Communication network user identity protection method, apparatus, device, medium, and product
By selecting the highest priority SUPI protection scheme in the mobile device ME and performing secondary processing on the SUCI to generate a new SUCI, the problems of existing technologies being unable to cope with quantum computing attacks and the increased cost of replacing the USIM card are solved. This achieves SUPI protection without replacing the card, improving security and cost-effectiveness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2025-11-11
- Publication Date
- 2026-06-12
AI Technical Summary
Existing technologies cannot effectively counter quantum computing attacks, and replacing USIM cards to support the PQC algorithm will increase operating costs. Existing users who do not replace their cards cannot solve the problem of SUPI protection against quantum attacks.
By selecting the highest priority SUPI protection scheme in the mobile device ME, the SUCI is processed again to generate a new SUCI. By utilizing the computing and storage capabilities of the ME, the changes in the network-side cryptographic policy can be supported, thus achieving SUPI protection without changing the card.
It enhances the quantum attack resistance of SUPI protection, reduces operating costs, fully utilizes ME's computing and storage capabilities, and supports SUPI protection for existing users.
Smart Images

Figure CN122205409A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security technology, and in particular to a method, apparatus, device, medium and product for protecting user identifiers in communication networks. Background Technology
[0002] With the rapid development of Internet technology, the network security risks of information systems continue to increase, and the threats and challenges are becoming increasingly severe. Cryptographic security is an important foundation of information security and can be used to effectively protect the data security of network information systems. Cryptographic technology is a core technology and an important means to protect network information systems.
[0003] In 5G networks, to enhance the security of the SUPI (Subscription Permanent Identifier) over the air interface, when the SUPI needs to be transmitted via the air interface, the UE (User Equipment) employs the ECIES (Elliptic Curve Integrated Encryption Scheme) algorithm. Based on the home network's public key, it encrypts and encapsulates the SUPI to generate a SUCI (Subscription Concealed Identifier). This SUCI is then transmitted to the home network via the air interface, replacing the SUPI, effectively protecting the privacy and security of the end user and preventing security risks such as tracking attacks. The ECIES algorithm uses either Profile A or Profile B based on the ECC (Elliptic Curve Cryptography) algorithm to achieve key negotiation and data encryption.
[0004] However, with the rapid development of quantum computing technology, future networks (such as 6G) will present a complex scenario where multiple algorithms coexist, including traditional algorithms (ECC), international PQC (Post-Quantum Cryptography) algorithms (ML-KEM, Module-Lattice-Based Key Encapsulation Mechanism), domestic PQC algorithms, and dedicated algorithms. This places higher demands on the algorithm compatibility of communication equipment, the uniformity of key management, and the flexibility of security protocols.
[0005] Supporting the PQC algorithm typically requires replacing or upgrading the USIM card, but widespread card replacement increases operational costs; existing users who don't replace their cards cannot resolve the quantum attack resistance issue of SUPI protection. Therefore, how to achieve SUPI protection for existing users who don't replace their cards to effectively cope with quantum attacks is a problem that urgently needs to be solved. Summary of the Invention
[0006] This application provides a method, apparatus, device, medium, and product for protecting user identifiers in communication networks, which addresses the technical problem that while USIM cards typically need to be replaced and upgraded to support the PQC algorithm, large-scale card replacement increases operating costs, and existing users who do not replace their cards cannot solve the problem of resisting quantum attacks under SUPI protection.
[0007] In a first aspect, embodiments of this application provide a method for protecting user identifiers in a communication network, applied to a mobile device (ME) in a user equipment (UE), the method comprising: Receive SUCI sent by the Universal User Identity Module (USIM) in the UE; If the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM, the highest priority target SUPI protection scheme that the ME can support is selected based on the first SUCI calculation information. Based on the target SUPI protection scheme, the SUCI is processed a second time to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI; The new SUCI is sent to the home network element.
[0008] In one embodiment, the secondary processing of the SUCI based on the target SUPI protection scheme to obtain a new SUCI includes: If the target SUPI protection scheme is not an empty scheme, based on the target SUPI protection scheme, set the protection scheme identifier, home network element public key identifier information, temporary password data, ciphertext data and integrity digest value in the new SUCI; The new SUCI is obtained by copying the protection scheme identifier, home network element public key identifier information, and temporary password data from the SUCI to the integrity digest value in the new SUCI.
[0009] In one embodiment, setting the protection scheme identifier, home network element public key identifier information, temporary cryptographic data, ciphertext data, and integrity digest value in the new SUCI based on the target SUPI protection scheme includes: Set the protection scheme identifier in the new SUCI to the protection scheme identifier of the target SUPI protection scheme; Set the home network element public key identifier information in the new SUCI to the home network element public key identifier information used by the target SUPI protection scheme; Set the temporary password data in the scheme output field of the new SUCI to the temporary password data generated based on the target SUPI protection scheme; The ciphertext data in the output field of the new SUCI scheme is set as the encrypted ciphertext data; the encrypted ciphertext data is obtained by encrypting the ciphertext data based on the cryptographic algorithm specified by the target SUCI protection scheme; The integrity digest value in the output field of the new SUCI scheme is set to the integrity digest value after integrity protection; the integrity digest value after integrity protection is obtained by performing integrity protection on the integrity digest value based on the cryptographic algorithm specified by the target SUCI protection scheme.
[0010] In one embodiment, the step of copying the protection scheme identifier, home network element public key identifier information, and temporary cryptographic data from the SUCI to the integrity digest value in the new SUCI to obtain the new SUCI includes: The new SUCI is obtained by copying the protection scheme identifier, home network element public key identifier information, temporary cryptographic data and integrity digest value from the SUCI to the integrity digest value in the new SUCI.
[0011] In one embodiment, after receiving the SUCI sent by the Universal User Identity Module (USIM) in the UE, the method further includes: If the version of the first SUCI calculation information stored in the ME is less than or equal to the version of the second SUCI calculation information stored in the USIM, the SUCI is taken as the new SUCI.
[0012] In one embodiment, after receiving the SUCI sent by the Universal User Identity Module (USIM) in the UE, the method further includes: Send a computation information version retrieval request to the USIM; the computation information version retrieval request is used to retrieve the version of the second SUCI computation information stored in the USIM; If the USIM does not return a response regarding the version of the computational information, it is determined that the version of the second SUCI computational information stored in the USIM is empty or 0.
[0013] In one embodiment, the SUCI sent by the USIM is sent to the ME when the USIM instructs the ME to calculate the SUCI; when the USIM instructs the ME to calculate the SUCI, the method further includes: If the ME stores the second SUCI calculation information stored in the USIM, the latest version of the SUCI calculation information is selected from the first SUCI calculation information stored in the ME and the second SUCI calculation information stored in the USIM and saved locally. Based on the latest version of SUCI calculation information, select the new SUPI protection scheme with the highest priority that ME can support; SUCI is calculated based on the new SUPI protection scheme and the public key of the home network element used by the new SUPI protection scheme.
[0014] Secondly, embodiments of this application provide a method for protecting user identifiers in a communication network, applied to a home network element, the method comprising: Receive SUCI sent by ME; wherein, the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. Based on the cryptographic algorithm specified by the target SUPI protection scheme, the ciphertext data in the SUCI is decrypted to obtain decrypted data; When the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI, the decrypted data is processed again to obtain SUPI.
