Method and system for remotely updating authentication algorithm in USIM or eSIM card by 5GC
By pre-installing authentication and authorization algorithm code in UDM and USIM/eSIM, and leveraging the collaborative work of AMF and UDM, remote updates of USIM/eSIM cards in 5G private networks are achieved. This solves the problem of online updates being impossible in existing technologies, improves security and operational efficiency, and adapts to the diverse security needs of key industries.
Patent Information
- Application Number
- CN202511759128.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-26
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2045-11-26
AI Technical Summary
Existing technologies cannot update the authentication and authorization algorithms of USIM/eSIM cards in 5G private networks online, resulting in insufficient security, high operating costs, and an inability to meet the security and operational efficiency requirements of key industries.
Multiple authentication and authorization algorithm executable codes are pre-installed in UDM and USIM/eSIM. Through the collaborative work of AMF and UDM, the authentication and authorization algorithms are updated remotely. AA IE is used for state switching and two-way authentication to achieve automatic updates for all users.
It supports remote switching between national standard and industry-customized authentication and authorization algorithms, enhances communication security, reduces manpower and equipment costs, simplifies operation and maintenance processes, and ensures communication stability and flexibility.
Smart Images

Figure CN121586006A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of 5G mobile communication technology, in particular to a method and system for remotely updating authentication algorithm in 5GC USIM or eSIM card. BACKGROUND
[0002] In the 5G mobile communication network, the USIM / eSIM card is the core carrier of user identity recognition and security authentication, which needs to store authentication algorithm, encryption key and other key information, and needs to use the matching authentication algorithm with the unified data management network element (UDM) to ensure the communication security of UE and network through mutual authentication. The current 3GPP 5G standard does not specify the online update scheme of authentication algorithm in USIM / eSIM card, and two methods are mainly used in industry practice: one is that the operator writes the authentication algorithm and related information offline into the USIM card according to the demand before card issuance, and the algorithm information in UDM is also configured offline by the manufacturer, so that the algorithm cannot be modified or switched online after network delivery; the other is to store the algorithm information to be updated in the OTA (Over The Air) server in advance or obtain it from the operator's specified database, and then push it to the USIM card of UE to realize the update. For the 5G private network independently constructed by domestic key industries, the replacement scheme of authentication algorithm also depends on offline configuration, that is, the algorithm information of UDM and USIM card is written offline before network delivery, and cannot be adjusted online after delivery.
[0003] The existing technical solutions have significant defects and cannot meet the security and operation efficiency requirements of key industry 5G private network: on the one hand, key industry private network needs to use national standard or industry standard authentication algorithm, and needs to switch algorithm regularly to avoid security risks, but the existing offline card writing and card replacement update method needs to invest a lot of manpower to reissue cards, which is complicated and easy to interrupt network service; on the other hand, the private network operator is usually the customer's IT department, which lacks the operation and maintenance capability of the operator level, and the additional deployment of OTA system will increase the equipment cost and maintenance complexity, which does not meet the needs of private network "simplified system and automatic operation". In addition, the existing related patents do not cover the authentication algorithm update scenario, or are only applicable to 3G network, which cannot adapt to the architecture and function requirements of 5G private network, resulting in obvious shortcomings in algorithm flexibility and update efficiency of key industry private network.
[0004] Therefore, there is an urgent need for a method for remotely updating authentication algorithm in 5GC USIM or eSIM card to solve the problems of existing technology, such as inability to update authentication algorithm of USIM / eSIM and UDM online, insufficient security, high operation cost, etc. SUMMARY
[0005] To this end, the application provides a method and system for 5GC remote updating of authentication algorithms in USIM or eSIM cards, solving the problems of the prior art, such as inability to update authentication algorithms of USIM / eSIM and UDM online, need for offline card writing and card replacement or additional deployment of an OTA system, resulting in insufficient security, high operating costs and the like.
[0006] To achieve the above-mentioned purpose, the application provides the following technical solutions: a method for 5GC remote updating of authentication algorithms in USIM or eSIM cards, characterized by comprising:
[0007] Pre-installing several authentication algorithm executable codes in UDM and USIM / eSIM;
[0008] Based on the user group authentication algorithm use strategy pre-configured in UDM, or when the current effective algorithm reaches the configured use period, UDM performs authentication algorithm update operation and sends a user authentication algorithm change notification containing target user information and new algorithm information to all AMFs within the UDM service range;
[0009] AMF updates the locally stored UE security capability AA IE based on the new algorithm information; constructs an update schedule table of user UE authentication algorithms and initializes it to obtain the initialized update schedule table;
[0010] AMF identifies the unconfirmed updated UE in the update schedule table and sends a configuration update message carrying AA IE to the unconfirmed updated UE;
[0011] UE extracts AA IE from the configuration update message and passes it to USIM / eSIM; USIM / eSIM locates the pre-installed authentication algorithm executable code based on the new algorithm ID and state information in AA IE, sets the new algorithm state to active and the original active algorithm state to inactive; after completing the update, UE sends an update completion confirmation message to AMF and calls the executable code of the new algorithm to complete bidirectional authentication with UDM through the pre-installed matching algorithm;
[0012] AMF receives the update completion confirmation message, updates the update schedule table, and reports the updated update schedule table to UDM; UDM summarizes the updated update schedule table and updates the user authentication algorithm table, changing the new algorithm state of the confirmed updated user from Pre-active to Active;
[0013] For the UE in roaming state or temporarily unable to receive messages in the update schedule, the AMF maintains the state unchanged and pings periodically; when the UE in roaming state or temporarily unable to receive messages roams back to the network served by the UDM and reestablishes the RRC connection, the algorithm update process is performed until the full-amount user authentication and authorization algorithm update is realized.
