Secure communication method and device, network equipment, computer storage medium and program product
By issuing authentication certificates through a CA center and utilizing quantum-secure direct communication, the security risks of non-service interfaces in 5G networks are resolved, enabling efficient and secure communication between network functions, resisting quantum computer attacks, and simplifying management overhead.
Patent Information
- Application Number
- CN202410497050.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-23
- Publication Date
- 2025-10-24
AI Technical Summary
In the virtualized open network architecture of 5G networks, there are security vulnerabilities in the non-service interfaces between the control plane and the user plane, and between the 5G core network and the wireless base station. The existing IPSec protocol's IKE channel establishment process is complex and cannot resist attacks from quantum computers. The security of traditional public-key cryptography algorithms is threatened, and the transmission rate of quantum-secure direct communication is insufficient.
Trustworthiness authentication between network functions is achieved through authentication certificates issued by a CA center. Security parameters are negotiated and session keys are generated using quantum-secure direct communication, enabling secure communication between network functions and simplifying the process of establishing secure channels.
It improves the authentication of trusted computing environments between network functions, avoids the risk of core network attacks caused by malicious infection of network functions, simplifies the management overhead of secure channels, resists attacks from quantum computers, and enhances communication security and transmission speed.
Smart Images

Figure CN120835295A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of secure communication technology, and in particular to a secure communication method and apparatus, network equipment, computer-readable storage medium, and computer program product. Background Art
[0002] While accelerating the commercial deployment of 5G networks, operators are faced with the challenge of transitioning from traditional network architecture to a virtualized, open architecture to improve network operational efficiency and reduce investment costs. With the virtualization of core network functions and the gradual shift of services to the cloud or edge, network functions (NFs) are being deployed physically in the cloud or at the edge, placing higher demands on the security of identity authentication, data transmission, and authentication between NFs.
[0003] Since the interfaces between the control plane and the user plane, and between the 5G core network and the wireless base station are currently non-service interfaces, and NFs do not establish secure transmission tunnels for some non-service interfaces or only use some of the tunnel establishment functions of the Internet Protocol Security (IPSec) for secure transmission, there are security risks in the communication process. Summary of the Invention
[0004] To solve the above technical problems, embodiments of the present invention provide a secure communication method and apparatus, a network device, a computer-readable storage medium, and a computer program product.
[0005] In a first aspect, the secure communication method provided in an embodiment of the present application is applied to a first network function, including:
[0006] Sending a first authentication certificate to a second network function, where the first authentication certificate is used by the second network function to authenticate the first network function;
[0007] receiving a second authentication certificate sent by the second network function, where the second authentication certificate is used by the first network function to authenticate the second network function, wherein the first authentication certificate and the second authentication certificate are issued by a certificate authority (CA);
[0008] If the first network function and the second network function are mutually authenticated, the first network function and the second network function negotiate security parameters through quantum secure direct communication, and use the security parameters to generate a session key. The session key is used for secure communication of messages between the first network function and the second network function.
[0009] In a second aspect, the secure communication method provided in the embodiments of the present application is applied to a CA center, including:
[0010] sending a first authentication certificate to a second network function, the first authentication certificate being used for the second network function to authenticate the first network function, and sending a second authentication certificate to the first network function, the second authentication certificate being used for the first network function to authenticate the second network function, wherein the first authentication certificate and the second authentication certificate are issued by the CA center.
[0011] In a third aspect, a secure communication apparatus is provided, and is applied to a first network function. The apparatus comprises:
[0012] a sending unit configured to send a first authentication certificate to a second network function, the first authentication certificate being used for the second network function to authenticate the first network function;
[0013] a receiving unit configured to receive a second authentication certificate sent by the second network function, the second authentication certificate being used for the first network function to authenticate the second network function; wherein the first authentication certificate and the second authentication certificate are issued by a CA center;
[0014] a generating unit configured to, if mutual authentication between the first network function and the second network function is passed, negotiate a security parameter between the first network function and the second network function through a quantum secure direct communication mode, and generate a session key by using the security parameter, the session key being used for the first network function and the second network function to perform secure communication of a message.
[0015] In a fourth aspect, a secure communication apparatus is provided, and is applied to a CA center. The apparatus comprises:
[0016] a sending unit configured to send a first authentication certificate to a first network function and send a second authentication certificate to a second network function, the first authentication certificate being used for the second network function to authenticate the first network function, and the second authentication certificate being used for the first network function to authenticate the second network function, wherein the first authentication certificate and the second authentication certificate are issued by the CA center.
[0017] In a fifth aspect, a network device is provided. The network device comprises a processor and a memory. The memory is configured to store a computer program. The processor is configured to invoke and run the computer program stored in the memory, and perform any one of the secure communication methods.
[0018] In a sixth aspect, a computer readable storage medium is provided. The computer readable storage medium is configured to store a computer program. The computer program is configured to make a computer perform any one of the methods.
[0019] In a seventh aspect, the computer program product provided by the embodiments of the present application includes computer program instructions, which cause a computer to execute any of the above methods.
[0020] In the technical solution of the embodiments of the present application, the first network function sends the first authentication certificate to the second network function and receives the second authentication certificate sent by the second network function, and the trustworthiness and security authentication is performed according to the first authentication certificate and the second authentication certificate. If the mutual authentication between the first network function and the second network function is passed, the security parameters are negotiated between the first network function and the second network function through the quantum secure direct communication mode, and the session key is generated by using the security parameters, so as to realize the secure communication of the messages between the first network function and the second network function. In this way, on the one hand, by increasing the authentication of the trusted computing environment of the two network functions, the security risk that the core network is attacked after the network function is maliciously infected under certain conditions is avoided. On the other hand, after the authentication of the trusted computing link, the quantum secure direct communication is used in the security parameter negotiation process, so as to avoid the problem that the public key negotiation in the prior art cannot resist the attack of the quantum computer, and the process of establishing a secure channel and other complex management overheads are simplified. BRIEF DESCRIPTION OF DRAWINGS
[0021] Figure 1 is a schematic diagram of a network architecture of the embodiments of the present application;
[0022] Figure 2 is a flowchart of the secure communication method provided by the embodiments of the present application Figure 1 ;
[0023] Figure 3 is a flowchart of the secure communication method provided by the embodiments of the present application Figure 2 ;
[0024] Figure 4 is a flowchart of the secure communication method provided by the embodiments of the present application Figure 3 ;
[0025] Figure 5 is a flowchart of the secure communication method provided by the embodiments of the present application Figure 4 ;
[0026] Figure 6 is a flowchart of the secure communication method provided by the embodiments of the present application Figure 5 ;
[0027] Figure 7 is a flowchart of the secure communication method provided by the embodiments of the present application Figure 6 ;
[0028] Figure 8 is a flowchart of the secure communication method provided by the embodiments of the present applicationFigure 7 ;
[0029] Figure 9 is a schematic diagram of a system device of a secure communication method provided by an embodiment of the present application;
[0030] Figure 10 is a schematic diagram of the structural composition of a secure communication device provided by an embodiment of the present application Figure 1 ;
[0031] Figure 1 is a schematic diagram of the structural composition of a secure communication device provided by an embodiment of the present application Figure 1 ;
[0032] Figure 1 is a schematic structural diagram of a network device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0033] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.
