Non-access stratum (NAS) signaling decryption method, electronic equipment and storage medium

By obtaining a security context list that uniquely identifies the target user, the problem of low NAS decryption efficiency and low accuracy under the 4G/5G converged network architecture is solved, and cross-network architecture compatibility and decryption efficiency are improved.

CN121486801APending Publication Date: 2026-02-06ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411071443.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-05
Publication Date
2026-02-06

AI Technical Summary

Technical Problem

Existing NAS decryption methods cannot effectively cope with the complexity and diversity of 4G/5G converged network architecture, resulting in low decryption efficiency and low accuracy. In particular, in out-of-order scenarios, incorrect key matching seriously affects the accuracy and reliability of NAS decryption.

Method used

By receiving NAS signaling from the first target interface, a list of target security contexts corresponding to the unique identifier of the target user is obtained, which includes security contexts of at least one network standard. The matching security context is selected and decrypted according to the network standard, reducing unnecessary context switching and lookup time, and achieving compatibility across network architectures.

Benefits of technology

It significantly improves decryption efficiency and accuracy, ensures the flexibility and reliability of decryption operations in multi-network converged environments, avoids key mismatch issues, and improves the efficiency and reliability of NAS signaling decryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121486801A_ABST
    Figure CN121486801A_ABST
Patent Text Reader

Abstract

The invention provides a non-access stratum (NAS) signaling decryption method, electronic equipment and a storage medium, and the method comprises the steps: firstly receiving an NAS signaling from a first target interface, and then obtaining a target user unique identifier corresponding to the NAS signaling and a target security context list corresponding to the target user unique identifier, the target security context list comprises a security context of at least one network type, then determining a target security context corresponding to the network type of the first target interface according to the target security context list, and then decrypting the NAS signaling through the target security context. According to the embodiment of the invention, the matched security context can be intelligently selected to decrypt the NAS signaling in allusion to a multi-system network convergence networking scene, so that unnecessary security context switching and searching time is reduced, and the decryption efficiency and accuracy of the NAS signaling are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to, but are not limited to, the technical field of communication, and in particular to a non-access stratum (NAS) signaling decryption method, an electronic device, a computer readable storage medium, and a computer program product. BACKGROUND

[0002] In the deep operation of a mobile communication network, non-access stratum (NAS) signaling is a core bridge for communication between a user equipment (UE) and an access and mobility management function (AMF) / mobility management entity (MME), and data exchange thereof is an indispensable cornerstone for deep network analysis and business insight by a deep packet inspection (DPI) collection system. In order to ensure the safe and worry-free operation of the network and the accurate and error-free data transmission, the core network implements strict integrity verification and encryption measures on the NAS signaling. However, this security mechanism also gives rise to an urgent need for NAS decryption technology.

[0003] The main challenges faced by current NAS decryption methods include architectural limitations. Existing decryption solutions are often limited to a single network architecture, such as 4G NAS decryption relying only on keys obtained from internal interfaces of a 4G network, and 5G NAS decryption relying only on internal interfaces of a 5G network. This design ignores the complexity and diversity in 4G / 5G converged network architecture and 4G / 5G interoperation scenarios, resulting in the inability of existing methods to effectively deal with such scenarios. SUMMARY

[0004] Embodiments of the present application provide a non-access stratum (NAS) signaling decryption method, an electronic device, a computer readable storage medium, and a computer program product, which can reduce unnecessary security context switching and lookup time, thereby improving the decryption efficiency and accuracy of NAS signaling.

[0005] In one aspect, the present application provides a non-access stratum (NAS) signaling decryption method, comprising: receiving NAS signaling from a first target interface; obtaining a target user unique identifier corresponding to the NAS signaling, and obtaining a target security context list corresponding to the target user unique identifier, wherein the target security context list includes security contexts of at least one network standard; determining a target security context corresponding to a network standard of the first target interface according to the target security context list; and decrypting the NAS signaling through the target security context.

[0006] In another aspect, an electronic device is provided and includes one or more processors and a memory storing one or more programs, when executed by the one or more processors, cause the one or more processors to implement the non-access stratum (NAS) signaling decryption method described above.

[0007] In another aspect, a computer-readable storage medium is provided and stores a computer program, when executed by a processor, implements the non-access stratum (NAS) signaling decryption method described above.

[0008] In another aspect, a computer program product is provided and includes a computer program, when executed by a processor, implements the non-access stratum (NAS) signaling decryption method described above.

[0009] In the embodiments of the present application, the NAS signaling from the first target interface is received first, and then the target user unique identifier corresponding to the NAS signaling is obtained, and the target security context list corresponding to the target user unique identifier is obtained, wherein the target security context list includes security contexts of at least one network mode. Since the target security context list includes security contexts of at least one network mode, even in a multi-network integration environment, the security context matching the network mode of the current interface can be intelligently selected and applied to decryption according to the target security context list, thereby reducing unnecessary security context switching and search time, and further improving the decryption efficiency. Further, after determining the target security context corresponding to the network mode of the first target interface according to the target security context list, the NAS signaling can be decrypted by the target security context. The embodiments of the present application achieve compatibility across network architectures by receiving the NAS signaling from the first target interface and being able to associate the target user unique identifier to the target security context list including security contexts of multiple network modes. In the decryption process, the embodiments directly select the matching security context for decryption according to the network mode to which the NAS signaling belongs (i.e., the network mode of the first target interface). Not only can the unnecessary context switching and search links be greatly reduced, thereby significantly improving the decryption efficiency, but also the accuracy and reliability of the decryption operation can be ensured through the directly associated security context. BRIEF DESCRIPTION OF DRAWINGS

[0010] Figure 1 is a 4G / 5G fusion networking architecture applied in related technologies; Figure 2 is a flowchart of the non-access stratum (NAS) signaling decryption method provided by an embodiment of the present application; Figure 3 is a flowchart of the non-access stratum (NAS) signaling decryption method provided by an embodiment of the present application; Figure 2A specific flowchart of step S230 is shown in the following figure; Figure 4 A flowchart of acquiring a target security context according to an embodiment of the present application is shown in the following figure; Figure 5 A flowchart of acquiring a target security context according to an embodiment of the present application is shown in the following figure; Figure 6 A flowchart of creating a security context list corresponding to a user unique identifier according to an embodiment of the present application is shown in the following figure; Figure 7 A flowchart of creating a security context list corresponding to a user unique identifier according to an embodiment of the present application is shown in the following figure; Figure 8 A flowchart of creating a security context list corresponding to a user unique identifier according to an embodiment of the present application is shown in the following figure; Figure 9 A flowchart of creating, updating and querying a security context according to an embodiment of the present application is shown in the following figure; Figure 10 A flowchart of maintaining a user unique identifier and feature parameter relationship list according to an embodiment of the present application is shown in the following figure; Figure 11 A flowchart of creating and querying a user unique identifier and feature parameter relationship list according to an embodiment of the present application is shown in the following figure; Figure 12 A flowchart of NAS signaling decryption process according to an embodiment of the present application is shown in the following figure; Figure 13 A NAS signaling decryption processing module according to an embodiment of the present application is shown in the following figure; Figure 14 A schematic diagram of an electronic device according to an embodiment of the present application is shown in the following figure. DETAILED DESCRIPTION

[0011] In order to make the purpose, technical method and advantages of the present application more clear, the present application is further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0012] It should be noted that although the logical order is shown in the flowchart, in some cases, the steps shown or described can be performed in an order different from that in the flowchart. In the description of the specification and claims and the above description of the drawings, the meaning of multiple (or multiple) is more than two, greater than, less than, more than, etc. is understood as not including the number, above, below, within, etc. is understood as including the number. If it is described as "first", "second", etc., it is only used to distinguish the technical features for the purpose, and cannot be understood as indicating or implying the relative importance or implicitly indicating the number of indicated technical features or implicitly indicating the sequence of indicated technical features.

[0013] Multi-network convergence typically refers to the integration of different network technologies into a unified system in the field of wireless communication to provide wider coverage, higher data rates, and better quality of service. This convergence can include multiple different network technologies, such as the convergence of 4G and 5G networks, or the integration of different generations of cellular network technologies, allowing users to seamlessly switch between different networks.

[0014] Given the current scale of communication networks and the future evolution of technologies, the commercialization of 5G has been carefully designed as a long and complex process of replacement, upgrading and iteration. In this process, the strategy of 4G and 5G coexistence has become an inevitable choice to ensure a smooth transition of network experience for both new and old users, and will continue for a considerable period of time.

