Communication method and communication apparatus
Patent Information
- Application Number
- CN202510372467.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2026-09-29
AI Technical Summary
[0082]应理解,上述第三方面至第十一方面的有益效果可以参考上述第一方面及其任一种可能的实现方式,在此不赘述。
Smart Images

Figure CN122845142A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more specifically, to a communication method and a communication device. Background Technology
[0002] Homomorphic encryption is a key technology in privacy computing. By encrypting original data using homomorphic encryption to obtain ciphertext, computation and analysis can be performed directly on the ciphertext, avoiding the exposure of the original data. How to apply homomorphic encryption to mobile communication networks to protect communication data privacy and improve communication data security has become an urgent problem to be solved. Summary of the Invention
[0003] This application provides a communication method for applying homomorphic encryption technology in communication networks to protect the privacy of communication data and improve the security of communication data.
[0004] Firstly, a communication method is provided. This method can be executed by a first network element, a component within the first network element, or a logic module or software capable of implementing all or part of the functions of the first network element. The first network element can be a network data analytics function (NWDAF) network element, a sensing function (SF) network element, etc. The first network element can also include multiple network elements, such as an access and mobility management function (AMF) network element and an NWDAF network element. The components within the first network element can be communication modules, processors, chips, or chip systems, etc. The communication module within the first network element can be a circuit or chip responsible for communication functions within the first network element. This circuit or chip can be a modem chip (also known as a baseband chip), a system-on-a-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip, etc. For ease of description, the following explanation will use the execution of the first network element as an example.
[0005] The communication method includes: a first network element receiving first ciphertext from a first communication device, the first ciphertext being obtained by encrypting second ciphertext using a first security algorithm. The second ciphertext is obtained by encrypting first data using N first keys corresponding to the second security algorithm, where N is an integer greater than 1. Additionally, the first network element can determine N first keys based on the second security algorithm and obtain N second keys based on these N first keys, the N second keys being obtained by encrypting N first keys using the first security algorithm. Thus, the first network element can decrypt the first ciphertext using the N second keys to obtain a third ciphertext, which is in the ciphertext state corresponding to the first security algorithm. It should be understood that during the decryption process, both the N second keys and the first ciphertext are in the ciphertext state corresponding to the first security algorithm. The third ciphertext in the ciphertext state corresponding to the first security algorithm can be understood as the third ciphertext being ciphertext in the encryption state of the first security algorithm, or in other words, the third ciphertext is the same as the result obtained by encrypting the first data using the first security algorithm, or in other words, the first data in plaintext state can be obtained by decrypting the third ciphertext using the first security algorithm.
[0006] In this embodiment of the application, the key or ciphertext in the ciphertext state corresponding to the first security algorithm indicates that the key or ciphertext has been encrypted using the first security algorithm and has not been decrypted using the first security algorithm; or, it can also indicate that the key or ciphertext needs to be decrypted using the decryption key corresponding to the first security algorithm to obtain the plaintext. The key or ciphertext in the ciphertext state corresponding to the first security algorithm can also be referred to as the key or ciphertext being in the ciphertext state corresponding to the first security algorithm.
[0007] In addition, the statement that the key or ciphertext is not in the ciphertext state corresponding to the first security algorithm means that the key or ciphertext was not encrypted based on the first security algorithm, or was previously encrypted based on the first security algorithm and has been decrypted based on the first security algorithm. The statement that the key or ciphertext is not in the ciphertext state corresponding to the first security algorithm can also be referred to as the key or ciphertext being in the plaintext state corresponding to the first security algorithm, or the key or ciphertext not being in the ciphertext state corresponding to the first security algorithm.
[0008] Similarly, the ciphertext state corresponding to the second security algorithm indicates that the key or ciphertext has been encrypted using the second security algorithm but has not been decrypted using the second security algorithm; or, it can also indicate that the key or ciphertext needs to be decrypted using the decryption key corresponding to the second security algorithm to obtain the plaintext. The ciphertext state corresponding to the second security algorithm can also be referred to as the key or ciphertext being in the ciphertext state corresponding to the second security algorithm.
[0009] Additionally, "the key or ciphertext is not in the ciphertext state corresponding to the second security algorithm" means that the key or ciphertext was not encrypted using the second security algorithm, or it was previously encrypted using the second security algorithm and has already been decrypted using the second security algorithm. Here, "the key or ciphertext is not in the ciphertext state corresponding to the second security algorithm" can also be referred to as "the key or ciphertext is in the plaintext state corresponding to the second security algorithm", or "the key or ciphertext is not in the ciphertext state corresponding to the second security algorithm".
[0010] Based on the above technical solution, after receiving the ciphertext (i.e., the first ciphertext) encrypted using the first security algorithm, the first network element can decrypt the first ciphertext using the obtained keys (i.e., N second keys) encrypted using the first security algorithm. It should be understood that during the decryption process, both the N second keys and the first ciphertext are in the ciphertext state corresponding to the first security algorithm; therefore, the first network element can decrypt the first ciphertext using the N second keys.
[0011] In this application, the ciphertext encrypted by the first security algorithm can be processed in the ciphertext state. The first security algorithm is, for example, a homomorphic encryption algorithm. In this technical solution, the ciphertext received by the first network element can be homomorphically encrypted, and the first network element can perform subsequent decryption based on the obtained N second keys. This technical solution defines the ciphertext transmission method and decryption method of homomorphic encryption, realizes the application of homomorphic encryption technology in communication networks, thereby achieving the protection of communication data privacy and the improvement of communication data security.
[0012] Furthermore, as mentioned above, decrypting the first ciphertext requires N second keys. Therefore, in the above technical solution, the first network element needs to obtain N second keys. On the one hand, in the prior art, the server decrypting the first ciphertext expands the master key encrypted based on the first security algorithm to obtain the N second keys during the decryption process. However, in this application, the first network element can obtain the N second keys required for decrypting the first ciphertext before decryption. The process of the first network element obtaining the N second keys in this application can be understood as a preprocessing process before the decryption process, which reduces the decryption latency compared to the server decryption process in the prior art. On the other hand, in the prior art, the server needs to perform key expansion on the master key encrypted based on the first security algorithm in the process of obtaining the N second keys. This can be understood as the server needing to deduce the round key based on the homomorphically encrypted master key. In this application, the first network element performs key expansion on the master key in plaintext state to obtain N first keys, and then obtains N second keys based on the N first keys. It does not need to perform key expansion on the master key in the encrypted state of the first security algorithm in the ciphertext state corresponding to the first security algorithm, which reduces the complexity of obtaining the N second keys, thereby improving the computational efficiency of homomorphic ciphertext and reducing the latency of the first network element performing data analysis.
[0013] In conjunction with the first aspect, in some implementations of the first aspect, the first network element obtains N second keys based on N first keys, including: the first network element generating N first keys. Furthermore, the first network element receives an encryption key corresponding to a first security algorithm from the first communication device, thereby enabling the first network element to encrypt the N generated first keys respectively based on the received encryption key to obtain N second keys.
[0014] Based on the above technical solution, the first network element can obtain N second keys based on N first keys in the following way: the first network element determines N first keys itself based on a second security algorithm, and obtains the encryption key corresponding to the first security algorithm required to encrypt the N first keys from the first communication device. Thus, the first network element can encrypt the N first keys itself to obtain N second keys, without needing to provide the N first keys to other devices for encryption to generate N second keys, which is then provided to the first network element. This reduces the key transmission process and improves security to some extent.
[0015] In conjunction with the first aspect, in some implementations of the first aspect, the first network element obtains N second keys based on N first keys, including: the first network element generating N first keys; and the first network element sending the N first keys to a first communication device, which encrypts the N first keys to obtain N second keys and sends them to the first network element.
[0016] Based on the above technical solution, the first network element can obtain N second keys based on N first keys in the following way: After the first network element determines N first keys based on the second security algorithm, it can provide the N first keys to other devices, and the other devices can encrypt the N first keys to generate N second keys and provide them to the first network element. This eliminates the need for the first network element to encrypt the N first keys, which can reduce the complexity of the first network element to a certain extent.
[0017] Furthermore, in this technical solution, the first communication device encrypts N first keys to generate N second keys. This enables the first communication device to perform homomorphic ciphertext calculations on the second ciphertext from the second communication device based on these N second keys, thereby improving the efficiency of the network in performing homomorphic encryption and / or homomorphic computation. For example, the first communication device receives the second ciphertext sent by the second communication device, encrypts the second ciphertext based on a first security algorithm to obtain a first ciphertext, and can decrypt the first ciphertext based on the N second keys to obtain a third ciphertext in the ciphertext state corresponding to the first security algorithm. Thus, the first communication device can perform homomorphic ciphertext calculations on the third ciphertext based on the computation key corresponding to the first security algorithm.
[0018] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: a first network element performing calculations on the third ciphertext based on the calculation key corresponding to the first security algorithm to obtain a first calculation result. The first network element sends the first calculation result to the first communication device, wherein, during the calculation process, the third ciphertext is in the ciphertext state corresponding to the first security algorithm.
[0019] Based on the above technical solution, the first network element can provide the first calculation result after homomorphic computation to the first communication device, enabling the first communication device to determine the analysis result related to the first data. Furthermore, the first calculation result is determined based on homomorphic computation of the third ciphertext in its ciphertext state using the computation key. This means that the first network element does not actually determine the plaintext of the first data during data analysis, ensuring the security of the first data and enhancing the data privacy protection of the second communication device. In addition, the first network element can perform homomorphic computation on the third ciphertext in its ciphertext state corresponding to the first security algorithm to obtain the analysis result related to the first data, enabling effective utilization of the data by the second communication device.
[0020] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the first network element receiving a computation key corresponding to the first security algorithm from the first communication device.
[0021] Based on the above technical solution, the computation key required for the first network element to perform homomorphic computation is provided by the first communication device. This first communication device possesses the encryption key, decryption key, and computation key corresponding to the first security algorithm. The first communication device centrally manages the keys corresponding to the first security algorithm, thereby improving key security.
[0022] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the first network element sending a second request message to the first communication device, the second request message being used to request encryption of data from the second communication device based on the first security algorithm, the second request message including a first identifier, the first identifier being associated with the first security algorithm.
[0023] Based on the above technical solution, the first network element can instruct the first communication device to encrypt the data subsequently received from the second communication device based on the first security algorithm through the second request message, instead of encrypting the data of all communication devices based on the first security algorithm, thereby realizing personalized services and improving service performance.
[0024] In conjunction with the first aspect, in some implementations of the first aspect, before the first network element sends the second request message to the first communication device, the first network element determines to provide computing services based on the first security algorithm to the second communication device.
[0025] Based on the above technical solution, before the first network element instructs the first communication device to encrypt the data subsequently received from the second communication device based on the first security algorithm via the second request message, the first network element determines that it can provide computing services based on the first security algorithm to the second communication device. This avoids the situation where, after the first network element instructs the first communication device to encrypt the data from the second communication device based on the first security algorithm, the first network element is unable to provide computing services based on the first security algorithm to the data from the second communication device after the first network element instructs the first communication device to encrypt the data from the second communication device based on the first security algorithm.
[0026] In conjunction with the first aspect, in certain implementations of the first aspect, the first network element determines to provide computing services based on the first security algorithm to the second communication device, including: the first network element determines to provide computing services based on the first security algorithm to the second communication device based on the subscription information of the second communication device.
[0027] Based on the above technical solution, the first network element can determine whether to provide computing services based on the first security algorithm to the second communication device based on the subscription information of the second communication device. The subscription information of the second communication device can indicate the needs of the second communication device. Thus, in this technical solution, the first network element determines whether to provide computing services based on the first security algorithm to the second communication device based on the subscription information of the second communication device, so that the first network element can provide services that meet the needs of the second communication device.
[0028] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: a first network element receiving a first request message from a second communication device, the first request message including an identifier of the second communication device; the first network element may obtain the subscription information of the second communication device based on the identifier of the second communication device.
[0029] In conjunction with the first aspect, in some implementations of the first aspect, the first identifier associated with the first security algorithm includes at least one of the following: the identifier of the second communication device, the identifier of the service to which the first data belongs, or the identifier of the service area to which the first communication device belongs.
[0030] Based on the above technical solution, the first identifier associated with the first security algorithm can take many different forms, thereby improving the flexibility of the solution.
[0031] In conjunction with the first aspect, in some implementations of the first aspect, the first network element determines to provide computing services based on the first security algorithm to the second communication device, including: the first network element determines to provide computing services based on the first security algorithm to a first service of the second communication device based on the type of the service to which the first data belongs, wherein the type of the first service is the same as the type of the service to which the first data belongs.
[0032] Based on the above technical solution, the first network element can determine whether to provide corresponding first security algorithm calculation services for certain services of the second communication device, thereby realizing service provision at the service granularity and improving service flexibility and personalization.
[0033] In conjunction with the first aspect, in certain implementations of the first aspect, the first network element determines, based on the subscription information, to provide the second communication device with computing services based on the first security algorithm, including: the first network element determining a security service policy for the second communication device based on the subscription information, the security service policy indicating the security protection requirements of the second communication device; and the first network element determining to provide the second communication device with computing services based on the first security algorithm according to the security service policy.
[0034] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the first network element sending the first identifier to the second communication device.
[0035] Based on the above technical solution, the first network element can send a first identifier associated with the first security algorithm to the second communication device. This allows the second communication device to carry the first identifier when sending the second ciphertext to the first communication device, enabling the first communication device to determine the first security algorithm based on the first identifier and then encrypt the second ciphertext. This avoids situations where the first communication device is unable to determine a suitable security algorithm for encryption, thus improving the accuracy of the solution.
[0036] Secondly, a communication method is provided. This method can be executed by a first communication device, a component within the first communication device, or a logic module or software capable of implementing all or part of the functions of the first communication device. The first communication device can be a network device, a encryption node, etc. The components within the first communication device can be modules, processors, chips, or chip systems, etc. The communication module within the first communication device can be a circuit or chip responsible for communication functions. This circuit or chip can be a modem chip (also known as a baseband chip, or a SoC chip or SIP chip containing a modem core). For ease of description, the following explanation uses the execution by the first communication device as an example.
[0037] The communication method includes: a first communication device sending a first ciphertext to a first network element, the first ciphertext being obtained by encrypting a second ciphertext based on a first security algorithm, the second ciphertext being obtained by encrypting first data of a second communication device based on N first keys corresponding to the second security algorithm, where N is an integer greater than 1. The first communication device receiving a first calculation result from the first network element, the first calculation result being obtained by calculating a third ciphertext based on a calculation key corresponding to the first security algorithm, the third ciphertext being obtained by decrypting the first ciphertext based on N second keys, the N second keys being obtained by encrypting the N first keys based on the first security algorithm, the N second keys supporting decryption of the first ciphertext in the ciphertext state encrypted by the first security algorithm. The first communication device decrypting the first calculation result based on the decryption key corresponding to the first security algorithm to obtain a second calculation result. The first communication device sending the second calculation result, securely protected by a third security algorithm, to the second communication device, wherein the third security algorithm is the second security algorithm, or the third security algorithm is determined through negotiation between the second communication device and the first communication device.
[0038] Based on the above technical solution, the first communication device sends ciphertext encrypted using the first security algorithm (i.e., the first ciphertext) to the first network element and receives a first calculation result from the first network element. This first calculation result is obtained by calculating a third ciphertext using the calculation key corresponding to the first security algorithm. The third ciphertext is obtained by decrypting the first ciphertext using N second keys. In other words, after receiving the ciphertext encrypted using the first security algorithm (i.e., the first ciphertext), the first network element can decrypt the first ciphertext using the obtained key (i.e., the N second keys) encrypted using the first security algorithm. It should be understood that during the decryption process, both the N second keys and the first ciphertext are in the ciphertext state corresponding to the first security algorithm.
[0039] In this application, the ciphertext encrypted by the first security algorithm can be processed in the ciphertext state. The first security algorithm is, for example, a homomorphic encryption algorithm. In this technical solution, the ciphertext received by the first network element can be homomorphically encrypted, and the first network element can perform subsequent decryption based on the obtained N second keys. This technical solution defines the transmission and decryption methods of homomorphically encrypted ciphertext in mobile communication networks, realizes the application of homomorphic encryption technology in communication networks, and thereby achieves the protection of communication data privacy and the improvement of communication data security.
[0040] In addition, the first communication device can also decrypt the first calculation result based on the decryption key corresponding to the first security algorithm to obtain the second calculation result, and send the second calculation result protected by the third security algorithm to the second communication device to improve the security of the second calculation result.
[0041] In conjunction with the second aspect, in some implementations of the second aspect, where the third security algorithm is the second security algorithm, the method further includes: a first communication device sending the second calculation result to the first network element. The first communication device receives the second calculation result, which is securely protected by the third security algorithm, from the first network element.
[0042] In this implementation, the third security algorithm for protecting the second calculation result can be a second security algorithm negotiated and determined between the first network element and the second communication device. The first communication device can send the second calculation result requiring security protection to the first network element, which then performs security protection on the second calculation result based on the second security algorithm and provides the second calculation result, protected by the third security algorithm, to the first communication device. This technical solution eliminates the need for the first communication device to perform security protection on the second calculation result, reducing the computational complexity of the first communication device.
[0043] In conjunction with the second aspect, in some implementations of the second aspect, where the third security algorithm is determined through negotiation between the second communication device and the first communication device, the method further includes: the first communication device performing security protection on the second calculation result based on the third security algorithm to obtain the second calculation result protected by the third security algorithm.
[0044] In this implementation, the third security algorithm for protecting the second calculation result can be determined through negotiation between the first communication device and the second communication device. Under the premise that the first communication device determines the third security algorithm, the first communication device can protect the second calculation result based on the third security algorithm on its own, without sending the second calculation result to the first network element. The first network element can protect the second calculation result based on the second security algorithm, which simplifies the interaction process between the first communication device and the first network element and reduces the signaling overhead between the first communication device and the first network element.
[0045] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: the first communication device sending the encryption key corresponding to the first security algorithm to the first network element.
[0046] Based on the above technical solution, the first network element can obtain N second keys based on N first keys in the following way: the first network element determines N first keys itself based on a second security algorithm, and obtains the encryption key corresponding to the first security algorithm required to encrypt the N first keys from the first communication device. Thus, the first network element can encrypt the N first keys itself to obtain N second keys, without needing to provide the N first keys to other devices for encryption to generate N second keys, which is then provided to the first network element. This reduces the key transmission process and improves security to some extent.
[0047] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: a first communication device receiving the N first keys from the first network element; the first communication device encrypting the N first keys respectively based on the encryption key corresponding to the first security algorithm to obtain N second keys; and the first communication device sending the N second keys to the first network element.
[0048] Based on the above technical solution, the first network element can obtain N second keys based on N first keys in the following way: After the first network element determines N first keys based on the second security algorithm, it can provide the N first keys to other devices, and the other devices can encrypt the N first keys to generate N second keys and provide them to the first network element. This eliminates the need for the first network element to encrypt the N first keys, which can reduce the complexity of the first network element to a certain extent.
[0049] Furthermore, in this technical solution, the first communication device encrypts N first keys to generate N second keys. This enables the first communication device to perform homomorphic ciphertext calculations on the second ciphertext from the second communication device based on these N second keys, thereby improving the efficiency of the network in performing homomorphic encryption and / or homomorphic computation. For example, the first communication device receives the second ciphertext sent by the second communication device, encrypts the second ciphertext based on a first security algorithm to obtain a first ciphertext, and can decrypt the first ciphertext based on the N second keys to obtain a third ciphertext in the ciphertext state corresponding to the first security algorithm. Thus, the first communication device can perform homomorphic ciphertext calculations on the third ciphertext based on the computation key corresponding to the first security algorithm.
