 and at least some of the components of the processor 1010.
[0330] Those skilled in the art will understand that the terminal 1000 may also include a power supply (such as a battery) to power each component, and the power supply may be logically connected to the processor 1010 through a power management system, thereby implementing functions such as charging, discharging, and power consumption management through the power management system. Figure 10 The terminal structure shown in the figure does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently, which will not be repeated here.
[0331] It should be understood that in an embodiment of the present application, the input unit 1004 may include a graphics processing unit (GPU) 10041 and a microphone 10042, and the graphics processor 10041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 1006 may include a display panel 10061, and the display panel 10061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 1007 includes a touch panel 10071 and at least one of other input devices 10072. The touch panel 10071 is also called a touch screen. The touch panel 10071 may include two parts: a touch detection device and a touch controller. Other input devices 10072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and an operating stick, which will not be repeated here.
[0332] In the embodiment of the present application, after receiving downlink data from a network-side device, the RF unit 1001 may transmit the data to the processor 1010 for processing. Furthermore, the RF unit 1001 may send uplink data to the network-side device. Typically, the RF unit 1001 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.
[0333] The memory 1009 can be used to store software programs or instructions and various data. The memory 1009 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 1009 may include a volatile memory or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct memory bus random access memory (DRRAM). The memory 1009 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
[0334] Processor 1010 may include one or more processing units. Optionally, processor 1010 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 1010.
[0335] Among them, the radio frequency unit 1001 can be used for the communication interface to send terminal security capability information to the network side device, the terminal security capability information includes the identifier of the security algorithm supported by the terminal, and the security algorithm includes a security algorithm with a packet length of 256 bits; receiving the identifier of the target security algorithm sent by the network side device, the target security algorithm is one of the security algorithms supported by the terminal; deriving a security key based on the identifier of the target security algorithm; and activating security protection with the network side device based on the target security algorithm and the security key.
[0336] In an embodiment of the present application, after a 256-bit security algorithm is introduced on the network side, the terminal negotiates a target security algorithm with the network side device, generates a security key based on the target security algorithm, and activates corresponding security based on the security key and the target security algorithm to improve communication security.
[0337] It can be understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the embodiment of the method for activating security, and achieve the same or corresponding technical effects. To avoid repetition, it will not be repeated here.
[0338] An embodiment of the present application also provides a network-side device, including a processor and a communication interface, the communication interface being used to receive terminal security capability information from a terminal, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; selecting a target security algorithm based on the terminal security capability information and a preconfigured algorithm priority list, the target security algorithm being one of the security algorithms supported by the terminal; deriving a security key based on the identifier of the target security algorithm; activating security protection with the terminal based on the target security algorithm and the security key; and sending the identifier of the target security algorithm to the terminal.
[0339] An embodiment of the present application also provides a network-side device, including a processor and a communication interface, the communication interface being used to receive terminal security capability information sent by a terminal, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; selecting a target security algorithm based on the terminal security capability information and a preconfigured algorithm priority list, the target security algorithm being one of the security algorithms supported by the terminal; deriving a security key based on the identifier of the target security algorithm; activating security protection with the terminal based on the target security algorithm and the security key; and sending the identifier of the target security algorithm to the terminal.
[0340] This network side device embodiment corresponds to the above-mentioned network side device method embodiment. Each implementation process and implementation method of the above-mentioned method embodiment can be applied to this network side device embodiment and can achieve the same technical effect.
[0341] The embodiment of the present application also provides a network side device (access network device). Figure 11 As shown, network-side device 1100 includes an antenna 111, a radio frequency device 112, a baseband device 113, a processor 114, and a memory 115. Antenna 111 is connected to radio frequency device 112. In the uplink direction, radio frequency device 112 receives information via antenna 111 and sends the received information to baseband device 113 for processing. In the downlink direction, baseband device 113 processes the information to be transmitted and sends it to radio frequency device 112. Radio frequency device 112 processes the received information and then sends it through antenna 111.
[0342] The method executed by the network-side device in the above embodiment may be implemented in the baseband device 113 , which includes a baseband processor.