[0014] As a preferred solution of the method for remotely updating the authentication algorithm in the USIM or eSIM card in the 5GC, the AA IE is of the BITSTRING type and has a length not less than 16 bits, and each 1 bit corresponds to 1 pre-installed authentication and authorization algorithm; the 1st bit corresponds to the Milenage algorithm set, the 2nd bit corresponds to the TUAK algorithm set, the 3rd bit corresponds to the SM4 algorithm, and the 4th-15th bits are reserved bits; if the bit value in the AA IE is 1, it indicates that the corresponding authentication and authorization algorithm has been pre-installed and is to be activated; if the bit value is 0, it indicates that the corresponding authentication and authorization algorithm is not pre-installed or does not need to be activated.
[0015] As a preferred solution of the method for remotely updating the authentication algorithm in the USIM or eSIM card in the 5GC, the update schedule includes user identification information, authentication algorithm information, AMF identification information and update state information.
[0016] As a preferred solution of the method for remotely updating the authentication algorithm in the USIM or eSIM card in the 5GC, the AMF obtains the user authentication and authorization algorithm change notification sent by the UDM through two ways; one is that the AMF pre-subscribes to the data management change notification from the UDM, and when the UDM detects the change of the user authentication and authorization algorithm data, the AMF pushes the user authentication and authorization algorithm change notification based on the subscription relationship; the second is that the UDM actively detects the change of the user authentication and authorization algorithm data, and sends the user authentication and authorization algorithm change notification to all AMFs within the service range.
[0017] As a preferred solution of the method for remotely updating the authentication algorithm in the USIM or eSIM card in the 5GC, when the AMF sends the configuration update message carrying the AA IE to the UE which has not confirmed the update, if the UE is in a connected state, the AMF sends the configuration update message to the UE; if the UE is in a non-connected state, the AMF pages the UE through the gNB, and after the UE reestablishes the RRC connection with the gNB, the configuration update message is sent to the UE.
[0018] The application also provides a system for remotely updating the authentication algorithm in the USIM or eSIM card in the 5GC, based on the above-mentioned method for remotely updating the authentication algorithm in the USIM or eSIM card in the 5GC, comprising:
[0019] The authentication and authorization algorithm executable code pre-installation module is used for pre-installing a plurality of authentication and authorization algorithm executable codes in the UDM and the USIM / eSIM.
[0020] A user authentication and authorization algorithm change notification sending module is configured to send a user authentication and authorization algorithm change notification containing target user information and new algorithm information to all AMFs within the service range of the UDM based on a user group authentication and authorization algorithm use policy pre-configured in the UDM or when the current effective algorithm reaches the configured use period, and the UDM performs an authentication and authorization algorithm update operation.
[0021] A user UE authentication and authorization algorithm update progress table construction and initialization module is configured to update the locally stored UE security capability AA IE based on the new algorithm information and the executable code of the authentication and authorization algorithm, construct a user UE authentication and authorization algorithm update progress table, and initialize the update progress table to obtain the initialized update progress table.
[0022] A configuration update message sending module is configured to send a configuration update message carrying an AA IE to a UE that has not been updated in the update progress table.
[0023] A new algorithm update starting module is configured to extract the AA IE from the configuration update message and pass it to the USIM / eSIM, locate the pre-installed executable code of the authentication and authorization algorithm based on the new algorithm ID and state information in the AA IE, set the new algorithm state to active and the original active algorithm state to inactive, and after the update is completed, the UE sends an update completion confirmation message to the AMF and calls the executable code of the new algorithm to complete bidirectional authentication with the UDM through the pre-installed matching algorithm.
[0024] A user UE authentication and authorization algorithm update progress table updating module is configured to update the update progress table after the AMF receives the update completion confirmation message and report the updated update progress table to the UDM, and the UDM aggregates the updated update progress table and updates the user authentication and authorization algorithm table to change the new algorithm state of the user that has confirmed the update from Pre-active to Active.
[0025] A non-online user configuration update processing module is configured to maintain the state of a UE in a roaming state or temporarily unable to receive messages in the update progress table unchanged and periodically page, and when the UE in a roaming state or temporarily unable to receive messages roams back to the network of the UDM service and re-establishes an RRC connection, perform algorithm update processing until full user authentication and authorization algorithm update is achieved.
[0026] As a preferred solution of the system for remotely updating authentication algorithms in a USIM or eSIM card of a 5GC, in the user UE authentication algorithm update progress table construction and initialization module, the AA IE is of a BIT STRING type and has a length of no less than 16 bits, and each 1 bit corresponds to 1 pre-installed authentication algorithm; the 1st bit corresponds to a Milenage algorithm set, the 2nd bit corresponds to a TUAK algorithm set, the 3rd bit corresponds to an SM4 algorithm, and the 4th to 15th bits are reserved bits; if the bit value in the AA IE is 1, it indicates that the corresponding authentication algorithm has been pre-installed and is to be activated; if the bit value is 0, it indicates that the corresponding authentication algorithm has not been pre-installed or does not need to be activated.
[0027] As a preferred solution of the system for remotely updating authentication algorithms in a USIM or eSIM card of a 5GC, in the user UE authentication algorithm update progress table construction and initialization module, the update progress table includes user identification information, authentication algorithm information, AMF identification information and update state information.
[0028] As a preferred solution of the system for remotely updating authentication algorithms in a USIM or eSIM card of a 5GC, in the user authentication algorithm change notification sending module, the AMF obtains the user authentication algorithm change notification sent by the UDM through two ways; one is that the AMF pre-subscribes to the data management change notification of the UDM, and when the UDM detects a change in the user authentication algorithm data, it pushes the user authentication algorithm change notification to the AMF based on the subscription relationship; two is that after the UDM actively detects a change in the user authentication algorithm data, it sends the user authentication algorithm change notification to all AMFs within the service range.