[0050] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: a first communication device receiving a second request message from the first network element, the second request message being used to request encryption of data from the second communication device based on the first security algorithm, the second request message including a first identifier, the first identifier being associated with the first security algorithm.
[0051] Based on the above technical solution, the first network element can instruct the first communication device to encrypt the data subsequently received from the second communication device based on the first security algorithm through the second request message, instead of encrypting the data of all communication devices based on the first security algorithm, thereby realizing personalized services and improving service performance.
[0052] In conjunction with the second aspect, in some implementations of the second aspect, the first identifier includes at least one of the following: the identifier of the second communication device, the identifier of the service to which the first data belongs, or the identifier of the service area to which the first communication device belongs.
[0053] Based on the above technical solution, the first identifier associated with the first security algorithm can take many different forms, thereby improving the flexibility of the solution.
[0054] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: a first communication device receiving the second ciphertext and the first identifier from a second communication device. The first communication device determines the first security algorithm based on the first identifier, and encrypts the second ciphertext based on the first security algorithm to obtain the first ciphertext.
[0055] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: a first communication device sending a first indication message to the first network element, the first indication message being used to indicate that the first ciphertext is ciphertext encrypted based on the encryption key corresponding to the first security algorithm.
[0056] Thirdly, a communication method is provided. This method can be executed by a first communication device, a component within the first communication device, or a logic module or software capable of implementing all or part of the functions of the first communication device. The first communication device can be a network device, a encryption node, etc. Components within the first communication device can be modules, processors, chips, or chip systems, etc. The communication module within the first communication device can be a circuit or chip responsible for communication functions. This circuit or chip can be a modem chip (also known as a baseband chip, or a SoC chip or SIP chip containing a modem core). For ease of description, the following explanation uses the execution by the first communication device as an example.
[0057] The communication method includes: a first communication device receiving N first keys corresponding to a second security algorithm from a first network element; the first communication device encrypting the N first keys respectively based on the encryption key corresponding to the first security algorithm to obtain N second keys; and the first communication device sending the N second keys to the first network element, wherein the N second keys support decryption of ciphertext obtained based on the second security algorithm under the ciphertext state corresponding to the first security algorithm.
[0058] Based on the above technical solution, after the first network element determines N first keys based on the second security algorithm, it can provide the N first keys to the first communication device. The first communication device encrypts the N first keys to generate N second keys and provides them to the first network element. This eliminates the need for the first network element to perform encryption processing on the N first keys, which can reduce the complexity of the first network element obtaining the N second keys to a certain extent.
[0059] Furthermore, the first communication device encrypts N first keys to generate N second keys, enabling the first communication device to perform homomorphic ciphertext calculations on the second ciphertext from the second communication device based on these N second keys. This improves the efficiency of the network in performing homomorphic encryption and / or homomorphic computation. For example, the first communication device receives the second ciphertext sent by the second communication device, encrypts the second ciphertext using a first security algorithm to obtain a first ciphertext, and can decrypt the first ciphertext using the N second keys to obtain a third ciphertext in the ciphertext state corresponding to the first security algorithm. Thus, the first communication device can perform homomorphic ciphertext calculations on the third ciphertext based on the computation key corresponding to the first security algorithm.
[0060] Fourthly, a communication device is provided. This communication device is used to execute the methods described in the first aspect and any implementation thereof. For example, the communication device includes modules, units, or means corresponding to the operations involved in the first aspect. These modules, units, or means can be implemented in software, hardware, or a combination of software and hardware.
[0061] In one possible design, the communication device includes: a communication unit for receiving first ciphertext, wherein the first ciphertext is obtained by encrypting second ciphertext using a first security algorithm, and the second ciphertext is obtained by encrypting first data using N first keys corresponding to the second security algorithm, where N is an integer greater than 1; a processing unit for obtaining N second keys based on the N first keys, wherein the N second keys are obtained by encrypting the N first keys using the first security algorithm; and the processing unit is further configured to decrypt the first ciphertext based on the N second keys to obtain a third ciphertext, wherein the third ciphertext is in the ciphertext state corresponding to the first security algorithm. During the decryption process, the N second keys and the first ciphertext are in the ciphertext state corresponding to the first security algorithm.
[0062] The communication unit can perform the receiving and transmitting processes described in the first aspect above, and the processing unit can perform other processes described in the first aspect above besides receiving and transmitting.
[0063] The aforementioned communication device may be a first network element, or a communication module in the first network element, or a chip in the first network element responsible for communication functions, such as a modem chip (also known as a baseband chip) or a SoC or SIP chip containing a modem module, or a logical node, logical module, or software that can realize all or part of the functions of the first network element.
[0064] Fifthly, a communication device is provided. This communication device is used to execute the methods described in the second aspect and any implementation thereof. For example, the communication device includes modules, units, or means corresponding to the operations involved in the second aspect. These modules, units, or means can be implemented in software, hardware, or a combination of software and hardware.
[0065] In one possible design, the communication device includes: a communication unit configured to send a first ciphertext to a first network element, wherein the first ciphertext is obtained by encrypting a second ciphertext based on a first security algorithm, and the second ciphertext is obtained by encrypting first data of a second communication device based on N first keys corresponding to the second security algorithm, where N is an integer greater than 1. The communication unit is further configured to receive a first calculation result from the first network element, wherein the first calculation result is obtained by calculating a third ciphertext based on a calculation key corresponding to the first security algorithm, and the third ciphertext is obtained by decrypting the first ciphertext based on N second keys, wherein the N second keys are obtained by encrypting the N first keys based on the first security algorithm, and the N second keys support decryption of the first ciphertext in the ciphertext state encrypted by the first security algorithm. A processing unit configured to decrypt the first calculation result based on a decryption key corresponding to the first security algorithm to obtain a second calculation result. The communication unit is further configured to send the second calculation result, which is securely protected by a third security algorithm, to the second communication device. Wherein, the third security algorithm is the second security algorithm, or the third security algorithm is determined through negotiation between the second communication device and the first communication device.
[0066] The communication unit can perform the receiving and transmitting processes described in the second aspect above, and the processing unit can perform other processes described in the second aspect above besides receiving and transmitting.
[0067] In another possible design, the communication device includes: a communication unit for receiving N first keys corresponding to a second security algorithm from a first network element; a processing unit for encrypting the N first keys respectively based on the encryption key corresponding to the first security algorithm to obtain N second keys; and the communication unit further for sending the N second keys to the first network element. The N second keys support decryption of ciphertext obtained based on the second security algorithm while maintaining the ciphertext state corresponding to the first security algorithm.
[0068] The communication unit can perform the receiving and transmitting processes described in the third aspect above, and the processing unit can perform other processes described in the third aspect above besides receiving and transmitting.
[0069] The aforementioned communication device may be a first communication device, or a communication module in the first communication device, or a chip in the first communication device that is responsible for communication functions, such as a modem chip (also known as a baseband chip) or a SoC or SIP chip containing a modem module, or a logic node, logic module or software that can implement all or part of the first communication device.
[0070] A sixth aspect provides a communication device. The communication device includes at least one processor. The at least one processor is capable of executing a computer program or instructions, which, when executed, cause the communication device to implement the methods of any one of the first to third aspects and any implementation thereof.
[0071] In one possible design, the communication device may further include at least one interface circuit. This interface circuit is used to implement communication functions within the communication device and / or communication functions between the communication device and other devices or components.
[0072] In one possible design, the communication device may further include at least one interface circuit and / or at least one memory. The at least one processor is coupled to the at least one memory. The at least one memory is used to store part or all of the necessary computer programs or instructions for implementing the functions involved in any of the first to third aspects and any implementation thereof. The interface circuit is used to implement the communication functions within the communication device and / or the communication functions between the communication device and other devices or components.
[0073] In one possible design, the at least one processor is used to communicate with other devices or components via at least one interface circuit.
[0074] The aforementioned communication device may be a first network element, or a communication module in the first network element, or a chip in the first network element responsible for communication functions, or a logic node, logic module, or software that can realize all or part of the functions of the first network element.
[0075] The aforementioned communication device may be a first communication device, or a communication module in the first communication device, or a chip in the first communication device responsible for communication functions, or a logic node, logic module, or software that can realize all or part of the functions of the first communication device.
[0076] In a seventh aspect, a communication system is provided. This communication system includes the communication apparatus described in the fourth and / or fifth aspects.
[0077] Eighthly, a chip or chip system is provided. The chip or chip system includes at least one processing circuit for executing a computer program or instructions, causing the chip or chip system to perform the methods described in the first to third aspects and any possible implementation thereof.
[0078] The chip or chip system may include output circuits or interfaces for transmitting information or data, and input circuits or interfaces for receiving information or data.
[0079] A ninth aspect provides a computer-readable storage medium. This computer-readable storage medium stores computer program code or instructions, which, when executed by a processor, implement the methods of the first to third aspects and any possible implementation thereof.
[0080] A tenth aspect provides a computer program product. The computer program product includes computer program code or instructions, wherein when a processor executes the computer program code or instructions, the method in any of the possible implementations of the first to third aspects is implemented.
[0081] Eleventhly, a computer program is provided. When the computer program is run, it causes the methods of the first to third aspects and any possible implementation thereof to be implemented.
[0082] It should be understood that the beneficial effects of the third to eleventh aspects mentioned above can be referenced from the first aspect mentioned above and any possible implementation thereof, which will not be elaborated here. Attached Figure Description
[0083] Figure 1 This is a schematic diagram of the network architecture 100 provided in this application.
[0084] Figure 2 This is a schematic diagram of a NAS security setup process.
[0085] Figure 3 This is a schematic diagram of a data processing procedure based on homomorphic encryption technology.
[0086] Figure 4 This is a schematic diagram of homomorphic key generation.
[0087] Figure 5 This is a schematic diagram of a homomorphic encryption process.
[0088] Figure 6 This is a schematic diagram of a homomorphic decryption process.
[0089] Figure 7 This is a schematic diagram of a homomorphic computation process.
[0090] Figure 8 This is a schematic diagram of a homomorphic encryption scheme.
[0091] Figure 9 This is a schematic diagram of a encryption process.
[0092] Figure 10 This is a schematic flowchart of a communication method provided in this application.
[0093] Figure 11This is a schematic flowchart of a first communication device determining a first security algorithm, as provided in this application.
[0094] Figure 12 This is a schematic flowchart of a first network element obtaining N second keys, as provided in this application.
[0095] Figure 13 This is a schematic diagram of a key provided in this application.
[0096] Figure 14 This is another key diagram provided in this application.
[0097] Figure 15 This is a schematic block diagram of the communication device 10 provided in the embodiments of this application.
[0098] Figure 16 This is a schematic diagram of another communication device 20 provided in an embodiment of this application. Detailed Implementation
[0099] To facilitate understanding of the embodiments of this application, the following points will be explained first.
[0100] First, in this application, "for indicating" can include both direct and indirect indication. When describing an indication message for indicating A, it can include whether the indication message directly indicates A or indirectly indicates A, but does not necessarily mean that the indication message carries A.
[0101] The information indicated by the instruction is called the information to be instructed. In the specific implementation process, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. It can also be indirectly indicated by indicating other information, where there is a relationship between the other information and the information to be instructed. It can also indicate only a part of the information to be indicated, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol-defined) arrangement of various pieces of information, thereby reducing instruction overhead to some extent. At the same time, common parts of various pieces of information can be identified and indicated uniformly to reduce the instruction overhead caused by individually indicating the same information.
[0102] Second, in this application, "at least one" refers to one or more, and "more than one" refers to two or more (including two). Furthermore, in the embodiments of this application, "first," "second," and various numerical designations (e.g., "#1," "#2," etc.) are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The sequence numbers of the processes below do not imply an order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. It should be understood that the objects described in this way can be interchanged where appropriate to describe solutions other than those in the embodiments of this application. Moreover, in the embodiments of this application, terms such as "S1010" are merely identifiers for descriptive convenience and do not limit the order of execution steps.
[0103] Third, in the embodiments of this application, the words "exemplary" or "for example" are used to indicate that they are examples, illustrations, or descriptions. Any embodiment or design that is described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design options. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0104] Fourth, the term "storage" in the embodiments of this application can refer to storage in one or more memories. These memories can be separate installations or integrated into an encoder, decoder, processor, or communication device. Alternatively, some memories can be separately installed, while others can be integrated into the decoder, processor, or communication device. The type of memory can be any form of storage medium, and this application does not limit this.
[0105] Fifth, in the implementation of this application, "protocol" may refer to standard protocols in the field of communications, such as the NR protocol and related protocols applied in future communication systems, and this application does not limit it.
[0106] Sixth, in the embodiments of this application, the terms "of", "corresponding (relevant)", "corresponding", and "associate" can sometimes be used interchangeably. It should be noted that when their differences are not emphasized, their intended meanings are consistent.
[0107] Seventh, in the embodiments of this application, "under the circumstances", "when", and "if" can sometimes be used interchangeably. It should be noted that when the distinction is not emphasized, their intended meanings are consistent.
[0108] Eighth, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0109] Ninth, in this article, "message", "information", or "information element (IE)" can be used interchangeably. There are no restrictions on the name of the message or information, as long as it can achieve the corresponding function.
[0110] Tenth, in this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, and "send information" can include direct transmission or indirect transmission through other units or modules. "Receive information from YY" can be understood as the source of the information being YY, and "receive information" can include direct reception from YY or indirect reception from YY through other units or modules. Besides air interface transmission or reception signals implemented at the system level, such as network devices or terminal devices, "send" can also be understood as the "output" of a chip interface, and "receive" can also be understood as the "input" of a chip interface. For example, a modem or system-on-a-chip (SoC) chip or system-in-package (SIP) chip transmits or receives signals. "Send" or "receive" can also be performed through device components, for example, by using buses, traces, or interfaces to transmit or receive signals through several parts, modules, or chips of a device.
[0111] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0112] The technical solutions of this application embodiment can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, 5th Generation (5G) systems, or New Radio (NR) systems and future communication systems, vehicle-to-X (V2X) communication, where V2X can include vehicle-to-network (V2N), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), etc., Long Term Evolution-Vehicle (LTE-V) communication, vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IoT), Long Term Evolution-Machine (LTE-M) communication, machine-to-machine (M2M) communication, and wireless local area networks (WLANs). (network, WLAN, etc.)
[0113] In addition, the technical solution of this application can be applied to satellite communication systems, high altitude platform station (HAPS) communication, non-terrestrial network (NTN) systems such as UAVs, integrated communication and navigation (ICAN) systems, global navigation satellite systems (GNSS), and ultra-dense low-Earth orbit satellite communication systems.
[0114] For ease of description, this application will use a public land mobile network (PLMN) or a 5G network as examples in its embodiments.
[0115] Figure 1This is a schematic diagram of the communication system applicable to this application. Taking the 5G network architecture based on a service-oriented architecture in a non-roaming scenario as defined during the 3rd Generation Partnership Project (3GPP) standardization process as an example, as shown in the figure, this network architecture can include three parts: the terminal equipment part, the data network (DN), and the operator network PLMN part. The functions of the network elements in each part are briefly explained below.
[0116] The terminal equipment section may include terminal equipment 110. Terminal equipment can be a device or module that is connected to the aforementioned communication system and has corresponding communication functions. Terminal equipment may also be referred to as user equipment (UE), terminal, user device, access terminal, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal unit, terminal station, terminal device, wireless communication equipment, user agent, or user device. The terminal typically contains a communication module, circuit, or chip that performs the corresponding communication functions. The terminal may also be configured with program instructions for performing the corresponding communication functions.
[0117] For example, the terminal in this application embodiment can be a mobile phone, a personal digital assistant (PDA) computer, a laptop computer, a tablet computer, a drone, a computer with wireless transceiver capabilities, a machine-type communication (MTC) terminal, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a point-of-sale (POS) machine, customer-premises equipment (CPE), a light user equipment (UE), a reduced capability user equipment (REDCAPUE), a wearable device (e.g., a smartwatch, smart bracelet, pedometer, smart glasses), an Internet of Things (IoT) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, or a transportation terminal. Wireless terminals in smart cities, smart homes (e.g., game consoles, smart TVs, smart speakers, smart refrigerators, and fitness equipment), transportation vehicles with wireless communication capabilities, communication modules, roadside units (RSUs) with terminal functions, and flying equipment (e.g., smart robots, hot air balloons, drones, and airplanes). Terminal devices can also be vehicle-mounted devices, such as complete vehicle units, vehicle-mounted modules, vehicle-mounted chips, on-board units (OBUs), or telematics boxes (T-BOXs).
[0118] The PLMN portion of the operator's network may include, but is not limited to, RAN 120 and the core network (CN) portion.
[0119] RAN 120 is the implementation system between service nodes and terminal equipment 110 in the operator network. For terminal equipment 110 to access the operator network, it first goes through RAN 120, and then can connect to service nodes in the operator network via RAN 120. In this application, RAN 120 may include one or more access network devices.
[0120] Access network equipment can be a network-side device with wireless transceiver capabilities. It can be a device within a radio access network (RAN) that provides wireless communication functionality to terminal devices, referred to as RAN equipment. RAN can be a cellular system related to the 3rd Generation Partnership Project (3GPP), such as a 5G mobile communication system, or a future-oriented evolution system (such as a next-generation mobile communication system). RAN can also be an open radio access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. For example, this access network equipment can be a base station, an evolved NodeB (eNodeB), a next-generation NodeB (gNB) in a 5G mobile communication system, a 3GPP subsequent evolution base station, a transmission reception point (TRP), an access node, a wireless relay node, or a wireless backhaul node in a WiFi system. In communication systems employing different radio access technologies (RATs), the names of devices with base station functionality may differ. For example, in an LTE system, it may be called an eNB or eNodeB, and in a 5G or NR system, it may be called a gNB. This application does not limit the specific name of the base station. Access network equipment may include one or more co-located or non-co-located transmit / receive points. Furthermore, access network equipment may include at least one of the following: one or more central units (CU), one or more distributed units (DU), and one or more radio units (RU). In different systems, CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art will understand their meaning. For example, in an open RAN (ORAN) system, CU may also be called O-CU (open CU), DU may also be called O-DU (open DU), CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application may be implemented through software modules, hardware modules, or a combination of software and hardware modules.For example, the functionality of a CU can be implemented by one entity or different entities. For instance, the CU's functionality can be further divided, separating the control plane and user plane and implementing them through different entities: a control plane CU entity (i.e., the CU-CP entity) and a user plane CU entity (i.e., the CU-UP entity). The CU-CP and CU-UP entities can be coupled with a DU to jointly complete the access network device's functionality. For example, the CU is responsible for handling non-real-time protocols and services, implementing the functions of the radio resource control (RRC) and packet data convergence protocol (PDCP) layers. The DU is responsible for handling physical layer protocols and real-time services, implementing the functions of the radio link control (RLC) layer, medium access control (MAC) layer, and physical (PHY) layer. In this way, some functions of the wireless access network device can be implemented through multiple network function entities. These network function entities can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). The access network device can also include an active antenna unit (AAU). The AAU implements some physical layer processing functions, radio frequency processing, and related functions of the active antenna. Since RRC layer information ultimately becomes PHY layer information, or is derived from PHY layer information, in this architecture, higher-layer signaling, such as RRC layer signaling, can also be considered as being sent by the DU, or by the DU+AAU. It is understood that access network equipment can be one or more of the following: CU nodes, DU nodes, and AAU nodes. Furthermore, the CU can be classified as an access network device in the radio access network (RAN), or as an access network device in the core network (CN); this application does not limit this. For example, in V2X technology, access network equipment can be a roadside unit (RSU). Multiple access network devices in a communication system can be base stations of the same type or different types. Base stations can communicate with terminal devices directly, or they can communicate with terminal devices through relay stations. In this embodiment, the device for implementing the access network device function can be the access network device itself, or it can be a device that supports the access network device in implementing the function, such as a chip system or a combination of devices or components that can implement the access network device function. This device can be installed in the access network device. In this embodiment, the chip system can be composed of chips, or it can include chips and other discrete devices.
