Communication method and apparatus, and readable storage medium
By using symmetric key encryption technology and random number-generated ciphertexts in low-power or low-computing devices, the security protection problem of the device without a battery or limited energy storage capacity is solved, and the efficient security guarantee of the device is achieved.
Patent Information
- Application Number
- PCT/CN2024/128035
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-30
- Filing Date
- 2024-10-29
- Publication Date
- 2025-05-08
AI Technical Summary
Existing wireless communication equipment requires manual replacement or recharge of batteries, resulting in high maintenance costs, serious environmental problems, and poses safety hazards, especially in low-power or low-computing equipment, which is difficult to achieve effective safety protection.
By using symmetric key encryption technology in the terminal device, the terminal device receives a random number in the first message, generates a ciphertext based on the random number, sequence number and key, and generates a subscription hidden identity (SUCI) using the key identification to realize identity protection of the terminal device and subsequent authentication and key negotiation.
When meeting the power consumption requirements of low-power or low-computing power devices, the permanent identification of terminal devices is effectively protected, the security of the device is improved, and the risk of playback attacks on the network side is reduced.
Smart Images

Figure CN2024128035_08052025_PF_FP_ABST
Abstract
Description
Communication method, device and readable storage medium
[0001] This application claims priority to the Chinese patent application with application number 202311435075.8 filed with the State Intellectual Property Office of China on October 30, 2023, and priority to the Chinese patent application with the invention name “Communication Method, Device and Readable Storage Medium”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a communication method, device, and readable storage medium. Background Art
[0003] In recent years, the Internet of Things (IoT) has garnered widespread attention in the wireless communications sector. By interconnecting more IoT devices, productivity and comfort can be improved. Reducing the size, complexity, and power consumption of IoT devices can enable the deployment of tens or even hundreds of billions of IoT devices for a variety of applications, providing greater added value. However, most existing wireless communications devices are battery-powered, requiring manual replacement or recharging. Therefore, powering IoT devices with manually replaceable or rechargeable batteries results in high maintenance costs, serious environmental concerns, and even safety risks in certain use cases, such as wireless sensors in the power and oil industries.
[0004] Therefore, a new physical network technology is needed to support battery-free devices without energy storage capabilities or energy storage devices that do not require manual replacement or charging. Some people have proposed that power can be obtained from the environment, such as by collecting radio waves, light, motion, heat or any other suitable source to provide energy for devices without batteries or with limited energy storage capabilities (such as using capacitors). These battery-free or energy-limited devices have limited size and complexity in practical applications, and the energy they provide through energy harvesters typically has an output power of 1μW (microwatt) to several hundred microwatts. Due to their limited energy storage capacity and the low output power of energy harvesting, they are required to have low power consumption.
[0005] For such devices without batteries or with limited energy storage capabilities, or low-power or low-computing devices, their security issues are worth considering.
[0006] Summary of the Invention
[0007] The embodiments of the present application provide a communication method, device, and readable storage medium, which can protect the permanent identification of low-power or low-computing power devices while meeting the power consumption requirements of low-power or low-computing power devices and improve the security of low-power or low-computing power devices.
[0008] The present application is introduced below from different aspects. It should be understood that the implementation methods and beneficial effects of the following different aspects can be referenced to each other.
[0009] In a first aspect, the present application provides a communication method, the method comprising: a terminal device receives a first message, the first message including a first random number (nonce); the terminal device generates a ciphertext based on the first random number, the serial number of the terminal device, and a first key, and generates a subscription concealed identifier (SUCI) based on the key identifier and the ciphertext; the terminal device sends a second message to a first network element. The key identifier can be used (for the terminal device and other network elements) to index the preconfigured first key. Exemplarily, the SUCI can be used for identity protection of the terminal device and for subsequent authentication and key agreement (AKA).
[0010] Illustratively, the serial number of the terminal device may be the serial number of the terminal device itself, or the serial number of a subscriber identity module (SIM) card in the terminal device, such as a mobile subscriber identification number (MSIN).
[0011] Exemplarily, the terminal device of the present application may be an Internet of Things device, such as: Ambient IoT (A-IoT) device, Passive IoT (P-IoT) device, smart tag, passive tag, active tag, industrial control element, etc. The Internet of Things device in the present application may be low-power, or low-computing power, or have limited energy storage capacity. The first network element of the present application may be an access and mobility management function (AMF) or a tag management function (TMF). Among them, the tag management function (TMF) can be understood as an AMF that specifically manages tags, which may be deployed in a toB (to business) park.
[0012] Exemplarily, the first key may be pre-configured in the terminal device.
[0013] Exemplarily, the first key may be a key of a symmetric encryption algorithm, or the first key may also be referred to as a symmetric key. Symmetric key encryption is also referred to as private key encryption or shared key encryption, i.e., the key used by the data sender to encrypt the plaintext is the same as the key used by the data receiver to decrypt the corresponding ciphertext. Specifically, the first key is also used to decrypt the ciphertext on the network side. Symmetric encryption algorithms include, but are not limited to, the Advanced Encryption Standard (AES) algorithm, or the Robin Montgomery algorithm (ROMAN), the Zuchongzhi algorithm ZUC-128 or ZUC stream cipher, or AES-128.
[0014] It is understood that the key used by the terminal device to encrypt the plaintext and the key used by the network side to decrypt the ciphertext have the same value. For ease of understanding, this application refers to both as the first key. Of course, in actual applications, different keys can also be distinguished, such as Key 1 and Key 2, and the values of Key 1 and Key 2 are the same.
[0015] Understandably, because IoT devices typically consume very little power, they are not suitable for the public key cryptography mechanisms used in existing cellular communication systems (e.g., Elliptic Curve Integrated Cryptography). This is because the existing UE identity authentication process requires the dynamic generation of a public key and the use of this public key to encrypt the UE's serial number. However, the generation and encryption of public keys are complex and energy-intensive. Therefore, the security protection schemes used in existing cellular communication systems cannot be directly applied to IoT devices.
[0016] Therefore, the terminal device of the present application uses the first key to encrypt its own serial number (Serial Number), and carries the key identifier of the first key in the SUCI, so that the network element on the network side can also use the same first key for decryption. There is no need to dynamically generate a public key to protect the serial number of the terminal device, that is, to protect the serial number of the terminal device using a symmetric key. While meeting the power consumption requirements of low-power or low-computing power devices (such as IoT devices), it can protect the permanent identification of low-power or low-computing power devices and improve the security of low-power or low-computing power devices.
[0017] In addition, the present application adds a first random number (nonce) during the generation process of the ciphertext, which can increase the freshness of the ciphertext or key, so that even if an attacker obtains a symmetric key (such as the first key), he cannot decrypt the ciphertext to obtain the serial number of the terminal device, which can further improve security; and can reduce replay attacks on the network side.
[0018] With reference to the first aspect, in one possible implementation, the SUCI is further generated based on one or more of the following: a subscription permanent identifier (SUPI) type, a home network identifier of the terminal device, the first random number, or a message authentication code. In other words, when generating the SUCI, the terminal device may generate the SUCI based on one or more of the following: the SUPI type, the home network identifier of the terminal device, the first random number, or a message authentication code, in addition to the key identifier and ciphertext.
[0019] In conjunction with the first aspect, in one possible implementation, the ciphertext is further generated based on a second random number (RAND). The second random number may be generated by the terminal device. In other words, when generating the ciphertext, the terminal device may also incorporate the second random number (RAND) into the ciphertext generation process. It will be appreciated that random numbers can be categorized as pseudorandom numbers and true random numbers. For example, the first random number (nonce) may be a true random number, and the second random number (RAND) may be a pseudorandom number.
[0020] The present application adds a second random number (RAND) during the ciphertext generation process, which can be used to increase the randomness of the ciphertext and further improve security.
[0021] In conjunction with the first aspect, in one possible implementation, the ciphertext may be obtained by encrypting the concatenated serial number of the terminal device and the second random number using a second key generated based on the first key and the first random number.
[0022] In combination with the first aspect, in a possible implementation, the ciphertext may be obtained by encrypting the concatenated serial number of the terminal device, the second random number, and the first random number based on the first key.
[0023] In conjunction with the first aspect, in one possible implementation, the second message includes the first random number. Exemplarily, the first random number is carried in the SUCI. Exemplarily, the first random number is carried as an information element in the second message.
[0024] The present application carries a first random number in the second message, which can be used by the first network element to verify the validity of the first random number, thereby reducing replay attacks on the network side and improving security.
[0025] In conjunction with the first aspect, in one possible implementation, the first message may be a selection message, which is used to trigger an access process for a terminal device. Exemplarily, the selection message may be a beam that enables the terminal device to obtain energy, thereby performing a subsequent access process. Exemplarily, the selection message may be a system information broadcast (SIB) message, which may be used by an access network device (such as a base station) to select a terminal device through broadcast for a subsequent access process.
[0026] This application notifies nonce by selecting a message (such as a SIB message), which helps to configure random numbers to terminals in batches and saves signaling overhead on the network side.
[0027] In conjunction with the first aspect, in one possible implementation, the first message may also be a random access response or a radio resource control connection establishment message during an access process. Alternatively, the first message may be a non-access stratum (NAS) message. When the first message is a NAS message, the first message may be sent by the first network element to the access network device, which may then forward the message to the terminal device.
[0028] In conjunction with the first aspect, in one possible implementation, before the terminal device receives the first message, the method further includes: the terminal device receiving a third message from an application function (AF), where the third message includes the key identifier and the first key. In other words, the key identifier and the first key used by the terminal device may be configured by the AF.
[0029] In a second aspect, the present application provides a communication method, comprising: a first network element sending a first random number to a terminal device via an access network device, the first random number being used by the terminal device to generate ciphertext; the first network element receiving a second message from the terminal device, the second message including a SUCI; and the first network element sending an authentication request to a second network element, the authentication request including the SUCI. The SUCI can be used to protect the identity of the terminal device. The SUCI can be generated based on a key identifier and the ciphertext. The key identifier can be used to index a first key. The first key can be used to decrypt the ciphertext to obtain a serial number of the terminal device. The second network element can be determined based on the home network identifier of the terminal device in the SUCI.
[0030] Exemplarily, the first random number is generated by the first network element.
[0031] Exemplarily, the second network element in the present application may be an authentication credential repository and processing function (ARPF) or a unified data management (UDM) function.
[0032] After receiving the second message from the terminal device (the second message includes the SUCI), the first network element of the present application sends the SUCI to the second network element through an authentication request, so that the second network element authenticates the terminal device to confirm the identity of the terminal device, thereby improving the security of the terminal device.
[0033] In combination with the second aspect, in a possible implementation, before the first network element sends the first random number to the terminal device through the access network device, the method further includes: the first network element receives a service request from the AF, and the service request includes a service indication or terminal device identification information. The service indication or terminal device identification information can be used to determine the above-mentioned terminal device. The specific determination method is described in the following method embodiment and is not described in detail here. Exemplarily, the service request can be used to request certain terminal devices to perform certain operations, for example: the service request is used to request terminal devices whose identification is within a certain range to perform inventory or temperature measurement and other operations. Therefore, after receiving the service request, the first network element can determine the corresponding terminal device based on the service request, and send the first random number to these terminal devices, so that these terminal devices generate ciphertext based on the first random number for authentication. For the convenience of description, this application takes a terminal device as an example for illustration.
[0034] This application triggers the first network element to send a first random number to some terminal devices through a service request, which can increase the flexibility of the solution without having to operate all terminal devices in the network.
[0035] In conjunction with the second aspect, in one possible implementation, after receiving the first random number, the terminal device may generate ciphertext based on the first random number, a serial number of the terminal device, and a first key, and generate a SUCI based on the key identifier and the ciphertext. The terminal device then sends a second message carrying the SUCI to the first network element.
[0036] Exemplarily, when generating the SUCI, the terminal device may generate the SUCI based on one or more of the following, in addition to the key identifier and the ciphertext: the type of the SUPI, the home network identifier of the terminal device, the first random number, or a message authentication code.
[0037] In conjunction with the second aspect, in one possible implementation, the second message includes the first random number. Exemplarily, the first random number is carried in the SUCI. Exemplarily, the first random number is carried as an information element in the second message.