[0015] See Figure 1 , Figure 1This diagram illustrates a 4G / 5G converged network architecture used in related technologies. This architecture overlays a 5G core network (5GC) onto a 4G network and achieves seamless interoperability between the 4G and 5G networks through the N26 interface, significantly accelerating the market rollout and deployment of 5G services. In this architecture, the core of the 4G mobile communication network consists of the Evolved Packet Core (EPC). The EPC network integrates a series of key network elements and interfaces, specifically including: the Mobility Management Entity (MME), the Serving Gateway (SGW), the Packet Data Network Gateway (PGW), the evolved NodeB (eNB), and the Home Subscriber Server (HSS). These network elements are closely connected through multiple key interfaces. For example, the S1-U interface is responsible for the transmission of user equipment data between the eNB and the S / P-GW; the S1MME interface carries the control signaling between the eNB and the MME, including NAS signaling and key communication between the eNodeB and the MME; the S6a interface is used for information exchange between the MME and the HSS, covering key information such as user authentication, service subscription and location update; the S10 interface facilitates context sharing and handover control between MMEs; and the S11 interface ensures smooth information flow between the MME and the S / P-GW. The core components of the 5G network architecture include the Access and Mobility Management Function (AMF), Session Management Function (SMF), Gateway Control (GW-C), Authentication Server Function (AUSF), and a series of key interfaces such as N1N2 (between UE, gNB, and AMF), N11 (between AMF and SMF / GW-C), N12 (between AMF and AAUSF), and N14 (between AMFs). These interfaces work together to support the efficient operation of the 5G network. In particular, the N1N2 interface, acting as a bridge between the gNodeB (gNB, i.e., the 5G base station) and the AMF, undertakes crucial control plane functions; the N11 interface facilitates flexible interaction and coordination between network functions, ensuring smooth management of service sessions; and the N12 and N14 interfaces are respectively used to enhance information exchange in the authentication process and necessary coordination between AMFs. This tight integration of components and interfaces constitutes the core competitiveness of the 5G network.User equipment (UE) can initiate an access request to a selected network (such as a 4G or 5G base station) to access the 4G / 5G converged network architecture.

[0016] NAS signaling is a communication protocol between User Equipment (UE) and the core network, primarily handling tasks such as mobility management, session management, service requests, and security control. NAS signaling is independent of radio access technology, meaning it can be used in different radio access networks (such as 4G and 5G). In 4G / 5G converged network architectures, NAS signaling is mainly transmitted between the UE and the MME / AMF. To ensure the security and reliability of the mobile communication network, the core network performs integrity protection and encryption on NAS signaling. It is worth noting that NAS signaling serves as a fundamental data source for deep packet inspection (DPI) acquisition systems for network monitoring, service analysis, and performance optimization; the accuracy and accessibility of its content are crucial for improving overall network management efficiency. Therefore, developing efficient NAS decryption methods is a key step in parsing and analyzing NAS signaling content, thereby optimizing network performance and enhancing security.

[0017] However, current NAS signaling decryption methods face the following main challenges: (1) Architectural limitations: Existing decryption schemes are often limited to a single network architecture. For example, 4G NAS decryption relies solely on keys obtained from the internal interface of the 4G network, while 5G NAS decryption relies solely on the internal interface of the 5G network. This design ignores the complexity and diversity of 4G and 5G interoperability scenarios under the 4G / 5G converged network architecture, making existing methods unable to effectively handle such scenarios. (2) Insufficient handling of out-of-order scenarios: During the processing of NAS signaling in the DPI acquisition system, due to factors such as network transmission delay and differences in processing mechanisms, signaling from different interfaces may exhibit out-of-order behavior. Given that different service scenarios may require the use of keys from different interfaces for decryption, out-of-order issues may lead to incorrect key matching, thereby seriously affecting the accuracy and reliability of NAS decryption.

[0018] To reduce unnecessary context switching and lookup steps and improve the decryption efficiency and accuracy of NAS signaling, this application provides a non-access stratum NAS signaling decryption method, electronic device, computer-readable storage medium, and computer program product. The method involves first receiving NAS signaling from a first target interface, then obtaining the target user's unique identifier corresponding to the NAS signaling and a target security context list corresponding to the target user's unique identifier. The target security context list includes security contexts for at least one network standard. Because the target security context list contains security contexts for at least one network standard, even in a multi-network converged environment, a security context matching the current interface's network standard can be intelligently selected and applied for decryption based on the target security context list, thereby reducing unnecessary security context switching and lookup time and improving decryption efficiency. Furthermore, after determining the target security context corresponding to the network standard of the first target interface based on the target security context list, the NAS signaling can be decrypted using the target security context. This application achieves cross-network architecture compatibility by receiving NAS signaling from the first target interface and associating the target user's unique identifier with a target security context list containing security contexts for multiple network standards. During the decryption process, this embodiment directly selects the matching security context for decryption based on the network type of the NAS signaling (i.e., the network type of the first target interface). This not only significantly reduces unnecessary context switching and lookup steps, thereby greatly improving decryption efficiency, but also ensures the accuracy and reliability of the decryption operation through the directly associated security context.

[0019] Based on the above analysis, the embodiments of this application will be further described below with reference to the accompanying drawings.

[0020] Reference Figure 2 , Figure 2 This is a flowchart of a non-access stratum NAS signaling decryption method provided in one embodiment of this application. The non-access stratum NAS signaling decryption method may include, but is not limited to, steps S210 to S240.

[0021] Step S210: Receive NAS signaling from the first target interface; Step S220: Obtain the unique identifier of the target user corresponding to the NAS signaling, and obtain the target security context list corresponding to the unique identifier of the target user, wherein the target security context list includes security contexts of at least one network standard; Step S230: Determine the target security context corresponding to the network standard of the first target interface based on the target security context list; Step S240: Decrypt the NAS signaling using the target security context.

[0022] For example, NAS signaling is the signaling exchanged between the core network (e.g., 4G / 5G network) and the UE through the NAS layer. In 4G networks, it is mainly transmitted through the S1MME interface; in 5G networks, it is mainly transmitted through the N1N2 interface. NAS signaling carries key information such as user registration, location updates, session establishment and release, and is an important means for mobile communication networks to achieve user management and session control. Specifically, user registration refers to the UE sending a registration request to the core network through NAS signaling and obtaining network access permissions through an authentication process; location updates refer to the core network tracking the UE's location information through NAS signaling so that it can quickly locate and serve users when needed; session management refers to the establishment, modification, and release of PDU sessions between the UE and the core network through NAS signaling to support the user's data transmission needs; security control refers to the fact that NAS signaling also contains security parameters and keys for protecting user equipment data and signaling security, ensuring the confidentiality and integrity of communication.

[0023] For example, the first target interface can be either the S1MME interface or the N1N2 interface. The S1MME interface is the interface between the eNB and MME in a 4G network. The N1N2 interface is the interface between the UE, gNB, and AMF in a 5G network. Specifically, the N1 interface is the interface between the UE and the AMF, used to transmit NAS signaling; it is the main channel for non-access stratum communication between the UE and the core network. The N2 interface is the interface between the access network (such as the gNB) and the AMF, used to transmit NAS signaling and control plane information between the access network and the core network. When a user equipment (UE) accesses a 4G / 5G network, NAS signaling can be transparently transmitted to the MME / AMF nodes in the core network through base stations (such as eNB and gNB) in the 4G / 5G network architecture.

[0024] For example, NAS signaling typically includes parameters for identifying users, such as International Mobile Subscriber Identity (IMSI), MobileStation International Subscriber Directory Number (MSISDN), and Subscription Permanent Identifier (SUPI). When the AMF receives NAS signaling, it first parses the signaling to obtain user-related information and uses this information as a unique identifier for the user. For instance, the IMSI or SUPI obtained by parsing the NAS signaling can be used as a unique identifier for the target user. These identifiers are unique within the network and can be used to identify different users. Once a user is identified, the user's security context list can be looked up, which contains the user's security configurations under different network standards.

[0025] For example, when each user equipment (UE) establishes a connection with the network, the network side assigns and maintains an independent security context for each device. These security contexts not only reflect the UE's identity, permissions, and network access characteristics, but also include information such as keys, algorithms, and parameters used to protect that type of signaling and data transmission. Examples include the ciphering algorithm type, encryption key (KNASenc), integrity protection algorithm type, integrity protection key (KNASint), and message sequence number. The network side can centrally manage these security contexts.

