Apparatus, method, apparatus, and computer readable medium for security
By generating and using integrity protection and encryption keys between terminal devices and network devices, the problem of data transmission security in 5G and 6G systems is solved, a secure tunnel is established, and the confidentiality and integrity of data transmission are enhanced.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ALCATEL LUCENT SHANGHAI BELL CO LTD
- Filing Date
- 2025-10-16
- Publication Date
- 2026-05-01
AI Technical Summary
In 5G and 6G mobile communication systems, existing mechanisms cannot effectively protect the data transmission security between user equipment and the home network. In particular, during roaming guidance and UE parameter updates, sensitive information is easily visible to mobile devices and cannot be kept invisible to access and mobility management functions.
A secure tunnel is established by generating and using integrity protection and encryption keys between terminal devices and network devices to ensure the confidentiality and integrity of data transmission. The TUAK and MILENAGE algorithm set proposed by 3GPP is used for key generation and verification.
It enables secure data transmission between terminal devices and the home network in 5G and 6G systems, enhances the confidentiality and integrity of data transmission, and ensures the security of sensitive information.
Smart Images

Figure CN121968092A_ABST
Abstract
Description
Technical Field
[0001] Various example embodiments relate to devices, methods, apparatuses, and computer-readable media for security purposes. Background Technology
[0002] In current 5G mobile communication systems, there is no end-to-end secure tunnel between the User Equipment (UE) and the Home Network (HN). If the HN sends data packets to the UE, the HN must first send the data packets to the Visited Public Land Mobile Network (VPLMN) / Access and Mobility Management Function (AMF), and then the VPLMN / AMF transmits the data packets to the UE via the Non-Access Stratum (NAS). For processes defined and used to securely transmit small amounts of data from the HN to the UE, such as Roaming Bootstrapping (SoR) and UE Parameter Update (UPU), the current mechanism does not provide sufficient security. Furthermore, in post-5G (B5G) systems, such as 6G mobile communication systems, sensitive information sent from the 6G HN to the 6G UE (e.g., enhanced / optimized re-authentication indications and randomization, re-authentication value lists, and other policies) should be visible to the Mobile Equipment (ME) and invisible to the VPLMN / AMF, but the current mechanism cannot effectively protect this sensitive information. Summary of the Invention
[0003] The following provides a brief overview of exemplary embodiments to provide a basic understanding of some aspects of the various embodiments. It should be noted that the content of this invention is not intended to identify key features of essential elements or define the scope of the embodiments; its sole purpose is to introduce some concepts in a simplified form as a prelude to the more detailed description provided below.
[0004] In a first aspect, an apparatus for a terminal device is disclosed. The apparatus may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the apparatus to at least: receive, integrity-protected and encrypted packets from a network device; generate at least one first key for integrity protection according to an integrity protection algorithm, and generate at least one second key for encryption according to an encryption algorithm; and, in response to the packets, send an acknowledgment to the network device, in the case that the packets have been successfully verified based on at least one first key and at least one second key, confirming that the packets have been integrity-protected by at least one first key and encrypted by at least one second key.
[0005] In a second aspect, an apparatus for a network device is disclosed. The apparatus may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the apparatus to at least: generate at least one first key for integrity protection according to an integrity protection algorithm, and generate at least one second key for encryption according to an encryption algorithm; send a packet to a terminal device that is at least integrity-protected by the at least one first key and encrypted by the at least one second key; and receive an acknowledgment from the terminal device that is both integrity-protected and encrypted in response to the packet.
[0006] In a third aspect, a method performed by means for a terminal device is disclosed. The method may include: receiving, from a network device, a packet that is integrity-protected and encrypted; generating at least one first key for integrity protection according to an integrity protection algorithm, and generating at least one second key for encryption according to an encryption algorithm; and, in response to the packet, sending to the network device an acknowledgment that the packet is integrity-protected by at least one first key and encrypted by at least one second key, provided that the packet is successfully verified based on at least one first key and at least one second key.
[0007] In a fourth aspect, a method performed by means for a network device is disclosed. The method may include: generating at least one first key for integrity protection according to an integrity protection algorithm, and generating at least one second key for encryption according to an encryption algorithm; sending a packet to a terminal device that is at least integrity-protected by at least one first key and encrypted by at least one second key; and receiving an acknowledgment from the terminal device that is both integrity-protected and encrypted in response to the packet.
[0008] Fifthly, an apparatus for a terminal device is disclosed. The apparatus may include: components for receiving, from a network device, packets that are integrity-protected and encrypted; components for generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for encryption according to an encryption algorithm; and components for, in response to a packet successfully verified based on at least one first key and at least one second key, sending to the network device an acknowledgment that is at least integrity-protected by at least one first key and encrypted by at least one second key.
[0009] In a sixth aspect, an apparatus for a network device is disclosed. The apparatus may include: components for generating at least one first key for integrity protection according to an integrity protection algorithm and generating at least one second key for encryption according to an encryption algorithm; components for sending a packet to a terminal device that is at least integrity-protected by at least one first key and encrypted by at least one second key; and components for receiving an acknowledgment of integrity protection and encryption from the terminal device in response to the packet.
[0010] In a seventh aspect, a computer-readable medium is disclosed. The computer-readable medium may include program instructions that, when executed by a means for a terminal device, cause the means to at least: receive a packet that is integrity-protected and encrypted from a network device; generate at least one first key for integrity protection according to an integrity protection algorithm, and generate at least one second key for encryption according to an encryption algorithm; and, in response to the packet, send an acknowledgment to the network device, in the event that the packet is successfully verified based on at least one first key and at least one second key, that the packet is integrity-protected by at least one first key and encrypted by at least one second key.
[0011] In an eighth aspect, a computer-readable medium is disclosed. The computer-readable medium may include program instructions that, when executed by a means for a network device, cause the means to at least: generate at least one first key for integrity protection according to an integrity protection algorithm, and generate at least one second key for encryption according to an encryption algorithm; send a packet to a terminal device that is at least integrity-protected by at least one first key and encrypted by at least one second key; and receive an acknowledgment from the terminal device that is both integrity-protected and encrypted in response to the packet.
[0012] Other features and advantages of exemplary embodiments of this disclosure will also become apparent when read in conjunction with the accompanying drawings, which illustrate the principles of exemplary embodiments of this disclosure by way of example. Attached Figure Description
[0013] Some exemplary embodiments will now be described by way of non-limiting examples with reference to the accompanying drawings.
[0014] Figure 1A An example diagram illustrating the generation of a separate key according to an exemplary embodiment of this disclosure is shown.
[0015] Figure 1B An example diagram of key generation for SoR according to an example embodiment of this disclosure is shown.
[0016] Figure 1C An example diagram of key generation for UPU is shown according to an example embodiment of the present disclosure.
[0017] Figure 2A An example diagram of the generation of a combined key according to an example embodiment of this disclosure is shown.
[0018] Figure 2B An example diagram is shown for key generation for both SoR and UPU according to an example embodiment of this disclosure.
[0019] Figure 3 An example sequence diagram is shown according to an example embodiment of the present disclosure.
[0020] Figure 4 An example sequence diagram is shown according to an example embodiment of the present disclosure.
[0021] Figure 5A An example sequence diagram is shown according to an example embodiment of the present disclosure.
[0022] Figure 5B An example diagram is shown that can be applied to the example embodiments of this disclosure for authentication vector generation.
[0023] Figure 5C K is shown as an example embodiment that can be applied to this disclosure. SEAF Example graph generated.
[0024] Figure 5D An example diagram of network authentication that can be applied to exemplary embodiments of this disclosure is shown.
[0025] Figure 5E K is shown as an example embodiment that can be applied to this disclosure. AMF Example graph generated.
[0026] Figure 6A An example sequence diagram is shown according to an example embodiment of the present disclosure.
[0027] Figure 6B An example diagram is shown that can be applied to the example embodiments of this disclosure for authentication vector generation.
[0028] Figure 6C An example diagram of network authentication that can be applied to exemplary embodiments of this disclosure is shown.
[0029] Figure 6D K is shown as an example embodiment that can be applied to this disclosure. AUSF and K SEAF Example graph generated.
[0030] Figure 6E K is shown as an example embodiment that can be applied to this disclosure. AMF Example graph generated.
[0031] Figure 6F K is shown as an example embodiment that can be applied to this disclosure. AUSF K SEAF and K AMF Example graph generated.
[0032] Figure 7 An example sequence diagram is shown according to an example embodiment of the present disclosure.
[0033] Figure 8 A flowchart illustrating an example method 800 for security according to an example embodiment of the present disclosure is shown.
[0034] Figure 9 A flowchart illustrating an example method 900 for security according to an example embodiment of the present disclosure is shown.
[0035] Figure 10 A block diagram illustrating an example device 1000 for security according to an example embodiment of the present disclosure is shown.
[0036] Figure 11 A block diagram illustrating an example device 1100 for security according to an example embodiment of the present disclosure is shown.
[0037] Figure 12 A block diagram illustrating an example device 1200 for security according to an example embodiment of the present disclosure is shown.
[0038] Figure 13 A block diagram illustrating an example device 1300 for security according to an example embodiment of the present disclosure is shown.
[0039] Throughout the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Repeated descriptions of the same elements will be omitted. Detailed Implementation
[0040] In the following description, some exemplary embodiments are described in detail with reference to the accompanying drawings. Specific details are included in the description for the purpose of providing a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts can be practiced without these specific details. In some cases, well-known circuits, technologies, and components are shown in block diagram form to avoid obscuring the described concepts and features.
[0041] For HN packets destined for UEs that should not be accessed by the 6G Serving Network (SN) or 6G Access Network (AN), both integrity protection and confidentiality protection should be enabled, but this is not supported in the current UPU or SoR.
[0042] Example embodiments of this disclosure can create a secure tunnel between the UE and HN that provides integrity and confidentiality protection, enabling the UE and HN to securely transmit data packets, such as parameters.
[0043] Figure 1A An example diagram illustrating the generation of a separate key according to an exemplary embodiment of this disclosure is shown. Figure 1A The process shown can be performed by HN's UE and / or network devices, and the network devices can be used as HN's Authentication Server Function (AUSF) entity, Unified Data Management (UDM) entity, Network Open Function (NEF) entity and / or Network Function (NF) entity.
[0044] Figure 1A The example key generation shown can be performed separately for SoR and UPU. In other words, it can be performed for either SoR or UPU. Figure 1A The example key generation is shown below. Furthermore, Figure 1A The generation of the cryptographic key (CK) and integrity key (IK) during the authentication and key negotiation (AKA) process is illustrated compared to the generation of the authentication token (AUTN). Dashed boxes indicate operations, functions, and / or values that can be omitted from AUTN generation during the AKA process. In this disclosure, CK may refer to the key used for confidentiality protection, IK may refer to the key used for integrity protection, and encryption and encryption are interchangeable. In this disclosure, f1, f2, f3, f4, and f5 refer to the authentication and key generation functions of the TUAK and / or MILENAGE algorithm sets proposed by the 3rd Generation Partnership Project (3GPP).