[0034] Figure 1 is a schematic diagram of a network architecture of an embodiment of the present application. As shown in Figure 1 , the network architecture includes user equipment, access network equipment and operator network (such as 5G network system), the operator network further includes core network and data network, and the user equipment accesses the operator network through the access network node. Specifically:
[0035] User Equipment (UE), UE is a logical entity, specifically, UE can be any one of a terminal device, a communication device, an Internet of Things (IoT) device. Wherein, the terminal device can be a smart phone, a smart watch, a smart tablet and the like. The communication device can be a server, a gateway (GW), a controller and the like. The IoT device can be a sensor, an electricity meter, a water meter and the like. Radio Access Net (RAN), RAN is responsible for the access of UE, and RAN can be a base station, a Wireless Fidelity (Wi-Fi) access point, a Bluetooth access point and the like. User Plane Function (UPF), UPF can be a gateway, a server, a controller, a user plane function network element and the like. The UPF can be set in the internal network of the operator, or set outside the operator network. The UPF is a user plane network element provided by the operator, and is a gateway for communication between the operator network and the data network. Data network (Data network, DN), DN is also called Packet Data Network (PDN). DN can be an operator external network, or an operator controlled network, used to provide service to users. Core network (core network, CN), CN provides an interface to the DN as a bearer network, provides communication connection, authentication, management, policy control and data service completion for UE. Wherein, the CN includes: access and mobility management network element, session management network element, authentication server network element, policy control node, application function network element, user plane node, and the related description is as follows: Access and Mobility Management Function (Access and Mobility Management Function, AMF), AMF is a control plane network element provided by the operator, responsible for access control and mobility management of UE accessing the operator network. Session Management Function (Session Management Function, SMF), SMF is a control plane network element provided by the operator, responsible for managing the session of UE data packets. Authentication Server Function (Authentication Server Function, AUSF), AUSF is a control plane network element provided by the operator, which can be used for authentication of network subscribers of the operator network.Unified Data Manager (UDM), UDM is a control plane network element provided by an operator, responsible for storing the Subscriber Permanent Identifier (SUPI) of the operator's network, registration information, credentials, subscription data, etc. Network Exposure Function (NEF), NEF is a control plane network element provided by an operator. NEF exposes the external interface of the operator's network to third parties in a secure manner. Application Function (AF), AF is used to store business security requirements and provide information for policy determination. Network Function Repository Function (NRF), NRF is responsible for NF automatic management, selection and scalability, including NFS registration, discovery, state monitoring, service authorization, etc., to realize on-demand configuration of network functions and services and interconnection between NFs. When the NF is powered on, it actively reports the information of its NFS to the NRF, and can find the appropriate opposite NFS through the NRF.
[0036] As shown in the core network system architecture diagram Figure 2 , all control plane NFs are located on a bus, and all control plane NFs use the same service interface protocol, such as Nnssf, Nnef, Nnrf, etc. The NFs supporting the service interface protocol have both the server side and the client side certificates of the Transport Layer Security (TLS), which can authenticate each other and can optionally use token-based or local policy-based authorization to authorize the legality of the message. In the 3rd Generation Partnership Project (3GPP) 33.501 protocol, it is specified to use the IPSec security protocol for integrity, confidentiality and replay protection of user plane / control plane data between non-3GPP terminals and non-3GPP interworking functions (Non-3GPP InterWorking Function, N3IWF), N2, N3, Xn, etc. However, the current interfaces between the control plane and the user plane, and between the 5G core network and the RAN are non-service interfaces, such as N3, N4, N6, N9 interfaces in Figure 1 . In actual engineering applications, the authentication, parameter negotiation and key sharing of the IPSec security protocol are too complex, and the Internet Key Exchange (IKE) channel establishment process is too complex. At present, some non-service interfaces (such as N3, N4, N6, N9 interfaces in Figure 2The security transmission tunnel is not established, or the security transmission only uses part of the functions of tunnel establishment in the IPSec protocol, and part of the security transmission is implemented according to the complete IPSec security protocol specified in the 3GPP protocol, and only the security of part of the user plane or control plane data transmission can be ensured.
[0037] It should be noted that, Figure 1 The system to which the application is applied is only shown in the form of an example, and of course, the method shown in the embodiments of the application can also be applied to other systems. In addition, the terms "system" and "network" are often used interchangeably in this paper. The term "and / or" in this paper is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, the character " / " in this paper generally represents an "or" relationship between the front and rear associated objects.
[0038] In order to facilitate understanding of the technical solutions of the embodiments of the application, the related technologies of the embodiments of the application are described below, and the following related technologies can be combined with the technical solutions of the embodiments of the application as optional schemes, which all belong to the protection scope of the embodiments of the application.
[0039] The prior art only uses part of the functions of IPSec tunnel establishment in the security of data transmission of part of the non-service interface in the virtualized deployment core network, and only the security of part of the user plane or control plane data transmission can be ensured. Even if the complete IPSec security protocol specified in the 3GPP protocol is implemented, on the one hand, the management overhead caused by the IKE channel establishment process is large, and on the other hand, the NFs in the virtualized deployment use certificates for identity authentication and authorization, without security risk assessment and authentication of the environment in which the NFs run. In addition, the public key cryptography algorithm used in identity authentication and key exchange in the IPSec security protocol is mostly based on the assumption of mathematical difficulty problem, and with the advent of quantum computers, the security of such protocols is facing a serious threat, and cannot cope with the security risk that the public key cryptography algorithm is broken due to the rapid development of quantum computers. Although quantum secure direct communication has appeared and can be used to prevent eavesdropping and resist quantum computer attacks, given that it also needs to be combined with identity authentication, and its transmission rate is currently in the technical dilemma of kilobits per second (Kbps) level, it is obviously not very realistic to directly use quantum secure direct communication to transmit session data at a rate of megabits per second (Gbps). Therefore, the following technical solutions of the embodiments of the application are proposed.
[0040] For the convenience of understanding the technical solutions of the embodiments of the present application, the technical solutions of the present application are described in detail below through specific embodiments. The above related technologies can be combined with the technical solutions of the embodiments of the present application as optional solutions, which all belong to the protection scope of the embodiments of the present application. The embodiments of the present application include at least part of the following contents.
[0041] Figure 3 is a flowchart of a secure communication method provided by the embodiments of the present application Figure 2 As shown in Figure 3 , the secure communication method is applied to a first network function, and specifically includes the following steps:
[0042] Step 201, sending a first authentication certificate to a second network function, the first authentication certificate being used for the second network function to authenticate the first network function.
[0043] Here, after receiving the first authentication certificate issued by the CA center, the first network function sends the first authentication certificate to the second network function. The second network function receives the first authentication certificate sent by the first network function, and performs trustworthiness authentication on the first network function based on the content of the first authentication certificate.
[0044] Step 201, receiving a second authentication certificate sent by a second network function, the second authentication certificate being used for the first network function to authenticate the second network function, wherein the first authentication certificate and the second authentication certificate are issued by a CA center.
[0045] Here, after receiving the second authentication certificate issued by the CA center, the second network function sends the second authentication certificate to the first network function. The first network function receives the second authentication certificate sent by the second network function, and performs trustworthiness authentication on the second network function based on the content of the second authentication certificate.
[0046] In some embodiments, the first network function and the second network function can be NFs paired through a non-service interface. The first network function can also be called NF1, and the second network function can also be called NF2, which is not specifically limited here. For example, referring to Figure 4 , the first network function is RAN, and the second network function is UPF; or the first network function is AMF, and the second network function is RAN; or the first network function is SMF, and the second network function is UPF.
[0047] Step 203, if the mutual authentication between the first network function and the second network function is passed, the first network function and the second network function negotiate security parameters through a quantum secure direct communication mode, and generate a session key using the security parameters, the session key being used for the first network function and the second network function to perform secure communication of messages.
[0048] Here, when the first network function confirms that the second network function is authenticated by the trusted computing environment according to the second authentication certificate, and the second network function confirms that the first network function is authenticated by the trusted computing environment according to the first authentication certificate, the first network function and the second network function negotiate the security parameters through the quantum secure direct communication mode, and transmit the data. Wherein, the quantum secure direct communication is that the first network function and the second network function receive and / or send data based on the quantum secure direct communication mode, and modulate and demodulate, encapsulate and decapsulate the data, etc.
[0049] In some embodiments, after the first network function and the second network function are mutually authenticated, the first network function or the second network function triggers the session message traffic transmission after completing the processing of the control plane or user plane data, and the first network function and the second network function perform subsequent session message secure communication based on the IPSec security protocol and the "National Cryptographic Standard GM / T0022 IPSec VPN Technical Specification" through the quantum secure direct communication mode. The secure message protocol provides confidentiality, data source authentication, connectionless integrity, anti-replay attack service and limited information flow protection.