[0015] In one embodiment, the secondary processing of the decrypted data to obtain SUPI includes: From the integrity digest value field in the scheme output field of the SUCI, obtain the SUPI protection scheme identifier, home network element public key identifier information, and temporary password data determined based on the initial SUPI protection scheme; the initial SUPI protection scheme is the highest priority SUPI protection scheme that USIM can support, selected based on the second SUCI calculation information. The decryption data is decrypted using the cryptographic algorithm specified in the initial SUPI protection scheme, the private key corresponding to the initial SUPI protection scheme, and the temporary cryptographic data to obtain SUPI.
[0016] In one embodiment, decrypting the decrypted data to obtain SUPI includes: Obtain the integrity digest value determined based on the initial SUPI protection scheme from the integrity digest value field in the scheme output field of the SUCI. If the validity of the integrity digest value is verified, the decrypted data is decrypted to obtain SUPI.
[0017] In one embodiment, after decrypting the ciphertext data in the SUCI based on the cryptographic algorithm specified by the target SUPI protection scheme to obtain decrypted data, and if the protection scheme identifier value indicates that the SUCI does not require secondary processing, the method further includes: Based on the decrypted data, SUPI is obtained.
[0018] Thirdly, embodiments of this application provide a communication network user identity protection device, applied to a mobile device (ME) in a user equipment (UE), comprising: The receiving module is used to receive the SUCI sent by the Universal User Identity Module (USIM) in the UE. The selection module is used to select the highest priority target SUPI protection scheme that the ME can support based on the first SUCI calculation information when the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM. A secondary processing module is used to perform secondary processing on the SUCI based on the target SUPI protection scheme to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, and the value of the protection scheme identifier is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI. The sending module is used to send the new SUCI to the home network element.
[0019] Fourthly, embodiments of this application provide a communication network user identifier protection device, applied to a home network element, comprising: The SUCI receiving module is used to receive SUCI sent by the ME; wherein, the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. The decryption module is used to decrypt the ciphertext data in the SUCI based on the cryptographic algorithm specified by the target SUPI protection scheme to obtain decrypted data; The user identifier acquisition module is used to perform secondary processing on the decrypted data to obtain SUPI when the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI.
[0020] Fifthly, embodiments of this application provide an electronic device, including a processor and a memory storing a computer program, wherein the processor executes the program to implement the steps of the communication network user identifier protection method described in the first or second aspect.
[0021] In a sixth aspect, embodiments of this application provide a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the communication network user identifier protection method described in the first or second aspect.
[0022] In a seventh aspect, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the communication network user identifier protection method described in the first or second aspect.
[0023] The communication network user identifier protection method, apparatus, device, medium, and product provided in this application embodiment, by having the ME select the highest priority target SUPI protection scheme supported by the ME based on the latest version of the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM, and then performing secondary processing on the SUCI based on the target SUPI protection scheme to obtain a new SUCI, fully utilizes the high computing and storage capabilities of the ME. The ME selects the latest SUCI calculation information to support changes in the network-side cryptographic policy, realizing SUPI protection for existing users without changing their cards, which is beneficial to improving the security of SUPI protection against quantum attacks. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is one of the flowcharts illustrating the communication network user identifier protection method provided in the embodiments of this application.
[0026] Figure 2 This is a schematic diagram illustrating the construction and definition of the protection scheme identifier in the new SUCI provided in this application embodiment.
[0027] Figure 3 This is a flowchart of the SUCI terminal side construction process that supports secondary processing, provided in the embodiments of this application.
[0028] Figure 4 This is the second flowchart illustrating the communication network user identifier protection method provided in the embodiments of this application.
[0029] Figure 5 This is a flowchart of the SUCI network-side decryption process that supports secondary processing, provided in an embodiment of this application.
[0030] Figure 6 This is a flowchart of the user identity submission process that supports secondary processing, provided in an embodiment of this application.
[0031] Figure 7 This is one of the structural schematic diagrams of the communication network user identification protection device provided in the embodiments of this application.
[0032] Figure 8 This is the second schematic diagram of the communication network user identification protection device provided in the embodiments of this application.
[0033] Figure 9 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0034] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0035] With the rapid development of quantum computing technology, traditional public-key cryptosystems, represented by ECC and RSA, face fundamental security threats. The mathematical problems they rely on, such as discrete logarithms and large integer factorization, can be efficiently solved by quantum algorithms, rendering existing encryption mechanisms unable to resist quantum attacks. To address this, the National Institute of Standards and Technology (NIST) has released ML-KEM as the standard algorithm for post-quantum cryptography (PQC). However, because ML-KEM was proposed relatively recently, its security has not yet been verified through long-term practical application. Therefore, during the transition period, a situation may arise where traditional cryptographic algorithms and post-quantum cryptographic algorithms coexist.
[0036] From a global perspective, countries are accelerating the development of localized PQC algorithms, potentially leading to regionally specific PQC cryptographic algorithms. In terms of industry applications, some operators or dedicated communication networks may adopt customized encryption algorithms for specific security needs. Therefore, future networks, represented by 6G, will face a complex scenario where multiple algorithms coexist, including traditional algorithms (ECC), international PQC algorithms (ML-KEM), domestic PQC algorithms, and industry-specific algorithms. This multi-algorithm coexistence places higher demands on the algorithm compatibility of communication equipment, the uniformity of key management, and the flexibility of security protocols.
[0037] However, existing technologies mainly have the following problems: 1) Incapable of resisting quantum attacks. The current 5G SUCI format and ECIES protection mechanism are based on elliptic curve cryptography (ECC) algorithms (such as Profile A / B), which cannot resist quantum computing attacks.
[0038] 2) Upgrading the USIM card is required to support the PQC algorithm. To counter quantum computing attacks, some technical solutions introduce post-quantum cryptography (PQC), replacing ECC encryption in ECIES with PQC KEM (a PQC-based key encapsulation mechanism) to resist quantum computing attacks. Due to the limited computing power of USIM cards, efficient cryptographic operations cannot be provided through software upgrades. Upgrading the USIM hardware to support the PQC algorithm requires adding processors for PQC calculations. Furthermore, USIM storage space is limited. SUCI calculation information files need to store the protection scheme and corresponding public key information. Compared to traditional public-key cryptography algorithms, the PQC algorithm's public key is relatively large. Therefore, upgrading the USIM hardware to support the PQC algorithm also requires increasing storage space. Thus, large-scale card replacement will increase operating costs.
[0039] 3) Existing users who do not upgrade their USIM cards cannot resolve the quantum attack resistance issue of SUPI protection. Since the USIM card merely stores the user's identifier, it is unlikely to be actively replaced with a new card supporting PQC for an extended period. Therefore, a large number of old USIM cards that have not been upgraded to support PQC exist in the network, including USIM cards that do not support SUCI encryption and those that do not support PQC encryption. For these existing users, even if the network-side HN requires SUPI protection supporting PQC, the USIM card cannot support SUPI protection based on the PQC algorithm.
[0040] 4) Even after the algorithm is cracked, there is still a possibility of needing to replace the card again. Since the PQC algorithm is relatively new and has not undergone long-term attack testing, if a user replaces their USIM card with one that supports a certain PQC algorithm, and that PQC algorithm is cracked, the USIM card will need to be replaced with a new one that supports the new PQC algorithm, which is costly.
