Calculation unit, calculation method, communication system, and program
By encrypting sequence numbers with a secret key in wireless communication systems, the vulnerability of key erasure is mitigated, ensuring secure protection of individual privacy through reversible encryption.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- KDDI CORP
- Filing Date
- 2024-11-05
- Publication Date
- 2026-05-19
AI Technical Summary
Existing wireless communication systems face security vulnerabilities where attackers can intercept and erase sequence numbers, compromising individual privacy by determining the duration of stay, as sequence numbers were not previously considered highly confidential.
Implement encryption processes, such as Rocca-S or AEGIS-256, to protect sequence numbers by making key erasure impossible and reversible, using operations like Enc(AK, SQN) instead of SQN(XOR)AK in authentication token calculations.
This approach enhances security by preventing key erasure and reducing the risk of sequence number leakage, thus protecting individual privacy during mutual authentication.
Smart Images

Figure 2026081509000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an arithmetic device, an arithmetic method, a communication system, and a program.
Background Art
[0002] Conventionally, a wireless communication system including a terminal device and a network is known. Usually, when starting new information communication between such a terminal device and a network, mutual authentication is performed. For example, Non-Patent Document 1 defines specific specifications for such mutual authentication.
[0003] In such specific specifications of mutual authentication, first, a serving network (SN) having a visitor location register (VLR) transmits an authentication data request to a home environment (HE) having a home location register (HLR), and the home environment responds thereto and returns an authentication data response consisting of a batch of authentication vectors. Next, in order to execute authentication between the serving network (SN) and the mobile station (MS), the serving network (SN) transmits a user authentication request. When a user authentication request is made, an authentication token AUTN is calculated.
[0004] The calculation of the authentication token AUTN includes the exclusive logical sum of a sequence number (SQN; sequence number) formed in the home environment and an authentication key (AK). Here, Non-Patent Document 2 reports the security vulnerability when performing an exclusive logical sum operation using the sequence number and the authentication key (AK).
Prior Art Documents
Non-Patent Documents
[0005]
Non-Patent Document 1
Non-Patent Document 2
[0006] Specifically, if an attacker intercepts an authentication token containing a sequence number transmitted from the network, they can erase the key by performing an exclusive OR operation again. In other words, since an attacker can obtain the sequence number from the authentication token, there is a possibility that the sequence number information will be leaked. Initially, sequence numbers were not considered highly confidential information. However, because it is possible to determine the duration of stay from the sequence number, there is a need to protect sequence numbers as information related to individual privacy.
[0007] This invention has been made in consideration of these circumstances, and its objective is to provide a computing device, a computing method, a communication system, and a program that can realize a mutual authentication method that can protect information concerning the privacy of persons operating terminal devices. [Means for solving the problem]
[0008] (1) One aspect of the present invention is a computing device that performs calculations in communication between a terminal device and a network, and uses a given key and information relating to the privacy of the person operating the terminal device, and performs calculations in a manner that makes it impossible to erase the key and is reversible. (2) In another aspect of the present invention, in the calculation device described in (1) above, the calculation is used to derive AUTN or AUTS. (3) In another aspect of the present invention, in the computing device described in (1) or (2) above, the information relating to the privacy of the person operating the terminal device is a sequence number. (4) In addition, in one aspect of the present invention, the method in which the key cannot be erased and is reversible in any of the computing devices described in (1) to (3) above is an encryption process. (5) In another aspect of the present invention, in the computing device described in (4) above, the encryption process is Rocca-S. (6) In another aspect of the present invention, in any of the computing devices described in (1) to (5) above, the network is a function for user authentication. (7) Another aspect of the present invention is a calculation method for performing calculations in communication between a terminal device and a network, the calculation method using a given key and information relating to the privacy of the person operating the terminal device, in a manner that makes it impossible to erase the key and is reversible. (8) Another aspect of the present invention is a communication system comprising a terminal device and a network, wherein, in communication between the terminal device and the network, a given key and information relating to the privacy of the person operating the terminal device are used to perform calculations in a manner that makes it impossible to erase the key and is reversible. (9) Another aspect of the present invention is a program that causes a computer to perform calculations in communication between a terminal device and a network, the program which uses a given key and information relating to the privacy of a person operating the terminal device to perform calculation steps in a manner that makes it impossible to erase the key and is reversible. [Effects of the Invention]
