Domain-based key management methods and devices
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2023-06-30
- Publication Date
- 2026-07-30
Smart Images

Figure 2026525391000001_ABST
Abstract
Description
[Technical Field]
[0001] This application relates to the field of communication technology, and more particularly to domain-based key management methods and devices. [Background technology]
[0002] With the convergence of communication, perception, and artificial intelligence, perception is emerging as an inherent capability of future communication networks, providing massive amounts of data to intelligent applications. Networks will function as both data producers and providers, offering reliable data services for various intelligent applications. Furthermore, networks will also function as network data consumers, leveraging data-driven intelligent applications to improve network performance and operational efficiency.
[0003] Furthermore, with social progress and growing awareness of data ownership, the requirements for data privacy protection are becoming increasingly stringent. How to fully explore and realize data values, how to efficiently utilize communication and computing resources within communication networks, and how to provide end-to-end data privacy and security protection technologies while meeting high security and privacy requirements, as well as while implementing various new network capabilities (such as intrinsic intelligence and ubiquitous awareness) and new services (such as immersive augmented reality (XR), digital twins, and meta-universes), are issues that urgently need to be addressed. [Overview of the Initiative]
[0004] This application provides a domain-based key management method and apparatus for managing homomorphic task keys in a communication network, supporting the application of homomorphic tasks to a communication network, and providing privacy computing capabilities to a communication network.
[0005] According to a first aspect, one embodiment of the present application provides a domain-based key management method. The method may be performed by a first control network element or by a component of the first control network element (e.g., a processor, chip, chip system, etc.). For example, the first control network element performs the method. The method includes the steps of the first control network element obtaining a first homomorphic encryption key corresponding to a first domain, The first control network element transmits the first homomorphic encryption key to M first homomorphic activation units belonging to the first domain, where M is an integer of 1 or more. The first control network element transmits a first homomorphic compute key to N second homomorphic enablement units belonging to the first domain, wherein N is an integer of 1 or more, and the first homomorphic compute key is determined based on the first homomorphic encryption key and / or the first homomorphic decryption key corresponding to the first homomorphic encryption key. Includes.
[0006] The homomorphic activation unit (for example, the first homomorphic activation unit or the second homomorphic activation unit) may be a terminal device, an access network device, a core network element, an isolated node, an application layer function node, etc.
[0007] According to the method described above, homomorphic tasks and key management can be performed on a domain basis. Each domain corresponds to one homomorphic encryption key, and all users within each domain correspond to the same homomorphic encryption key. The homomorphic encryption key may be decoupled from user state and specific homomorphic tasks, so that the same homomorphic ciphertext of a user can be provided to homomorphic computation parties of different homomorphic tasks for homomorphic computation, improving the reusability of the user's homomorphic ciphertext and facilitating the transfer of homomorphic ciphertext between different homomorphic tasks. In addition, domain-level homomorphic encryption keys rather than user-level homomorphic encryption keys (for example, each homomorphic encryption party corresponds to one homomorphic encryption key) can reduce the number of homomorphic encryption keys within homomorphic tasks, reduce the derivation of homomorphic computation keys, reduce the complexity of homomorphic computation, and improve the efficiency of homomorphic computation.
[0008] In a possible design, the N second homomorphic enablement units are homomorphic computation parties participating in the first homomorphic task within the first domain. The first homomorphic computation key is determined based on K homomorphic encryption keys and / or K homomorphic decryption keys corresponding to K domains and participating in the first homomorphic task, wherein the participants in the first homomorphic task are distributed across the K domains, the K domains include the first domain, the K homomorphic encryption keys include the first homomorphic encryption key, and the K homomorphic decryption keys include the first homomorphic decryption key, where K is an integer greater than or equal to 1.
[0009] In the above design, if the participants in the first homomorphism task are distributed across K domains, the first homomorphism computation key may be determined based on K homomorphism encryption keys and / or K homomorphism decryption keys corresponding to the K domains, and as a result the first homomorphism computation key may fit the homomorphism encryption keys and / or homomorphism decryption keys of the K domains, supporting the computation of encrypted ciphertext from the K domains.
[0010] In a possible design, K domains are obtained by partitioning based on the network architecture layer and / or service type slice. The first domain is used as an example. The first domain may correspond to the core network, access network, or application layer. The aforementioned first domain corresponds to a data network, cloud server, cloud server cluster, or application in the application layer. The first domain corresponds to an access network set, the access network set includes P access network nodes or cells, where P is an integer of 1 or more. The first domain corresponds to the public land mobile network (PLMN) of the core network, or one or more network elements within the PLMN of the core network, or The first domain corresponds to a network slice, a network slice of the core network, or a network slice of the application layer.
[0011] The aforementioned design provides different domain partitioning schemes to meet different requirements for domain-based key management.
[0012] In a possible design, the acquisition of a first homomorphic encryption key corresponding to a first domain by a first control network element includes the derivation of a first homomorphic encryption key and a first homomorphic decryption key corresponding to the first domain. In this design, the control network element derives the keys without requiring excessive exchanges during key derivation, thereby reducing communication overhead.
[0013] In a possible design, the first control network element obtains a first homomorphic encryption key and a first homomorphic decryption key corresponding to a first domain from a key management party. The key management party is, for example, a key management center (KMC). In this design, the key management party may also obtain information (or parameters related to key derivation) about the homomorphic encryption and decryption keys for the domains corresponding to each control network element, thereby enabling the key management party to quickly derive homomorphic computation keys applicable to multiple domains within a homomorphic task.
[0014] The two designs described above support different key derivation mechanisms. Homomorphic encryption and decryption keys may be derived by a control network element or a key management party, thereby satisfying different key management requirements. The key management party derives the keys.
[0015] In a possible design, the method further includes the first control network element deciding to establish a secure channel to the key management party before the first control network element obtains a first homomorphic encryption key and a first homomorphic decryption key corresponding to a first domain from the key management party.
[0016] In the aforementioned design, before the control network element exchanges keys with the key management party, the control network element and the key management party perform mutual authentication and establish a secure channel to help avoid key leakage and improve security.
[0017] In a possible design, before the first control network element transmits the first homomorphic compute key to the N second homomorphic activating units belonging to the first domain, the method The first control network element receives a first homomorphic task request, the first homomorphic task request is used to request (or indicate) the configuration of the first homomorphic task, The first control network element transmits task configuration information to Q third homomorphic enablement units participating in the first homomorphic task within the first domain, wherein the task configuration information includes homomorphic task rolls of the Q third homomorphic enablement units, the Q third homomorphic enablement units include the N second homomorphic enablement units, the N second homomorphic enablement units are the homomorphic compute parties participating in the first homomorphic task within the first domain, and Q is an integer greater than or equal to N. It also includes.
[0018] Alternatively, before the first control network element transmits the first homomorphic compute key to the N second homomorphic activation units belonging to the first domain, the method: The first control network element receives a first homomorphic task subrequirement, the first homomorphic task subrequirement to (or indicate) that it constitutes the first homomorphic task in the first domain, The first control network element transmits task configuration information to Q third homomorphic enablement units participating in the first homomorphic task within the first domain, wherein the task configuration information includes homomorphic task rolls of the Q third homomorphic enablement units, the Q third homomorphic enablement units include the N second homomorphic enablement units, the N second homomorphic enablement units are the homomorphic compute parties participating in the first homomorphic task within the first domain, and Q is an integer greater than or equal to N. It also includes.
[0019] In the above design, homomorphic tasks can be managed on a domain-based basis. A control network element corresponding to each domain can manage homomorphic tasks on homomorphic activation units within the domain corresponding to the control network element. The load on the control network elements can be reduced through domain-based management, and management efficiency can be improved.
[0020] In a possible design, the participants in the first homomorphism task are distributed across the K domains, the K domains include the first domain, K is an integer greater than or equal to 1, and the method is The first control network element separately transmits a first homomorphic task subrequirement to (K-1) control network elements corresponding to (K-1) domains other than the first domain among the K domains, wherein the first homomorphic task subrequirement requests (indicates) that the first homomorphic task be constituted in the (K-1) domains. It also includes.
[0021] In the aforementioned design, if participants in a homomorphic task relate to multiple domains, the homomorphic task request may be divided into multiple homomorphic task subrequirements based on the domains, and the homomorphic task subrequirements are forwarded across domains by using control network elements within each domain to support the implementation of cross-domain homomorphic tasks.
[0022] In a possible design, the method further includes: A first control network element sends key parameters for a first domain to a key management party, the key parameters being determined based on a first homomorphic encryption key and / or first homomorphic decryption key corresponding to the first domain; and the first control network element receives a first homomorphic compute key from the key management party.
[0023] In the above design, the key management party can derive a homomorphic computation key based on the key parameters of the K domains participating in the homomorphic task, enabling the homomorphic computation key to be adapted to the homomorphic encryption key of the K domains participating in the homomorphic task, thereby supporting the implementation of cross-domain homomorphic tasks.
[0024] In a possible design, before the first control network element transmits the task configuration information to the Q third homomorphic enablement units participating in the first homomorphic task within the first domain, the method The first control network element determines the homomorphic task roll of the Q third homomorphic activators participating in the first homomorphic task within the first domain, based on the first homomorphic task request and the homomorphic capability information of L fourth homomorphic activators belonging to the first domain, wherein the L fourth homomorphic activators include the Q third homomorphic activators, and L is an integer greater than or equal to Q. It also includes.
[0025] The homomorphic capability information for a homomorphic enablement unit may include one or more of the following: the identifier of the homomorphic enablement unit, its type, homomorphic encryption capability level, homomorphic encryption security level, homomorphic encryption enablement identifier, homomorphic decryption enablement identifier, homomorphic computation enablement identifier, identifiers of supported homomorphic encryption algorithms, identifiers of supported homomorphic computation algorithms, etc. A homomorphic task request may include one or more of the following: the homomorphic task output type, the homomorphic task type, the homomorphic task quality requirements, data user parameters, the number of data users, the number of data providers, data provider parameters, etc.
[0026] According to the aforementioned design, the control network elements may select homomorphic enablement units based on the homomorphic capability information of each homomorphic enablement unit and the homomorphic task requirements carried in the homomorphic task request, in order to help improve the reliability of homomorphic tasks.
[0027] In a possible design, the method further includes the steps of: a first control network element acquiring homomorphic capability information for any one of L fourth homomorphic enablement units; and the first control network element generating a homomorphic capability profile for the fourth homomorphic enablement unit based on the homomorphic capability information for the fourth homomorphic enablement unit.
[0028] The first control network element can obtain homomorphic capability information of homomorphic enablement units by having them actively report by homomorphic enablement units (e.g., a fourth homomorphic enablement unit) or by sending a report request to a homomorphic enablement unit to request a report from that unit. According to the design described above, the homomorphic capability information of the homomorphic enablement units is maintained on the first control network element side, and the selection of homomorphic enablement units based on the homomorphic capability information of the homomorphic enablement units is supported, which helps to improve the reliability of homomorphic tasks.