[0029] As a preferred solution of the system for remotely updating authentication algorithms in a USIM or eSIM card of a 5GC, in the non-online user configuration update processing module, when the AMF sends a configuration update message carrying the AA IE to the UE that has not confirmed the update, if the UE is in a connected state, the AMF sends the configuration update message to the UE; if the UE is in a non-connected state, the AMF pages the UE through the gNB, and after the UE re-establishes the RRC connection with the gNB, the configuration update message is sent to the UE.
[0030] The present application has the following advantages:
[0031] Firstly, the present application supports remote switching of national standards and industry customized authentication algorithms, can update algorithms regularly to avoid security vulnerabilities, and greatly improves the communication security protection capability of 5G special networks in key industries.
[0032] Secondly, the present application does not need offline card writing, card replacement or additional deployment of an OTA system, and automatically updates through the cooperation of 5GC native network elements, reduces the manpower investment and equipment cost of the special network IT department, and simplifies the operation and maintenance process.
[0033] Third, the UDM and the USIM / eSIM pre-installed algorithm executable code, only need to switch algorithm state when updating, no need to download additional programs, combined with AMF periodic paging and roaming back to the mechanism of updating, to achieve the full amount of user fast synchronization update.
[0034] Fourth, the application supports multi-user group differentiated algorithm configuration, algorithm iteration upgrade, roaming user coverage and other scenarios, which can flexibly match the diversified security needs and operation mode of key industry private network.
[0035] Fifth, based on the 3GPP 5G standard architecture design, compatible with USIM / eSIM two kinds of card types, through the state rollback mechanism and bidirectional authentication verification, ensure that the algorithm update process does not interrupt the network service, and guarantee the stability of communication. BRIEF DESCRIPTION OF DRAWINGS
[0036] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only exemplary, and for those skilled in the art, other drawings can be derived from the provided drawings without creative labor.
[0037] The structure, proportion, size and the like shown in the specification are only used to cooperate with the content disclosed in the specification, so that those skilled in the art can understand and read, and are not used to limit the limiting conditions of the implementation of the present application, so they do not have technical significance. Any modification of structure, change of proportion relationship or adjustment of size, without affecting the effect and purpose that the present application can produce, should still fall within the scope of the technical content disclosed by the present application.
[0038] Figure 1 A flowchart of a method for 5GC remote updating authentication algorithm in USIM or eSIM card provided in embodiment 1 of the present application is shown in the figure;
[0039] Figure 2 A specific implementation flowchart of the present application in a possible embodiment provided in embodiment 1 of the present application is shown in the figure;
[0040] Figure 3 A schematic diagram of the architecture of a system for 5GC remote updating authentication algorithm in USIM or eSIM card provided in embodiment 2 of the present application is shown in the figure. DETAILED DESCRIPTION
[0041] The objectives, technical solutions, and advantages of the present application will become more apparent after reading the detailed description of the embodiments of the present application with reference to the drawings, wherein:
[0042] The following are the meanings of the English words or abbreviations involved in the following content:
[0043] 5GC: 5G Core Network, the core system of the fifth generation mobile communication network;
[0044] AA: Authentication Algorithm, authentication algorithm;
[0045] eSIM: Embedded-SIM, embedded SIM card;
[0046] UICC: Universal Integrated Circuit Card, universal integrated circuit card;
[0047] UDM: Unified Data Management, Unified Data Management (network element);
[0048] USIM: User Service Identity Module, User Service Identity Module;
[0049] AMF: Access and Mobility Management Function, Access and Mobility Management Function (network element);
[0050] AES: Advanced Encryption Standard, Advanced Encryption Standard;
[0051] AKA: Authentication and Key Agreement, Authentication and Key Agreement;
[0052] AUSF: Authentication Server Function, Authentication Server Function (network element);
[0053] SMF: Session Management function, Session Management function (network element);
[0054] PCRF: Policy and Charging Rules Function, policy and charging rules function (network element);
[0055] UPF: User Plane Function, user plane function (network element).
[0056] Embodiment 1
[0057] Referring to Figure 1 Embodiment 1 of the present application provides a method for 5GC to remotely update authentication algorithms in USIM or eSIM cards, comprising the following steps:
[0058] S1, preinstall several authentication algorithm executable codes required in the life cycle of UDM and USIM / eSIM in both of them;
[0059] S2, based on the user group authentication algorithm use strategy preconfigured in UDM, or when the current effective algorithm reaches the configured use period, UDM performs authentication algorithm update operation, and sends user authentication algorithm change notification containing target user information and new algorithm information to all AMFs within the service range of UDM;
[0060] S3, AMF matches the authentication algorithm executable code preinstalled in UDM based on the new algorithm information, updates the locally stored UE security capability AA IE, constructs the update schedule table of user UE authentication algorithm, initializes, and obtains the initialized update schedule table;
[0061] S4, AMF identifies the unconfirmed updated UE based on the initialized update schedule table, and sends a configuration update message carrying AA IE to the unconfirmed updated UE until the UE receives successfully;
[0062] S5, UE extracts AA IE from the configuration update message and delivers it to USIM / eSIM; USIM / eSIM locates the preinstalled authentication algorithm executable code based on the new algorithm ID and state information in AA IE, sets the new algorithm state to active, and the original active algorithm state to inactive; after completing the update, UE replies to the AMF with an update completion confirmation message, and calls the executable code of the new algorithm to initiate a primary authentication request, and completes the mutual authentication with UDM through the preinstalled matching algorithm;
[0063] S6. After the update completion confirmation message is received, the AMF updates the update progress table and reports the updated update progress table to the UDM. The UDM summarizes the updated update progress table reported by the AMF and obtains the summary result. Based on the summary result, the UDM updates the user authentication and authorization algorithm table stored in the UDM and changes the new algorithm status of the confirmed updated users from Pre-active to Active.