[0050] In some embodiments, the first network function and the second network function generate a session key, and after the session key reaches a lifetime, the first network function and the second network function again negotiate security parameters through the quantum secure direct communication mode, and generate a session key using the security parameters, which is used for the first network function and the second network function to perform secure communication of messages.
[0051] As can be seen from the above, the secure communication method provided by the embodiments of the present application sends the first authentication certificate to the second network function and receives the second authentication certificate sent by the second network function, performs trustworthiness and security authentication according to the first authentication certificate and the second authentication certificate, and if the mutual authentication between the first network function and the second network function is passed, the first network function and the second network function negotiate security parameters through the quantum secure direct communication mode, and generate a session key using the security parameters, to realize the secure communication of messages between the first network function and the second network function. In this way, on the one hand, by increasing the trusted computing environment authentication of both network functions, the security risk of the core network being attacked after the network function is maliciously infected under certain circumstances is avoided; on the other hand, after the trusted computing link is authenticated, the quantum secure direct communication is used in the security parameter transmission process, the problem that the public key negotiation in the prior art cannot resist the attack of the quantum computer is avoided, and the overly complex management overhead process such as the establishment of a secure channel is simplified.
[0052] Figure 3 is a flowchart of the secure communication method provided by the embodiments of the present application Figure 5 , for example Figure 4As shown, before the first authentication certificate is sent to the second network function in step 201, the following steps are further included:
[0053] Step 301, sending a first authentication request file to the CA center, the first authentication request file including first information, the first information being information for the CA center to verify the first network function.
[0054] Here, the first network function locally generates a post-quantum public-private key pair, the first network function applies for an authentication certificate based on the IPSc security protocol, sends a first authentication request file to the CA center, and the first authentication request file includes first information. The CA center verifies the legitimacy and trustworthiness of the first network function based on the first information.
[0055] In some embodiments, the first information includes: a domain name of the first network function, an applicant corresponding to the first network function, a post-quantum public key of the first network function, and a trustworthiness measurement value of the first network function; wherein the trustworthiness measurement value of the first network function is content added by the first network function in an extension item or an added field of a certificate based on the IPSc security protocol. The post-quantum public key of the first network function is a post-quantum public-private key pair generated by the first network function locally based on a post-quantum cryptographic algorithm, and here, the post-quantum cryptographic algorithm can be a hash algorithm.
[0056] Step 302, receiving the first authentication certificate sent by the CA center, the first authentication certificate including a first certificate plaintext and a first certificate signature, the first certificate plaintext including the first information, and the first certificate signature being obtained by the CA center in the following manner: calculating a hash digest of the first certificate plaintext based on a post-quantum cryptographic algorithm to obtain a first digest; and signing the first digest with a post-quantum private key of the CA center to obtain the first certificate signature.
[0057] In some embodiments, the first certificate plaintext further includes information such as an authentication certificate issuing authority and an authentication certificate validity period. Here, the CA center adds the certificate issuing authority and the certificate validity date based on the first authentication request file. Specifically, the first certificate plaintext is composed of the first information, the certificate issuing authority, and the certificate validity period.
[0058] In some embodiments, the CA center audits the first authentication request file through online or offline, etc. If the first network function does not pass the verification of the CA center, the CA center returns the first authentication request file to the first network function. If the first network function passes the verification of the CA center, the CA center calculates the hash digest of the first certificate plaintext based on a hash function, i.e., a first digest. The CA center signs the first digest according to a local post-quantum private key to obtain a first certificate signature. The CA center sends the first authentication certificate carrying the first certificate plaintext and the first certificate signature to the first network function. The first network function receives the first authentication certificate sent by the CA center and sends the first authentication certificate to the second network function.
[0059] As can be seen from the above, the security communication method provided by the embodiments of the present application realizes the generation of a post-quantum public-private key pair, signature and verification based on the first information, etc. between the CA center and the first network function in the identity authentication link, so as to resist the attack of a quantum computer on a traditional public key cryptography algorithm.
[0060] In some embodiments, the second authentication certificate includes a second certificate plaintext and a second certificate signature. The second certificate plaintext includes second information, and the second information is the information for verifying the second network function by the CA center. The second certificate signature is obtained by the CA center through the following way: calculating the hash digest of the second certificate plaintext based on a post-quantum cryptography algorithm to obtain a second digest; and signing the second digest by using the post-quantum private key of the CA center to obtain the second certificate signature.
[0061] Here, the second network function generates a post-quantum public-private key pair locally. The second network function applies for an authentication certificate to the CA center based on the IPSc security protocol and sends a second authentication request file to the CA center. The second authentication request file includes the second information. The CA center verifies the legality and credibility of the second network function based on the second information.
[0062] In some embodiments, the second information includes: a domain name of the second network function, an applicant corresponding to the second network function, a post-quantum public key of the second network function, and a trusted measurement value of the second network function; wherein the trusted measurement value of the second network function is content added by the second network function in an extension item or an added field of a certificate based on an IPSec security protocol; and the post-quantum public key of the second network function is a post-quantum public-private key pair generated by the second network function locally based on a post-quantum cryptographic algorithm, where the post-quantum cryptographic algorithm can be a hash algorithm.
[0063] In some embodiments, the second certificate plaintext further includes information such as an authentication certificate issuing authority and an authentication certificate validity period. Here, the CA center adds the certificate issuing authority and the certificate validity date based on the second authentication request file. Specifically, the second certificate plaintext is composed of the second information, the certificate issuing authority, and the certificate validity period.
[0064] In some embodiments, the CA center audits the second authentication request file through online or offline methods, and if the second network function does not pass the verification of the CA center, the CA center returns the second authentication request file to the second network function. If the second network function passes the verification of the CA center, the CA center calculates the second certificate plaintext based on a hash function to obtain a hash digest of the second certificate plaintext, i.e., a second digest. The CA center signs the second digest based on a local post-quantum private key to obtain a second certificate signature. The CA center sends the second authentication certificate carrying the second certificate plaintext and the second certificate signature to the second network function. The second network function receives the second authentication certificate sent by the CA center and sends the second authentication certificate to the first network function.
[0065] As can be seen from the above, the security communication method provided by the embodiments of the present application realizes the generation of a post-quantum public-private key pair, signature and signature verification based on a post-quantum cryptographic algorithm and second information between the CA center and the second network function in the identity authentication link, so as to resist quantum computer attacks on traditional public key cryptographic algorithms.
[0066] In some embodiments, after receiving the second authentication certificate sent by the second network function, the method further comprises: calculating a hash digest of the second certificate plaintext in the second authentication certificate based on a post-quantum cryptographic algorithm to obtain a third digest; verifying the second certificate signature in the second authentication certificate using a post-quantum public key of the CA center to obtain a second digest; and comparing whether the third digest and the second digest are consistent, and if consistent, the first network function passes the authentication of the second network function.
[0067] Here, after the first network function receives the second authentication certificate sent by the second network function, the first network function calculates a hash digest of the second certificate plaintext based on the IPSec security protocol and according to a post-quantum cryptographic algorithm to obtain a third digest. The first network function decrypts and verifies the second certificate signature in the second authentication certificate using a post-quantum public key of the CA center to obtain a decrypted second digest. The first network function compares the values of the third digest and the second digest, and if the values are consistent, the first network function passes the authentication of the second network function, and the authentication of the second network function by the first network function is completed.
[0068] In some embodiments, after the second network function receives the first authentication certificate sent by the first network function, the method further comprises: calculating a hash digest of the first certificate plaintext in the first authentication certificate based on a post-quantum cryptographic algorithm to obtain a fourth digest; verifying the first certificate signature in the first authentication certificate using a post-quantum public key of the CA center to obtain the first digest; and comparing whether the fourth digest and the first digest are consistent, and if consistent, the second network function passes the authentication of the first network function.