[0045] In operation 110, the network device can generate a random number (RAND) 115 specific to the SoR or UPU, and the UE can receive the RAND 115 from the network device. In some embodiments, the RAND 115 can be generated for an AKA procedure, meaning that the RAND used in a previous AKA can be used for... Figure 1A The key generation is shown. In some embodiments, the network device may generate a new RAND 115 for deriving CK 120 and IK 125.
[0046] RAND 115 and for network devices (e.g., AUSF entities, denoted as K) AUSF The keys are input into functions f3 and f4 respectively to generate CK 120 and IK 125. CK 120 and IK 125 can be used for SoR or UPU.
[0047] Figure 1B An example diagram of key generation for SoR according to an example embodiment of this disclosure is shown. Figure 1AThe example key generation shown is for the case of SoR. Figure 1B The example key generation for SoR shown is from Figure 1A Simplified. In this case, RAND 115 is specific to SoR and is labeled as RAND. SoR RAND SoR and K AUSF The inputs are fed into functions f3 and f4 respectively to generate CK and IK for SoR. In this case, CK 120 is the CK for SoR, denoted as CK. SoR Furthermore, IK 125 is an IK for SoR, denoted as IK. SoR .
[0048] Figure 1C An example diagram of key generation for a UPU is shown according to an example embodiment of this disclosure. Figure 1A The example key generation shown is for the UPU case. Figure 1B The example key generation for UPU shown is from Figure 1A Simplified. In this case, RAND 115 is specific to the UPU and is identified as RAND. UPU RAND UPU and K AUSF The inputs are fed into functions f3 and f4 respectively to generate CK and IK for the UPU. In this case, CK 120 is the CK for the UPU, denoted as CK. UPU Furthermore, IK 125 is the IK used for UPUs, denoted as IK. UPU .
[0049] Figures 1A to 1C SoR and UPU are shown as examples. The exemplary embodiments of this disclosure are not limited to SoR and UPU. Alternatively or additionally, in some embodiments, the UE and network device may be... Figures 1A to 1C The method shown generates CK and IK for data transmission HN process other than SoR and UPU.
[0050] Figure 2A An example diagram of the generation of a combined key according to an example embodiment of this disclosure is shown. Figure 2A The process shown can be performed by HN's UE and / or network devices.
[0051] Figure 2A The example key generation shown can be performed against both SoR and UPU. In other words, Figure 2A The example key generation shown can be performed for both SoR and UPU, and therefore can be called combined key generation. Furthermore, Figure 2AThe generation of CK and IK during the AKA process is shown compared to the AUTN generation. Dashed boxes indicate operations, functions, and / or values that can be omitted from the AUTN generation during the AKA process.
[0052] In operation 210, the network device can generate RAND 215 for both SoR and UPU, and the UE can receive RAND 215 from the network device. In some embodiments, RAND 215 can be generated for the AKA procedure, meaning that the RAND used in the previous AKA can be used for... Figure 2A The key generation is shown. In some embodiments, the network device may generate a new RAND 215 for deriving CK 220 and IK 225.
[0053] RAND 215 and K AUSF The inputs are fed into functions f3 and f4, respectively, to generate CK 220 and IK 225. CK 220 and IK 225 can be shared by SoR and UPU. In some embodiments, CK 220 can be an HN cryptographic key, and IK 225 can be an HN integrity protection key.
[0054] Figure 2B An example diagram is shown for key generation for both SoR and UPU according to an example embodiment of this disclosure. Figure 2B The example key generation shown is from Figure 2A Simplified. RAND 215 is shared by SoR and UPU. RAND 215 and K AUSF These are input to functions f3 and f4 respectively to generate a CK shared by both SoR and UPU, and an IK shared by both SoR and UPU. CK220 is the CK shared by both SoR and UPU, denoted as CK. SoR_UPU Furthermore, IK 225 is an IK shared by SoR and UPU, denoted as IK. SoR_UPU .
[0055] Therefore, according to the example embodiments of this disclosure, the SoR and UPU processes can be enhanced by key generation techniques, and some mechanisms for generating AUTN from the AKA process, such as the f3 and f4 functions, can be reused and adapted.
[0056] Figure 2A and Figure 2B SoR and UPU are shown as examples. The exemplary embodiments of this disclosure are not limited to SoR and UPU. Alternatively or additionally, in some embodiments, the UE and network device may be... Figure 2A and Figure 2BThe method shown generates the combined CK and combined IK used by the SoR, UPU, and HN processes for data transmission other than SoR and UPU.
[0057] In some embodiments, when the UE and / or network device from K AUSF When deriving the keys used for SoR integrity protection and SoR encryption, or when the UE and / or network device obtains the key from K AUSF When deriving the key used for UPU integrity protection and UPU encryption, or when the UE and / or network device obtains the key from K AUSF When deriving CK and IK for another data transmission HN procedure, or when the UE and / or network device from K AUSF When deriving the CK and IK shared by SoR, UPU and another data transmission HN process, the parameters used to generate (multiple) CK and (multiple) IK may include the HN algorithm type distinguisher, the length of the HN algorithm type distinguisher, the HN algorithm identifier, and the length of the HN algorithm identifier.
[0058] In some embodiments, the following parameters can be used to form the string S input to the key derivation function (KDF).
[0059] - Function Code (FC) = Value not used for generating any other key - P0 = 6G HN algorithm type distinguisher - L0 = 6G HN algorithm type distinguisher length (e.g., 0x00, 0x01) - P1 = 6G HN algorithm identifier - L1 = 6G HN algorithm identifier length (e.g., 0x00, 0x01) The 6G HN algorithm type distinguisher can be the 6G SoR encryption algorithm (represented as 6G-SoR-enc-alg) used for the SoR encryption algorithm and the 6G SoR integrity protection algorithm (represented as 6G-SoR-int-alg) used for the SoR integrity protection algorithm. The 6G HN algorithm type distinguisher can also be the 6G UPU encryption algorithm (represented as 6G-UPU-enc-alg) used for the UPU encryption algorithm and the 6G UPU integrity protection algorithm (represented as 6G-UPU-int-alg) used for the UPU integrity protection algorithm. Values 0x00 and 0x05 to 0xf0 can be reserved for future use of new HN encryption and integrity protection, such as HN processes for data transmission other than SoR and UPU. The 6G HN algorithm type distinguisher can also be the 6G New HN Feature encryption algorithm (represented as 6G-New HN Feature-enc-alg) and the 6G New HN Feature integrity protection algorithm (represented as 6G-New HNFeature-int-alg). Values 0xf1 to 0xff can be reserved for private use or independent non-public network (SNPN) use cases. Table 1 shows an example 6G HN algorithm type distinguisher.
[0060] Table 1
[0061] Figure 3 Example sequence diagrams are shown according to exemplary embodiments of the present disclosure. References Figure 3 UE 310 can represent any terminal device. SN 320 and HN 330 are shown to represent the network side serving UE 310. In SN 320, Radio Access Network (RAN) 322 and AMF entity 324 are shown as example SN elements. In HN 330, AUSF entity 332 and UDM entity 334 are shown as example HN elements. UE 310 can be related to... Figures 1A to 1C and Figures 2A to 2B The UE described, and AUSF entity 332 may be about Figures 1A to 1C and Figures 2A to 2B Examples of network devices described. It can be assumed that UE 310, RAN 322, AMF entity 324, AUSF entity 332, and UDM entity 334 can support 6G.
[0062] refer to Figure 3UE 310 can send security capabilities specific to UE 310 to AMF entity 332. For example, UE 310 can send information 312 about UE security capabilities to AMF entity 332. In some embodiments, UE 310 can send information 312 to AMF entity 324 via RAN 322, and AMF entity 324 can also forward information 312 to AMF entity 332. In some embodiments, information 312 can be sent from UE 310 to AMF entity 324 via a registration request and from AMF entity 324 to AMF entity 332 via an authentication request.
[0063] The AUSF entity 332 can store the security capabilities of UE 310 after receiving the security capabilities of UE 310. In operation 338, UE 310, SN 320 and HN 330 can complete the AKA procedure, which can be similar to the AKA procedure described in 3GPP Technical Specification (TS) 33.501.
[0064] In operation 340, AUSF entity 332 can select an integrity protection algorithm and an encryption algorithm based on the security capabilities for UE 310. Then, in operation 342, AUSF entity 332 can generate at least one first key for integrity protection according to the integrity protection algorithm, and generate at least one second key for encryption according to the encryption algorithm. In some embodiments, the first key may be IK, and the second key may be CK. In some embodiments, AUSF entity 332 may use... Figures 1A to 1C Individual IK and individual CK are generated as shown. In some embodiments, AUSF entity 332 can be... Figures 2A to 2B The combination IK and combination CK are generated in the manner shown.
[0065] Then, in operation 344, AUSF entity 332 can execute a Secure Mode Command (SMC) procedure with UE 310. From the UE's perspective, UE 310 can execute the SMC procedure with AUSF entity 332. In other words, in operation 344, the SMC procedure can run between UE 310 and AUSF entity 332, therefore the SMC procedure can be referred to as a 6G HN SMC procedure.
[0066] In operation 344, AUSF entity 332 may send packet 346 to UE 310, which is protected for integrity by IK generated in operation 342 and encrypted by CK generated in operation 342. In some embodiments, AUSF entity 332 may send one or more containers to UE 310. In some embodiments, packet 346 may be contained within one or more containers. Alternatively or additionally, the one or more containers may include information about the algorithm selected in operation 340 and the RAND used in operation 342 to generate CK(multiple) and IK(multiple)
[0067] In some embodiments, in operation 342, AUSF entity 332 is Figures 1A to 1C When generating separate IK and separate CK as shown, AUSF entity 332 can construct and send separate containers for the separate IK and separate CK respectively. For example, the container may include information about the algorithm and RAND used to generate the key for SoR, the container may include information about the algorithm and RAND used to generate the key for UPU, and the container may include information about the algorithm and RAND used to generate the key for another data transmission HN process.
[0068] In some embodiments, in operation 342, AUSF entity 332 is Figures 2A to 2B When generating the combined IK and combined CK in the manner shown, AUSF entity 332 can construct and send a container for the combined IK and combined CK. For example, a container may include information about the algorithm and the RAND used to generate the combined key common to the SoR, UPU, and another data transmission HN process.