[0064] S7. For UEs that are in roaming status or temporarily unable to receive messages in the initial update schedule, the AMF maintains the update status unchanged and periodically pages them; when a UE that is in roaming status or temporarily unable to receive messages roams back to the UDM service network and rebuilds the RRC connection, the algorithm update process is performed until the full user authentication and authorization algorithm is updated.
[0065] In this embodiment, in step S1, executable code for several authentication and authorization algorithms required throughout their lifecycle is pre-installed in the UDM and USIM / eSIM.
[0066] Specifically, as a unified data management network element, the UDM needs to store executable code for various authentication and authorization algorithms, including but not limited to the Milenage algorithm set, the TUAK algorithm set, and the SM4 algorithm. It must ensure that these codes are consistent with the versions installed in the USIM / eSIM to meet the compatibility requirements of two-way authentication. The USIM / eSIM, as the secure carrier of the user terminal, synchronously pre-installs the same algorithm executable code, storing it in its secure storage area to prevent unauthorized access and tampering. Pre-installation avoids the code download process during updates; only a state switch is needed to enable the algorithm, improving update efficiency and security.
[0067] In this embodiment, in step S2, based on the user group authentication and authorization algorithm usage strategy pre-configured in UDM, or when the currently effective algorithm reaches the configured usage period, UDM performs an authentication and authorization algorithm update operation and sends a user authentication and authorization algorithm change notification containing target user information and new algorithm information to all AMFs within the UDM service range.
[0068] Specifically, the pre-configured user group policies in UDM can set algorithm switching rules for different user groups based on factors such as the user's industry and security level. For example, users in a specific industry may switch algorithms every 3 months. Simultaneously, UDM monitors the usage period of the currently effective algorithm in real time and automatically triggers an update when the preset period is reached. After triggering the update, UDM generates a notification of the change in the user authentication algorithm. The target user information can be uniquely identified through SUPI (User Permanent Identifier), and the new algorithm information includes the algorithm ID, corresponding function identifier, etc., ensuring that AMF can accurately identify the algorithm that needs to be updated. The notification is then sent to all AMFs within its service area, initiating a network-wide update process.
[0069] The AMF obtains user authentication algorithm change notifications sent by the UDM in two ways: First, the AMF subscribes to data management change notifications from the UDM in advance. When the UDM detects a change in the user authentication algorithm data, it pushes the user authentication algorithm change notification to the AMF based on the subscription relationship. Second, after the UDM actively detects a change in the user authentication algorithm data, it sends the user authentication algorithm change notification to all AMFs within its service range.
[0070] In this embodiment, in step S3, the AMF updates the AA IE of the UE security capabilities stored locally by matching the new algorithm information with the executable code of the authentication and authorization algorithm pre-installed in the UDM; it constructs and initializes the update schedule of the user UE authentication and authorization algorithm to obtain the initialized update schedule.
[0071] Specifically, upon receiving a change notification from the UDM, the AMF first matches the corresponding pre-installed authentication and authorization algorithm executable code in the UDM with the algorithm ID from the new algorithm information to confirm the algorithm's validity and completeness. Subsequently, the AMF updates the AA IE (Authentication Algorithm Information Element) in the locally stored UE security capability data. The AA IE uses a bit string format, with each bit corresponding to a pre-installed algorithm, and the 0 / 1 status of the bit value indicates whether the algorithm is yet to be activated. Simultaneously, the AMF constructs an update progress table, which includes the user's SUPI, the bit string corresponding to the new algorithm, the AMF's own ID, and the update status. This table tracks the algorithm update progress for each user, providing a basis for subsequent message sending and status synchronization.
[0072] In this AA IE, the bit string is of type BIT STRING and is at least 16 bits long. Each bit corresponds to one pre-installed authentication algorithm. The first bit corresponds to the Milenage algorithm set, the second bit corresponds to the TUAK algorithm set, the third bit corresponds to the SM4 algorithm, and bits 4-15 are reserved. If a bit value of 1 in the AA IE, it means that the corresponding authentication algorithm has been pre-installed and is waiting to be activated. If a bit value of 0, it means that the corresponding authentication algorithm has not been pre-installed or does not need to be activated.
[0073] In this embodiment, in step S4, the AMF identifies UEs that have not confirmed the update based on the initialized update schedule, and sends a configuration update message carrying AA IE to the UEs that have not confirmed the update until the UEs successfully receive it.
[0074] Specifically, the AMF initiates targeted update message pushes based on user records marked "Unconfirmed Update" in the update progress table. The configuration update message uses the format "UE generic configuration update," carrying the updated AA IE from step S3, explicitly indicating the new algorithm the UE needs to activate. If the UE is connected, the AMF sends the message directly through the existing connection; if the UE is idle, the AMF initiates paging via the gNB, waiting for the UE to re-establish the RRC connection before sending the message. The AMF continuously monitors the message transmission status; if no confirmation of receipt is received from the UE, it will resend the message according to a preset period until successful reception by the UE is confirmed, ensuring the update command effectively reaches the terminal.
[0075] In this embodiment, in step S5, the UE extracts the AA IE from the configuration update message and passes it to the USIM / eSIM; the USIM / eSIM locates the pre-installed authentication algorithm executable code based on the new algorithm ID and status information in the AA IE, sets the new algorithm status to active, and sets the original active algorithm status to inactive; after the update is completed, the UE replies to the AMF with an update completion confirmation message, and calls the executable code of the new algorithm to initiate a main authentication request, and completes two-way authentication with the UDM through the pre-installed matching algorithm.