[0121] Additionally, as an example, the access network equipment in this application may also include service management and orchestration (SMO), wherein the SMO includes a RAN intelligent controller (RIC). Optionally, the RIC includes two types: a non-real-time radio intelligent controller (non-RT-RIC) and a near-real-time radio intelligent controller (near-RT-RIC).
[0122] The non-RT-RIC is deployed within the SMO, and its main responsibilities are: to provide policy and machine language (ML) model management, and a large amount of information to achieve intelligent RAN optimization; and to enable rApp functionality. rApp can collect information and take action through the A1, O1, O2, and open fronthaul management plane (Open FH M-Plane) interfaces to achieve RAN optimization. rApp is a portable, functional application.
[0123] The near-RT-RIC is deployed within the SMO, and its main responsibility is to provide near real-time radio resource control and optimization to the base station based on data collected by the E2 nodes.
[0124] The CN part may include, but is not limited to, the following network functions (NFs): User plane function (UPF)130, Network exposure function (NEF)131, Network function repository function (NRF)132, Policy control function (PCF)133, Unified data management (UDM)134, Unified data repository (UDR)135, Network data analytics function (NWDAF)136, Authentication server function (AUSF)137, AMF138, Session management function (SMF)139.
[0125] Optionally, the CN part may also include network elements such as application function (AF) 141 and / or sensing function (SF) 142.
[0126] Data network DN 140, also known as packet data network (PDN), is typically a network located outside the operator's network, such as a third-party network. However, in some implementations, the DN can also be deployed by the operator, meaning the DN is part of a PLMN. This application does not restrict whether the DN belongs to a PLMN. An operator's PLMN can connect to multiple data networks DN 140. Various services can be deployed on the data network DN 140, providing data and / or voice services to terminal devices 110. For example, data network DN 140 can be a private network of a smart factory. Sensors installed in the workshop of the smart factory can be terminal devices 110. A control server for the sensors is deployed in the data network DN 140, providing services to the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions. As another example, data network DN 140 can be an internal office network of a company. The mobile phones or computers of the company's employees can be terminal devices 110, and the employees' mobile phones or computers can access information and data resources on the company's internal office network. Terminal device 110 can establish a connection with the operator network through an interface (such as N1) provided by the operator network and use data and / or voice services provided by the operator network. Terminal device 110 can also access data network DN 140 through the operator network and use operator services deployed on data network DN 140, and / or services provided by third parties.
[0127] The following is a brief explanation of the NF functions included in CN.
[0128] 1. PCF 133 is a control plane function provided by the operator. It supports a unified policy framework to govern network behavior, provide policy rules and subscription information related to policy decisions to other control functions, etc.
[0129] 2. UDM 134 is a control plane function provided by the operator, responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribed users in the operator's network. The SUPI undergoes confidentiality protection during transmission; this confidential SUPI is called the subscription concealed identifier (SUCI). The information stored in UDM 134 can be used for authentication and authorization of terminal device 110 when accessing the operator's network. Specifically, the subscribed users of the aforementioned operator's network can be users of services provided by the operator's network, such as users using a subscriber identity module (SIM) card from operator A or operator B. The credentials of the subscribed users can be a long-term key stored in the SIM card or a small file containing information related to SIM card encryption, used for authentication and / or authorization. It should be noted that, for the sake of convenience, the permanent identifier, trust certificate, security context, authentication data (cookie), and token are not distinguished or limited in this application embodiment for the purpose of description.
[0130] 3. UDR 135 is a control plane function provided by the operator, which provides UDM with the ability to store and retrieve subscription data, PCF with the ability to store and retrieve policy data, and stores and retrieves user NF group identifier (group ID) information, etc.
[0131] 4. NWDAF 136 is a control plane function provided by the operator. Its main function is to collect data from NF, external application functions (AF), and operation, administration and maintenance (OAM) systems, and to provide NWDAF service registration, data access, and analysis data to NF and AF. In this application, NWDAF is mainly responsible for security-related data analysis. Therefore, in this application, NWDAF can also be understood as a network element with security analysis capabilities. The term NWDAF is just an example; other network element names may be used subsequently, and this application does not limit this.
[0132] 5. AUSF 137 is a control plane function provided by the operator, typically used for Level 1 authentication, i.e., authentication between terminal device 110 (the subscriber) and the operator's network. After receiving an authentication request from the subscriber, AUSF 137 can authenticate and / or authorize the subscriber using the authentication and / or authorization information stored in UDM 134, or generate the subscriber's authentication and / or authorization information using UDM 134. AUSF 137 can then send the authentication and / or authorization information back to the subscriber.
[0133] 6. AMF 138 is a control plane network function provided by the operator's network, which is responsible for access control and mobility management of terminal equipment 110 accessing the operator's network. This includes functions such as mobility state management, allocation of temporary user identity identifiers, authentication and authorization of users.
[0134] 7. SF 142 is used for network elements that process and compute sensed data. It can be any network element capable of computation, such as network data analysis function network elements, analysis logical function network elements (AnLF), model trains logical function network elements (MTLF) and other artificial intelligence (AI) function network elements, or location management function (LMF), as well as any future network elements with computational tasks.
[0135] In this application, the sensing control function (SF) can be deployed in the core network or in a non-core network, without limitation. The SF can utilize access network equipment and / or terminal equipment for sensing. The SF can be co-located with other network elements, or its functions can be implemented by other network elements, or the SF can be configured independently; this application does not limit this. Optionally, the SF can also be called a sensing control function (SCF) or other possible names.
[0136] For example, the SF can transmit sensing control signaling with access network equipment and / or terminal equipment through access and mobility management function network elements. The sensing measurement data acquired by the access network equipment and / or terminal equipment can be transmitted to the SF via the control plane or user plane. The user plane can be forwarded through user plane function network elements or directly transmitted to the SF. For example, the aforementioned communication interfaces (such as N1, N2, N5, or N8, etc.) can support the transmission of sensing service-related information, such as authentication information, sensing service type, sensing service quality requirements, sensing measurement data, or sensing information.
[0137] It is understandable that the aforementioned network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualization functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented in hardware or software.
[0138] Figure 1 Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nausf, Namf, Nsmf, Nran, N1, N2, N3, N4, and N6 are interface sequence numbers. For example, the meaning of the above interface sequence numbers can be found in the 3GPP standard protocol, and this application does not limit the meaning of the above interface sequence numbers. It should be noted that the interface names between the various network functions in the figure are merely examples; in specific implementations, the interface names of this system architecture may be other names, and this application does not limit them. Furthermore, the names of the messages (or signaling) transmitted between the above network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.
[0139] For ease of explanation, in this application embodiment, network functions (such as NEF 131…SMF139) are collectively referred to as NF, that is, the NF described below in this application embodiment can be replaced with any network function. Additionally, Figure 1 The network functions described below are only schematic representations and are not limited to the NFs described later. Figure 1 The network functions shown in the image.
[0140] It should be understood that the network architecture described above for the embodiments of this application is only a network architecture described from the perspective of service-oriented architecture. The network architecture applicable to the embodiments of this application is not limited to this, and any network architecture that can realize the functions of the above-described network elements is applicable to the embodiments of this application. For example, at least one of the network elements, access network devices, or terminal devices in this application can be deployed in NTN.
[0141] It should also be understood that AMF, SMF, UPF, NEF, AUSF, NRF, PCF, UDM, and SF shown in the diagram can be understood as network elements in the core network used to implement different functions, for example, they can be combined into network slices as needed. These core network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the above network elements. Furthermore, Figure 1 The network architecture shown may also include other network elements, such as sensing function network elements, artificial intelligence logic function (e.g., model training logic function, analysis logic function) network elements, etc.
[0142] It should also be understood that the above naming is defined solely for the purpose of distinguishing different functions and should not constitute any limitation on this application. This application does not preclude the possibility of using other naming conventions in 5G networks and other future networks. For example, in future communication networks, some or all of the above-mentioned network elements may use the terminology from 5G, or they may use other names, etc.
[0143] It should be noted that the above Figure 1 The embodiments of this application are merely illustrative of the scenarios in which they can be applied and do not constitute any limitation on the scope of protection of this application. The embodiments provided in this application can also be applied to other communication scenarios. For example, the SF network element mentioned above can also be other computing network elements used to process the data provided by the terminal. These will not be illustrated one by one here.
[0144] To facilitate understanding of the embodiments of this application, some basic concepts involved in this application are briefly explained. It should be understood that the basic concepts introduced below are illustrated using the basic concepts specified in the NR protocol as examples, but do not limit the embodiments of this application to be applied only to NR systems. Therefore, the standard names that appear when describing using an NR system as an example are functional descriptions, and the specific names are not limited, but only indicate the function of the device, which can be extended to other future systems.
[0145] 1. Privacy computation (or privacy computing): refers to a set of technologies that enable data analysis and computation while protecting the data itself from public disclosure, achieving the goal of making the data "usable but not visible"; and realizing the transformation and release of data value while fully protecting data and privacy security.
[0146] 2. Homomorphic Encryption: An important technique in privacy computing, homomorphic encryption encrypts the original data to obtain ciphertext, which can then be directly used for computation and analysis, preventing the original data from being exposed. The data before and after homomorphic encryption has the same computational properties, meaning both are homomorphic.
[0147] 3. Non-access stratum messages: These are messages sent by a terminal device to subsequent nodes through a wireless access node. This includes messages sent from the terminal device to the core network through the access network equipment, or messages sent from the terminal device to the core network through the DU. Because the access node does not process these messages, they are called non-access stratum messages. For ease of description, this application refers to all messages not processed by the access node as non-access stratum (NAS) messages. However, it should be understood that the name of the message is not limited in this application, and messages not processed by the access node may have other names (e.g., other possible names defined in future communication protocols).
[0148] 4. NAS Security Setup: For ease of understanding, combined with... Figure 2 Explain the NAS security setup process defined by the existing protocol.
[0149] Figure 2 This is a schematic diagram of a NAS security setup process. From Figure 2 As can be seen, establishing NAS security involves the following steps:
[0150] Step 1: The UE sends an initial NAS message to the access and mobility management function network element.
[0151] For example, if the UE does not have a NAS security context, the initial NAS message should only contain plaintext information elements (IEs), that is, the initial NAS message includes the subscription identifier (e.g., SUCI or Globally Unique Temporary Identity (GUTI)), UE security capabilities, ngKSI, etc.
[0152] For example, if the UE has a NAS security context, the initial NAS message sent should include the aforementioned plaintext information elements, as well as the complete initial NAS message encrypted in an encrypted NAS container. If the initial NAS message is protected and the access and mobility management function (AMF) network element has the same security context, steps 2 to 4 below can be omitted, and in this case, the AMF network element should use the complete initial NAS message in the NAS container as the message to respond to.
[0153] Step 2: If the Access and Mobility Management (AMF) element cannot obtain the NAS security context locally or in the last visited AMF, or if the AMF fails to perform an integrity check on the received initial NAS message, the AMF element should initiate an authentication process with the UE (e.g., Figure 2 Step 2b is shown in the diagram. This application does not limit the specific authentication process, and will not elaborate on it here.
[0154] For example, if the access and mobility management function (AMU) network element obtains the old NAS security context from the AMU network element last accessed by the UE (e.g., Figure 2In step 2a), as shown, if the AMF can decipher the NAS container with the same security context and obtain the initial NAS message, then steps 2b to 4 can be omitted. If the Access and Mobility Management Function (AMF) element obtains the new K_AMF from the last accessed AMF element (which received keyAmfChangeInd), then step 2b can be omitted.
[0155] Step 3: If UE authentication is successful, the access and mobility management function network element should send a NAS security mode command message (NAS SMC).
[0156] If the initial NAS message is protected but fails the integrity check (e.g., due to a MAC failure or the access and mobility management function (AM) element being unable to find the security context to use), or the AM element is unable to decrypt the complete initial NAS message in the NAS container (e.g., due to receiving "keyAmfChangeInd" from the last accessed AM element), then the AM element should include a flag in the NAS security mode command message requesting the UE to send the complete initial NAS message in the NAS security mode complete message.
[0157] Step 4: The UE should send a NAS secure mode completion message to the Access and Mobility Management Function (AMS) network element in response to the NAS secure mode command message. The NAS secure mode completion message should be encrypted and its integrity protected. Furthermore, if the AMS network element requested or the UE sent an unprotected initial NAS message, the NAS secure mode completion message should include the complete initial NAS message from the NAS container. The AMS network element should use the complete initial NAS message from the NAS container as the message to respond to.
[0158] Step 5: The Access and Mobility Management (AMS) network element should send a response to the initial NAS message. This message should be encrypted and its integrity protected.
[0159] 5. Homomorphic Encryption and Privacy Computation: Data is one of the five major factors of production in the digital society. With the convergence of communication and sensing, sensing, as an inherent capability of future communication networks, provides a wealth of data to intelligent networks by sensing the network's own state, surrounding environment, and user / device behavior. From the perspective of data value mining, the network is both a producer and provider of data, offering trusted data services to various intelligent applications, and a consumer of network data, improving network performance and operational efficiency through data-driven intelligent applications.
[0160] In future communication networks, computing resources will be distributed across various infrastructures, including central clouds, edge clouds, network devices, and even terminal devices. These computing resources, along with the artificial intelligence algorithms or specific functional applications attached to them, will not only serve the network or devices themselves to improve performance and optimize network operations, but will also be exposed to upper-layer applications through a unified interface. Nodes in the communication network infrastructure will provide additional computing capabilities in addition to basic connectivity.
[0161] Homomorphic encryption (HE) is a technology that aims to perform computational processing on ciphertext data without exposing the plaintext data, thereby enabling data value mining while providing privacy protection.
[0162] Figure 3 This is a schematic diagram of a data processing procedure based on homomorphic encryption technology. For example... Figure 3 As shown, plaintext data m is homomorphically encrypted to obtain ciphertext data c = E. pk (m), and this encrypted data is computed using homomorphic computation C. f Afterwards, the encrypted result was obtained. The result obtained by homomorphic decryption of the ciphertext is the same as the plaintext result f(m) obtained by calculating m using the plaintext calculation function f.
[0163] This application does not impose any restrictions on the encryption key used in the homomorphic encryption process. For example, homomorphic encryption can be fully homomorphic encryption (FHE), asymmetric encryption or symmetric encryption, as long as the ciphertext has a certain algebraic structure; or in other words, the ciphertext has homomorphic properties.
[0164] 6. Homomorphic Encryption Process: This includes homomorphic key generation (HE.Keygen), homomorphic encryption (HE.Enc), homomorphic decryption (HE.Dec), and homomorphic evaluation (HE.Eval). Homomorphic evaluation can also be called homomorphic analysis or homomorphic evaluation. For example, homomorphic encryption can be abbreviated as HE = (HE.Keygen, HE.Enc, HE.Dec, HE.Eval), meaning HE consists of four algorithmic parts.
[0165] To facilitate understanding, the following is a simple introduction to the various stages of the homomorphic encryption process, using an asymmetric encryption scheme as an example (where n is a security parameter):
[0166] (1) Key generation: (pk, evk, sk) ← HE.Keygen(1 n The function outputs a public key (pk), a homomorphic evaluation key (evk), and a private key (sk), where the public key is abbreviated as pk, and pk serves as the homomorphic encryption key K. enc =pk; Homomorphic evaluation key abbreviation K eval The homomorphic evaluation key can also be called the homomorphic computation key; the private key is abbreviated as sk, and sk serves as the homomorphic decryption key K. dec =sk.
[0167] Figure 4 This is a schematic diagram of homomorphic key generation. For example... Figure 4 As shown, the key generation device can generate homomorphic keys based on key materials and a key generator, wherein the key materials include the parameters required to generate the homomorphic keys. Figure 4 As shown, the key generation device inputs key materials to the key generator and outputs a homomorphic key, which may include a homomorphic encryption key K. enc Decryption key K dec and compute key K eval The key material can be generated by the key generation device itself or obtained from other devices. This application does not impose any restrictions on the source of the key material.
[0168] It should be noted that, Figure 4 The key generation device shown is a device that includes a key generator, which can be understood as a processing unit within the key generation device, used to generate homomorphic keys. The key generation device may also include a communication unit, a storage unit, etc. For example, after generating a homomorphic key through the key generator, the key generation device can store the homomorphic key in the storage unit. This allows the key generation device to directly retrieve the homomorphic key from the storage unit when it needs to perform related homomorphic processing based on the homomorphic key, eliminating the need for real-time homomorphic key generation and reducing the latency of the key generation device in obtaining the homomorphic key.
[0169] For example, homomorphic key generation device A generates homomorphic encryption key K. enc Homomorphic computation key K eval Homomorphic decryption key K dec Among them, the homomorphic encryption key K enc Send the homomorphic computing key K to homomorphic encryption device B. eval Homomorphic decryption key K is sent to homomorphic computing device C. dec Send to homomorphic decryption device D.
[0170] In a homomorphic encryption task, multiple homomorphic encryption devices can encrypt data from different sources, and multiple homomorphic computing devices can perform homomorphic computations. These multiple homomorphic computing devices can perform homomorphic computations in a single-hop manner, for example, each of the multiple homomorphic computing devices performs homomorphic computations and outputs the corresponding computation results, and the management device determines the homomorphic computation result based on the outputs of the multiple homomorphic computing devices; or, the multiple homomorphic computing devices can perform homomorphic computations in a multi-hop manner, for example, the multiple homomorphic computing devices perform homomorphic computations sequentially, the computation result output by the previous homomorphic computing device is input into the next homomorphic computing device, and the computation result output by the last homomorphic computing device is used as the homomorphic computation result.
[0171] A homomorphic encryption task can also have multiple homomorphic decryption devices. The decryption result can be given to multiple data-using devices. Depending on the key deployment, the homomorphic decryption device and the data-using device can be the same or different entities. The keys of multiple homomorphic encryption devices in a homomorphic encryption task can be the same or different.
[0172] (2) Homomorphic encryption: c←HE.Enc pk (m). Homomorphic encryption devices use homomorphic encryption keys K. enc =pk, the homomorphic encryption process is to encrypt a single bit plaintext message m∈{0,1} into ciphertext c.
[0173] Figure 5 This is a schematic diagram of a homomorphic encryption process. For example... Figure 5 As shown, homomorphic encryption devices can be based on homomorphic encryption key K. enc Encrypt plaintext m into ciphertext c, such as Figure 5 As shown, the homomorphic encryption device inputs plaintext m to the homomorphic encryptor, and the homomorphic encryptor uses the homomorphic encryption key K. enc The plaintext m is encrypted to output ciphertext c. The plaintext m can be generated by the homomorphic encryption device itself or obtained from other devices; this application does not impose any restrictions on the source of the plaintext m.