[0069] Here, after the second network function receives the first authentication certificate sent by the first network function, the second network function calculates a hash digest of the first certificate plaintext based on the IPSec security protocol and according to a post-quantum cryptographic algorithm to obtain a fourth digest. The second network function decrypts and verifies the first certificate signature in the first authentication certificate using a post-quantum public key of the CA center to obtain a decrypted first digest. The second network function compares the values of the fourth digest and the first digest, and if the values are consistent, the second network function passes the authentication of the first network function, and the authentication of the first network function by the second network function is completed.
[0070] In some embodiments, the first network function authenticates the trusted computing environment of the second network function, the second network function authenticates the trusted computing environment of the first network function, and after the first network function and the second network function pass the authentication, mutual trusted environment authentication of the two parties is completed.
[0071] From the above, the security communication method provided by the embodiment of the application receives the second authentication certificate sent by the second network function through the first network function, calculates a third digest from the second authentication certificate, and verifies the signature of the second certificate by using the public key of the CA center to obtain the second digest, and completes the authentication of the trusted computing environment of the second network function by comparing the values of the two; similarly, the second network function receives the first authentication certificate sent by the first network function, calculates a fourth digest from the first authentication certificate, and verifies the signature of the first certificate by using the public key of the CA center to obtain the first digest, and completes the authentication of the trusted computing environment of the first network function by comparing the values of the two; in this way, the identity authentication link in the implementation of the IPSec security protocol of the network function matched at both ends of the non-service interface is added to authenticate the trusted computing environment of the two network functions, thereby avoiding the network function from being maliciously infected in a specific case and reducing the security risk of the core network being attacked.
[0072] Figure 5 is the flowchart of the security communication method provided by the embodiment of the application Figure 1 As shown in Figure 6 , in step 202, the first network function and the second network function negotiate security parameters through a quantum secure direct communication mode, specifically including:
[0073] Step 401, sending a first security parameter to the second network function through a quantum secure direct communication mode, the first security parameter being a security parameter supported by the first network function.
[0074] Here, the first network function directly sends the first security parameter supported by the first network function to the second network function based on the quantum secure direct communication mode. The second network function demodulates the received first security parameter through the quantum secure direct communication mode, and checks whether the first security parameter information is a security parameter supported by the second network function based on the network function capability level of the second network function. If the second network function supports the first security parameter, the first security parameter passes the check, and the second network function sends first confirmation information to the first network function through the quantum secure direct communication mode. If the second network function does not support the first security parameter, the second network function sends a second security parameter to the first network function through the quantum secure direct communication mode, wherein the second security parameter is a security parameter supported by the second network function.
[0075] In some embodiments, the first security parameter can be a preset arbitrary or non-repetitive random number value (Number once, Nonce) payload information, a session encryption algorithm, a hash algorithm, an identity authentication mode, a security encapsulation protocol, an encapsulation mode, a lifetime, and a security alliance payload information.
[0076] Step 402, if the first network function receives the first confirmation message sent by the second network function through the quantum secure direct communication mode, it is determined that the first security parameter negotiation is successful.
[0077] Here, if the second network function supports the first security parameter, the second network function sends the first confirmation information to the first network function through the quantum secure direct communication mode. If the first network function receives the first confirmation information sent by the second network function through the quantum secure direct communication mode, the security parameter negotiation is successful, that is, the first security parameter.
[0078] Step 403, if the second security parameter sent by the second network function is received through the quantum secure direct communication mode, it is checked whether the first network function supports the second security parameter; if the first network function supports the second security parameter, a second confirmation message is sent to the second network function, and the second confirmation message is used to indicate that the second security parameter negotiation is successful.
[0079] Here, if the second network function does not support the first security parameter, the second network function sends the second security parameter to the first network function through the quantum secure direct communication mode, wherein the second security parameter is a security parameter supported by the second network function. The first network function receives the second security parameter sent by the second network function through the quantum secure direct communication mode, and checks whether the first network function supports the second security parameter based on the network function capability level of the first network function itself. If the first network function supports the second security parameter, a second confirmation message is sent to the second network function, and the second confirmation message is used to indicate that the second security parameter negotiation is successful. If the first network function does not support the second security parameter, the establishment of the security communication tunnel is terminated.
[0080] In some embodiments, the second security parameter can be preset Nonce load information, a session encryption algorithm, a hash algorithm, an identity authentication mode, a security encapsulation protocol, an encapsulation mode, a lifetime, and SA load information.
[0081] From the above, the application provides a secure communication method, the first network function sends the first security parameter supported by the first network function to the second network function through the quantum secure direct communication mode, if the first confirmation message sent by the second network function is received through the quantum secure direct communication mode, it is determined that the first security parameter negotiation is successful, if the second security parameter sent by the second network function is received through the quantum secure direct communication mode, it is checked whether the first network function supports the second security parameter, if the first network function supports the second security parameter, the second confirmation message is sent to the second network function, the second confirmation message is used to indicate that the second security parameter negotiation is successful, in this way, quantum secure direct communication is used in the security parameter negotiation and transmission process, on the one hand, the problem that the Diffie-Hellman key exchange protocol (Diffie-Hellman Key Exchange, DH) algorithm or the domestic commercial cipher (Shangyong Mima2 / 3 / 4, SM2 / 3 / 4) and other asymmetric cipher algorithms cannot resist quantum computer attacks when they are used for session data public key negotiation in the prior art is avoided, on the other hand, the overly complex management overhead of the IKE security channel and IPSec SA establishment of the IPSec security protocol is simplified, and only the session data establishment process of the IPSec tunnel needs to be concerned.
[0082] In some embodiments, the session key is generated using the security parameter, including: generating a basic key parameter using the security parameter, generating a derived session key parameter based on the basic key parameter, and generating a session key based on the derived session key parameter.
[0083] Here, after the security parameter is negotiated between the first network function and the second network function, the first network function uses the post-quantum cryptographic algorithm to generate the basic key parameter using the security parameter as the parameter, generates the derived session key parameter based on the key parameter, and generates the session key using the derived session key parameter and the security parameter. Specifically, the post-quantum cryptographic algorithm can be a hash algorithm, the first network function uses the hash-based message authentication code (HMAC) cryptographic algorithm with key to generate the basic key parameter SKEYID using the Nonce payload information, the data (Cookie) stored locally, and the like as parameters, generates the derived session key parameter SKEYID_d based on the basic key parameter SKEYID, and generates the session key KEYMAT using the derived session key parameter SKEYID_d, the SA payload information, the Nonce payload information, and the like.
[0084] From the above, the security communication method provided by the embodiment of the application, the first network function and the second network function generate basic key parameters by using security parameters, generate derived session key parameters based on the basic key parameters, and generate session keys based on the derived session key parameters; in this way, quantum secure direct communication is used in the security parameter negotiation and transmission and symmetric key exchange process, on the one hand, the problem that the DH algorithm or the asymmetric cryptographic algorithm such as SM2 / 3 / 4 cannot resist quantum computer attacks when the session data public key is negotiated in the prior art is avoided; on the other hand, the overly complex management overhead of the IKE security channel and IPSec SA establishment of the IPSec security protocol is simplified, and only the session data establishment process of the IPSec tunnel needs to be concerned.
[0085] It should be noted that the above scheme for the first network function can also be applied to the second network function, that is, the "first network function" and the "second network function" can be replaced with each other to implement the above scheme.
[0086] Figure 5 is a flow diagram of the security communication method provided by the embodiment of the application Figure 6 As shown in Figure 7 , the security communication method is applied to a CA center, and specifically includes the following steps:
[0087] Step 501, a first authentication certificate is sent to a first network function, and a second authentication certificate is sent to a second network function, the first authentication certificate is used for the second network function to authenticate the first network function, and the second authentication certificate is used for the first network function to authenticate the second network function, wherein the first authentication certificate and the second authentication certificate are issued by the CA center.