[0038] In conjunction with the second aspect, in one possible implementation, when the first network element determines that the first random number included in the second message is valid, the first network element then sends an authentication request to the second network element. The authentication request can be used to request authentication of the terminal device to confirm the identity of the terminal device. Regarding the method for determining whether the first random number included in the second message is valid, please refer to the description of the method embodiment below and will not be described in detail here. The first network element of the present application sends the authentication request again when the first random number is valid, which can further improve security.
[0039] In conjunction with the second aspect, in one possible implementation, after receiving the authentication request, the second network element may decrypt the ciphertext using the first key indexed by the key identifier to obtain the serial number of the terminal device; and then determine the SUPI of the terminal device based on the serial number of the terminal device. The specific method for determining the SUPI can be found in the description of the method embodiment below and is not detailed here. This SUPI can be used for subsequent execution of the AKA mechanism.
[0040] In conjunction with the second aspect, in one possible implementation, the authentication request further includes one or more of the following: indication information, or the first random number. The indication information may be used to indicate that the SUCI is an identifier of a low-power device or a low-computing-power device.
[0041] This application carries indication information in the authentication request, which has a clear meaning and facilitates the second network element to distinguish whether the authentication request is for a cellular device or a low-power device or a low-computing power device, and helps the second network element to confirm its behavior after receiving the authentication request.
[0042] In a third aspect, the present application provides a communication method, comprising: a second network element receiving an authentication request from a first network element, the authentication request including a SUCI, the SUCI generated based on a key identifier and ciphertext, the key identifier being used to index a first key; the second network element decrypting the ciphertext using the first key to obtain a serial number of a terminal device; and then determining a SUPI of the terminal device based on the serial number of the terminal device. The SUPI can be used to subsequently execute an AKA mechanism.
[0043] Exemplarily, the first key may be pre-configured in the second network element.
[0044] The second network element of the present application uses the first key to decrypt the ciphertext in the SUCI to obtain the serial number of the terminal device. The decryption key is the same as the key used by the terminal device to encrypt its own serial number, that is, a symmetric key method is used to protect the serial number of the terminal device. While meeting the power consumption requirements of low-power or low-computing power devices (such as IoT devices), it can protect the permanent identification of low-power or low-computing power devices and improve the security of low-power or low-computing power devices.
[0045] In conjunction with the third aspect, in one possible implementation, the second network element determines the SUPI of the terminal device based on the serial number of the terminal device, including: the second network element recombines and splices the serial number (Serial Number) of the terminal device, the plaintext in the SUCI, and / or other parameters (which may refer to content other than the plaintext in the SUCI) to obtain the SUPI of the terminal device.
[0046] Exemplarily, the plain text in the SUCI includes one or more of the following: the SUPI type, the home network identifier of the terminal device, a routing indicator, a key identifier k1, or the first random number (nonce). Other parameters include a mobile country code (MCC) and / or a mobile network code (MNC).
[0047] In conjunction with the third aspect, in one possible implementation, after the second network element decrypts the ciphertext using the first key to obtain the serial number of the terminal device, the method further includes: the second network element generating an authentication vector based on the master key corresponding to the SUPI, and performing an authentication and key agreement (AKA) mechanism. It will be understood that in the AKA mechanism, the SUPI corresponds to a master key, from which a cipher key (CK) and an integrity key (IK) can be derived for subsequent communication security.
[0048] In conjunction with the third aspect, in one possible implementation, before the second network element generates the authentication vector based on the master key corresponding to the SUPI, the method further includes: the second network element determining, based on a preconfigured correspondence between the key identifier and the SUPI, that the SUPI is valid; and if the SUPI is valid, the second network element may generate the authentication vector based on the master key corresponding to the SUPI.
[0049] In combination with the third aspect, in a possible implementation, before the second network element receives the authentication request from the first network element, the method also includes: the second network element receives a key generation request from the AF, and the key generation request includes the key identifier; the second network element generates one or more keys based on the key identifier; the second network element sends a key generation response to the AF, and the key generation response includes the one or more keys, and the one or more keys include the first key.
[0050] Exemplarily, the key generation request further includes one or more home network identifiers, and the one or more home network identifiers are used to generate one or more keys in combination with the key identifier.
[0051] In a fourth aspect, the present application provides a communication method, comprising: a first network element sending a first random number to a terminal device via an access network device, the first random number being used by the terminal device to generate ciphertext; the first network element receiving a second message from the terminal device, the second message including a SUCI, the SUCI being generated based on a key identifier and the ciphertext; the first network element obtaining a key factor for deriving the first key from a key storage network element based on the key identifier, and then determining the first key based on the key factor and the first random number; the first network element decrypting the ciphertext in the SUCI using the first key to obtain a serial number of the terminal device, and determining a SUPI of the terminal device based on the serial number of the terminal device. The SUPI can be used to subsequently execute an AKA mechanism.
[0052] The first network element of the present application uses the first key to decrypt the ciphertext in the SUCI to obtain the serial number of the terminal device. The decryption key is the same as the key used by the terminal device to encrypt its own serial number, that is, a symmetric key method is used to protect the serial number of the terminal device. While meeting the power consumption requirements of low-power or low-computing power devices (such as IoT devices), it can protect the permanent identification of low-power or low-computing power devices and improve the security of low-power or low-computing power devices.
[0053] In conjunction with the fourth aspect, in a possible implementation, after the first network element receives the second message from the terminal device, the first network element may split the SUCI in the second message to obtain a key identifier and a cipher.
[0054] In combination with the fourth aspect, in a possible implementation, before the first network element sends the first random number to the terminal device through the access network device, the method further includes: the first network element receives a service request from the AF, the service request including a service indication or terminal device identification information, and the service request also including a key identification. Exemplarily, the service request can be used to request certain terminal devices to perform certain operations, for example: the service request is used to request terminal devices whose identification is within a certain range to perform inventory or temperature measurement and other operations. The key identification can be used to obtain a key factor for deducing the first key. The service indication or terminal device identification information can be used to determine the above-mentioned terminal device. The specific determination method is described in the following method embodiment and is not described in detail here.
[0055] In conjunction with the fourth aspect, in one possible implementation, the first network element determines the first key based on the key factor and the first random number, including: the first network element determines one or more valid random numbers, and determines one or more keys based on the key factor and the one or more random numbers; the first network element decrypts the ciphertext based on the one or more keys, and determines the key that successfully decrypts the ciphertext as the first key. In other words, the first network element may perform multiple decryption attempts and, if the decryption is successful, obtain the serial number of the terminal device.
[0056] Exemplarily, the first network element may also determine one or more keys based on the key factor, the key identifier, and the one or more random numbers.
[0057] In the present application, when the first random number (nonce) is not carried in the second message, the first network element can also decrypt the ciphertext through multiple attempts, which can save air interface resources and is beneficial to low-power / low-computing power devices.
[0058] In conjunction with the fourth aspect, in one possible implementation, after receiving the first random number, the terminal device may generate ciphertext based on the first random number, a serial number of the terminal device, and a first key, and generate a SUCI based on the key identifier and the ciphertext. The terminal device then sends a second message carrying the SUCI to the first network element.
[0059] Exemplarily, when generating the SUCI, the terminal device may generate the SUCI based on one or more of the following, in addition to the key identifier and the ciphertext: the type of the SUPI, the home network identifier of the terminal device, the first random number, or a message authentication code.
[0060] In combination with the fourth aspect, in one possible implementation, after the first network element determines the SUPI of the terminal device based on the serial number of the terminal device, the method further includes: the first network element sends a fourth message to the second network element, the fourth message including the SUPI, and the fourth message is used to trigger the AKA mechanism.
[0061] Exemplarily, before the first network element sends the fourth message to the second network element, the method further includes: the first network element determining, based on a preconfigured correspondence between the key identifier and the SUPI, that the SUPI is valid; and if the SUPI is valid, the first network element further sending the fourth message to the second network element. This application preconfigures a correspondence between the key identifier and the SUPI, and if the SUPI is valid, then sending the fourth message to trigger the AKA mechanism. Because the SUPI is valid, the master key corresponding to the SUPI in the AKA mechanism is also valid, thereby improving the accuracy of the AKA mechanism.
[0062] In conjunction with the fourth aspect, in a possible implementation, after the second network element receives the fourth message, the second network element may generate an authentication vector based on the master key corresponding to the SUPI, and perform an authentication and key agreement AKA mechanism.
[0063] In a fifth aspect, the present application provides a communication method, comprising: a second network element receiving a fourth message from a first network element, the fourth message including the SUPI, the fourth message being used to trigger an AKA mechanism; the second network element generating an authentication vector based on a master key corresponding to the SUPI, and performing an authentication and key agreement AKA mechanism. It will be understood that in the AKA mechanism, the SUPI corresponds to a master key, from which a cipher key (CK) and an integrity key (IK) can be derived for subsequent communication security.
[0064] In a sixth aspect, the present application provides a communication device, which may be a terminal device, a first network element, a second network element, or a chip therein. The communication device includes a unit and / or module for executing the method provided by any one of the first to fifth aspects, or any possible implementation of any one of the aspects, such as a transceiver unit and / or a processing unit. The transceiver unit is used to send and receive various information or signaling, and thus can also achieve the beneficial effects (or advantages) of the method provided by any one of the first to fifth aspects.
[0065] In a seventh aspect, the present application provides a communication device, comprising a processor configured to execute the method described in any one of the first to fifth aspects, or any possible implementation thereof. Alternatively, the processor is configured to execute a program stored in a memory, and when the program is executed, the method described in any one of the first to fifth aspects, or any possible implementation thereof, is executed.
[0066] In combination with the seventh aspect, in a possible implementation, the memory is located outside the above-mentioned communication device.
[0067] In combination with the seventh aspect, in a possible implementation, the memory is located within the above-mentioned communication device.
[0068] In the present application, the processor and the memory may also be integrated into one device, that is, the processor and the memory may also be integrated together.
[0069] In combination with the seventh aspect, in a possible implementation, the communication device further includes a transceiver, and the transceiver is used to send or receive various messages.
[0070] In an eighth aspect, the present application provides a readable storage medium having program instructions stored thereon, which, when executed on a communication device, enables the communication device to execute the communication method described in any one of the first to fifth aspects, or any possible implementation of any one of the aspects.
[0071] In a ninth aspect, the present application provides a program product comprising instructions, which, when executed, enables the model authorization method described in any possible implementation of any of the first to fifth aspects to be executed.
[0072] In a tenth aspect, the present application provides a communication device, which can be implemented in the form of a chip or in the form of a device, and the device includes a processor. The processor is used to read and execute a program stored in a memory to execute one or more of any aspects of the first to fifth aspects, or one or more of the communication methods provided in any possible implementation of any aspect. Optionally, the device also includes a memory, which is connected to the processor via a circuit. Further optionally, the device also includes a communication interface, and the processor is connected to the communication interface. The communication interface is used to receive information and / or signaling to be processed, and the processor obtains the information and / or signaling from the communication interface, processes the information and / or signaling, and outputs the processing results through the communication interface. The communication interface can be an input and output interface.
[0073] Optionally, the processor and memory may be physically independent units, or the memory may be integrated with the processor.
[0074] In the eleventh aspect, the present application provides a communication system, which includes a terminal device and a first network element or a second network element, the terminal device is used to execute the method described in the above-mentioned first aspect or any possible implementation of the first aspect, the first network element is used to execute the method described in the above-mentioned second aspect, the above-mentioned fourth aspect, or any possible implementation of any aspect therein, and the second network element is used to execute the method described in the above-mentioned third aspect, the above-mentioned fifth aspect, or any possible implementation of any aspect therein.
[0075] The technical effects achieved in the above-mentioned aspects can be referred to each other or to the beneficial effects in the method embodiments shown below, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0076] Figure 1 is a schematic diagram of the 5G network architecture defined by 3GPP TS 23.501;
[0077] FIG2 is a simplified flowchart of UE identity authentication according to an embodiment of the present application;
[0078] FIG3 is a flow chart of a communication method provided in an embodiment of the present application;
[0079] FIG4 is a schematic diagram of a method for generating SUCI provided in an embodiment of the present application;
[0080] FIG5 is a flow chart of a key configuration method provided in an embodiment of the present application;
[0081] FIG6 is another flow chart of a communication method according to an embodiment of the present application;
[0082] FIG7 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0083] FIG8 is another schematic structural diagram of a communication device provided in an embodiment of the present application;
[0084] FIG9 is another schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0085] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application.