[0069] In operation 314, UE 310 can generate (multiple) IKs based on an integrity protection algorithm and (multiple) CKs based on an encryption algorithm. Utilizing one or more containers sent from AUSF entity 332, UE 310 can generate IKs based on the same algorithms and inputs used by AUSF entity 332 (e.g., RAND and K). AUSF To generate (multiple) IK and (multiple) CK.
[0070] Therefore, UE 310 can use the CK(s) generated in operation 314 to decrypt packet 346 and use the IK(s) generated in operation 314 to verify the integrity of packet 346, thereby verifying the received packet 346. In some embodiments, packet 346 may include security capabilities for UE 310 transmitted from UE 310. By replaying the security capabilities received from AMF entity 332, UE 310 can determine whether packet 346 has been modified by SN 320 (e.g., RAN 322 and / or AMF entity 324).
[0071] If packet 346 is successfully verified based on the IK(s) and CK(s) generated in operation 314, in response to packet 346, UE 310 may send an acknowledgment (ACK) 316 to AUSF entity 332, which is protected for integrity by the IK(s) generated in operation 314 and encrypted by the CK(s) generated in operation 314.
[0072] Upon receiving ACK 316, AUSF entity 332 can use the (multiple) CKs generated in operation 342 to decrypt ACK 316, and use the (multiple) IKs generated in operation 342 to verify the integrity of ACK 316.
[0073] Therefore, encryption and integrity protection from HN 330 can be used to enhance SoR, UPU and / or another data transmission HN process, and HN SMC process can be performed, thus establishing a secure tunnel between UE 310 and HN 330.
[0074] Then, in operation 326, UE 310 and SN 320 can perform the access layer (AS) and NAS SMC procedures.
[0075] Figure 4 An example sequence diagram is shown according to an example embodiment of the present disclosure. Figure 4 The example sequences shown can also be executed by RAN 322 and AMF entity 324 of UE 310, SN 320, and AUSF entity 332 and UDM entity 334 of HN 330.
[0076] refer to Figure 4UE 310 can send information about its security capabilities to AMF entity 324. For example, UE 310 can send information 312 about its security capabilities to AMF entity 324 via RAN 322. In some embodiments, information 312 can be sent from UE 310 to AMF entity 324 via a registration request. AMF entity 324 can then send an authentication request 426 for UE 310 to AMF entity 332. In some embodiments, authentication request 426 does not need to include information about UE 310's security capabilities. And in operation 338, UE 310, SN 320, and HN 330 can complete the AKA procedure.
[0077] In some embodiments, the integrity protection algorithm and encryption algorithm may be pre-configured. For example, the network operator may pre-configure the algorithms in AUSF entity 332 and UE 310. The integrity protection algorithm and encryption algorithm may be unique during the HN process.
[0078] In operation 442, AUSF entity 332 can generate (multiple) IKs according to the integrity protection algorithm and (multiple) CKs according to the encryption algorithm. In some embodiments, AUSF entity 332 can... Figures 1A to 1C Individual IK and individual CK are generated as shown. In some embodiments, AUSF entity 332 can be... Figures 2A to 2B The combination IK and combination CK are generated in the manner shown.
[0079] Then, in operation 444, an authentication process can be performed between HN 330 and UE 310.
[0080] In operation 444, AUSF entity 332 may send packet 446 to UE 310, which is protected for integrity by IK(s) generated in operation 442 and encrypted by CK(s) generated in operation 442. In some embodiments, AUSF entity 332 may send one or more containers to UE 310. In some embodiments, packet 346 may be contained within one or more containers. Alternatively or additionally, one or more containers may include the RAND used in operation 442 to generate CK(s) and IK(s).
[0081] In some embodiments, in operation 442, AUSF entity 332 is... Figures 1A to 1CWhen generating separate IKs and separate CKs as shown, AUSF entity 332 can construct and send separate containers for each separate IK and separate CK. For example, a container may include information about a RAND used to generate a key for SoR, information about a RAND used to generate a key for UPU, and information about a RAND used to generate a key for another data transmission HN process.
[0082] In some embodiments, in operation 442, AUSF entity 332 is... Figures 2A to 2B When the combined IK and combined CK are generated in the manner shown, AUSF entity 332 can construct and send a container for the combined IK and combined CK. For example, a container may include information about RAND used to generate a combined key shared by the SoR, UPU, and another data transmission HN process.
[0083] In operation 414, UE 310 can generate (multiple) IKs based on an integrity protection algorithm and (multiple) CKs based on an encryption algorithm. In some embodiments, the integrity protection algorithm and the encryption algorithm can be provided by the network operator in the Universal Subscriber Identity Module (USIM) of UE 310, so the ME of UE 310 can retrieve the algorithm from the USIM. Therefore, UE 310 can use the same algorithm and inputs (e.g., RAND and K) as AUSF entity 332. AUSF To generate (multiple) IK and (multiple) CK.
[0084] Therefore, UE 310 can use the CK(s) generated in operation 414 to decrypt packet 446, and use the IK(s) generated in operation 414 to verify the integrity of packet 446, thereby verifying the received packet 446. UE 310 can determine whether packet 446 has been modified by SN 320 (e.g., RAN 322 and / or AMF entity 324).
[0085] If packet 446 is successfully verified based on the IK(s) and CK(s) generated in operation 414, in response to packet 446, UE 310 may send ACK 416 to AUSF entity 332, which is protected for integrity by the IK(s) generated in operation 414 and encrypted by the CK(s) generated in operation 414.
[0086] Upon receiving ACK 416, AUSF entity 332 can use the CK(s) generated in operation 442 to decrypt ACK 416 and use the IK(s) generated in operation 442 to verify the integrity of ACK 416.
[0087] Therefore, encryption and integrity protection from HN 330 can be used to enhance SoR, UPU and / or another data transmission HN process, and a secure tunnel can be established between UE 310 and HN 330.
[0088] Then, in operation 326, UE 310 and SN 320 can execute the AS and NAS SMC procedures.
[0089] Figure 5A An example sequence diagram is shown according to an example embodiment of the present disclosure. Figure 5A The example sequence diagram shown can be Figure 4 The example sequence diagram shown is based on the implementation of the 6G AKA adaptation process.
[0090] refer to Figure 5A ,and Figure 4 In contrast, in SN 320, RAN 322 is omitted, and the Secure Anchoring Function (SEAF) entity 325 is also shown. It can be understood that transmissions between AMF entity 324 / SEAF entity 325 and UE 110 can be via RAN 322, and operations related to AMF entity 324 / SEAF entity 325 can be performed by AMF entity 324 and / or SEAF entity 325. In HN 330, with Figure 4 In contrast, Authentication Credentials Storehouse and Processing Function (ARPF) entity 335 and Subscription Identifier Dehiding Function (SIDF) entity 337 are also shown. Operations associated with UDM entity 334 / ARPF entity 335 / SIDF entity 337 can be performed by UDM entity 334, ARPF entity 335 and / or SIDF entity 337.
[0091] In operation 510, UE 310 may perform a Subscription Permanent Identifier (SUPI) to Subscription Hidden Identifier (SUCI) hiding. UE 310 may then send a registration request 512 to AMF entity 324 / SEAF entity 325 via the RAN entity. Registration request 512 may include UE 310's SUCI and / or 6G Globally Unique Temporary UE Identifier (6G-GUTI). In some embodiments, registration request 512 may also include UE security capabilities of UE 110.
[0092] Upon receiving registration request 512, AMF entity 324 / SEAF entity 325 may send authentication request 520 to AUSF entity 332. Authentication request 520 may include the SUCI and / or 6G-GUTI of UE 310, and may also include the name of SN 320, referred to as SN-name.
[0093] Upon receiving authentication request 520, AUSF entity 332 may send authentication acquisition request 530 to UDM entity 334 / ARPF entity 335 / SIDF entity 337. Authentication acquisition request 530 may include the SUCI and / or 6G-GUTI of UE 310, and the SN-name of SN 320.
[0094] Upon receiving authentication request 530, in operation 532, UDM entity 334 / ARPF entity 335 / SIDF entity 337 can perform SUCI to SUPI de-hiding. In operation 532, UDM entity 334 / ARPF entity 335 / SIDF entity 337 can also select an authentication method. Then, in operation 534, UDM entity 334 / ARPF entity 335 / SIDF entity 337 can generate an authentication vector.
[0095] Figure 5B An example diagram is shown that can be applied to example embodiments of authentication vector generation in this disclosure. (Reference) Figure 5B Long-term key K refers to the authentication key shared between the USIM and the authentication authority (AuC) in the UE 310's 3G Home Environment (HE), 4G Home Subscriber Server (HSS), or 5G / 6G UDM, and usable by both the USIM and the authentication authority. AMF refers to the authentication management field. Those skilled in the art will understand that the AMF, as input for key generation, is the authentication management field, distinct from AMF entity 324. Figure 5B In the example authentication vector generation shown, the generated authentication vector can be represented as 6G HE AV.
[0096] Return to reference Figure 5A Then, UDM entity 334 / ARPF entity 335 / SIDF entity 337 can send an authentication acquisition response 536 to AUSF entity 332. The authentication acquisition response 536 may include the generated 6G HE AV, UE 310's SUPI, and an indication of authentication and key management (AKMA) for the application.
[0097] Upon receiving authentication and obtaining response 536, in operation 538, AUSF entity 332 can be stored... Figure 2B The expected response (XRES) generated in the process is denoted as XRES. And calculate the expected hash response (HXRES), denoted as HXRES. .
[0098] Then, in operation 540, AUSF entity 332 can generate a key for SEAF entity 325, denoted as K. SEAF .
[0099] Figure 5C K is shown as an example embodiment that can be applied to this disclosure. SEAF Example image generated. Reference Figure 5C Except for K SEAF In addition, AUSF entity 332 can also generate 6G service environment (SE) AV.
[0100] Return to reference Figure 5A Then, AUSF entity 332 can send authentication response 542 to AMF entity 324 / SEAF entity 325. Authentication response 542 may include 6G SE AV.
[0101] Upon receiving authentication response 542, in operation 522, AMF entity 324 / SEAF entity 325 may store the HXRES included in the 6G SE AV. Then, AMF entity 324 / SEAF entity 325 can send authentication request 524 to UE 310. Authentication request 524 may include RAND, AUTN, key set identifier for next-generation radio access networks (ngKSI), and anti-bidding down between architectures (ABBA).
[0102] Upon receiving authentication request 524, UE 310 can perform network authentication in operation 514.
[0103] Figure 5D An example diagram of network authentication that can be applied to exemplary embodiments of this disclosure is shown. References Figure 5D In operation 514, UE 310 can verify whether the Message Authentication Code (MAC) == Expected MAC (XMAC) & Sequence Number (SQN) is within the correct range.