[0088] Here, the CA center sends the first authentication certificate to the first network function, and the first network function receives the first authentication certificate signed by the CA center. The first network function sends the first authentication certificate to the second network function. Similarly, the CA center sends the second authentication certificate to the second network function, and the second network function receives the second authentication certificate signed by the CA center. The second network function sends the second authentication certificate to the first network function. The first network function receives the second authentication certificate sent by the second network function and performs trustworthiness authentication on the second network function based on the content of the second authentication certificate. Similarly, the second network function receives the first authentication certificate sent by the first network function and performs trustworthiness authentication on the first network function based on the content of the first authentication certificate. When the first network function confirms that the second network function passes the trustworthiness authentication of the trusted computing environment according to the second authentication certificate, and the second network function confirms that the first network function passes the trustworthiness authentication of the trusted computing environment according to the first authentication certificate, the first network function and the second network function negotiate security parameters through quantum secure direct communication and perform data transmission. The quantum secure direct communication is that the first network function and the second network function receive and / or send data based on the quantum secure direct communication mode, and perform data modulation and demodulation, encapsulation and decapsulation, etc.
[0089] In some embodiments, the first network function and the second network function can be NFs paired through a non-service interface. The first network function can also be referred to as NF1, and the second network function can also be referred to as NF2, which is not specifically limited here. For example, referring to Figure 6 , the first network function is RAN, and the second network function is UPF; or the first network function is AMF, and the second network function is RAN; or the first network function is SMF, and the second network function is UPF.
[0090] As can be seen from the above, the security communication method provided by the embodiments of the present application sends the first authentication certificate to the first network function and the second authentication certificate to the second network function through the CA center. The first authentication certificate is used for the second network function to authenticate the first network function, and the second authentication certificate is used for the first network function to authenticate the second network function. The first authentication certificate and the second authentication certificate are signed by the CA center. In this way, on the one hand, by increasing the trustworthiness authentication of the trusted computing environment of both network functions, the security risk of the core network being attacked after the network function is maliciously infected under certain circumstances is avoided. On the other hand, after the trustworthiness authentication through the trusted computing link, quantum secure direct communication is used in the security parameter transmission process, which avoids the problem that the public key negotiation in the prior art cannot resist the attack of a quantum computer, and simplifies the overly complex management overhead process of establishing a secure channel.
[0091] Figure 7 is a flowchart of the security communication method provided by the embodiments of the present applicationFigure 8 As shown in Figure 7 Step 501, before sending the first authentication certificate to the first network function, the following steps are further included:
[0092] Step 601, receiving the first authentication request file sent by the first network function, the first authentication request file including first information, the first information being information for the CA center to verify the first network function.
[0093] Here, the CA center receives the first authentication request file sent by the first network function. Specifically, the first network function generates a post-quantum public-private key pair locally, applies for an authentication certificate based on the IPSc security protocol to the CA center, and sends the first authentication request file to the CA center, the first authentication request file including the first information. The CA center verifies the legality and credibility of the first network function based on the first information.
[0094] In some embodiments, the first information includes: the domain name of the first network function, the applicant corresponding to the first network function, the post-quantum public key of the first network function, and the trustworthiness measurement value of the first network function; wherein the trustworthiness measurement value of the first network function is content added by the first network function in the extension item or the added field of the certificate based on the IPSc security protocol.
[0095] Step 602, after the first information is verified, calculating a hash digest of the first certificate plaintext based on a post-quantum cryptographic algorithm to obtain a first digest, the first certificate plaintext including the first information; and signing the first digest with the post-quantum private key of the CA center to obtain a first certificate signature.
[0096] Here, the CA center audits the first authentication request file through online or offline methods, and if the first network function fails to pass the verification of the CA center, the CA center returns the first authentication request file to the first network function. If the first network function passes the verification of the CA center, the CA center calculates the hash digest of the first certificate plaintext based on a hash function to obtain the first digest. The CA center signs the first digest according to the local post-quantum private key to obtain the first certificate signature.
[0097] Step 603, generating a first authentication certificate including the first certificate plaintext and the first certificate signature.
[0098] Here, the CA center generates a first authentication certificate including the first certificate plaintext and the first certificate signature, and sends the first authentication certificate carrying the first certificate plaintext and the first certificate signature to the first network function. The first network function receives the first authentication certificate sent by the CA center and sends the first authentication certificate to the second network function.
[0099] In some embodiments, the first certificate plaintext further includes information of an authentication certificate issuing authority, an authentication certificate validity period, and the like. Here, the CA center adds the certificate issuing authority and the certificate validity date on the basis of the first authentication request file. Specifically, the first certificate plaintext is composed of the first information, the certificate issuing authority, and the certificate validity period.
[0100] As can be seen from the above, the security communication method provided by the embodiments of the present application, by the CA center receiving the first authentication request file including the first information sent by the first network function, calculating the hash digest of the first certificate plaintext to obtain the first digest after the first information is verified, and signing the first digest by using the private key of the CA center to obtain the first certificate signature, so as to generate the first authentication certificate including the first certificate plaintext and the first certificate signature and send it to the first network function; in this way, the CA center and the first network function based on the post-quantum cryptography algorithm and the first information and the like are realized to generate, sign, and verify the public and private key pairs in the identity authentication link, so as to achieve the effect of resisting the quantum computer attack on the traditional public key cryptography algorithm.
[0101] Figure 8 is the flowchart of the security communication method provided by the embodiments of the present application Figure 9 As shown in Figure 9 , before the second authentication certificate is sent to the second network function in step 501, the following steps are further included:
[0102] Step 701, receiving the second authentication request file sent by the second network function, the second authentication request file including second information, the second information being the information for the CA center to verify the second network function.
[0103] Here, the CA center receives the second authentication request file sent by the second network function. Specifically, the second network function generates the post-quantum public and private key pair locally, applies for the authentication certificate to the CA center based on the IPSc security protocol, and sends the second authentication request file to the CA center, the second authentication request file including the second information. The CA center verifies the legality and credibility of the second network function based on the second information.
[0104] In some embodiments, the second information includes: the domain name of the second network function, the applicant corresponding to the second network function, the post-quantum public key of the second network function, and the trustworthiness measurement value of the second network function; wherein the trustworthiness measurement value of the second network function is the content added by the second network function in the extension item or the added field of the certificate based on the IPSc security protocol.
[0105] Step 702, after the second information is verified, calculating the hash digest of the second certificate plaintext based on the post-quantum cryptography algorithm to obtain the second digest, the second certificate plaintext including the second information; and signing the second digest by using the private key of the CA center to obtain the second certificate signature.
[0106] The center signs the second digest by using a post-quantum private key to obtain a second certificate signature.
[0107] Here, the CA center audits the second network function by using an online or offline method, and returns the second authentication request file to the second network function if the second network function fails to pass the verification of the CA center. If the second network function passes the verification of the CA center, the CA center calculates the second certificate plaintext by using a hash function to obtain a hash digest of the second certificate plaintext, that is, a second digest. The CA center signs the second digest by using a post-quantum private key to obtain a second certificate signature.
[0108] In step 703, a second authentication certificate including the second certificate plaintext and the second certificate signature is generated.
[0109] Here, the CA center generates a second authentication certificate including the second certificate plaintext and the second certificate signature, and sends the second authentication certificate carrying the second certificate plaintext and the second certificate signature to the second network function. The second network function receives the second authentication certificate sent by the CA center, and sends the second authentication certificate to the first network function.
[0110] In some embodiments, the second certificate plaintext further includes information such as a certificate issuing authority and a certificate validity period. Here, the CA center adds the certificate issuing authority and the certificate validity date on the basis of the second authentication request file. Specifically, the second certificate plaintext is composed of the second information, the certificate issuing authority, and the certificate validity period.
[0111] As can be seen from the above, the security communication method provided by the embodiments of the present application receives the second authentication request file including the second information sent by the second network function through the CA center, calculates a hash digest of the second certificate plaintext to obtain a second digest after the second information passes the verification, and signs the second digest by using a private key of the CA center to obtain a second certificate signature, so as to generate a second authentication certificate including the second certificate plaintext and the second certificate signature and send the second authentication certificate to the second network function. In this way, the CA center and the second network function generate, sign, and verify a public-private key pair based on a post-quantum cryptographic algorithm and the second information in the identity authentication link, so as to resist quantum computer attacks on traditional public key cryptographic algorithms.