[0086] In the description of this application, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, "at least one" means one or more, and "plurality" means two or more. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c; a and b; a and c; b and c; or a, b, and c. Among them, a, b, and c can be single or multiple.
[0087] In the description of this application, words such as "first" and "second" are used only to distinguish different objects and do not limit the quantity or execution order. Moreover, words such as "first" and "second" do not necessarily mean different. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units inherent to the process, method, product, or device.
[0088] In this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary," "for example," or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary," "for example," or "for example" is intended to present the relevant concepts in a concrete way.
[0089] It should be understood that in this application, "when", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances, and do not limit the time. It does not require that the device must perform a judgment action when it is implemented, nor does it mean that there are other limitations.
[0090] Elements used in the singular herein are intended to mean "one or more" rather than "one and only one" unless specifically stated otherwise.
[0091] Additionally, the terms "system" and "network" are often used interchangeably herein.
[0092] It should be understood that in the various embodiments of the present application, expressions such as "A corresponds to B," "A corresponds to / is associated with B," and the like all indicate that there is a corresponding relationship between A and B, and that B can be determined based on A. It should also be understood that determining / generating B based on A does not mean determining B based solely on A; B can also be determined based on A and / or other information.
[0093] The following briefly introduces the network architecture of the present application. It should be understood that the network architecture described in the present application is for the purpose of more clearly illustrating the technical solutions of the embodiments of the present application and does not constitute a limitation on the technical solutions provided by the embodiments of the present application.
[0094] The technical solution provided in this application can be applied to wireless communication systems, which include but are not limited to a triple architecture of network side (such as core network), access network equipment, and terminal equipment (such as IoT devices). For example: fifth generation (5G) communication system or new radio (NR), long term evolution (LTE) network, MulteFire network (creating a new wireless network by independently operating LTE technology on unlicensed spectrum (such as global 5GHz unlicensed spectrum)), or home base station network, mobile network with wireless fidelity (Wi-Fi) access, wideband code division multiple access (WCDMA) network, fixed-mobile converged network (fixed access network accesses mobile network), and other future communication systems, such as sixth generation mobile communication system.
[0095] For example, the technical solution provided in this application can be applied to the 5G network architecture defined in the 3rd Generation Partnership Project Technical Specifications (3GPP TS) 23.501.
[0096] Refer to Figure 1, which is a schematic diagram of the 5G network architecture defined by 3GPP TS23.501. As shown in Figure 1, the 5G network architecture can be divided into two parts: the access network and the core network. The access network is used to implement functions related to wireless access, which may include the radio access network (RAN) and user equipment (UE). The core network may include but is not limited to the following logical functions: network slice selection function (NSSF), network exposure function (NEF), network repository function (NRF), policy control function (PCF), unified data management (UDM) function, application function (AF), network slice specific authentication and authorization function (NSSAAF), authentication server function (AUSF), access and mobility management function (AMF), session management function (SMF), or user plane function (UPF), etc. It can be understood that "Nnssf", "Nnef", "Nnrf", "Npcf", "Nudm", "Naf", "Nnssaaf", "Nausf", "Namf", and "Nsmf" in Figure 1 represent the names of service interfaces. For details, please refer to the relevant description in the 3GPP standard protocol, which is not explained in detail here.
[0097] In one possible implementation, the UE may access the data network by establishing a session from the UE to the RAN, then to the UPF, and then to the data network (DN), namely, a protocol data unit (PDU) session (PDU session).
[0098] Among them, UE can be a terminal device, such as a mobile phone, an IoT terminal device, a smart terminal, a vehicle terminal, a vehicle-mounted device, a wearable device, a multimedia device, a streaming device, etc. Exemplarily, IoT terminal devices (or simply IoT devices) include but are not limited to: smart tags, passive tags, active tags, radio frequency identification (RFID) devices, personal wearable devices, cars, scooters, industrial control components, smart home devices, handheld phones, ambient IoT devices (Ambient IoT, A-IoT), etc. In one possible implementation, the IoT device of the present application can be a low-power device or a low-computing power device, or a device without a battery or with limited energy storage capacity.
[0099] The RAN can be used to provide wireless access for terminal devices, including but not limited to: 5G base stations (Next-Generation node B, gNB), wireless base stations (evolved Node B, eNodeB or eNB) in LTE networks, wireless fidelity access points (Wi-Fi APs), worldwide interoperability for microwave access base stations (WiMAX BSs), relay stations, etc. In the 5G RAN architecture, the gNB can include a centralized unit (CU) and a distributed unit (DU). The gNB can also include a radio unit (RU). The CU and DU can be understood as a logical functional division of the base station. The CU and DU can be physically separated or deployed together. For example, multiple DUs can share a CU, or a single DU can be connected to multiple CUs. The CU and DU can be connected via the F1 interface.
[0100] The AMF is primarily responsible for mobility management in mobile networks, such as user location updates, user network registration, and user handover. The SMF is primarily responsible for session management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating Internet Protocol (IP) addresses to users and selecting the UPF that provides message forwarding capabilities. The PCF is responsible for providing policies to the AMF and SMF, such as Quality of Service (QoS) policies and slice selection policies. The UDM can be used to store user data, such as subscription information, authentication, or authorization information. The NSSAAF is primarily responsible for the authentication and authorization of network slices and can interact with the Authentication, Authorization, and Accounting Server (AAA-S) through the Authentication, Authorization, and Accounting Proxy (AAA-P). The AF can be responsible for providing services to the 3GPP network, such as influencing service routing and interacting with the PCF for policy control. The UPF is primarily responsible for processing user messages, such as forwarding and billing. DN may refer to an operator network that provides data transmission services to users, such as IP Multimedia Service (IMS) and the Internet.
[0101] It is understood that the various network functions shown in Figure 1 can refer to relevant protocols or standards, etc., and this application does not expand on them. It should also be understood that N1, N2, N3, N4, N6, etc. shown in Figure 1 are all interface sequence numbers. For example, the meaning of the above interface sequence numbers can be found in the meaning defined in the 3GPP standard protocol, and this application does not limit the meaning of the above interface sequence numbers.
[0102] When a UE in an existing cellular communication system (such as 5G) accesses for the first time, it will first perform UE identity authentication, and then perform the UE's AKA process, such as the fifth-generation authentication and key agreement (5G authentication and key agreement, 5G-AKA) process, or the extensible authentication protocol (EAP) AKA' process. This application mainly focuses on the UE's identity authentication. See Figure 2, which is a simplified process diagram of UE identity authentication provided by an embodiment of the present application. According to the policy of the security anchor function (SEAF), SEAF can initiate authentication with the UE in any process of establishing a signaling connection with the UE. As shown in Figure 2, the UE uses a subscription concealed identifier (SUCI) or a 5G globally unique temporary identifier (5G-GUTI) in a registration request (for example, carried by an N1 message). When SEAF is ready to start authentication with the UE, SEAF invokes the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate request message to the authentication server function (AUSF). The request message may include SUCI or 5G-GUTI, and the service network name (SN-name). If SEAF has a valid 5G-GUTI and re-authenticates the UE, SEAF shall include the subscription permanent identifier (SUPI) in the Nausf_UEAuthentication_Authenticate Request message, otherwise it shall include SUCI.
[0103] When the AUSF receives the Nausf_UEAuthentication_Authenticate Request message, it compares the service network name with the expected service network name to check whether the SEAF is authorized to use the received service network name. The AUSF temporarily stores the received service network name. If the service network is not authorized to use the service network name, the AUSF includes the "unauthorized service network" message in the Nausf_UEAuthentication_Authenticate Response. The AUSF sends a Nudm_UEAuthentication_Get request to the UDM, which includes the following information: SUCI or SUPI, and the service network name. When the UDM receives the Nudm_UEAuthentication_Get request, if it includes SUCI, the UDM calls the subscription identifier de-concealing function (SIDF). Before the UDM processes the request, the SIDF parses the SUCI to obtain the SUPI. The SIDF can decrypt the SUCI to obtain its long-term identity, namely the SUPI, such as the international mobile subscriber identity (IMSI). The UDM / authentication credential repository and processing function (ARPF) selects the authentication method supported in the subscriber data based on the SUPI, such as 5G-AKA.
[0104] In one possible implementation, the SUCI may be constructed by sequentially concatenating the SUPI Type field, the Home Network Identifier field, the Routing Indicator field, the Protection Scheme ID field, the Home Network Public Key ID field, and the Scheme Output field to obtain the SUCI. The SUPI Type field indicates the type of SUPI and has a value between 0 and 7. The Home Network Identifier field indicates the home network identifier. The Routing Indicator is recorded in the Universal Subscriber Identity Module (USIM). The Protection Scheme ID field indicates the protection algorithm ID of the SUPI. The Home Network Public Key ID field indicates the home network key (here, the public key) and has a value between 0 and 255. The Scheme Output field indicates the SUPI ciphertext. The SUPI ciphertext is obtained by encrypting the SUPI using the home network public key.
[0105] Based on the above-mentioned UE identity authentication process and SUCI construction method, it can be seen that the encryption of SUPI is implemented using the public key on the network side, so that the UDM can decrypt SUCI with the unified private key on the network side to obtain SUPI. However, in the existing UE identity authentication process, SUPI is encrypted using a public key encryption algorithm (for example, the elliptic curve integrated encryption scheme (ECIES)), which requires dynamic generation of public keys. The generation method of public keys is complex and energy-intensive, and encrypting SUPI with public keys is also complex and energy-intensive. For low-power or low-computing-power devices, their energy consumption cannot support the generation of public keys and public-key encryption. Therefore, it is not feasible to use existing security protection mechanisms to protect low-power or low-computing-power devices.
[0106] Based on this, the present application provides a communication method, device and readable storage medium, which protect the permanent identification through symmetric encryption, which can not only meet the power consumption requirements of low-power or low-computing power devices (such as IoT devices), but also improve the security of low-power or low-computing power devices.
[0107] In one possible implementation, the low-power or low-computing power devices in this application may include but are not limited to Internet of Things devices.
[0108] The technical solution provided in this application will be described in detail below with reference to more drawings.
[0109] The technical solutions provided in this application are described through a plurality of embodiments, with specific reference to the description of each embodiment below. Among them, the same or similar parts between each embodiment or implementation can refer to each other. In each embodiment in this application, and each implementation method / implementation method / implementation method in each embodiment, if there is no special explanation and logical conflict, the terms and / or descriptions between different embodiments and each implementation method / implementation method / implementation method in each embodiment are consistent and can be referenced to each other, and the technical features in different embodiments and each implementation method / implementation method / implementation method in each embodiment can be combined to form new embodiments, implementation methods, implementation methods, or implementation methods according to their inherent logical relationships. The implementation methods of this application described below do not constitute a limitation on the scope of protection of this application.
[0110] In one possible implementation, the terminal device of the present application may be an Internet of Things device, such as: Ambient Internet of Things (A-IoT) device, Passive Internet of Things (Passive IoT, P-IoT) device, smart tag, passive tag, active tag, industrial control element, etc. The Internet of Things device in the present application may be low-power, or low-computing power, or have limited energy storage capacity. The first network element in the present application may be an AMF or a tag management function (TMF). The tag management function (TMF) can be understood as a network element that manages tags (such as registration, authentication, etc.), which may be deployed in a toB (to business) park. It should be understood that TMF can be an independently set network element, or it can be jointly set up with other network elements (such as AMF network element). The second network element in the present application may be an ARPF or a UDM.
[0111] In one possible implementation, the present application also relates to a key storage network element, which can be used to store and retrieve keys or key-related information. The key storage network element can be a separately set network element, or it can be combined with the AMF / TMF, or it can be combined with the AF, depending on whether the key management is done by a third party or an operator. If the operator manages the key, the key storage network element can be set in the UDM, or combined with the AMF / TMF. If the third party manages the key, the key storage network element can be combined with the AF.