[0009] According to the present invention, it is possible to provide a computing device, a computing method, and a communication system that can realize a mutual authentication method capable of protecting information regarding the privacy of persons operating terminal devices. [Brief explanation of the drawing]
[0010] [Figure 1] This figure shows a schematic network architecture of a wireless communication system according to one embodiment. [Figure 2] This is the first flowchart illustrating the mutual authentication process of the wireless communication system according to this embodiment. [Figure 3] This is a first schematic diagram showing an example of calculations in the authentication center according to this embodiment. [Figure 4] This is a second flowchart illustrating the mutual authentication process of the wireless communication system according to this embodiment. [Figure 5] This is a second schematic diagram showing an example of calculations in the authentication center according to this embodiment. [Figure 6] This is a block diagram showing an example of the internal configuration of the arithmetic unit according to this embodiment. [Modes for carrying out the invention]
[0011] [Embodiment] Preferred embodiments of the computing device, computing method, communication system, and program according to aspects of the present invention will be described in detail below with reference to the accompanying drawings. It should be noted that the embodiments of the present invention are not limited to these embodiments, and include various modifications and improvements. In other words, the components described below include those that are easily conceivable to those skilled in the art, and those that are substantially the same, and the components described below can be combined as appropriate. Furthermore, various omissions, substitutions, or modifications of components can be made without departing from the spirit of the present invention. Also, in the following drawings, the scale and number of components in each structure may differ from the scale and number of components in the actual structure in order to make each structure easier to understand.
[0012] In the following description, for the sake of convenience, terms and names defined in the IETF (Internet Engineering Task Force) and 3GPP (registered trademark) LTE (3rd Generation Partnership Project Long Term Evolution) standards may be used. However, this embodiment is not limited by such terms and names and is also applicable to systems based on other standards.
[0013] [Wireless Communication System] FIG. 1 is a diagram showing a schematic network architecture of a wireless communication system according to an embodiment. First, the outline of the wireless communication system to which the arithmetic method and arithmetic device according to this embodiment are applied will be described while referring to the figure. In the figure, as an example, a 5G network architecture is shown. In the example described below, a wireless communication system will be described, but the communication system according to this embodiment is also applicable to a wired communication system.
[0014] The network elements of the 5G network architecture include a UE (User Equipment). In the following description, the UE may be described as a user device, user terminal, user equipment, terminal device, or simply a terminal, etc. The UE may be a smartphone, tablet terminal, wearable terminal, etc.
[0015] The network architecture shown in the figure further includes a Radio Access Network (RAN), an Access and Mobility Function (AMF), a Unified Data Management (UDM), an Authentication Server Function (AUSF), a Security Anchor Function (SEAF), etc.
[0016] The main function of the RAN is to control users for wireless access to the mobile communication network. Conceptually, the RAN is included between devices (e.g., smartphones, computers, or any remote controller) and provides a connection to the core network of the devices.
[0017] The AMF network element is responsible for terminal access management and mobility management, such as registration management, connection management, mobility management, reachability management, etc. In actual applications, the AMF network element includes the mobility management function of the Mobility Management Entity (MME) within the LTE network framework and further includes an access management function.
[0018] The SEAF network element is configured to complete authentication for the UE. In 5G, as shown in the figure, the function of SEAF may be combined with the AMF.
[0019] The AUSF network element has an authentication server function and is configured to respond to the authentication requested by the SEAF network element. During the authentication process, the AUSF network element receives the authentication vector sent from the UDM, processes the authentication vector, and sends the processed authentication vector to the SEAF.
[0020] The UDM network element may store the user's subscription information and may generate authentication parameters, etc.
[0021] The ARPF network element has an authentication information repository and processing function and is configured to store the user's long-term authentication information, such as the key K. In 5G, the function of the ARPF network element may be combined with the UDM network element.
[0022] [Procedure for Authentication Key Sharing] The procedure for authentication key sharing will be described while referring to FIGS. 2 and 3.
[0023] Figure 2 is a first flowchart showing the mutual authentication flow of the wireless communication system according to this embodiment. The figure shows the authentication key sharing protocol in 3GPP®. The figure shows the exchange of information between the Mobile Station (MS), Visitor Location Register (VLR) / Serving Network (SN), and Home Environment (HE) / Home Location Register (HLR). In the following description, MS may also be referred to as the terminal device, SN / VLR and HE / HLR as the network, and HE / HLR as the authentication center.