[0112] Embodiment one
[0113] Figure 10 is a flowchart of the security communication method provided by the embodiments of the present application Figure 1 As shown in Figure 10 is a whole flowchart of the security communication method provided by the embodiments of the present application, which is applied to a first network function NF1, a second network function NF2, and a CA center. The NF1 and the NF2 are core network non-service interface paired NFs, and specifically include the following steps:
[0114] Step 801, NF1 locally generates a post-quantum public-private key pair, and applies for a certificate of authentication to the CA center.
[0115] Here, NF1 sends a first authentication request file to the CA center, and the first authentication request file includes first information, which is information for the CA center to verify NF1.
[0116] Step 802, the CA center audits the authentication request file through online / offline and other ways, adds information such as the issuing authority and the validity period to the certificate plaintext information, then hashes, and then signs with the local post-quantum private key.
[0117] Here, the CA center receives the first authentication request file sent by NF1, which includes the first information, verifies the first information through online / offline and other ways, calculates the hash digest of the first certificate plaintext after the first information is verified, obtains the first digest, and signs the first digest with the local post-quantum private key of the CA center to obtain the first certificate signature.
[0118] Step 803, the CA center issues a certificate, and returns the certificate plaintext information and the signed information to NF1.
[0119] Here, the CA center generates a first authentication certificate including the first certificate plaintext and the first certificate signature, and sends the first authentication certificate to NF1.
[0120] Step 804, NF2 adopts similar steps in 801-803 to perform legitimacy and trusted authentication.
[0121] Here, NF2 sends a second authentication request file to the CA center, and the second authentication request file includes second information, which is information for the CA center to verify NF2. The CA center receives the second authentication request file sent by NF2, which includes the second information, verifies the second information through online / offline and other ways, calculates the hash digest of the second certificate plaintext after the second information is verified, obtains the second digest, and signs the second digest with the local post-quantum private key of the CA center to obtain the second certificate signature. The CA center generates a second authentication certificate including the second certificate plaintext and the second certificate signature, and sends the second authentication certificate to NF2.
[0122] Step 805, NF1 sends the certificate authenticated by the CA center to NF2.
[0123] Here, NF1 sends the first authentication certificate audited by the CA center to NF2.
[0124] Step 806, NF2 calculates the hash digest value of the plaintext information in the certificate of NF1, and uses the post-quantum public key of the CA certificate to decrypt the signature comparison to authenticate NF1.
[0125] Here, after NF2 receives the first authentication certificate sent by NF1, NF2 calculates the hash digest of the plaintext of the first certificate based on the IPSec security protocol to obtain a fourth digest. NF2 decrypts the first certificate signature in the first authentication certificate using the post-quantum public key of the CA center to obtain the decrypted first digest. NF2 compares the values of the fourth digest and the first digest, and if the values are consistent, NF2 authenticates NF1 successfully, completing the authentication of NF1 by NF2.
[0126] Step 807, using similar steps in 805-806, NF1 authenticates NF2, and after passing, the peer NF completes mutual authentication.
[0127] Here, after NF1 receives the second authentication certificate sent by NF2, NF1 calculates the hash digest of the plaintext of the second certificate based on the IPSec security protocol to obtain a third digest. NF1 decrypts the second certificate signature in the second authentication certificate using the post-quantum public key of the CA center to obtain the decrypted second digest. NF1 compares the values of the third digest and the second digest, and if the values are consistent, NF1 authenticates NF2 successfully, completing the authentication of NF2 by NF1.
[0128] Step 808, NF1 sends the first security parameter information to NF2 through quantum secure direct communication.
[0129] Here, after NF1 and NF2 successfully authenticate each other, data information is transmitted through quantum secure direct communication.
[0130] Here, the first security parameter can be Nonce payload information, session encryption algorithm, hash algorithm, identity authentication method, security encapsulation protocol, encapsulation mode, lifetime, security alliance payload information.
[0131] Step 809, NF2 receives and demodulates the above-mentioned first security parameter information in step 808 through quantum secure direct communication, and then checks according to its own NF capability level to return first confirmation information or second security parameter.
[0132] Here, if NF2 does not support the first security parameter, NF2 sends the second security parameter to NF1 through quantum secure direct communication; if NF2 supports the first security parameter, the security parameter negotiation is successful, and the first confirmation information is returned to NF1.
[0133] Step 810, NF1 receives and demodulates the first confirmation information or the second security parameter returned by NF2 through the quantum secure direct communication mode; if the second security parameter is received, it is checked whether the second security parameter information can be supported; if supported, the second confirmation information is returned to NF2.
[0134] Here, NF1 receives the second security parameter sent by NF2 through the quantum secure direct communication mode, and checks whether the second security parameter is supported based on the network function capability level of NF1 itself. If NF1 supports the second security parameter, the second confirmation information is sent to NF2, and the second confirmation information is used to indicate that the second security parameter negotiation is successful. If NF1 does not support the second security parameter, the establishment of the secure communication tunnel is terminated.
[0135] Step 811, NF1 and NF2 use the HMAC cryptographic algorithm to generate a basic key parameter, and then derive a session key parameter and a session key.
[0136] Here, NF1 and NF2 use the HMAC cryptographic algorithm to generate a basic key parameter SKEYID using Nonce payload information, Cookie, etc. as parameters, generate a derived session key parameter SKEYID_d based on the key parameter SKEYID, and generate a session key KEYMAT using the derived session key parameter SKEYID_d, SA payload information, Nonce payload information, etc.
[0137] Step 812, NF1 and NF2 perform subsequent session security message communication according to the "National Cryptographic GM / T 0022 IPSec VPN Technical Specification".
[0138] Step 813, after the survival time is reached, steps similar to 808-811 are repeated to perform rehandshake of the protocol parameters of the peer NF.
[0139] Embodiment two
[0140] Figure 10 It is a system device schematic diagram of the secure communication method provided by the embodiment of the application, applied to a first network function NF1, a second network function NF2 and a CA center, wherein the NF1 and the NF2 are core network non-service interface paired NFs. As shown in Figure 10 The secure communication system 900 is applied to the CA center, the NF1 and the NF2. The secure communication system 900 comprises a network function processing module 901 for performing 5G core network element network function processing, containing processing of control plane and user plane data of the core network.
[0141] The secure communication system 900 further comprises an IPSec security protocol cluster processing module 902, a post-quantum processing module 903, a quantum secure direct communication processing module 904, and a data processing and payload encapsulation forwarding module 905.
[0142] The network function processing module 901 is configured to perform network function processing of a 5G core network element, and mainly perform processing of control plane and user plane data of a core network NF that is not service-oriented interface matched.
[0143] The IPSec security protocol cluster processing module 902 is configured to perform processing of an IPSec security protocol cluster in the core network NF, including identity authentication, data integrity and data source authentication, data confidentiality and anti-replay attack processing, and further adapted to interface with the post-quantum processing module 903 and the quantum secure direct communication processing module 904 for interface communication.
[0144] The post-quantum processing module 903 is configured to generate post-quantum public and private keys resistant to quantum attacks, perform signature verification processing of post-quantum cryptographic algorithms, and adapt to the interface of the IPSec security protocol cluster processing module 902 for calling.
[0145] The quantum secure direct communication processing module 904 is configured to perform data modulation and demodulation, encapsulation and decapsulation of quantum secure direct communication receiving and sending, and adapt to the interface of the IPSec security protocol cluster processing module 902 for calling.
[0146] The data processing and payload encapsulation forwarding module 905 is configured to perform packetization, encapsulation and forwarding of session data processed by the IPSec security protocol cluster, receive, decapsulate and unpack the peer device, and perform IP routing.