[0104] Return to reference Figure 5A Then, UE 310 can send authentication response 516 to AMF entity 324 / SEAF entity 325. Authentication response 516 may include the response generated in operation 514, denoted as RES. .
[0105] Upon receiving authentication response 516, in operation 526, AMF entity 324 / SEAF entity 325 can calculate the hash response (HRES), denoted as HRES. And HRES With the stored HXRES Comparison. In HRES With HXRES In the event of a match, AMF entity 324 / SEAF entity 325 may send authentication request 527 to AUSF entity 332. Authentication request 527 may include RES .
[0106] Upon receiving authentication request 527, in operation 544, AUSF entity 332 can utilize the stored XRES Verify RES If the verification is successful in operation 544, AUSF entity 332 can generate (multiple) CKs and (multiple) IKs in operation 546.
[0107] In some embodiments, during operation 546, the AUSF entity 332 may, for example, be... Figure 1A , Figure 1B and Figure 1C The illustrated method generates CK and IK separately for the SoR, UPU, and / or another data transmission HN process. In some embodiments, during operation 546, the AUSF entity 332 may, for example, be... Figure 2A and Figure 2B The method shown generates a combination CK and a combination IK that are shared by the SoR, UPU, and / or another data transmission HN process.
[0108] Then, AUSF entity 332 can send authentication response 548 to AMF entity 324 / SEAF entity 325. Authentication response 548 may include authentication result, UE 310's SUPI, and the generated K. SEAF And HN packets that are protected for integrity by (multiple) IKs and encrypted by (multiple) CKs.
[0109] Furthermore, AUSF entity 332 can send an authentication result confirmation request 550 to UDM entity 334 / ARPF entity 335 / SIDF entity 337. Upon receiving the authentication result confirmation request 550, in operation 552, UDM entity 334 can store the authentication status of UE 310. UDM entity 334 / ARPF entity 335 / SIDF entity 337 can send an authentication result confirmation response 554 to AUSF entity 332.
[0110] Upon receiving authentication response 548, in operation 528, SEAF entity 325 can generate a key for AMF entity 324, denoted as K. AMF .
[0111] Figure 5E K is shown as an example embodiment that can be applied to this disclosure. AMF Example graph generated. In generating K... AMF Afterwards, SEAF entity 325 can send K to AMF entity 324.AMF and ngKSI.
[0112] Return to reference Figure 5A Then, AMF entity 324 / SEAF entity 325 can send authentication result 529 to UE 310. Authentication result 529 may include HN packets that are integrity protected by (multiple) IKs and encrypted by (multiple) CKs.
[0113] Upon receiving authentication result 529, in operation 518, UE 310 can generate (multiple) CKs and (multiple) IKs. In some embodiments, in operation 518, UE 310 can, for example, use... Figure 1A , Figure 1B and Figure 1C The illustrated method generates CK and IK separately for the SoR, UPU, and / or another data transmission HN process. In some embodiments, during operation 518, UE 310 may, for example, use... Figure 2A and Figure 2B The method shown generates a combination CK and a combination IK that are shared by the SoR, UPU, and / or another data transmission HN process.
[0114] In some embodiments, UE 310 may use the generated CK(s) to decrypt HN packets and use the generated IK(s) to verify the integrity of HN packets. In some embodiments, UE 310 may send a response to ACK 519 to AUSF entity 332 via AMF entity 324 / SEAF entity 325, the response being integrity-protected and encrypted by the generated CK(s) and IK(s). Upon receiving the response to ACK 519, AUSF entity 332 may use the generated CK(s) to decrypt the response to ACK 519 and use the generated IK(s) to verify the integrity of the response to ACK 519.
[0115] Figure 6A An example sequence diagram is shown according to an example embodiment of the present disclosure. Figure 6A The example sequence diagram shown can be Figure 4 The example sequence diagram shown is based on the implementation of the Extensible Authentication Protocol (EAP) AKA master adaptation process.
[0116] refer to Figure 6A ,and Figure 4In contrast, in SN 320, RAN 322 is omitted, and SEAF entity 325 is also shown. It can be understood that transmissions between AMF entity 324 / SEAF entity 325 and UE 110 can be via RAN 322, and operations related to AMF entity 324 / SEAF entity 325 can be performed by AMF entity 324 and / or SEAF entity 325. In HN 330, with Figure 4 In comparison, ARPF entity 335 and SIDF entity 337 are also shown. Operations associated with UDM entity 334 / ARPF entity 335 / SIDF entity 337 can be performed by UDM entity 334, ARPF entity 335 and / or SIDF entity 337.
[0117] In operation 610, UE 310 may perform SUPI to SUCI hiding. UE 310 may then send registration request 612 to AMF entity 324 / SEAF entity 325. Registration request 612 may include UE 310's SUCI and / or 6G-GUTI. In some embodiments, registration request 612 may also include UE 110's UE security capabilities.
[0118] Upon receiving registration request 612, AMF entity 324 / SEAF entity 325 may send authentication request 620 to AUSF entity 332. Authentication request 620 may include UE 310's SUCI and / or 6G-GUTI, and may also include SN-name.
[0119] Upon receiving authentication request 620, AUSF entity 332 may send authentication acquisition request 630 to UDM entity 334 / ARPF entity 335 / SIDF entity 337. Authentication acquisition request 630 may include the SUCI and / or 6G-GUTI of UE 310, and the SN-name of SN 320.
[0120] Upon receiving authentication request 630, in operation 632, UDM entity 334 / ARPF entity 335 / SIDF entity 337 can perform SUCI to SUPI de-hiding. In operation 632, UDM entity 334 / ARPF entity 335 / SIDF entity 337 can also select an authentication method. Then, in operation 634, UDM entity 334 / ARPF entity 335 / SIDF entity 337 can generate an authentication vector.
[0121] Figure 6B An example diagram is shown that can be applied to example embodiments of authentication vector generation in this disclosure. Figure 6B In the example authentication vector generation shown, the generated authentication vector can be represented as EAP-AKA' AV.
[0122] Return to reference Figure 6A Then, UDM entity 334 / ARPF entity 335 / SIDF entity 337 can send an authentication acquisition response 636 to AUSF entity 332. The authentication acquisition response 636 may include the generated EAP-AKA' AV, UE 310's SUPI and AKMA indications.
[0123] Upon receiving authentication response 636, in operation 638, AUSF entity 332 may store XRES. AUSF entity 332 may also send authentication response 640 to AMF entity 324 / SEAF entity 325. Authentication response 640 may include an EAP request and / or an AKA challenge.
[0124] Upon receiving authentication response 640, AMF entity 324 / SEAF entity 325 may send authentication request 622 to UE 310. Authentication request 622 may include EAP request and / or AKA' challenge, as well as ngKSI and ABBA.
[0125] Upon receiving authentication request 622, UE 310 can perform network authentication in operation 614.
[0126] Figure 6C An example diagram of network authentication that can be applied to exemplary embodiments of this disclosure is shown. References Figure 6C In operation 614, UE 310 can verify whether MAC == XMAC & SQN is within the correct range.
[0127] Return to reference Figure 6A Then, UE 310 can send authentication response 616 to AMF entity 324 / SEAF entity 325. Authentication response 616 may include EAP response and / or AKA' challenge.
[0128] Upon receiving authentication response 616, AMF entity 324 / SEAF entity 325 may send authentication request 624 to AUSF entity 332. Authentication request 624 may include an EAP response and / or an AKA challenge.
[0129] Upon receiving authentication request 624, in operation 642, AUSF entity 332 can verify RES using the stored XRES. If verification is successful in operation 642, in operation 644, AUSF entity 332 can deduce the key for AUSF entity 332, denoted as K. AUSF and K SEAF .
[0130] Figure 6D K is shown as an example embodiment that can be applied to this disclosure.AUSF and K SEAF The generated example image. Then, return to the reference. Figure 6A In operation 646, AUSF entity 332 can generate (multiple) CKs and (multiple) IKs.
[0131] In some embodiments, during operation 646, the AUSF entity 332 may, for example, be... Figure 1A , Figure 1B and Figure 1C The illustrated method generates CK and IK separately for the SoR, UPU, and / or another data transmission HN process. In some embodiments, during operation 646, the AUSF entity 332 may, for example, be... Figure 2A and Figure 2B The method shown generates a combination CK and a combination IK that are shared by the SoR, UPU, and / or another data transmission HN process.
[0132] Then, optionally, in operation 648, UE 310 and AUSF entity 332 may perform additional EAP message exchange via AMF entity 324 / SEAF entity 325.
[0133] Then, AUSF entity 332 can send authentication response 650 to AMF entity 324 / SEAF entity 325. Authentication response 650 may include indication of EAP success, UE 310's SUPI, and the generated K. SEAF And an indication that the HN packet is protected by IK integrity by (multiple) and encrypted by (multiple) CK.
[0134] Furthermore, AUSF entity 332 can send an authentication result confirmation request 652 to UDM entity 334 / ARPF entity 335 / SIDF entity 337. Upon receiving the authentication result confirmation request 652, in operation 654, UDM entity 334 can store the authentication status of UE 310. UDM entity 334 / ARPF entity 335 / SIDF entity 337 can send an authentication result confirmation response 656 to AUSF entity 332.
[0135] Upon receiving authentication response 650, in operation 626, SEAF entity 325 can generate K. AMF .
[0136] Figure 6E K is shown as an example embodiment that can be applied to this disclosure. AMF Example graph generated. In generating K... AMF Afterwards, SEAF entity 325 can send K to AMF entity 324. AMF and ngKSI.
[0137] Return to reference Figure 6A Then, AMF entity 324 / SEAF entity 325 can send authentication result 628 or NAS SMC 629 to UE 310. Authentication result 628 or NAS SMC 629 may include indications of EAP success, ngKSI, ABBA, and indications of HN packets that are integrity protected by (multiple) IKs and encrypted by (multiple) CKs.
[0138] Upon receiving authentication result 628 or NAS SMC 629, in operation 617, UE 310 can generate K. AUSF K SEAF and K AMF .
[0139] Figure 6F K is shown as an example embodiment that can be applied to this disclosure. AUSF K SEAF and K AMF Example graph generated. In generating K... AMF Then, return to the reference. Figure 6A In operation 618, UE 310 can generate (multiple) CKs and (multiple) IKs.
[0140] In some embodiments, during operation 618, UE 310 may, for example, use Figure 1A , Figure 1B and Figure 1C The illustrated method generates CK and IK separately for the SoR, UPU, and / or another data transmission HN process. In some embodiments, during operation 618, UE 310 may, for example, use... Figure 2A and Figure 2B The method shown generates a combination CK and a combination IK that are shared by the SoR, UPU, and / or another data transmission HN process.