[0041] 5) Existing technologies primarily rely on the computational and storage capabilities of the USIM, failing to fully utilize the computational and storage capabilities of the ME. Compared to the USIM, the ME offers superior performance, and its cryptographic module supports software upgrades. From a user perspective, the ME is updated more frequently than the USIM. Existing technologies fail to fully leverage the ME's capabilities to support changes in SUPI-protected algorithms.
[0042] To address the aforementioned issues, this application addresses the problem by having the ME select the highest priority target SUPI protection scheme it supports based on the latest version of the first SUCI calculation information when the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM. The ME then performs secondary processing on the SUCI based on the target SUPI protection scheme to update it and obtain a new SUCI. This fully utilizes the ME's high computing and storage capabilities. The ME selects the latest SUCI calculation information to support changes in network-side cryptographic policies, which helps improve the security of SUPI protection against quantum attacks. Furthermore, for existing users, the ME can perform SUPI protection based on locally stored SUCI calculation information, thus effectively responding to quantum computing attacks without requiring card replacement.
[0043] Figure 1 This is one of the flowcharts illustrating the communication network user identifier protection method provided in this application embodiment. (Refer to...) Figure 1 This application provides a method for protecting user identifiers in a communication network, which may specifically include the following steps: Step 101: Receive the SUCI sent by the Universal User Identity Module (USIM) in the UE.
[0044] It should be noted that the implementing entity of the communication network user identifier protection method provided in this application embodiment can be the mobile device ME in the user equipment ME. The user equipment involved in this application embodiment can be a device that provides voice and / or data connectivity to the user, a handheld device with wireless connection function, or other processing devices connected to a wireless modem, etc.
[0045] It should be noted that the embodiments of this application are applicable not only to 5G communication networks, but also to future communication networks such as 6G, and this application makes no limitation herein. The following embodiments of this application use a 5G communication network as an example for illustration.
[0046] In this embodiment of the application, when the network side requires the user equipment (UE) to send a user identity identifier for network authentication, the ME in the user equipment (UE) can read the SUCI generation policy from the USIM card.
[0047] In some embodiments, when the USIM instructs the USIM to calculate the SUCI, the ME can invoke the GET IDENTITY command to retrieve the SUCI calculated by the USIM. After receiving the GET IDENTITY command, the USIM can select the highest priority SUPI protection scheme it supports (such as using the ECIES mechanism) to calculate the SUCI based on the SUCI calculation information stored locally, and return the calculated SUCI to the ME. The ME can then receive the SUCI calculated by the USIM sent by the USIM.
[0048] Step 102: If the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM, select the highest priority target SUPI protection scheme that the ME can support based on the first SUCI calculation information.
[0049] In this embodiment, the ME can check whether it locally stores the SUCI calculation information of the current USIM. If the ME does not locally store the SUCI calculation information of the current USIM, it indicates that the ME has never obtained the SUCI calculation information of the current USIM, and the ME can use the SUCI generated by the USIM received from the USIM as the newly generated SUCI. If the ME locally stores the SUCI calculation information of the current USIM, it can determine the size relationship between the version of the first SUCI calculation information stored locally by the ME and the version of the first SUCI calculation information of the USIM.
[0050] In some embodiments, if the version of the first SUCI calculation information stored locally by the ME is greater than the version of the second SUCI calculation information stored locally by the USIM, it indicates that the first SUCI calculation information stored locally by the ME is the latest version of the SUCI calculation information. In this case, the ME can select the highest priority target SUPI protection scheme that it supports based on the first SUCI calculation information, thereby performing secondary processing on the SUCI generated by the USIM through the target SUPI protection scheme.
[0051] It should be noted that for existing users who do not change their cards, the version of the second SUCI calculation information stored in the USIM can be 0 or empty. In this case, by comparing the size relationship of the SUCI calculation information versions, it can be determined that the first SUCI calculation information stored locally by the ME is the latest version of the SUCI calculation information, which can then be used for SUPI protection.
[0052] Step 103: Based on the target SUPI protection scheme, perform secondary processing on the SUCI to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, and the value of the protection scheme identifier is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI.
[0053] In this embodiment, the USIM can select the highest priority initial SUPI protection scheme it supports based on the locally stored first SUCI calculation information, thereby encrypting and protecting the SUPI based on the cryptographic algorithm indicated by the initial SUPI protection scheme, generating the SUCI and sending it to the ME.
[0054] In some embodiments, if the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM, it indicates that the first SUCI calculation information stored locally by the ME is the latest version of the SUCI calculation information, and the ME needs to perform secondary processing on the SUCI generated by the USIM calculation. Specifically, after selecting the highest priority target SUPI protection scheme that the ME can support based on the latest version of the SUCI calculation information, the ME can update the protection scheme identifier, home network element public key identifier information, temporary cipher data, ciphertext data, and integrity digest value in the new SUCI based on the target SUPI protection scheme to generate a new SUCI.
[0055] Figure 2 This is a schematic diagram illustrating the construction and definition of the protection scheme identifier in the new SUCI provided in this application embodiment. (Refer to...) Figure 2 In some embodiments, the protection scheme identifier of the new SUCI may include multiple flag bits. The value of the highest flag bit can be used to indicate whether the home network element needs to perform secondary processing when decrypting the current SUCI. When the value of the highest flag bit is 0, it can indicate that the home network element needs to perform secondary processing when decrypting the current SUCI; when the value of the highest flag bit is 0, it can indicate that the home network element does not need to perform secondary processing when decrypting the current SUCI.
[0056] Each of the other flag bits in the protection scheme identifier can correspond to a specific cryptographic algorithm scheme from a predefined set of cryptographic algorithms. The value of each other flag bit can be used to indicate whether the cryptographic algorithm scheme corresponding to that flag bit is selected. Different flag bits can correspond to different cryptographic algorithm schemes. In the embodiments of this application, the value of each flag bit except the highest bit in the protection scheme identifier of the new SUCI can be determined based on one or more cryptographic algorithms specified by the target SUPI protection scheme.
[0057] Step 104: Send the new SUCI to the home network element.
[0058] In some embodiments, the ME can send the generated new SUCI to the home network element HN via an Initial Registration Request. After receiving the SUCI sent by the UE, the home network element HN can decrypt it to obtain the final SUPI.
[0059] This embodiment of the application, when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM, allows the ME to select the highest priority target SUPI protection scheme supported by the ME based on the latest version of the first SUCI calculation information, and to perform secondary processing on the SUCI based on the target SUPI protection scheme to obtain a new SUCI. This fully utilizes the high computing and storage capabilities of the ME, and the ME selects the latest SUCI calculation information to support changes in the network-side cryptographic policy, thus achieving SUPI protection for existing users without changing their cards, which is beneficial to improving the security of SUPI protection against quantum attacks.
[0060] Based on any of the above embodiments, the step of performing secondary processing on the SUCI based on the target SUPI protection scheme to obtain a new SUCI includes: If the target SUPI protection scheme is not an empty scheme, based on the target SUPI protection scheme, set the protection scheme identifier, home network element public key identifier information, temporary password data, ciphertext data and integrity digest value in the new SUCI; The new SUCI is obtained by copying the protection scheme identifier, home network element public key identifier information, and temporary password data from the SUCI to the integrity digest value in the new SUCI.
[0061] In this embodiment of the application, during the process of the ME selecting the highest priority target SUPI protection scheme that it can support based on the locally stored SUCI calculation information, if the target SUPI protection scheme selected by the ME is a null-scheme, then the ME does not need to perform secondary processing on the SUCI generated by the USIM and sent to the ME, and the ME can use the SUCI as a new SUCI.