[0026] For example, when obtaining the target security context list corresponding to a target user's unique identifier, the corresponding security context list can be queried using the user's unique identifier (such as IMSI or SUPI). In other words, whenever a user device accesses a network, its unique identifier (such as MAC address, IMSI, device ID, etc.) can be used to query or generate a series of security context information (i.e., the target security context list) associated with that user's unique identifier. It is worth noting that, given the user device's ability to connect to diverse networks (such as 4G and 5G networks), each network has its unique network standard requirements. Therefore, when constructing the security context associated with the user's unique identifier, it is necessary to ensure that it covers the security parameters and rules of at least one of the network standards the user device may access; that is, the user device's security context list includes security contexts for at least one network standard.

[0027] For example, since a user equipment (UE) can support multiple network standards simultaneously, it is necessary to determine which security context to use for decryption based on the interface receiving NAS signaling (i.e., the network standard). Once the list of target security contexts corresponding to the unique identifier of the target user is obtained, the target security context to be used can be determined based on the current network standard (e.g., 4G or 5G) and the first target interface (e.g., S1MME or N1N2). Specifically, if the first target interface is S1MME, a security context corresponding to the 4G network standard is selected from the target security context list for subsequent encryption, integrity protection, and other security operations. If the first target interface is N1N2, a security context corresponding to the 5G network standard can be selected. Based on the first target interface and the current network standard, the appropriate target security context can be accurately determined and selected to ensure the secure transmission of UE data and the normal operation of the network.

[0028] For example, after determining the target security context, security parameters (such as keys, algorithms, etc.) in the target security context can be used to decrypt the NAS signaling in order to recover the original NAS signaling content.

[0029] For example, before decryption, the validity and integrity of the target security context can be verified to ensure that it has not been tampered with before proceeding with the subsequent decryption steps.

[0030] In this embodiment, by employing the non-access stratum (NAS) signaling decryption method including steps S210 to S240 described above, after receiving NAS signaling from the first target interface, the unique identifier of the target user corresponding to the NAS signaling can be obtained, and the corresponding target security context list can be retrieved accordingly. The target security context list includes security contexts for at least one network standard, ensuring the comprehensiveness of the information. Since the target security context list integrates security context information for at least one network standard, even in a multi-network converged environment, the security context matching the current interface network standard can be intelligently selected and applied for decryption based on the target security context list. In other words, the key matching the current interface network standard can be intelligently selected and applied for decryption based on the target security context list, effectively avoiding key mismatch problems and greatly improving the flexibility and efficiency of the decryption process. Furthermore, after determining the target security context corresponding to the network standard of the first target interface based on the target security context list, the NAS signaling can be decrypted using the target security context. This embodiment maintains a dynamically updated list of target security contexts and intelligently selects matching security contexts for decryption based on the network standard to which the NAS signaling belongs. This reduces unnecessary context switching and search steps, thus significantly improving decryption efficiency. Furthermore, by ensuring that decryption is performed using keys matching the security context, the accuracy and reliability of NAS signaling decryption are achieved.

[0031] In this application embodiment, different operations are used to obtain the target security context list based on different network scenarios.

[0032] The first scenario is the user going online scenario. The following will provide an example of the process of obtaining the target security context list in the user going online scenario.

[0033] Under 4G network standards, when a user equipment (UE) initiates and accesses the network (i.e., the user goes online), the S6a interface can allocate a completely new security context for the UE. This process carries multiple sets of original keys (e.g., Key Derived from the Secret Key used for EPS Security, Kasme, the master key used to generate and distribute various security keys), which are crucial for ensuring communication security. Simultaneously, the S1MME interface triggers the exchange of SECURITYMODE COMMAND and SECURITY MODE COMPLETE messages. Essentially, after the UE successfully accesses the network, the network side sends a SECURITY MODE COMMAND message to the UE. This message contains configuration information for encryption and integrity protection algorithms used for subsequent communication, as well as related key parameters. Upon receiving this message, the UE configures its security parameters according to the instructions and generates the corresponding key. Subsequently, the UE sends a SECURITY MODE COMPLETE message to the network side in response to the SECURITY MODE COMMAND message. These messages not only contain the type of encryption algorithm used, but also specify the type of integrity protection algorithm, thereby ensuring the confidentiality and integrity of data transmission.

[0034] In 5G networks, the process of user equipment accessing the network also involves the allocation of a security context, but this is accomplished through the N12 interface. Similar to 4G, multiple sets of raw keys (such as Kamf) are carried in the 5G environment to ensure communication security. Furthermore, the N1N2 interface triggers the interaction of SECURITY MODE COMMAND and SECURITY MODE COMPLETE messages, which specify in detail the encryption algorithm type and integrity protection algorithm type to meet the higher security and efficiency requirements of 5G networks.

[0035] For example, since the target security context list of the user equipment includes security context information for at least one network standard, the target security context determined for the network standard matching the first target interface includes the original key information for at least one network standard to ensure highly reliable secure communication in different network environments. See also Figure 3 The process of determining the target security context corresponding to the network standard of the first target interface based on the target security context list in step S230 may include, but is not limited to, steps S310 to S320.

[0036] Step S310: When the NAS signaling is a security mode control message, obtain the target original key information corresponding to the network type of the first target interface from the target security context list; Step S320: Obtain the target security context based on the target's original key information, as well as the integrity protection algorithm information and encryption algorithm information carried in the security mode control message.

[0037] For example, a security mode control message is a type of NAS signaling that can be used to establish or update a security context between the UE and the core network, including the selection of encryption and integrity protection algorithms, key generation and distribution, etc., to ensure the confidentiality, integrity and authentication of subsequent communications. In this embodiment, the security mode control message can be a SECURITY MODE COMMAND message or a SECURITY MODE COMPLETE message.

[0038] The target security context list stores a list of security context information under different network standards. Each security context contains key information, algorithm information, etc., corresponding to a specific network standard. When the UE accesses the network through the first target interface (S1MME or N1N2), it can retrieve the corresponding original key information from the target security context list based on the network standard of the first target interface. This key information will be used in the subsequent security context generation process.

[0039] For example, the security mode control message includes information on the integrity protection algorithm and encryption algorithm used to protect NAS signaling messages. This algorithm information specifies the specific algorithms that the UE and AMF / MME should use during communication to ensure message integrity and confidentiality. Using the target raw key information obtained from the target security context list, combined with the integrity protection algorithm and encryption algorithm information specified in the security mode control message, the final target security context can be generated. It should be noted that the target security context contains all the parameters and keys required for encryption, decryption, integrity protection, and verification during subsequent communication.

[0040] For example, the raw key information for each network standard may include multiple sets of raw key information, each set including an AUTH parameter and a raw key. The AUTH parameter is key data used to verify user identity or message integrity, and may include a specific authentication vector, sequence number, timestamp, or other parameters that uniquely identify a user or message. During key negotiation and distribution, the AUTH parameter can be used to ensure that only legitimate users or devices can access network resources and prevent unauthorized access and attacks. The raw key is the key necessary for encrypting and decrypting communication messages. These may include keys for encrypting user device data, keys for protecting message integrity, and keys for other security functions. Because different network standards (such as 4G, 5G, etc.) may have different security requirements and characteristics, different key information and algorithms are needed to ensure secure communication. Using multiple sets of raw key information can improve system security. For example, different keys can be used for different security functions (such as encryption, integrity protection, etc.), or keys can be changed periodically at different times to reduce the risk of being cracked.

[0041] For example, in the process of retrieving the target raw key information corresponding to the network type of the first target interface from the target security context list, the target raw key information corresponding to the network type of the first target interface and the AUTH parameter can be retrieved from the target security context list when the NAS signaling carries the AUTH parameter. For example, assume the NAS signaling carries an AUTH parameter: AUTH1. This parameter is used to search for key information matching a specific network type and AUTH parameter from the predefined target security context list. The target security context list stores security context information under different network types (4G, 5G, etc.), including keys, algorithms, etc. When the first target interface is an S1MME interface, since the network type corresponding to the S1MME interface is a 4G network, the target security context list can be searched for entries matching 4G network and AUTH1, and then the target raw key information can be extracted from the matching entries. Similarly, when the first target interface is the N1N2 interface, since the network standard corresponding to the N1N2 interface is the 5G network, an entry matching the 5G network and AUTH1 can be searched in the target security context list, and then the corresponding target raw key information can be extracted from the matching entry.