[0141] In some embodiments, UE 310 may use the generated CK(s) to decrypt the HN packet and use the generated IK(s) to verify the integrity of the HN packet. In some embodiments, UE 310 may send a response to ACK 519, which is protected and encrypted by the generated CK(s) and IK(s) via AMF entity 324 / SEAF entity 325 to AUSF entity 332. Upon receiving the response to ACK 519, AUSF entity 332 may use the generated CK(s) to decrypt the response to ACK 519 and use the generated IK(s) to verify the integrity of the response to CK 519.
[0142] Figure 7 An example sequence diagram is shown according to an example embodiment of the present disclosure. Figure 7The example sequences shown can also be executed by RAN 322 and AMF entity 324 of UE 310, SN 320, and AUSF entity 332 and UDM entity 334 of HN 330.
[0143] refer to Figure 7 UE 310 can send information about its security capabilities to AMF entity 324. For example, UE 310 can send information 312 about its security capabilities to AMF entity 324 via RAN 322. In some embodiments, information 312 can be sent from UE 310 to AMF entity 324 via a registration request. AMF entity 324 can then send an authentication request 426 for UE 310 to AMF entity 332. In some embodiments, authentication request 426 does not need to include information about UE 310's security capabilities. And in operation 338, UE 310, SN 320, and HN 330 can complete the AKA procedure.
[0144] In operation 442, AUSF entity 332 can generate (multiple) IKs according to the integrity protection algorithm and (multiple) CKs according to the encryption algorithm. In some embodiments, AUSF entity 332 can... Figures 1A to 1C Individual IK and individual CK are generated as shown. In some embodiments, AUSF entity 332 can be... Figures 2A to 2B The combination IK and combination CK are generated in the manner shown.
[0145] In some embodiments, for HN packets to be sent to UE 310, after integrity protection by the IK(s) generated in operation 442 and encryption by the CK(s) generated in operation 442, in operation 742, AUSF entity 332 may perform integrity protection and encryption on the HN packets using authentication and key generation functions f8 and f9, which are recommended by the European Telecommunications Standards Institute (ETSI) Security Algorithm Expert Group (SAGE). For example, f8 may be used for encryption, and f9 may be used for integrity protection.
[0146] Then, in operation 444, an authentication process can be performed between HN 330 and UE 310.
[0147] In operation 744, AUSF entity 332 may send packet 746 to UE 310, which is integrity protected and encrypted by the IK(s) and CK(s) generated in operation 442, and further encrypted and integrity protected by f8 and f9. In some embodiments, AUSF entity 332 may send one or more containers to UE 310. In some embodiments, packet 746 may be contained within one or more containers. Alternatively or additionally, one or more containers may include the RAND used in operation 442 to generate the CK(s) and IK(s).
[0148] In some embodiments, in operation 442, AUSF entity 332 is... Figures 1A to 1C When generating separate IKs and separate CKs as shown, AUSF entity 332 can construct and send separate containers for the separate IKs and separate CKs, respectively. For example, a container may include information about a RAND used to generate a key for SoR, a container may include information about a RAND used to generate a key for UPU, and a container may include information about a RAND used to generate a key for another data transmission HN process.
[0149] In some embodiments, in operation 442, AUSF entity 332 is... Figures 2A to 2B When the combined IK and combined CK are generated in the manner shown, AUSF entity 332 can construct and send a container for the combined IK and combined CK. For example, a container may include information about RAND used to generate a combined key shared by the SoR, UPU, and another data transmission HN process.
[0150] In operation 414, UE 310 can generate (multiple) IKs according to the integrity protection algorithm and (multiple) CKs according to the encryption algorithm. Then, UE 310 can use (multiple) CKs generated in operations 414 and f8 to decrypt packet 746 and use (multiple) IKs generated in operations 414 and f9 to verify the integrity of packet 746, thereby verifying the received packet 746.
[0151] In some embodiments, information about the integrity protection algorithm and the encryption algorithm, as well as information about f8 and f9, can be, for example, in a manner similar to... Figure 4 The implementation method is pre-configured in UE 310 and AUSF entity 332. In some embodiments, information regarding the integrity protection algorithm and encryption algorithm, as well as information regarding f8 and f9, can be provided by AUSF entity 332, for example, in a manner similar to... Figure 3 The notification method of the embodiment.
[0152] Upon successful verification of packet 746, in response to packet 746, UE 310 may perform encryption on ACK using (multiple) CKs generated in operation 414, and perform integrity protection on ACK using (multiple) IKs generated in operation 414. In operation 714, UE 310 may perform integrity protection and encryption on the acknowledgment using authentication and key generation functions f8 and f9. For example, f8 may be used for encryption, and f9 may be used for integrity protection.
[0153] Then, UE 310 can send ACK 716 to AUSF entity 332, which is protected for integrity by IK(s) generated in operations 414 and f9 and encrypted by CK(s) generated in operations 414 and f8.
[0154] Upon receiving ACK 716, AUSF entity 332 can use the (multiple) CKs generated in operations 442 and f8 to decrypt ACK 716, and use the (multiple) IKs generated in operations 442 and f9 to verify the integrity of ACK 716.
[0155] Therefore, encryption and integrity protection from HN 330 can be used to enhance SoR, UPU and / or another data transmission HN process, and a secure tunnel can be established between UE 310 and HN 330.
[0156] Then, in operation 326, UE 310 and SN 320 can execute the AS and NAS SMC procedures.
[0157] UE 310 and AUSF entity 332 can refresh individual or combined keys. For key refreshes targeting SoR, UPU, and another data transmission HN procedure, AUSF entity 332 can generate a new individual RAND. SoR RAND UPU And another RAND or a combination of RANDs, and thus newly generate corresponding CKs and IKs for SoR, UPU and / or another data transmission HN process. Receive the newly generated RANDs from AUSF entity 332, and UE 310 may also newly generate corresponding CKs and IKs for SoR, UPU and / or another data transmission HN process.
[0158] The secure data transfer service, denoted as Nn_SecureDataTransfer, establishes a secure tunnel between UE 310 and HN 330 and can be used to securely transfer data between UE 310 and HN 330.
[0159] In some embodiments, UE 310 may use the Secure Data Transmission Service to send data to a network device that is protected for integrity by (multiple) IKs and encrypted by (multiple) CKs. In some embodiments, the data may also be encrypted for integrity protection by f8 and f9 using the Secure Data Transmission Service.
[0160] In some embodiments, the network device may use the Secure Data Transmission Service to send data to the UE 310 that is protected for integrity by (multiple) IKs and encrypted by (multiple) CKs. In some embodiments, the data may also be encrypted for integrity protection by f8 and f9 using the Secure Data Transmission Service.
[0161] In some embodiments, the Nn_SecureDataTransfer service may include the following APIs: request / response, where HN 330 can securely transmit data to UE 310; and subscription / notification, where UE 310 is permitted to transmit data to HN 330, and HN 330 can deliver the data to the NF chain.
[0162] In the above example embodiment, AUSF entity 332 is used as an example of a network device. The operations performed by AUSF entity 332 in the above example embodiment can also be performed by UDM entity 334, NEF entity, and / or another NF entity. For example, secure data transmission services can be implemented by AUSF entity 332, UDM entity 334, NEF entity, and / or another NF entity. In addition to or as an alternative to AUSF entity 332, the network device according to the example embodiment can be used as UDM entity 334, NEF entity, and / or another NF entity, which, as an entity of HN 330, such as AUSF entity 332, can send secure packets to UE 310.
[0163] Similar to the example embodiments described above, in some embodiments, the UE 310 may also trigger or share uplink data or requests according to configuration, and the uplink transmission may be hidden from the 6G SN and sent toward the 6G HN.
[0164] In the example embodiments of this disclosure, functions such as f3, f4, f8, and f9 recommended by ETSI SAGE can be reused, and the key generation mechanisms for Radio Resource Control (RRC) for AN and NAS for SN can be applied to HN key generation.
[0165] Furthermore, according to the example embodiments of this disclosure, sensitive information can be protected, and in addition to the USIM in the case of secure grouping, the ME can also decrypt and continue sensitive information on demand.
[0166] Figure 8A flowchart illustrating an example method 800 for security according to an example embodiment of the present disclosure is shown. Example method 800 can be performed, for example, by a device for a terminal device (such as UE 310 described above).
[0167] refer to Figure 8 Example method 800 may include: operation 810, receiving a packet that is protected and encrypted with integrity from a network device; operation 820, generating at least one first key for integrity protection according to an integrity protection algorithm, and generating at least one second key for encryption according to an encryption algorithm; and operation 830, in response to the packet, sending an acknowledgment to the network device that the packet is protected with integrity by at least one first key and encrypted by at least one second key, provided that the packet has been successfully verified based on at least one first key and at least one second key.
[0168] In some embodiments, example method 800 may include: using authentication and key generation functions f3 and f4 to generate at least one first key and at least one second key based on a random number received from a network device and a key for the network device.
[0169] In some embodiments, the parameters used to generate at least one first key and at least one second key may include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, the home network algorithm identifier, and the length of the home network algorithm identifier.
[0170] In some embodiments, example method 800 may include: sending a security capability for an end device to a network device; and performing an SMC process with the network device, wherein the packet may include a security capability for the end device sent from the end device, and the integrity protection algorithm and encryption algorithm may be selected by the network device.
[0171] In some embodiments, integrity protection algorithms and encryption algorithms may be pre-configured.
[0172] In some embodiments, example method 800 may include performing integrity protection and encryption on the confirmation using authentication and key generation functions f8 and f9.
[0173] In some embodiments, example method 800 may include: refreshing at least one first key for integrity protection and at least one second key for encryption.
[0174] In some embodiments, at least one first key may include at least one of the following: a first key for the SoR process, a first key for the UPU process, a first key for the data transmission HN process, or a first key shared by the SoR process, the UPU process, and the data transmission HN process; and at least one second key may include at least one of the following: a second key for the SoR process, a second key for the UPU process, a second key for the data transmission HN process, or a second key shared by the SoR process, the UPU process, and the data transmission HN process.
[0175] In some embodiments, example method 800 may include: using a secure data transmission service to send data to a network device that is at least protected for integrity by at least one first key and encrypted by at least one second key.
[0176] Figure 9 A flowchart illustrating an example method 900 for security according to an example embodiment of the present disclosure is shown. Example method 900 can be performed, for example, by means of a network device (such as the network device in the example above), which can be, for example, the AUSF entity 332, UDM entity 334, NEF entity, and / or another NF entity described above.