[0112] In each embodiment of the present application, "network element A sends information A to network element B" can be understood as the destination of the information A is network element B, the source of the information A is network element A, and there may be forwarding by intermediate network elements in the transmission path from the source to the destination of the information A. The embodiments of the present application only show the source and destination of the information A. It can be understood that the information may undergo necessary processing between the source and destination of the information, such as format changes, but the destination can understand the valid information from the source. Similar expressions in this application can be understood similarly and will not be elaborated here.
[0113] Each embodiment is described in detail below.
[0114] See Figure 3, which is a flow chart of a communication method provided by an embodiment of the present application. This method primarily describes how a terminal device uses a symmetric key to encrypt its own serial number (Serial Number). The ARPF / UDM of the home network decrypts the symmetric key and determines the SUPI based on the decrypted information. Symmetric key encryption, also known as dedicated key encryption or shared key encryption, means that the key used by the data sender to encrypt the plaintext is the same as the key used by the data receiver to decrypt the corresponding ciphertext.
[0115] As shown in FIG3 , the communication method includes but is not limited to the following steps:
[0116] S101: An access network device (such as a base station) sends a first message to a terminal device (such as an IoT device). The first message includes a first random number (nonce).
[0117] Correspondingly, the terminal device (such as an IoT device) receives the first message.
[0118] In one possible implementation, the above-mentioned first random number (nonce) can be generated by the first network element (such as AMF / TMF), so the first random number (nonce) can be sent by the first network element to the access network device (such as a base station), and the access network device (such as a base station) then sends it to the terminal device (such as an IoT device). Exemplarily, the first message carrying the first random number can be a non-access stratum (NAS) message. For example: the first network element can send a NAS message to the terminal device through the access network device, and the NAS message can include the first random number. Here, the access network device forwards the NAS message sent by the first network element. It can be understood that the forwarding of the access network device can be transparent forwarding, or it can be forwarding after processing all or part of the content in the NAS message, and the embodiment of the present application does not limit this.
[0119] As another example, the above-mentioned first message may be a downlink message in the access process, such as a random access response or a radio resource control (RRC) connection setup message. For example: the first network element may send an N2 message to the access network device, and the N2 message includes the first random number. After receiving the N2 message, the access network device may send a select message to the terminal device, and the select message may be used to trigger the access process of the terminal device (such as an IoT device). In one possible implementation, the select message may include the first random number. For example, the select message may be a beam that enables the terminal device to obtain energy, which enables the terminal device to obtain energy and thus perform a subsequent access process. For another example, the select message may be a system information broadcast (SIB) message, which may be used by the access network device (such as a base station) to select the terminal device through broadcasting to perform a subsequent access process. In another possible implementation, the selection message does not include the first random number, and the access network device may send the first random number to the terminal device during a subsequent access process, such as by carrying the first random number in a random access response or a radio resource control (RRC) connection setup message during the access process. Alternatively, the access network device may send the first random number to the terminal device during the RRC establishment process.
[0120] In one possible implementation, before step S101, the communication method further includes: an application function (AF) sending a service request to a first network element (such as an AMF / TMF), where the service request includes a service indication or terminal device identification information. Exemplarily, the AF may send the service request to the first network element via an NEF. The service indication or terminal device identification information may be used to determine one or more terminal devices. After receiving the service request, the first network element (such as an AMF / TMF) may determine the one or more terminal devices based on the service request. Exemplarily, the service request may be used to request certain terminal devices to perform certain operations, for example, the service request is used to request terminal devices whose terminal device identifications are within a certain range to perform operations such as inventory or temperature measurement. Therefore, after receiving the service request, the first network element may determine the corresponding terminal device based on the service request. Furthermore, the first network element may generate a first random number (nonce) and may send the first random number to one or more access network devices associated with the one or more terminal devices, so that these terminal devices generate a ciphertext based on the first random number for authentication. Here, "access network device associated with the terminal device" can be understood as: an access network device used to serve the terminal device, an access network device that establishes a connection with the terminal device, or an access network device whose coverage includes the terminal device. Exemplarily, the first network element also stores the first random number to facilitate subsequent verification of the validity of the first random number. For clarity, the embodiments of this application use a terminal device as an example.
[0121] Exemplarily, the terminal device identification information may be a terminal device identification range, such as an IoT ID range, which may be used to indicate all terminal devices within a terminal ID range. It is understood that a terminal device identification range may include one or more terminal device identifications.
[0122] Exemplarily, the above-mentioned service indication may correspond to the identification of one or more terminal devices. For example, the correspondence between the service indication and the identification of the terminal device may be pre-configured, as shown in Table 1 below. It will be understood that Table 1 below is only an example, and the embodiment of the present application does not specifically limit the correspondence between the service indication and the identification of the terminal device. After the first network element receives a service request containing a service indication, it may determine the identification range of the terminal device based on the service indication and the pre-configured correspondence, thereby determining one or more terminal devices.
[0123] Table 1
[0124] S102, the terminal device (such as an IoT device) generates a ciphertext based on the first random number, the serial number of the terminal device, and the first key.
[0125] Exemplarily, the serial number of the terminal device may refer to the serial number of the terminal device itself, or may refer to the serial number of a subscriber identity module (SIM) card in the terminal device, such as a mobile subscriber identification number (MSIN), which is not limited in the embodiments of the present application.
[0126] S103: The terminal device (such as an IoT device) generates a SUCI based on the key identifier k1 and the above ciphertext. The key identifier k1 is used to index the first key.
[0127] The first key may be pre-configured in the terminal device (such as an IoT device).
[0128] In one possible implementation, after receiving the above-mentioned first message, the terminal device (such as an IoT device) can generate a cipher based on the first random number (nonce), the serial number (serial number) of the terminal device, and the first key in the first message. Exemplarily, the terminal device can use the first random number (nonce) and / or the first key (which can be indexed by the key identifier) as input to execute a preconfigured first key generation algorithm to generate a temporary key. It can be understood that there are many key generation algorithms, such as a key derivation function (KDF) and a hash algorithm. The embodiment of the present application does not limit the specific key generation algorithm used. Furthermore, the terminal device can use the temporary key to encrypt the serial number of the terminal device to obtain a cipher. As another example, the terminal device can use the first key (which can be indexed by the key identifier) to encrypt the spliced serial number of the terminal device and the first random number (nonce) to obtain a cipher.
[0129] There are many encryption methods, such as Advanced Encryption Standard (AES), Robin Montgomery Algorithm (ROMAN), ZUC-128, or AES-128.
[0130] In one possible implementation, when generating a ciphertext, the terminal device may also generate it based on a second random number (RAND). For example, the terminal device may use the temporary key to encrypt the serial number of the spliced terminal device and the second random number (RAND) to obtain a ciphertext (cipher). Alternatively, the terminal device may use a first key (which may be indexed by a key identifier) to encrypt the serial number of the spliced terminal device, the first random number (nonce), and the second random number (RAND) to obtain a ciphertext (cipher). The second random number (RAND) may be generated by the terminal device. It will be understood that random numbers can be divided into pseudo-random numbers and true random numbers. The first random number (nonce) in the embodiment of the present application may be a true random number, and the second random number (RAND) may be a pseudo-random number.
[0131] The first key in the embodiment of the present application can be the same for multiple terminal devices (such as multiple IoT devices), and it can be understood as a group key. Correspondingly, the key identifier used to index the first key can also be the same for multiple terminal devices (such as multiple IoT devices). In other words, multiple terminal devices in the embodiment of the present application can use the same key to generate ciphertext. In addition, because the embodiment of the present application uses a symmetric key, that is, the key used for decryption and encryption is the same. Therefore, if the serial number of the terminal device is directly encrypted, since multiple terminal devices have the first key, it is easy for an attacker to obtain it.
[0132] Therefore, to improve security, the embodiment of the present application adds a first random number (nonce) during the ciphertext generation process. This can increase the freshness of the ciphertext or key, making it impossible for an attacker to decrypt the ciphertext and obtain the serial number of the terminal device even if they possess the symmetric key (such as the first key). It can also reduce replay attacks on the network side (such as the second network element). It can be understood that replay attacks, also known as replay attacks or playback attacks, refer to an attacker sending a packet that has already been received by the destination host to deceive the system. It is mainly used in the identity authentication process to undermine the correctness of the authentication.
[0133] In addition, the embodiment of the present application also adds a second random number (RAND) during the generation process of the ciphertext (cipher), which can be used to increase the randomness of the ciphertext (cipher) and further improve security.
[0134] In one possible implementation, after obtaining a cipher, the terminal device may generate a SUCI based on the key identifier and the cipher. Exemplarily, the SUCI may be formed by concatenating the key identifier and the cipher, for example: SUCI = {key identifier || cipher}, where the symbol "||" indicates concatenation, which will not be described further below. Alternatively, the SUCI may be formed by concatenating the key identifier, the cipher, and other parameters, as described below. The key identifier may be used (by the terminal device and the second network element) to index the first key. For ease of distinction, the key identifier used to index the first key will be referred to as key identifier k1 below.
[0135] In one possible implementation, when generating a SUCI, the terminal device may further generate the SUCI based on one or more of the following: the SUPI type, the terminal device's home network identifier, a routing indicator, the aforementioned first nonce, or a message authentication code (MAC). It is understood that the SUPI type can be indicated by the SUPI type field, which can represent a SUPI encryption and permutation method. In embodiments of the present application, the SUPI type can be a new type that is different from any existing SUPI type. For example, in embodiments of the present application, the value of the SUPI Type field can be a reserved value of the existing SUPI Type field, which can be used to represent the SUPI of an IoT terminal device, or the SUPI of a low-power device / low-computing device. The terminal device's home network identifier can be the network identifier to which the terminal device belongs, such as a public land mobile network ID (PLMN ID), which can be indicated by the Home Network Identifier field. In embodiments of the present application, the terminal device's home network identifier can be used to determine the second network element (e.g., ARPF / UDM). The Routing Indicator is recorded in the terminal device's USIM. MAC (Message Authentication Code) can be used to provide integrity protection (or integrity verification).
[0136] For example, see Figure 4, which is a schematic diagram of a method for generating SUCI provided in an embodiment of the present application. As shown in Figure 4, SUCI can be a SUPI type (such as SUPI Type), a home network identifier (Home Network Identifier) of a terminal device, a key identifier k1, and a cipher, for example: SUCI = {SUPI Type || Home Network Identifier || Key Identifier k1 || cipher}. Alternatively, SUCI can be a SUPI type, a home network identifier of a terminal device, a routing indicator, a key identifier k1, and a cipher, for example: SUCI = {SUPI type || Home Network Identifier || Routing Indicator || Key Identifier k1 || cipher || MAC}. Alternatively, SUCI can be a SUPI type, a home network identifier of a terminal device, a key identifier k1, a cipher, and a MAC, for example: SUCI = {SUPI type || Home Network Identifier || Key Identifier k1 || cipher || MAC}. Alternatively, the SUCI can be a concatenation of the SUPI type, the terminal device's home network identifier, the key identifier k1, the first nonce, the ciphertext, and the MAC, for example: SUCI = {SUPI type||Home Network Identifier||Key Identifier k1||nonce||cipher||MAC}. Due to limited space, possible construction / generation methods of the SUCI are not listed here. The symbol "||" represents the "concatenation" operation and is not further described below. In one possible implementation, the first nonce can be carried in the Home Network Public Key ID field of the SUCI.
[0137] In one possible implementation, a key identifier in an embodiment of the present application can index one or more preconfigured keys. It is understood that if a key identifier can index multiple preconfigured keys, then during the subsequent decryption process of the second network element (such as ARPF / UDM), the multiple keys indexed by the key identifier can be used to decrypt the ciphertext respectively, that is, the second network element may try multiple times before decryption is successful.
[0138] In one possible implementation, before step S102, the home network identifier and at least one key identifier of the terminal device may be pre-configured. The at least one key identifier includes a key identifier k1 (used to index the first key). Exemplarily, the home network identifier and at least one key identifier of the terminal device may be pre-set in the terminal device by the manufacturer, producer, seller or operator of the terminal device. Before executing step S102, the terminal device may first determine the key identifier k1 from at least one pre-set key identifier, and then determine the first key based on the key identifier k1. Exemplarily, one or more keys (including the first key) corresponding to (or indexed by) the key identifier k1 may be pre-defined by a standard protocol. Furthermore, exemplarily, one or more keys (including the first key) corresponding to (or indexed by) the key identifier k1 may also be pre-set in the terminal device. This is not limited in the embodiments of the present application.