[0029] In a possible design, the method further includes: a first control network element receives F first pieces of information from F second control network elements, the first piece of information from any one of the F second control network elements includes homomorphic capability information of at least one homomorphic enablement unit belonging to the domain corresponding to the second control network element, and the first control network element determines (K-1) domains to which participants in a homomorphic encryption task are distributed, where F is an integer greater than or equal to 1, based on the first homomorphism task request and the F first pieces of information.
[0030] In the aforementioned design, the control network elements can help perform accurate cross-domain scheduling of homomorphic tasks by determining the domains associated with a homomorphic task based on homomorphic capability information of homomorphic enablement units within each domain and homomorphic task requirements carried in a homomorphic task request.
[0031] According to a second aspect, one embodiment of the present application provides a domain-based key management method. The method may be performed by a key management party or by a component of the key management party (e.g., a processor, chip, chip system, etc.). For example, the key management party performs the method. The method is a step in which the key management party obtains key parameters for K domains participating in a first homomorphic task from K control network elements, wherein the participants in the first homomorphic task are distributed across the K domains, the K control network elements each correspond to one of the K domains, and the key parameter for any one of the K domains is determined based on the homomorphic encryption key and / or homomorphic decryption key of the domain, where K is an integer of 1 or more. The key management party determines the first homomorphic computation key for the first homomorphic task based on the key parameters of the K domains, The key management party separately transmits the first homomorphic computed key to the K control network elements, Includes.
[0032] In a possible design, K domains include a first domain, and K control network elements include a first control network element corresponding to the first domain, and the step of a key management party obtaining key parameters for K domains participating in a first homomorphic task from the K control network elements includes the step of the key management party receiving key parameters for the first domain from the first control network elements, the key parameters being determined based on a first homomorphic encryption key and / or first homomorphic decryption key corresponding to the first domain, and the step of the key management party separately transmitting a first homomorphic computation key to the K control network elements includes the step of the key management party transmitting a first homomorphic computation key to the first control network elements.
[0033] In a possible design, K domains include a first domain, and K control network elements include a first control network element corresponding to the first domain, and the method further includes the steps of: a key management party deriving a first homomorphic encryption key and a first homomorphic decryption key for the first domain; and the key management party transmitting the first homomorphic encryption key and the first homomorphic decryption key to the first control network element corresponding to the first domain.
[0034] In a possible design, the step of a key management party obtaining key parameters for K domains participating in a first homomorphic task from K control network elements includes the step of the key management party determining the key parameters of the first domain based on the first homomorphic encryption key and / or first homomorphic decryption key of the first domain.
[0035] In a possible design, K domains are obtained by partitioning based on the network architecture layer and / or service type slice.
[0036] In a possible design, the first domain corresponds to the core network, access network, or application layer. The aforementioned first domain corresponds to a data network, cloud server, cloud server cluster, or application in the application layer. The first domain corresponds to an access network set, the access network set includes P access network nodes or cells, where P is an integer of 1 or more. The first domain corresponds to a PLMN of the core network, or one or more network elements within a PLMN of the core network, The first domain corresponds to a network slice, a network slice of the core network, or a network slice of the application layer.
[0037] According to a third aspect, an embodiment of the present application provides a communication device. The device has a function to carry out the method according to the first or second aspect. The function may be implemented by hardware or by hardware running corresponding software. The hardware or software includes one or more modules corresponding to the function, for example, an interface unit and a processing unit.
[0038] In possible designs, the device may be a chip or an integrated circuit.
[0039] In a possible design, the device includes memory and a processor. The memory is configured to store instructions to be executed by the processor. Once the instructions are executed by the processor, the device may perform a method according to the first or second embodiment.
[0040] According to a fourth aspect, an embodiment of the present application provides a communication device. The communication device includes an interface circuit and a processor, the processor and the interface circuit being coupled to each other. The processor is configured to carry out the method according to the first or second aspect by using logic circuits or by executing instructions. The interface circuit is configured to receive signals from a communication device other than the communication device and transmit the signals to the processor, or to transmit signals from the processor to a communication device other than the communication device. It can be understood that the interface circuit may be a transceiver, a transceiver machine, a wireless transceiver, or an input / output interface.
[0041] Optionally, the communication device may further include memory configured to store instructions executed by the processor, input data required by the processor to execute instructions, or data generated after the processor has executed instructions. The memory may be a physically separate unit, or it may be coupled to the processor, or the processor may include the memory (i.e., the processor and memory are integrated).
[0042] In possible implementations, communication devices are chips.
[0043] According to a fifth aspect, one embodiment of the present application provides a domain-based key management system. The system may include a first control network element according to the first aspect and a key management party according to the second aspect.
[0044] According to the sixth aspect, one embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program or instruction. When the computer program or instruction is executed by a processor, the method according to the first or second aspect can be carried out.
[0045] According to the seventh aspect, one embodiment of the present application further provides a computer program product including a computer program or instruction. When the computer program or instruction is executed by a processor, the method according to the first or second aspect can be carried out.
[0046] According to the eighth aspect, one embodiment of the present application further provides a chip system. The chip system includes a processor. The processor is configured to be coupled to memory. The memory is configured to store a program or instructions. When a program or instructions are executed by the processor, the method according to the first or second aspect can be carried out.
[0047] For technical effects that can be achieved in the second through eighth embodiments, please refer to the technical effects that can be achieved in the first embodiment. Further details will not be explained again here. [Brief explanation of the drawing]
[0048] [Figure 1A] This is a diagram of a homomorphic encryption algorithm according to one embodiment of the present invention. [Figure 1B] This is a diagram of a homomorphic encryption algorithm according to one embodiment of the present invention. [Figure 1C]This is a diagram of a homomorphic encryption algorithm according to one embodiment of the present invention. [Figure 1D] This is a diagram of a homomorphic encryption algorithm according to one embodiment of the present invention.
[0049] [Figure 2] This is a diagram of a homomorphic encryption scheme according to one embodiment of the present invention.
[0050] [Figure 3] This is a diagram of a possible and non-limiting communication system architecture according to one embodiment of the present invention.
[0051] [Figure 4] This figure shows how a homomorphic task is performed in a communication network according to one embodiment of the present invention.
[0052] [Figure 5] This is a diagram showing the structure of a homomorphic encryption control function network element according to one embodiment of the present invention.
[0053] [Figure 6] This is a diagram of a domain-based key management method according to one embodiment of the present invention.
[0054] [Figure 7] Figure (1) shows a domain division according to one embodiment of the present invention.
[0055] [Figure 8] Figure (2) shows a domain division according to one embodiment of the present application.
[0056] [Figure 9] This is a diagram of a homomorphic encryption key architecture according to one embodiment of the present invention.
[0057] [Figure 10] This is a diagram of a homomorphic task management architecture according to one embodiment of the present invention.
[0058] [Figure 11] Figure (1) shows a homomorphic task management process according to one embodiment of the present invention.
[0059] [Figure 12] Figure (2) shows a homomorphic task management process according to one embodiment of the present invention.
[0060] [Figure 13] This is a diagram of a cross-domain homomorphic encryption task according to one embodiment of the present invention.
[0061] [Figure 14] This is a diagram illustrating a domain-based key management procedure according to one embodiment of the present invention.
[0062] [Figure 15] This is a structural diagram (1) of a communication device according to one embodiment of the present invention.
[0063] [Figure 16] (2) is a structural diagram of a communication device according to one embodiment of the present invention. [Modes for carrying out the invention]
[0064] To facilitate understanding by those skilled in the art, some terms used in this application will be explained before the embodiments of this application are described.
[0065] Homomorphic encryption (HE) is a technique that enables computation and processing of ciphertext data without exposing the data plaintext. HE focuses on privacy-preserving computation, performing data value extraction while providing privacy protection. HE is built upon basic cryptography by adding homomorphic computation capabilities to the ciphertext. Homomorphic encryption allows direct computation on encrypted ciphertext, yielding a decrypted computation result that matches the computation result on the plaintext for the computation result on the ciphertext. Homomorphic encryption can be classified into partially homomorphic, partially homomorphic, and fully homomorphic encryption. Partially homomorphic encryption supports only homomorphic addition or homomorphic multiplication. Partially homomorphic encryption allows a limited number of arbitrary homomorphic operations, which can be homomorphic addition, homomorphic multiplication, or homomorphic computation of another arithmetic operation. Fully homomorphic encryption supports an infinite number of homomorphic operations. Fully homomorphic encryption can be asymmetric public-key encryption or symmetric encryption, as long as the ciphertext has an algebraic structure.
[0066] A homomorphic encryption scheme HE=(HE.Keygen, HE.Enc, HE.Dec, HE.Eval) is formed by four algorithms: HE.Keygen represents key generation, HE.Enc represents homomorphic encryption, HE.Dec represents homomorphic decryption, and HE.Eval represents homomorphic evaluation, also known as homomorphic computation. Below, to explain homomorphic encryption, an asymmetric encryption scheme is used as an example, where n is the security parameter.
[0067] (1) Key generation: (pk,evk,sk)←HE.Keygen(1 n ). See Figure 1A. The homomorphic key generation party (abbreviated as HEKG) provides the key generator with key material (for example, 1 n You can input a public key (pk) and output it as a homomorphic encryption key:K encOutputs the key K as the evaluation key (evk), also called the homomorphic calculation key, i.e., pk, and outputs the secret key (sk) as the homomorphic decryption key. eval
[0068] (2) Homomorphic encryption: c ← HE.Enc pk (m). Refer to Figure 1B. The homomorphic encryption party (abbreviated as HEenc) may encrypt the single-bit plaintext message m ∈ {0, 1} into the ciphertext c using the homomorphic encryption key K enc = pk.
[0069] (3) Homomorphic decryption: m ← HE.Dec sk (c). Refer to Figure 1C. The homomorphic decryption party (abbreviated as HEdec) may decrypt the ciphertext c using the homomorphic decryption key K dec = sk and restore the ciphertext to the plaintext message m ∈ {0, 1}.
[0070] (4) Homomorphic evaluation (or homomorphic calculation): c f ← HE.Eval evk (f, c1, …, c l ), which is also called homomorphic calculation. Refer to Figure 1D. Based on the input ciphertexts c1, …, c l and the homomorphic calculation key K eval = evk, the homomorphic calculation party (HEcalc, or abbreviated as HEeval) may execute the homomorphic calculation function f: {0, 1}l → {0, 1} on the ciphertexts to obtain the output ciphertext cf of the homomorphic calculation.
[0071] Here, f represents an arithmetic circuit having addition gates and multiplication gates over GF(2) (GF represents a finite field, and GF is the abbreviation of Galois Field). Generally, the homomorphic calculation HE.Eval can be decomposed into a plurality of basic operators, for example, the homomorphic addition c add ← HE.Add evk 0](c1, c2) and the homomorphic multiplication c mult ← HE.Mult evk (c1, c2).