[0343] The baseband device 113 may include, for example, at least one baseband board on which a plurality of chips are arranged, such as Figure 11 As shown, one of the chips is, for example, a baseband processor, which is connected to the memory 115 via a bus interface to call the program in the memory 115 to execute the network device operations shown in the above method embodiment.
[0344] The network side device may further include a network interface 116, which is, for example, a Common Public Radio Interface (CPRI).
[0345] The network side device 1100 of the embodiment of the present application further includes: instructions or programs stored in the memory 115 and executable on the processor 114, and the processor 114 calls the instructions or programs in the memory 115 to execute Figure 7 The methods executed by the modules shown achieve the same technical effects, so they will not be described here to avoid repetition.
[0346] The embodiment of the present application also provides a network side device (core network device). Figure 12 As shown, the network side device 1200 includes: a processor 1201, a network interface 1202 and a memory 1203. The network interface 1202 is, for example, a Common Public Radio Interface (CPRI).
[0347] Specifically, the network side device 1200 of the embodiment of the present invention further includes: instructions or programs stored in the memory 1203 and executable on the processor 1201, and the processor 1201 calls the instructions or programs in the memory 1203 to execute. Figure 8 The methods executed by the modules shown achieve the same technical effects, so they will not be described here to avoid repetition.
[0348] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned method embodiment for activating security are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0349] The processor is the processor in the terminal described in the above embodiment. The readable storage medium can be non-volatile or non-transitory. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk. In some examples, the readable storage medium can be non-transitory.
[0350] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned method embodiment for activating security, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0351] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0352] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned method embodiment for activating security, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0353] An embodiment of the present application also provides a system for activating security, including: a terminal and a network-side device, wherein the terminal can be used to execute the steps of the method for activating security as described above, and the network-side device can be used to execute the steps of the method for activating security as described above.
[0354] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0355] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general-purpose hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.
[0356] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.
Claims
1. A method for activating security, characterized in that, include: The terminal sends terminal security capability information to the network side device, where the terminal security capability information includes an identifier of a security algorithm supported by the terminal, where the security algorithm includes a security algorithm with a packet length of 256 bits; The terminal receives an identifier of a target security algorithm sent by the network-side device, where the target security algorithm is one of the security algorithms supported by the terminal; The terminal derives a security key according to the identifier of the target security algorithm; The terminal activates security protection with the network-side device according to the target security algorithm and the security key.
2. The method according to claim 1, characterized in that The terminal derives a security key according to the identifier of the target security algorithm, including: When the block length of the target security algorithm is 128 bits, the terminal derives a 256-bit first key according to the identifier of the target security algorithm; the terminal obtains the security key by inputting the first key into a truncation function; or When the packet length of the target security algorithm is 256 bits, the terminal derives a 256-bit first key according to the identifier of the target security algorithm; the terminal skips the truncation function and uses the first key as the security key.
3. The method according to claim 1, characterized in that The terminal security capability information further includes first indication information, where the first indication information is used to indicate that the terminal supports the authentication encryption mode.
4. The method according to any one of claims 1 to 3, characterized in that The network side device is the access and mobility management function AMF; The terminal sending the terminal security capability information to the network side device includes: the terminal sending a registration request message to the AMF, where the registration request message includes the terminal security capability information; The terminal receiving the identifier of the target security algorithm sent by the network side device includes: the terminal receiving a non-access layer security mode command NAS SMC message sent by the AMF, the NAS SMC message including the identifier of the target security algorithm, and the NAS SMC message being used to activate NAS security.
5. The method according to claim 4, characterized in that The target security algorithm includes an encryption algorithm with a block length of 256 bits and an integrity protection algorithm with a block length of 256 bits; The terminal derives a security key according to the identifier of the target security algorithm, including: The terminal derives a non-access stratum encryption key Knas-enc' having a length of 256 bits based on the identifier of the encryption algorithm and the access and mobility management function key Kamf, and derives a non-access stratum integrity protection key Knas-int' having a length of 256 bits based on the identifier of the integrity protection algorithm and the access and mobility management function key Kamf; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates NAS encryption with the AMF according to the encryption algorithm and Knas-enc'; The terminal activates NAS integrity protection with the AMF according to the integrity protection algorithm and the Knas-int'.