[0024] (Step S111) First, the SN / VLR makes an Authentication Data Request to the HE / HLR.
[0025] (Step S112) When HE / HLR receives an authentication data request from SN / VLR, it generates one or more (e.g., N, where N is an integer greater than or equal to 1) authentication vectors AV(1··N).
[0026] (Step S113) HE / HLR responds to SN / VLR with one or more generated authentication vectors AV(1··N) (Authentication Data Response).
[0027] (Step S114) The SN / VLR stores one or more authentication vectors obtained from the HE / HLR upon request.
[0028] Furthermore, the process from step S111 to step S114 can also be described as the process of distributing the authentication vector from HE to SN.
[0029] (Step S115) SN / VLR selects authentication vector AV(i) from the stored one or more authentication vectors AV(1··N).
[0030] (Step S116) The SN / VLR makes a user authentication request to the MS. In the user authentication request, the SN / VLR sends a random challenge RAND(i) and an authentication token AUTN(i) to the MS (User Authentication Request). The authentication token AUTN(i) will be described later with reference to Figure 3.
[0031] (Step S117) The MS verifies whether it can accept the authentication token AUTN(i). If the MS can accept the authentication token AUTN(i), it computes the response RES(i).
[0032] (Step S118) The response RES(i) calculated by the MS is sent back to the SN / VLR as the user authentication response (User Authentication Response).
[0033] (Step S119) The MS further computes a cipher key (CK(i)) and an integrity key (IK(i)).
[0034] (Step S120) SN / VLR compares the received response RES(i) with XRES.
[0035] (Step S121) If RES(i) and the Expected Response (XRES) match, the SN / VLR determines that authentication and key agreement exchange are complete and selects the Cipher Key (CK(i)) and the Integrity Key (IK(i)).
[0036] Furthermore, the process from step S115 to step S121 can also be described as the authentication and key establishment process.
[0037] Figure 3 is a first schematic diagram showing an example of calculations in the authentication center according to this embodiment. In the authentication center, calculations as shown in the figure are performed. f1 and f2 are message authentication functions. f3, f4 and f5 are key generation functions.
[0038] In this case, the Message Authentication Code (MAC) can be expressed by the following formula (1).
[0039] MAC=f1K(SQN||RAND||AMF)...(1)
[0040] Furthermore, the expected response (XRES) can be expressed by the following formula (2).
[0041] XRES = f2K(RAND) ... (2)
[0042] Furthermore, the encryption key (Cipher Key) CK can be expressed by the following formula (3).
[0043] CK = f3K(RAND)···(3)
[0044] Furthermore, the Integrity Key (IK) used to authenticate integrity can be expressed by the following formula (4).
[0045] IK = f4K(RAND) ... (4)
[0046] Furthermore, the Anonymous Key (AK) can be expressed by the following formula (5).
[0047] AK = f5K(RAND)···(5)
[0048] The authentication token AUTN can be expressed by the following formula (6) using the sequence number SQN and the anonymous key AK.
[0049]
number
[0050] Here, as described in Non-Patent Document 2 above, the attacker can obtain the sequence number by utilizing and deriving the following equation (7).
[0051]
number
[0052] In other words, if an attacker intercepts an authentication token containing a sequence number transmitted from the network, they can erase the key by performing an exclusive OR operation again, potentially leading to the leakage of sequence number information. Initially, sequence numbers were not considered highly confidential information, but because it is possible to determine the duration of stay from sequence numbers, there has been a demand to protect sequence numbers as information related to the privacy of those operating terminal devices.
[0053] Therefore, according to this embodiment, an authentication token AUTN is calculated using a given anonymous key AK and a sequence number (which can also be said to be information related to the privacy of the person operating the terminal device) in a way that makes it impossible to erase the key and is reversible. Conventionally, since the challenge of protecting the sequence number was not anticipated, the relatively lightweight operation of exclusive OR has been used. Conventionally, the exclusive OR used in calculations is reversible, but it is an operation that allows the key to be erased.
[0054] Encryption can be used as an example of an operation that is impossible to erase and is reversible. Specifically, in the calculation of the authentication token AUTN, by performing the operation Enc(AK, SQN) instead of SQN(XOR)AK, the attack described in Non-Patent Document 2 can be prevented. Enc(AK, SQN) is the encryption process of the sequence number SQN using the secret key AK.