[0072] The entire homomorphic encryption scheme HE=(HE.Keygen, HE.Enc, HE.Dec, HE.Eval) is shown in Figure 2, and after decryption, the ciphertext-based calculation result is equivalent to the plaintext-based calculation result, where,
number
[0073] In a homomorphic task, multiple homomorphic encryption parties may encrypt data from different sources, multiple homomorphic computation parties may execute a homomorphic computation circuit, or there may be single-hop or multi-hop homomorphic computation parties. A homomorphic task may have multiple homomorphic decryption parties. The decryption result may be sent to multiple data users. Based on the key arrangement, the homomorphic decryption parties and data users may be the same entity or different entities. A fully homomorphic encryption may be an asymmetric public-key encryption or a symmetric encryption, as long as the ciphertext has an algebraic structure. The homomorphic encryption keys of multiple homomorphic encryption parties in a homomorphic task may be the same or different. The homomorphic computation key may include a bootstrap key (BSK) and a key switching key (KSK). The BSK may be used by the homomorphic computation decryption circuit on the ciphertext to reduce noise. KSK can be used to mitigate the problem of increasing ciphertext size caused by ciphertext multiplication by replacing the product of ciphertexts with a new ciphertext having the same dimensions as the original ciphertext and removing the cross-item of the corresponding key after the ciphertext has been computed.
[0074] In addition, note that "and / or" in this application describes the relationship between related objects and indicates that three relationships may exist. For example, A and / or B may represent the following three cases: A exists alone, both A and B exist, and B exists alone. The character " / " usually indicates an "or" relationship between related objects.
[0075] In this application, "at least one" means one or more, and "multiple" means two or more. In the description of this application, terms such as "first" and "second" are used solely for the purpose of distinction and explanation and should not be understood as indicating or implying relative importance or order.
[0076] The above explains some of the terms used in the embodiments of this application. The following describes a communication system architecture to which the embodiments of this application are applicable.
[0077] Figure 3 shows a possible and non-limiting communication system architecture to which one embodiment of the present application may be applied. As shown in Figure 3, the communication system 3000 includes a radio access network (RAN) 100 and a core network (CN) 200. Optionally, the communication system 3000 may further include an internet 300. The RAN 100 includes at least one network device (e.g., 110a and 110b in Figure 3, collectively referred to as 110) and at least one terminal device (e.g., 120a to 120j in Figure 3, collectively referred to as 120). The RAN 100 may further include other RAN nodes, e.g., radio relay devices and / or radio backhaul devices (not shown in Figure 3), etc. The terminal device 120 is connected to the network device 110 wirelessly. The network device 110 is connected to the core network 200 wirelessly or wired. The core network devices in the core network 200 and the network devices 110 in the RAN 100 may be different physical devices, or they may be the same physical device that integrates the logical functions of the core network and the logical functions of the wireless access network.
[0078] RAN100 may be a cellular system associated with the 3rd generation partnership project (3GPP), such as a 4th generation (4G) mobile communication system, a 5th generation (5G) mobile communication system, or an evolved system after 5G (e.g., a 6G mobile communication system). Alternatively, RAN100 may be an open access network (open RAN, O-RAN, or ORAN), a cloud radio access network (CRAN), or a Wi-Fi system. Alternatively, RAN100 may be a communication system that integrates two or more of the aforementioned systems.
[0079] It should be understood that Figure 3 shows only possible communication system architectures to which embodiments of the present application may be applicable. In other possible scenarios, the communication system architecture may alternatively include other devices.
[0080] Network device 110 is a node in a radio access network (RAN) and is sometimes called an access network device or RAN node (or device). Network device 110 is configured to help terminal devices perform radio access. Multiple network devices 110 in the communication system 3000 may be the same type of node or different types of nodes. In some scenarios, the roles of network device 110 and terminal device 120 are relative. For example, network element 120i in Figure 3 may be a helicopter or unmanned aerial vehicle and may be configured as a mobile base station. For terminal device 120j accessing RAN 100 via network element 120i, network element 120i is a base station. However, for base station 110a, network element 120i is a terminal device. Network devices 110 and terminal devices 120 are sometimes called communication devices. For example, network elements 110a and 110b in Figure 3 may be understood as communication devices with base station functionality, and network elements 120a to 120j may be understood as communication devices with terminal device functionality.
[0081] In possible scenarios, network equipment may be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a transmission point (TP), a next-generation NodeB (gNB), a next-generation base station in a 6th generation (6G) mobile communication system, a base station in a future mobile communication system, a satellite, an access point (AP) in a Wi-Fi system, an integrated access and backhaul (IAB) node, or a network equipment located within a non-terrestrial network (NTN) communication system of a mobile exchange, and which may be deployed on a high-altitude platform or satellite. In a CRAN scenario, network equipment may be a macro base station (e.g., 110a in Figure 3), a micro base station or indoor station (e.g., 110b in Figure 3), a relay node or donor node, or a radio controller. The network device may alternatively be a device that functions as a base station in device-to-device (D2D) communication, vehicle internet communication, unmanned aerial vehicle communication, or machine-based communication. Optionally, the network device may alternatively be a server, wearable device, vehicle, or in-vehicle device. For example, the access network device in vehicle-to-everything (V2X) technology may be a roadside unit (RSU).
[0082] In another possible scenario, multiple network devices collaborate to support terminal devices when implementing radio access, with different network devices separately performing some of the base station's functions. For example, network devices may include a central unit (CU), a distributed unit (DU), a CU control plane (CP), a CU user plane (UP), and a radio unit (RU). CUs and DUs may be located separately or included in the same network element, such as a baseband unit (BBU). RUs may be included in radio frequency devices or radio frequency units, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that network devices may be CU nodes, DU nodes, or devices containing both CU and DU nodes. Furthermore, a CU may be classified as a network device within an access network (RAN), or a CU may be classified as a network device within a core network (CN). This is not limited to this context.
[0083] The form of the network device is not limited to the embodiments of this application. The equipment for implementing the functions of the network device may be the network device itself, or it may be equipment that enables the network device to perform its functions, such as a chip system. The equipment may be mounted on the network device or used together with the network device.
[0084] The terminal device 120 may also be called a terminal, user equipment (UE), mobile station (MS), mobile terminal (MT), etc., or it may be a device that provides voice or data connectivity to a user, or it may be an Internet of Things device. For example, the terminal device includes a handheld device, an in-vehicle device, etc., that have wireless connectivity. Currently, terminal devices may include mobile phones, tablet computers, notebook computers, palmtop computers, mobile internet devices (MIDs), wearable devices (e.g., smartwatches, smart bands, pedometers, etc.), in-vehicle devices (e.g., cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, smart point-of-sale (POS) machines, customer-premises equipment (CPE), wireless terminals in industrial control, smart home devices (e.g., refrigerators, televisions, air conditioners, electric meters, etc.), smart robots, robotic arms, workshop equipment, wireless terminals in autonomous driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, and flying devices (e.g., smart robots, hot air balloons, unmanned aerial vehicles, or airplanes). Alternatively, terminal devices may be other devices that have terminal functions. For example, the terminal device may be, alternatively, a device that has terminal functionality in D2D communication.
[0085] The device type of the terminal device is not limited to the embodiments of the present application. The device for implementing the functions of the terminal device may be the terminal device itself, or it may be a device that enables the terminal device to perform its functions, such as a chip system. The device may be mounted on the terminal device or used together with the terminal device. In the embodiments of the present application, the chip system may include a chip, or it may include a chip and other separate components.
[0086] Each network element or device within the communication system (which may also be called a communication network) shown in Figure 3 may have homomorphic encryption and / or homomorphic computing capabilities. Therefore, in embodiments of the present application, it may be considered that homomorphic tasks corresponding to homomorphic encryption are supported in the communication network in order to provide privacy computing capabilities to the communication network.
[0087] Figure 4 shows an example of performing a homomorphic task in a communication network according to the present invention. The communication network may also be called a telecommunications network. The communication network may be deployed as cells, and each cell may have thousands of terminal devices that wirelessly access the cell's serving cell. In Figure 4, terminal devices such as intelligent vehicles composed of on-board units (OBUs), smartphones, VR / AR devices, and smart cameras may have homomorphic encryption capabilities. If privacy protection is required, homomorphic encryption can be performed on the generated confidential data, and the data is then transmitted to another terminal node in the communication network, a roadside unit (RSU), a base station, a network function (NF) in the core network (hereinafter abbreviated as NF), a cloud provider, etc., where homomorphic computation is performed on the ciphertext, and finally the computed ciphertext data is sent to the data user for homomorphic decryption.
[0088] Multiple homomorphic tasks (e.g., homomorphic tasks 1-4 in Figure 4) can exist throughout a communication network. Based on (fully) homomorphic cryptography, communication networks can provide privacy-preserving and privacy-computing services for highly secure and confidential services. When applying homomorphic tasks to a communication network, how to design the key architecture for homomorphic encryption tasks and how to manage the homomorphic task keys are issues worth considering.
[0089] In view of the foregoing, the present invention provides a domain-based key management scheme for managing homomorphic task keys in a communication network, supporting the application of homomorphic tasks to a communication network, and providing privacy computing capabilities to a communication network. Embodiments of the present invention will be described in detail below with reference to the attached drawings.
[0090] Figure 5 shows the structure of a homomorphic encryption control function (HECF) network element according to one embodiment of the present invention. The HECF network element may include some or all of the functions of units such as a homomorphic task management unit, a homomorphic capability management unit, a key management unit, a ciphertext data storage management (CDSM) unit, and an HECF interface management (HEinterM) unit.
[0091] In some implementations, homomorphic tasks are sometimes called homomorphic encryption tasks, homomorphic task management units are sometimes called homomorphic encryption task management (HETM) units, homomorphic capability management units are sometimes called homomorphic encryption capability management (HECapM) units, and key management units are sometimes called homomorphic encryption key management (HEKM) units.
[0092] A homomorphic task management unit may have one or more functions such as homomorphic task request management, homomorphic task scheduling management, and homomorphic task profile management. The homomorphic task request management function may be used to manage all homomorphic task requests, receive homomorphic task requests from homomorphic task request parties, parse homomorphic task requests, respond to homomorphic tasks based on the homomorphic task scheduling management results, and filter out repeated or inappropriate homomorphic task requests. The homomorphic task scheduling management function may be used to perform homomorphic task scheduling (or orchestration) based on the parsing results of homomorphic task requests and a list of homomorphic capability information, distribute homomorphic task configurations to homomorphic encryption parties, homomorphic computation parties, homomorphic decryption parties, etc., and receive homomorphic configuration responses / task responses. The homomorphic task profile management function can be used to generate homomorphic task profiles (which may be stored in the homomorphic task management unit) based on homomorphic task requests (or homomorphic task request analysis results), homomorphic task scheduling results, etc., and can perform profile management such as transfer, update, store, and discard.
[0093] A homomorphic capability management unit may have a homomorphic enabler unit capability management function and a homomorphic capability profile management function, and may receive homomorphic capability information reported by a homomorphic enabler unit (e.g., a homomorphic encryption party, a homomorphic computation party, a homomorphic decryption party, etc.), and may generate, store, or update homomorphic capability profiles registered by a homomorphic enabler unit based on the homomorphic capability information, and the homomorphic capability profiles registered by a homomorphic enabler unit may be stored in a homomorphic encryption capability management unit.