6. The method according to claim 4, characterized in that After the terminal sends the terminal security capability information to the network side device, the method further includes: The terminal receives second indication information, where the second indication information is used to instruct the terminal to use the authentication encryption mode of the target security algorithm.
7. The method according to claim 6, characterized in that The terminal derives a security key according to the identifier of the target security algorithm, including: The terminal derives a second key Knas' having a length of 256 bits based on the second indication information and the access and mobility management function key Kamf, the authentication encryption algorithm type difference and the algorithm identifier of the target security algorithm; The terminal activating security protection with the network-side device according to the target security algorithm and the security key includes: The terminal activates NAS encryption and integrity protection with the AMF according to the target security algorithm of the authenticated encryption mode and the second key Knas'.
8. The method according to claim 6, characterized in that The terminal derives a security key according to the identifier of the target security algorithm, including: The terminal derives a second key Knas' having a length of 256 bits based on the second indication information and the non-access stratum encryption key Knas-enc' and the non-access stratum integrity protection key Knas-int'; The terminal activating security protection with the network-side device according to the target security algorithm and the security key includes: The terminal activates NAS encryption and integrity protection with the AMF according to the target security algorithm of the authenticated encryption mode and the second key Knas'.
9. The method according to any one of claims 1 to 3, characterized in that The network side device is a radio access network RAN; The terminal sending the terminal security capability information to the network side device includes: the terminal sending the terminal security capability information to the RAN through the AMF; The terminal receiving the identifier of the target security algorithm sent by the network side device includes: the terminal receiving an access layer security mode command AS SMC message sent by the RAN, the AS SMC message including the identifier of the target security algorithm, and the AS SMC message being used to activate radio resource control RRC security.
10. The method according to claim 9, characterized in that The target security algorithm includes an encryption algorithm with a block length of 256 bits and an integrity protection algorithm with a block length of 256 bits; The terminal derives a security key according to the identifier of the target security algorithm, including: The terminal uses the identifier of the encryption algorithm and the access layer key K gNB , derive the wireless access control encryption key Krrc-enc' with a length of 256 bits, and the terminal uses the identifier of the integrity protection algorithm and the access layer key K gNB , derive the 256-bit wireless access control integrity protection key Krrc-int'; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates RRC encryption with the RAN according to the encryption algorithm and Krrc-enc′; The terminal activates RRC integrity protection with the RAN according to the integrity protection algorithm and the Krrc-int′.
11. The method according to claim 10, characterized in that After the terminal sends the terminal security capability information to the network side device, the method further includes: The terminal receives third indication information, where the third indication information is used to instruct the terminal to use the authenticated encryption mode of the target security algorithm.
12. The method according to claim 11, characterized in that The terminal derives a security key according to the identifier of the target security algorithm, including: The terminal, based on the third indication information, uses the access layer key K gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a third key Krrc' with a length of 256 bits; The terminal activating security protection with the network-side device according to the target security algorithm and the security key includes: The terminal activates RRC encryption and integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the third key Krrc′.
13. The method according to claim 11, characterized in that The terminal derives a security key according to the identifier of the target security algorithm, including: The terminal derives a third key Krrc' having a length of 256 bits based on the third indication information and the radio access control encryption key Krrc-enc' and the radio access control integrity protection key Krrc-int'; The terminal activating security protection with the network-side device according to the target security algorithm and the security key includes: The terminal activates RRC encryption and integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the third key Krrc′.
14. The method according to claim 9, characterized in that The method further comprises: The terminal receives an RRC reconfiguration message, where the RRC reconfiguration message includes a user plane UP security activation indication, where the UP security activation indication is used to indicate whether user plane encryption is enabled and whether user plane integrity protection is enabled.
15. The method according to claim 14, characterized in that The UP security activation indication is used to indicate the activation of user plane encryption and user plane integrity protection, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; The terminal deriving a security key according to the identifier of the target security algorithm includes: The terminal uses the identifier of the encryption algorithm and the access layer key K gNB , derive the user plane encryption key Kup-enc' of length 256 bits, and the terminal uses the identifier of the integrity protection algorithm and the access layer key K gNB , derive the user plane integrity protection key Kup-int' with a length of 256 bits; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates user plane encryption with the RAN according to the encryption algorithm and Kup-enc'; The terminal activates user plane integrity protection with the RAN according to the integrity protection algorithm and Kup-int'.