[0042] For example, when the source of the target original key information is a second target interface (S6a / N12 interface) corresponding to the network standard of the first target interface (S1MME / N1N2 interface), the target security context can be obtained based on the target original key information and the integrity protection algorithm information and encryption algorithm information carried in the security mode control message. It should be noted that when the source of the target original key information is a second target interface corresponding to the network standard of the first target interface, the key is usually generated or negotiated at a higher layer (such as an authentication server) and subsequently used for communication encryption and integrity protection at a lower layer (such as between the base station and the core network). Specifically, the S6a interface is generally used for authentication and key negotiation between the MME and HSS / HLR in 4G networks. In 5G networks, the N12 interface can be used for authentication and key negotiation between the AMF and AUSF. If the target original key information comes from the S6a / N12 interface, this indicates that these keys were generated after successful authentication between the user equipment (UE) and the network authentication server, or negotiated within the network for secure communication. Once keys are generated or negotiated on the S6a / N12 interface, these keys need to be transmitted to network elements that require them for subsequent secure communication. The raw key information can be used with integrity protection algorithm information and encryption algorithm information carried in the security mode control message to establish or update the target security context. Therefore, when the source of the target raw key information is a second target interface corresponding to the network standard of the first target interface, the target security context is obtained based on this key information and the algorithm information (integrity protection algorithm information and encryption algorithm information) carried in the security mode control message.

[0043] The second scenario is the network handover scenario. The following will provide an example of the process of obtaining the target security context list in the network handover scenario.

[0044] In scenarios involving the handover from 4G to 5G networks, when a UE first enters a 5G network from 4G, it first needs to register and authenticate with the 5G network to confirm whether a security context needs to be created. During this process, the UE sends a registration request containing its unique identifier (such as IMSI or SUPI) to the 5G network. Upon receiving the UE's registration request, the 5G network's AMF (Active Security Context) checks whether a security context already exists associated with that user's unique identifier. If it does, the AMF retrieves the security context list, which contains critical security information such as encryption keys, integrity protection keys, serial numbers (SN), and algorithm identifiers. If it does not exist, the AMF can request the security context information from the 4G network's core network (such as the MME) or generate a new security context list based on network policies and configurations. It's important to note that during the registration and authentication process, the UE and the 5G network exchange NAS (Security Context Allocation) signaling. Specifically, the AMF or relevant network nodes parse this NAS signaling to obtain user information, service requests, etc., carried within it. Simultaneously, the AMF will also perform integrity protection and encryption on NAS signaling based on the information in the security context list to ensure the confidentiality and integrity of the signaling. As the UE's activities in the 5G network (such as data transmission, location updates, etc.) progress, the security context list may need to be updated. For example, when the encryption key or integrity protection key between the UE and the network expires, the network will trigger a key update process and update the corresponding information in the security context list. Network nodes will also periodically or as needed maintain and verify the security context list to ensure its accuracy and validity.

[0045] It should be noted that in the scenario of switching from 5G to 4G network, when the UE enters the 4G network from 5G for the first time, the process of confirming the creation of a security context and subsequent operations are similar to the process of confirming whether a security context needs to be created when the UE enters the 5G network from 4G for the first time. For details, please refer to the process of confirming whether a security context needs to be created when the UE enters the 5G network from 4G for the first time. It will not be repeated here.

[0046] In 4G network environments, security contexts are typically transmitted via the S10 interface during intra-network handover. However, in 4G to 5G handover scenarios, to ensure a seamless and secure transition, the security context is transmitted from the MME to the AMF via the N26 interface. This transmitted security context includes the final encryption key, integrity protection key, and multiple sets of original key kasmes used before the handover, which serve as the basis for generating other keys.

[0047] In 5G network technology, during intra-network handover, security context is typically transmitted via the N14 interface (interface between AMFs). In 5G-to-4G handover scenarios, security context is transmitted from the 5G AMF to the 4G MME via the N26 interface. Similarly, these transmitted security contexts include the final encryption key, integrity protection key, and multiple sets of original keys (Kamf) used before the handover, which serve as the basis for generating other keys.

[0048] It is worth noting that in these network handover scenarios, whether the security context is transmitted within the 4G network architecture via the S10 interface, exchanged between 4G and 5G networks using the N26 interface, or transmitted within the 5G network architecture via the N14 interface, when the security context flows between networks, the TSC cell on the receiving side (such as the S1MME interface of the 4G network or the N1N2 interface of the 5G network) will be assigned a network handover scenario identifier. This identifier can be marked with the value "1" (i.e., TSC=1). This network handover scenario identifier applies not only to cross-network handover scenarios from 4G to 5G or vice versa, but also to various handover situations within both 4G and 5G networks. By assigning a network handover scenario identifier to the TSC cell, it is possible to identify that a network handover is currently underway and take corresponding security measures accordingly. This includes, but is not limited to: real-time synchronization of security context: ensuring that the security context of the user device can be quickly and securely transmitted from the source network to the target network during the handover process to maintain the encryption and integrity of communication; migration of session state: as the security context is transmitted, the relevant session state information also needs to be correctly migrated to ensure that the user's service experience is not affected; updating of security policies: depending on the security policy of the target network being switched, it may be necessary to further process or update the transmitted security context (including keys) to adapt to the new network environment.

[0049] For example, the integrity protection key is generated based on a specific integrity protection algorithm, an initial key, and a sequence number, while the encryption key is generated based on an encryption algorithm, a corresponding initial key, and a sequence number. Given that different network standards (such as 4G and 5G) may employ different key parameters due to varying technical standards and security requirements, the target security context includes at least one integrity protection key and encryption key for each network standard. This ensures flexible and robust security protection in diverse network environments and constantly evolving security needs. It allows the network to select or switch appropriate keys and algorithms as needed to maintain data integrity and confidentiality during communication.

[0050] For example, in the process of determining the target security context corresponding to the network standard of the first target interface based on the target security context list, if the NAS signaling is not a security mode control message and the TSC information element of the first target interface has a network handover scenario identifier (TSC=1), the target integrity protection key and target encryption key corresponding to the network standard of the first target interface can be obtained from the target security context list to obtain the target security context. That is, when processing NAS signaling that is not a security mode control message, if the TSC (Transmission Security Control) network element of the first target interface is marked as having a network handover scenario (e.g., TSC=1), the target integrity protection key and target encryption key matching the specific network standard (e.g., 4G, 5G, etc.) of the first target interface can be found from the pre-stored target security context list. This process aims to dynamically determine and apply appropriate security parameters (such as the target integrity protection key, target encryption key, etc.) according to the current network environment (which may be during network handover or reselection), thereby ensuring the security and integrity of data transmission. It is worth noting that even when the NAS signaling is not a security mode control message, the network side can still adjust the security policy according to the context and network status. Specifically, when a network switching identifier is detected in the TSC cell of the first target interface, the network standard of the first target interface, such as S1MME / N1N2, determines which set of target integrity protection keys and target encryption keys need to be selected from the security context list. These keys are closely related to the security requirements of interfaces such as S10 / N26. By obtaining the target integrity protection keys and target encryption keys corresponding to interfaces such as S10 / N26 from the target security context list, the target security context can be obtained.

[0051] The third scenario is other than user login and network switching scenarios. The process of obtaining the target security context list for other scenarios will be illustrated below.

[0052] In a service request scenario, assuming a User Equipment (UE) has already established a secure connection with the network (4G / 5G network), and at some point later, due to network roaming, session resumption, or reconnection, the UE needs to make another service request, but the security context (including key information) remains valid and unchanged. Specifically, the UE sends a service request message to the network, which includes the user's unique identifier (such as IMSI) and network standard information (4G / 5G network standard). Upon receiving the service request, if the network verifies that the current security context is still valid (i.e., the security context has not changed), the network can directly query a pre-stored list of target security contexts based on the user's unique identifier (IMSI) and network standard information to obtain the target security context (such as original key information, integrity protection algorithm information, and encryption algorithm information) that matches these parameters (user unique identifier, network standard information).

[0053] It should be noted that in the third scenario, the TSC cell does not have a network handover scenario identifier.

[0054] For example, since the target security context contains an integrity protection key and an encryption key for at least one network standard, and the integrity protection key includes an integrity protection algorithm, a raw key, and a sequence number, while the encryption key includes an encryption algorithm, a raw key, and a sequence number, the target security context includes raw key information, integrity protection algorithm information, and encryption algorithm information for at least one network standard. When the NAS signaling is not a security mode control message and the TSC (Transmission Security Control) element of the first target interface does not have a network handover scenario identifier, the target raw key information, target integrity protection algorithm information, and target encryption algorithm information corresponding to the network standard of the first target interface can be obtained from the target security context list to obtain the target security context. That is, when processing NAS signaling that is not a security mode control message, and the TSC (Transmission Security Control) network element of the first target interface is not marked as having a network handover scenario identifier (e.g., TSC is not equal to 1), the target security context matching the network standard of the first target interface can be found from the pre-stored target security context list. In this case, the obtained information includes target raw key information, target integrity protection algorithm information, and target encryption algorithm information.