[0174] It should be noted that, Figure 5The homomorphic encryption device shown is a device that includes a homomorphic encryptor, which can be understood as a processing unit within the homomorphic encryption device, used to perform homomorphic encryption. The homomorphic encryption device may also include a communication unit, a storage unit, etc. For example, after generating ciphertext through the homomorphic encryptor, the homomorphic encryption device can store the ciphertext in the storage unit. This allows the homomorphic encryption device to directly retrieve the ciphertext from the storage unit when it needs to process it subsequently (e.g., to transmit the ciphertext to other devices), without needing to generate the ciphertext in real time, thus reducing the latency of the homomorphic encryption device in retrieving the ciphertext.
[0175] (3) Homomorphic decryption: m←HE.Dec sk (c) The homomorphic decryption device uses the homomorphic decryption key K. dec =sk, the homomorphic decryption process is to decrypt the ciphertext c and restore it to the plaintext message m∈{0,1}.
[0176] Figure 6 This is a schematic diagram of a homomorphic decryption process. For example... Figure 6 As shown, the homomorphic decryption device can be based on the decryption key K. dec Restore the ciphertext c to plaintext m, such as Figure 6 As shown, the homomorphic decryption device inputs the ciphertext c to the homomorphic decryptor, and the homomorphic decryptor uses the decryption key K. dec Decrypt the ciphertext c and output the plaintext m.
[0177] It should be noted that, Figure 6 The homomorphic decryption device shown is a device that includes a homomorphic decryptor, which can be understood as a processing unit within the homomorphic decryption device, used to perform homomorphic decryption. The homomorphic decryption device may also include a communication unit, a storage unit, etc. For example, after generating plaintext m through the homomorphic decryptor, the homomorphic decryption device can store the plaintext m in the storage unit. This allows the homomorphic decryption device to directly retrieve the plaintext from the storage unit when it needs to process the plaintext (e.g., transmit the plaintext to other devices), without needing to generate the plaintext in real time, thus reducing the latency of the homomorphic decryption device in obtaining the plaintext.
[0178] (4) Homomorphic computation: c f ←HE.Eval evk (f,c1,…,c l This can also be called homomorphic evaluation. The homomorphic computation process is based on the input ciphertext c1,…,c l Homomorphic computation key K evel Homomorphic computing devices (which may be called HEcalc or HEeval) perform homomorphic computation of the function f: {0,1} under ciphertext. l →{0,1}, obtain the output ciphertext c of the homomorphic computation. f .
[0179] Figure 7 This is a schematic diagram of a homomorphic computation process. For example... Figure 7 As shown, homomorphic computing devices can be based on computing key K eval The input ciphertexts c1, ..., c l Homomorphic computation yields c f ,like Figure 7 As shown, the homomorphic computing device inputs ciphertext c1,…,c l To the homomorphic calculator, the key K is calculated within the homomorphic calculator. eval For ciphertext c1, ..., c l Perform calculations and output the ciphertext c. f Homomorphic calculators can also be called homomorphic calculation circuits, homomorphic calculation functions, etc.
[0180] It should be noted that, Figure 7 The homomorphic computing device shown is a device that includes a homomorphic calculator, which can be understood as a processing unit within the homomorphic computing device, used to perform homomorphic computation. The homomorphic computing device may also include a communication unit, a storage unit, etc. For example, the homomorphic computing device generates ciphertext c through the homomorphic calculator. f Then, the ciphertext c can be... f Stored in a storage unit to support subsequent homomorphic computing devices that need to process the ciphertext c. f When processing (e.g., when processing the ciphertext c) f The encrypted text can be directly retrieved from the storage unit when transmitted to other devices. f No need for real-time ciphertext processing f This reduces the need for homomorphic computing devices to obtain ciphertext c. f The time delay.
[0181] The homomorphic computation function f described above represents an arithmetic circuit with addition and multiplication gates over a finite field (galois field, GF). Generally, homomorphic computation HE.Eval is decomposed into multiple fundamental operators, such as homomorphic addition c. add ←HE.Add evk (c1,c2) and homomorphic multiplication c mult ←HE.Mult evk (c1,c2).
[0182] For example, the entire homomorphic encryption scheme HE = (HE.Keygen, HE.Enc, HE.Dec, HE.Eval). The following section combines... Figure 8 Here is a brief introduction to the entire homomorphic encryption scheme.
[0183] Figure 8 This is a schematic diagram of a homomorphic encryption scheme. (For example...) Figure 8 As shown, the ciphertext calculation result, after decryption, is equivalent to the plaintext calculation result.
[0184]
[0185] 7. Bootstrapping Key: Bootstrapping is a special technique for processing ciphertext. After processing, it can "refresh" ciphertext with near-critical noise into a new ciphertext with very low noise. The main method is to transform a high-noise ciphertext... Re-encrypt using the new key k2 to create another fully homomorphic ciphertext. Use the new key k2 to encrypt the old key k1 into ciphertext as well. This refers to the bootstrapping key (BSK). The homomorphic computing device then uses homomorphic computation to establish the corresponding homomorphic decryption circuit. By decrypting the inner ciphertext and restoring it to plaintext, a completely new low-noise HE ciphertext under a new key can be obtained.
[0186] Bootstrap keys, as a type of homomorphic computing key, need to be generated by a key generation device and distributed to homomorphic computing devices. Besides bootstrap keys, another type of homomorphic computing key is the key switching key (KSK). Taking the RLWE homomorphic encryption scheme with a one-party key as an example, assuming the ciphertext... The corresponding key is Homomorphic computation of multiplication of two ciphertexts ct and ct' The corresponding key is After ciphertext multiplication, not only does the ciphertext size expand, but the key also exhibits exponential cross terms. After each ciphertext computation, a relinearization key (i.e., a key transformation key) is needed to convert the ciphertext product into a new ciphertext with the same dimension as the original ciphertext, and eliminate the corresponding key cross terms before proceeding to the next layer of circuit computation.
[0187] 8. Advanced Encryption Standard (AES) Round Key: The AES encryption algorithm uses a fixed-length master key (128 bits, 192 bits, or 256 bits). For example, if the master key length of the AES encryption algorithm is 128 bits, the AES encryption algorithm is denoted as AES-128; similarly, if the master key length of the AES encryption algorithm is 192 bits, the AES encryption algorithm is denoted as AES-192; and if the master key length of the AES encryption algorithm is 256 bits, the AES encryption algorithm is denoted as AES-256.
[0188] The AES-128, AES-192, and AES-256 mentioned above are symmetric block cipher algorithms. It should be understood that symmetric block cipher algorithms can also include other algorithms besides AES-128, AES-192, or AES-256, such as the Snow encryption algorithm, which will not be illustrated here. The following explanation uses AES as an example of a symmetric block cipher algorithm.
[0189] AES encryption requires multiple round keys. These round keys are generated from the master key through a key scheduling process. The master key can also be called the original key; this application does not impose any restrictions on the key name.
[0190] For example, AES-128 (using a 128-bit master key) requires 11 round keys, AES-192 requires 13 round keys, and AES-256 requires 15 round keys.
[0191] After obtaining the round key, a round key addition operation is performed in each round of AES encryption. This round key addition operation involves XORing the current plaintext data (a 4x4 byte matrix) with the round key byte by byte. The round key addition operation is performed at the beginning of each encryption round and at the end of each round. Specifically:
[0192] Before the first round of encryption begins, a round key addition operation is performed, which XORs the initial plaintext with the first round key.
[0193] At the end of each round of encryption, the round key is incremented again using the round key corresponding to that round.
[0194] In the final round of encryption, byte substitution, row shifting, and column obfuscation are not performed; only the round key is added.
[0195] To facilitate understanding, the AES round key generation process will be described using AES-128 as an example. For instance, the process of obtaining the round key through key expansion includes the following steps:
[0196] Step 1.1: Divide the original 128-bit key into four 32-bit words in groups of four bytes. These four 32-bit words are denoted as w[0], w[1], w[2] and w[3].
[0197] As shown above, the AES-128 encryption process requires 11 round keys, each of which is 128 bits. Therefore, a total of 44 32-bit words need to be generated to form the 11 128-bit round keys. For example, the 44 32-bit words are denoted as w[i], where i ranges from 0 to 43. For i values of 0, 1, 2, and 3, w[0], w[1], w[2], and w[3] are obtained by dividing the original 128-bit key. For i values of 4 to 43, w[i] needs to be calculated.
[0198] Step 2.1: Calculate w[i]. 4≤i≤43.
[0199] When i is a multiple of 4, w[i] satisfies the following formula:
[0200]
[0201] In the above equation (1-1), the symbol This indicates the XOR operation. T represents the transformation function, which includes byte substitution, rotWord, and the XOR operation between the byte substitution and the round constant (rcon).
[0202] The circular shift operation described above shifts four bytes in a 32-bit byte to the left by one byte. For example, the byte sequence [a,b,c,d] is transformed into [b,c,d,a] after the circular shift operation.
[0203] The byte substitution operation described above is implemented through a substitution box (S-box), which is a predefined 16x16 byte lookup table used to replace one byte with another. This operation is non-linear, which improves the security of the password.
[0204] The round constant (rcon) mentioned above is a round-related constant used to introduce diffusion during key expansion.
[0205] When the value of is not a multiple of 4, w[i] satisfies the following formula:
[0206]
[0207] Step 3.1: Generate round keys.
[0208] Each round key consists of four 32-bit words. By dividing the 44 32-bit words w[0] to w
[43] generated in steps 1.1 and 2.1 above into groups of four in order, 11 round keys can be obtained.
[0209] To make it easier to understand, the key expansion process is briefly described below.
[0210] Assume the original 128-bit key is k = [k0, k1, ..., k 15 The original 128-bit key is divided into four 32-bit words: w[0] = [k0, k1, k2, k3], w[1] = [k4, k5, k6, k7], w[2] = [k8, k9, k3], and w[3] = [k4, k5, k6, k7]. 10 ,k 11 ],w[3]=[k 12 ,k 13 ,k 14 ,k 15 ].
[0211] When calculating w[4], since i = 4 is a multiple of 4, then The process of calculating w[4] is as follows: first, w[3] is cyclically shifted to obtain w. temp Then for w temp Byte substitution yields w temp2 Then w temp2 XORing with the round constant (rcon) yields T(w[3]), and finally...
[0212] For example, suppose the initial 128-bit AES key is: 3C,A1,OB,21,57,FO,19,16,90,2E,13,80,AC,C1,07,BD. Then the four 32-bit words w[0] = [3C,A1,OB,21], w[1] = [57,FO,19,16], w[2] = [90,2E,13,80], w[3] = [AC,C1,07,BD].
[0213] The round keys for the first round are w[4], w[5], w[6], and w[7]. Since 4 is a multiple of 4, therefore:
[0214] The calculation steps for T(w[3]) are as follows:
[0215] w[3]=[AC,C1,07,BD] is obtained by cyclic shifting w temp =[C1,07,BD,AC];
[0216] w temp = [C1, 07, BD, AC] as input to the S-box, output is w temp2 =[78,C5,7A,91]. This w temp2=[78,C5,7A,91] is XORed with the first round's constant Rconj[1] to obtain T(w[3]) =[79,C5,7A,91]. Therefore
[0217] The calculations of w[5], w[6] and w[7] are as follows:
[0218]
[0219] Therefore, the key for the first round is 45,64,71,B0,12,94,68,A6,82,BA,7B,26,2E,7B,7C,9B.
[0220] 9. Trans-chipper Operation: The trans-chipper operation involved in this application can be understood as converting ciphertext in a non-homomorphic encryption state into ciphertext in a homomorphic encryption state; or, converting ciphertext in a homomorphic encryption state into ciphertext in a non-homomorphic encryption state. For example, the process by which the first communication device homomorphically encrypts the first ciphertext to generate the second ciphertext in the embodiments mentioned below can be called a trans-chipper operation, wherein the first ciphertext is ciphertext encrypted by the first security algorithm and belongs to the non-homomorphic encryption state, and the second ciphertext is ciphertext encrypted by homomorphism and belongs to the homomorphic encryption state.
[0221] It should be understood that the above-described conversion operation between ciphertext in a non-homomorphic encryption state and ciphertext in a homomorphic encryption state is called a ciphertext conversion operation, which is only an example and does not constitute any limitation on the scope of protection of this application. For example, it can also be called proxy re-encryption (PRE), conversion operation between non-homomorphic encrypted ciphertext and homomorphic encrypted ciphertext, ciphertext conversion, or first operation, etc.
[0222] The aforementioned "ciphertext in homomorphic encryption state" can also be described as "in homomorphic ciphertext state", "in ciphertext state corresponding to homomorphic encryption algorithm", or "in homomorphic state", etc. In this application, the description of the state encrypted by homomorphic encryption algorithm is not limited in any way. In the following text, for the sake of convenience, the state encrypted by homomorphic encryption algorithm is uniformly described as "in homomorphic ciphertext state".
[0223] The above text combined Figure 1This paper briefly introduces the application scenarios of the communication method provided in the embodiments of this application, and describes the basic concepts that may be involved in the embodiments of this application. Among these basic concepts, the homomorphic encryption process and its security are introduced. As can be seen from the above, homomorphic encryption technology can still perform data computation and generate calculation results even when the data is in a ciphertext state. Furthermore, since homomorphic encryption and ciphertext computation are the same execution method, any computational operation can be performed. Therefore, AES encryption or decryption operations can also be performed under homomorphic encryption. This process of performing AES encryption and decryption under homomorphic encryption ciphertext can be understood as a type of encryption conversion, that is, superimposing AES encryption and decryption operations on homomorphically encrypted ciphertext. For ease of understanding, the following will combine... Figure 9 This section describes the process of declassification.
[0224] In combination Figure 9 Before explaining the AES encryption and decryption operations superimposed on homomorphically encrypted ciphertext, a brief introduction to the symbolic representations of plaintext, ciphertext, key, and calculation results involved in this application is provided:
[0225] Plaintext: m, for example, the first data in the following embodiment can be denoted as m.
[0226] Symmetric encryption operation: Enc AES (), for example, encryption based on the second security algorithm in the following embodiments can be denoted as Enc. AES ();
[0227] AES Ciphertext: Ciphertext obtained by encrypting using the AES algorithm, which can be denoted as Enc. AES (m), or simply c, for example, the second ciphertext in the following embodiment can be denoted as Enc. AES (m), or c;
[0228] Homomorphic (HE) encryption operation: Enc HE (), for example, encryption based on the first security algorithm in the following embodiments can be denoted as Enc. HE ();
[0229] Homomorphic computation operation: Eval HE ();
[0230] Homomorphic AES ciphertext: Ciphertext obtained by homomorphically encrypting AES ciphertext can be denoted as HE+AES ciphertext, or simply Enc. HE (c);
[0231] Homomorphic ciphertext: Ciphertext obtained by encryption using a homomorphic algorithm, which can be denoted as Enc. HE (m);
[0232] Calculation result: result.
[0233] It should be understood that the symbolic representations of plaintext, ciphertext, key, and calculation results described above are merely examples and do not constitute any limitation on the scope of protection of this application. Plaintext, ciphertext, key, and calculation results in this application can also be represented in other ways, and no specific representation is limited in this application. For example, a symmetric encryption operation can also be denoted as Enc. snow (); For example, homomorphic encryption operations can also be denoted as Enc FHE (), etc., will not be listed here.
[0234] Figure 9 This is a schematic diagram of the encryption process. For example... Figure 9 As shown, the declassification process includes the following steps:
[0235] Step 1.2: The client uploads the ciphertext c and the homomorphically encrypted key k to the server. Here, key k is the AES key, and the homomorphically encrypted key k can be denoted as Enc. HE (k). For example, the client uses AES key k to encrypt user data m to obtain ciphertext c, and encrypts key k based on a homomorphic encryption algorithm to obtain Enc. HE (k).
[0236] Step 2.2: The server uses a homomorphic encryption algorithm to encrypt the ciphertext c, generating a two-layer encrypted ciphertext Enc (HE+AES). HE (c)
[0237] Step 3.2: The server uses the key Enc in the homomorphic encryption state. HE (k), for the ciphertext Enc in the homomorphic encryption state HE (c) Perform AES decryption calculation.
[0238] For example, Eval HE (E -1 ) = Eval HE (AES -1 (k,c)) generates Enc HE (m), Enc HE (m) is in the ciphertext state corresponding to homomorphic encryption.
[0239] Step 4.2: Process the ciphertext Enc HE (m) performs homomorphic computation to obtain the computation result in an encrypted state.
[0240] but Figure 9 During the encryption process shown, the server needs to process the ciphertext Enc HE(c) During the decryption process, based on steps 1.1 to 3.4 described above, the Enc in the homomorphic ciphertext state is... HE (k) Performing key expansion to generate round keys has high computational complexity and prolongs decryption time.
[0241] This application provides a communication method for applying homomorphic encryption technology in communication networks to protect the privacy of communication data and improve the security of communication data.
[0242] It should be understood that the embodiments shown below do not particularly limit the specific structure of the execution subject of the method provided in the embodiments of this application, as long as it is possible to communicate according to the method provided in the embodiments of this application by running a program that records the code of the method provided in the embodiments of this application. For example, the execution subject of the method provided in the embodiments of this application may be a network element or device; or, it may be a functional module in a network element or device that can call and execute a program.
[0243] Figure 10 This is a schematic flowchart illustrating a communication method provided in this application. It includes the following steps:
[0244] S1010, the first communication device sends the first ciphertext to the first network element, and correspondingly, the first network element receives the first ciphertext from the first communication device.
[0245] For example, the first ciphertext is obtained by encrypting the second ciphertext using a first security algorithm. The second ciphertext is obtained by encrypting the first data using N first keys corresponding to the second security algorithm, where N is an integer greater than 1.
[0246] For example, the first data includes, but is not limited to: AI perception data, point cloud data, UAV data, or computational data.
[0247] This application does not limit the specific type of the first data. It can be data that the second communication device requests the first network element to process. The first data has high security protection requirements, so as to achieve the processing of the first data without the network side knowing the first data in plaintext state.
[0248] For example, the first communication device sending the first ciphertext to the first network element can be: the first communication device sending a data analysis request message to the first network element, the data analysis request message carrying the first ciphertext.
[0249] Optionally, the data analysis request message may also carry an identifier of a second communication device, which indicates that the communication device for the currently requested data analysis service is the second communication device. Optionally, the data analysis request message may also carry first indication information, which indicates that the first ciphertext is ciphertext encrypted using an encryption key corresponding to the first security algorithm.
[0250] In this application, the first security algorithm can be a homomorphic encryption algorithm. A description of homomorphic encryption algorithms can be found in the basic concepts section above, and will not be repeated here. For example, the ciphertext encrypted by this first security algorithm can be processed in its ciphertext state.
[0251] The aforementioned ciphertext encrypted with the first security algorithm can also be described as being processed in the ciphertext state: ciphertext encrypted with the first security algorithm is homomorphic, and the ciphertext after homomorphic encryption can be processed in the ciphertext state, etc.
[0252] Furthermore, the first security algorithm in this application can be a security algorithm included in a first security context, and the encryption key included in the first security context can be called the first security key. Therefore, the first security algorithm in this application can also be described as a first security context, a first security key, or a homomorphic security algorithm, etc. When the first security algorithm is described as a first security context, it means that the corresponding steps are performed based on the security algorithm and / or security key included in the first security context; when the first security algorithm is described as a first security key, it means that the corresponding steps are performed based on the first security key and / or the security algorithm corresponding to the first security key. This application does not limit the name of the first security algorithm; the ciphertext encrypted based on the first security algorithm only needs to be processed in the ciphertext state.