[0055] Specifically, one example of encryption processing is the algorithm defined as f8. Another example is the use of a proprietary symmetric-key algorithm tailored to the length of the sequence number SQN. More specific examples of encryption processing include Rocca-S and AEGIS-256. Note that the operations according to this embodiment are not limited to such encryption processing, and other operations that make key erasure impossible and are reversible may also be used. Operations that make key erasure impossible and are reversible may include, for example, matrix transformations.
[0056] This process is performed on both the receiving and transmitting sides of AUTN. Specifically, if the operation Enc(AK, SQN) is performed instead of SQN(XOR)AK, the sequence number SQN is decrypted by decrypting the encrypted document. This improves security without affecting other parts of the current 3GPP®.
[0057] [Resynchronization Procedure] Next, the resynchronization procedure will be explained with reference to Figures 4 and 5. During resynchronization, AUTS is used instead of the authentication token AUTN. Since SQN(XOR)AK is also used in AUTS, there is a possibility of being subjected to the attack described in Non-Patent Document 2. Therefore, in this embodiment, even during resynchronization, AUTS is generated by performing an operation that makes key erasure impossible and is reversible, instead of using SQN(XOR)AK.
[0058] Figure 4 is a second flowchart showing the mutual authentication flow of the wireless communication system according to this embodiment. This figure shows the resynchronization protocol in 3GPP®. This figure shows the exchange of information between the Mobile Station (MS), the Serving Network (SN), and the Home Environment (HE).
[0059] (Step S211) This step corresponds to step S116, which was described with reference to Figure 2. SN makes a user authentication request to MS.
[0060] (Step S212) Here, if synchronization fails, the MS sends an AUTS to the SN. The AUTS will be described later with reference to Figure 5.
[0061] (Step S213) When SN receives a synchronization failure message including AUTS from MS, it sends an authentication data request including a synchronization failure ind, along with the parameters RAND and AUTS, to HE.
[0062] (Step S214) When HE receives such an authentication data request, including a Synch Failure ind, it sends an authentication data response to SN. The authentication data response includes an authentication vector.
[0063] Figure 5 is a second schematic diagram showing an example of a calculation in the authentication center according to this embodiment. In the authentication center, the calculation shown in the figure is performed. As shown in the figure, the exclusive OR of the sequence number SQN and the anonymous key AK is also used in the calculation of AUTS. As explained with reference to Figure 3, in such cases there was a problem that an attacker could guess the sequence number.
[0064] Therefore, according to this embodiment, in the calculation of AUTS, instead of the exclusive OR operation between the sequence number SQN and the anonymous key AK, an operation that makes key erasure impossible and is reversible is used. Specifically, since the function FNC shown in the figure is an exclusive OR operation, in this embodiment, the function FNC is made into an operation that makes key erasure impossible and is reversible. As an example of a specific calculation method, it is possible to use a method similar to the one described with reference to Figure 3.
[0065] [Internal structure] Figure 6 is a block diagram showing an example of the internal configuration of a computing device according to this embodiment. The computing device shown in the figure is provided in at least one of the UE or the network. At least some of the functions of the computing device can be realized using a computer as shown in the figure. The computer consists of a central processing unit (processor) 901, RAM 902, input / output ports 903, input / output devices 904 and 905, etc., and a bus 906. The computer itself can be realized using existing technology. The central processing unit 901 executes instructions contained in programs read from RAM 902, etc. The central processing unit 901 writes data to RAM 902, reads data from RAM 902, and performs arithmetic and logical operations according to each instruction. RAM 902 stores data and programs. Each element contained in RAM 902 has an address and can be accessed using that address. RAM stands for "Random Access Memory". Input / output ports 903 are ports for the central processing unit 901 to exchange data with external input / output devices, etc. Input / output devices 904 and 905 are input / output devices. Input / output devices 904 and 905 exchange data with the central processing unit 901 via input / output port 903. Bus 906 is a common communication channel used inside the computer. For example, the central processing unit 901 reads and writes data to RAM 902 via bus 906. Also, for example, the central processing unit 901 accesses input / output ports via bus 906. Furthermore, all or part of each functional unit of the network 30 or terminal device 50 may be implemented using hardware such as ASICs, PLDs, or FPGAs. Furthermore, all or part of each functional unit may be implemented by a combination of software and hardware.