[0094] The key management unit has the function of managing homomorphic task keys. For example, the key management unit may perform exchanges with other key exchange parties, and the content exchanged may include one or more of the following: key material, history keys, public parameters used to generate homomorphic task keys, etc. The key management unit may also generate cryptographic / decryption keys (symmetric / asymmetric / homomorphic encryption keys or symmetric / asymmetric / homomorphic decryption keys) and homomorphic operation keys, and manage key distribution, use, updating, storage, destruction, and key lifecycle.
[0095] The ciphertext data storage management unit may have one or more functions such as ciphertext reception and transmission management, ciphertext storage lifecycle management, and ciphertext storage management. Ciphertext reception and transmission management supports receiving ciphertext from a homomorphic enablement unit or encryption party, or sending ciphertext to a homomorphic enablement unit or decryption party. Ciphertext storage lifecycle management supports setting a lifecycle for each ciphertext. The ciphertext lifecycle starts when the ciphertext is received, and the ciphertext is deleted after the ciphertext lifecycle ends. Ciphertext storage management supports partitioned storage for ciphertexts. Specifically, ciphertext storage is partitioned based on one or more of the following: the user to which the ciphertext belongs (e.g., a homomorphic enablement unit), the encryption key corresponding to the ciphertext, the network layer associated with the ciphertext, the network slice type associated with the ciphertext, and the security context associated with the ciphertext.
[0096] In this embodiment of the present application, the homomorphic enablement unit may be a terminal device, an access network device, a core network element, an independent node (IN), an application function (AF) node, etc., and may be used as a participant in a homomorphic task, for example, a homomorphic encryption party, a homomorphic computation party, or a homomorphic decryption party. Key exchange parties may include units that store symmetric keys or user security contexts at all levels in the symmetric key architecture of a universal subscriber identity module (USIM) in a communication network, such as network elements or infrastructure in a communication network, such as unified data management (UDM) / authentication credential repository and processing function (ARPF) network elements, authentication server function (AUSF) network elements, security anchor function (SEAF) network elements, access and mobility management function (AMF) network elements, gNB / non-3GPP interworking function (N3IWF) network elements, USIM / mobile equipment (ME) network elements, and third-party key management centers (KMCs) with independent key architectures.
[0097] HECF network elements may be located within a communication network, independently as functional network elements or nodes within the communication network, or integrated with existing network elements or nodes within the communication network. For example, a network exposure function (NEF) network element within a communication network may have the functionality of an HECF network element, an access and mobility management function (AMF) network element may have the functionality of an HECF network element, and a session management function (SMF) network element may have the functionality of an HECF network element. It can be understood that one or more HECF network elements may be located within a communication network, or that one or more network elements having the functionality of an HECF network element may be located within a communication network. HECF network elements may have different names in different communication systems.
[0098] Figure 6 illustrates a domain-based key management method according to one embodiment of the present invention. In Figure 6, for example, a control network element performs the method. The control network element may be an HECF network element, or a network element having the functionality of an HECF network element, or a component of a network element having the functionality of an HECF network element (e.g., a processor, chip, chip system, etc.), or equipment corresponding to such a component.
[0099] S601: The first control network element obtains the first homomorphic encryption key corresponding to the first domain.
[0100] In this embodiment of the present application, the communication network may be divided into multiple domains for homomorphic task management, and each domain is managed by multiple control network elements. Each control network element may be responsible for homomorphic task management, homomorphic capability management, key management, interface (e.g., HECF interface) management, ciphertext data storage management, etc., within the domain corresponding to the control network element.
[0101] In some implementations, domains can be obtained by partitioning based on the network architecture layer and / or service type slices. Service type slices, also called traffic type slices, are segmented based on the service type (or traffic type) within an operator's communication network and may be logical networks given specific network characteristics, i.e., network slices. Different network slices may have network slices for distinct network performance requirements, such as ultra-reliable low-latency communications (uRLLC), massive machine type communication (mMTC), and enhanced mobile broadband (eMBB).
[0102] A first domain corresponding to (or managed by) a first control network element is used as an example. The first domain may correspond to a core network, an access network, or an application layer, and may correspond to a data network, cloud server, cloud service cluster, or application in the application layer, or may correspond to a PLMN of the core network, or one or more network elements within a PLMN of the core network.
[0103] In addition, the first domain may alternatively correspond to an access network set. An access network set may contain P access network nodes or cells, where P is an integer of 1 or more. The access network set may determine (or identify) the P access network nodes or cells based on one or more of the following: cell identifier (cell id), access network node identifier (gNB id), access management function-related identifier (e.g., AMF identifier (AMF id), AMF set identifier (AMF set id), AMF region identifier (AMF region id)), tracking area indicator (TAI), network slice identifier, etc.
[0104] The first domain may, alternatively, correspond to a network slice, a core network slice, or an application layer network slice. Network slices can be determined or identified using network slice selection assistance information (NSSAI), slice / service type (SST) identifiers, etc.
[0105] For an example, please refer to the domain partitioning diagram shown in Figure 7. A communication network may be divided into domains corresponding to the access network (AN), core network (CN), and application (APP) layers, based on the network architecture layers of the access network, core network (CN), and application layer, and each domain is managed by different control network elements (e.g., HECF network elements).
[0106] Refer to the domain partitioning diagram shown in Figure 8. A communication network can initially be partitioned based on the access network (network architecture level 1), the core network (network architecture level 2), and the application layer (network architecture level 3). The access network layer and the core network layer can be further partitioned based on the service type (ST), for example, the network slice type. The access network can be further partitioned based on the access network set (access network site). For example, in Figure 8, ST1, ST2, and ST3 may each represent different types of network slices. The network slices ST1, ST2, and ST3 in the application layer may be partitioned as different domains, the network slices ST1, ST2, and ST3 in the core network may be partitioned as different domains, and different access network sets in the access network may be partitioned as different domains, for example, 3GPP access network set 1 (3GPP AN 1), 3GPP access network set 2 (3GPP AN 2), and non-3GPP access network set 3 (non-3GPP AN 3).
[0107] In this embodiment of the present application, it should be understood that the partition rules for multiple domains may be the same or different, and there may be common sets between different domains or there may be no common sets. For example, if domain 0 corresponds to PLMN0, domain 1 corresponds to network slice 1 within PLMN0, and domain 2 corresponds to network slice 2 within PLMN0, then domain 0 may include domains 1 and 2.
[0108] In this embodiment of the present application, homomorphic encryption keys may be at the domain level, i.e., each domain corresponds to one homomorphic encryption key. The domain partitioning shown in Figure 8 is still used as an example. See the diagram of the homomorphic encryption key architecture shown in Figure 9. Each domain in Figure 8 corresponds to one homomorphic encryption key. For example, the domain corresponding to the network slice of ST1 in the application layer corresponds to homomorphic encryption key K APP,ST1 In response to this, the domain of the network slice corresponding to ST2 in the application layer is the homomorphic encryption key K APP,ST2 In response to this, the network slice domains that support ST3 in the application layer use homomorphic encryption key K APP,ST3 In response to this, ..., domains that support the access network Non-3GPP AN 3 use homomorphic encryption key K non-AN3 This corresponds to the above. The homomorphic decryption key for each domain may be stored only in the control network element corresponding to that domain.
[0109] The homomorphic encryption key and homomorphic decryption key corresponding to each domain may be derived by the control network element corresponding to the domain, or by the key management party, or collaboratively by both the control network element and the key management party. The key management party may be a KMC, or it may be a network element or infrastructure such as an ARPF or AMF in a communication network.
[0110] The first domain is still used as an example. The first control network element may input public parameters (e.g., the security parameters described above) and public reference values used for key derivation into a key generator to derive a first homomorphic encryption key and a first homomorphic decryption key corresponding to the first domain, and may further derive a set of temporary homomorphic compute keys corresponding to the first domain. The security parameters may be determined by the first control network element, and the public reference values may be common reference strings (CRS) that can be provided by the key management party. The key generator may be an algorithm, function, algorithmic procedure, etc., for key derivation.
[0111] In some implementations, key generators corresponding to different homomorphic encryption algorithms may differ. In this embodiment of the present application, the key generator may be determined based on the homomorphic encryption algorithm supported by the homomorphic activating unit in the first domain. For example, a homomorphic activating unit acting as a homomorphic activating unit or a homomorphic encryption party in the first domain supports homomorphic encryption algorithm 1, and the first control network element may select a key generator applicable to homomorphic encryption algorithm 1 and perform key derivation.
[0112] S602: The first control network element transmits the first homomorphic encryption key to M first homomorphic enablement units belonging to the first domain, and in response, the M first homomorphic enablement units receive the first homomorphic encryption key. M is an integer greater than or equal to 1.
[0113] In possible implementations, the M first homomorphic enablers belonging to the first domain may be all homomorphic enablers within the first domain, or one or more homomorphic enablers that function as homomorphic encryption parties within the first domain (e.g., support homomorphic encryption). After obtaining the first homomorphic encryption key corresponding to the first domain, the first control network element may transmit the first homomorphic encryption key to all homomorphic enablers within the first domain, or to one or more homomorphic enablers that function as homomorphic encryption parties within the first domain.
[0114] In another possible implementation, the M first homomorphic enablement units belonging to the first domain may further include one or more homomorphic enablement units that function as homomorphic encryption parties for homomorphic tasks (e.g., first homomorphic tasks) within the first domain. After a homomorphic task (e.g., first homomorphic task) has been scheduled (or orchestrated) in the first domain, the first control network element may further transmit the first homomorphic encryption key to one or more homomorphic enablement units that function as homomorphic encryption parties for the homomorphic task in the first domain.
[0115] S603: The first control network element transmits the first homomorphic calculation key to N second homomorphic activation units belonging to the first domain, and in response, the N second homomorphic activation units receive the first homomorphic calculation key.
[0116] N is an integer greater than or equal to 1, and the first homomorphic computation key may be determined based on the first homomorphic encryption key and / or the first homomorphic decryption key corresponding to the first homomorphic encryption key.
[0117] In some embodiments, after scheduling (or orchestrating) homomorphic tasks (e.g., first homomorphic tasks) in a first domain, the first control network element may transmit the first homomorphic compute key to N second homomorphic enablement units that function as homomorphic compute parties for the homomorphic tasks in the first domain. For example, after completing the configuration of homomorphic task rolls (e.g., homomorphic compute parties, homomorphic encryption parties, etc.) of homomorphic enablement units that participate in and establish homomorphic tasks in the first domain, the first control network element may transmit the first homomorphic compute key to N second homomorphic compute units that function as homomorphic compute parties for the homomorphic tasks in the first domain.
[0118] In this embodiment of the present application, one homomorphic task corresponds to one homomorphic computation key set, and one homomorphic computation key set corresponding to one homomorphic task may include one or more keys used in homomorphic computation. For example, the homomorphic computation key corresponding to the first homomorphic task may include a BSK and a KSK. For the functions of the BSK and KSK, please refer to the above description of homomorphic encryption. Further details will not be described again.