[0076] Specifically, after receiving the configuration update message, the UE parses and extracts the AA IE (Application Authentication Interface) and passes it to the USIM / eSIM for processing. Based on the new algorithm ID in the AA IE, the USIM / eSIM locates the target algorithm in its pre-installed algorithm executable code and switches the new algorithm's running state to active based on the status information, while simultaneously setting the original active algorithm's state to inactive, achieving seamless algorithm switching. After the state switch is complete, the UE sends a "UEgeneric configuration complete" confirmation message to the AMF (Application Management Function) to indicate that the update is complete. Subsequently, the UE immediately invokes the executable code of the new algorithm to initiate a primary authentication request, completing two-way authentication with the UDM (User Device Manager) using the pre-installed matching algorithms of both parties to verify the validity and compatibility of the new algorithm.
[0077] In this embodiment, in step S6, after the AMF receives the update completion confirmation message, it updates the update progress table and reports the updated update progress table to the UDM. The UDM summarizes the updated update progress table reported by the AMF and obtains a summary result. Based on the summary result, the UDM updates the user authentication and authorization algorithm table stored in the UDM and changes the new algorithm status of the confirmed updated users from Pre-active to Active.
[0078] Specifically, after receiving the update completion confirmation message from the UE, the AMF immediately changes the update status of the corresponding user from "unconfirmed update" to "confirmed update" in the update progress table, completing local progress tracking. Subsequently, the AMF reports the updated progress table to the UDM periodically or in real time, ensuring that the UDM has a grasp of the update dynamics across the entire network. The UDM collects all progress tables reported by the AMF, performs summary analysis, and counts the number and details of users who have completed and have not completed the update. Based on the summary results, the UDM updates its own stored user authentication and authorization algorithm table, adjusting the new algorithm status of confirmed update users from Pre-active to Active, marking the completion of the algorithm update process for that user on the network side.
[0079] In this embodiment, in step S7, for UEs that are in roaming status or temporarily unable to receive messages in the initial update schedule, the AMF maintains the update status unchanged and periodically pages them; when a UE that is in roaming status or temporarily unable to receive messages roams back to the UDM service network and rebuilds the RRC connection, the algorithm update process is performed until the full user authentication and authorization algorithm is updated.
[0080] Specifically, for UEs in roaming status or temporarily unable to receive messages due to signal issues, power off, or other reasons, the AMF does not change their "unconfirmed update" status and initiates paging at a preset frequency to ensure that these UEs receive update instructions promptly when they reconnect to the network. When a roaming UE returns to the UDM service network and rebuilds its RRC connection, or when a UE temporarily unable to receive messages regains communication capability, the AMF immediately repeats steps S4 to S6, sending configuration update messages, tracking update progress, and synchronizing with the UDM. Ultimately, this achieves the update of authentication and authorization algorithms for all target users, ensuring the consistency and security of the entire network algorithm.
[0081] In one possible embodiment, a specific algorithm update example is provided as follows:
[0082] like Figure 2 As shown, the specific update steps are as follows:
[0083] T1, UDM, and USIM / eSIM all contain pre-installed executable code for various authentication and authorization algorithms that will be used throughout their lifecycle.
[0084] T2. After configuring the authentication and authorization algorithm policy (which specifies which users use which set of authentication and authorization algorithms at which time period) table for a batch of users in the ready industry customer private network on the "Multi-Authentication and Authorization Algorithm UDM": AMF will notify AMF of "which UEs' authentication and authorization algorithms have changed" by "subscribing to data management change notifications" to UDM, or by UDM proactively notifying AMF of "which UEs' authentication and authorization algorithms have changed" when it detects changes in user data.
[0085] T3. In the UE security capability data definition in UDM and AMF, a new IE needs to be added: In this embodiment, the Authentication Algorithm (AA) IE is defined as shown in Table 1:
[0086] IE / Group Name Presence Range IE type and reference Semantics description Authentication Algorithms (AA) M BIT STRING (SIZE(16, …))
[0087] Table 1 Authentication Algorithm (AA) IE
[0088] In Table 1, each bit in the Bit string represents an authentication algorithm: "All bits are 0" means the UE does not support any authentication algorithm; "1st bit" corresponds to the Milenage algorithm set; "2nd bit" corresponds to the TUAK algorithm set; "3rd bit" corresponds to the SM4 algorithm; "4-15 bits" are reserved for future use. A bit value of 1 indicates that the algorithm represented by this bit is supported and needs to be activated; a bit value of 0 indicates that the algorithm represented by this bit is not supported. For algorithm descriptions, please refer to TS 33.401
[15] and the "SM4 Block Cipher Algorithm" standard (GM / T 0002-2012) issued by the State Cryptography Administration of China.
[0089] Meanwhile, the AMF must contain an authentication algorithm ID to be configured for UISM / eSIM, and its status is shown in Table 2:
[0090] Subscribers Authentication Algorithm AMF ID Status of the Authentication Algorithm updated SUPI / other BIT STRING (SIZE(16, …)) ID of the AMF responsible for updating the UE Done / Not Done
[0091] Table 2 Authentication and Authorization Algorithm ID Machine Status
[0092] After receiving a notification from the UDM that the user authentication algorithm data has changed (including the ID of the newly activated authentication algorithm), the AMF will update the locally stored "UE security capability AA IE". This update triggers the AMF to send a UEgeneric configuration update message to the UE, carrying the above AA IE.
[0093] After receiving this message, T4 and UE retrieve the information from the AA IE and hand it over to USIM. USIM then updates its authentication algorithm and its status list based on this information, sets the status of the new algorithm to active (pre-activated), and sets the status of the currently active authentication algorithm to "inactive".