[0177] refer to Figure 9 Example method 900 may include: operation 910, generating at least one first key for integrity protection according to an integrity protection algorithm, and generating at least one second key for encryption according to an encryption algorithm; operation 920, sending a packet to a terminal device that is at least integrity protected by at least one first key and encrypted by at least one second key; and operation 930, receiving an acknowledgment of integrity protection and encryption from the terminal device in response to the packet.
[0178] In some embodiments, example method 900 may include: using authentication and key generation functions f3 and f4 to generate at least one first key and at least one second key based on a random number generated by the device and a key for the network device.
[0179] In some embodiments, the parameters used to generate at least one first key and at least one second key may include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, the home network algorithm identifier, and the length of the home network algorithm identifier.
[0180] In some embodiments, example method 900 may include: receiving security capabilities for the terminal device from a terminal device; selecting an integrity protection algorithm and an encryption algorithm based on the security capabilities for the terminal device; and performing an SMC process with the terminal device, wherein the packet includes the security capabilities for the terminal device sent from the terminal device.
[0181] In some embodiments, example method 900 may include performing integrity protection and encryption on the packet using authentication and key generation functions f8 and f9.
[0182] In some embodiments, example method 900 may include: refreshing at least one first key for integrity protection and at least one second key for encryption.
[0183] In some embodiments, at least one first key may include at least one of the following: a first key for the SoR process, a first key for the UPU process, a first key for the data transmission HN process, or a first key shared by the SoR process, the UPU process, and the data transmission HN process; and at least one second key may include at least one of the following: a second key for the SoR process, a second key for the UPU process, a second key for the data transmission HN process, or a second key shared by the SoR process, the UPU process, and the data transmission HN process.
[0184] In some embodiments, example method 900 may include: using a secure data transmission service to send data to a terminal device that is at least protected for integrity by at least one first key and encrypted by at least one second key.
[0185] In some embodiments, the device can be used as at least one of the following: an AUSF entity, a UDM entity, a NEF entity, or an NF entity.
[0186] Figure 10 A block diagram illustrating an example security device 1000 according to an exemplary embodiment of the present disclosure is shown. This device may be, for example, at least part of a device for a terminal device, such as UE 310 in the above example.
[0187] like Figure 10 As shown, the example device 1000 may include at least one processor 1010 and at least one memory 1020 that can store instructions 1030. When executed by the at least one processor 1010, the instructions 1030 may cause the device 1000 to perform at least the example method 800 described above.
[0188] In various example embodiments, at least one processor 1010 in example device 1000 may include, but is not limited to, at least one hardware processor, including at least one microprocessor (such as a central processing unit (CPU)), a portion of at least one hardware processor, and any other suitable dedicated processor (such as those developed based on, for example, field-programmable gate arrays (FPGAs) and application-specific integrated circuits (ASICs)). Furthermore, at least one processor 1010 may also include... Figure 10At least one other circuit or element not shown in the diagram.
[0189] In various example embodiments, at least one memory 1020 in example device 1000 may include at least one storage medium of various forms, such as transient and / or non-transient memory. Transient memory may include, but is not limited to, for example, random access memory (RAM), cache, etc. Non-transient memory may include, but is not limited to, for example, read-only memory (ROM), hard disk, flash memory, etc. As used herein, the term "non-transient" is a limitation on the medium itself (i.e., tangible, not tactile) rather than on the persistence of data storage (e.g., RAM vs. ROM). Furthermore, at least one memory 1020 may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatuses, or any combination thereof.
[0190] In addition, in various example embodiments, example device 1000 may also include at least one other circuit, element, and interface, such as at least one I / O interface, at least one antenna element, etc.
[0191] In various example embodiments, circuits, components, elements, and interfaces in example device 1000, including at least one processor 1010 and at least one memory 1020, can be coupled together in any suitable manner (e.g., electrical, magnetic, optical, electromagnetic, etc.) via any suitable connection (including but not limited to bus, cross switch, wiring, and / or wireless line).
[0192] It should be understood that the structure of the device on the UE 310 side is not limited to the example device 1000 described above.
[0193] Figure 11 A block diagram illustrating an example device 1100 for security according to an example embodiment of the present disclosure is shown. This device may be, for example, at least part of an apparatus for a network device (such as a network device), which may be, for example, AUSF entity 332, UDM entity 334, NEF entity and / or another NF entity as shown in the above example.
[0194] like Figure 11 As shown, the example device 1100 may include at least one processor 1110 and at least one memory 1120 that can store instructions 1130. When executed by the at least one processor 1110, the instructions 1130 may cause the device 1100 to perform at least the example method 900 described above.
[0195] In various example embodiments, at least one processor 1110 in example device 1100 may include, but is not limited to, at least one hardware processor, including at least one microprocessor (such as a central processing unit (CPU)), a portion of at least one hardware processor, and any other suitable dedicated processor (such as those developed based on, for example, field-programmable gate arrays (FPGAs) and application-specific integrated circuits (ASICs)). Furthermore, at least one processor 1110 may also include... Figure 11 At least one other circuit or element not shown in the diagram.
[0196] In various example embodiments, at least one memory 1120 in example device 1100 may include at least one storage medium of various forms, such as transient and / or non-transient memory. Transient memory may include, but is not limited to, for example, random access memory (RAM), cache, etc. Non-transient memory may include, but is not limited to, for example, read-only memory (ROM), hard disk, flash memory, etc. As used herein, the term "non-transient" is a limitation on the medium itself (i.e., tangible, not tactile) rather than on the persistence of data storage (e.g., RAM vs. ROM). Furthermore, at least one memory 1120 may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatuses, or any combination thereof.
[0197] In addition, in various example embodiments, example device 1100 may also include at least one other circuit, element, and interface, such as at least one I / O interface, at least one antenna element, etc.
[0198] In various example embodiments, circuits, components, elements, and interfaces in example device 1100, including at least one processor 1110 and at least one memory 1120, can be coupled together in any suitable manner (e.g., electrical, magnetic, optical, electromagnetic, etc.) via any suitable connection (including but not limited to bus, cross switch, wiring, and / or wireless line).
[0199] It should be understood that the structure of the network device is not limited to the example device 1100 described above.
[0200] Figure 12 A block diagram illustrating an example security apparatus 1200 according to an exemplary embodiment of the present disclosure is shown. This apparatus may be, for example, at least part of a terminal device, such as UE 310 in the above example.
[0201] like Figure 12As shown, the example apparatus 1200 may include: a component 1210 for receiving a packet that is integrity-protected and encrypted from a network device; a component 1220 for generating at least one first key for integrity protection according to an integrity protection algorithm and at least one second key for encryption according to an encryption algorithm; and a component 1230 for sending an acknowledgment to the network device in response to the packet, provided that the packet has been successfully verified based on at least one first key and at least one second key, that the packet has been integrity-protected by at least one first key and encrypted by at least one second key.
[0202] In some embodiments, the apparatus 1200 may include a component for generating at least one first key and at least one second key based on a random number received from a network device and a key for the network device using authentication and key generation functions f3 and f4.
[0203] In some embodiments, the parameters used to generate at least one first key and at least one second key may include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, the home network algorithm identifier, and the length of the home network algorithm identifier.
[0204] In some embodiments, the apparatus 1200 may include: components for sending security capabilities for an end device to a network device; and components for performing an SMC process with the network device, wherein the packet may include security capabilities for the end device sent from the end device, and the integrity protection algorithm and encryption algorithm may be selected by the network device.
[0205] In some embodiments, integrity protection algorithms and encryption algorithms may be pre-configured.
[0206] In some embodiments, the apparatus 1200 may include components for performing integrity protection and encryption on the authentication using authentication and key generation functions f8 and f9.
[0207] In some embodiments, the apparatus 1200 may include a component for refreshing at least one first key for integrity protection and at least one second key for encryption.
[0208] In some embodiments, at least one first key may include at least one of the following: a first key for the SoR process, a first key for the UPU process, a first key for the data transmission HN process, or a first key shared by the SoR process, the UPU process, and the data transmission HN process; and at least one second key may include at least one of the following: a second key for the SoR process, a second key for the UPU process, a second key for the data transmission HN process, or a second key shared by the SoR process, the UPU process, and the data transmission HN process.
[0209] In some embodiments, the apparatus 1200 may include a component for sending data, which is protected for integrity by at least one first key and encrypted by at least one second key, to a network device using a secure data transmission service.
[0210] In some example embodiments, examples of components in example device 1200 may include circuitry. For example, an example of component 1210 may include circuitry configured to perform operation 810 of example method 800, an example of component 1220 may include circuitry configured to perform operation 820 of example method 800, and an example of component 1230 may include circuitry configured to perform operation 830 of example method 800.
[0211] Example device 1200 may also include components having circuitry configured to perform example method 800. In some example embodiments, examples of components may also include software modules and any other suitable functional entities.
[0212] Figure 13 A block diagram illustrating an example security apparatus 1300 according to an example embodiment of the present disclosure is shown. This apparatus may be, for example, at least part of a network device, such as the network device in the above example, which may be, for example, AUSF entity 332, UDM entity 334, NEF entity, and / or another NF entity as described above.
[0213] like Figure 13 As shown, the example apparatus 1300 may include: a component 1310 for generating at least one first key for integrity protection according to an integrity protection algorithm and generating at least one second key for encryption according to an encryption algorithm; a component 1320 for sending a packet to a terminal device that is at least integrity-protected by at least one first key and encrypted by at least one second key; and a component 1330 for receiving an acknowledgment that is integrity-protected and encrypted from the terminal device in response to the packet.
[0214] In some embodiments, the apparatus 1300 may include a component for generating at least one first key and at least one second key based on a random number generated by the apparatus and a key for a network device using authentication and key generation functions f3 and f4.
[0215] In some embodiments, the parameters used to generate at least one first key and at least one second key may include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, the home network algorithm identifier, and the length of the home network algorithm identifier.
[0216] In some embodiments, the apparatus 1300 may include: components for receiving security capabilities for the terminal device from a terminal device; components for selecting an integrity protection algorithm and an encryption algorithm based on the security capabilities for the terminal device; and components for performing an SMC process with the terminal device, wherein the packet includes the security capabilities for the terminal device sent from the terminal device.
[0217] In some embodiments, the apparatus 1300 may include components for performing integrity protection and encryption on packets using authentication and key generation functions f8 and f9.
[0218] In some embodiments, the apparatus 1300 may include components for refreshing at least one first key for integrity protection and at least one second key for encryption.
[0219] In some embodiments, at least one first key may include at least one of the following: a first key for the SoR process, a first key for the UPU process, a first key for the data transmission HN process, or a first key shared by the SoR process, the UPU process, and the data transmission HN process; and at least one second key may include at least one of the following: a second key for the SoR process, a second key for the UPU process, a second key for the data transmission HN process, or a second key shared by the SoR process, the UPU process, and the data transmission HN process.