[0119] The homomorphic computation key for a homomorphic task may be determined based on K homomorphic encryption keys and / or K homomorphic decryption keys corresponding to K domains distributed among the participants of the homomorphic task (e.g., homomorphic encryption party, homomorphic computation party, etc.), where K is an integer greater than or equal to 1.
[0120] For example, a homomorphic task is a first homomorphic task, K is equal to 1, and participants in the first homomorphic task are distributed across the first domain. The first homomorphic computation key corresponding to the first homomorphic task may be determined by the first control network element and / or key management party based on the first homomorphic encryption key and / or first homomorphic decryption key corresponding to the first domain. For example, a set of temporary homomorphic computation keys corresponding to the first domain, derived by the first control network element using a key generator, may be used as the first homomorphic computation key corresponding to the first homomorphic task.
[0121] For example, a homomorphic task is a first homomorphic task, where K is greater than 1, and the participants in the first homomorphic task are distributed across K domains, including the first domain. The first homomorphic computation key corresponding to the first homomorphic task may be determined by a key management party based on K homomorphic encryption keys and / or K homomorphic decryption keys corresponding to the K domains.
[0122] In one example, each control network element corresponding to one of the K domains may send domain-based key parameters to a key management party, where the key parameters for each domain are determined based on the homomorphic encryption key and / or homomorphic decryption key corresponding to the domain. The key management party may derive a first homomorphic computation key corresponding to a first homomorphic task based on the key parameters of the K domains, and send the first homomorphic computation key to the K control network elements corresponding to the K domains, thereby distributing the first homomorphic computation key to the homomorphic computation parties participating in the first homomorphic task in the K domains.
[0123] The following provides an example of how a key management party (using KMC as an example) derives a first homomorphic computation key corresponding to a first homomorphic task based on key parameters of K domains, where i = 0, 1, 2, ..., K, and HECF network elements are control network elements.
[0124] In the phase of deriving homomorphic encryption and decryption keys:
[0125] (0) The HECF control network element of domain i first derives the homomorphic decryption key (secret key): K dec =(1,s i )∈R q 2 , here, s i These are components of the homomorphic decryption key in domain i, and can be generated based on random parameters of the domain, secret parameters such as the key, by using a key derivation function. q 2 The 'q' indicates a polynomial ring whose modulus is q, and the superscript '2' indicates the dimension.
[0126] (1) KMC generates common criteria and distributes them to HECF network elements in all domains. The common criteria are a and g, where a∈R q d (Random polynomial vector), g∈Z d is the gadget vector, Z d This is a set of integers with dimension d.
[0127] (2) HECF network elements within domain i have a common reference value and homomorphic decryption key s i Based on the public key b of domain i i and temporary homomorphic computation key D i Generate the key and send the public key and temporary homomorphic computed key to the KMC.
[0128] public key (homomorphic encryption key) b in domain i i The method of generation is not limited. The following is merely an example. b i =(-a·s i +e i )∈R q d and e i This is random "noise" introduced for the security of ciphertext.
[0129] Temporary homomorphism evaluation key D in domain i i =[d i,0 |d i,1 |d i,2 ]∈R q d×3 The method of generation is not limited. The following is merely an example. r i This is a randomly distributed small polynomial sample.
[0130] d i,1 ←U(R q d ) and d i,1 is R q d This is a sample taken from the uniform distribution shown above.
[0131] d i,0 =-s i ·d i,1 +r i ·g+e i1 ∈R q d , temporary homomorphism evaluation key component d i,0 is the homomorphic decoding key component s i , public parameter g, newly introduced random quantity r i , and the temporary homomorphism evaluation key component d i,1 It is calculated based on [the following].
[0132] d i,2 =r i · a+s i ·g+e i2 ∈R q d , temporary homomorphism evaluation key component d i,2 is the homomorphic decoding key component s i , publicly available parameters a and g, and the newly introduced random quantity r i It is calculated based on [the following].
[0133] In the derivation phase of the homomorphism key for K parties corresponding to K domains (e.g., the first homomorphism key for the first homomorphism task):
[0134] (3) The HECF network elements within domain i send the public key b within domain i i and the temporary homomorphic calculation key D i to KMC. The homomorphic task is related to the homomorphic encryption keys and homomorphic decryption keys of K domains. KMC generates the K-party homomorphic calculation keys (KSK and BSK) based on the K public keys and the temporary homomorphic calculation keys, and distributes the keys to multiple homomorphic calculation parties (the calculation parties only need to have computing power, and the number of calculation parties does not need to be limited).
[0135] Method for generating the K-party key switching key (KSK) {K i,j} 1≦i,j≦k ’is not limited. The following is just an example.
Number
[0136] The method for generating the K-party bootstrapping key (BSK) is not limited. The following is just an example. d i,j =r i,j ·a + s i,j ·g + e i,j
[0137] The K-party bootstrapping key component d i,j is calculated based on the homomorphic decryption key component s i,j the public parameters a and g, the newly introduced random quantity r i,j and the random noise component e i,j
[0138] The K-party bootstrapping key component F i,j = [f0, f1] is sampled from a random uniform distribution (f1) and then calculated according to the following formula f0. f0 = -z i ·f1 + r i,j ·g + e i,j
[0139] K - party bootstrapping key component F i,j is the new homomorphic encryption key component z i , public parameter g, newly introduced random quantity r i,j , and random noise component e i,j and is calculated based on
[0140] In this embodiment of the present application, it should be understood that the homomorphic encryption key and the homomorphic decryption key (including the homomorphic encryption key and the homomorphic decryption key) may be separated from the homomorphic task, and the life cycles of the homomorphic encryption key and the homomorphic decryption key and the homomorphic calculation key may be different. For example, the life cycle of the homomorphic calculation key continues only during the period of the homomorphic task corresponding to the homomorphic calculation key. After the homomorphic task ends, the homomorphic calculation key corresponding to the homomorphic task needs to be discarded (or invalidated). For example, after the first homomorphic task ends, the homomorphic calculation party participating in the first homomorphic task deletes the homomorphic calculation key corresponding to the first homomorphic task. However, the homomorphic encryption key and the homomorphic decryption key within the sub - domain are separated from the homomorphic task. After the homomorphic task ends, the homomorphic encryption key and the homomorphic decryption key within the sub - domain do not need to be discarded (or invalidated) and may continue to be used. For example, the homomorphic encryption key and the homomorphic decryption key in a specific domain (e.g., the first domain) can be derived after the control network element within the domain (e.g., the first control network element) decides to establish a secure channel to the key management party. All homomorphic encryptions within the domain are performed by using the same derived homomorphic encryption key. After a specific homomorphic task ends, the homomorphic encryption key and the homomorphic decryption key within the domain do not need to be discarded (or invalidated) and may continue to be used.
[0141] In some implementations, periodic updates or triggered updates may be selected for the homomorphic encryption key and the homomorphic decryption key.
[0142] Refer to Figure 10. In this embodiment of the present application, each control network element (for example, the control network elements in Figure 10 are HECF network elements) may be responsible for homomorphic task management, homomorphic capability management, key management, interface (e.g., HECF interface) management, ciphertext data storage management, etc., within the domain corresponding to the control network element. A homomorphic enablement unit may perform exchanges with control network elements in the domain where the homomorphic enablement unit is located via a control plane (CP) interface, for example, by reporting homomorphic capability information to the control network element and receiving task configuration information from the control network element. A homomorphic task request party may send a homomorphic task request to a control network element (e.g., HECF network element 1) in the domain where the homomorphic task request party is located (e.g., domain 1). The control network element in the domain may analyze the homomorphic task request and exchange the homomorphic capability profile of the homomorphic enablement unit in the management domain with a control network element in another domain via a control plane interface (e.g., HECF interface). In addition, if participants in a homomorphic task are related to homomorphic enablement units in other domains (e.g., Domain 2 and Domain 3), the homomorphic task subrequirements may be transmitted to control network elements in the other domains. Transmission of user plane (UP) data, ciphertext, etc., may be performed between different homomorphic enablement units, based on the configuration of the homomorphic task.
[0143] In some implementations, participants in a homomorphic task may include one or more of the following: a homomorphic encryption party, a homomorphic computation party, a homomorphic decryption party, a data provider, a data user, a key management party, etc.
[0144] In the following explanation, for example, participants in a first homomorphic task are distributed across K domains (domain 1, domain 2, and domain 3), and an HECF network element (first control network element) that receives a first homomorphic task request divides the first homomorphic task request into multiple first homomorphic task subrequirements, forwards the first homomorphic task subrequirements across domains (to domains 2 and 3), and HECF network elements (control network elements) within the K domains schedule (or orchestrate) the first homomorphic task.
[0145] Figure 11 is a diagram of a possible homomorphic task management process according to one embodiment of the present invention. This process includes the following steps:
[0146] S1101: The homomorphic task request party sends a first homomorphic task request to HECF network element 1 (first control network element), and HECF network element 1 receives the first homomorphic task request.
[0147] S1102: HECF network element 1 separately transmits the first homomorphic task subrequirements to HECF network element 2 and HECF network element 3.
[0148] In this embodiment of the present application, a homomorphic task request may include one or more of the following: a homomorphic task output type, a homomorphic task type, homomorphic task quality requirements, data user parameters, the number of data users, the number of data providers, and data provider parameters. After receiving a first homomorphic task request, HECF network element 1 can determine, based on the first homomorphic task request, the domains in which the participants of the first homomorphic task are distributed.
[0149] For example, HECF network element 1 may obtain first information for F domains, where F may be an integer greater than or equal to (K-1), and the F domains may be other domains in the PLMN where domain 1 is located, or other domains where network slices of the same type as domain 1 are located. This is not limited to the present application. The first information for each domain may include homomorphic capability information for at least one homomorphic enablement unit within the domain (in Figure 10, L homomorphic enablement units are used as an example). The homomorphic capability information for each homomorphic enablement unit may include one or more of the following: identifier, type, homomorphic encryption capability level, homomorphic encryption security level, homomorphic encryption enablement identifier, homomorphic decryption enablement identifier, homomorphic computation enablement identifier, identifier of supported homomorphic encryption algorithms, identifier of supported homomorphic computation algorithms, etc. The first information for each domain may be transmitted to HECF network element 1 by the HECF network element corresponding to the domain.
[0150] After receiving the first homomorphism task request, HECF network element 1 obtains identifiers for multiple data providers included in the first homomorphism task through analysis. Based on the first information in domain 1 and the first information in F domains, HECF network element 1 learns the homomorphism activation units in domains 1, 2, and 3 that correspond to each of the multiple data providers. In this case, HECF network element 1 can separately send the first homomorphism task subrequest to HECF network element 2 corresponding to domain 2 and HECF network element 3 corresponding to domain 3, instructing HECF network elements 2 and 3 to configure the first homomorphism task in domains 2 and 3, respectively.