[0094] T5. After the UE completes this modification: The UE replies to the AMF with the message "UE generic configuration complete" to confirm completion and immediately uses the new authentication algorithm; it initiates a main authentication request and uses the new authentication algorithm to complete the two-way authentication between the UE and the network.
[0095] T6 and AMF confirm, based on the messages received from the UE, that all UEs in the service area have been updated one by one, and refresh the local user UE authentication algorithm update progress table (ID corresponds to authentication algorithm, and new algorithm update status table).
[0096] T7 and AMF will update the UE authentication and authorization algorithm update schedule.
[0097] T8. For the refresh of the UE authentication algorithm update schedule, the AMF is triggered to report the "refreshed UE authentication algorithm update schedule" to the UDM.
[0098] T9 and UDM summarize the reports from all AMFs they serve and then update their user authentication and authorization algorithm table. This table lists the authentication and authorization algorithm groups currently used by different users / user groups, and whether they are currently using them, as shown in Table 3.
[0099] User Authentication Algorithm AMF ID Status of the Authentication Algorithm currently SUPI / other BIT STRING (SIZE(16, …)) ID of the AMF responsible for updating the UE Active / Pre-active / Inactive
[0100] Table 3 User Authentication Algorithm Table
[0101] Table 3 shows that the current status of the authentication algorithm is divided into three categories: "Active / Pre-active / Inactive". This design makes it easy for UDM to know which algorithm is running stably before the update, and to roll back if the configuration fails.
[0102] T10. For UEs that have moved to networks other than the network served by the UDM, updates are temporarily not possible. The AMF continues to page and maintain the local UE authentication algorithm update progress table. Once the UE that has roamed out of this network moves back to the network served by this UDM, the RRC connection can be re-established, and the UE can receive the "UE generic configuration update" message sent by the AMF of this network. The above steps T5-T9 are repeated until the authentication algorithm of all UEs is completely updated.
[0103] The application scenarios of this invention are as follows:
[0104] In critical industry 5G private network scenarios, this invention can be remotely and automatically updated via 5GC without the need for offline card writing or additional OTA system deployment, thus meeting the needs of private network IT departments for streamlined operation and maintenance and efficient operation.
[0105] In multi-user group differentiated security scenarios, when a 5G private network needs to configure different authentication and authorization algorithms for user groups with different security levels, the algorithm update for different user groups can be triggered through UDM preset policies to achieve differentiated management and synchronous switching of algorithms, ensuring that the communication security of different user groups is adapted to their business needs.
[0106] In scenarios involving algorithm iteration and security upgrades, when existing authentication algorithms have security vulnerabilities or the industry releases new security algorithm standards, private network operators can use this invention to quickly trigger algorithm updates for all UEs across the network. This eliminates the need for users to manually operate or replace their USIM / eSIM cards, allowing for the completion of algorithm upgrades for all users in a short time and timely blocking of security risks.
[0107] It should be noted that the method of this disclosure embodiment can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of this disclosure embodiment, and the multiple devices will interact with each other to complete the method described.
[0108] It should be noted that the above description describes some embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0109] Example 2
[0110] See Figure 3 Embodiment 2 of the present invention also provides a system for remotely updating the authentication algorithm in a USIM or eSIM card using a 5GC, comprising:
[0111] The authentication and authorization algorithm executable code pre-installation module 001 is used to pre-install several authentication and authorization algorithm executable codes required during the lifecycle of UDM and USIM / eSIM.
[0112] The user authentication and authorization algorithm change notification sending module 002 is used to update the authentication and authorization algorithm of the UDM based on the user group authentication and authorization algorithm usage policy pre-configured in the UDM, or when the currently effective algorithm reaches the configured usage period, and send a user authentication and authorization algorithm change notification containing target user information and new algorithm information to all AMFs within the UDM service range.
[0113] The User UE Authentication and Authorization Algorithm Update Schedule Construction and Initialization Module 003 is used by the AMF to update the AA IE of the UE security capabilities stored locally by matching the Authentication and Authorization Algorithm executable code pre-installed in the UDM based on the new algorithm information; constructing and initializing the update schedule of the User UE Authentication and Authorization Algorithm to obtain the initialized update schedule.
[0114] The configuration update message sending module 004 is used by the AMF to identify UEs that have not confirmed the update based on the initialized update schedule, and send a configuration update message carrying AA IE to the UEs that have not confirmed the update until the UEs successfully receive it;
[0115] The new algorithm update startup module 005 is used by the UE to extract the AA IE from the configuration update message and pass it to the USIM / eSIM; the USIM / eSIM locates the pre-installed authentication and authorization algorithm executable code based on the new algorithm ID and status information in the AA IE, sets the new algorithm status to active, and sets the original active algorithm status to inactive; after the update is completed, the UE replies to the AMF with an update completion confirmation message, and calls the executable code of the new algorithm to initiate a main authentication request, and completes two-way authentication with the UDM through the pre-installed matching algorithm;
[0116] The User UE Authentication and Authorization Algorithm Update Progress Table Module 006 is used for the AMF to update the update progress table based on the update completion confirmation message, and to report the updated update progress table to the UDM; the UDM summarizes the updated update progress table reported by the AMF to obtain a summary result; based on the summary result, the UDM updates the user authentication and authorization algorithm table stored in the UDM, and changes the new algorithm status of the confirmed updated users from Pre-active to Active;
[0117] The offline user configuration update processing module 007 is used to maintain the update status of UEs that are in roaming state or temporarily unable to receive messages in the initial update schedule and periodically page them; when a UE in roaming state or temporarily unable to receive messages roams back to the UDM service network and rebuilds the RRC connection, the algorithm update processing is performed until the full user authentication and authorization algorithm is updated.