[0062] In this embodiment of the application, if the target SUPI protection scheme selected by the ME is not a null scheme, the step of performing secondary processing on the SUCI based on the target SUPI protection scheme to obtain a new SUCI can continue.
[0063] Figure 3This is a flowchart illustrating the SUCI terminal-side construction process supporting secondary processing, as provided in an embodiment of this application. (Refer to...) Figure 3 In some embodiments, if the protection scheme identifier (i.e., the protection scheme ID field) in the SUCI sent by the USIM to the ME is not a null scheme, then based on the target SUPI protection scheme, the protection scheme identifier, home network element public key identifier information, temporary cipher data, ciphertext data, and integrity digest value in the new SUCI can be set. The protection scheme identifier, home network element public key identifier information, and temporary cipher data in the SUCI sent by the USIM to the ME can be copied to the integrity digest value in the new SUCI, thereby generating a new SUCI after secondary processing.
[0064] In some embodiments, if the SUPI protection scheme ID field in the original SUCI sent by the USIM to the ME is a null-scheme, the ME can obtain the plaintext SUPI from the SUCI and calculate a new SUCI using the cryptographic algorithm specified by the selected target SUPI protection scheme (such as using the ECIES mechanism).
[0065] This application embodiment selects a target SUPI protection scheme based on the latest SUCI computation information stored locally on the ME, and sets the protection scheme identifier, home network element public key identifier information, temporary cryptographic data, ciphertext data and integrity digest value in the new SUCI. This can update the SUPI protection strategy to the latest cryptographic protection strategy in a timely manner, which is beneficial to improving the security of SUPI protection against quantum attacks.
[0066] Based on any of the above embodiments, the step of setting the protection scheme identifier, home network element public key identifier information, temporary cipher data, ciphertext data, and integrity digest value in the new SUCI based on the target SUPI protection scheme includes: Set the protection scheme identifier in the new SUCI to the protection scheme identifier of the target SUPI protection scheme; Set the home network element public key identifier information in the new SUCI to the home network element public key identifier information used by the target SUPI protection scheme; Set the temporary password data in the scheme output field of the new SUCI to the temporary password data generated based on the target SUPI protection scheme; The ciphertext data in the output field of the new SUCI scheme is set as the encrypted ciphertext data; the encrypted ciphertext data is obtained by encrypting the ciphertext data based on the cryptographic algorithm specified by the target SUCI protection scheme; The integrity digest value in the output field of the new SUCI scheme is set to the integrity digest value after integrity protection; the integrity digest value after integrity protection is obtained by performing integrity protection on the integrity digest value based on the cryptographic algorithm specified by the target SUCI protection scheme.
[0067] In this embodiment of the application, if the target SUPI protection scheme selected by the ME is not a null scheme, a new SUCI can be obtained by performing secondary processing on the SUCI based on the target SUPI protection scheme.
[0068] Please continue to refer to Figure 3 In some embodiments, the ME may use the cryptographic algorithm specified by its chosen target SUPI protection scheme (such as the ECIES mechanism) to encrypt the ciphertext field (i.e., the ciphertext data field) in the SUCI generated by the USIM and sent to the ME, and the ME may calculate the encrypted value ciphertext2 and the digest value MAC-Tag2.
[0069] In some embodiments, the protection scheme ID field of the new SUCI can be set to the target SUPI protection scheme ID selected by the ME, and the highest bit can be set to 1, indicating that the home network element needs to perform secondary processing when decrypting the current SUCI.
[0070] In some embodiments, the HN public key ID field of the new SUCI can be set to the public key identification information of the home network element used when the ME is encrypted using the target SUPI protection scheme.
[0071] In some embodiments, the first part of the scheme output field of the new SUCI can be set to Ephermeral Cryptography Data (ECD) generated during encryption. For example, if the ECC algorithm is used, this part is the generated temporary public key; if the PQC KEM algorithm is used, this part is the encrypted and encapsulated temporary key generated during the PQC KEM calculation process.
[0072] In some embodiments, the ciphertext portion (i.e., ciphertext data) in the scheme output field of a new SUCI can be set to ciphertext2.
[0073] In some embodiments, the MAC-Tag portion of the scheme output field of a new SUCI can be set to MAC-Tag2.
[0074] This application embodiment selects a target SUPI protection scheme based on the latest SUCI computation information stored locally on the ME, and sets the protection scheme identifier, home network element public key identifier information, temporary cryptographic data, ciphertext data and integrity digest value in the new SUCI. This can update the SUPI protection strategy to the latest cryptographic protection strategy in a timely manner, which is beneficial to improving the security of SUPI protection against quantum attacks.
[0075] Based on any of the above embodiments, the step of copying the protection scheme identifier, home network element public key identifier information, and temporary cryptographic data from the SUCI to the updated integrity digest value to obtain a new SUCI includes: The protection scheme identifier, home network element public key identifier information, temporary cryptographic data, and integrity digest value in the SUCI are copied to the updated integrity digest value to obtain the new SUCI.
[0076] In some embodiments, after setting the MAC-Tag portion (i.e. the integrity digest value field) in the scheme output field of the new SUCI to MAC-Tag2, the SUPI protection scheme ID, HN public key ID, temporary cryptographic data, and MAC-Tag in the original SUCI calculated and sent to the ME by the USIM can be copied to MAC-Tag2.
[0077] This application embodiment copies the integrity digest value MAC-Tag from the original SUCI, which is calculated and generated by the USIM and sent to the ME, to the MAC-Tag2 of the new SUCI. This facilitates integrity verification during subsequent decryption and further improves security.
[0078] Based on any of the above embodiments, after receiving the SUCI sent by the Universal User Identity Module (USIM) in the UE, the method further includes: If the version of the first SUCI calculation information stored in the ME is less than or equal to the version of the second SUCI calculation information stored in the USIM, the SUCI is taken as the new SUCI.
[0079] In some embodiments, after the ME receives the SUCI generated and returned by the USIM, the ME can check whether it has stored the SUCI calculation information of the current USIM locally and generate a new SUCI. If the local SUCI calculation information version is less than or equal to the USIM's SUCI calculation information version, the ME does not need to perform secondary processing on the SUCI generated and returned by the USIM, and the ME can use the SUCI as the newly generated SUCI.
[0080] This application embodiment ensures that the latest cryptographic protection strategy is used for SUPI protection by sending the SUCI generated and returned by the USIM as the new SUCI to the home network element when the version of the SUCI calculation information stored in the ME is less than or equal to the version of the SUCI calculation information stored in the USIM. This is beneficial to improving the security of SUPI protection against quantum attacks.
[0081] Based on any of the above embodiments, after receiving the SUCI sent by the Universal User Identity Module (USIM) in the UE, the method further includes: Send a computation information version retrieval request to the USIM; the computation information version retrieval request is used to retrieve the version of the second SUCI computation information stored in the USIM; If the USIM does not return a response regarding the version of the computational information, it is determined that the version of the second SUCI computational information stored in the USIM is empty or 0.
[0082] In some embodiments, after the ME receives the SUCI generated and returned by the USIM, the ME can first send a computation information version retrieval request to the USIM to obtain the SUCI computation information version stored locally by the USIM. If the USIM does not have this instruction (e.g., the existing USIM will not return a computation information version response), it can be determined that the USIM's SUCI computation information version is empty or 0, and then the ME can further check whether it has stored the current USIM's SUCI computation information locally, and generate a new SUCI.