[0055] See Figure 4For example, when the NAS signaling is not a security mode control message and the TSC information cell of the first target interface does not have a network handover scenario identifier, the target original key information, target integrity protection algorithm information and target encryption algorithm information corresponding to the network standard of the first target interface are obtained from the target security context list to obtain the target security context, including but not limited to steps S410 to S420.

[0056] Step S410: Obtain the target original key information, target integrity protection algorithm information, and target encryption algorithm information corresponding to the network standard of the first target interface from the target security context list; Step S420: When the source of the target original key information is the second target interface corresponding to the network standard of the first target interface, the target security context is obtained based on the target original key information, the target integrity protection algorithm information, and the target encryption algorithm information.

[0057] For example, the target security context list contains a set of predefined security information for various network standards. Based on the network standard of the first target interface, the corresponding target original key information, target integrity protection algorithm information, and target encryption algorithm information can be retrieved.

[0058] For example, after obtaining the target original key information, when the target original key information originates from a second target interface that is compatible with or corresponds to the network standard of the first target interface, the target security context can be obtained based on the target original key information, target integrity protection algorithm information, and target encryption algorithm information from the determined source. For example, taking seamless handover between 4G and 5G networks as an example, during the network environment transition process, whether upgrading from 4G to 5G or switching in the opposite direction, the confidentiality and integrity of user equipment data must be strictly guaranteed. Therefore, during the handover process, it is necessary to identify the current network interface type and key characteristics, and construct an appropriate security context accordingly. Specifically, when it involves an S1MME interface query and the target key is of the 4G standard, or an N1N2 interface query accompanied by a 5G standard key, the network side can accurately integrate these key information (target original key information, target integrity protection algorithm information, and target encryption algorithm information) to obtain and apply the target security context, ensuring the security of data transmission.

[0059] The following example provides a detailed explanation of the specific process for obtaining the target security context.

[0060] See Figure 5 , Figure 5This is a flowchart illustrating the process of obtaining a target security context, provided as a specific example of this application. After receiving NAS signaling from a first target interface (S1MME / N1N2 interface), obtaining the target user's unique identifier corresponding to the NAS signaling, and obtaining a list of target security contexts corresponding to the target user's unique identifier, including at least one network standard, during the process of obtaining the target security context based on the user's unique identifier, if the NAS signaling is a security mode control message (SECURITY MODE COMMAND or SECURITY MODE COMPLETE message) and carries an AUTH parameter, the corresponding target raw key information (Kasme) can be matched according to the network standard of the first target interface and the AUTH parameter. If the source of the Kasme is a second target interface (S6a / N12) corresponding to the network standard of the first target interface, the target security context can be obtained based on the target raw key information, and the integrity protection algorithm information and encryption algorithm information carried in the security mode control message. Furthermore, when the NAS signaling is not a security mode control message and the TSC cell of the first target interface has a network handover scenario identifier, after confirming that the target security context list uniquely identified by the user is created by the S10 / N26 interface, the target integrity protection key and target encryption key corresponding to the network standard of the first target interface can be obtained from the target security context list, thereby obtaining the target security context. Additionally, when the NAS signaling is not a security mode control message and the TSC cell of the first target interface does not have a network handover scenario identifier, the target original key information, target integrity protection algorithm information, and target encryption algorithm information corresponding to the network standard of the first target interface can be obtained from the target security context list. When the source of the target original key information is the second target interface corresponding to the network standard of the first target interface, that is, when the network standard of the security context is consistent with the query message (i.e., S1MME must use a 4G key, N1N2 must use a 5G key), the target security context can be obtained based on the target original key information, target integrity protection algorithm information, and target encryption algorithm information.

[0061] For example, after decrypting the NAS signaling through the target security context, if the decryption is successful, the integrity protection key and encryption key used for decryption are updated to the target security context to ensure the security and timeliness of subsequent communications.

[0062] For example, before obtaining the list of target security contexts corresponding to the target user's unique identifier, a list of security contexts corresponding to the user's unique identifier can be created first. For example... Figure 6 As shown, the process of creating a security context list corresponding to a user's unique identifier may include, but is not limited to, steps S610 to S620.

[0063] Step S610: Obtain the original key information from the second target interface and obtain the user's unique identifier corresponding to the original key information. The second target interface includes interfaces of various network standards. Step S620: Add the original key information and the source of the original key information to the security context list corresponding to the user's unique identifier.

[0064] For example, the second target interface includes at least one of the S6a interface and the N12 interface; obtaining the original key information from the second target interface includes at least one of the following: Obtain multiple sets of original keys corresponding to the first network standard from the S6a interface; Obtain multiple sets of original keys corresponding to the second network standard from the N12 interface.

[0065] It should be noted that the S6a interface is typically used for communication between the MME and HSS in 4G networks. It supports security-related functions such as user authentication, location updates, and key management. The N12 interface, on the other hand, can be used for similar functions in 5G networks, such as user authentication and key management.

[0066] For example, obtaining raw key information and its corresponding user unique identifier from the second target interface aims to acquire user-related raw key information from interfaces of different network standards. This key information is crucial for subsequent security operations such as encryption, decryption, and authentication. Generally, for each interface, corresponding operations can be performed to obtain the key. For example, multiple sets of raw keys corresponding to the first network standard (such as a 4G network) can be obtained from the S6a interface, and multiple sets of raw keys corresponding to the second network standard (5G network) can be obtained from the N12 interface. Simultaneously with obtaining the key information, the associated user unique identifier can also be obtained. This identifier can be used to associate the key information with a specific user, ensuring that the keys can be correctly identified and used in subsequent operations.

[0067] For example, adding the original key information and its source to a security context list corresponding to the user's unique identifier aims to securely store the acquired original key information and its source in the security context list corresponding to the user's unique identifier, thereby ensuring that the key information can be quickly found and used when needed.

[0068] For example, when a user equipment (UE) attempts to access a 4G network for the first time, the MME initiates communication with the HSS, requesting the user's authentication information via the S6a interface. Upon responding to the request, the HSS returns multiple sets of raw keys (e.g., Ki values ​​and their derived keys), along with the user's unique identifier corresponding to these keys. The MME can then add all the raw key information obtained in the first step (the 4G keys obtained from the S6a interface) and their source (the S6a interface) to the security context list corresponding to the user's unique identifier.

[0069] For example, when a user equipment (UE) attempts to access a 5G network for the first time, the AMF initiates communication with the AUSF, requesting the user's authentication information via the N12 interface. Upon responding to the request, the AUSF returns multiple sets of raw keys and the user's unique identifier corresponding to these keys. The AMF can then add all the raw key information obtained in the first step (the 5G keys obtained from the N12 interface) and their source (the N2 interface) to the security context list corresponding to the user's unique identifier.

[0070] See Figure 7 For example, the process of creating a security context list corresponding to a user's unique identifier may include, but is not limited to, steps S710 to S720.

[0071] Step S710: Obtain integrity protection algorithm information and encryption algorithm information from the security mode control message from the first target interface, and obtain the user unique identifier corresponding to the integrity protection algorithm information and encryption algorithm information. The first target interface includes interfaces of various network standards. Step S720: Add the integrity protection algorithm information and encryption algorithm information to the security context list corresponding to the user's unique identifier.

[0072] For example, the first target interface includes at least one of the S1MME interface and the N1N2 interface; the step S710 of obtaining integrity protection algorithm information and encryption algorithm information from the security mode control message from the first target interface includes at least one of the following: Obtain the integrity protection algorithm information and encryption algorithm information corresponding to the first network standard (4G network) from the security mode control message from the S1MME interface; Obtain the integrity protection algorithm information and encryption algorithm information corresponding to the second network standard (5G network) from the security mode control message from the N1N2 interface.

[0073] For example, for each interface (such as the S1MME interface and the N1N2 interface), the network side parses the received security mode control message to extract integrity protection algorithm information and encryption algorithm information. While extracting the algorithm information, it also obtains the associated unique user identifier. This identifier is used to associate the algorithm information with a specific user, ensuring that these algorithms can be correctly applied in subsequent operations.