[0147] Figure 11 Figure 1 is a structural composition diagram of a secure communication device provided by an embodiment of the present application Figure 2 The secure communication device 1000 is applied to a first network function, as shown in Figure 11 The secure communication device 1000 comprises:
[0148] A sending unit 1001 is configured to send a first authentication certificate to a second network function; the first authentication certificate is used for the second network function to authenticate the first network function.
[0149] A receiving unit 1002 is configured to receive a second authentication certificate sent by the second network function; the second authentication certificate is used for the first network function to authenticate the second network function; and the first authentication certificate and the second authentication certificate are issued by a CA center.
[0150] The processing unit 1003 is configured to, if the mutual authentication between the first network function and the second network function is passed, negotiate a security parameter between the first network function and the second network function through a quantum secure direct communication mode, and generate a session key by using the security parameter, where the session key is used for the first network function and the second network function to perform secure communication of a message.
[0151] In some embodiments, before the sending unit 1001 sends the first authentication certificate to the second network function, the sending unit 1001 is further configured to send a first authentication request file to a CA center, where the first authentication request file includes first information, and the first information is information for the CA center to verify the first network function.
[0152] In some embodiments, the receiving unit 1002 is further configured to receive the first authentication certificate sent by the CA center, where the first authentication certificate includes a first certificate plaintext and a first certificate signature, the first certificate plaintext includes the first information, and the first certificate signature is obtained by the CA center in the following manner: calculating a hash digest of the first certificate plaintext based on a post-quantum cryptographic algorithm to obtain a first digest; and signing the first digest by using a post-quantum private key of the CA center to obtain the first certificate signature.
[0153] In some embodiments, the second authentication certificate includes a second certificate plaintext and a second certificate signature, the second certificate plaintext includes second information, and the second information is information for the CA center to verify the second network function, and the second certificate signature is obtained by the CA center in the following manner: calculating a hash digest of the second certificate plaintext based on a post-quantum cryptographic algorithm to obtain a second digest; and signing the second digest by using a post-quantum private key of the CA center to obtain the second certificate signature.
[0154] In some embodiments, after the receiving unit 1002 receives the second authentication certificate sent by the second network function, the processing unit 1003 is further configured to calculate a hash digest of the second certificate plaintext in the second authentication certificate to obtain a third digest; verify the second certificate signature in the second authentication certificate by using a public key of the CA center to obtain the second digest; and compare whether the third digest and the second digest are consistent, and if the third digest and the second digest are consistent, the first network function passes the authentication of the second network function.
[0155] In some embodiments, the sending unit 1001 is further configured to send a first security parameter to the second network function through a quantum secure direct communication mode, where the first security parameter is a security parameter supported by the first network function.
[0156] In some embodiments, the receiving unit 1002 is further configured to, if the first confirmation message sent by the second network function is received through the quantum secure direct communication manner, determine that the first security parameter negotiation is successful; if the second security parameter sent by the second network function is received through the quantum secure direct communication manner, check whether the first network function supports the second security parameter; and if the first network function supports the second security parameter, send a second confirmation message to the second network function, where the second confirmation message is used to indicate that the second security parameter negotiation is successful.
[0157] In some embodiments, the processing unit 1003 is further configured to generate a basic key parameter by using the security parameter, generate a derived session key parameter based on the basic key parameter, and generate a session key based on the derived session key parameter.
[0158] Those skilled in the art should understand that, Figure 11 The implementation functions of each unit in the secure communication apparatus shown can be understood with reference to the related description of the foregoing method. Figure 11 The functions of each unit in the secure communication apparatus shown can be implemented by a program running on a processor, or by a specific logic circuit.
[0159] Figure 12 is a structural composition of the secure communication apparatus provided by the embodiments of the present application Figure 12 and is applied to a CA center, as shown in the figure, the secure communication apparatus 1100 comprises: Figure 12
[0160] The sending unit 1101 is configured to send a first authentication certificate to the first network function and send a second authentication certificate to the second network function, the first authentication certificate is used for the second network function to authenticate the first network function, the second authentication certificate is used for the first network function to authenticate the second network function, and the first authentication certificate and the second authentication certificate are issued by the CA center.
[0161] The secure communication apparatus 1100 further comprises a receiving unit 1102 configured to receive a first authentication request file sent by the first network function, the first authentication request file comprising first information, and the first information being information for the CA center to verify the first network function.
[0162] The secure communication apparatus 1100 further comprises a processing unit 1103 configured to, after the first information is verified, calculate a hash digest of a first certificate plaintext based on a post-quantum cryptographic algorithm to obtain a first digest, and the first certificate plaintext comprises the first information; and sign the first digest by using a post-quantum private key of the CA center to obtain a first certificate signature.
[0163] The processing unit 1103 is further configured to generate a first authentication certificate including the first certificate plaintext and the first certificate signature.
[0164] The receiving unit 1102 is further configured to receive a second authentication request file sent by the second network function, the second authentication request file including second information, the second information being information for verifying the second network function by the CA center.
[0165] The processing unit 1103 is further configured to, after the second information is verified, calculate a hash digest of a second certificate plaintext based on a post-quantum cryptographic algorithm, to obtain a second digest, the second certificate plaintext including the second information; and sign the second digest by using a post-quantum private key of the CA center, to obtain a second certificate signature.
[0166] The processing unit 1103 is further configured to generate a second authentication certificate including the second certificate plaintext and the second certificate signature.
[0167] Those skilled in the art should understand that, Figure 12 The implementation functions of the units in the secure communication apparatus shown can be understood with reference to the related descriptions of the foregoing method. The functions of the units in the secure communication apparatus shown can be implemented by a program running on a processor, or by a specific logic circuit.
[0168] is a schematic structural diagram of a network device 1200 provided by an embodiment of the present application. The network device 1200 shown includes a processor 1210, which can invoke and run a computer program from a memory to implement the method in the embodiments of the present application.
[0169] Optionally, as shown, The network device 1200 can further include a memory 1220. The processor 1210 can invoke and run a computer program from the memory 1220 to implement the method in the embodiments of the present application.
[0170] The memory 1220 can be a separate device independent of the processor 1210, or can be integrated in the processor 1210.
[0171] Optionally, as shown, The network device 1200 can further include a transceiver 1230, and the processor 1210 can control the transceiver 1230 to communicate with other devices, specifically, to send information or data to other devices, or to receive information or data sent by other devices.
[0172] The transceiver 1230 can include a transmitter and a receiver. The transceiver 1230 can further include an antenna, and the number of antennas can be one or more.
[0173] Optionally, the network device 1200 can be specifically a network device of the embodiments of the present application, and the network device 1200 can implement the corresponding processes implemented by the network device in each method of the embodiments of the present application. For brevity, details are not repeated here.
[0174] It should be understood that the processor of the embodiments of the present application can be an integrated circuit chip having a processing capability of a signal. In the implementation process, each step of the above method embodiments can be completed by integrated logic circuits of hardware or instructions in the form of software in the processor. The processor mentioned above can be a general processor, a digital signal processor (Digital Signal Processor, DSP), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register or other mature storage medium in the art. The storage medium is located in the memory, and the processor reads the information in the memory, and combines the hardware to complete the steps of the above method.
[0175] It is to be understood that the memory in the embodiments of the present application can be a volatile memory or a nonvolatile memory, or can include both volatile and nonvolatile memory. Among them, the nonvolatile memory can be a read-only memory (Read-Only Memory, ROM), a programmable read-only memory (Programmable ROM, PROM), an erasable programmable read-only memory (Erasable PROM, EPROM), an electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) or a flash memory. The volatile memory can be a random access memory (Random Access Memory, RAM) used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (Static RAM, SRAM), dynamic random access memory (Dynamic RAM, DRAM), synchronous dynamic random access memory (Synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (Synchlink DRAM, SLDRAM) and direct memory bus random access memory (Direct Rambus RAM, DR RAM). It should be noted that the memory of the system and method described herein is intended to include, but not limited to, these and any other suitable types of memory.