[0083] It should be noted that for existing USIMs, since the SUCI calculation information version of the USIM is empty or 0 at this time, if the ME locally stores the SUCI calculation information of the current USIM, the SUCI calculation information stored locally by the ME must be the latest SUCI calculation information.
[0084] This application embodiment obtains the version of the SUCI computation information stored in the USIM by sending a computation information version acquisition request to the USIM. If the USIM does not return a computation information version response, it is determined that the version of the SUCI computation information stored in the USIM is empty or 0. This facilitates the ME to select the latest SUCI computation information to support changes in the network-side cryptographic policy, thereby achieving SUPI protection for existing users who do not change their cards and improving the security of SUPI protection against quantum attacks.
[0085] Based on any of the above embodiments, the SUCI sent by the USIM is sent to the ME when the USIM instructs the ME to calculate the SUCI; when the USIM instructs the ME to calculate the SUCI, the method further includes: If the ME stores the second SUCI calculation information stored in the USIM, the latest version of the SUCI calculation information is selected from the first SUCI calculation information stored in the ME and the second SUCI calculation information stored in the USIM and saved locally. Based on the latest version of SUCI calculation information, select the new SUPI protection scheme with the highest priority that ME can support; SUCI is calculated based on the new SUPI protection scheme and the public key of the home network element used by the new SUPI protection scheme.
[0086] In this embodiment, when the network side requires the UE to send an identity identifier for network authentication, the ME can read the SUCI generation policy from the USIM card. If the USIM indicates that the ME should calculate the SUCI, the ME can obtain SUCI calculation-related information from the USIM, including SUPI, home network identifier, routing indication, SUCI calculation information, and SUCI calculation information version.
[0087] In some embodiments, the ME can check whether it has locally stored the SUCI calculation information for the current USIM. If the ME does not have the SUCI calculation information for the current USIM stored locally, it means that the ME has never obtained the SUCI calculation information for the current USIM, and the ME can save the SUCI calculation-related information obtained from the USIM locally. If the ME has the SUCI calculation information for the current USIM stored locally, it means that the ME has stored the SUCI calculation information for the current USIM locally, and the ME can compare the version of the SUCI calculation information stored by the ME with the version of the SUCI calculation information obtained from the USIM to obtain the latest version of the SUCI calculation information, and save it locally.
[0088] It should be noted that if the SUCI calculation information does not contain version information (such as existing USIM cards), it is considered to be an older version.
[0089] In this embodiment, the ME can select the highest priority target SUPI protection scheme it can support to calculate SUCI based on the locally stored SUCI protection information (such as using the ECIES mechanism).
[0090] In this embodiment, the ME compares the SUCI calculation information stored in the ME with the version of the SUCI calculation information obtained from the USIM to obtain the latest version of the SUCI calculation information, and saves it locally. This allows the ME to select the latest SUCI calculation information to support changes in the network-side cryptographic policy, thereby achieving SUPI protection for existing users without changing their cards and improving the security of SUPI protection against quantum attacks.
[0091] Figure 4This is the second flowchart illustrating the communication network user identifier protection method provided in this application embodiment. (Refer to...) Figure 4 This application provides a method for protecting user identifiers in a communication network, which may specifically include the following steps: Step 401: Receive the SUCI sent by the ME; wherein the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information, when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. Step 402: Based on the cryptographic algorithm specified by the target SUPI protection scheme, decrypt the ciphertext data in the SUCI to obtain decrypted data; Step 403: If the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI, the decrypted data is processed again to obtain SUPI.
[0092] It should be noted that the implementing entity of the communication network user identifier protection method provided in this application embodiment can be a home network element, such as a UDM / ARPF (Unified Data Management / Authentication Credential Repository and Processing Function) network element.
[0093] It should be noted that the embodiments of this application are applicable not only to 5G communication networks, but also to future communication networks such as 6G, and this application makes no limitation herein. The following embodiments of this application use a 5G communication network as an example for illustration.
[0094] In some embodiments, if the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM, it indicates that the first SUCI calculation information stored locally by the ME is the latest version of the SUCI calculation information, and the ME needs to perform secondary processing on the SUCI generated by the USIM calculation. Specifically, after selecting the highest priority target SUPI protection scheme that the ME can support based on the latest version of the SUCI calculation information, the ME can update the protection scheme identifier, home network element public key identifier information, temporary password data, ciphertext data, and integrity digest value in the new SUCI based on the target SUPI protection scheme, generate a new SUCI, and send it to the home network element.
[0095] In some embodiments, the protection scheme identifier of the new SUCI may include multiple flag bits. The value of the highest-order flag bit can be used to indicate whether the home network element needs to perform secondary processing when decrypting the current SUCI. When the value of the highest-order flag bit is 0, it can indicate that the home network element needs to perform secondary processing when decrypting the current SUCI; when the value of the highest-order flag bit is 0, it can indicate that the home network element does not need to perform secondary processing when decrypting the current SUCI. Each of the other flag bits in the protection scheme identifier can correspond to a specific cryptographic algorithm scheme in a predefined set of cryptographic algorithms. The value of each of the other flag bits can be used to indicate whether to select the cryptographic algorithm scheme corresponding to that flag bit. Different flag bits can correspond to different cryptographic algorithm schemes. In the embodiments of this application, the ME can determine the value of each flag bit other than the highest-order bit in the protection scheme identifier of the new SUCI based on one or more cryptographic algorithms specified by the target SUCI protection scheme.
[0096] In some embodiments, after receiving the SUCI sent by the UE, the HN network element can sequentially obtain the temporary cipher data ECD2 from the target SUPI protection scheme ID, the home network element public key ID2 field, and the scheme output field (Schemeoutput) of the SUCI. Based on the cryptographic algorithm specified by the target SUPI protection scheme and the corresponding private key, the ciphertext2 in the scheme output field of the SUCI is decrypted to obtain the decrypted data plaintext2.
[0097] In some embodiments, when the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI, for example, when the value of the highest bit flag of the SUPI protection scheme identifier in SUCI is 1, the decrypted data plaintext2 can be processed to obtain plaintext1, and SUPI can be obtained from the decrypted plaintext1.
[0098] In this embodiment, HN can generate an authentication vector AV based on the decrypted SUPI to complete AKA bidirectional authentication, and the UE and the network side can establish a data connection.
[0099] In this embodiment of the application, the ME can periodically or as needed obtain the latest SUCI calculation strategy information from the SUCI calculation information acquisition service provided by the home network HN, save it locally, and establish a correspondence with the current USIM.
[0100] This embodiment of the application, when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM, allows the ME to select the highest priority target SUPI protection scheme supported by the ME based on the latest version of the first SUCI calculation information, and to update the SUCI by secondary processing based on the target SUPI protection scheme to obtain a new SUCI. The home network element then decrypts the new SUCI to obtain the SUPI. This fully utilizes the high computing and storage capabilities of the ME, and the ME selects the latest SUCI calculation information to support changes in the network-side cryptographic policy, thus achieving SUPI protection for existing users without changing their SIM cards. This is beneficial for improving the security of SUPI protection against quantum attacks.