[0074] For example, adding algorithm information to the security context list aims to add the integrity protection algorithm information and encryption algorithm information obtained in step S710 to the security context list corresponding to the user's unique identifier. This ensures that this algorithm information can be quickly retrieved and applied when needed to protect the integrity and confidentiality of user equipment data. It should be noted that during this process, if a security context list has not yet been created for the user equipment, the network side will first create a new list. If the list already exists, it will be updated based on the existing list.

[0075] For example, when a user equipment (UE) first accesses a 4G network, the MME can send a security mode control message to the UE via the S1MME interface. This message contains integrity protection algorithm information and encryption algorithm information applicable to the 4G network. The UE can extract this information from the message and verify that it is associated with the UE's unique user identifier.

[0076] For example, when a user equipment (UE) switches from a 4G network to a 5G network, it can establish a connection with a new access point (such as a gNB) and communicate with the AMF (Access Provider Function) via the N1 interface. To ensure communication security, the AMF sends a security mode control message to the UE through the N1N2 interface. This message contains integrity protection algorithm information and encryption algorithm information suitable for the 5G network; these algorithms will be used to protect the communication between the UE and the network. The UE can extract the integrity protection algorithm information and encryption algorithm information from the security mode control message and verify that they are associated with the UE's unique user identifier.

[0077] For example, regardless of whether the algorithm information is obtained from the S1MME interface or the N1N2 interface, the user equipment will add this information to the security context list corresponding to the user's unique identifier. This list now contains the integrity protection algorithms and encryption algorithms required by the user under different network standards, ensuring seamless switching and continuous communication security for the user equipment across different networks.

[0078] See Figure 8 For example, the process of creating a security context list corresponding to a user's unique identifier may include, but is not limited to, steps S810 to S820.

[0079] Step S810: Obtain the integrity protection key and encryption key from the third target interface, and obtain the user unique identifier corresponding to the integrity protection key and encryption key. The third target interface includes interfaces of various network standards, and the TSC cell of the first target interface has a network handover scenario identifier. Step S820: Add the integrity protection key and encryption key to the security context list corresponding to the user's unique identifier.

[0080] For example, the third target interface includes at least one of the S10 interface, N14 interface, and N26 interface; obtaining the integrity protection key and encryption key from the third target interface includes at least one of the following: Obtain the integrity protection key and encryption key corresponding to the first network standard from the S10 interface or N26 interface; Obtain the integrity protection key and encryption key corresponding to the second network standard from the N14 interface or N26 interface.

[0081] For example, obtaining keys and a user's unique identifier from a third-party target interface is intended to receive integrity protection keys and encryption keys from the third-party target interface, which are necessary for secure user communication. Simultaneously, it is also necessary to obtain the user's unique identifier corresponding to this key information in order to associate the key information with a security context list corresponding to the user's unique identifier.

[0082] For example, step S820 aims to ensure the security of user equipment data by adding the integrity protection key and encryption key obtained from the third target interface to the security context list corresponding to the user's unique identifier, thereby obtaining the latest security context list and ensuring that these key information can be found and applied in real time and quickly.

[0083] For example, upon identifying the current network standard and active interface, the corresponding interface can be invoked to obtain key information for different network standards. For instance, upon detecting 4G network activity, the latest integrity protection key and encryption key can be requested from the S10 or N26 interface. Similarly, upon detecting 5G network activity, the corresponding integrity protection key and encryption key can be obtained from the N14 or N26 interface. Once this key information is successfully obtained and verified (ensuring the integrity and tamper-proof nature of the key information), it will be stored in a security context list associated with the user's unique identifier.

[0084] For example, in a scenario where a user equipment (UE) switches from a 4G network to a 5G network, the TSC (Transfer Controller) cell contains a network handover scenario identifier, and it is necessary to ensure a seamless transfer of the UE's security context from the 4G network to the 5G network. During this process, the MME (Mechanical Management Interface) can directly synchronize the security context with the AMF (Application Management Frame) via the N26 interface. Specifically, the MME sends the UE's security context (including the integrity protection key and encryption key) and its unique user identifier to the AMF via the N26 interface. After receiving the security context information from the MME and verifying its integrity and validity, the AMF can add the UE's security context and its unique user identifier to the security context list corresponding to the unique user identifier, preparing to provide 5G services to the UE.

[0085] The following example illustrates the process of creating and querying the security context of a user device.

[0086] See Figure 9 , Figure 9This is a schematic diagram illustrating the creation, updating, and querying of security contexts provided in an embodiment of this application. In a scenario where a user equipment supporting both 4G and 5G dual-mode accesses a hybrid network with 4G and 5G network coverage, assuming initial access is to the 4G network, the device communicates with the HSS via the S6a interface for initial authentication. Subsequently, the MME (Mobility Management Entity) uses the S6a interface to obtain the user's original key information (such as AUTH1+Kasme1, AUTH2+Kasme2, etc.) and the user's unique identifier (such as IMSI) from the HSS, and records this information and its source (S6a interface) in a security context list associated with the user's unique identifier. Next, the MME sends a security mode control message to the user equipment via the S1MME interface. This message carries integrity protection and encryption algorithm information suitable for the 4G network. After the user equipment confirms that this information matches its own unique identifier, it adds it to the security context list. Furthermore, when a user equipment (UE) switches within a 4G network, since it's a switch within the same network standard, the N26 interface (which crosses network standards) is not involved. During this process, the TSC cell recognizes this as an intra-network handover scenario and initiates the corresponding security context update procedure. In this process, after receiving key security parameters transmitted via the S10 interface, including the latest integrity protection algorithm information, encryption algorithm information, encryption key (KNASenc), integrity protection key (KNASint), and serial number, the UE verifies their integrity and authenticity and updates them to the corresponding security context list. Additionally, when the UE switches from a 4G network to a 5G network, the key security parameters are transmitted to the AMF via the N26 interface. The UE receives a security context update message containing the new key from the AMF, verifies and confirms its association with the user's unique identifier, and updates the integrity protection key and encryption key in the security context list. It is worth noting that in a 5G network environment, the original key information (such as AUTH+Kamf) obtained by the device from the AFS via the N12 interface differs from the information in the 4G network. Ultimately, the target security context list integrates the security context information of user equipment under both 4G and 5G networks. After obtaining the user's unique identifier, NAS signaling can efficiently query and retrieve matching security context information from this list, thereby matching the correct key and improving the accuracy of NAS decryption. Furthermore, with successful decryption of the NAS signaling, the target security context list is synchronously updated using the updated KNASenc and KNASint, ensuring the timeliness and accuracy of the security context. The operational logic of this process in the 5G network is similar to that in the 4G network and will not be elaborated further here.

[0087] For example, after receiving NAS signaling from the first target interface, the unique identifier of the target user corresponding to the NAS signaling is obtained, including one of the following: Obtain the target user's unique identifier from NAS signaling; or, If the NAS signaling does not carry a unique user identifier, the target feature parameters are obtained from the NAS signaling, and the unique user identifier corresponding to the target feature parameters is obtained from the list of user unique identifiers and feature parameters.

[0088] For example, when the NAS signaling directly contains the target user's unique identifier, this unique identifier can be directly extracted from the NAS signaling. However, in some cases, the NAS signaling may not directly carry the user's unique identifier, but rather some characteristic parameters that can indirectly identify the user. These characteristic parameters may include the user's device information, location information, network access point information, or any other information that can uniquely or nearly uniquely identify the user. When receiving NAS signaling that does not carry the user's unique identifier but carries characteristic parameters, these characteristic parameters can be extracted from the signaling first. Then, a record matching or closest to matching these characteristic parameters can be searched in the user unique identifier and characteristic parameter relationship list. Once a match is found, the target user's unique identifier corresponding to the target characteristic parameters can be obtained from that record.

[0089] Reference Figure 10 For example, before obtaining the target user's unique identifier corresponding to the NAS signaling, the target user's unique identifier corresponding to these feature parameters can be obtained by maintaining a list of relationships between user unique identifiers and feature parameters. The process of maintaining the list of relationships between user unique identifiers and feature parameters includes, but is not limited to, steps S1010 to S1030.

[0090] Step S1010: Create a list of relationships between user unique identifiers and feature parameters; Step S1020: Obtain the user's unique identifier and the corresponding feature parameters from the signaling from the fourth target interface; Step S1030: Add the user's unique identifier and the corresponding feature parameters to the user's unique identifier and feature parameter relationship list; The fourth target interface includes at least one of the following: S1MME interface, N1N2 interface, S6a interface, N12 interface, S11 interface, and N11 interface.