[0151] If an HECF network element receiving a first homomorphic task subrequirement can instruct participants in the first homomorphic task within the domain corresponding to the HECF network element to configure the first homomorphic task, then the information contained in the first homomorphic task subrequirement may be the same as, partially the same as, or different from, the information contained in the first homomorphic task request. For example, a first homomorphic task subrequirement that HECF network element 1 sends to HECF network element 2 corresponding to domain 2 may contain only the data provider parameters for the first homomorphic task in domain 2, and not the data provider parameters for the first homomorphic tasks in domains 1 and 3.
[0152] S1103: HECF network element 1 transmits task configuration information to at least one third homomorphic enablement unit participating in the first homomorphic task in domain 1, HECF2 transmits task configuration information to at least one third homomorphic enablement unit participating in the first homomorphic task in domain 2, and HECF3 transmits task configuration information to at least one third homomorphic enablement unit participating in the first homomorphic task in domain 3.
[0153] HECF network element 1, HECF network element 2, or HECF network element 3, after receiving a first homomorphic task request (or first homomorphic task subrequirement), can parse the first homomorphic task request (or first homomorphic task subrequirement), perform first homomorphic task scheduling (or orchestration), and transmit task configuration information to at least one third homomorphic enablement unit participating in the first homomorphic task in the corresponding domain, the task configuration information including the homomorphic task scroll of at least one third homomorphic enablement unit.
[0154] For example, HECF network element 1 determines the homomorphic task roll of Q third homomorphic enablement units participating in the first homomorphic task in the first domain, based on the first homomorphic task request and the homomorphic capability information of L fourth homomorphic enablement units belonging to domain 1, where Q is an integer greater than or equal to 1 and L is an integer greater than or equal to Q. HECF network element 1 can analyze the first homomorphic task request and, for example, obtain parameters of the data provider (e.g., quantity, identifier, etc.), and for the data provider, based on the homomorphic capability information of the L fourth homomorphic enablement units in domain 1, such as homomorphic encryption enablement information and homomorphic computation enablement information, it can select the homomorphic enablement units of the corresponding quantity for which homomorphic encryption enablement is true as homomorphic encryption parties, and select the homomorphic enablement units for which homomorphic encryption enablement is true as homomorphic computation parties, and compute the encrypted ciphertext. After determining the homomorphic task rolls of the Q third homomorphic enablement units participating in the first homomorphic task within the first domain, HECF network element 1 may transmit task configuration information to the Q third homomorphic enablement units participating in the first homomorphic task within domain 1, the task configuration information including the homomorphic task rolls of the Q third homomorphic enablement units (e.g., homomorphic compute party, homomorphic cryptography party, etc.).
[0155] S1104: HECF network element 1 receives a task configuration response sent by at least one third homomorphic enablement unit participating in a first homomorphic task in domain 1; HECF network element 2 receives a task configuration response sent by at least one third homomorphic enablement unit participating in a first homomorphic task in domain 2; and HECF network element 3 receives a task configuration response sent by at least one third homomorphic enablement unit participating in a first homomorphic task in domain 3.
[0156] S1105: HECF network element 2 sends a first homomorphic task sub-response to HECF network element 1. HECF network element 2 sends a first homomorphic task sub-response to HECF network element 1.
[0157] S1106: HECF network element 1 sends the first homomorphic task response to the homomorphic task requesting party.
[0158] After receiving task configuration information, the third homomorphic enablement unit may respond to the HECF network element that transmitted the task configuration information with a task configuration response, which may indicate that the third homomorphic enablement unit has received the task configuration information. After receiving task configuration responses from at least one third homomorphic enablement unit in the corresponding domain, HECF network element 2 or HECF network element 3 may send a first homomorphic task sub-response to HECF network element 1 to notify HECF network element 1 that the configuration of the first homomorphic task in domain 2 or domain 3 is complete. After receiving the first homomorphic task sub-responses and task configuration responses from at least one third homomorphic enablement unit in domain 1 from HECF network elements 2 and 3, HECF network element 1 may respond to the homomorphic task requesting party with a first homomorphic task response to notify the homomorphic task requesting party that the configuration of the first homomorphic task is complete.
[0159] It should be understood that in some implementations, a first homomorphic task may alternatively relate to only one domain, for example, only domain 1 corresponding to HECF network element 1 that receives the first homomorphic task request. In this case, only HECF network element 1 schedules the first homomorphic task in domain 1.
[0160] The capability information of L homomorphic enablement units within each HECF network element may be actively reported by the homomorphic enablement units to the HECF network elements in the domain to which the homomorphic enablement units belong, or may be reported by the homomorphic enablement units in response to a homomorphic capability information reporting request from the HECF network elements. This is not limited to the present application. For each homomorphic enablement unit in a corresponding domain, the HECF network element may generate or update a homomorphic capability profile of the homomorphic enablement unit based on the acquired homomorphic capability information of the homomorphic enablement unit, and the homomorphic capability profile of the homomorphic enablement unit includes the homomorphic capability information of the homomorphic enablement unit. For example, domain 1, corresponding to HECF network element 1, includes a fourth homomorphic enablement unit. HECF network element 1 may acquire the homomorphic capability information of the fourth homomorphic enablement unit and generate or update a homomorphic capability profile of the fourth homomorphic enablement unit based on the homomorphic capability information.
[0161] According to the homomorphic task management process shown in Figure 11, if the participants in a homomorphic task are related not only to the domain where the HECF network element receiving the homomorphic task request is located, but also to another domain, the HECF network element receiving the homomorphic task request can send homomorphic task subrequirements obtained by splitting the homomorphic task request to the HECF network element in the other domain, thereby performing cross-domain homomorphic task configuration (or scheduling) and satisfying the user's requirements for performing the cross-domain homomorphic task.
[0162] Figure 12 is a diagram of another possible homomorphic task management process according to one embodiment of the present invention. This process includes the following steps:
[0163] S1201: The homomorphic task request party sends a first homomorphic task request to HECF network element 0 (i.e., HECF0), and HECF network element 0 receives the first homomorphic task request.
[0164] S1202: HECF network element 0 sends the first homomorphic task subrequirements separately to HECF network element 1 (i.e., HECF1) and HECF network element 2 (i.e., HECF2).
[0165] S1203: HECF1 transmits task configuration information to at least one third homomorphic enablement unit participating in the first homomorphic task in Domain 1, and HECF2 transmits task configuration information to at least one third homomorphic enablement unit participating in the first homomorphic task in Domain 2.
[0166] S1204: HECF network element 1 receives a task configuration response sent by at least one third homomorphic enablement unit participating in a first homomorphic task in domain 1, and HECF network element 2 receives a task configuration response sent by at least one third homomorphic enablement unit participating in a first homomorphic task in domain 2.
[0167] S1205: HECF network element 1 sends a first homomorphic task sub-response to HECF network element 0, and HECF network element 2 sends a first homomorphic task sub-response to HECF network element 0.
[0168] S1206: HECF network element 0 sends the first homomorphic task response to the homomorphic task requesting party.
[0169] Unlike the homomorphic task management process shown in Figure 11, in the homomorphic task management process shown in Figure 12, the HECF network element 0 that receives the first homomorphic task request does not have to directly transmit task configuration information to the homomorphic activation unit, nor does it have to schedule the homomorphic activation unit. For example, domain 0 corresponding to HECF network element 0 may include domain 1 corresponding to HECF network element 1 and domain 1 corresponding to HECF network element 2. For example, domain 0 corresponds to PLMN0, domain 1 corresponds to network slice 1 in PLMN0, and domain 2 corresponds to network slice 2 in PLMN1. In this case, domain 0 may include domains 1 and 2. After receiving the first homomorphic task request, HECF network element 0 divides the first homomorphic task request into multiple first homomorphic task subrequirements, and HECF network elements (e.g., HECF network element 1 and HECF network element 2) corresponding to the multiple domains (e.g., domains 1 and 2) included in domain 0 can transmit task configuration information to the homomorphic activation unit.
[0170] The principle of the homomorphic task management process shown in Figure 12 is the same as that of the homomorphic task management process shown in Figure 11. For the implementation of S1201 to S1206, please refer to the implementation of S1101 to S1106. Details will not be described again.
[0171] According to the homomorphic task management process shown in Figure 12, if the participants in a homomorphic task are distributed across different domains other than the domain where the HECF network element receiving the homomorphic task request is located, the HECF network element receiving the homomorphic task request can send the homomorphic task subrequirements obtained by subdividing the homomorphic task request to the HECF network element in the other domain, thereby performing cross-domain homomorphic task configuration (or scheduling) and satisfying the user requirements for performing the cross-domain homomorphic task.
[0172] In this embodiment of the present application, homomorphic decoding may be implemented by HECF network elements (i.e., control network elements). If all homomorphic participants in a homomorphic task are located in a single domain, homomorphic decoding may be performed by HECF network elements within that domain.
[0173] If the homomorphic encryption parties in a homomorphic task span K domains (K>1), then the HECF network elements within the domains where the K homomorphic encryption parties reside can first decrypt the ciphertext separately, and then the data user can sum the decrypted data from the K HECF network elements to obtain the final decryption result.
[0174] Alternatively, if the homomorphic encryption party in a homomorphic task spans K domains (K>1), the HECF network element in the domain where the data user is located may first apply the decryption key (e.g., a homomorphic decryption key) in the domain where the encryption party is located to the HECF network element in the domain where the homomorphic encryption party is located, and then the HECF network element in the domain where the data user is located may perform co-decryption based on the decryption key (the decryption key for the K domains).
[0175] Figure 13 is a diagram of a cross-domain homomorphic encryption task according to one embodiment of the present invention. The data provider for the homomorphic task may be slice 1 and slice 2 at the APP level. Slice 1 and slice 2 correspond to two different domains and are different network slice instances (NSIs), e.g., NSI1 and NSI2. The homomorphic encryption party may be a homomorphic enablement unit on the terminal device (e.g., UE), e.g., the UE's APP. The homomorphic encryption key for slice 1 is K APP,slice1 (This is denoted as K1 in Figure 13), and the homomorphic encryption key for slice 2 is K APP,slice2(This is denoted as K2 in Figure 13). The homomorphic computing party is an APP (provider APP) that provides services on the network side, for example, an HECF within the APP that provides services (for example, an HECF APP A homomorphic computation party may be a network element. A homomorphic computation party may be a terminal device, or a network element or entity in an access network (e.g., a base station, roadside unit, non-3GPP access point, etc.), or a network element or entity in a core network (e.g., a core network function (NF), an independent node, etc.). Regardless of the number of homomorphic encryption parties in a homomorphic encryption task, the number of homomorphic encryption keys in a homomorphic encryption task depends only on the number of domains.
[0176] In the following description, for example, the domains are based on PLMN, the participants in the first homomorphism task belong to the first domain "PLMN1" and the second domain "PLMN2", and the control network elements corresponding to PLMN1 and PLMN2 are the first control network element "HECF network element 1" and the second control network element "HECF network element 2", respectively. Figure 14 is a diagram of a domain-based key management procedure according to one embodiment of the present invention.
[0177] S1401: HECF network element 1 obtains the first homomorphic encryption key corresponding to PLMN1, and HECF network element 2 obtains the second homomorphic encryption key corresponding to PLMN2.