[0253] Furthermore, the homomorphic encryption involved in this application can be fully homomorphic encryption or non-fully homomorphic encryption (e.g., partially homomorphic encryption (PHE) or leveled fully homomorphic encryption, etc.), and no specific homomorphic encryption method is limited.
[0254] For example, the first security algorithm involved in this application includes, but is not limited to:
[0255] The following algorithms are used: RSA, ElGamal, Paillier, Boneh-Goh-Nissim, Gentry, BGV, BFV, GSW, THEW, Fast HEM Cryptosystem with Worst-case to Average-case Reductions (FHEW), and the Cheon-Kim-Kim-Song Homomorphic Encryption Scheme (CKKS). This application does not impose any limitations on the first security algorithm upon which homomorphic encryption is based; for ease of description, the CKKS algorithm will be used as an example below.
[0256] In this application, the first security algorithm is a security algorithm known to the first communication device. For example, the first communication device generates a first security context corresponding to the first security algorithm based on the instruction of the first network element or the second communication device.
[0257] In this application, the second security algorithm can be a symmetric block cipher algorithm. For example, the second security algorithm can be AES encryption algorithm, Snow encryption algorithm, or other symmetric block cipher algorithms. For ease of description, the following description uses AES encryption algorithm as an example.
[0258] Furthermore, the second security algorithm in this application can be a security algorithm included in a second security context, and the encryption key included in the second security context can be called the second security key, which can be understood as the master key of the second security algorithm. Therefore, the second security algorithm in this application can also be described as a second security context, a second security key, or a block security algorithm, etc. When the second security algorithm is described as a second security context, it means that the corresponding steps are performed based on the security algorithm and / or security key included in the second security context; when the second security algorithm is described as a second security key, it means that the corresponding steps are performed based on the second security key and / or the security algorithm corresponding to the second security key. This application does not limit the name of the second security algorithm; multiple keys are required during the encryption and / or decryption process based on the second security algorithm.
[0259] In this application, the second security algorithm is a security algorithm negotiated and determined between the second communication device and the first network element. For example, the second security context corresponding to the second security algorithm is negotiated and determined between the second communication device and the first network element.
[0260] The communication method in this application can be executed by a first communication device, a component within the first communication device, or a logic module or software capable of implementing all or part of the functions of the first communication device. The component within the first communication device can be a module, processor, chip, or chip system, etc. The communication module within the first communication device can be a circuit or chip responsible for communication functions within the first communication device. This circuit or chip can be a modem chip (also known as a baseband chip), or a SoC chip or SIP chip containing a modem core.
[0261] Furthermore, the first communication device in this application can be one device or multiple devices. For example, the first communication device includes multiple devices, and different devices can perform different steps. For instance, the first communication device includes device #1 and device #2, where device #1 is used to receive the first ciphertext, and device #2 is used to encrypt the first ciphertext. That is to say, the function of the first communication device may be performed separately by multiple devices. For ease of description, the following description uses the first communication device performing the communication method as an example.
[0262] For example, the first communication device can be an access network device or a component within an access network device; alternatively, the first communication device can be a network node or a component within a network node. This application does not impose any specific limitations on the form of the first communication device, as long as it achieves the corresponding function. For instance, in this application, the first communication device can be a RAN, RAN-CU, or a security gateway, etc., a node capable of implementing homomorphic encryption.
[0263] The communication method in this application can be executed by a first network element, a component within the first network element, or a logic module or software capable of implementing all or part of the functions of the first network element. Components within the first network element can be modules, processors, chips, or chip systems, etc. The communication module within the first network element can be a circuit or chip responsible for communication functions within the first network element. This circuit or chip can be a modem chip (also known as a baseband chip), or a SoC chip or SIP chip containing a modem core.
[0264] Furthermore, in this application, the first network element can be one device or multiple devices. For example, the first network element may be AMF and NWDAF. That is to say, the function of the first network element may be performed by multiple network elements respectively. For ease of description, the following description uses the execution of the communication method by the first network element as an example.
[0265] The N first keys corresponding to the aforementioned second security algorithm, where N is an integer greater than 1, can be understood as: multiple keys are required during the encryption and decryption process based on this second security algorithm. These multiple first keys can be generated from the master key corresponding to this second security algorithm. The master key can also be called the original key.
[0266] For example, if the second security algorithm is the AES-128 encryption algorithm described in the basic concepts section above, then the N first keys can be the 11 round keys corresponding to the AES-128 encryption algorithm introduced in the basic concepts section above. The generation process of these 11 round keys can be referred to the description in the basic concepts section above, and will not be repeated here. The N first keys can be denoted as rk1, rk2, rk3…rkN.
[0267] For example, the first ciphertext is obtained by the first communication device encrypting the second ciphertext, wherein the second ciphertext is obtained by the second communication device encrypting the first data based on N first keys corresponding to the second security algorithm, and the first ciphertext is obtained by the first communication device encrypting the second ciphertext based on the first security algorithm. Figure 10 The method flow shown may also include the following steps S1001 to S1004:
[0268] S1001, the second communication device encrypts the first data based on N first keys corresponding to the second security algorithm to obtain the second ciphertext.
[0269] The communication method in this application can be executed by a second communication device, a component within the second communication device, or a logic module or software capable of implementing all or part of the functions of the second communication device. The component in the second communication device can be a module, processor, chip, or chip system, etc., in the first communication device. The communication module in the second communication device can be a circuit or chip responsible for communication functions within the second communication device. This circuit or chip can be a modem chip (also known as a baseband chip), or a SoC chip or SIP chip containing a modem core.
[0270] Furthermore, the second communication device in this application can be a single device or multiple devices. For example, the second communication device may include multiple devices, each capable of performing different steps. For instance, the second communication device may include device #3 and device #4, where device #3 generates N second keys and a second ciphertext, and device #4 sends the second ciphertext to the first communication device. In other words, the function of the second communication device may be performed separately by multiple devices. For ease of description, the following explanation uses the second communication device performing the communication method as an example.
[0271] For example, the second communication device encrypts the first data based on N first keys corresponding to the second security algorithm to obtain the second ciphertext. This can be achieved by the second communication device encrypting the first data separately using each of the N first keys to obtain the second ciphertext. The first data can be plaintext data to be processed by the second communication device, or it can be plaintext data to be processed by another device, which can send the first data to be analyzed to the second communication device. This application does not limit the method by which the second communication device determines the first data.
[0272] For example, the first data may include M data groups. The second communication device encrypts each of the M data groups based on N first keys to obtain M ciphertexts. These M ciphertexts are then combined to obtain the second ciphertext. For instance, the first data is denoted as m, the N first keys are denoted as rk1, rk2, rk3…rkN, and taking the AES algorithm as an example, the second security algorithm is denoted as AES, and the encryption operation based on the second security algorithm is denoted as Enc. AES The first data is divided into M data groups (m1, m2, m3…mM). The second communication device encrypts m1 based on rk1, rk2, rk3…rkN to obtain Enc. AES (m1), and then based on rk1, rk2, rk3…rkN, m2, m3…mM are encrypted sequentially to obtain Enc AES (m2), Enc AES (m3)...Enc AES (mM), finally Enc AES (m1), Enc AES (m2), Enc AES (m3)...Enc AES (mM) merged to obtain Enc AES (m), the Enc AES (m) is the second ciphertext mentioned above.
[0273] It should be understood that the specific process by which the second communication device encrypts the first data based on N first keys to obtain the second ciphertext is not described in detail in this application. For details, please refer to the description of encrypting plaintext data based on the AES encryption algorithm in the current related technologies.
[0274] Optionally, before encrypting the first data based on the N first keys corresponding to the second security algorithm, the second communication device has already determined the second security algorithm. For example, the second communication device can negotiate and determine the required second security algorithm with the first network element. Figure 10 The method flow shown may also include:
[0275] S1002, the second communication device and the first network element negotiate and determine the second security algorithm.
[0276] For example, the second communication device and the first network element negotiate to determine the second security algorithm, including: the second communication device and the first network element negotiate to determine the algorithm type and / or the algorithm length of the second security algorithm. For example, the second communication device and the first network element negotiate to determine that the second security algorithm is a symmetric block encryption algorithm; or, for example, the second communication device and the first network element negotiate to determine that the algorithm length corresponding to the second security algorithm is 128 bits, 192 bits, or 256 bits, etc.
[0277] For example, the negotiation between the second communication device and the first network element to determine the second security algorithm may be as follows:
[0278] The first network element sends a NAS SMC to the second communication device. The second communication device selects an appropriate key generation algorithm and key parameters. Based on this key generation algorithm and key parameters, the first network element and the second communication device can determine the second security context corresponding to the second security algorithm. Furthermore, the first network element can also indirectly negotiate keys with the second communication device through other network elements (such as the RAN). The purpose of key negotiation is to ensure that both the second communication device and the first network element have the same key, which is used for symmetric block encryption (e.g., AES encryption, Snow encryption, etc.) of the data from the second communication device.
[0279] After the first network element and the second communication device negotiate and determine the key generation algorithm and key parameters, the first network element and the second communication device can generate a second security context.
[0280] For example, the second communication device generates a symmetric key as the key in the second security context according to the negotiated parameters. One symmetric key generation method is: Symmetric key = KDF(downlink count, Alg ID, Kamf), where Kamf represents the original key used to generate the symmetric key, Alg ID represents the algorithm ID, and downlink count represents the count value. KDF is a key derivation function.
[0281] For example, the first network element may obtain the second security context in the following ways:
[0282] The first network element can generate a symmetric key as the key in the second security context based on the negotiated parameters. The method by which the first network element generates the second security context can be the same as the method described above for the second communication device to generate the second security context, and will not be repeated here; or...
[0283] The first network element can provide the parameters required to generate the second security context to other network elements, which will then generate the second security context and provide it to the first network element.
[0284] The second security context includes at least one of the following: the second security algorithm, the encryption key corresponding to the second security algorithm, the identifier of the encryption key corresponding to the second security algorithm, or the identifier of the second communication device.
[0285] Optionally, the first network element can be a NAS network element, such as NAS NF, which is a network element capable of establishing a secure NAS connection with the second communication device. The second security context can be a non-access stratum security context, which is stored in both the second communication device and the first network element. In this scenario, the process of negotiating and determining the second security context between the second communication device and the core network element (such as the first network element) can refer to the description of NAS security establishment in the basic concepts section above, as described above. Figure 2 The NAS security mode command message and NAS security mode completion message shown carry parameters for generating a second security context, which supports the generation of a second security context between the second communication device and the first network element. This will not be elaborated here.
[0286] By way of example and not limitation, the second communication device in this application may determine the second security algorithm in a manner other than negotiating with the first network element. For example, the second security algorithm may be pre-configured, and the second communication device and the first network element may determine the second security algorithm based on pre-configured information.
[0287] For example, the protocol predefines or the management device preconfigures the algorithm type and / or algorithm length of the symmetric block cipher used between the second communication device and the first network element. For instance, the management device preconfigures a policy for data transmission between the second communication device and the first network element, which instructs the symmetric block cipher to use the AES-128 algorithm. The second communication device and the first network element encrypt or decrypt the data transmitted between them based on the AES-128 algorithm according to this policy. Alternatively, the protocol may specify that the second communication device and the first network element use the AES-128 algorithm to encrypt or decrypt the data transmitted between them.
[0288] Optionally, during the negotiation process between the second communication device and the first network element to determine the second security algorithm, they may also negotiate to determine the aforementioned first security algorithm, meaning that the negotiation process corresponding to the second security algorithm is the same as the negotiation process corresponding to the first security algorithm. Alternatively, the negotiation process corresponding to the second security algorithm may be different from the negotiation process corresponding to the first security algorithm.
[0289] For example, the second communication device and the first network element negotiate the aforementioned second security algorithm and the first security algorithm through an algorithm negotiation process. After the first network element determines the first security algorithm through the negotiation process, it can notify the first communication device of the information related to the first security algorithm. This information includes at least one of the following: the identifier of the first security algorithm, the encryption key corresponding to the first security algorithm, the identifier of the encryption key corresponding to the first security algorithm, or the identifier of the second communication device.
[0290] It should be understood that after the second communication device determines the second security algorithm, it can determine the number of round keys based on the algorithm length corresponding to the second security algorithm, and execute the round key expansion algorithm to obtain the aforementioned N first keys.
[0291] S1003, the second communication device sends the second ciphertext to the first communication device, and correspondingly, the first communication device receives the second ciphertext from the second communication device.
[0292] For example, the second communication device sending the second ciphertext to the first communication device can be: the second communication device sending message #1 to the first communication device, the message #1 including the second ciphertext. Optionally, message #1 can be used to request the first network element to process data.
[0293] Optionally, including the second ciphertext in message #1 can mean that message #1 includes a NAS container. A NAS container can be understood as any message that needs to be processed by the core network, such as a data plane message. This NAS container includes the second ciphertext; for example, a NAS container in message #1 carries the second ciphertext, which is first data encrypted using a second security algorithm. This second security algorithm can be a symmetric security context, and the NAS container can be called a symmetric encrypted ciphertext container.
[0294] For example, the NAS container included in message #1 in this application may be referred to as a field, information, or payload, etc.
[0295] Optionally, message #1 may also include a first identifier, which indicates a first security algorithm so that the first communication device can encrypt the second ciphertext based on the first security algorithm to obtain the first ciphertext. The first identifier is associated with the first security algorithm. The operation of the first communication device encrypting the second ciphertext based on the first security algorithm can be referred to as encryption or encryption processing.
[0296] The first identifier may be the identifier of the second communication device, the identifier of the service to which the first data belongs, or the identifier of the service area to which the first communication device belongs.
[0297] Here, the first identifier is the identifier of the second communication device, which can be understood as the first communication device performing encryption processing on all data from the second communication device. For example, the first identifier is the UE ID of the second communication device. The second communication device can carry the UE ID in message #1, and the first communication device performs encryption processing on the data of the second communication device identified by the UE ID. Exemplarily, the first communication device can, based on the following... Figure 11 The step S1130 shown establishes the association between the first identifier and the first security algorithm, thereby encrypting the data from the second communication device based on the first identifier and the first security algorithm.
[0298] The first identifier is the identifier of the service to which the first data belongs. This can be understood as the first communication device performing encryption processing on service data of a specific service type, including the type of service to which the first data belongs. For example, if the first identifier is a service ID, the second communication device can carry the service ID in message #1, and the first communication device performs encryption processing on the data of the service identified by the service ID. Alternatively, if the first identifier is a service ID, the second communication device can carry the service ID in message #1, and the first communication device determines the type of service based on the service ID and performs encryption processing on the data of the service belonging to that type. Exemplarily, the first communication device can, based on the following... Figure 11 The step S1130 shown establishes the association between the first identifier and the first security algorithm, thereby encrypting the data of a specific business type based on the first security algorithm based on the first identifier.
[0299] The first identifier is the identifier of the service area to which the first communication device belongs. This can be understood as the first communication device performing encryption processing on the data of communication devices within its service area. For example, the first identifier could be a service area ID. Within this service area, there are communication devices #1 and #2 provided by the first communication device. The second communication device could carry the service area ID in message #1, and the first communication device could perform encryption processing on the data of communication devices within the service area identified by the service area ID. Exemplarily, the first communication device could, based on the following... Figure 11 The step S1130 shown establishes the association between the first identifier and the first security algorithm, thereby encrypting the data of the communication devices in the service area based on the first identifier and the first security algorithm.
[0300] It should be understood that the aforementioned first identifier being at least one of the identifiers of the second communication device, the service to which the first data belongs, or the service area to which the first communication device belongs is merely an example and does not constitute any limitation on the scope of protection of this application. The first identifier may also be in other possible forms, such as a PDU session ID or a global norm-aware pooling identifier (GNAPID); or, for example, a network layer ID, such as a connection ID in Quick UDP internet connections, or an IP address. The first identifier may also be called a service ID or a connection ID, etc., which will not be listed here.
[0301] To facilitate understanding, the following will combine... Figure 11 The process by which the first communication device generates a first security context associated with the first identifier is described, but will not be detailed here.
[0302] Optionally, message #1 can be called a data analysis request message, a business information calculation request message, etc.
[0303] Optionally, message #1 includes instruction information #1, which indicates that the second ciphertext should be homomorphically encrypted.
[0304] After receiving instruction information #1, the first communication device can determine a first security algorithm for encrypting the second ciphertext. For example, after receiving instruction information #1, the first communication device generates a first security context, and then the first communication device can encrypt the second ciphertext based on the first security context to obtain the first ciphertext.
[0305] For example, the above-mentioned instruction information #1 instructing the second ciphertext to be homomorphically encrypted can be understood as: instruction information #1 instructing the first communication device to perform a ciphertext transcryption operation on the received second ciphertext, or instruction information #1 instructing the second ciphertext to have a ciphertext transcryption requirement, etc. In this application, no specific instruction content of instruction information #1 is limited, as long as it can instruct the second ciphertext to be homomorphically encrypted.
[0306] The instruction information #1 in this application includes, but is not limited to, the following possible implementations:
[0307] Method 1.1: Indication information #1 can be a field carried in message #1. For example, indication information #1 can be specific information in message #1 used to indicate control bits, parameters, or bits for homomorphic encryption of the second ciphertext.
[0308] Method 1.2: Instruction information #1 can be the name of message #1. For example, if message #1 is a cipher request message, then after receiving message #1, the first communication device can perform homomorphic encryption on the second ciphertext based on the name of message #1.
[0309] It should be understood that this application does not impose any restrictions on the form of message #1, and any information that can instruct the homomorphic encryption of the second ciphertext is within the protection scope of this application.
[0310] S1004, the first communication device encrypts the second ciphertext based on the first security algorithm to obtain the first ciphertext.
[0311] For example, the first communication device encrypts the second ciphertext based on a first security algorithm, and the process of obtaining the first ciphertext can be understood as a process of encrypting. For example, the second ciphertext can be denoted as Enc. AES (m) or ciphertext c, taking the first security algorithm as a homomorphic encryption algorithm as an example, this first security algorithm is denoted as HE, and the encryption operation based on the first security algorithm can be represented as Enc HE (), then the first ciphertext can be represented as Enc HE (Enc AES (m)), or Enc HE (c). This first ciphertext can be understood as a homomorphic AES ciphertext.
[0312] For example, the first communication device performs homomorphic encryption on the second ciphertext based on a selected homomorphic encryption algorithm. For instance, the first communication device performs homomorphic encryption on the second ciphertext based on the CKKS algorithm, and the resulting first ciphertext is denoted as Enc. HE (c), or, Enc HE (Enc AES (m)). Where m is the first ciphertext, Enc HE () indicates homomorphic encryption. The first communication device may select a homomorphic encryption algorithm based on instructions from the first network element and / or the second communication device, or the homomorphic encryption algorithm selected by the first communication device may be predefined in the protocol. For example, the second communication device may instruct the first communication device to encrypt the second ciphertext using a homomorphic encryption algorithm during the transmission of the second ciphertext to the first communication device; or, for example, the first network element may use a homomorphic encryption algorithm as described below. Figure 11In step S1130, the first communication device is instructed to use a homomorphic encryption algorithm to encrypt data from the second communication device; for example, the protocol specifies that the first communication device uses the CKKS algorithm to encrypt data from the second communication device, etc.