[0091] For example, creating a list of user unique identifiers and characteristic parameters aims to establish a list or database for storing the relationships between user unique identifiers (such as IMSI) and corresponding characteristic parameters. This list serves as the basis for subsequent query and matching operations, enabling indirect identification of the user through characteristic parameters when the NAS signaling does not directly carry the user unique identifier. It should be noted that characteristic parameters include not only user unique identifiers (such as IMSI), but also globally unique temporary identifiers (GUTI), AUTH, and IPTEID (IPTransport Entity Identifier, a unique identifier used to identify IP transmission entities). These characteristic parameters collectively constitute the infrastructure and operating mechanism of mobile communication networks, playing a crucial role in improving network performance, optimizing user experience, and ensuring network security.

[0092] For example, by listening to, receiving and parsing signaling from the fourth target interface, the user's unique identifier and associated characteristic parameters can be extracted.

[0093] For example, when performing step S1030, if a record with the same user unique identifier already exists in the relationship list, it can be decided, based on business needs, whether to update the feature parameters of the existing record or keep it as is (or perform other processing), thereby ensuring data consistency and integrity and avoiding duplicate or conflicting records.

[0094] The following example illustrates the process of maintaining and querying the list of relationships between user unique identifiers and characteristic parameters.

[0095] See Figure 11 , Figure 11This is a flowchart illustrating the creation and querying of a user unique identifier and characteristic parameter relationship list provided in this application embodiment. The process begins with a pre-built (potentially initially empty) user unique identifier and characteristic parameter relationship list. Subsequently, upon receiving signaling from the fourth target interface, the first step is to confirm the source of this signaling. Depending on the source, the execution path will differ: If the signaling originates from the S1MME interface or the N1N2 interface and carries a user unique identifier, it is further verified whether it also contains specific characteristic parameters (such as GUTI). If the GUTI exists, it is matched with the user unique identifier and added to the aforementioned relationship list. If the signaling does not carry a user unique identifier but contains characteristic parameters, the corresponding user unique identifier is queried from the list using those characteristic parameters. If the signaling originates from the S6a interface or the N12 interface and contains both a user unique identifier and AUTH information, these two will be paired and added to the relationship list. If the signaling originates from the S11 interface or the N11 interface and carries both a user unique identifier and IPTEID, these two sets of information will also be added to the relationship list accordingly. Through the above steps, a comprehensive list of relationships between user unique identifiers and characteristic parameters is created and maintained. Subsequently, when NAS signaling is received from the first target interface, this list can be efficiently utilized to quickly and accurately extract the target user's unique identifier associated with the NAS signaling.

[0096] For example, after obtaining the target user's unique identifier corresponding to the NAS signaling, if the target security context list corresponding to the target user's unique identifier is not obtained, the NAS signaling is stored in a buffer and a timer is run to wait for the target security context list; if the target security context list is not obtained after the timer expires, the NAS signaling is released. Specifically, when the security context list corresponding to the target user's unique identifier is not found immediately, the relevant NAS signaling is temporarily stored in a buffer. This buffer can be used to temporarily store signaling that is waiting for further processing so that the required security context list can be retried at a later time. Simultaneously with storing the NAS signaling in the buffer, a timer with a set waiting time threshold is started to control how long the system should remain in a waiting state before the target security context list appears. During the timer's execution, the security context list corresponding to the target user's unique identifier will continue to be attempted to be obtained. If the target security context list is successfully obtained within this time, the NAS signaling will continue to be processed and removed from the buffer. Figure 5As shown, assuming a waiting time threshold of 2 seconds, if the target security context list is obtained within 2 seconds, NAS signaling will continue to be processed. If the target security context list is not obtained after the timer expires, it means that NAS signaling cannot continue to be processed under the current conditions. At this time, the NAS signaling will be released from the buffer. It is worth noting that by caching NAS signaling and releasing it after the timer expires, deadlocks or crashes caused by waiting for uncertain resources can be avoided. In addition, when a large number of NAS signaling needs to be processed, the latency caused by resource waiting can be reduced, thereby improving user experience and satisfaction.

[0097] For example, the process of decrypting NAS signaling based on the acquired target security context includes: if decryption fails, storing the NAS signaling in a buffer and running a timer to reacquire the target security context list; if the target security context list is not acquired after the timer expires, releasing the NAS signaling. Specifically, when decrypting NAS signaling using the target security context fails, the NAS signaling is stored in a buffer. Simultaneously with storing the NAS signaling in the buffer, the target security context list is attempted to be reacquired. To control the waiting time for reacquiring the security context list, a timer with a set time threshold is started to control how long the system should remain in a waiting state before re-attempting decryption. If a new target security context list is successfully acquired within this time threshold, the NAS signaling will be decrypted again. If the system still has not acquired the target security context list after the timer expires, or if decryption still fails even after acquiring a new security context list, it means that NAS signaling cannot be processed under the current conditions. At this point, the NAS signaling is released from the buffer.

[0098] The following example illustrates the NAS signaling decryption process.

[0099] See Figure 12 , Figure 12 This is a flowchart of the NAS signaling decryption process provided in this application embodiment. After receiving encrypted NAS signaling, a security context information query is triggered. The specific implementation steps for triggering the query are as follows: Figure 12As shown: Step S1: If the received NAS signaling does not have an encrypted message header, i.e., it is unencrypted, it is directly sent to the data analysis system for further processing; otherwise, it enters different processing flows according to the encrypted message type. Step S2: If the encrypted message type is 3, a security context query is triggered. If the encrypted message type is not 3, the encrypted message header is skipped before being sent to the data analysis system for further processing. Step S3: If the encrypted message type is 4, a security context query is triggered. Step S4: Messages of encrypted message types 2 and 4 are encrypted themselves. If the security context information has been obtained, proceed to Step S5. Step S5: Verify whether the key is correct. When NAS signaling enables integrity protection, it carries a Message authentication code element, which can be used to verify the correctness of the key. When the message authentication code calculated using the integrity protection algorithm and integrity protection key matches the one carried in the signaling, the verification is considered successful. The signaling can then be decrypted using the encryption algorithm and encryption key, and the final key information of the security context is updated. If the security context information is not obtained or the verification fails, the NAS signaling is cached and a timer is run to wait for the target security context list to be retrieved again. For example, if a security context is found within 2 seconds, decryption is attempted again; otherwise, the cached NAS signaling is released. It should be noted that the data analysis system's processing can at least include: parsing and verifying NAS signaling, and corresponding business logic processing. For example, when parsing received NAS signaling messages, the data analysis system first parses the received NAS signaling to identify and extract various information elements and data fields from the message. Based on the parsed message content, the data analysis system executes corresponding business logic. It should be noted that in the NAS signaling decryption process of this example, encrypted message type 2 indicates integrity protected and ciphered, which is a general encrypted message; encrypted message type 3 indicates integrity protected with new 5G NAS security context, meaning the message itself is not encrypted, but only prompts for updating the security context, which is generally used by SECURITY MODE COMMAND; encrypted message type 4 indicates integrity protected and ciphered with new 5G NAS security context, meaning the message itself is encrypted, which is used by SECURITY MODE COMPLETE.

[0100] For example, based on the NAS signaling decryption process described in the above embodiments, this application also provides a NAS decryption device, such as... Figure 13 As shown, the decryption device includes a user unique identifier backfilling module, a security context maintenance module, and a NAS decryption processing module. The user unique identifier backfilling module maintains a list of relationships between user unique identifiers and feature parameters. Specifically, when the AMF / MME peripheral interface carries a user unique identifier, it can create and update the list of relationships between the user unique identifier and feature parameters carried by itself and the NAS signaling. When the NAS signaling does not carry a user unique identifier, it ensures that the user unique identifier can be obtained by querying the list of relationships between user unique identifiers and feature parameters. The security context maintenance module maintains a list of security contexts corresponding to the user unique identifier. Specifically, when the S6a / N12 / S10 / N26 / N14 interfaces carry a user unique identifier and security context parameters, it creates a list of security contexts corresponding to the user unique identifier. After the NAS signaling obtains the user unique identifier, it obtains and matches security context information by querying the list of security contexts corresponding to the user unique identifier. After the NAS signaling is successfully decrypted by the NAS decryption processing module, the security context list is updated. The NAS decryption module triggers security context queries to decrypt NAS signaling. Specifically, this includes: triggering a security context query; decrypting the NAS signaling based on the returned security context information; and caching the NAS signaling if no security context is currently available. Additionally, the data acquisition system can collect MME / AMF peripheral interface signaling. After interface parsing and basic signaling decoding, the signaling is processed by the user unique identifier backfilling module. The data analysis system module can be used for NAS signaling parsing, verification, and corresponding business logic processing.