16. The method according to claim 14, characterized in that The UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm used by the RRC uses the authenticated encryption mode; The terminal deriving a security key according to the identifier of the target security algorithm includes: The terminal uses the access layer key K gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a fourth key Kup' with a length of 256 bits; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates user plane encryption and user plane integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the fourth key Kup'.
17. The method according to claim 14, characterized in that The UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm used by the RRC uses the authenticated encryption mode; The terminal deriving a security key according to the identifier of the target security algorithm includes: The terminal derives a single fourth key Kup' with a length of 256 bits based on the user plane encryption key Kup-enc' and the user plane integrity protection key Kup-int'; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates user plane encryption and user plane integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the fourth key Kup'.
18. The method according to claim 14, characterized in that The UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits; The terminal deriving a security key according to the identifier of the target security algorithm includes: The terminal uses the identifier of the encryption algorithm and the access layer key K gNB , derive the user plane encryption key Kup-enc' with a length of 256 bits; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates user plane encryption with the RAN according to the encryption algorithm and the Kup-enc′.
19. The method according to claim 14, wherein The UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; The terminal deriving a security key according to the identifier of the target security algorithm includes: The terminal uses the identifier of the target security algorithm in the authentication encryption mode and the access layer key K gNB , derive the user plane encryption key Kup-enc' with a length of 256 bits; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates user plane encryption with the RAN according to the target security algorithm of the authenticated encryption mode and the user plane encryption key Kup-enc'.
20. The method according to claim 14, wherein The UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm includes an integrity protection algorithm with a packet length of 256 bits; The terminal deriving a security key according to the identifier of the target security algorithm includes: The terminal uses the identifier of the integrity protection algorithm and the access layer key K gNB , derive the user plane integrity protection key Kup-int' with a length of 256 bits; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates user plane integrity protection with the RAN according to the integrity protection algorithm and Kup-int'.
21. The method according to claim 14, wherein The UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; The terminal deriving a security key according to the identifier of the target security algorithm includes: The terminal uses the identifier of the target security algorithm in the authentication encryption mode and the access layer key K gNB , derive the user plane integrity protection key Kup-int' with a length of 256 bits; The terminal activates security protection with the network-side device according to the target security algorithm and the security key, including: The terminal activates user plane integrity protection with the RAN according to the target security algorithm of the authenticated encryption mode and the user plane integrity protection key Kup-int'.
22. The method according to any one of claims 15 to 21, characterized in that The identifier of the target security algorithm is obtained by the terminal according to the AS SMC message or the RRC reconfiguration message.
23. The method according to any one of claims 18 to 21, characterized in that The method further comprises at least one of the following: The terminal turns on RRC encryption according to the radio access control encryption key Krrc-enc' and the encryption algorithm corresponding to the target security algorithm of the authentication encryption mode; The terminal enables RRC integrity protection according to the radio access control integrity protection key Krrc-int' and the integrity protection algorithm corresponding to the target security algorithm in the authenticated encryption mode.
24. A method for activating security, characterized in that, include: The access network device receives terminal security capability information from the terminal, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; The access network device selects a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, where the target security algorithm is one of the security algorithms supported by the terminal; The access network device derives a security key according to the identifier of the target security algorithm; The access network device activates security protection with the terminal according to the target security algorithm and the security key; The access network device sends the identifier of the target security algorithm to the terminal.
25. The method according to claim 24, characterized in that The access network device derives a security key according to the identifier of the target security algorithm, including: When the packet length of the target security algorithm is 128 bits, the access network device derives a 256-bit first key according to the identifier of the target security algorithm; the access network device obtains the security key by inputting the first key into a truncation function; or When the packet length of the target security algorithm is 256 bits, the access network device derives a 256-bit first key based on the identifier of the target security algorithm; the access network device skips the truncation function and uses the first key as the security key.