[0101] Based on any of the above embodiments, the secondary processing of the decrypted data to obtain SUPI includes: From the integrity digest value field in the scheme output field of the SUCI, obtain the SUPI protection scheme identifier, home network element public key identifier information, and temporary password data determined based on the initial SUPI protection scheme; the initial SUPI protection scheme is the highest priority SUPI protection scheme that USIM can support, selected based on the second SUCI calculation information. The decryption data is decrypted using the cryptographic algorithm specified in the initial SUPI protection scheme, the private key corresponding to the initial SUPI protection scheme, and the temporary cryptographic data to obtain SUPI.
[0102] Figure 5 This is a flowchart of the SUCI network-side decryption process supporting secondary processing, provided in an embodiment of this application. (Refer to...) Figure 5In some embodiments, the home network element can sequentially obtain the temporary cipher data ECD2 from the protection scheme ID2, HN public key ID2 field and scheme output field of the SUCI sent by the ME, and use the cryptographic algorithm specified in the protection scheme corresponding to the protection scheme ID2 (i.e. the initial SUPI protection scheme) and the corresponding private key decryption scheme output field ciphertext2 to obtain the decrypted data plaintext2.
[0103] This application embodiment performs secondary processing on the SUCI sent by the ME through the home network element, which can decrypt the original user identity identifier SUPI information. It makes full use of the ME's high computing and storage capabilities, realizes SUPI protection for existing users without changing cards, and helps to improve the security of SUPI protection against quantum attacks.
[0104] Based on any of the above embodiments, the step of decrypting the decrypted data to obtain SUPI includes: Obtain the integrity digest value determined based on the initial SUPI protection scheme from the integrity digest value field in the scheme output field of the SUCI. If the validity of the integrity digest value is verified, the decrypted data is decrypted to obtain SUPI.
[0105] In some embodiments, the home network element can also obtain the integrity digest value MAC-Tag1 determined based on the initial SUPI protection scheme from the integrity digest value field MAC-Tag2 in the scheme output field of SUCI, and verify the legality of MAC-Tag1 (integrity verification). If the legality verification of the integrity digest value MAC-Tag1 is successful, the home network element can further decrypt the decrypted data plaintext2 to obtain the user identity identifier SUPI.
[0106] In this embodiment of the application, the integrity digest value MAC-Tag1 determined based on the initial SUPI protection scheme is verified by the home network element, thereby verifying the legitimacy of the SUCI sent by the ME, avoiding the problem of tampering with the transmitted information, and improving the security of SUPI protection against quantum attacks.
[0107] Based on any of the above embodiments, after decrypting the ciphertext data in the SUCI using the cryptographic algorithm specified by the target SUPI protection scheme to obtain decrypted data, and when the protection scheme identifier value indicates that the SUCI does not require secondary processing, the method further includes: Based on the decrypted data, SUPI is obtained.
[0108] In some embodiments, if the value of the protection scheme identifier indicates that no secondary processing is required when decrypting the SUCI, for example, if the value of the highest bit flag of the SUPI protection scheme identifier in the SUCI is 0, then no secondary processing is performed, and the SUPI can be obtained from the decrypted data plaintext2.
[0109] To better understand the embodiments of this application, the following specific embodiment will be used to illustrate the embodiments of this application.
[0110] Figure 6 This is a flowchart illustrating the user identity submission process that supports secondary processing, as provided in an embodiment of this application. (Refer to...) Figure 6 In one specific embodiment, the user identity submission process may include the following steps: Step 1: When the network side requires the UE to send its identity identifier for network authentication, the ME reads the SUCI generation policy from the USIM card: Step 1.1, USIM indicates that SUCI is calculated by ME: Step 1.1.1: ME obtains SUCI calculation-related information from USIM, including SUPI, home network identifier, routing indication, SUCI calculation information, and SUCI calculation information version.
[0111] Step 1.1.2: ME checks whether the SUCI calculation information for the current USIM is stored locally. Step 1.1.2.1: If not, it means that this ME has never obtained the SUCI calculation information of the current USIM. In this case, the ME will save the SUCI calculation related information obtained from the USIM to the local machine.
[0112] Step 1.1.2.2: If present, it means that the ME has stored the current USIM's SUCI calculation information locally. The ME then compares the SUCI calculation information stored by itself with the version of the SUCI calculation information obtained from the USIM to obtain the latest version of the SUCI calculation information and saves it locally. Note: If the SUCI calculation information does not contain version information (such as for existing USIM cards), it is considered to be an older version.
[0113] Step 1.1.3: The ME selects the highest priority protection scheme it supports based on the locally stored SUCI protection information to calculate the SUCI (e.g., using the ECIES mechanism): Step 1.2, USIM indicates that SUCI is calculated by USIM: Step 1.2.1: The ME calls the GET IDENTITY command to obtain the SUCI from the USIM. The USIM selects the highest priority protection scheme it supports based on the SUCI protection information stored locally to calculate the SUCI (such as using the ECIES mechanism), and returns the SUCI to the ME.
[0114] Step 1.2.2: ME obtains the SUCI calculation information version of the USIM. If the USIM does not have this instruction (such as the existing USIM), the SUCI calculation information version of the USIM will be empty or 0.
[0115] Step 1.2.3: ME checks whether the current USIM's SUCI calculation information is saved locally and generates a new SUCI: Step 1.2.3.1: If not, it means that this ME has never obtained the SUCI calculation information of the current USIM, then the ME will use this SUCI as the newly generated SUCI.
[0116] Step 1.2.3.2: If so, it means that ME has stored the current USIM's SUCI calculation information locally. Then, determine the version of the local SUCI calculation information and the version of the USIM's SUCI calculation information: Step 1.2.3.2.1: If the local SUCI calculation information version is less than or equal to the USIM SUCI calculation information version, then ME does not need to perform secondary processing on the SUCI, and ME will use the SUCI as the newly generated SUCI.
[0117] Step 1.2.3.2.2: If the local SUCI calculation information version is greater than the USIM SUCI calculation information version, then ME will perform secondary processing on the SUCI: Step 1.2.3.2.2.1: ME selects the highest priority protection scheme it can support based on the local SUCI protection information.
[0118] 1) If the protection scheme selected by the ME is the null scheme, then the ME does not need to perform secondary processing on the SUCI, and the ME will use the SUCI as the newly generated SUCI.
[0119] 2) If the protection scheme selected by ME is not a null scheme, proceed to the next step.
[0120] Step 1.2.3.2.2.2: If the protection scheme Id field of the SUCI returned by USIM is not a null scheme, then a new SUCI after secondary processing is generated. 1) ME uses the cryptographic algorithm specified by its chosen protection scheme (such as the ECIES mechanism) to encrypt the ciphertext field in SUCI, and calculates the encrypted value ciphertext2 and the digest value MAC-Tag2.
[0121] 2) Set the new protection scheme Id field to the protection scheme Id selected by ME, and set the highest bit to 1, indicating that secondary processing is required.
[0122] 3) Set the new HN public key Id field to the HN public key Id used during ME encryption.
[0123] 4) Set the first part of the new scheme output field to Ephermeral Cryptography Data (ECD) generated during encryption. For example, if the ECC algorithm is used, this part is the generated temporary public key; if the PQC KEM algorithm is used, this part is the encrypted and encapsulated temporary key generated during the PQC KEM calculation process.
[0124] 5) Set the ciphertext part of the new Scheme output field to ciphertext2.
[0125] 6) Set the MAC-Tag part of the new Scheme output field to MAC-Tag2.