[0220] In some embodiments, the apparatus 1300 may include a component for sending data, which is protected for integrity by at least one first key and encrypted by at least one second key, to a terminal device using a secure data transmission service.
[0221] In some embodiments, the device can be used as at least one of the following: an AUSF entity, a UDM entity, a NEF entity, or an NF entity.
[0222] In some example embodiments, examples of components in example device 1300 may include circuitry. For example, an example of component 1310 may include circuitry configured to perform operation 910 of example method 900, an example of component 1320 may include circuitry configured to perform operation 920 of example method 900, and an example of component 1330 may include circuitry configured to perform operation 930 of example method 900.
[0223] Example device 1300 may also include components having circuitry configured to perform example method 900. In some example embodiments, examples of components may also include software modules and any other suitable functional entities.
[0224] Example embodiments of this disclosure also provide a computer-readable medium including program instructions that, when executed by a means for a terminal device (such as UE 310 in the above example), cause the means to at least: receive a packet that is integrity-protected and encrypted from a network device; generate at least one first key for integrity protection according to an integrity protection algorithm, and generate at least one second key for encryption according to an encryption algorithm; and, in response to a packet that has been successfully verified based on at least one first key and at least one second key, send an acknowledgment to the network device that the packet is integrity-protected by at least one first key and encrypted by at least one second key.
[0225] In some embodiments, the computer-readable medium may include instructions that, when executed by the device, cause the device to: generate at least one first key and at least one second key based on a random number received from the network device and a key for the network device, using authentication and key generation functions f3 and f4.
[0226] In some embodiments, the parameters used to generate at least one first key and at least one second key may include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, the home network algorithm identifier, and the length of the home network algorithm identifier.
[0227] In some embodiments, the computer-readable medium may include instructions that, when executed by the device, enable the device to: send a security capability for the terminal device to a network device; and perform an SMC process with the network device, wherein the packet may include a security capability for the terminal device sent from the terminal device, and the integrity protection algorithm and encryption algorithm may be selected by the network device.
[0228] In some embodiments, integrity protection algorithms and encryption algorithms may be pre-configured.
[0229] In some embodiments, the computer-readable medium may include instructions that, when executed by the device, cause the device to: perform integrity protection and encryption on the authentication using authentication and key generation functions f8 and f9.
[0230] In some embodiments, the computer-readable medium may include instructions that, when executed by a device, cause the device to perform the following: refresh at least one first key for integrity protection and at least one second key for encryption.
[0231] In some embodiments, at least one first key may include at least one of the following: a first key for the SoR process, a first key for the UPU process, a first key for the data transmission HN process, or a first key shared by the SoR process, the UPU process, and the data transmission HN process; and at least one second key may include at least one of the following: a second key for the SoR process, a second key for the UPU process, a second key for the data transmission HN process, or a second key shared by the SoR process, the UPU process, and the data transmission HN process.
[0232] In some embodiments, the computer-readable medium may include instructions that, when executed by a device, cause the device to: use a secure data transmission service to send data to the network device that is protected for integrity by at least one first key and encrypted by at least one second key.
[0233] Example embodiments of this disclosure also provide a computer-readable medium including program instructions that, when executed by an apparatus for a network device (such as the network device in the example above), cause the apparatus to at least: generate at least one first key for integrity protection according to an integrity protection algorithm and generate at least one second key for encryption according to an encryption algorithm; send a packet to a terminal device that is at least integrity-protected by at least one first key and encrypted by at least one second key; and receive an acknowledgment from the terminal device that the packet is integrity-protected and encrypted in response to the packet.
[0234] In some embodiments, the computer-readable medium may include instructions that, when executed by the device, cause the device to: use authentication and key generation functions f3 and f4 to generate at least one first key and at least one second key based on a random number generated by the device and a key for a network device.
[0235] In some embodiments, the parameters used to generate at least one first key and at least one second key may include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, the home network algorithm identifier, and the length of the home network algorithm identifier.
[0236] In some embodiments, the computer-readable medium may include instructions that, when executed by a device, cause the device to: receive security capabilities for the terminal device from a terminal device; select an integrity protection algorithm and an encryption algorithm based on the security capabilities for the terminal device; and perform an SMC process with the terminal device, wherein the packet includes the security capabilities for the terminal device sent from the terminal device.
[0237] In some embodiments, a computer-readable medium may include instructions that, when executed by a device, cause the device to: perform integrity protection and encryption on packets using authentication and key generation functions f8 and f9.
[0238] In some embodiments, the computer-readable medium may include instructions that, when executed by the device, may cause the device to: refresh at least one first key for integrity protection and at least one second key for encryption.
[0239] In some embodiments, at least one first key may include at least one of the following: a first key for the SoR process, a first key for the UPU process, a first key for the data transmission HN process, or a first key shared by the SoR process, the UPU process, and the data transmission HN process; and at least one second key may include at least one of the following: a second key for the SoR process, a second key for the UPU process, a second key for the data transmission HN process, or a second key shared by the SoR process, the UPU process, and the data transmission HN process.
[0240] In some embodiments, the computer-readable medium may include instructions that, when executed by the device, cause the device to: use a secure data transmission service to send data to a terminal device that is protected for integrity by at least one first key and encrypted by at least one second key.
[0241] In some embodiments, the device may be used as at least one of the following: an AUSF entity, a UDM entity, a NEF entity, or an NF entity.
[0242] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, wherein a list of two or more elements, combined with “and” or “or”, means at least one element, or at least any two or more elements, or at least all elements.
[0243] The term "terminal device" refers to any terminal device capable of wireless communication. As an example and not a limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices can include, but are not limited to, mobile phones, cellular phones, smartphones, Voice over IP (VoIP) phones, wireless local loop phones, tablet computers, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback facilities, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop-mounted devices (LMEs), USB dongles, smart devices, wireless customer premises equipment (CPEs), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in industrial and / or automated processing chain environments), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, etc. Terminal equipment may also correspond to the mobile terminal (MT) portion of an IAB node (e.g., a relay node). In the above description, the terms "terminal equipment," "communication equipment," "terminal," "user equipment," and "UE" are used interchangeably.
[0244] Throughout this disclosure, the term "circuit" may refer to one or more or all of the following: (a) a hardware circuit implementation (such as an implementation in purely analog and / or digital circuitry); (b) a combination of hardware circuitry and software, such as (where applicable) (i) a combination of analog and / or digital hardware circuitry with software / firmware, and (ii) any portion of a hardware processor having software (including (multiple) digital signal processors, software, and (multiple) memories that work together to enable a device such as a mobile phone or server to perform various functions); and (c) (multiple) hardware circuitry and / or (multiple) processors that require software (e.g., firmware) for operation, such as being a (multiple) microprocessor or part of a (multiple) microprocessor, but where the software may be absent when operation does not require it. This definition of "circuit" applies to all or all of the use of the term in this disclosure, including in any claim. As another example, as used in this disclosure, the term "circuit" also covers implementations of hardware circuitry or processors (or multiple processors) alone, or portions of hardware circuitry or processors and their accompanying software and / or firmware. For example, where applicable to the elements of the claims, the term "circuit" also covers baseband integrated circuits or processor integrated circuits for mobile devices or similar integrated circuits in servers, cellular network devices or other computing or network devices.
[0245] Another example embodiment may relate to computer program code or instructions that cause a device to perform at least the corresponding methods described above. Another example embodiment may relate to a computer-readable medium on which such computer program code or instructions are stored. In some embodiments, such a computer-readable medium may include at least one storage medium of various forms, such as volatile memory and / or non-volatile memory. Volatile memory may include, but is not limited to, for example, RAM, cache, etc. Non-volatile memory may include, but is not limited to, ROM, hard disk, flash memory, etc. Non-volatile memory may also include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or equipment, or any combination thereof.
[0246] Unless the context clearly requires otherwise, throughout the specification and claims, the words “comprising,” “including,” etc., shall be interpreted in an inclusive sense, rather than an exclusive or exhaustive sense; that is, the sense of “including but not limited to.” The word “coupled,” as commonly used herein, refers to two or more elements that can be directly connected or connected via one or more intermediate elements. Similarly, the word “connected,” as commonly used herein, refers to two or more elements that can be directly connected or connected via one or more intermediate elements. Furthermore, when used in this application, the words “this,” “above,” “below,” and similar terms shall refer to the application as a whole and not to any particular part thereof. Where the context permits, the use of singular or plural terms in the description may also include the plural or singular accordingly. The word “or,” referring to a list of two or more items, covers all of the following interpretations: any item in the list, all items in the list, and any combination of items in the list.
[0247] Furthermore, the conditional language used herein, such as “can,” “may,” “possibly,” “can,” “e.g.,” “for example,” “like,” etc., unless otherwise specifically stated or otherwise understood in the context in which they are used, is generally intended to convey that certain embodiments include certain features, elements, and / or states, while other embodiments do not include certain features, elements, and / or states. Therefore, such conditional language is not generally intended to imply that said features, elements, and / or states are required in any way for one or more embodiments, or that one or more embodiments must include logic for determining whether such features, elements, and / or states are included or will be performed in any particular embodiment, with or without author input or prompting.
[0248] As used herein, the term "determine" (and its grammatical variations) can include at least: calculation, operation, processing, derivation, measurement, investigation, lookup (e.g., searching in a table, database, or other data structure), ascertainment, etc. Furthermore, "determine" can include receiving (e.g., receiving information), accessing (e.g., accessing data in memory), obtaining, etc. Moreover, "determine" can include parsing, selecting, picking, building, etc.
[0249] While some embodiments have been described, these embodiments have been presented by way of example and are not intended to limit the scope of this disclosure. In fact, the apparatuses, methods, and systems described herein can be embodied in a variety of other forms; furthermore, various omissions, substitutions, and changes can be made to the form of the methods and systems described herein without departing from the spirit of this disclosure. For example, although blocks are presented in a given arrangement, alternative embodiments may utilize different components and / or circuit topologies to perform similar functions, and some blocks may be deleted, moved, added, subdivided, combined, and / or modified. At least one of these blocks can be implemented in a variety of different ways. The order of these blocks may also be changed. Any suitable combination of elements and actions of some of the embodiments described above can be combined to provide other embodiments. The appended claims and their equivalents are intended to cover such forms or modifications that fall within the scope and spirit of this disclosure.