[0176] It should be understood that the above-mentioned memory is exemplary but not limiting, for example, the memory in the embodiments of the present application can also be static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (synch link DRAM, SLDRAM) and direct memory bus random access memory (Direct Rambus RAM, DR RAM) and the like. That is, the memory in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
[0177] The embodiment of the present application further provides a computer readable storage medium for storing the computer program.
[0178] Optionally, the computer readable storage medium can be applied to the network device in the embodiment of the present application, and the computer program makes the computer execute the corresponding process realized by the network device in the various methods of the embodiment of the present application, which will not be repeated here for the sake of brevity.
[0179] Optionally, the computer readable storage medium can be applied to the mobile terminal / terminal device in the embodiment of the present application, and the computer program makes the computer execute the corresponding process realized by the mobile terminal / terminal device in the various methods of the embodiment of the present application, which will not be repeated here for the sake of brevity.
[0180] The embodiment of the present application further provides a computer program product comprising computer program instructions.
[0181] Optionally, the computer program product can be applied to the network device in the embodiment of the present application, and the computer program instructions make the computer execute the corresponding process realized by the network device in the various methods of the embodiment of the present application, which will not be repeated here for the sake of brevity.
[0182] Optionally, the computer program product can be applied to the mobile terminal / terminal device in the embodiment of the present application, and the computer program instructions make the computer execute the corresponding process realized by the mobile terminal / terminal device in the various methods of the embodiment of the present application, which will not be repeated here for the sake of brevity.
[0183] The embodiment of the present application further provides a computer program.
[0184] Optionally, the computer program can be applied to the network device in the embodiment of the present application, and when the computer program runs on the computer, makes the computer execute the corresponding process realized by the network device in the various methods of the embodiment of the present application, which will not be repeated here for the sake of brevity.
[0185] Optionally, the computer program can be applied to the mobile terminal / terminal device in the embodiment of the present application, and when the computer program runs on the computer, makes the computer execute the corresponding process realized by the mobile terminal / terminal device in the various methods of the embodiment of the present application, which will not be repeated here for the sake of brevity.
[0186] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0187] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.
[0188] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are merely schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0189] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0190] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.
[0191] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the technical solutions that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0192] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A secure communication method, characterized by, The method is applied to a first network function, and comprises the following steps: sending a first authentication certificate to a second network function, the first authentication certificate being used for authentication of the first network function by the second network function; receiving a second authentication certificate sent by the second network function, the second authentication certificate being used for authentication of the second network function by the first network function; wherein the first authentication certificate and the second authentication certificate are issued by a certificate authority (CA) center; if mutual authentication between the first network function and the second network function is passed, then the first network function and the second network function negotiate security parameters through a quantum secure direct communication mode, and generate a session key by using the security parameters, the session key being used for secure communication of messages between the first network function and the second network function.
2. The method of claim 1, wherein, Before the step of sending the first authentication certificate to the second network function, the method comprises the following steps: sending a first authentication request file to the CA center, the first authentication request file comprising first information, the first information being information used for verification of the first network function by the CA center; receiving the first authentication certificate sent by the CA center, the first authentication certificate comprising a first certificate plaintext and a first certificate signature, the first certificate plaintext comprising the first information, and the first certificate signature being obtained by the CA center through the following manner: calculating a hash digest of the first certificate plaintext based on a post-quantum cryptographic algorithm to obtain a first digest; and signing the first digest by using a post-quantum private key of the CA center to obtain the first certificate signature.
3. The method of claim 1, wherein, The second authentication certificate comprises a second certificate plaintext and a second certificate signature, the second certificate plaintext comprising second information, the second information being information used for verification of the second network function by the CA center, and the second certificate signature being obtained by the CA center through the following manner: calculating a hash digest of the second certificate plaintext based on a post-quantum cryptographic algorithm to obtain a second digest; and signing the second digest by using a post-quantum private key of the CA center to obtain the second certificate signature.
4. The method of claim 3, wherein, After the step of receiving the second authentication certificate sent by the second network function, the method further comprises the following steps: calculating a hash digest of the second certificate plaintext in the second authentication certificate based on a post-quantum cryptographic algorithm to obtain a third digest; verifying the second certificate signature in the second authentication certificate by using a post-quantum public key of the CA center to obtain the second digest; comparing whether the third digest and the second digest are consistent, and if so, then the first network function passes the authentication of the second network function.
5. The method of claim 1, wherein, The negotiation of the security parameters between the first network function and the second network function through the quantum secure direct communication mode comprises the following steps: sending a first security parameter to the second network function through the quantum secure direct communication mode, the first security parameter being a security parameter supported by the first network function; if a first confirmation message sent by the second network function is received through the quantum secure direct communication mode, then it is determined that the negotiation of the first security parameter is successful. If the second security parameter sent by the second network function is received through the quantum secure direct communication mode, it is checked whether the first network function supports the second security parameter; if the first network function supports the second security parameter, a second confirmation message is sent to the second network function, and the second confirmation message is used to indicate that the second security parameter negotiation is successful.
6. The method according to any one of claims 1 to 5, characterized in that, The generating the session key by using the security parameter comprises: Generating a basic key parameter by using the security parameter, generating a derived session key parameter based on the basic key parameter, and generating a session key based on the derived session key parameter.
7. A secure communication method characterized by, The method applied to the CA center comprises: sending a first authentication certificate to a first network function and a second authentication certificate to a second network function, the first authentication certificate being used for the second network function to authenticate the first network function, and the second authentication certificate being used for the first network function to authenticate the second network function, wherein the first authentication certificate and the second authentication certificate are issued by the CA center.
8. The method of claim 7, wherein, Before the first authentication certificate is sent to the first network function, the method further comprises: receiving a first authentication request file sent by the first network function, the first authentication request file comprising first information, the first information being information for the CA center to verify the first network function; after the first information is verified, calculating a hash digest of a first certificate plaintext based on a post-quantum cryptographic algorithm to obtain a first digest, the first certificate plaintext comprising the first information, and signing the first digest by using a post-quantum private key of the CA center to obtain a first certificate signature; generating the first authentication certificate comprising the first certificate plaintext and the first certificate signature.
9. The method of claim 7, wherein, Before the second authentication certificate is sent to the second network function, the method further comprises: receiving a second authentication request file sent by the second network function, the second authentication request file comprising second information, the second information being information for the CA center to verify the second network function; after the second information is verified, calculating a hash digest of a second certificate plaintext based on a post-quantum cryptographic algorithm to obtain a second digest, the second certificate plaintext comprising the second information, and signing the second digest by using a post-quantum private key of the CA center to obtain a second certificate signature; generating the second authentication certificate comprising the second certificate plaintext and the second certificate signature.
10. A secure communication device, characterized by The device applied to the first network function comprises: a sending unit configured to send a first authentication certificate to a second network function, the first authentication certificate being used for the second network function to authenticate the first network function; a receiving unit configured to receive a second authentication certificate sent by the second network function, the second authentication certificate being used for the first network function to authenticate the second network function; wherein the first authentication certificate and the second authentication certificate are issued by a certificate authority (CA) center. The processing unit is configured to, if mutual authentication between the first network function and the second network function is passed, negotiate security parameters between the first network function and the second network function through a quantum secure direct communication mode, and generate a session key by using the security parameters, the session key being used for secure communication of messages between the first network function and the second network function.
11. A secure communication device, characterized by The device is applied to a CA center, and the device comprises: The sending unit is configured to send a first authentication certificate to the first network function and send a second authentication certificate to the second network function, the first authentication certificate being used for authentication of the first network function by the second network function, and the second authentication certificate being used for authentication of the second network function by the first network function, wherein the first authentication certificate and the second authentication certificate are issued by the CA center.
12. A network device, comprising: The device comprises: A processor and a memory for storing a computer program, the processor being configured to invoke and run the computer program stored in the memory to execute the method according to any one of claims 1 to 9.
13. A computer-readable storage medium, characterized in that, A computer program for causing a computer to execute the method according to any one of claims 1 to 9.
14. A computer program product, characterised in that, Computer program instructions for causing a computer to execute the method according to any one of claims 1 to 9.