[0126] 7) Copy the protection scheme ID, HN public key ID, temporary password data, and MAC-Tag (optional) from the original SUCI to MAC-Tag2.
[0127] Step 1.2.3.2.2.3: If the protection scheme Id field of the SUCI returned by USIM is a null scheme, then ME obtains the plaintext SUPI from the SUCI and calculates the new SUCI using the cryptographic algorithm specified by the selected protection scheme (such as using the ECIES mechanism).
[0128] Step 2: ME sends the newly generated SUCI to the network side HN via an Initial Registration Request.
[0129] Step 3: After HN receives the SUCI sent by UE, it decrypts it to obtain the final SUPI: Step 3.1: Sequentially retrieve the temporary cipher data ECD2 from the protection scheme Id2, HN public key Id2 field, and scheme output field after the routing indication field of SUCI. Use the cryptographic algorithm specified in the protection scheme corresponding to protection scheme Id2 and the corresponding private key to decrypt ciphertext2 in the scheme output field to obtain plaintext2, and verify the legality of MAC-Tag2.
[0130] Step 3.2: Determine if the highest bit of the protection scheme Id2 in SUCI is 1: Step 3.2.1: If the value is 0, no further processing is required. SUPI can be obtained from the decrypted plaintext data plaintext2.
[0131] Step 3.2.2: If the value is 1, then secondary processing is required: Step 3.2.2.1: Obtain the temporary cryptographic data ECD1 from the protection scheme Id1, HN public key Id1 field, and scheme output field after the MAC-Tag2 field. Step 3.2.2.2: Decrypt plaintext2 obtained in the above steps using the cryptographic algorithm specified in the protection scheme corresponding to protection scheme Id1 and the corresponding private key to obtain plaintext1, and verify the legality of MAC-Tag1 (optional). SUPI can be obtained based on the decrypted plaintext1.
[0132] Step 4: HN generates the authentication vector AV based on the decrypted SUPI, completes AKA bidirectional authentication, and establishes a data connection between the UE and the network side.
[0133] Step 5: ME can periodically or as needed obtain the latest SUCI calculation strategy information from the SUCI calculation information acquisition service provided by the home network HN, save it locally, and establish a correspondence with the current USIM.
[0134] In summary, this application has the following technical advantages: 1) The SUCI structure and construction process that support secondary processing can support SUPI protection based on PQC to deal with quantum computing attacks.
[0135] 2) The high computing and storage capabilities of ME can be fully utilized, and ME can select the latest SUCI computing information on USIM or ME to support changes in cryptographic strategies on the network side, thereby improving the security of SUPI protection against quantum attacks.
[0136] 3) It can solve the SUPI protection problem of existing USIM cards (including USIM cards that do not support SUCI encryption, USIM cards that do not support PQC algorithm encryption, etc.), and after deployment, it can support the use of cards without replacement.
[0137] 4) Compared to USIM, ME has stronger performance and its cryptographic module also supports software upgrades. Even the performance of the software-implemented cryptographic module is stronger than that of the USIM card. From the user's perspective, ME is updated more frequently than USIM. Even if a certain PQC algorithm is cracked, it can be replaced with a new algorithm through ME software upgrades.
[0138] 5) The service network does not need to be modified and is unaware of the changes to the new protocol.
[0139] 6) This solution is compatible with existing 3GPP protocols. Compared with the original 3GPP AKA authentication protocol, it only requires modification of ME and UDM, without modifying other network elements and related interfaces. The modification cost is low and the compatibility with the original protocol is high.
[0140] The communication network user identification protection device provided in the embodiments of this application is described below. The communication network user identification protection device described below can be referred to in correspondence with the communication network user identification protection method described above.
[0141] Figure 7 This is one of the structural schematic diagrams of the communication network user identification protection device provided in the embodiments of this application. (Refer to...) Figure 7 This invention provides a communication network user identifier protection device, applied to a mobile device (ME) in a user equipment (UE). The device may specifically include the following modules: The receiving module 710 is used to receive the SUCI sent by the Universal User Identity Module (USIM) in the UE; Selection module 720 is used to select the highest priority target SUPI protection scheme that the ME can support based on the first SUCI calculation information when the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM. The secondary processing module 730 is used to perform secondary processing on the SUCI based on the target SUPI protection scheme to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, and the value of the protection scheme identifier is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI. The sending module is used to send the new SUCI to the home network element.
[0142] Figure 8This is a second structural schematic diagram of the communication network user identification protection device provided in the embodiments of this application. (Refer to...) Figure 8 This invention provides a communication network user identifier protection device, applied to a home network element. The device may specifically include the following modules: SUCI receiving module 810 is used to receive SUCI sent by ME; wherein, the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. The decryption module 820 is used to decrypt the ciphertext data in the SUCI based on the cryptographic algorithm specified by the target SUPI protection scheme to obtain decrypted data; The user identifier acquisition module 830 is used to perform secondary processing on the decrypted data to obtain SUPI when the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI.
[0143] Figure 9 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 9 As shown, the electronic device may include: a processor 910, a communication interface 920, a memory 930, and a communication bus 940, wherein the processor 910, the communication interface 920, and the memory 930 communicate with each other via the communication bus 940. The processor 910 can call a computer program in the memory 930 to execute steps of the communication network user identification protection method, such as including: Receive SUCI sent by the Universal User Identity Module (USIM) in the UE; If the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM, the highest priority target SUPI protection scheme that the ME can support is selected based on the first SUCI calculation information. Based on the target SUPI protection scheme, the SUCI is processed a second time to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI; Send the new SUCI to the home network element; or Receive SUCI sent by ME; wherein, the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. Based on the cryptographic algorithm specified by the target SUPI protection scheme, the ciphertext data in the SUCI is decrypted to obtain decrypted data; When the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI, the decrypted data is processed again to obtain SUPI.
[0144] Furthermore, the logical instructions in the aforementioned memory 930 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0145] On the other hand, embodiments of this application also provide a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can perform the steps of the communication network user identification protection method provided in the above embodiments, such as including: Receive SUCI sent by the Universal User Identity Module (USIM) in the UE; If the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM, the highest priority target SUPI protection scheme that the ME can support is selected based on the first SUCI calculation information. Based on the target SUPI protection scheme, the SUCI is processed a second time to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI; Send the new SUCI to the home network element; or Receive SUCI sent by ME; wherein, the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. Based on the cryptographic algorithm specified by the target SUPI protection scheme, the ciphertext data in the SUCI is decrypted to obtain decrypted data; When the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI, the decrypted data is processed again to obtain SUPI.
[0146] On the other hand, embodiments of this application also provide a processor-readable storage medium storing a computer program, the computer program being used to cause a processor to execute the steps of the communication network user identifier protection method provided in the above embodiments, for example including: Receive SUCI sent by the Universal User Identity Module (USIM) in the UE; If the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM, the highest priority target SUPI protection scheme that the ME can support is selected based on the first SUCI calculation information. Based on the target SUPI protection scheme, the SUCI is processed a second time to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI; Send the new SUCI to the home network element; or Receive SUCI sent by ME; wherein, the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. Based on the cryptographic algorithm specified by the target SUPI protection scheme, the ciphertext data in the SUCI is decrypted to obtain decrypted data; When the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI, the decrypted data is processed again to obtain SUPI.
[0147] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).