26. The method according to claim 24, characterized in that The terminal security capability information further includes first indication information, where the first indication information is used to indicate that the terminal supports the authentication encryption mode.
27. The method according to any one of claims 24 to 26, characterized in that The target security algorithm includes an encryption algorithm with a block length of 256 bits and an integrity protection algorithm with a block length of 256 bits; The access network device derives a security key according to the identifier of the target security algorithm, including: The access network device uses the identifier of the encryption algorithm and the access layer key K gNB , derive the wireless access control encryption key Krrc-enc' with a length of 256 bits, and the access network device uses the identifier of the integrity protection algorithm and the access layer key K gNB , derive the 256-bit wireless access control integrity protection key Krrc-int'; The access network device activates security protection with the terminal according to the target security algorithm and the security key, including: The access network device activates RRC encryption with the terminal according to the encryption algorithm and Krrc-enc'; The access network device activates RRC integrity protection with the terminal according to the integrity protection algorithm and the Krrc-int'.
28. The method according to any one of claims 24 to 26, characterized in that The algorithm priority list also includes a security algorithm using authenticated encryption mode, and the method further includes: The access network device determines, according to the first indication information in the terminal security capability information, third indication information, where the third indication information is used to indicate the use of an authenticated encryption mode of the target security algorithm; The access network device sends the third indication information to the terminal.
29. The method according to claim 28, characterized in that The access network device derives a security key according to the identifier of the target security algorithm, including: The access network device uses the access layer key K gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a third key Krrc' with a length of 256 bits; The access network device activating security protection with the terminal according to the target security algorithm and the security key includes: The access network device activates RRC encryption and integrity protection with the terminal according to the target security algorithm of the authenticated encryption mode and the third key Krrc'.
30. The method according to claim 28, wherein The access network device derives a security key according to the identifier of the target security algorithm, including: The access network device derives a third key Krrc' of 256 bits in length based on the radio access control encryption key Krrc-enc' and the radio access control integrity protection key Krrc-int'; The access network device activating security protection with the terminal according to the target security algorithm and the security key includes: The access network device activates RRC encryption and integrity protection with the terminal according to the target security algorithm of the authenticated encryption mode and the third key Krrc'.
31. The method according to any one of claims 24 to 30, characterized in that The method further comprises: The access network device determines a UP security activation indication, where the UP security activation indication is used to indicate whether user plane encryption is enabled and whether user plane integrity protection is enabled.
32. The method according to claim 31, characterized in that The UP security activation indication is used to indicate the activation of user plane encryption and user plane integrity protection, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits and an integrity protection algorithm with a packet length of 256 bits; The access network device deriving the security key according to the identifier of the target security algorithm includes: The access network device uses the identifier of the encryption algorithm and the access layer key K gNB , derive the user plane encryption key Kup-enc' of length 256 bits, and the access network device uses the identifier of the integrity protection algorithm and the access layer key K gNB , derive the user plane integrity protection key Kup-int' with a length of 256 bits; The access network device activates security protection with the terminal according to the target security algorithm and the security key, including: The access network device activates user plane encryption with the terminal according to the encryption algorithm and Kup-enc'; The access network device activates user plane integrity protection with the terminal according to the integrity protection algorithm and Kup-int'.
33. The method according to claim 31, characterized in that The UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm used by the RRC uses the authenticated encryption mode; The access network device deriving the security key according to the identifier of the target security algorithm includes: The access network device uses the access layer key K gNB , the authentication encryption algorithm type difference and algorithm identifier of the target security algorithm are used to derive a fourth key Kup' with a length of 256 bits; The access network device activates security protection with the terminal according to the target security algorithm and the security key, including: The access network device activates user plane encryption and user plane integrity protection with the terminal according to the target security algorithm in the authenticated encryption mode and the fourth key Kup'.