[0313] For example, suppose Enc AES (m) is the encoded polynomial, where encoding is understood as encryption via a second security algorithm, and the polynomial is understood as plaintext, i.e., Enc. AES (m) is the second ciphertext mentioned above. υ is obtained by sampling from χ′, and e0 and e1 are obtained by sampling from χ. Then the ciphertext Enc after homomorphic encryption is... HE (c)=υ·pk+(Enc AES (m)+e0,e1)modq L The ciphertext obtained through encryption is q. L The layer, the ciphertext is q L The complexity of layer-based ciphertext representation is q. L Where χ is the noise distribution, which is a discrete Gaussian distribution on the ring R that is related to the safety level λ, and χ′ is a uniform random distribution on the ring R.
[0314] In this application, the homomorphically encrypted ciphertext can be processed in its ciphertext state; in other words, the data before and after homomorphically encrypted data have the same computational properties. For example, the homomorphically encrypted ciphertext of data a is denoted as Enc. HE (a), the Enc HE (a) Supports processing, meaning the data processing device can directly access Enc HE (a) Process the data to obtain the processing result of data a. The property that supports processing in encrypted form can be called homomorphism.
[0315] It should be noted that the term "homomorphic encryption" used in this application to describe the homomorphic encryption method is merely an example and does not constitute any limitation on the scope of protection of this application. For example, homomorphic encryption can also be called first encryption, privacy encryption, ciphertext computation, circuit computation, or computational encryption, etc.
[0316] It should be understood that this application does not impose any limitations on the specific process of homomorphic encryption, and reference can be made to descriptions of homomorphic encryption in current or future related technologies.
[0317] Furthermore, after receiving the first ciphertext, the first network element can decrypt the first ciphertext based on N second keys. Figure 10 The method flow shown also includes the following steps S1020 and S1030:
[0318] S1020, the first network element obtains N second keys based on N first keys.
[0319] For example, N second keys are obtained by encrypting N first keys using a first security algorithm. These N second keys support the decryption of ciphertext encrypted using both the first and second security algorithms within the ciphertext state corresponding to the first security algorithm. The result is in the ciphertext state corresponding to the first security algorithm and the plaintext state corresponding to the second security algorithm. For instance, these N second keys support the decryption of the aforementioned first ciphertext within the ciphertext state corresponding to the first security algorithm, where the first ciphertext is the ciphertext encrypted using both the first and second security algorithms.
[0320] It should be understood that in this communication method, the first network element directly performs key expansion on the master key in plaintext state to obtain N first keys, and obtains N second keys based on the N first keys. The first network element does not need to perform key expansion on the master key in ciphertext state corresponding to the first security algorithm, which helps to reduce computational complexity.
[0321] In this application, the first network element can obtain N second keys based on N first keys in multiple ways. The following will combine... Figure 12 The process by which the first network element obtains N second keys based on N first keys will not be detailed here.
[0322] S1030, the first network element decrypts the first ciphertext based on N second keys to obtain the third ciphertext.
[0323] For example, N second keys are keys encrypted using the first security algorithm, and the first ciphertext is also ciphertext encrypted using the first security algorithm. During the process of the first network element decrypting the first ciphertext based on the N second keys, both the N second keys and the first ciphertext are in the ciphertext state corresponding to the first security algorithm. Specifically, when the first network element decrypts the first ciphertext using the second security algorithm based on the N second keys, the resulting third ciphertext is in the ciphertext state corresponding to the first security algorithm, but in the plaintext state corresponding to the second security algorithm.
[0324] The aforementioned third ciphertext, in the ciphertext state corresponding to the first security algorithm, can be understood as follows: the third ciphertext is the ciphertext encrypted using the first security algorithm; for example, the third ciphertext is the first data encrypted using the first security algorithm. For instance, the third ciphertext can be denoted as: Enc HE (m). In other words, the third ciphertext is the same as the result obtained by encrypting the first data based on the first security algorithm, or the first data in plaintext state needs to be decrypted based on the first security algorithm.
[0325] During the process of the first network element decrypting the first ciphertext based on N second keys, the N second keys and the first ciphertext in the ciphertext state corresponding to the first security algorithm can be understood as follows: the N second keys are obtained by encrypting N first keys based on the first security algorithm, and the first ciphertext is obtained by encrypting the second ciphertext based on the first security algorithm. During the process of the first network element decrypting the first ciphertext based on N second keys, the first network element does not need to decrypt the N second keys or the first ciphertext based on the first security algorithm, but directly processes the N second keys and the first ciphertext in the ciphertext state corresponding to the first security algorithm.
[0326] For example, the first network element decrypts the first ciphertext based on N second keys to obtain the third ciphertext, which may include the following steps:
[0327] Step 1.3: Determine that the first ciphertext consists of M block ciphertexts, for example, Enc HE (c) Including Enc HE (c1.0), Enc HE (c2.0), Enc HE (c3.0)...Enc HE (cM.0).
[0328] Step 2.3: Based on the second key #n (e.g., Enc) among N second keys... HE (rkn)) Decrypting the block ciphertext Enc HE (c1.n-1), yielding the intermediate ciphertext Enc HE (c1.n), where n = 1, 2, ..., N-1.
[0329] For example, based on the second key #1 among N second keys (e.g., Enc HE (rk1) Decrypting the block ciphertext Enc HE (c1.0) yields the intermediate ciphertext Enc. HE (c1.1), based on the second key #2 among N second keys (e.g., Enc HE (rk2) Decrypting the block ciphertext Enc HE (c1.1) yields the intermediate ciphertext Enc HE (c1.2), and so on.
[0330] Step 3.3: Based on the second key #N (e.g., Enc) among N second keys HE (rkN)) Decrypting the block ciphertext Enc HE (c1.N-1) yields the block ciphertext Enc. HE The ciphertext in the ciphertext state corresponding to the first security algorithm (c1.0) is denoted as Enc.HE (m1).
[0331] Furthermore, for other block ciphertexts Enc HE (c2.0), Enc HE (c3.0)...Enc HE (cM.0) can be obtained by referring to steps 1.3 to 3.3 above, respectively, to obtain the ciphertext Enc in the ciphertext state corresponding to the first security algorithm. HE (m2), Enc HE (m3)...Enc HE (mM). Among them, Enc HE (m1), Enc HE (m2), Enc HE (m3)...and Enc HE (mM) is merged to obtain the decryption result of the first ciphertext based on N second key pairs of the first network element, which is the aforementioned third ciphertext. This third ciphertext is in the ciphertext state corresponding to the first security algorithm. The third ciphertext is the same as the ciphertext obtained by encrypting the first data based on the first security algorithm, and can be denoted as Enc. HE (m).
[0332] Optionally, after obtaining the third ciphertext, the first network element can also perform calculations on the third ciphertext to obtain the first calculation result. Figure 10 The method flow shown may also include:
[0333] S1040, the first network element performs calculations on the third ciphertext based on the calculation key corresponding to the first security algorithm to obtain the first calculation result.
[0334] The third ciphertext supports computation in the ciphertext state corresponding to the first security algorithm. Therefore, the first network element can directly perform computation on the third ciphertext based on the computation key corresponding to the first security algorithm, without needing to decrypt the third ciphertext based on the first security algorithm before or during the computation.
[0335] For example, the first data is a matrix, and the first calculation result can be the rank of that matrix under homomorphic ciphertext. For instance, the calculation based on the computation key corresponding to the first security algorithm is denoted as Eval. HE (), the third ciphertext is denoted as Enc HE (m), the computation of the third ciphertext based on the computation key corresponding to the first security algorithm can be expressed as: Eval HE (Enc HE (m)), the first calculation result is the ciphertext state corresponding to the first security algorithm.
[0336] Optionally, if the computation key corresponding to the first security algorithm required by the first network element to compute the third ciphertext is provided by the first communication device, the first network element can request the first communication device to provide the computation key. For example, the first network element sends a request message #X to the first communication device to request the computation key. After receiving the request message #X, the first communication device sends the computation key corresponding to the first security algorithm to the first network element according to the request message #X. Optionally, the request message #X includes a first identifier, which is associated with the first security algorithm. The first communication device can determine the computation key corresponding to the first security algorithm based on the first identifier and then send the computation key to the first network element.
[0337] Furthermore, the first network element can also provide the first calculation result to the first communication device. Figure 10 The method flow shown may also include:
[0338] S1050, the first network element sends the first calculation result to the first communication device, and correspondingly, the first communication device receives the first calculation result from the first network element.
[0339] As can be seen from the above, the first communication device in this application can be one device or multiple devices. If the first communication device includes multiple devices, the device that performs the uplink transmission process (e.g., receiving the second ciphertext from the second communication device and performing encryption to send the encrypted first ciphertext to the first network element, etc.) and the device that performs the downlink transmission process (e.g., receiving the first calculation result from the first network element) may not be the same device. In this case, different devices included in the first network element can obtain the same first security algorithm; or, different devices included in the first network element can obtain different keys corresponding to the first security algorithm. For example, the device that performs the uplink transmission process obtains the encryption key corresponding to the first security algorithm, and the device that performs the downlink transmission process obtains the decryption key corresponding to the first security algorithm.
[0340] Alternatively, the same first security algorithm can be determined among different devices in the following ways:
[0341] Different devices determine the same first security algorithm through pre-configuration. This can be understood as achieving synchronization of the first security algorithm among different devices. For example, different devices included in the first network element can obtain the first security algorithm from a device that already stores it, thus achieving synchronization. Alternatively, different devices included in the first network element can obtain the context related to the first security algorithm from a key management center. This application does not impose any limitations on this.
[0342] The aforementioned key management center can be understood as a device in a communication system used to manage all security keys. This key management center can also be called a key generation center, key management device, etc.
[0343] S1060, the first communication device decrypts the first calculation result based on the decryption key corresponding to the first security algorithm to obtain the second calculation result.
[0344] For example, when the first security algorithm is a homomorphic encryption algorithm, the first communication device can obtain the second calculation result using the homomorphic decryption key. For instance, if the first data is a matrix, the first calculation result can be the rank of the matrix under homomorphic ciphertext, and the second calculation result can also be the rank of the matrix. For example, the first calculation result might be in the ciphertext state corresponding to the first security algorithm, and the second calculation result might be in the plaintext state.
[0345] In this application, after obtaining the second calculation result, the first communication device can obtain a second calculation result protected by a third security algorithm, and then provide the second calculation result protected by the third security algorithm to the second communication device. Figure 10 The communication method shown may further include the following step S1070:
[0346] S1070, the first communication device sends a second calculation result protected by a third security algorithm to the second communication device, and correspondingly, the second communication device receives the second calculation result protected by the third security algorithm from the first communication device.
[0347] As one possible implementation, the third security algorithm is the second security algorithm described above. As can be seen from the above, the second security algorithm is determined through negotiation between the second communication device and the first network element.
[0348] In this implementation, the second calculation result, which is protected by the third security algorithm, is determined by the first network element. For example, before step S1070, Figure 10 The communication method shown further includes the following steps S1071 to S1073:
[0349] S1071, the first communication device sends the second calculation result to the first network element.
[0350] S1072, the first network element performs security protection on the second calculation result based on the second security algorithm, and obtains the second calculation result protected by the third security algorithm.
[0351] For example, the second calculation result is denoted as result. Taking the second security algorithm as AES as an example, the second security algorithm is denoted as AES, and the encryption operation based on the second security algorithm is denoted as Enc. AES(), then the second calculation result protected by the third security algorithm can be denoted as Enc. AES (result).
[0352] S1073, the first network element sends the second calculation result, which is protected by the third security algorithm, to the first communication device.
[0353] As another possible implementation, the third security algorithm is determined through negotiation between the second communication device and the first communication device.
[0354] In this implementation, the second calculation result, which is protected by the third security algorithm, is determined by the first communication device. For example, before step S1070, Figure 10 The method flow shown also includes the following steps S1074 and S1075:
[0355] S1074, the second communication device and the first communication device negotiate to determine the third security algorithm.
[0356] The description of the negotiation between the second communication device and the first network element to determine the second security algorithm can be referred to in step S1002 above, which will not be repeated here.
[0357] Optionally, the definition of the third security algorithm can be found in the description of the second security algorithm, and will not be repeated here. For example, the third security algorithm can be a NAS security algorithm between the second communication device and the first communication device.
[0358] S1075, the first communication device performs security protection on the second calculation result based on the third security algorithm, and obtains the second calculation result protected by the third security algorithm.
[0359] Figure 10 In the communication method shown, after the first network element receives the ciphertext (i.e., the first ciphertext) encrypted based on the first security algorithm, it can decrypt the first ciphertext based on the obtained keys (i.e., N second keys) encrypted based on the first security algorithm. It should be understood that during the decryption process, both the N second keys and the first ciphertext are in the ciphertext state corresponding to the first security algorithm, so the first network element can decrypt the first ciphertext based on the N second keys.
[0360] Figure 10 The communication method shown defines the ciphertext transmission and decryption methods of homomorphic encryption in mobile communication networks, realizing the application of homomorphic encryption technology in communication networks, which can protect the privacy of communication data and improve the security of communication data.
[0361] In addition, such as Figure 9 As shown, the server is used to process the encrypted Enc HE(c) The round key used for decryption is obtained by key expansion of the master key in the homomorphic ciphertext state. This has high computational complexity and prolongs the decryption process. Figure 10 The communication method shown proposes to directly expand the master key in the plaintext state to obtain N first keys, and then encrypt the N first keys based on the first security algorithm to obtain N second keys, which are used to decrypt the first ciphertext. This helps to significantly reduce the complexity of key acquisition and improve decryption efficiency.
[0362] Figure 11 This is a schematic flowchart illustrating how a first communication device determines a first security algorithm, as provided in this application. It includes the following steps:
[0363] S1110, the second communication device sends a first request message to the first network element, and correspondingly, the first network element receives the first request message from the second communication device.
[0364] For example, the first request message includes an identifier of the second communication device. The identifier of the second communication device is used to indicate the second communication device; for example, the identifier of the second communication device can be identification information such as SUPI, GPSI, or SUCI of the second communication device.
[0365] For example, the first request message can create a request message for a service, and the first request message may also include service type information, wherein the service type indicated by the service type information includes, but is not limited to: computing task, session service, integrated sensing and communication (ISAC) service, or AI inference service, etc.
[0366] Furthermore, after receiving the first request message, the first network element can determine whether to provide computing services based on the first security algorithm to the second communication device based on the identifier of the second communication device. The following explanation uses the determination to provide computing services based on the first security algorithm to the second communication device as an example. Figure 11 The method flow shown may also include:
[0367] S1120, the first network element is determined to provide computing services based on the first security algorithm for the second communication device.
[0368] For example, the first network element determining to provide computing services based on the first security algorithm to the second communication device may be: the first network element determining to provide homomorphic encryption services to the second communication device, wherein the homomorphic encryption service may be for the business data of the second communication device, and the first network element supports data analysis and / or processing services in homomorphic ciphertext state.
[0369] Optionally, the first network element determines to provide computing services based on the first security algorithm to the second communication device based on the subscription information of the second communication device. For example, the first network element determines the security service policy of the second communication device based on the subscription information of the second communication device, and determines to provide computing services based on the first security algorithm to the second communication device according to the security service policy. For example, the first network element determines to provide encrypted computing services to the second communication device based on the subscription information of the second communication device and other pre-configured information (such as the current computing power usage of the second communication device).
[0370] The security service strategy of the second communication device may be at least one of the following:
[0371] The core network side processes data from the second communication device in encrypted form, provides advanced privacy protection for the second communication device, or provides advanced privacy protection in specific services (such as computing services, AI services, sensing services, or UAV services). This can be understood as the security protection requirements for the second communication device being either the security requirements of the second communication device itself or the security protection requirements of the service.
[0372] As an example and not a limitation, when the first request message mentioned above includes service type information, the first network element may also consider the service type indicated by the service type information when determining whether to provide the second communication device with a computing service based on the first security algorithm. For example, the first network element may determine to provide the second communication device with a computing service based on the first security algorithm based on the second communication device's subscription information, which could be: the first network element determines to provide the second communication device with a first service based on the first security algorithm based on the second communication device's subscription information and service type information, wherein the type of the first service is the type indicated by the service type information of the service to which the first data belongs.
[0373] It should be understood that the above-mentioned method of the first network element determining whether to provide computing services based on the first security algorithm to the second communication device based on the subscription information of the second communication device is merely an example and does not constitute any limitation on the scope of protection of this application. The first network element may also determine whether to provide computing services based on the first security algorithm to the second communication device in other ways. For example, the first request message mentioned above includes indication information #2, which indicates that the second communication device has homomorphic encryption requirements. Indication information #2 can be either the security requirements of the service or the security requirements of the second communication device.
[0374] Optionally, the indication information #2 may explicitly or implicitly indicate that the second communication device has homomorphic encryption requirements. For example, the indication information #2 may be a message name or a parameter carried in the message.
[0375] Optionally, instruction information #2 may not carry the fifth instruction information. By default, the network side will enable homomorphic encryption for all or some services of the second communication device according to the pre-configured policy. For example, the network side may confirm that the second communication device is a certain type of device (e.g., a device with a security requirement level higher than a preset threshold), and by default, all services related to the second communication device will use homomorphic encryption.
[0376] If the first network element is determined to provide computing services based on the first security algorithm to the second communication device, or is determined to provide computing services based on the first security algorithm to the first service of the second communication device, it can instruct the first communication device to provide encryption services for the data of the second communication device. Figure 11 The method flow shown also includes:
[0377] S1130, the first network element sends a second request message to the first communication device, and correspondingly, the first communication device receives the second request message from the first network element.
[0378] For example, the second request message is used to request encryption of data from the second communication device based on the first security algorithm.
[0379] Optionally, the first network element can determine the first communication device that provides services to the second communication device on its own, or it can determine the first communication device that provides services to the second communication device from other network elements. For example, the first network element can trigger a downlink service request operation of the first communication device through a routing request message. This downlink service request operation is used to determine the first communication device that the second communication device is currently or previously in; or the first network element can determine the first communication device that the second communication device is currently or previously in through a paging operation by other network elements (such as an AMF).
[0380] For example, the second request message requesting encryption of data from the second communication device based on the first security algorithm can be understood as: the second request message requesting the first communication device to generate a first security context corresponding to the first security algorithm, which is used to encrypt data from the second communication device. Alternatively, the second request message can be interpreted as requesting the first communication device to encrypt data from the second communication device.
[0381] Optionally, the second request message carries a first identifier associated with a first security algorithm.
[0382] For example, the first identifier includes, but is not limited to, at least one of the following:
[0383] The identifier of the second communication device, the identifier of the service to which the first data belongs, or the identifier of the service area to which the first communication device belongs.
[0384] If the first identifier is the identifier of the second communication device, it can be understood that the encryption key is at the granularity of the second communication device. For example, the first communication device performs homomorphic encryption on data from the second communication device based on the encryption key. The identifier of the second communication device can be its subscription concealed identifier (SUCI), globally unique temporary identifier (GUTI), SUPI, or other information used to identify the second communication device.
[0385] If the first identifier is the identifier of the service corresponding to the first data, it can be understood that the encryption key is at the service granularity of the second communication device. For example, the first communication device performs homomorphic encryption processing on the data received from the second communication device's computing service, AI service, sensing service, or UAV service, etc., based on the encryption key. Here, the identifier of the service corresponding to the first data can be the service ID.
[0386] If the first identifier is the identifier of the service area to which the first communication device belongs, it can be understood that the encryption key is at the service area granularity. For example, the first communication device performs homomorphic encryption processing on data from devices within the service area of the first communication device based on the encryption key.