[0139] In another possible implementation, the home network identifier of the terminal device may be pre-set in the terminal device by the manufacturer, seller, or operator of the terminal device. The key identifier k1 and the first key may be pre-configured by the AF / NEF for one or more terminal devices (such as IoT devices). For example, see Figure 5, which is a flowchart of a key configuration method provided in an embodiment of the present application. As shown in Figure 5, the key configuration method includes but is not limited to steps S1 to S4.
[0140] S1. The AF / NEF sends a key generation request to a second network element (such as an ARPF / UDM). The key generation request includes a key identifier k1.
[0141] In a possible implementation, the key generation request further includes one or more home network identifiers. The one or more home network identifiers can be used to generate one or more keys in combination with the key identifier k1.
[0142] S2. The second network element (such as ARPF / UDM) generates one or more keys based on the key identifier k1 in the key generation request, where the one or more keys include the first key.
[0143] In one possible implementation, after obtaining the one or more keys (including the first key), the second network element (e.g., ARPF / UDM) may store the key identifier k1 in association with the one or more keys. In other words, the second network element associates the one or more keys (including the first key) with the key identifier k1, so that the first key can be subsequently indexed based on the key identifier k1.
[0144] In one possible implementation, if the key generation request includes one or more home network identifiers, the second network element (such as ARPF / UDM) can generate one or more keys (including the first key) based on the key identifier k1 and the one or more home network identifiers. Accordingly, the second network element (such as ARPF / UDM) obtains the one or more keys and can store the key identifier k1, the one or more home network identifiers, and the one or more keys accordingly. In other words, the second network element establishes an association between the one or more keys (including the first key), the key identifier k1, and the one or more home network identifiers, so as to facilitate subsequent indexing to the first key based on the key identifier k1 and / or the home network identifier.
[0145] S3: The second network element (e.g., ARPF / UDM) sends a key generation response to the AF / NEF, which includes the one or more keys. Exemplarily, the AF / NEF receives and stores the one or more keys. The AF / NEF may also record the correspondence between at least two of the following: key identifier k1, the one or more keys, and one or more home network identifiers.
[0146] S4. The AF / NEF sends a third message to one or more terminal devices (such as IoT devices). The third message includes the key identifier k1 and the first key.
[0147] In one possible implementation, the third message includes a key identifier k1 and one or more keys, including a first key. Taking a terminal device as an example, after receiving the one or more keys, the terminal device can select one of the keys (referred to as the first key) for encryption. It is understood that the key configuration method shown in FIG5 can be executed before step S102. Exemplarily, the key configuration method shown in FIG5 can be performed before step S101, or when the device is initialized, or when the device is produced, and the embodiment of the present application does not impose any restrictions.
[0148] S104: The terminal device (e.g., IoT device) sends a second message to the first network element (e.g., AMF / TMF), where the second message includes the SUCI. The SUCI can be used to protect the identity of the terminal device (e.g., IoT device).
[0149] Correspondingly, the first network element (such as AMF / TMF) receives the second message.
[0150] In one possible implementation, the second message may include the SUCI. Exemplarily, the second message also includes the first nonce. In other words, the first nonce may be explicitly or implicitly carried in the second message. For example, if the SUCI does not carry the first nonce, the second message may explicitly carry the first nonce, for example, by including the first nonce as an information element in the second message. If the SUCI carries the first nonce, this indicates that the first nonce is implicitly carried in the second message. Of course, if the SUCI carries the first nonce, the second message may also explicitly carry the first nonce. This embodiment of the present application is not limited to this.
[0151] Exemplarily, the second message may be a registration request or a response message to a service request, such as a response message sent by the UE in response to a service request from the network side. The registration request may be used for registering a terminal device when it first accesses the network.
[0152] S105: The first network element (e.g., AMF / TMF) sends an authentication request to the second network element (e.g., ARPF / UDM), where the authentication request includes the SUCI. The second network element is determined based on the home network identifier of the terminal device in the SUCI.
[0153] Correspondingly, the second network element (such as ARPF / UDM) receives the authentication request.
[0154] In one possible implementation, after receiving the second message, the first network element (such as AMF / TMF) may split the SUCI in the second message to obtain the home network identifier of the terminal device. The first network element (such as AMF / TMF) may determine the second network element (such as ARPF / UDM) based on the home network identifier of the terminal device, and may send an authentication request to the second network element (such as ARPF / UDM). Exemplarily, the first network element (such as AMF / TMF) may send an authentication request to the second network element (such as ARPF / UDM) via the AUSF. The authentication request may include the SUCI. It is understood that the AUSF is located in the home network and can be determined based on the home network identifier of the terminal device.
[0155] In one possible implementation, after receiving the second message, the first network element (such as the AMF / TMF) may verify whether the first nonce included in the second message is valid. Exemplarily, the first network element may decompose the SUCI in the second message to obtain the home network identifier of the terminal device. If the first nonce is implicitly carried in the second message, decomposing the SUCI may also obtain the first nonce. If the first nonce is explicitly carried in the second message, the first nonce may be directly obtained from the second message. Exemplarily, there are various ways for the first network element to verify whether the first nonce included in the second message is valid. For example, the first network element may start a timer for the first nonce when sending it. When the first network element receives the second message, it may check whether the timer has expired. If the timer has expired, the first nonce is invalid. If the timer has not expired, the first nonce is valid. Alternatively, when the timer times out, the first random number (nonce) stored in the first network element is deleted. When the first network element receives the second message, it checks whether the first random number exists in the local storage. If the first random number does not exist in the local storage of the first network element, it means that the first random number is invalid. If the first random number exists in the local storage of the first network element, it means that the first random number is valid. For another example, if the first random number included in the second message is not the random number most recently sent by the first network element, it means that the first random number is invalid; if the first random number included in the second message is the random number most recently sent by the first network element, it means that the first random number is valid. Alternatively, if the first random number included in the second message is not generated by the first network element, it means that the first random number is invalid; if the first random number included in the second message is generated by the first network element, it means that the first random number is valid.
[0156] In one possible implementation, when the first random number included in the second message is valid, the first network element (such as AMF / TMF) can determine the second network element (such as ARPF / UDM) based on the home network identifier of the terminal device, and can send an authentication request to the second network element (such as ARPF / UDM). Exemplarily, the first network element (such as AMF / TMF) can send an authentication request to the second network element (such as ARPF / UDM) through AUSF. The authentication request may include the SUCI. It can be understood that the AUSF is located in the home network and can be determined based on the home network identifier of the terminal device. When the first random number included in the second message is invalid, the first network element (such as AMF / TMF) can send a response message to the terminal device, and the response message can be used to indicate the result of the failure of the terminal device authentication process. Exemplarily, the response message may also carry a failure cause value indication, for example: the first random number is invalid or expired.
[0157] In one possible implementation, the authentication request may further include one or more of the following: indication information, or the first nonce. The indication information may be used to indicate that the SUCI is an identifier of a low-power device, a low-computing device, or an IoT device. Exemplarily, the first network element may determine whether to include the indication information in the authentication request based on a specific field in the SUCI (e.g., the SUPI Type field). For example, if the SUPI Type field in the SUCI indicates that the SUPI type is a specific type, and that the specific type corresponds to a low-power device, a low-computing device, or an IoT device, the first network element may include the indication information in the authentication request. Furthermore, exemplarily, if the first network element is a special network element such as a TMF, the first network element may include the indication information in the authentication request. The first nonce may be explicitly or implicitly included in the authentication request. For example, if the SUCI does not include the first nonce, the first nonce may be explicitly included in the authentication request, for example, by including the first nonce as an information element in the authentication request. If the SUCI carries the first nonce, it indicates that the first nonce is implicitly carried in the authentication request. Of course, if the SUCI carries the first nonce, the authentication request may also explicitly carry the first nonce. This embodiment of the present application does not impose any restrictions on this.
[0158] S106 , the second network element (such as ARPF / UDM) decrypts the ciphertext in the SUCI using the first key corresponding to the key identifier k1 to obtain the serial number of the terminal device.
[0159] S107: The second network element (such as ARPF / UDM) determines the SUPI of the terminal device based on the serial number of the terminal device. The SUPI can be used for AKA authentication of the terminal device.
[0160] In one possible implementation, after receiving the authentication request, the second network element (e.g., ARPF / UDM) may split the SUCI in the authentication request to obtain the key identifier k1 and the ciphertext. The key identifier k1 may be used to index the first key. Exemplarily, the correspondence between the key identifier k1 and the first key may be preconfigured at the second network element.
[0161] In one possible implementation, the key identifier k1 only indexes the first key. The second network element (e.g., ARPF / UDM) can use the first key to decrypt the ciphertext and obtain the serial number of the terminal device. In other words, after decrypting the ciphertext using the first key, the second network element retains the serial number of the terminal device and ignores other content (if any), such as the first random number (nonce) and / or the second random number (RAND). It can be understood that decrypting the ciphertext using the first key is the inverse of generating the ciphertext. For example, the second network element can use the first random number (which can be obtained through the authentication request) and / or the first key as input and execute a preconfigured second key generation algorithm to generate a temporary key. The second network element then uses the temporary key to decrypt the ciphertext and obtain the serial number of the terminal device. The second key generation algorithm is identical to the first key generation algorithm, and the inputs to the second key generation algorithm are also identical to the first key generation algorithm. Therefore, the temporary key generated by the terminal device is also the same as the temporary key generated by the second network element.
[0162] In another possible implementation, key identifier k1 can index multiple keys, including the first key. The second network element (such as ARPF / UDM) can use the multiple keys indexed by key identifier k1 to decrypt the ciphertext. The key that can successfully decrypt is the first key. In other words, the second network element can make multiple decryption attempts and obtain the serial number of the terminal device if the decryption is successful.
[0163] In one possible implementation, after receiving the authentication request, the second network element (e.g., ARPF / UDM) may first determine the decryption method (whether symmetric key decryption is used), and then decrypt the cipher in the SUCI based on the determined decryption method. For example, if the authentication request carries indication information, and the indication information indicates that the SUCI is an identifier of a low-power device, a low-computing device, or an IoT device, the second network element may determine that the decryption method is symmetric key decryption. Alternatively, if the authentication request does not carry indication information, the second network element may determine the decryption method based on a specific field in the SUCI (e.g., the SUPI Type field). If the SUPI Type field in the SUCI indicates that the SUPI type is a specific type, and the specific type corresponds to a low-power device, a low-computing device, or an IoT device, the second network element may determine that the decryption method is symmetric key decryption. Symmetric key decryption may involve decrypting the cipher in the SUCI using one or more keys (including the first key) indexed by the key identifier k1.
[0164] In one possible implementation, if the SUCI in the authentication request carries a MAC (Message Authentication Code), before decrypting the cipher, the second network element may use the MAC to perform an integrity check on the SUCI or other content in the SUCI other than the MAC (e.g., SUPI type, home network identifier of the terminal device, key identifier k1, or a first random number). If the integrity check passes, the cipher is decrypted using one or more keys (including the first key) indexed by key identifier k1. If the integrity check fails, the second network element (e.g., ARPF / UDM) may send an authentication response to the first network element (e.g., AMF / TMF). The authentication response carries information indicating authentication failure and, optionally, a reason for the authentication failure (e.g., integrity check failure).
[0165] In one possible implementation, after obtaining the serial number of the terminal device, the second network element may reassemble and concatenate the serial number (Serial Number) of the terminal device, the plaintext in the SUCI, and / or other parameters (which may refer to content other than the plaintext in the SUCI) to obtain the SUPI of the terminal device. Exemplarily, the plaintext in the SUCI may refer to content other than the ciphertext (and MAC) in the SUCI. For example, the plaintext in the SUCI includes one or more of the following: SUPI type, the home network identifier of the terminal device, a routing indicator, a key identifier k1, or the first random number (nonce). For example: SUPI = {SUPI Type || Home Network Identifier || Key Identifier k1 || Serial Number}. This embodiment of the present application does not limit the concatenation order of the plaintext contents in the SUCI, nor does it limit the concatenation order of the plaintext contents and the serial number of the terminal device. Exemplarily, the other parameters include a mobile country code (MCC) and / or a mobile network code (MNC). For example: SUPI = {MCC||MNC||Serial Number}, where Serial Number can be MSIN. The present embodiment does not limit the splicing order.