[0178] For example, the first homomorphic encryption key corresponding to PLMN1 and the second homomorphic encryption key corresponding to PLMN2 are derived by the KMC. For PLMN1, the homomorphic enablement unit in PLMN1 (e.g., a network element in CN, UE, etc.) may report cryptographic capabilities, such as homomorphic encryption security levels, or identifiers of supported homomorphic encryption algorithms to HECF network element 1 in the domain. After receiving the cryptographic capabilities transmitted from the homomorphic enablement unit in PLMN1, HECF network element 1 sends a derivation request for homomorphic encryption keys and homomorphic decryption keys to the KMC, and the derivation request may include an identifier of a homomorphic encryption algorithm. The identifier of the homomorphic encryption algorithm carried in the derivation request may be determined based on the identifiers of homomorphic encryption algorithms supported by the homomorphic enablement unit in PLMN1. For example, if all homomorphic enablement units in PLMN1 support homomorphic encryption algorithm 1, HECF1 may include identification information for homomorphic encryption algorithm 1 in the homomorphic encryption key and homomorphic decryption key derivation requests sent to KMC. Alternatively, if more than a specified percentage threshold of homomorphic enablement units in PLMN1 support homomorphic encryption algorithm 1, HECF1 may instead include an identifier for homomorphic encryption algorithm 1 in the homomorphic encryption key and homomorphic decryption key derivation requests sent to KMC, and determine that homomorphic enablement units in PLMN1 that support homomorphic encryption algorithm 1 can be orchestrated or scheduled as homomorphic computation parties for homomorphic tasks, thereby ensuring the reliable execution of homomorphic tasks.
[0179] After receiving homomorphic encryption key and homomorphic decryption key derivation requests from HECF network element 1, KMC may derive a first homomorphic encryption key and a first homomorphic decryption key corresponding to PLMN1 based on the key generator corresponding to the identifier of the homomorphic encryption algorithm carried in the derivation request, and deliver the first homomorphic encryption key and the first homomorphic decryption key to HECF network element 1.
[0180] For an implementation where HECF network element 2 obtains the second homomorphic encryption key and second homomorphic decryption key corresponding to PLMN2, please refer to the previously mentioned implementation where HECF network element 1 obtains the first homomorphic encryption key and first homomorphic decryption key corresponding to PLMN1. Details will not be described again.
[0181] It can be understood that, before the aforementioned steps are performed, network authentication may be performed between the network elements in the AN or CN within the PLMN (e.g., PLMN1 and PLMN2), the HECF, and the KMC to establish a secure channel. The UE may also access the network (e.g., the AN and / or CN) and perform authentication with the network (e.g., authentication and key agreement, AKA) to establish a secure channel.
[0182] S1402: HECF network element 1 transmits the first homomorphic encryption key to the first homomorphic enabler belonging to PLMN1, and HECF network element 2 transmits the second homomorphic encryption key to the first homomorphic enabler belonging to PLMN2.
[0183] S1403: HECF network element 1 and HECF network element 2 perform first homomorphic task scheduling (or orchestration).
[0184] For example, an application layer APP, as a homomorphic task request party, sends a first homomorphic task request requesting the computation results of data related to UE1 in PLMN1 and UE2 in PLMN2. After receiving the first homomorphic task request (or first homomorphic task subrequest) corresponding to the first homomorphic task, HECF network elements in the communication network (e.g., HECF network element 1 and HECF network element 2) may perform homomorphic task scheduling (or orchestration). For example, homomorphic enablement units are selected to participate in the first homomorphic task, and the selected homomorphic enablement units participating in the first homomorphic task may include a homomorphic encryption party, a homomorphic computation party, and so on.
[0185] S1404: HECF network element 1 sends a homomorphic computed key derivation request to KMC, and HECF network element 2 sends a homomorphic computed key derivation request to KMC.
[0186] The homomorphic key derivation request sent to the KMC by HECF network element 1 may include the identifier of the first homomorphic task, key parameters determined based on the first homomorphic encryption key and / or the first homomorphic decryption key, and public parameters used to derive the first homomorphic encryption key and / or the first homomorphic decryption key. The key parameters determined based on the first homomorphic encryption key and / or the first homomorphic decryption key may be one or more of the first homomorphic encryption key, the first homomorphic decryption key, and the first temporary homomorphic key, or they may be key parameters used to derive the first homomorphic encryption key and / or the first homomorphic decryption key. For the implementation in which HECF network element 2 sends the homomorphic key derivation request to the KMC, please refer to the implementation implemented by HECF network element 1. Further details will not be described again.
[0187] It should be understood that step S1404 may not be performed if the key parameters carried in the homomorphic computed key derivation request sent to the KMC by HECF network element 1 and / or HECF network element 2 are stored in the KMC. For example, the homomorphic encryption key and homomorphic decryption key of HECF network element 1 and HECF network element 2 are both derived by the KMC. If the KMC stores the key parameters corresponding to HECF network element 1 and HECF network element 2 that are used to derive the homomorphic computed key, then step S1404 may not be performed.
[0188] S1405: KMC derives the two-party homomorphism computation key for the first homomorphism task.
[0189] After receiving key parameters from HECF network element 1 and key parameters from HECF network element 2, KMC can derive two-party homomorphic computation keys corresponding to PLMN1 and PLMN2 based on the key parameters from HECF network element 1 and key parameters from HECF network element 2.
[0190] S1406: KMC sends homomorphic computed keys to HECF network element 1 and HECF network element 2.
[0191] S1407: HECF network element 1 transmits a homomorphic calculation key to a second homomorphic activation unit which functions as a homomorphic calculation party in PLMN1, and HECF network element 2 transmits a homomorphic calculation key to a second homomorphic activation unit which functions as a homomorphic calculation party in PLMN2.
[0192] The above explanation should be understood to mean that the cryptographic capability reported by a homomorphic enabling unit (e.g., a network element in an AN or CN, such as a UE) includes homomorphic encryption capability, such as homomorphic encryption security level and identification information of supported homomorphic encryption algorithms, and is provided by using an example in which an HECF network element obtains homomorphic encryption and decryption keys. It should be understood that the above cryptographic capability may further include symmetric / asymmetric encryption capability that does not include homomorphic features, such as whether corresponding / asymmetric encryption is supported. An HECF network element may further obtain symmetric / asymmetric encryption and decryption keys that do not include homomorphic features, for example by using KMC to derive domain-level symmetric / asymmetric encryption and decryption keys, and send the domain-level symmetric / asymmetric encryption keys to the encryption party. In this case, when the symmetric / asymmetric ciphertext is received by a computation party (e.g., a homomorphic computation party), the symmetric ciphertext may first be converted to a homomorphic ciphertext, and then the homomorphic computation is performed. Alternatively, the computed homomorphic ciphertext may be sent to the decryption party (e.g., an HECF network element), or the computed homomorphic ciphertext may be converted to a symmetric / asymmetric ciphertext before being sent to the decryption party. This is not limited to the present invention.
[0193] According to the present invention, homomorphic tasks and key management can be performed on a domain basis. Each domain corresponds to one homomorphic encryption key, and users within each domain correspond to the same homomorphic encryption key. The homomorphic encryption key may be separated from the user state and specific homomorphic tasks, so that the same homomorphic ciphertext of a user can be provided to homomorphic computation parties of different homomorphic tasks for homomorphic computation, improving the reusability of the user's homomorphic ciphertext and facilitating the transfer of homomorphic ciphertext between different homomorphic tasks. In addition, domain-level homomorphic encryption keys rather than user-level homomorphic encryption keys (for example, each homomorphic encryption party corresponds to one homomorphic encryption key) can reduce the number of homomorphic encryption keys within homomorphic tasks, reduce the derivation of homomorphic computation keys, reduce the complexity of homomorphic computation, and improve the efficiency of homomorphic computation.
[0194] The following describes a communication device provided in embodiments of the present application. Figure 15 is a diagram showing the structure of a communication device according to embodiments of the present application. The communication device may include units or modules corresponding to all or some of the steps in the embodiments of the method described above, and may be configured to perform steps performed by a control network element (e.g., a first control network element) or a key management party (e.g., a KMC) in the embodiments described above. For further details, refer to the description of embodiments of the method described above.
[0195] As shown in Figure 15, the communication device 1500 includes a processing unit 1510 and an interface unit 1520. The processing unit 1510 may be a processor or processing circuit, and the interface unit 1520 may further be a transceiver unit or an input / output interface. The communication device 1500 may be configured to perform steps carried out by a control network element or a key management party in the embodiments described above.
[0196] When the communication device 1500 is configured to perform the steps performed by the first control network element in the above-described embodiment, the processing unit 1510 is configured to acquire a first homomorphic encryption key corresponding to a first domain, and the interface unit 1520 is configured to transmit the first homomorphic encryption key to M first homomorphic enablement units belonging to the first domain, where M is an integer greater than or equal to 1, and to transmit the first homomorphic calculation key to N second homomorphic enablement units belonging to the first domain, where N is an integer greater than or equal to 1, and the first homomorphic calculation key is determined based on the first homomorphic encryption key and / or the first homomorphic decryption key corresponding to the first homomorphic encryption key.
[0197] For alternative implementations, please refer to the relevant descriptions of the first control network element or key management party in the embodiments described above. Further details will not be provided here.
[0198] As shown in Figure 16, the present invention further provides a communication device 1600, which includes a processor 1610 and may further include a communication interface 1620. The processor 1610 and the communication interface 1620 are coupled to each other. It can be understood that the communication interface 1620 may be a transceiver, an input / output interface, an input interface, an output interface, an interface circuit, etc. Optionally, the communication device 1600 further includes a memory 1630, which is configured to store instructions executed by the processor 1610, input data necessary for the processor 1610 to execute instructions, or data generated after the processor 1610 has executed instructions. The memory 1630 may be a physically separate unit, or it may be coupled to the processor 1610, or the processor 1610 may include the memory 1630.
[0199] When the communication device 1600 is configured to perform steps performed by the first control network element or key management party in the above-described embodiment, the processor 1610 may be configured to perform the functions of the processing unit 1510, and the communication interface 1620 may be configured to perform the functions of the interface unit 1520.
[0200] It should be noted that the processor in the embodiments of this application may be a Central Processing Unit (CPU), or another general-purpose processor, a Digital Signal Processor (DSP), an Application-Specific Integrated Circuit (ASIC), a logic circuit, a Field Programmable Gate Array (FPGA), or another programmable logic element, a transistor logic element, a hardware component, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0201] The steps of the method in the embodiments of this application may be implemented by hardware or by executing software instructions by a processor. The software instructions may include corresponding software modules. The software modules may be stored in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk drives, removable hard disk drives, CD-ROMs, or any other form of storage medium well known in the art. For example, the storage medium may be coupled to a processor, as a result the processor may read information from and write information to the storage medium. Of course, the storage medium may be a component of the processor. The processor and storage medium may be located within an ASIC. Furthermore, the ASIC may be located within a network device or terminal device. Of course, the processor and storage medium may, alternatively, exist as separate components within the network device or terminal device.