[0250] The abbreviations used in the specification and / or figures are defined as follows: 3GPP TS (Third Generation Partnership Project) Technical Specification 3G third-generation mobile communication system 4G fourth-generation mobile communication system 5G fifth-generation mobile communication system 6G sixth generation mobile communication system 6G-GUTI (Globally Unique Temporary UE Identifier) Degradation prevention between ABBA architectures ACK confirmation AMF access and mobility management functions AMF Certification Management Fields AK Anonymous Key AKA Authentication and Key Negotiation AKMA is used for application authentication and key management. AN access network ARPF credential storage and processing functions AS Access Layer AuC Certification Center AUSF Authentication Server Functionality AUTN Authentication Token AV Authentication Vector After B5G CK cryptographic key EAP Extensible Authentication Protocol ETSI (European Telecommunications Standards Institute) FC function codes HE belongs to the environment HN Belonging Network HRES Hash Response HSS belongs to user server HXRES Hash Expected Response IK Integrity Key KDF key derivation function MAC Message Authentication Code ME mobile devices NAS Non-Access Layer NEF Network Open Functions NF Network Functions ngKSI Next Generation Radio Access Network RAN Radio Access Network RAND random numbers RES response RFC for Comments Request RRC Radio Resource Control SAGE Security Algorithm Expert Group SE Service Environment SEAF safety anchoring function SIDF subscription identifier unhiding function SMC Safe Mode Command SN service network SNPN Independent Non-Public Network SoR Roaming Guide SQN serial number SUCI subscription hidden identifier SUPI subscription permanent identifier UDM Unified Data Management UE User Equipment UPUUE parameter update USIM Universal Subscriber Identification Module VPLMN surveyed public land mobile networks XMAC Expected MAC XRES expected response.
Claims
1. An apparatus for a terminal device, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the device to at least: Receive integrity-protected and encrypted packets from network devices; At least one first key for integrity protection is generated according to the integrity protection algorithm, and at least one second key for encryption is generated according to the encryption algorithm. as well as If the packet is successfully verified based on at least the at least one first key and the at least one second key, in response to the packet, an acknowledgment that is at least protected for integrity by the at least one first key and encrypted by the at least one second key is sent to the network device.
2. The apparatus of claim 1, wherein the apparatus is configured to: The at least one first key and the at least one second key are generated using authentication and key generation functions f3 and f4, based on a random number received from the network device and a key used by the network device.
3. The apparatus according to claim 1 or 2, wherein the parameters for generating the at least one first key and the at least one second key include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, a home network algorithm identifier, and the length of the home network algorithm identifier.
4. The apparatus according to claim 1 or 2, wherein the apparatus is configured to: Sending security capabilities for the terminal device to the network device; and The network device executes a security mode command procedure, wherein the packet includes the security capabilities for the terminal device sent from the terminal device, and the integrity protection algorithm and the encryption algorithm are selected by the network device.
5. The apparatus according to claim 1 or 2, wherein the integrity protection algorithm and the encryption algorithm are pre-configured.
6. The apparatus according to claim 1 or 2, wherein the apparatus is configured to: The authentication and key generation functions f8 and f9 are used to perform integrity protection and encryption on the confirmation.
7. The apparatus according to claim 1 or 2, wherein the apparatus is configured to: Refresh the at least one first key used for integrity protection and the at least one second key used for encryption.
8. The apparatus according to claim 1 or 2, wherein the at least one first key comprises at least one of the following: a first key for a roaming setup process, a first key for a user equipment parameter update process, a first key for a data transmission home network process, or a first key shared by the roaming setup process, the user equipment parameter update process, and the data transmission home network process; and The at least one second key includes at least one of the following: a second key for the roaming guidance process, a second key for the user equipment parameter update process, a second key for the data transmission home network process, or a second key shared by the roaming guidance process, the user equipment parameter update process, and the data transmission home network process.
9. The apparatus according to claim 1 or 2, wherein the apparatus is configured to: Using a secure data transmission service, data that is protected for integrity by at least one first key and encrypted by at least one second key is sent to the network device.
10. An apparatus for a network device, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the device to at least: At least one first key for integrity protection is generated according to the integrity protection algorithm, and at least one second key for encryption is generated according to the encryption algorithm. Sending packets to the terminal device that are at least protected for integrity by the at least one first key and encrypted by the at least one second key; as well as In response to the packet receiving an integrity-protected and encrypted acknowledgment from the terminal device.
11. The apparatus of claim 10, wherein the apparatus is configured to: The at least one first key and the at least one second key are generated using authentication and key generation functions f3 and f4, based on a random number generated by the device and a key used for the network device.
12. The apparatus of claim 10 or 11, wherein the parameters for generating the at least one first key and the at least one second key include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, a home network algorithm identifier, and the length of the home network algorithm identifier.
13. The apparatus according to claim 10 or 11, wherein the apparatus is configured to: Receive security capabilities for the terminal device from the terminal device; Based on the security capabilities of the terminal device, the integrity protection algorithm and the encryption algorithm are selected; and The process of executing a security mode command with the terminal device, wherein the packet includes the security capabilities of the terminal device sent from the terminal device.
14. The apparatus according to claim 10 or 11, wherein the apparatus is configured to: Integrity protection and encryption are performed on the packets using authentication and key generation functions f8 and f9.
15. The apparatus according to claim 10 or 11, wherein the apparatus is configured to: Refresh the at least one first key used for integrity protection and the at least one second key used for encryption.
16. The apparatus of claim 10 or 11, wherein the at least one first key comprises at least one of the following: a first key for a roaming setup process, a first key for a user equipment parameter update process, a first key for a data transmission home network process, or a first key shared by the roaming setup process, the user equipment parameter update process, and the data transmission home network process; and The at least one second key includes at least one of the following: a second key for the roaming guidance process, a second key for the user equipment parameter update process, a second key for the data transmission home network process, or a second key shared by the roaming guidance process, the user equipment parameter update process, and the data transmission home network process.
17. The apparatus according to claim 10 or 11, wherein the apparatus is configured to: Using a secure data transmission service, data that is protected for integrity by at least one first key and encrypted by at least one second key is sent to the terminal device.
18. The apparatus according to claim 10 or 11, wherein the apparatus is used as at least one of the following: an authentication server functional entity, a unified data management entity, a network open functional entity, or a network functional entity.
19. A method performed by means for a terminal device, comprising: Receive integrity-protected and encrypted packets from network devices; At least one first key for integrity protection is generated according to the integrity protection algorithm, and at least one second key for encryption is generated according to the encryption algorithm. as well as If the packet is successfully verified based on at least the at least one first key and the at least one second key, in response to the packet, an acknowledgment that is at least protected for integrity by the at least one first key and encrypted by the at least one second key is sent to the network device.
20. The method of claim 19, comprising: The at least one first key and the at least one second key are generated using authentication and key generation functions f3 and f4, based on a random number received from the network device and a key used by the network device.
21. The method according to claim 19 or 20, wherein the parameters for generating the at least one first key and the at least one second key include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, a home network algorithm identifier, and the length of the home network algorithm identifier.
22. The method of claim 19 or 20, comprising: Send security capabilities for the terminal device to the network device; as well as The network device executes a security mode command procedure, wherein the packet includes the security capabilities for the terminal device sent from the terminal device, and the integrity protection algorithm and the encryption algorithm are selected by the network device.
23. The method according to claim 19 or 20, wherein the integrity protection algorithm and the encryption algorithm are pre-configured.
24. The method according to claim 19 or 20, comprising: The authentication and key generation functions f8 and f9 are used to perform integrity protection and encryption on the confirmation.
25. The method according to claim 19 or 20, comprising: Refresh the at least one first key used for integrity protection and the at least one second key used for encryption.
26. The method according to claim 19 or 20, wherein the at least one first key comprises at least one of the following: a first key for a roaming bootstrapping process, a first key for a user equipment parameter update process, a first key for a data transmission home network process, or a first key shared by the roaming bootstrapping process, the user equipment parameter update process, and the data transmission home network process; and The at least one second key includes at least one of the following: a second key for the roaming guidance process, a second key for the user equipment parameter update process, a second key for the data transmission home network process, or a second key shared by the roaming guidance process, the user equipment parameter update process, and the data transmission home network process.
27. The method according to claim 19 or 20, comprising: Using a secure data transmission service, data that is protected for integrity by at least one first key and encrypted by at least one second key is sent to the network device.
28. A method performed by means for a network device, comprising: At least one first key for integrity protection is generated according to the integrity protection algorithm, and at least one second key for encryption is generated according to the encryption algorithm. Sending packets to the terminal device that are at least protected for integrity by the at least one first key and encrypted by the at least one second key; as well as In response to the packet receiving an integrity-protected and encrypted acknowledgment from the terminal device.
29. The method of claim 28, comprising: The at least one first key and the at least one second key are generated using authentication and key generation functions f3 and f4, based on a random number generated by the device and a key used for the network device.
30. The method according to claim 28 or 29, wherein the parameters for generating the at least one first key and the at least one second key include a home network algorithm type distinguisher, the length of the home network algorithm type distinguisher, a home network algorithm identifier, and the length of the home network algorithm identifier.
31. The method according to claim 28 or 29, comprising: Receive security capabilities for the terminal device from the terminal device; Based on the security capabilities of the terminal device, the integrity protection algorithm and the encryption algorithm are selected. as well as The process of executing a security mode command with the terminal device, wherein the packet includes the security capabilities of the terminal device sent from the terminal device.
32. The method according to claim 28 or 29, comprising: Integrity protection and encryption are performed on the packets using authentication and key generation functions f8 and f9.
33. The method according to claim 28 or 29, comprising: Refresh the at least one first key used for integrity protection and the at least one second key used for encryption.
34. The method according to claim 28 or 29, wherein the at least one first key comprises at least one of the following: a first key for a roaming guidance process, a first key for a user equipment parameter update process, a first key for a data transmission home network process, or a first key shared by the roaming guidance process, the user equipment parameter update process, and the data transmission home network process; and The at least one second key includes at least one of the following: a second key for the roaming guidance process, a second key for the user equipment parameter update process, a second key for the data transmission home network process, or a second key shared by the roaming guidance process, the user equipment parameter update process, and the data transmission home network process.
35. The method according to claim 28 or 29, comprising: Using a secure data transmission service, data that is protected for integrity by at least one first key and encrypted by at least one second key is sent to the terminal device.
36. The method according to claim 28 or 29, wherein the apparatus is used as at least one of the following: an authentication server functional entity, a unified data management entity, a network open functional entity, or a network functional entity.
37. An apparatus for a terminal device, comprising components for performing the method according to any one of claims 19 to 27.
38. An apparatus for a network device, comprising components for performing the method according to any one of claims 28 to 36.
39. A computer-readable medium comprising program instructions that, when executed by a means for a terminal device, cause the means to perform at least the method according to any one of claims 19 to 27.
40. A computer-readable medium comprising program instructions that, when executed by a means for a network device, cause the means to perform at least the method according to any one of claims 28 to 36.