34. The method according to claim 31, wherein The UP security activation indication is used to indicate the start of user plane encryption and the start of user plane integrity protection, and the target security algorithm used by the RRC uses the authenticated encryption mode; The access network device deriving the security key according to the identifier of the target security algorithm includes: The access network device derives a single fourth key Kup' with a length of 256 bits based on the user plane encryption key Kup-enc' and the user plane integrity protection key Kup-int'; The access network device activates security protection with the terminal according to the target security algorithm and the security key, including: The access network device activates user plane encryption and user plane integrity protection with the terminal according to the target security algorithm in the authenticated encryption mode and the fourth key Kup'.
35. The method according to claim 31, wherein The UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm includes an encryption algorithm with a packet length of 256 bits; The access network device deriving the security key according to the identifier of the target security algorithm includes: The access network device uses the identifier of the encryption algorithm and the access layer key K gNB , derive the user plane encryption key Kup-enc' with a length of 256 bits; The access network device activates security protection with the terminal according to the target security algorithm and the security key, including: The access network device activates user plane encryption with the terminal according to the encryption algorithm and Kup-enc'.
36. The method according to claim 31, wherein The UP security activation indication is used to indicate that user plane encryption is enabled and user plane integrity protection is not enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; The access network device deriving the security key according to the identifier of the target security algorithm includes: The access network device uses the identifier of the target security algorithm in the authentication encryption mode and the access layer key K gNB , derive the user plane encryption key Kup-enc' with a length of 256 bits; The access network device activates security protection with the terminal according to the target security algorithm and the security key, including: The access network device activates user plane encryption with the terminal according to the target security algorithm of the authentication encryption mode and the user plane encryption key Kup-enc'.
37. The method according to claim 31, wherein The UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm includes an integrity protection algorithm with a packet length of 256 bits; The access network device deriving the security key according to the identifier of the target security algorithm includes: The access network device uses the identifier of the integrity protection algorithm and the access layer key K gNB , derive the user plane integrity protection key Kup-int' with a length of 256 bits; The access network device activates security protection with the terminal according to the target security algorithm and the security key, including: The access network device activates user plane integrity protection with the terminal according to the integrity protection algorithm and Kup-int'.
38. The method according to claim 31, wherein The UP security activation indication is used to indicate that user plane encryption is not enabled and user plane integrity protection is enabled, and the target security algorithm used by the RRC uses an authenticated encryption mode; The access network device deriving the security key according to the identifier of the target security algorithm includes: The access network device uses the identifier of the target security algorithm in the authentication encryption mode and the access layer key K gNB , derive the user plane integrity protection key Kup-int' with a length of 256 bits; The access network device activates security protection with the terminal according to the target security algorithm and the security key, including: The access network device activates user plane integrity protection with the terminal according to the target security algorithm in authenticated encryption mode and the user plane integrity protection key Kup-int'.
39. The method according to any one of claims 35 to 38, characterized in that The method further comprises at least one of the following: The access network device enables RRC encryption according to the radio access control encryption key Krrc-enc' and the encryption algorithm corresponding to the target security algorithm of the authentication encryption mode; The access network device enables RRC integrity protection according to the radio access control integrity protection key Krrc-int' and the integrity protection algorithm corresponding to the target security algorithm in the authenticated encryption mode.
40. A method for activating security, characterized in that, include: The core network device receives terminal security capability information sent by the terminal, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; The core network device selects a target security algorithm according to the terminal security capability information and a preconfigured algorithm priority list, where the target security algorithm is one of the security algorithms supported by the terminal; The core network device derives a security key according to the identifier of the target security algorithm; The core network device activates security protection with the terminal according to the target security algorithm and the security key; The core network device sends the identifier of the target security algorithm to the terminal.
41. The method according to claim 40, characterized in that The core network device derives a security key according to the identifier of the target security algorithm, including: When the packet length of the target security algorithm is 128 bits, the core network device derives a 256-bit first key according to the identifier of the target security algorithm; the core network device obtains the security key by inputting the first key into a truncation function; or When the packet length of the target security algorithm is 256 bits, the core network device derives a 256-bit first key based on the identifier of the target security algorithm; the core network device skips the truncation function and uses the first key as the security key.
42. The method according to claim 40, wherein The terminal security capability information further includes first indication information, where the first indication information is used to indicate that the terminal supports the authentication encryption mode.