[0118] In this embodiment, in the user UE authentication algorithm update progress table construction and initialization module 003, AAIE is of type BIT STRING and has a length of not less than 16 bits, with each bit corresponding to one pre-installed authentication algorithm; the first bit corresponds to the Milenage algorithm set, the second bit corresponds to the TUAK algorithm set, the third bit corresponds to the SM4 algorithm, and bits 4-15 are reserved; a bit value of 1 in AAIE indicates that the corresponding authentication algorithm has been pre-installed and is waiting to be activated; a bit value of 0 indicates that the corresponding authentication algorithm has not been pre-installed or does not need to be activated.
[0119] In this embodiment, the update schedule table in the user UE authentication and authorization algorithm update schedule table construction and initialization module 003 includes: user identification information, authentication algorithm information, AMF identification information and update status information.
[0120] In this embodiment, in the user authentication algorithm change notification sending module 002, the AMF obtains the user authentication algorithm change notification sent by the UDM in two ways: First, the AMF subscribes to data management change notifications from the UDM in advance. When the UDM detects a change in the user authentication algorithm data, it pushes the user authentication algorithm change notification to the AMF based on the subscription relationship. Second, after the UDM actively detects a change in the user authentication algorithm data, it sends the user authentication algorithm change notification to all AMFs within its service range.
[0121] In this embodiment, in the offline user configuration update processing module 007, when the AMF sends a configuration update message carrying AA IE to a UE that has not confirmed the update, if the UE is in a connected state, the AMF sends the configuration update message to the UE; if the UE is in a disconnected state, the AMF pages the UE through the gNB, and after the UE re-establishes the RRC connection with the gNB, it sends the configuration update message to the UE.
[0122] It should be noted that the information interaction and execution process between the modules of the above system are based on the same concept as the method embodiment in Embodiment 1 of this application, and the resulting technical effects are the same as those in the method embodiment of this application. For details, please refer to the description in the method embodiment shown above in this application, and it will not be repeated here.
[0123] Example 3
[0124] Embodiment 3 of the present invention provides a non-transitory computer-readable storage medium storing program code for a method of remotely updating an authentication algorithm in a USIM or eSIM card using 5GC. The program code includes instructions for executing the method of remotely updating an authentication algorithm in a USIM or eSIM card using 5GC as described in Embodiment 1 or any possible implementation thereof.
[0125] Computer-readable storage media can be any available medium that a computer can access, or a data storage device such as a server or data center that integrates one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
[0126] Example 4
[0127] Embodiment 4 of the present invention provides an electronic device, including: a memory and a processor;
[0128] The processor and the memory communicate with each other via a bus; the memory stores program instructions that can be executed by the processor, and the processor can call the program instructions to execute a method for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC, as described in Embodiment 1 or any possible implementation thereof.
[0129] Specifically, a processor can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor that reads software code stored in memory. This memory can be integrated into the processor or located outside the processor and exist independently.
[0130] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable system. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.
[0131] It is obvious to those skilled in the art that the modules or steps of the present invention described above can be implemented using general-purpose computing systems. They can be centralized on a single computing system or distributed across a network of multiple computing systems. Optionally, they can be implemented using program code executable by a computing system, thereby storing them in a storage system for execution by the computing system. In some cases, the steps shown or described can be performed in a different order than those presented herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0132] Although the present invention has been described in detail above with general descriptions and specific embodiments, modifications or improvements can be made to it, which will be obvious to those skilled in the art. Therefore, all such modifications or improvements made without departing from the spirit of the present invention fall within the scope of protection claimed by the present invention.
Claims
1. A method for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC, characterized in that, include: Several authentication and authorization algorithm executable codes are pre-installed in UDM and USIM / eSIM; Based on the user group authentication and authorization algorithm usage policy pre-configured in UDM, or when the currently effective algorithm reaches the configured usage period, UDM performs an authentication and authorization algorithm update operation and sends a user authentication and authorization algorithm change notification containing target user information and new algorithm information to all AMFs within the UDM service scope. Based on the new algorithm information, AMF matches the executable code of the authentication and authorization algorithm and updates the AA IE of the UE security capabilities stored locally; it constructs and initializes the update schedule table of the user UE authentication and authorization algorithm to obtain the initialized update schedule table. AMF identifies UEs that have not confirmed updates in the update schedule and sends a configuration update message carrying AAIE to the UEs that have not confirmed updates; The UE extracts the AA IE from the configuration update message and passes it to the USIM / eSIM; the USIM / eSIM locates the pre-installed authentication algorithm executable code based on the new algorithm ID and status information in the AA IE, sets the new algorithm status to active, and sets the original active algorithm status to inactive; after the update is completed, the UE replies to the AMF with an update completion confirmation message, and calls the executable code of the new algorithm to complete two-way authentication with the UDM through the pre-installed matching algorithm; After receiving the update completion confirmation message, AMF updates the update progress table and reports the updated update progress table to UDM; UDM summarizes the updated update progress table and updates the user authentication and authorization algorithm table, changing the new algorithm status of confirmed update users from Pre-active to Active. For UEs that are in roaming status or temporarily unable to receive messages in the update schedule, the AMF maintains its status and periodically pages them; when a UE that is in roaming status or temporarily unable to receive messages roams back to the UDM service network and rebuilds the RRC connection, the algorithm update process is performed until the full user authentication and authorization algorithm is updated.