[0166] In one possible implementation, after the second network element obtains the SUPI, it can determine whether to execute the authentication and key agreement (AKA) mechanism based on the local policy and / or the indication information in the authentication request. Exemplarily, the indication information in the authentication request can also indicate whether to execute the AKA mechanism. Alternatively, the local policy indicates a specific device type to start / trigger / execute the AKA mechanism; then when the type of the terminal device is determined to be the specific device type based on the SUPI, the second network element can determine to execute the AKA mechanism. If it is determined to execute the AKA mechanism, the second network element can generate an authentication vector based on the master key corresponding to the above-mentioned SUPI and execute the corresponding AKA mechanism. It can be understood that in the AKA mechanism, the SUPI corresponds to a master key, and the encryption key (CK) and integrity key (IK) are deduced based on the master key for subsequent communication security. Among them, the specific implementation of the AKA mechanism can refer to the existing technology, such as EAP-AKA' or 5G-AKA, etc., which will not be described in detail in the embodiments of this application. EAP is an extensible authentication protocol.
[0167] In one possible implementation, before generating an authentication vector based on the master key corresponding to the SUPI, the second network element may determine whether the SUPI is valid. Exemplarily, the second network element may determine whether the SUPI of the terminal device is valid based on a preconfiguration (e.g., a list of relationships between preconfigured key identifiers and SUPIs). For example, if the SUPI corresponding to the key identifier k1 in the relationship list is the same as the SUPI of the terminal device, then the SUPI of the terminal device is valid. If the SUPI is valid, the second network element generates an authentication vector based on the master key corresponding to the SUPI and performs subsequent operations.
[0168] In one possible implementation, the second network element (e.g., ARPF / UDM) may send an authentication response to the first network element (e.g., AMF / TMF) to indicate the identity authentication result of the terminal device. For example, if the second message sent in step S104 is a registration request, the first network element (e.g., AMF / TMF) may send a registration response to the terminal device to indicate the registration result of the terminal device.
[0169] The embodiment of the present application utilizes symmetric keys for encryption and decryption, without the need for a public key encryption algorithm (such as an elliptic curve integrated encryption scheme (ECIES)) and / or a public key generation algorithm, which can reduce the power consumption of terminal devices and meet the power consumption requirements of low-power or low-computing power devices. The embodiment of the present application also adds a random number (nonce) to the ciphertext, which can increase the freshness of the ciphertext and improve the security of low-power or low-computing power devices. Therefore, the embodiment of the present application can protect the permanent identification of low-power or low-computing power devices while meeting the low-power consumption requirements and improve the security of low-power or low-computing power devices.
[0170] Referring to Figure 6, which is another flow diagram of a communication method provided in an embodiment of the present application, the method mainly introduces that the terminal device uses a symmetric key to encrypt its own serial number (Serial Number), the AMF / TMF uses the symmetric key to decrypt it, and determines the SUPI based on the decrypted information.
[0171] As shown in FIG6 , the communication method includes but is not limited to the following steps:
[0172] S201, the application function (AF) sends a service request to the first network element (such as AMF / TMF), the service request includes a service indication or terminal device identification information, the service request also includes a key identification k1, the service indication or terminal device identification information is used to determine the terminal device.
[0173] Correspondingly, the first network element (such as AMF / TMF) receives the service request.
[0174] In one possible implementation, the application function (AF) sends a service request to the first network element (such as AMF / TMF), and the service request includes a service indication or terminal device identification information, and the service request also includes a key identifier k1. Exemplarily, the AF can send a service request to the first network element through the NEF. The service indication or terminal device identification information can be used to determine one or more terminal devices. Exemplarily, the service request can be used to request certain terminal devices to perform certain operations, for example: the service request is used to request terminal devices whose identification is within a certain range to perform inventory or temperature measurement operations. The key identifier k1 can be used to determine the key factor for deducing the first key, or the first key; the specific determination method is described below. Exemplarily, the service request may also include a key factor for deducing the first key. The key factor in the embodiment of the present application may include all or part of the parameters / information for deducing / generating the first key. For example, the key factor may be a key element for deducing the first key, and the first key K_SUCI may be generated by inputting the key factor and the encryption algorithm identifier Algorithm ID into a key derivation function (KDF), that is, K_SUCI=KDF(key element, Algorithm ID).
[0175] In one possible implementation, after receiving the service request, the first network element (such as AMF / TMF) can generate a first random number (nonce), and can determine one or more terminal devices based on the service request. The specific determination method can refer to the relevant description in the embodiment shown in Figure 3 above, which will not be repeated here. Exemplarily, the first network element can also store the first random number and the key identifier k1 in the service request. Furthermore, if the service request carries a key factor for deducing the first key, the first network element can also store the key factor for subsequent use. The first network element (such as AMF / TMF) can send the generated first random number (nonce) to the access network device (such as a base station) associated with the one or more terminal devices, so that the access network device (such as a base station) can send the first random number (nonce) to the one or more terminal devices (such as an IoT device) determined above. For the sake of clarity, the embodiments of this application are described below using a terminal device as an example.
[0176] S202: An access network device (such as a base station) sends a first message to a terminal device (such as an IoT device), where the first message includes a first random number (nonce).
[0177] Correspondingly, the terminal device (such as an IoT device) receives the first message.
[0178] S203, the terminal device (such as an IoT device) generates a ciphertext based on the first random number, the serial number of the terminal device, and the first key.
[0179] S204: The terminal device (such as an IoT device) generates a SUCI based on the key identifier k1 and the above ciphertext. The key identifier k1 is used to index the first key.
[0180] In one possible implementation, the implementation of steps S202 to S204 in the embodiment of the present application can refer to the implementation of steps S101 to S103 in the embodiment shown in Figure 3 above, and will not be repeated here.
[0181] In a possible implementation, the SUCI generated by the terminal device does not carry the first random number (nonce).
[0182] S205: The terminal device (e.g., IoT device) sends a second message to the first network element (e.g., AMF / TMF), where the second message includes the SUCI. The SUCI can be used to protect the identity of the terminal device (e.g., IoT device).
[0183] Correspondingly, the first network element (such as AMF / TMF) receives the second message.
[0184] In one possible implementation, the second message may include the SUCI. Exemplarily, the second message may be a registration request or a response message to a service request, such as a response message sent by the UE in response to a previous service request from the network. The registration request may be used for registering a terminal device upon initial access.
[0185] S206. The first network element (such as AMF / TMF) obtains a key factor for deducing the first key from the key storage network element based on the key identifier k1.
[0186] S207. The first network element (such as AMF / TMF) determines the first key based on the key factor and the first random number (nonce).
[0187] S208: The first network element (such as AMF / TMF) decrypts the ciphertext in the SUCI using the first key to obtain the serial number of the terminal device.
[0188] In one possible implementation, after the first network element (such as AMF / TMF) receives the above-mentioned second message, it can determine one or more valid random numbers based on its own internal policy (such as whether the timer of the random number has expired). Exemplarily, each time the first network element generates / sends a random number, a timer can be set for the random number. The first network element maintains a random number cache list, as shown in Table 2 below, where one random number corresponds to one timer. For example: when the first network element receives the above-mentioned second message, it obtains the random numbers (there may be one or more) in the random number cache list whose timers have not expired, and these random numbers are valid random numbers. For another example: when the timer of a random number in the random number cache list expires, the first network element can delete the random number from the random number cache list. Then when the first network element receives the above-mentioned second message, the random numbers currently existing in the random number cache list (there may be one or more) are valid random numbers.
[0189] Table 2
[0190] It is understood that if there are multiple valid random numbers, multiple decryption attempts can be made during the subsequent decryption process. In the embodiment of the present application, the first random number (nonce) is not carried in the second message, which can save air interface resources and is beneficial to low power / low computing power devices.
[0191] In one possible implementation, after receiving the second message, the first network element (such as the AMF / TMF) may split the SUCI in the second message to obtain the key identifier k1 and the ciphertext. Exemplarily, a correspondence between the key identifier and the key factor may be preconfigured / prestored in the key storage network element. The first network element may obtain the key factor for deriving the first key from the key storage network element based on the key identifier k1. It is understood that the first network element may split the SUCI before determining a valid random number, after determining a valid random number, or simultaneously. The embodiments of the present application do not limit the order of execution. It is understood that if the service request includes the key factor for deriving the first key, the first network element may not need to obtain it from the key storage network element.
[0192] Furthermore, the first network element may determine one or more keys based on the key factor and the one or more valid random numbers (including the first random number) determined above. The one or more keys include the first key. It will be appreciated that if only one valid random number (i.e., the first random number) is determined above, the first network element may determine / generate the first key based on the key factor and the first random number. Exemplarily, the first network element may determine one or more keys based on the key factor, the one or more valid random numbers (including the first random number) determined above, and the key identifier k1 (which may be obtained by splitting the SUCI or may be carried in the service request). The one or more keys include the first key.
[0193] In one possible implementation, the first network element can decrypt the above-mentioned cipher based on the above-mentioned one or more keys (including the first key), and the key that can be successfully decrypted is the first key. In other words, the first network element can make multiple decryption attempts, and obtain the serial number of the terminal device when the decryption is successful. It can be understood that when the first key is determined, the first network element uses the first key to decrypt the above-mentioned cipher to obtain the serial number of the terminal device. In other words, after the first network element decrypts the cipher using the first key, it retains the serial number of the terminal device and ignores other content (if any), such as the above-mentioned first random number (nonce) and / or the above-mentioned second random number (RAND). It can be understood that the method of decrypting the cipher using a key is the inverse operation of generating the cipher.
[0194] In one possible implementation, before step S208, the first network element may use the MAC (message authentication code) in the SUCI to perform an integrity check on the SUCI or other content in the SUCI other than the MAC (e.g., the SUPI type, the home network identifier of the terminal device, or the key identifier k1). If the integrity check passes, step S208 is performed again. If the integrity check fails, the first network element (e.g., the AMF / TMF) may return a response to the terminal device indicating that the registration of the terminal device has failed. The response may also include the reason for the registration failure, such as failure of the integrity check.
[0195] S209: The first network element (such as AMF / TMF) determines the SUPI of the terminal device based on the serial number of the terminal device. The SUPI can be used for AKA authentication of the terminal device.
[0196] In a possible implementation, the implementation of step S209 in the embodiment of the present application can refer to the implementation of step S107 in the embodiment shown in Figure 3 above, and will not be repeated here.
[0197] In one possible implementation, after obtaining the SUPI, the first network element (e.g., AMF / TMF) may send a fourth message to the second network element (e.g., ARPF / UDM). This fourth message may be used to trigger the AKA mechanism. The fourth message includes the SUPI of the terminal device. Exemplarily, the fourth message may be an authentication request (e.g., Nausf_UEauthentication_authenticate).
[0198] In one possible implementation, the second network element (e.g., ARPF / UDM) may send an authentication response to the first network element (e.g., AMF / TMF) to indicate the identity authentication result of the terminal device. After receiving the authentication response, the first network element (e.g., AMF / TMF) may send a registration response to the terminal device to indicate the registration result of the terminal device.
[0199] In one possible implementation, after the first network element (such as AMF / TMF) obtains the SUPI, the local policy and / or the service indication in the service request determine whether to execute the authentication and key agreement (AKA) mechanism. Exemplarily, if the service indication in the above service request indicates that the IoT device is to be operated, the first network element may determine to execute the authentication and key agreement (AKA) mechanism. Alternatively, the local policy indicates that the IoT devices of certain IoT ID segments execute the authentication and key agreement (AKA) mechanism, then when the service indication in the service request indicates that the IoT devices of these IoT ID segments are to be operated, the first network element may determine to execute the authentication and key agreement (AKA) mechanism. If it is determined to execute the AKA mechanism, the first network element may send a fourth message to the second network element to trigger the AKA mechanism.