[0202] All or part of the embodiments described above can be implemented using software, hardware, firmware, or any combination thereof. When software is used to implement an embodiment, all or part of the embodiment may be implemented in the form of a computer program product. A computer program product includes one or more computer programs or instructions. When a computer program or instruction is loaded onto a computer and executed, it generates all or part of the procedures or functions according to the embodiments of the present application. The computer may be a general-purpose computer, a dedicated computer, a computer network, a network device, a user device, or another programmable device. The computer program or instruction may be stored on a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, a computer program or instruction may be transmitted by wired or wireless means from one network device, terminal, computer, server, or data center to another network device, terminal, computer, server, or data center. The computer-readable storage medium may be any available medium accessible by a computer, or a data storage device, such as a server or data center integrating one or more available media. The usable media may be magnetic media, such as floppy disks, hard disk drives, or magnetic tapes; optical media, such as digital video discs; or semiconductor media, such as solid-state drives. The computer-readable storage medium may be volatile or non-volatile storage medium, or may include both volatile and non-volatile storage mediums.
[0203] In the embodiments of this application, unless otherwise specified or there is no logical conflict, terms and / or descriptions in different embodiments are consistent and can be referenced to one another. Technical features in different embodiments may be combined on an internal logical basis to form new embodiments.
[0204] In addition, it should be understood that the term “for example” in the embodiments of this application is used to represent an example, illustration, or description. Any embodiment or design described as “example” in this application should not be construed as being preferable or advantageous to other embodiments or designs. More precisely, the term “for example” is intended to present a concept in a particular way.
[0205] It should be further understood that the various numbers in the embodiments of this application are distinguished simply for the sake of clarity and are not used to limit the scope of the embodiments of this application. The sequence numbers of the processes described above do not mean execution sequences, and the execution sequence of a process should be determined based on the function and internal logic of the process.
Claims
1. A domain-based key management method, The first control network element obtains a first homomorphic encryption key corresponding to the first domain, The first control network element transmits the first homomorphic encryption key to M first homomorphic activation units belonging to the first domain, where M is an integer of 1 or more. The first control network element transmits a first homomorphic compute key to N second homomorphic activation units belonging to the first domain, wherein N is an integer of 1 or more, and the first homomorphic compute key is determined based on the first homomorphic encryption key and / or the first homomorphic decryption key corresponding to the first homomorphic encryption key. A method that includes this.
2. The N second homomorphic activation units are homomorphic computation parties participating in the first homomorphic task within the first domain, The method according to claim 1, wherein the first homomorphic computation key is determined based on K homomorphic encryption keys and / or K homomorphic decryption keys corresponding to K domains, the participants in the first homomorphic task are distributed across the K domains, the K domains include the first domain, the K homomorphic encryption keys include the first homomorphic encryption key, and the K homomorphic decryption keys include the first homomorphic decryption key, where K is an integer of 1 or more.
3. The method according to claim 2, wherein the K domains are obtained by partitioning based on the network architecture layer and / or service type slice.
4. The first domain corresponds to the core network, access network, or application layer. The first domain corresponds to a data network, cloud server, cloud server cluster, or application in the application layer. The first domain corresponds to an access network set, the access network set includes P access network nodes or cells, where P is an integer of 1 or more. The first domain corresponds to the Public Land Mobile Network (PLMN) of the core network, or one or more network elements within the PLMN of the core network, or The method according to any one of claims 1 to 3, wherein the first domain corresponds to a network slice, a network slice of the core network, or a network slice of the application layer.
5. The step of obtaining the first homomorphic encryption key corresponding to the first domain using the first control network element is: The first control network element derives the first homomorphic encryption key and the first homomorphic decryption key corresponding to the first domain, or The first control network element obtains the first homomorphic encryption key and the first homomorphic decryption key corresponding to the first domain from the key management party. The method according to any one of claims 1 to 4, including the method described in any one of claims 1 to 4.
6. Before the first control network element obtains the first homomorphic encryption key and the first homomorphic decryption key corresponding to the first domain from the key management party, the method The first control network element determines to establish a secure channel to the key management party, The method according to claim 5, further comprising:
7. Before the first control network element transmits the first homomorphic calculation key to the N second homomorphic activation units belonging to the first domain, the method: The first step of receiving a first homomorphic task request by the first control network element, wherein the first homomorphic task request is used to request the configuration of the first homomorphic task, A step of transmitting task configuration information to Q third homomorphic activation units participating in the first homomorphic task within the first domain by the first control network element, wherein the task configuration information includes homomorphic task rolls of the Q third homomorphic activation units, the Q third homomorphic activation units include the N second homomorphic activation units, the N second homomorphic activation units are the homomorphic computation parties participating in the first homomorphic task within the first domain, and Q is an integer greater than or equal to N, The method according to any one of claims 1 to 6, further comprising:
8. Before the first control network element transmits the first homomorphic calculation key to the N second homomorphic activation units belonging to the first domain, the method: The steps include receiving a first homomorphic task subrequirement by the first control network element, wherein the first homomorphic task subrequirement constitutes the first homomorphic task in the first domain, A step of transmitting task configuration information to Q third homomorphic activation units participating in the first homomorphic task within the first domain by the first control network element, wherein the task configuration information includes homomorphic task rolls of the Q third homomorphic activation units, the Q third homomorphic activation units include the N second homomorphic activation units, the N second homomorphic activation units are the homomorphic computation parties participating in the first homomorphic task within the first domain, and Q is an integer greater than or equal to N, The method according to any one of claims 1 to 6, further comprising:
9. The participants in the first homomorphism task are distributed across the K domains, the K domains include the first domain, K is an integer of 1 or more, and the method is A step of transmitting a first homomorphic task subrequirement separately to (K-1) control network elements corresponding to (K-1) domains other than the first domain among the K domains, wherein the first homomorphic task subrequirement indicates that the (K-1) domains constitute the first homomorphic task. The method according to claim 7, further comprising:
10. The aforementioned method, The first control network element transmits key parameters of the first domain to the key management party, wherein the key parameters are determined based on the first homomorphic encryption key and / or first homomorphic decryption key corresponding to the first domain. The first control network element receives the first homomorphic computed key from the key management party, The method according to any one of claims 1 to 9, further comprising:
11. Before the first control network element transmits the task configuration information to the Q third homomorphic enablement units participating in the first homomorphic task within the first domain, the method: A first control network element determines the homomorphic task roll of the Q third homomorphic activators participating in the first homomorphic task within the first domain, based on the first homomorphic task request and the homomorphic capability information of the L fourth homomorphic activators belonging to the first domain, wherein the L fourth homomorphic activators include the Q third homomorphic activators, and L is an integer greater than or equal to Q. The method according to claim 7, further comprising:
12. The aforementioned method, The first control network element acquires homomorphic capability information for any one of the L fourth homomorphic activation units, The method according to claim 11, further comprising the step of generating a homomorphic capability profile of the fourth homomorphic enablement unit based on the homomorphic capability information of the fourth homomorphic enablement unit using the first control network element.
13. The aforementioned method, A step of receiving F pieces of first information from F second control network elements by the first control network element, wherein the first information from any one of the F second control network elements includes homomorphic capability information of at least one homomorphic activation unit belonging to the domain corresponding to the second control network element. The first control network element determines the (K-1) domains in which the participants of the homomorphic encryption task are distributed, based on the first homomorphic task request and the F first pieces of information. The method according to claim 9, further comprising:
14. A domain-based key management method, A key management party obtains key parameters for K domains participating in a first homomorphism task from K control network elements, wherein the participants in the first homomorphism task are distributed across the K domains, the K control network elements each correspond to one of the K domains, and the key parameter for any one of the K domains is determined based on the homomorphic encryption key and / or homomorphic decryption key of the domain, where K is an integer of 1 or more. The key management party determines the first homomorphic computation key for the first homomorphic task based on the key parameters of the K domains, The key management party separately transmits the first homomorphic computation key to the K control network elements. A method that includes this.
15. The K domains include a first domain, the K control network elements include a first control network element corresponding to the first domain, and the step of obtaining the key parameters of the K domains participating in the first homomorphic task from the K control network elements by the key management party is: The steps include receiving key parameters for the first domain from the first control network element by the key management party, wherein the key parameters are determined based on a first homomorphic encryption key and / or a first homomorphic decryption key corresponding to the first domain, The step of the key management party separately transmitting the first homomorphic computation key to the K control network elements is: The method according to claim 14, further comprising the step of transmitting the first homomorphic computed key to the first control network element by the key management party.
16. The K domains include the first domain, the K control network elements include the first control network elements corresponding to the first domain, and the method is The key management party derives the first homomorphic encryption key and the first homomorphic decryption key for the first domain, The key management party transmits the first homomorphic encryption key and the first homomorphic decryption key to the first control network element corresponding to the first domain. The method according to claim 14 or 15, further comprising:
17. The step of the key management party obtaining the key parameters of the K domains participating in the first homomorphism task from the K control network elements is: The method according to claim 16, further comprising the step of determining the key parameters of the first domain based on the first homomorphic encryption key and / or the first homomorphic decryption key of the first domain by the key management party.
18. The method according to any one of claims 15 to 17, wherein the K domains are obtained by partitioning them based on a network architecture layer and / or a service type slice.
19. The first domain corresponds to the core network, access network, or application layer. The first domain corresponds to a data network, cloud server, cloud server cluster, or application in the application layer. The first domain corresponds to an access network set, the access network set includes P access network nodes or cells, where P is an integer of 1 or more. The first domain corresponds to the Public Land Mobile Network (PLMN) of the core network, or one or more network elements within the PLMN of the core network, or The method according to any one of claims 15 to 18, wherein the first domain corresponds to a network slice, a network slice of the core network, or a network slice of the application layer.
20. A communication device, including an interface unit and a processing unit, The interface unit is configured to receive and transmit data. A communication device wherein the processing unit is configured to perform the method according to any one of claims 1 to 19 by using the interface unit.
21. A communication device comprising a processor and an interface circuit, wherein the interface circuit is configured to receive a signal from a communication device other than the communication device and transmit the signal to the processor, or to transmit a signal from the processor to a communication device other than the communication device, and the processor is configured to carry out the method according to any one of claims 1 to 19 by using logic circuits or by executing instructions.
22. A computer program product that stores a computer program or instruction, and when the computer program or instruction is executed by a processor, the method described in any one of claims 1 to 19 is performed.
23. A chip system comprising a processor, wherein the processor is configured to be coupled to a memory, the memory is configured to store a computer program or instruction, and when the computer program or instruction is executed by the processor, the method according to any one of claims 1 to 19 is performed.
24. A computer-readable storage medium, wherein the storage medium stores a computer program or instruction, and when the computer program or instruction is executed by a processor, the method according to any one of claims 1 to 19 is performed.
25. A domain-based key management system, wherein the system includes a first control network element and a key management party. The first control network element is configured to carry out the method described in any one of claims 1 to 13, The key management party is configured to implement the method described in any one of claims 14 to 19, a domain-based key management system.