[0387] It should be understood that the above-mentioned possible forms of the first identifier are merely examples and do not constitute any limitation on the scope of protection of this application. The first identifier may also be in other forms. For example, the first identifier may be an identifier of the type of the second communication device, and the data identifying a certain type of device needs to be homomorphically encrypted.
[0388] In this application, the first identifier can be a service ID and / or a connection ID. For example, the first identifier can be a PDU session ID or a global norm-aware pooling (GNAP) ID; or, for example, a network layer ID, such as a connection ID in a Quic connection, or an IP address, which can be considered a service ID or a connection ID.
[0389] S1140, the first communication device acquires the first security algorithm.
[0390] For example, after receiving the second request message, the first communication device determines that the data from the second communication device needs to be encrypted based on the first security algorithm. Therefore, the first communication device obtains the first security algorithm, which is associated with the first identifier.
[0391] This application does not limit how the first communication device obtains the first security algorithm. For example, the second communication device may generate a decryption key corresponding to the first security algorithm based on security parameters, then generate an encryption key corresponding to the first security algorithm based on the decryption key, and then send the encryption key to the first communication device. Another example is that the first communication device requests the first security algorithm from a key management center. Yet another example is that the protocol predefines or the management device preconfigures the algorithm type of the homomorphic encryption algorithm used between the first and second communication devices. For instance, the management device preconfigures a encryption strategy for the first and second communication devices, specifying that the homomorphic encryption part uses the CKKS algorithm; or the protocol stipulates that the first communication device uses a predefined protocol for security protection, which specifies the use of the CKKS algorithm for homomorphic encryption protection. Here, the key management center can be understood as a device in the communication system used to manage all security keys. This key management center can also be called a key generation center, key management device, etc. The management device can be understood as a device in the communication system used to manage all communication devices and capable of configuring algorithms for the communication devices in the communication system.
[0392] The homomorphic encryption key can be simply called the encryption key, or denoted as pk. The homomorphic encryption key can also be called the public key, and the homomorphic decryption key can also be called the private key.
[0393] As one possible implementation, the first communication device determines the homomorphic encryption key and the homomorphic decryption key by generating sk based on the security parameters corresponding to the first security algorithm, and then generating pk based on sk.
[0394] As another possible implementation, the first communication device can determine the homomorphic encryption key and the homomorphic decryption key by requesting the homomorphic encryption key and the homomorphic decryption key corresponding to the first security algorithm from the key management center.
[0395] It should be understood that the method by which the first communication device determines the homomorphic encryption key and the homomorphic decryption key described above is merely an example and does not constitute any limitation on the scope of protection of this application. For example, the first communication device may also obtain the first security algorithm based on historical communication data.
[0396] Optionally, Figure 10 The illustrated method flow may also include the following steps:
[0397] S1150, the first communication device sends a second response message to the first network element, and correspondingly, the first network element receives the second response message from the first communication device.
[0398] The second response message is used to respond to the second request message mentioned above, indicating to the first network element whether the encryption task has been successfully created. This second response message can be called the encryption task creation response message.
[0399] Optionally, if the aforementioned first identifier is determined by the first network element, then Figure 10 The illustrated method flow may also include the following steps:
[0400] S1160, the first network element sends a first response message to the second communication device, and correspondingly, the second communication device receives the first response message from the first network element.
[0401] The first response message is used to respond to the aforementioned first request message, indicating to the second communication device that the service creation was successful. This first response message can be referred to as the service creation response message. The first response message carries a first identifier.
[0402] It should be understood that Figure 11 The example shown of the first communication device obtaining the first security algorithm in response to the second request message of the first network element is merely one example of the first communication device obtaining the first security algorithm and does not constitute any limitation on the scope of protection of this application. In this application, the first communication device can also obtain the first security algorithm in other ways. For example, during the process of the first communication device receiving the second ciphertext from the second communication device, it receives an instruction from the second communication device to perform homomorphic encryption on the second ciphertext (e.g., instruction information #1). The first communication device can obtain the first security algorithm in response to the instruction information #1. Examples will not be given here.
[0403] Figure 12 This is a schematic flowchart of a first network element obtaining N second keys, as provided in this application.
[0404] In this application, the first network element obtains N second keys based on N first keys, including but not limited to the following two possible implementation methods:
[0405] As one possible implementation, the first network element generates the required N second keys based on the N first keys. For example, the first network element obtains N second keys based on the N first keys, specifically including:
[0406] The first network element generates N first keys; the first network element receives the encryption key corresponding to the first security algorithm from the first communication device; the first network element encrypts the N first keys based on the encryption key to obtain N second keys.
[0407] In this implementation, Figure 12 The method flow shown also includes the following steps S1201 to S1204.
[0408] S1201, the first network element generates N first keys.
[0409] As can be seen from the above, the first network element can negotiate with the second communication device to determine the second security algorithm. After determining the second security algorithm, N first keys can be generated based on the second security algorithm.
[0410] For example, the first network element can generate N first keys based on the master key corresponding to the second security algorithm. For instance, if the second security algorithm is the AES-128 encryption algorithm described above, then the N first keys can be the 11 round keys corresponding to the AES-128 encryption algorithm introduced in the basic concepts above. The generation process of these 11 round keys can be referred to the description in the basic concepts above, and will not be repeated here.
[0411] S1202, the first network element sends a request message #1 to the first communication device, and correspondingly, the first communication device receives the request message #1 from the first network element.
[0412] Specifically, request message #1 is used to request the encryption key corresponding to the first security algorithm. For example, request message #1 can be called a encryption key request message. Request message #1 may carry a first identifier, which is associated with the first security algorithm. A description of the first identifier can be found above. Figure 11 The description of the first identifier in step S1130 will not be repeated here.
[0413] It should be noted that the order of the different steps in this application does not imply the order of execution. The execution order of each step should be determined by its function and internal logic. For example, the timing of the above steps S1201 and S1202 may be that step S1201 is executed first and then step S1202 is executed, or step S1202 is executed first and then step S1201 is executed.
[0414] S1203, the first communication device sends the encryption key corresponding to the first security algorithm to the first network element, and correspondingly, the first network element receives the encryption key corresponding to the first security algorithm from the first communication device.
[0415] For example, after receiving the aforementioned request message #1, the first communication device can determine, based on request message #1, that the encryption key required by the first network element is the encryption key corresponding to the first security algorithm. For instance, the request message #1 carries a first identifier, and the first communication device can determine the first security algorithm associated with the first identifier based on the first identifier, and provide the encryption key corresponding to the first security algorithm to the first network element.
[0416] Optionally, the first communication device sends a response message #1 to the first network element. This response message #1 can be called a encryption key response message, and it carries the encryption key corresponding to the first security algorithm.
[0417] It should be understood that the above-mentioned example of the first network element obtaining the encryption key corresponding to the first security algorithm from the first communication device is merely an example and does not constitute any limitation on the scope of protection of this application. The first network element can also obtain the encryption key corresponding to the first security algorithm through other means. For example, the first network element can obtain the encryption key corresponding to the first security algorithm from a key management center, and these will not be listed here.
[0418] S1204, the first network element encrypts N first keys based on the encryption key corresponding to the first security algorithm to obtain N second keys.
[0419] For example, after the first network element generates N first keys and obtains the encryption key corresponding to the first security algorithm, it can encrypt the N first keys respectively based on the encryption key corresponding to the first security algorithm to obtain N second keys.
[0420] For example, the first network element generates N first keys rk1, rk2, rk3...rkN based on the master key corresponding to the second security algorithm, and receives the encryption key pk corresponding to the first security algorithm from the first communication device. Taking the first security algorithm as a homomorphic encryption algorithm as an example, this first security algorithm is denoted as HE, and the encryption operation based on the first security algorithm can be denoted as Enc. HE (). The first network element encrypts N first keys based on this encryption key to obtain N second keys Enc. HE (rk1), Enc HE (rk2), Enc HE (rk3)...Enc HE (rkN).
[0421] Figure 12In the communication method shown, the first network element obtains N second keys based on N first keys in the following way: the first network element determines N first keys itself based on a second security algorithm, and obtains the encryption key corresponding to the first security algorithm required to encrypt the N first keys from the first communication device. Thus, the first network element can encrypt the N first keys itself to obtain N second keys without providing the N first keys to other devices, reducing the key transmission process and improving security to a certain extent.
[0422] As another possible implementation, the first network element provides N first keys to the first communication device, which then generates N second keys and sends them to the first network element. For example, the first network element obtains N second keys based on the N first keys, specifically including:
[0423] The first network element generates N first keys. The first network element sends the N first keys to the first communication device. The first communication device encrypts each of the N first keys based on the encryption key corresponding to the first security algorithm, obtaining N second keys. The first communication device sends the N second keys to the first network element.
[0424] In this implementation, Figure 12 The method flow shown also includes the following steps S1205 to S1208.
[0425] S1205, the first network element generates N first keys.
[0426] Referring to the description of step S1201 above, it will not be repeated here.
[0427] S1206, the first network element sends N first keys to the first communication device, and correspondingly, the first communication device receives N first keys from the first network element.
[0428] For example, a first network element sends a request message #2 to a first communication device. This request message #2 carries N first keys, and is used to request the first communication device to encrypt the N first keys based on a first security algorithm. Optionally, the request message #2 can be called a key encryption request message. Optionally, the request message #2 carries a first identifier, which is associated with the first security algorithm. Optionally, the request message #2 may include information about the first keys, including their identifier, length information, etc.
[0429] The aforementioned N first keys and request message #2 can be transmitted separately. For example, after the first network element sends N first keys to the first communication device, it sends request message #2 to the first communication device. Request message #2 is used to request the first communication device to encrypt the N first keys based on the first security algorithm.
[0430] Optionally, the first network element may send N first keys to the first communication device in the following possible ways:
[0431] Method 2.1: The first network element sends each of the N first keys to the first communication device.
[0432] For example, N first keys are denoted as rk1, rk2, rk3...rkN, and the first network element sends rk1, rk2, rk3...rkN to the first communication device respectively.
[0433] Method 2.2: The first network element sends N keys generated by the first key to the first communication device.
[0434] For example, N first keys are denoted as rk1, rk2, rk3…rkN. A first network element can send key #1 to a first communication device. Key #1 is a key generated based on rk1, rk2, rk3…rkN, and can be denoted as rk1||rk2||rk3||...||rkN. The first communication device can reconstruct N first keys based on key #1 (e.g., by dividing rk1||rk2||rk3||...||rkN based on the key length information to obtain rk1, rk2, rk3…rkN), where "||" represents the key concatenation symbol.
[0435] It should be understood that methods 2.1 and 2.2 described above are merely illustrative examples of possible ways for the first network element to send N first keys to the first communication device, and do not constitute any limitation on the scope of protection of this application. The first communication device only needs to be able to obtain N first keys based on the key information provided by the first network element.
[0436] For example, the method by which the first communication device obtains N first keys through the key information provided by the first network element can also be: the first network element sends N keys #2 to the first communication device, and each of the N keys #2 is determined based on the N first keys. In this implementation, the step S1206 above, in which the first network element sends N first keys to the first communication device, can be replaced by describing the first network element sending N keys #2 to the first communication device, or the first network element sending the keys determined by the N keys #2 to the first communication device.
[0437] For ease of understanding, combined with Figure 13 This section briefly describes the process of determining N keys #2 based on N first keys.
[0438] like Figure 13As shown, the N first keys include first key #1, first key #2, and first key #3, denoted as rk1, rk2, and rk3. The N keys #2 include key #2.1, key #2.2, and key #2.3, as follows: Figure 13 The chipertext1, chipertext2, and chipertext3 are shown in the image.
[0439] from Figure 13 As can be seen from this, the process of processing rk1, rk2, and rk3 based on the security mode to obtain N keys #2 is as follows:
[0440] Key #2.1 is determined based on the initialization vector (IV) and the first key #1. For example, the initialization vector, rk1, and chipertext1 satisfy the following relationship:
[0441] chipertext1 = rk1⊕IV, where chipertext1 represents key #2.1, rk1 represents first key #1, IV represents initialization vector, and ⊕ represents XOR operation.
[0442] Similarly, determining key #2.2 based on the first key #2 and key #2.1 can be achieved by XORing the first key #2 and key #2.1 by bit order. For example, the first key #2, key #2.1, and key #2.2 satisfy the following relationship:
[0443] chipertext2 = rk2 ⊕ chipertext1, where chipertext2 represents key #2.2, rk2 represents the first key #2, chipertext1 represents key #2.1, and ⊕ represents XOR operation.
[0444] Determining key #2.3 based on key #3 and key #2.2 can be achieved by XORing key #3 and key #2.2 by bit order. For example, key #3, key #2.2, and key #2.3 satisfy the following relationship:
[0445] Chipertext3 = rk3 ⊕ chipertext2, where chipertext3 represents key #2.3, rk3 represents the first key #3, chipertext2 represents key #2.3, and ⊕ represents XOR operation.
[0446] As can be seen from the above, N keys #2 can be Figure 13 The chipertext1, chipertext2, and chipertext3 are shown in the image.
[0447] In this implementation, the first network element sends the aforementioned N keys #2 to the first communication device, and the first communication device can reconstruct N first keys based on the received N keys #2. For example, based on the received chipertext1, chipertext2, and chipertext3, the reverse input is performed. Figure 13 The secure connection mode shown determines N first keys rk1, rk2, and rk3. Alternatively,
[0448] In this implementation, the first network element sends the key #X determined by the aforementioned N keys #2 to the first communication device. The first communication device can reconstruct the N keys #2 based on the received key #X, and then reconstruct the N first keys based on the N keys #2. For example, based on the received chipertext1||chipertext2||chipertext3, chipertext1, chipertext2, and chipertext3 are reconstructed (e.g., chipertext1||chipertext2||chipertext3 is segmented based on the key length information to obtain chipertext1, chipertext2, and chipertext3), and chipertext1, chipertext2, and chipertext3 are then input in reverse order. Figure 13 The secure connection mode shown determines N first keys rk1, rk2, and rk3.
[0449] S1207, the first communication device encrypts N first keys respectively based on the encryption key corresponding to the first security algorithm to obtain N second keys.
[0450] For example, given N first keys rk1, rk2, rk3...rkN, and taking a homomorphic encryption algorithm as the first security algorithm (denoted as HE), the encryption operation based on this first security algorithm can be denoted as Enc. HE (). The first communication device encrypts N first keys based on the encryption key corresponding to the first security algorithm, resulting in N second keys, which can be denoted as Enc. HE (rk1), Enc HE (rk2), Enc HE (rk3)...Enc HE (rkN), or it can also be written as Enc HE (chipertext1.1), Enc HE (chipertext2.1), Enc HE (chipertext3.1)...Enc HE(chipertextN.1). The N second keys are denoted as Enc. HE (chipertext1.1), Enc HE (chipertext2.1), Enc HE (chipertext3.1)...Enc HE For a description of (chipertextN.1), please refer to the following text. Figure 14 The description in the text will not be repeated here.
[0451] S1208, the first communication device sends N second keys to the first network element, and correspondingly, the first network element receives N second keys from the first communication device.
[0452] For example, the first communication device sends a response message #2 to the first network element. The response message #2 carries N second keys and responds to the aforementioned request message #2. Optionally, the request message #2 can be called a key encryption response message. The response message #2 may also carry information about the second keys, including the identifier and length information of the second keys.
[0453] Optionally, the first communication device may send N second keys to the first network element in the following ways:
[0454] Method 3.1: The first communication device sends each of the N second keys to the first network element.
[0455] For example, N second keys are denoted as Enc HE (rk1), Enc HE (rk2), Enc HE (rk3)...Enc HE (rkN), the first communication device sends the Enc to the first network element. HE (rk1), Enc HE (rk2), Enc HE (rk3)...Enc HE (rkN).
[0456] Method 3.2: The first communication device generates a key for the first network element N second keys.
[0457] For example, N second keys are denoted as Enc HE (rk1), Enc HE (rk2), Enc HE (rk3)...Enc HE (rkN), the first communication device sends key #3 to the first network element, which is Enc HE(rk1)||Enc HE (rk2)||Enc HE (rk3)||…||Enc HE (rkN). The first network element can recover N second keys based on key #3 (e.g., based on the key length information of Enc). HE (rk1)||Enc HE (rk2)||Enc HE (rk3)||…||Enc HE (rkN) is divided to obtain Enc HE (rk1), Enc HE (rk2), Enc HE (rk3)...Enc HE (rkN)).
[0458] It should be understood that the methods 3.1 and 3.2 described above are merely illustrative examples of possible ways in which the first communication device sends N second keys to the first network element, and do not constitute any limitation on the scope of protection of this application. The first network element only needs to be able to obtain N second keys based on the key information provided by the first communication device.
[0459] For example, the method by which the first network element obtains N second keys through the key information provided by the first communication device can also be: the first communication device sends N keys #4 to the first network element, and each of the N keys #4 is determined based on the N second keys. In this implementation, the step S1208 above, in which the first communication device sends N second keys to the first network element, can be replaced by describing the first communication device sending N keys #4 to the first network element, or the keys determined by the N keys #4.
[0460] For ease of understanding, combined with Figure 14 This section briefly describes the process of determining N keys #4 based on N second keys.
[0461] like Figure 14 As shown, the N second keys include second key #1, second key #2, and second key #3, denoted as Enc. HE (rk1), Enc HE (rk2) and Enc HE (rk3), N keys #4 including key #4.1, key #4.2 and key #4.3, such as Figure 14 The chipertext1.1, chipertext2.1, and chipertext3.1 are shown.
[0462] from Figure 14 As can be seen from this, based on the security mode, Enc HE(rk1), Enc HE (rk2) and Enc HE The process of processing (rk3) to obtain N keys #4 is as follows:
[0463] Key #4.1 is determined based on IV and second key #1, for example, initialization vector, Enc HE The following relationship exists between (rk1) and chipertext1.1:
[0464] chipertext1.1 = Enc HE (rk1)⊕IV, where chipertext1.1 represents key #4.1, Enc HE (rk1) represents the second key #1, IV represents the initial vector, and ⊕ represents the XOR operation.
[0465] Similarly, determining key #4.2 based on the second key #2 and key #4.1 can be achieved by XORing the second key #2 and key #4.1 by bit order. For example, the second key #2, key #4.1, and key #4.2 satisfy the following relationship:
[0466] chipertext2.1 = Enc HE (rk2)⊕chipertext1, where chipertext2.1 represents key #4.2, Enc HE (rk2) represents the second key #2, chipertext1.1 represents the key #4.1, and ⊕ represents the XOR operation.
[0467] Determining key #4.3 based on second key #3 and key #4.2 can be achieved by XORing second key #3 and key #4.2 by bit order. For example, second key #3, key #4.2, and key #4.3 satisfy the following relationship:
[0468] Chipertext3.1 = Enc HE (rk3)⊕chipertext2, where chipertext3.1 represents key #4.3, Enc HE (rk3) represents the second key #3, chipertext2.1 represents the key #4.3, and ⊕ represents the XOR operation.
[0469] As can be seen from the above, N keys #4 can be Figure 14 The chipertext1.1, chipertext2.1, and chipertext3.1 are shown.