[0200] In the embodiment of the present application, decryption is performed at the first network element and the SUPI is determined based on the decrypted information, which can better reuse subsequent authentication processes, such as the AKA mechanism; and there is no need to change the behavior of the second network element.
[0201] In one possible implementation, before sending the fourth message to the second network element, the first network element may determine whether the SUPI is valid. Exemplarily, the first network element may determine whether the SUPI of the terminal device is valid based on a preconfiguration (e.g., a preconfigured relationship list between key identifiers and SUPIs). For example, if the SUPI corresponding to the key identifier k1 in the relationship list is the same as the SUPI of the terminal device, then the SUPI of the terminal device is valid. If the SUPI is valid, the first network element may send a fourth message to the second network element to trigger the authentication and key agreement (AKA) mechanism.
[0202] The embodiment of the present application utilizes symmetric keys for encryption and decryption, without the need for a public key encryption algorithm (such as an elliptic curve integrated encryption scheme (ECIES)) and / or a public key generation algorithm, which can reduce the power consumption of terminal devices and meet the power consumption requirements of low-power or low-computing power devices. The embodiment of the present application also adds a random number (nonce) to the ciphertext, which can increase the freshness of the ciphertext and improve the security of low-power or low-computing power devices. Therefore, the embodiment of the present application can protect the permanent identification of low-power or low-computing power devices while meeting the low-power consumption requirements and improve the security of low-power or low-computing power devices.
[0203] The above content elaborates on the method of the present application in detail. In order to facilitate better implementation of the above scheme of the embodiment of the present application, the embodiment of the present application also provides corresponding devices or equipment.
[0204] The embodiment of the present application can divide the terminal device, the first network element, and the second network element of the present application into functional modules according to the above-mentioned method example, and also divide the functional modules of the above-mentioned network elements according to the above-mentioned method example. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation. The communication device of the embodiment of the present application will be described in detail below with reference to Figures 7 to 9.
[0205] Referring to Figure 7 , Figure 7 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. As shown in Figure 7 , the communication device includes a transceiver unit 10 and a processing unit 20. The transceiver unit 10 can implement corresponding communication functions, and the processing unit 20 is used for data processing. For example, the transceiver unit 10 can also be referred to as a communication interface or a communication unit.
[0206] In some embodiments of the present application, the communication device may be the terminal device shown above. That is, the communication device shown in FIG7 may be used to execute the steps or functions performed by the terminal device in the above method embodiments. For example, the communication device may be a terminal device or a chip or functional module configured in the terminal device, etc., which is not limited in the present embodiment. The transceiver unit 10 is used to execute the operations related to terminal device transceiver reception and transmission in the above method embodiments, and the processing unit 20 is used to execute the operations related to terminal device processing in the above method embodiments.
[0207] Exemplarily, the transceiver unit 10 is used to receive a first message, where the first message includes a first random number; the transceiver unit 10 is also used to send a second message, where the second message includes a SUCI, where the SUCI is generated based on a key identifier and a ciphertext, where the key identifier is used to index the first key, and where the ciphertext is generated based on the first random number, the serial number of the terminal device, and the first key.
[0208] Exemplarily, the processing unit 20 is configured to generate a ciphertext based on the first random number, the serial number of the terminal device, and the first key.
[0209] Exemplarily, the processing unit 20 is further configured to generate a SUCI based on the ciphertext and the key identifier.
[0210] Exemplarily, the processing unit 20 is further configured to generate various messages, such as the second message, to be sent by the transceiver unit 10. The processing unit 20 is further configured to control the transceiver unit 10 to send or receive various messages.
[0211] Exemplarily, the second message includes the first random number.
[0212] Exemplarily, the SUCI is further generated based on one or more of the following: the type of SUPI, the home network identifier of the terminal device, the first random number, or a message authentication code.
[0213] Exemplarily, the ciphertext is also generated based on a second random number.
[0214] Exemplarily, the processing unit 20 is specifically configured to encrypt the concatenated serial number of the terminal device and the second random number using a second key to obtain a ciphertext. The second key is generated based on the first key and the first random number.
[0215] Exemplarily, the processing unit 20 is specifically configured to encrypt the concatenated serial number of the terminal device, the second random number, and the first random number using the first key to obtain a ciphertext.
[0216] Exemplarily, the first message is a selection message, which is used to trigger an access process of the terminal device.
[0217] Exemplarily, the first message is a random access response or a radio resource control connection establishment message in an access process; or, the first message is a NAS message.
[0218] Exemplarily, the transceiver unit 10 is further configured to receive a third message from the AF, where the third message includes the key identifier and the first key.
[0219] Exemplarily, the serial number is a Mobile Subscriber Identification Number (MSIN).
[0220] In the embodiment of the present application, for specific descriptions of the first message, the second message, the ciphertext, the SUCI, the third message, and each network element, etc., please refer to the above method embodiment and will not be described in detail here.
[0221] It is understood that the specific descriptions of the transceiver unit and the processing unit shown in the embodiments of the present application are merely examples. For the specific functions or execution steps of the transceiver unit and the processing unit, reference can be made to the above-mentioned method embodiments, which will not be described in detail here. In addition, the technical effects of the embodiments of the present application refer to the technical effects of the above-mentioned method embodiments, and for the sake of brevity, they will not be repeated here.
[0222] Reusing Figure 7, in some other embodiments of the present application, the communication device may be the first network element shown above. That is, the communication device shown in Figure 7 may be used to execute the steps or functions performed by the first network element in the above method embodiment. Exemplarily, the communication device may be the first network element or a chip or functional module configured in the first network element, etc., which is not limited in the embodiments of the present application. The transceiver unit 10 is used to execute the operations related to the first network element's transceiver in the above method embodiment, and the processing unit 20 is used to execute the operations related to the first network element's processing in the above method embodiment.
[0223] Exemplarily, the transceiver unit 10 is configured to send a first random number to the terminal device through the access network device, where the first random number is used to generate ciphertext. The transceiver unit 10 is further configured to receive a second message from the terminal device, where the second message includes a SUCI, where the SUCI is generated based on a key identifier and the ciphertext, where the key identifier is used to index a first key, and where the first key is used to decrypt the ciphertext to obtain a serial number of the terminal device.
[0224] Exemplarily, the processing unit 20 is configured to generate a first random number. The processing unit 20 may also be configured to control the transceiver unit 10 to receive or send various messages.
[0225] Exemplarily, the transceiver unit 10 is further configured to receive a service request from the AF, where the service request includes a service indication or terminal device identification information, and the service indication or terminal device identification information is used to determine the terminal device.
[0226] Exemplarily, the second message includes the first random number.
[0227] Exemplarily, the SUCI is further generated based on one or more of the following: the type of SUPI, the home network identifier of the terminal device, the first random number, or a message authentication code.
[0228] Exemplarily, the transceiver unit 10 is further configured to, if the first random number included in the second message is valid, send an authentication request to a second network element, the authentication request including the SUCI, wherein the second network element determines the home network identifier of the terminal device based on the SUCI.
[0229] Exemplarily, the authentication request further includes one or more of the following: indication information, or the first random number. The indication information is used to indicate that the SUCI is an identifier of a low-power device or a low-computing-power device.
[0230] Exemplarily, the above service request also includes a key identifier.
[0231] Exemplarily, the processing unit 20 is further used to obtain a key factor for deriving the first key from the key storage network element based on the key identifier; the processing unit 20 is further used to determine the first key based on the key factor and the first random number.
[0232] Exemplarily, the processing unit 20 is further specifically used to: determine one or more valid random numbers, and determine one or more keys based on the key factor and the one or more random numbers; decrypt the ciphertext based on the one or more keys, and determine the key that successfully decrypts the ciphertext as the first key.
[0233] Exemplarily, the processing unit 20 is further configured to decrypt the ciphertext using the first key to obtain the serial number of the terminal device; the processing unit 20 is further configured to determine the SUPI of the terminal device based on the serial number of the terminal device.
[0234] Exemplarily, the transceiver unit 10 is further configured to send a fourth message to the second network element, where the fourth message includes the SUPI, and the fourth message is used to trigger an AKA mechanism.
[0235] Exemplarily, the processing unit 20 is further configured to determine, based on a preconfigured correspondence between the key identifier and the SUPI, that the SUPI is valid; and the transceiver unit 10 is further specifically configured to send a fourth message to the second network element if the SUPI is valid.
[0236] Exemplarily, the serial number is a Mobile Subscriber Identification Number (MSIN).
[0237] In the embodiment of the present application, for specific descriptions of the second message, ciphertext, SUCI, fourth message, SUPI, and each network element, etc., refer to the above method embodiment and will not be described in detail here.
[0238] It is understood that the specific descriptions of the transceiver unit and the processing unit shown in the embodiments of the present application are merely examples. For the specific functions or execution steps of the transceiver unit and the processing unit, reference can be made to the above-mentioned method embodiments, which will not be described in detail here. In addition, the technical effects of the embodiments of the present application refer to the technical effects of the above-mentioned method embodiments, and for the sake of brevity, they will not be repeated here.
[0239] Reusing Figure 7, in some other embodiments of the present application, the communication device may be the second network element shown above. That is, the communication device shown in Figure 7 may be used to execute the steps or functions performed by the second network element in the above method embodiment. Exemplarily, the communication device may be the second network element or a chip or functional module configured in the second network element, etc., which is not limited in the embodiments of the present application. The transceiver unit 10 is used to execute the operations related to the second network element's transceiver in the above method embodiment, and the processing unit 20 is used to execute the operations related to the second network element's processing in the above method embodiment.
[0240] Exemplarily, the transceiver unit 10 is configured to receive an authentication request from a first network element, where the authentication request includes a SUCI, where the SUCI is generated based on a key identifier and the ciphertext, where the key identifier is used to index a first key; the processing unit 20 is configured to decrypt the ciphertext using the first key to obtain a serial number of the terminal device; and the processing unit 20 is further configured to obtain a SUPI of the terminal device based on the serial number of the terminal device.
[0241] Exemplarily, the processing unit 20 is further configured to generate an authentication vector based on a master key corresponding to the SUPI, and execute an AKA mechanism.
[0242] Exemplarily, the processing unit 20 is further configured to determine that the SUPI is valid based on a preconfigured correspondence between the key identifier and the SUPI; and the processing unit 20 is further specifically configured to generate an authentication vector based on a master key corresponding to the SUPI if the SUPI is valid.
[0243] Exemplarily, the authentication request further includes one or more of the following: indication information, or the first random number. The indication information is used to indicate that the SUCI is an identifier of a low-power device or a low-computing-power device.
[0244] Exemplarily, the transceiver unit 10 is further used to receive a key generation request from the AF, which key generation request includes the key identifier; the processing unit 20 is further used to generate one or more keys based on the key identifier; the transceiver unit 10 is further used to send a key generation response to the AF, which key generation response includes the one or more keys, and the one or more keys include the first key.
[0245] Exemplarily, the key generation request further includes one or more home network identifiers, and the one or more home network identifiers are used to generate one or more keys in combination with the key identifier.
[0246] In the embodiment of the present application, for specific descriptions of the authentication request, SUCI, SUPI, key generation request, key generation response, and each network element, please refer to the above method embodiment (such as Figure 3), and will not be described in detail here.
[0247] It is understood that the specific descriptions of the transceiver unit and the processing unit shown in the embodiment of the present application are only examples. For the specific functions or execution steps of the transceiver unit and the processing unit, reference can be made to the above-mentioned method embodiment (such as Figure 3), which will not be described in detail here. In addition, the technical effects of the embodiment of the present application refer to the technical effects in the above-mentioned method embodiment (such as Figure 3), and for the sake of brevity, they will not be repeated here.
[0248] The above describes the communication device according to the embodiment of the present application. The following describes possible product forms of the communication device. It should be understood that any product having the functions of the communication device described in FIG. 7 falls within the scope of protection of the embodiment of the present application. It should also be understood that the following description is merely illustrative and does not limit the product forms of the communication device according to the embodiment of the present application to these examples.