[0066] [Summary of Embodiments] According to the embodiments described above, the calculation method according to this embodiment performs calculations in wireless communication between a terminal device and a network. Furthermore, the calculation method uses a given key (anonymous key AK) and information regarding the privacy of the person operating the terminal device (e.g., sequence number SQN) to perform calculations in a way that makes it impossible to erase the key and is reversible. By adopting such a configuration, even if an authentication token containing a sequence number transmitted from the network is intercepted, an attacker cannot erase the key, and the risk of leakage of sequence number information can be reduced.
[0067] The calculation method described above is performed by a computing device installed in the terminal device or network. This calculation is used to derive AUTN or AUTS. Therefore, according to this embodiment, a mutual authentication method is available that can protect information regarding the privacy of the person operating the terminal device.
[0068] Furthermore, in the embodiments described above, the information relating to the privacy of the person operating the terminal device is the sequence number. Conventionally, sequence numbers were not considered highly confidential information. However, since it is possible to determine the time spent on the device based on the sequence number, there has been a need to protect the sequence number as information relating to the privacy of the person operating the terminal device. According to this embodiment, since the leakage of sequence numbers can be suppressed, information relating to an individual's privacy can be protected.
[0069] Furthermore, according to this embodiment, existing encryption processes can be used as an example of a method that makes key erasure impossible and is reversible. More specific examples of encryption processes include Rocca-S and AEGIS-256. According to this embodiment, personal and privacy-related information can be easily protected.
[0070] Furthermore, the above-described embodiment makes it possible to realize a mutual authentication method that can protect information regarding the privacy of the person operating the terminal device, thereby contributing to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation."
[0071] Although embodiments of the present invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments, and design modifications and the like are also included within the scope of the gist of the present invention.
[0072] Alternatively, computer programs for realizing the functions of each of the above-mentioned devices may be recorded on a computer-readable recording medium, and the programs recorded on this recording medium may be loaded into a computer system and executed. Note that the term "computer system" here may include hardware such as an operating system and peripheral devices. Furthermore, "computer-readable recording media" refers to writable non-volatile memory such as flexible disks, magneto-optical disks, ROMs, and flash memory, portable media such as DVDs (Digital Versatile Discs), and storage devices such as hard disks built into computer systems.
[0073] Furthermore, "computer-readable recording media" also includes volatile memory (e.g., DRAM (Dynamic Random Access Memory)) within a computer system that acts as a server or client when a program is transmitted via a network such as the Internet or a communication line such as a telephone line, which retains the program for a certain period of time. In addition, the above program may be transmitted from the computer system that stores the program in a storage device, etc., to another computer system via a transmission medium or by transmission waves within the transmission medium. Here, the "transmission medium" for transmitting the program refers to a medium that has the function of transmitting information, such as a network such as the Internet or a communication line such as a telephone line. Furthermore, the above program may be for the purpose of realizing a part of the above-mentioned functions. Moreover, it may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already recorded in the computer system. [Explanation of symbols]
[0074] MS…Mobile Station, SN…Serving Network, VLR…Visitor Location Register, HE…Home Environment, HLR…Home Location Register
Claims
1. A computing device that performs calculations in communication between a terminal device and a network, Using the given key and information regarding the privacy of the person operating the terminal device, the calculation is performed in a way that makes it impossible to erase the key and is reversible. Computing device.
2. The aforementioned calculation is used to derive AUTON or AUTOS. The computing device according to claim 1.
3. The information relating to the privacy of the person operating the terminal device is a sequence number. The computing device according to claim 1 or claim 2.
4. The method that makes it impossible to erase the aforementioned key and is reversible is encryption. The computing device according to claim 1 or claim 2.
5. The encryption process is Rocca-S. The computing device according to claim 4.
6. The aforementioned network is a function for user authentication. The computing device according to claim 1 or claim 2.
7. A calculation method for performing calculations in communication between a terminal device and a network, Using the given key and information regarding the privacy of the person operating the terminal device, the calculation is performed in a way that makes it impossible to erase the key and is reversible. Calculation method.
8. A communication system comprising terminal devices and a network, In communication between the terminal device and the network, a given key and information regarding the privacy of the person operating the terminal device are used to perform calculations in a manner that makes it impossible to erase the key and is reversible. Communication system.
9. On the computer, A program that performs calculations in communication between a terminal device and a network, Using the given key and information regarding the privacy of the person operating the terminal device, the system performs a calculation step in a manner that makes it impossible to erase the key and is reversible. program.