[0101] Reference Figure 14 This application also discloses an electronic device, the electronic device 1400 comprising: One or more processors 1401; The memory 1402 stores one or more programs that, when executed by one or more processors 1401, cause the one or more processors 1401 to implement the non-access stratum (NAS) signaling decryption method as described in any of the preceding embodiments.

[0102] In addition, one embodiment of this application discloses a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the non-access stratum (NAS) signaling decryption method as described in any of the preceding embodiments.

[0103] Furthermore, one embodiment of this application also discloses a computer program product, including a computer program that, when executed by a processor, implements the non-access stratum (NAS) signaling decryption method as described in any of the preceding embodiments.

[0104] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0105] The above is a detailed description of the preferred embodiments of this application. However, this application is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of this application. All such equivalent modifications or substitutions are included within the scope defined by the claims of this application.

Claims

1. A method for decrypting non-access stratum (NAS) signaling, the method comprising: Receive NAS signaling from the first target interface; Obtain the unique identifier of the target user corresponding to the NAS signaling, and obtain the target security context list corresponding to the unique identifier of the target user, wherein the target security context list includes security contexts of at least one network standard; The target security context corresponding to the network standard of the first target interface is determined based on the target security context list. The NAS signaling is decrypted using the target security context.

2. The method according to claim 1, characterized in that, The target security context includes raw key information for at least one network standard; Determining the target security context corresponding to the network standard of the first target interface based on the target security context list includes: When the NAS signaling is a security mode control message, the target original key information corresponding to the network type of the first target interface is obtained from the target security context list; The target security context is obtained based on the target original key information, as well as the integrity protection algorithm information and encryption algorithm information carried in the security mode control message.

3. The method according to claim 2, characterized in that, The raw key information for each network standard includes multiple sets of raw key information, each set of raw key information including AUTH parameters and raw keys; obtaining the target raw key information corresponding to the network standard of the first target interface from the target security context list includes: When the NAS signaling carries the AUTH parameter, the target original key information corresponding to the network type of the first target interface and the AUTH parameter is obtained from the target security context list.

4. The method according to claim 2, characterized in that, Based on the target original key information, and the integrity protection algorithm information and encryption algorithm information carried in the security mode control message, the target security context is obtained, including: When the source of the target original key information is a second target interface corresponding to the network standard of the first target interface, the target security context is obtained based on the target original key information, as well as the integrity protection algorithm information and encryption algorithm information carried by the security mode control message.

5. The method according to claim 1, characterized in that, The target security context includes at least one network standard integrity protection key and encryption key; Determining the target security context corresponding to the network standard of the first target interface based on the target security context list includes: If the NAS signaling is not a security mode control message and the TSC information cell of the first target interface has a network handover scenario identifier, the target integrity protection key and the target encryption key corresponding to the network type of the first target interface are obtained from the target security context list to obtain the target security context.

6. The method according to claim 1, characterized in that, The target security context includes at least one network standard's original key information, integrity protection algorithm information, and encryption algorithm information; Determining the target security context corresponding to the network standard of the first target interface based on the target security context list includes: When the NAS signaling is not a security mode control message and the TSC information cell of the first target interface does not have a network handover scenario identifier, the target original key information, target integrity protection algorithm information and target encryption algorithm information corresponding to the network type of the first target interface are obtained from the target security context list to obtain the target security context.

7. The method according to claim 6, characterized in that, The step of obtaining the target security context from the target security context list, including retrieving the target original key information, target integrity protection algorithm information, and target encryption algorithm information corresponding to the network standard of the first target interface, includes: Obtain the target original key information, target integrity protection algorithm information, and target encryption algorithm information corresponding to the network standard of the first target interface from the target security context list; When the source of the target original key information is a second target interface corresponding to the network standard of the first target interface, the target security context is obtained based on the target original key information, the target integrity protection algorithm information, and the target encryption algorithm information.

8. The method according to claim 1, characterized in that, After decrypting the NAS signaling using the target security context, the method further includes: If decryption is successful, the integrity protection key and encryption key used for decryption will be updated in the target security context.

9. The method according to claim 1, characterized in that, Before obtaining the target security context list corresponding to the unique identifier of the target user, the process also includes: Create a list of security contexts corresponding to the user's unique identifier.

10. The method according to claim 9, characterized in that, The creation of a security context list corresponding to a user's unique identifier includes: Obtain the original key information from the second target interface, and obtain the user's unique identifier corresponding to the original key information. The second target interface includes interfaces of various network standards. Add the original key information and the source of the original key information to the security context list corresponding to the user's unique identifier.

11. The method according to claim 10, characterized in that, The second target interface includes at least one of the S6a interface and the N12 interface; obtaining the original key information from the second target interface includes at least one of the following: Obtain multiple sets of original keys corresponding to the first network standard from the S6a interface; Obtain multiple sets of original keys corresponding to the second network standard from the N12 interface.

12. The method according to claim 9, characterized in that, The creation of a security context list corresponding to a user's unique identifier includes: The integrity protection algorithm information and encryption algorithm information are obtained from the security mode control message from the first target interface, and the user unique identifier corresponding to the integrity protection algorithm information and the encryption algorithm information is obtained. The first target interface includes interfaces of various network standards. Add the integrity protection algorithm information and the encryption algorithm information to the security context list corresponding to the user's unique identifier.

13. The method according to claim 12, characterized in that, The first target interface includes at least one of the S1MME interface and the N1N2 interface; obtaining integrity protection algorithm information and encryption algorithm information from the security mode control message from the first target interface includes at least one of the following: Obtain the integrity protection algorithm information and encryption algorithm information corresponding to the first network standard from the security mode control message from the S1MME interface; Obtain the integrity protection algorithm information and encryption algorithm information corresponding to the second network standard from the security mode control message from the N1N2 interface.

14. The method according to claim 9, characterized in that, The creation of a security context list corresponding to a user's unique identifier includes: The integrity protection key and encryption key are obtained from the third target interface, and the user unique identifier corresponding to the integrity protection key and the encryption key is obtained. The third target interface includes interfaces of various network standards, and the TSC information cell of the first target interface has a network handover scenario identifier. Add the integrity protection key and the encryption key to the security context list corresponding to the user's unique identifier.

15. The method according to claim 14, characterized in that, The third target interface includes at least one of the S10 interface, N14 interface, and N26 interface; obtaining the integrity protection key and encryption key from the third target interface includes at least one of the following: Obtain the integrity protection key and encryption key corresponding to the first network standard from the S10 interface or N26 interface; Obtain the integrity protection key and encryption key corresponding to the second network standard from the N14 interface or N26 interface.

16. The method according to claim 1, characterized in that, The step of obtaining the unique identifier of the target user corresponding to the NAS signaling includes one of the following: Obtain the unique identifier of the target user from the NAS signaling; or, If the NAS signaling does not carry a unique user identifier, the target feature parameters are obtained from the NAS signaling, and the unique user identifier corresponding to the target feature parameters is obtained from the list of relationships between unique user identifiers and feature parameters.

17. The method according to claim 1, characterized in that, Before obtaining the unique identifier of the target user corresponding to the NAS signaling, the process also includes: Create a list of relationships between user unique identifiers and characteristic parameters; Obtain the user's unique identifier and the corresponding feature parameters from the signaling from the fourth target interface; Add the user's unique identifier and the corresponding feature parameters to the user's unique identifier and feature parameter relationship list; The fourth target interface includes at least one of the following: S1MME interface, N1N2 interface, S6a interface, N12 interface, S11 interface, and N11 interface.

18. The method according to claim 1, characterized in that, The method further includes: If the target security context list corresponding to the unique identifier of the target user is not obtained or decryption fails, the NAS signaling is stored in the buffer and a timer is run to wait for the target security context list; If the target security context list is not obtained after the timer expires, the NAS signaling will be released.

19. An electronic device comprising: One or more processors; A memory having stored one or more programs that, when executed by one or more processors, cause the one or more processors to implement the Non-Access Stratum (NAS) signaling decryption method as described in any one of claims 1-18.

20. A computer-readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the Non-Access Stratum (NAS) signaling decryption method as described in any one of claims 1-18.

21. A computer program product comprising a computer program that, when executed by a processor, implements the Non-Access Stratum (NAS) signaling decryption method as described in any one of claims 1-18.