[0148] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0149] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0150] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A method for protecting user identifiers in a communication network, characterized in that, The method, applied to a mobile device ME in a user equipment (UE), includes: Receive SUCI sent by the Universal User Identity Module (USIM) in the UE; If the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM, the highest priority target SUPI protection scheme that the ME can support is selected based on the first SUCI calculation information. Based on the target SUPI protection scheme, the SUCI is processed a second time to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI; The new SUCI is sent to the home network element.
2. The communication network user identifier protection method according to claim 1, characterized in that, The process of performing secondary processing on the SUCI based on the target SUPI protection scheme to obtain a new SUCI includes: If the target SUPI protection scheme is not an empty scheme, based on the target SUPI protection scheme, set the protection scheme identifier, home network element public key identifier information, temporary password data, ciphertext data and integrity digest value in the new SUCI; The new SUCI is obtained by copying the protection scheme identifier, home network element public key identifier information, and temporary password data from the SUCI to the integrity digest value in the new SUCI.
3. The communication network user identifier protection method according to claim 2, characterized in that, The step of setting the protection scheme identifier, home network element public key identifier information, temporary cipher data, ciphertext data, and integrity digest value in the new SUCI based on the target SUPI protection scheme includes: Set the protection scheme identifier in the new SUCI to the protection scheme identifier of the target SUPI protection scheme; Set the home network element public key identifier information in the new SUCI to the home network element public key identifier information used by the target SUPI protection scheme; Set the temporary password data in the scheme output field of the new SUCI to the temporary password data generated based on the target SUPI protection scheme; The ciphertext data in the output field of the new SUCI scheme is set as the encrypted ciphertext data; the encrypted ciphertext data is obtained by encrypting the ciphertext data based on the cryptographic algorithm specified by the target SUCI protection scheme; The integrity digest value in the output field of the new SUCI scheme is set to the integrity digest value after integrity protection; the integrity digest value after integrity protection is obtained by performing integrity protection on the integrity digest value based on the cryptographic algorithm specified by the target SUCI protection scheme.
4. The communication network user identifier protection method according to claim 3, characterized in that, The process of copying the protection scheme identifier, home network element public key identifier information, and temporary cryptographic data from the SUCI to the integrity digest value in the new SUCI yields the new SUCI, which includes: The new SUCI is obtained by copying the protection scheme identifier, home network element public key identifier information, temporary cryptographic data and integrity digest value from the SUCI to the integrity digest value in the new SUCI.
5. The method for protecting user identifiers in a communication network according to claim 1, characterized in that, After receiving the SUCI sent by the Universal User Identity Module (USIM) in the UE, the following is also included: If the version of the first SUCI calculation information stored in the ME is less than or equal to the version of the second SUCI calculation information stored in the USIM, the SUCI is taken as the new SUCI.
6. The method for protecting user identifiers in a communication network according to claim 1, characterized in that, After receiving the SUCI sent by the Universal User Identity Module (USIM) in the UE, the following is also included: Send a computation information version retrieval request to the USIM; the computation information version retrieval request is used to retrieve the version of the second SUCI computation information stored in the USIM; If the USIM does not return a response regarding the version of the computational information, it is determined that the version of the second SUCI computational information stored in the USIM is empty or 0.
7. The method for protecting user identifiers in a communication network according to claim 1, characterized in that, The SUCI sent by the USIM is sent to the ME when the USIM instructs the ME to calculate the SUCI; when the USIM instructs the ME to calculate the SUCI, the method further includes: If the ME stores the second SUCI calculation information stored in the USIM, the latest version of the SUCI calculation information is selected from the first SUCI calculation information stored in the ME and the second SUCI calculation information stored in the USIM and saved locally. Based on the latest version of SUCI calculation information, select the new SUPI protection scheme with the highest priority that ME can support; SUCI is calculated based on the new SUPI protection scheme and the public key of the home network element used by the new SUPI protection scheme.
8. A method for protecting user identifiers in a communication network, characterized in that, Applied to home network elements, the method includes: Receive SUCI sent by ME; wherein, the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. Based on the cryptographic algorithm specified by the target SUPI protection scheme, the ciphertext data in the SUCI is decrypted to obtain decrypted data; When the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI, the decrypted data is processed again to obtain SUPI.
9. The method for protecting user identifiers in a communication network according to claim 8, characterized in that, The secondary processing of the decrypted data to obtain SUPI includes: From the integrity digest value field in the scheme output field of the SUCI, obtain the SUPI protection scheme identifier, home network element public key identifier information, and temporary password data determined based on the initial SUPI protection scheme; the initial SUPI protection scheme is the highest priority SUPI protection scheme that USIM can support, selected based on the second SUCI calculation information. The decryption data is decrypted using the cryptographic algorithm specified in the initial SUPI protection scheme, the private key corresponding to the initial SUPI protection scheme, and the temporary cryptographic data to obtain SUPI.
10. The method for protecting user identifiers in a communication network according to claim 9, characterized in that, The process of decrypting the decrypted data to obtain SUPI includes: Obtain the integrity digest value determined based on the initial SUPI protection scheme from the integrity digest value field in the scheme output field of the SUCI. If the validity of the integrity digest value is verified, the decrypted data is decrypted to obtain SUPI.
11. The method for protecting user identifiers in a communication network according to claim 8, characterized in that, After decrypting the ciphertext data in the SUCI using the cryptographic algorithm specified by the target SUPI protection scheme to obtain decrypted data, and if the protection scheme identifier value indicates that the SUCI does not require secondary processing, the process further includes: Based on the decrypted data, SUPI is obtained.
12. A communication network user identification protection device, characterized in that, Mobile equipment (ME) used in user equipment (UE) includes: The receiving module is used to receive the SUCI sent by the Universal User Identity Module (USIM) in the UE. The selection module is used to select the highest priority target SUPI protection scheme that the ME can support based on the first SUCI calculation information when the version of the first SUCI calculation information stored in the ME is greater than the version of the second SUCI calculation information stored in the USIM. A secondary processing module is used to perform secondary processing on the SUCI based on the target SUPI protection scheme to obtain a new SUCI; wherein, the new SUCI includes a protection scheme identifier, and the value of the protection scheme identifier is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether secondary processing is required when decrypting the SUCI. The sending module is used to send the new SUCI to the home network element.
13. A communication network user identification protection device, characterized in that, Applied to home network elements, including: The SUCI receiving module is used to receive SUCI sent by the ME; wherein, the SUCI includes a protection scheme identifier, the value of which is used to indicate the cryptographic algorithm specified by the target SUPI protection scheme and whether the SUCI needs to be processed again; the target SUPI protection scheme is the highest priority SUPI protection scheme that the ME can support, selected based on the first SUCI calculation information when the version of the first SUCI calculation information stored by the ME is greater than the version of the second SUCI calculation information stored by the USIM. The decryption module is used to decrypt the ciphertext data in the SUCI based on the cryptographic algorithm specified by the target SUPI protection scheme to obtain decrypted data; The user identifier acquisition module is used to perform secondary processing on the decrypted data to obtain SUPI when the value of the protection scheme identifier indicates that secondary processing is required when decrypting SUCI.
14. An electronic device comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the communication network user identification protection method as described in any one of claims 1-7 or 8-11.
15. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the communication network user identification protection method according to any one of claims 1-7 or 8-11.
16. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the communication network user identification protection method according to any one of claims 1-7 or 8-11.