43. The method according to any one of claims 40 to 42, characterized in that The target security algorithm includes an encryption algorithm with a block length of 256 bits and an integrity protection algorithm with a block length of 256 bits; The core network device derives a security key according to the identifier of the target security algorithm, including: The core network device derives a non-access stratum encryption key Knas-enc' having a length of 256 bits based on the identifier of the encryption algorithm and the access and mobility management function key Kamf, and derives a non-access stratum integrity protection key Knas-int' having a length of 256 bits based on the identifier of the integrity protection algorithm and the access and mobility management function key Kamf; The core network device activates security protection with the terminal according to the target security algorithm and the security key, including: The core network device activates NAS encryption with the terminal according to the encryption algorithm and Knas-enc'; The core network device activates NAS integrity protection with the terminal according to the integrity protection algorithm and the Knas-int'.
44. The method according to any one of claims 40 to 42, characterized in that The algorithm priority list also includes a security algorithm using authenticated encryption mode, and the method further includes: The core network device determines, according to the first indication information in the terminal security capability information, second indication information, where the second indication information is used to indicate the use of an authenticated encryption mode of the target security algorithm; The core network device sends the second indication information to the terminal.
45. The method according to claim 44, wherein The core network device derives a security key according to the identifier of the target security algorithm, including: The core network device derives a second key Knas' having a length of 256 bits according to the access and mobility management function key Kamf, the authentication encryption algorithm type difference of the target security algorithm, and the algorithm identifier; The core network device activating security protection with the terminal according to the target security algorithm and the security key includes: The core network device activates NAS encryption and integrity protection with the terminal according to the target security algorithm of the authenticated encryption mode and the second key Knas'.
46. The method according to claim 44, wherein The core network device derives a security key according to the identifier of the target security algorithm, including: The core network device derives a second key Knas' having a length of 256 bits according to the non-access layer encryption key Knas-enc' and the non-access layer integrity protection key Knas-int'; The core network device activating security protection with the terminal according to the target security algorithm and the security key includes: The core network device activates NAS encryption and integrity protection with the terminal according to the target security algorithm of the authenticated encryption mode and the second key Knas'.
47. A device for activating security, applied to a terminal, characterized in that: include: A communication module, configured to send terminal security capability information to a network-side device, wherein the terminal security capability information includes an identifier of a security algorithm supported by the terminal, wherein the security algorithm includes a security algorithm with a packet length of 256 bits; The communication module is configured to receive an identifier of a target security algorithm sent by the network-side device, where the target security algorithm is one of the security algorithms supported by the terminal; The communication module is configured to derive a security key based on an identifier of the target security algorithm; The communication module is used to activate security protection with the network side device according to the target security algorithm and the security key.
48. A device for activating security, applied to access network equipment, characterized in that: include: a communication module, configured to receive terminal security capability information from a terminal, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; The communication module is configured to select a target security algorithm based on the terminal security capability information and a preconfigured algorithm priority list, wherein the target security algorithm is one of the security algorithms supported by the terminal; The communication module is configured to derive a security key based on an identifier of the target security algorithm; The communication module is configured to activate security protection with the terminal according to the target security algorithm and the security key; The access network device sends the identifier of the target security algorithm to the terminal.
49. A device for activating security, applied to core network equipment, characterized in that: include: a communication module, configured to receive terminal security capability information sent by a terminal, the terminal security capability information including an identifier of a security algorithm supported by the terminal, the security algorithm including a security algorithm with a packet length of 256 bits; The communication module is configured to select a target security algorithm based on the terminal security capability information and a preconfigured algorithm priority list, wherein the target security algorithm is one of the security algorithms supported by the terminal; The communication module is configured to derive a security key based on an identifier of the target security algorithm; The communication module is configured to activate security protection with the terminal according to the target security algorithm and the security key; The communication module is configured to send the identifier of the target security algorithm to the terminal.
50. A terminal, characterized in that: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method according to any one of claims 1 to 23 are implemented.
51. A network side device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method according to any one of claims 24 to 46 are implemented.
52. A readable storage medium, characterized in that The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the method according to any one of claims 1 to 23 are implemented, or the steps of the method according to any one of claims 24 to 46 are implemented.