[0470] In this implementation, the first communication device sends the aforementioned N keys #4 to the first network element, and the first network element can reconstruct N second keys based on the received N keys #4. For example, based on the received chipertext1.1, chipertext2.1, and chipertext3.1, the reverse input is performed. Figure 14 The secure connection mode shown determines N second keys Enc HE (rk1), Enc HE (rk2) and Enc HE (rk3). Or,
[0471] In this implementation, the first communication device sends the key #Y determined by the aforementioned N keys #4 to the first network element. The first network element can reconstruct the N keys #4 based on the received key #Y, and then reconstruct the N second keys based on the N keys #4. For example, based on the received chipertext1.1||chipertext2.1||chipertext3.1, chipertext1.1, chipertext2.1, and chipertext3.1 are reconstructed (e.g., chipertext1.1||chipertext2.1||chipertext3.1 is segmented based on the key length information to obtain chipertext1.1, chipertext2.1, and chipertext3.1), and then chipertext1.1, chipertext2.1, and chipertext3.1 are input in reverse order. Figure 14 The secure connection mode shown determines N second keys Enc HE (rk1), Enc HE (rk2) and Enc HE (rk3).
[0472] It should be noted that when the first communication device generates N second keys, since the first communication device knows the N second keys and the encryption key corresponding to the first security algorithm, if the first communication device deploys the corresponding homomorphic computing capability, then after receiving the second ciphertext from the second communication device, the first communication device can perform homomorphic ciphertext computation processing on the second ciphertext. In other words, the first communication device can realize the functions of the first communication device and the first network element, simplifying the interaction between the first communication device and the first network element, thereby improving the efficiency of the network in performing homomorphic encryption and / or homomorphic computation.
[0473] For example, a first communication device receives a second ciphertext sent by a second communication device, encrypts the second ciphertext using a first security algorithm to obtain a first ciphertext, and can decrypt the first ciphertext using N second keys to obtain a third ciphertext. This third ciphertext is in the ciphertext state corresponding to the first security algorithm. Therefore, the first communication device can perform homomorphic ciphertext calculations on the third ciphertext using the calculation key corresponding to the first security algorithm. The process of the first communication device decrypting the first ciphertext and performing homomorphic ciphertext calculations on the third ciphertext can be referred to the description above of the first network element decrypting the first ciphertext and performing homomorphic ciphertext calculations on the third ciphertext, and will not be repeated here.
[0474] Figure 12 In the communication method shown, the way the first network element obtains N second keys based on N first keys can be as follows: After the first network element determines N first keys based on the second security algorithm, it can provide the N first keys to other devices, and the other devices can encrypt the N first keys to generate N second keys and provide them to the first network element. This eliminates the need for the first network element to encrypt the N first keys, which can reduce the complexity of the first network element to a certain extent.
[0475] It should be understood that Figure 12 The two methods shown for the first network element to obtain N second keys are merely examples and do not constitute any limitation on the scope of protection of this application. In this application, the first network element can also obtain the above-mentioned N second keys in other ways, such as obtaining the required N second keys from the key management center, etc., which will not be illustrated here.
[0476] The sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0477] It should also be understood that, unless otherwise specified or logically conflicting, the terminology and / or descriptions in the various embodiments of this application are consistent and can be referenced interchangeably. Furthermore, technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0478] The above, combined with Figures 10 to 14 The communication method provided in the embodiments of this application is described in detail. The above communication method is mainly described from the perspective of interaction between various entities. It is understood that, in order to realize the above functions, the first communication device, the first network element, and the second communication device include hardware structures and / or software modules corresponding to the execution of each function.
[0479] Those skilled in the art will recognize that, based on the units and algorithm steps described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0480] The following combination Figure 15 and Figure 16 The communication device provided in this application is described in detail. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for details not described in detail, please refer to the method embodiments above; for brevity, some details are omitted.
[0481] This application embodiment can divide the first communication device, the first network element, and the second communication device into functional modules according to the above method example. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the division of functional modules according to each function as an example.
[0482] Figure 15 This is a schematic block diagram of a communication device 10 provided in an embodiment of this application. The device 10 includes a transceiver unit 11 and a processing unit 12. The transceiver unit 11 can implement corresponding communication functions, and the processing unit 12 is used for data processing. In other words, the transceiver unit 11 is used to perform operations related to receiving and sending, and the processing unit 12 is used to perform other operations besides receiving and sending. The transceiver unit 11 can also be referred to as a communication interface or a communication unit.
[0483] Optionally, the device 10 may further include a storage unit 13, which may be used to store instructions and / or data. The processing unit 12 may read the instructions and / or data in the storage unit to enable the device to perform the operation of the device in the aforementioned method embodiments.
[0484] In one design, the device 10 may correspond to the first communication device in the above method embodiments, or to a component of the first communication device (such as a chip).
[0485] The device 10 can implement the steps or processes corresponding to those performed by the first communication device in the above method embodiment. The transceiver unit 11 can be used to perform the transceiver-related operations of the first communication device in the above method embodiment, and the processing unit 12 can be used to perform the processing-related operations of the first communication device in the above method embodiment.
[0486] In one possible implementation, transceiver unit 11 is configured to send a first ciphertext to a first network element. The first ciphertext is obtained by encrypting a second ciphertext using a first security algorithm. The second ciphertext is obtained by encrypting first data of a second communication device using N first keys corresponding to the second security algorithm, where N is an integer greater than 1. Transceiver unit 11 is also configured to receive a first calculation result from the first network element. The first calculation result is obtained by calculating a third ciphertext using a calculation key corresponding to the first security algorithm. The third ciphertext is obtained by decrypting the first ciphertext using N second keys, where the N second keys are obtained by encrypting the N first keys using the first security algorithm. The N second keys support decryption of the first ciphertext in the ciphertext state encrypted by the first security algorithm. Processing unit 12 is configured to decrypt the first calculation result using a decryption key corresponding to the first security algorithm to obtain a second calculation result. Transceiver unit 11 is also configured to send the second calculation result, which is securely protected by a third security algorithm, to the second communication device. The third security algorithm is either the second security algorithm itself, or the third security algorithm is determined through negotiation between the second communication device and the first communication device.
[0487] Wherein, when the device 10 is used to perform Figure 10 When the method is in use, the transceiver unit 11 can be used to execute the steps of transmitting and receiving information in the method, such as steps S1003, S1010, S1050, S1071, S1073, S1074 and S1070; the processing unit 12 can be used to execute the processing steps in the method, such as steps S1004, S1060 and S1075.
[0488] When the device 10 is used to perform Figure 11 When the method is in use, the transceiver unit 11 can be used to execute the steps of transmitting and receiving information in the method, such as steps S1130, S1150 and S1160; the processing unit 12 can be used to execute the processing steps in the method, such as step S1140.
[0489] When the device 10 is used to perform Figure 12 When the method is in use, the transceiver unit 11 can be used to execute the steps of transmitting and receiving information in the method, such as steps S1202, S1203, S1206 and S1208; the processing unit 12 can be used to execute the processing steps in the method, such as step S1207.
[0490] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0491] In another design, the device 10 may correspond to the first network element in the above method embodiment, or a component of the first network element (such as a chip).
[0492] The device 10 can implement the steps or processes corresponding to the first network element in the above method embodiment. The transceiver unit 11 can be used to perform the transceiver-related operations of the first network element in the above method embodiment, and the processing unit 12 can be used to perform the processing-related operations of the first network element in the above method embodiment.
[0493] In one possible implementation, transceiver unit 11 is configured to receive first ciphertext, which is obtained by encrypting second ciphertext using a first security algorithm. The second ciphertext is obtained by encrypting first data using N first keys corresponding to the second security algorithm, where N is an integer greater than 1. Processing unit 12 is configured to obtain N second keys based on the N first keys, where the N second keys are obtained by encrypting the N first keys using the first security algorithm. Processing unit 12 is further configured to decrypt the first ciphertext using the N second keys to obtain a third ciphertext, which is in the ciphertext state corresponding to the first security algorithm; wherein, during the decryption process, the N second keys and the first ciphertext are in the ciphertext state corresponding to the first security algorithm.
[0494] Wherein, when the device 10 is used to perform Figure 10 When the method is in use, the transceiver unit 11 can be used to execute the steps of transmitting and receiving information in the method, such as steps S1002, S1010, S1050, S1071 and S1073; the processing unit 12 can be used to execute the processing steps in the method, such as steps S1020, S1030, S1040 and S1072.
[0495] When the device 10 is used to perform Figure 11 When the method is in use, the transceiver unit 11 can be used to execute the steps of transmitting and receiving information in the method, such as steps S1130, S1150 and S1110; the processing unit 12 can be used to execute the processing steps in the method, such as step S1120.
[0496] When the device 10 is used to perform Figure 12When the method is in use, the transceiver unit 11 can be used to execute the steps of transmitting and receiving information in the method, such as steps S1202, S1203, S1206 and S1208; the processing unit 12 can be used to execute the processing steps in the method, such as steps S1201, S1204 and S1205.
[0497] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0498] It should also be understood that the device 10 here is embodied in the form of a functional unit. The term "unit" here can refer to an application-specific integrated circuit (ASIC), electronic circuitry, a processor (e.g., a shared processor, a proprietary processor, or a group processor, etc.) and memory for executing one or more software or firmware programs, integrated logic circuitry, and / or other suitable components supporting the described functions. In an alternative example, those skilled in the art will understand that device 10 may specifically be a mobility management network element in the above embodiments, and may be used to execute the various processes and / or steps corresponding to the mobility management network element in the above method embodiments; or, device 10 may specifically be a terminal device in the above embodiments, and may be used to execute the various processes and / or steps corresponding to the terminal device in the above method embodiments. To avoid repetition, further details are omitted here.
[0499] The apparatus 10 of each of the above-described schemes has the function of implementing the corresponding steps performed by the entities (such as the first communication device, the first network element, and the second communication device) in the above-described methods. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above-described functions; for example, the transceiver unit can be replaced by a transceiver (for example, the transmitting unit in the transceiver unit can be replaced by a transmitter, and the receiving unit in the transceiver unit can be replaced by a receiver), and other units, such as processing units, can be replaced by processors, which respectively execute the transceiver operations and related processing operations in each method embodiment.
[0500] In addition, the transceiver unit 11 can also be a transceiver circuit (for example, it may include a receiving circuit and a transmitting circuit), and the processing unit can be a processing circuit.
[0501] Figure 16 This is a schematic diagram of another communication device 20 provided in an embodiment of this application. The device 20 includes a processor 21, which is used to execute computer programs or instructions stored in a memory 22, or to read data / signaling stored in the memory 22, to perform the methods in the above-described method embodiments. Optionally, there may be one or more processors 21.
[0502] Optionally, such as Figure 16 As shown, the device 20 also includes a memory 22 for storing computer programs or instructions and / or data. The memory 22 may be integrated with the processor 21 or may be disposed separately. Optionally, there may be one or more memories 22.
[0503] Optionally, such as Figure 16 As shown, the device 20 also includes a transceiver 23 for receiving and / or transmitting signals. For example, the processor 21 controls the transceiver 23 to receive and / or transmit signals.
[0504] As one approach, the device 20 is used to implement the operations performed by the first communication device, the first network element, and the second communication device in the various method embodiments described above.
[0505] It should be understood that the processor mentioned in the embodiments of this application can be a central processing unit (CPU), or it can be one or more combinations of other general-purpose processors, digital signal processors (DSPs), microprocessor units (MPUs), microcontroller units (MCUs), graphics processing units (GPUs), field-programmable gate arrays (FPGAs), artificial intelligence processors (AI processors), or neural processing units (NPUs); or, the processor mentioned in the embodiments of this application can be an ASIC or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0506] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be cache or random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DRRAM).
[0507] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.
[0508] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0509] This application also provides a chip system (or processing system) including logic circuits and input / output interfaces.
[0510] The logic circuit can be a processing circuit in the chip system. The logic circuit can be coupled to a memory cell, calling instructions from the memory cell, enabling the chip system to implement the methods and functions of the embodiments of this application. The input / output interface can be an input / output circuit in the chip system, outputting processed information or inputting data or signaling information to be processed into the chip system for processing.
[0511] As one approach, the chip system is used to implement the operations performed by the first communication device, the first network element, and the second communication device in the various method embodiments described above.
[0512] For example, the logic circuit is used to implement the processing-related operations performed by the first communication device, the first network element, and the second communication device in the above method embodiments; the input / output interface is used to implement the sending and / or receiving-related operations performed by the first communication device, the first network element, and the second communication device in the above method embodiments.
[0513] This application also provides a computer-readable storage medium storing computer instructions for implementing the methods executed by the first communication device, the first network element, and the second communication device in the above-described method embodiments.
[0514] For example, when the computer program is executed by the computer, the computer can implement the methods performed by the first communication device, the first network element, and the second communication device in the various embodiments of the above methods.
[0515] This application also provides a computer program product comprising instructions that, when executed by a computer, implement the methods performed by the first communication device, the first network element, and the second communication device in the above-described method embodiments.
[0516] This application also provides a communication system, including the aforementioned first network element and first communication device. Optionally, the communication system further includes the aforementioned second communication device.
[0517] The explanations and beneficial effects of the relevant contents in any of the devices provided above can be found in the corresponding method embodiments provided above, and will not be repeated here.
[0518] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0519] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0520] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of apparatus or units may be electrical, mechanical, or other forms.
[0521] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0522] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0523] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0524] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method, characterized in that, include: Receive first ciphertext, which is obtained by encrypting second ciphertext based on a first security algorithm. The second ciphertext is obtained by encrypting first data based on N first keys corresponding to the second security algorithm, where N is an integer greater than 1. N second keys are obtained based on the N first keys, and the N second keys are obtained by encrypting the N first keys based on the first security algorithm; The first ciphertext is decrypted based on the N second keys to obtain the third ciphertext, which is in the ciphertext state corresponding to the first security algorithm; During the decryption process, the N second keys and the first ciphertext are in the ciphertext state corresponding to the first security algorithm.
2. The method according to claim 1, characterized in that, The process of obtaining N second keys based on the N first keys includes: Generate the N first keys; Receive the encryption key corresponding to the first security algorithm from the first communication device; The N first keys are encrypted using the encryption key to obtain N second keys.
3. The method according to claim 1, characterized in that, The process of obtaining N second keys based on the N first keys includes: Generate the N first keys; Send the N first keys to the first communication device; Receive the N second keys from the first communication device.
4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: The third ciphertext is calculated based on the calculation key corresponding to the first security algorithm to obtain the first calculation result; Send the first calculation result; During the calculation process, the third ciphertext is in the ciphertext state corresponding to the first security algorithm.
5. The method according to claim 4, characterized in that, The method further includes: Receive the computation key.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: A second request message is sent to a first communication device. The second request message is used to request that data from a second communication device be encrypted based on the first security algorithm. The second request message includes a first identifier, which is associated with the first security algorithm.
7. The method according to claim 6, characterized in that, Before sending the second request message to the first communication device, the method further includes: It is determined that the second communication device will be provided with computing services based on the first security algorithm.
8. The method according to claim 7, characterized in that, The determination to provide computing services based on the first security algorithm to the second communication device includes: Based on the subscription information of the second communication device, it is determined that computing services based on the first security algorithm will be provided to the second communication device.
9. The method according to claim 8, characterized in that, The determination to provide computing services based on the first security algorithm to the second communication device based on the subscription information of the second communication device includes: Based on the contract information, a security service policy for the second communication device is determined, and the security service policy is used to indicate the security protection requirements of the second communication device. According to the security service policy, the second communication device is determined to provide computing services based on the first security algorithm.
10. The method according to any one of claims 7 to 9, characterized in that, The first data is data from the first service, and the determination to provide computing services based on the first security algorithm to the second communication device includes: It is determined that the first service will be provided with computing services based on the first security algorithm.
11. The method according to any one of claims 6 to 10, characterized in that, The first identifier includes at least one of the following: The identifier of the second communication device, the identifier of the service to which the first data belongs, or the identifier of the service area to which the first communication device belongs.
12. The method according to any one of claims 6 to 11, characterized in that, The method further includes: The first identifier is sent to the second communication device.
13. A communication method, characterized in that, Applied to a first communication device, the method includes: Send a first ciphertext to the first network element. The first ciphertext is obtained by encrypting a second ciphertext based on a first security algorithm. The second ciphertext is obtained by encrypting the first data of the second communication device based on N first keys corresponding to the second security algorithm, where N is an integer greater than 1. The system receives a first calculation result from the first network element. The first calculation result is obtained by calculating the third ciphertext based on the calculation key corresponding to the first security algorithm. The third ciphertext is obtained by decrypting the first ciphertext based on N second keys. The N second keys are obtained by encrypting the N first keys based on the first security algorithm. The N second keys support decryption of the first ciphertext in the ciphertext state corresponding to the first security algorithm. The first calculation result is decrypted using the decryption key corresponding to the first security algorithm to obtain the second calculation result. The second calculation result, which is securely protected by the third security algorithm, is sent to the second communication device. The third security algorithm is either the second security algorithm or the third security algorithm is determined through negotiation between the second communication device and the first communication device.
14. The method according to claim 13, characterized in that, When the third security algorithm is the second security algorithm, the method further includes: Send the second calculation result to the first network element; Receive the second calculation result, which is securely protected by the third security algorithm, from the first network element.
15. The method according to claim 13, characterized in that, When the third security algorithm is determined through negotiation between the second communication device and the first communication device, the method further includes: The second calculation result is protected by the third security algorithm to obtain the second calculation result protected by the third security algorithm.
16. The method according to any one of claims 13 to 15, characterized in that, The method further includes: Send the encryption key corresponding to the first security algorithm to the first network element.
17. The method according to any one of claims 13 to 15, characterized in that, The method further includes: Receive the N first keys from the first network element; Based on the encryption key corresponding to the first security algorithm, the N first keys are encrypted respectively to obtain N second keys; Send the N second keys to the first network element.
18. The method according to any one of claims 13 to 17, characterized in that, The method further includes: The system receives a second request message from the first network element. The second request message is used to request that data from the second communication device be encrypted based on the first security algorithm. The second request message includes a first identifier, which is associated with the first security algorithm.
19. The method according to claim 18, characterized in that, The first identifier includes at least one of the following: The identifier of the second communication device, the identifier of the service to which the first data belongs, or the identifier of the service area to which the first communication device belongs.
20. The method according to claim 18 or 19, characterized in that, The method further includes: Receive the second ciphertext and the first identifier from the second communication device; The first security algorithm is determined based on the first identifier, and the second ciphertext is encrypted based on the first security algorithm to obtain the first ciphertext.
21. The method according to any one of claims 13 to 20, characterized in that, The method further includes: Send a first indication message to the first network element. The first indication message is used to indicate that the first ciphertext is ciphertext obtained by encrypting based on the first security algorithm.
22. A communication method, characterized in that, Applied to a first communication device, the method includes: Receive N first keys corresponding to the second security algorithm from the first network element; Based on the encryption key corresponding to the first security algorithm, the N first keys are encrypted respectively to obtain N second keys; Send the N second keys to the first network element; The N second keys support the decryption of ciphertext obtained based on the second security algorithm in the ciphertext state corresponding to the first security algorithm.
23. A communication device, characterized in that, include: One or more modules for performing the method as described in any one of claims 1 to 12, or one or more modules for performing the method as described in any one of claims 13 to 21, or one or more modules for performing the method as described in claim 22.
24. A communication device, characterized in that, The method includes at least one processor for executing a computer program or instructions to cause the method of any one of claims 1 to 12 to be performed, or to cause the method of any one of claims 13 to 21 to be performed, or to cause the method of claim 22 to be performed.
25. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program or instructions that, when executed by a processor, implement the method as described in any one of claims 1 to 22.
26. A computer program product, characterized in that, It includes a computer program or instructions that, when executed by a processor, implement the method as described in any one of claims 1 to 22.