2. The method for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC according to claim 1, characterized in that, AA IE is of type BIT STRING and is at least 16 bits long, with each bit corresponding to one pre-installed authentication algorithm; the first bit corresponds to the Milenage algorithm set, the second bit corresponds to the TUAK algorithm set, the third bit corresponds to the SM4 algorithm, and bits 4-15 are reserved bits; if a bit value of 1 in AA IE is 1, it means that the corresponding authentication algorithm has been pre-installed and is waiting to be activated. A bit value of 0 indicates that the corresponding authentication algorithm is not pre-installed or does not need to be activated.
3. The method for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC according to claim 2, characterized in that, The update schedule includes: user identification information, authentication algorithm information, AMF identification information, and update status information.
4. The method for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC according to claim 3, characterized in that, AMF obtains user authentication algorithm change notifications sent by UDM in two ways: First, AMF subscribes to data management change notifications from UDM in advance. When UDM detects a change in user authentication algorithm data, it pushes the user authentication algorithm change notification to AMF based on the subscription relationship. Second, after UDM actively detects a change in user authentication algorithm data, it sends the user authentication algorithm change notification to all AMFs within its service range.
5. The method for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC according to claim 4, characterized in that, When the AMF sends a configuration update message carrying AA IE to a UE that has not confirmed the update, if the UE is in a connected state, the AMF sends the configuration update message to the UE; if the UE is in a disconnected state, the AMF pages the UE through the gNB, and after the UE re-establishes the RRC connection with the gNB, it sends the configuration update message to the UE.
6. A system for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC, employing the method for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC as described in any one of claims 1-5, characterized in that... include: An authentication and authorization algorithm executable code pre-installation module is used to pre-install several authentication and authorization algorithm executable codes in UDM and USIM / eSIM; The user authentication and authorization algorithm change notification sending module is used to update the authentication and authorization algorithm of the UDM based on the user group authentication and authorization algorithm usage policy pre-configured in the UDM, or when the currently effective algorithm reaches the configured usage period, and send a user authentication and authorization algorithm change notification containing target user information and new algorithm information to all AMFs within the UDM service scope. The User UE Authentication and Authorization Algorithm Update Schedule Construction and Initialization Module is used by the AMF to update the AA IE of the UE security capabilities stored locally based on the new algorithm information and matching the executable code of the authentication and authorization algorithm; construct the update schedule of the user UE authentication and authorization algorithm and initialize it to obtain the initialized update schedule; The configuration update message sending module is used by the AMF to identify UEs that have not confirmed updates in the update schedule and send configuration update messages carrying AA IE to the UEs that have not confirmed updates. The new algorithm update startup module is used by the UE to extract the AA IE from the configuration update message and pass it to the USIM / eSIM; the USIM / eSIM locates the pre-installed authentication and authorization algorithm executable code based on the new algorithm ID and status information in the AA IE, sets the new algorithm status to active, and sets the original active algorithm status to inactive; after the update is completed, the UE replies to the AMF with an update completion confirmation message, and calls the executable code of the new algorithm to complete two-way authentication with the UDM through the pre-installed matching algorithm; The User UE Authentication and Authorization Algorithm Update Progress Table Update Module is used to update the update progress table after the AMF receives the update completion confirmation message, and report the updated update progress table to the UDM; the UDM summarizes the updated update progress table and updates the User Authentication and Authorization Algorithm Table, changing the new algorithm status of confirmed updated users from Pre-active to Active. The offline user configuration update processing module is used to maintain the AMF status and periodically page UEs that are in roaming status or temporarily unable to receive messages in the update schedule. When a UE in roaming status or temporarily unable to receive messages roams back to the UDM service network and rebuilds the RRC connection, the algorithm update processing is performed until the full user authentication and authorization algorithm is updated.
7. A system for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC according to claim 6, characterized in that, In the module for constructing and initializing the user UE authentication algorithm update schedule, the AA IE is of type BIT STRING and has a length of not less than 16 bits, with each bit corresponding to one pre-installed authentication algorithm; the first bit corresponds to the Milenage algorithm set, the second bit corresponds to the TUAK algorithm set, the third bit corresponds to the SM4 algorithm, and bits 4-15 are reserved; a bit value of 1 in the AA IE indicates that the corresponding authentication algorithm has been pre-installed and is waiting to be activated. A bit value of 0 indicates that the corresponding authentication algorithm is not pre-installed or does not need to be activated.
8. A system for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC according to claim 7, characterized in that, In the module for constructing and initializing the user UE authentication algorithm update schedule, the update schedule includes: user identification information, authentication algorithm information, AMF identification information, and update status information.
9. A system for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC according to claim 8, characterized in that, In the user authentication algorithm change notification sending module, the AMF obtains the user authentication algorithm change notification sent by the UDM in two ways: First, the AMF subscribes to the data management change notification in advance from the UDM. When the UDM detects a change in the user authentication algorithm data, it pushes the user authentication algorithm change notification to the AMF based on the subscription relationship. Second, after the UDM actively detects a change in the user authentication algorithm data, it sends the user authentication algorithm change notification to all AMFs within its service range.
10. A system for remotely updating the authentication algorithm in a USIM or eSIM card using 5GC according to claim 9, characterized in that, In the offline user configuration update processing module, when the AMF sends a configuration update message carrying AA IE to a UE that has not confirmed the update, if the UE is in a connected state, the AMF sends the configuration update message to the UE; if the UE is in a disconnected state, the AMF pages the UE through the gNB, and after the UE re-establishes the RRC connection with the gNB, it sends the configuration update message to the UE.
Citation Information
Patent Citations
Network access authentication method and its USIM card
CN101132649A
Authentication method, authentication system and smart card
CN102625311A
Method and system for enabling 5G network to flexibly support a plurality of main authentication algorithms
CN111405557A
Algorithm updating method and device
CN119769066A
System and method for utilizing a token for authentication with multiple secure online sites
US20070186277A1