[0249] In one possible implementation, in the communication device shown in FIG7 , the processing unit 20 may be one or more processors, and the transceiver unit 10 may be a transceiver. Alternatively, the transceiver unit 10 may be a transmitting unit and a receiving unit, wherein the transmitting unit may be a transmitter and the receiving unit may be a receiver, and the transmitting unit and receiving unit are integrated into a single device, such as a transceiver. In embodiments of the present application, the processor and transceiver may be coupled, and the connection method between the processor and transceiver is not limited in embodiments of the present application. During the execution of the above-described method, the process of sending information in the above-described method can be understood as the process of the processor outputting the above-described information. When outputting the above-described information, the processor outputs the above-described information to the transceiver for transmission by the transceiver. After being output by the processor, the above-described information may require further processing before reaching the transceiver. Similarly, the process of receiving information in the above-described method can be understood as the process of the processor receiving the above-described information. When the processor receives the input information, the transceiver receives the above-described information and inputs it into the processor. Furthermore, after the transceiver receives the above-described information, the above-described information may require further processing before being input into the processor.
[0250] Refer to Figure 8, which is another structural diagram of the communication device provided in an embodiment of the present application. As shown in Figure 8, the communication device provided in an embodiment of the present application can be used to implement the method described in any of the above method embodiments, and reference can be made to the description in the above method embodiments. The communication device can be the aforementioned terminal device, or the first network element, or the second network element, or the chip or circuit therein. Exemplarily, the communication device includes one or more processors 1001 and a transceiver 1002. The communication device may further include a memory 1003. In one implementation, the communication device also includes an input and output device (not shown in the figure).
[0251] Processor 1001 is primarily used to process communication protocols and communication data, control the entire communication device, execute software programs, and process software program data. Memory 1003 is primarily used to store software programs and data. Transceiver 1002 may include control circuitry and an antenna. The control circuitry is primarily used to convert baseband signals into radio frequency signals and process radio frequency signals. The antenna is primarily used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input / output devices, such as a touch screen, display, and keyboard, are primarily used to receive user input and output data to the user.
[0252] When the communication device is powered on, the processor 1001 can read the software program in the memory 1003, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be sent wirelessly, the processor 1001 performs baseband processing on the data to be sent and outputs the baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and then transmits the radio frequency signal to the outside in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the radio frequency circuit receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor 1001. The processor 1001 converts the baseband signal into data and processes the data.
[0253] In another implementation, the RF circuit and antenna may be provided independently of the processor performing baseband processing. For example, in a distributed scenario, the RF circuit and antenna may be remotely arranged independent of the communication device.
[0254] The processor 1001 , the transceiver 1002 , and the memory 1003 may be connected via a communication bus.
[0255] Exemplarily, when the communication device is used to execute the steps, methods, or functions performed by the terminal device in the first embodiment of the above-mentioned method (such as Figure 3), the processor 1001 can be used to execute steps S102 and S103 in Figure 3, and / or for executing other processes of the technology described in this document; the transceiver 1002 can be used to execute step S104 in Figure 3, and / or for other processes of the technology described in this document.
[0256] Exemplarily, when the communication device is used to execute the steps, methods, or functions performed by the first network element in the first embodiment of the above-mentioned method (such as Figure 3), the processor 1001 can be used to generate a first random number and an authentication request, and / or to execute other processes of the technology described in this document; the transceiver 1002 can be used to execute step S105 in Figure 3, and / or to execute other processes of the technology described in this document.
[0257] Exemplarily, when the communication device is used to execute the steps, methods, or functions performed by the second network element in the first embodiment of the above-mentioned method (such as Figure 3), the processor 1001 can be used to execute steps S106 and S107 in Figure 3, and / or to execute other processes of the technology described in this document; the transceiver 1002 can be used to receive an authentication request, and / or other processes of the technology described in this document.
[0258] Exemplarily, when the communication device is used to execute the steps, methods, or functions performed by the access network device in the first embodiment of the above-mentioned method (such as Figure 3), the processor 1001 can be used to obtain a first message, and / or to execute other processes of the technology described in this document; the transceiver 1002 can be used to execute step S101 in Figure 3, and / or other processes of the technology described in this document.
[0259] Exemplarily, when the communication device is used to execute the steps, methods or functions performed by the terminal device in the second embodiment of the above-mentioned method (such as Figure 6), the processor 1001 can be used to execute steps S203 and S204 in Figure 6, and / or for executing other processes of the technology described in this document; the transceiver 1002 can be used to execute step S205 in Figure 6, and / or for other processes of the technology described in this document.
[0260] Exemplarily, when the communication device is used to execute the steps, methods, or functions performed by the first network element in the second embodiment of the above-mentioned method (such as Figure 6), the processor 1001 can be used to execute steps S206 to S209 in Figure 6, and / or used to execute other processes of the technology described in this document; the transceiver 1002 can be used to send a fourth message, and / or used for other processes of the technology described in this document.
[0261] Exemplarily, when the communication device is used to execute the steps, methods, or functions performed by the AF network element in the second embodiment of the above method (such as Figure 6), the processor 1001 can be used to generate a service request, and / or to execute other processes of the technology described in this document; the transceiver 1002 can be used to execute step S201 in Figure 6, and / or other processes of the technology described in this document.
[0262] Exemplarily, when the communication device is used to execute the steps, methods, or functions performed by the access network device in the second embodiment of the above-mentioned method (such as Figure 6), the processor 1001 can be used to obtain a first message, and / or to execute other processes of the technology described in this document; the transceiver 1002 can be used to execute step S202 in Figure 6, and / or to execute other processes of the technology described in this document.
[0263] In any of the above implementations, the processor 1001 may include a transceiver for implementing receiving and transmitting functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing the receiving and transmitting functions may be separate or integrated. The transceiver circuit, interface, or interface circuit may be used for reading and writing code / data, or the transceiver circuit, interface, or interface circuit may be used for transmitting or delivering signals.
[0264] In any of the above implementations, the processor 1001 may store instructions, which may be computer programs. The computer programs, when executed on the processor 1001, may cause the communication device to perform the methods described in the above method embodiments. The computer programs may be embedded in the processor 1001, in which case the processor 1001 may be implemented by hardware.
[0265] In one implementation, the communication device may include a circuit that can implement the functions of sending, receiving, or communicating in the aforementioned method embodiment. The processor and transceiver described in this application can be implemented in an integrated circuit (IC), an analog IC, a radio frequency integrated circuit (RFIC), a mixed signal IC, an application specific integrated circuit (ASIC), a printed circuit board (PCB), an electronic device, etc. The processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductor (CMOS), N-type metal oxide semiconductor (nMetal-oxide-semiconductor, NMOS), P-channel metal oxide semiconductor (positive channel metal oxide semiconductor, PMOS), bipolar junction transistor (bipolar junction transistor, BJT), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.
[0266] It is understood that the communication device shown in the embodiment of the present application may also have more components than those in Figure 8, and the embodiment of the present application is not limited to this. The methods performed by the processor and transceiver shown above are only examples. For the specific steps performed by the processor and transceiver, please refer to the description of the various method embodiments above.
[0267] In another possible implementation, in the communication device shown in Figure 7, the processing unit 20 can be one or more logic circuits, and the transceiver unit 10 can be an input / output interface, or a communication interface, or an interface circuit, or an interface, etc. Or the transceiver unit 10 can also be a sending unit and a receiving unit, the sending unit can be an output interface, and the receiving unit can be an input interface, and the sending unit and the receiving unit are integrated into one unit, such as an input / output interface. Referring to Figure 9, Figure 9 is another structural diagram of a communication device provided in an embodiment of the present application. As shown in Figure 9, the communication device shown in Figure 9 includes a logic circuit 901 and an interface 902. That is, the above-mentioned processing unit 20 can be implemented with a logic circuit 901, and the transceiver unit 10 can be implemented with an interface 902. Among them, the logic circuit 901 can be a chip, a processing circuit, an integrated circuit or a system on chip (SoC) chip, etc., and the interface 902 can be a communication interface, an input / output interface, a pin, etc. Exemplarily, Figure 9 is shown as an example of the above-mentioned communication device being a chip, and the chip includes a logic circuit 901 and an interface 902.
[0268] In the embodiment of the present application, the logic circuit and the interface may also be coupled to each other. The embodiment of the present application does not limit the specific connection method between the logic circuit and the interface.
[0269] Illustratively, when the communication device is used to execute the method, function, or step performed by the terminal device in the aforementioned method embodiment, interface 902 is configured to input a first message, where the first message includes a first random number. Interface 902 is also configured to output a second message, where the second message includes a SUCI, where the SUCI is generated based on a key identifier and ciphertext, where the key identifier is used to index the first key, and where the ciphertext is generated based on the first random number, the serial number of the terminal device, and the first key. Illustratively, logic circuit 901 is configured to generate the ciphertext and the SUCI.
[0270] Exemplarily, when the communication device is used to execute the method, function, or step performed by the first network element in the aforementioned method embodiment, the logic circuit 901 is used to generate a first random number; the interface 902 is used to output the first random number, and the first random number is used to generate a ciphertext; the interface 902 is also used to input a second message, and the second message includes a SUCI, and the SUCI is generated based on the key identifier and the ciphertext, and the key identifier is used to index a first key, and the first key is used to decrypt the ciphertext to obtain the serial number of the terminal device.
[0271] Exemplarily, when the communication device is used to execute the method, function, or step performed by the second network element in the aforementioned method embodiment, the interface 902 is used to input an authentication request, where the authentication request includes a SUCI, where the SUCI is generated based on a key identifier and a ciphertext, where the key identifier is used to index a first key; the logic circuit 901 is used to decrypt the ciphertext using the first key to obtain the serial number of the terminal device; the logic circuit 901 is also used to obtain the SUPI of the terminal device based on the serial number of the terminal device.
[0272] In the embodiment of the present application, for specific descriptions of the first message, the second message, the ciphertext, the SUCI, the SUPI, the authentication request, etc., please refer to the method embodiment shown above and will not be described in detail here.
[0273] It can be understood that the communication device shown in the embodiment of the present application can implement the method provided in the embodiment of the present application in the form of hardware, or can implement the method provided in the embodiment of the present application in the form of software, etc., and the embodiment of the present application is not limited to this.
[0274] For the specific implementation of the embodiment shown in FIG9 , reference may also be made to the above embodiments, which will not be described in detail here.
[0275] An embodiment of the present application also provides a communication system, which includes at least two of a terminal device, a first network element, and a second network element. At least two of the terminal device, the first network element, and the second network element can be used to execute the method in the aforementioned method embodiment.
[0276] In addition, the present application also provides a computer program, which is used to implement the operations and / or processing performed by the terminal device in the method provided by the present application.
[0277] The present application also provides a computer program, which is used to implement the operations and / or processing performed by the first network element in the method provided in the present application.
[0278] The present application also provides a computer program, which is used to implement the operations and / or processing performed by the second network element in the method provided in the present application.
[0279] The present application also provides a computer-readable storage medium, which stores computer code. When the computer code runs on a computer, the computer executes the operations and / or processing performed by the terminal device in the method provided by the present application.
[0280] The present application also provides a computer-readable storage medium, which stores computer code. When the computer code runs on a computer, it enables the computer to execute the operations and / or processing performed by the first network element in the method provided by the present application.
[0281] The present application also provides a computer-readable storage medium, which stores computer code. When the computer code runs on a computer, it enables the computer to execute the operations and / or processing performed by the second network element in the method provided by the present application.
[0282] The present application also provides a computer program product, which includes computer code or computer program. When the computer code or computer program is run on a computer, the operations and / or processing performed by the terminal device in the method provided by the present application are executed.
[0283] The present application also provides a computer program product, which includes computer code or computer program. When the computer code or computer program runs on a computer, the operations and / or processing performed by the first network element in the method provided by the present application are executed.
[0284] The present application also provides a computer program product, which includes computer code or computer program. When the computer code or computer program runs on a computer, the operations and / or processing performed by the second network element in the method provided by the present application are executed.
[0285] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or can be electrical, mechanical or other forms of connection.
[0286] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the technical effects of the solutions provided in the embodiments of the present application.
[0287] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0288] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a readable storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned readable storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and other media that can store program code.
[0289] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that: include: The terminal device receives a first message, where the first message includes a first random number; The terminal device sends a second message to the first network element, where the second message includes a subscription hidden identifier SUCI, where the SUCI is generated based on a key identifier and a ciphertext, where the key identifier is used to index a first key, and where the ciphertext is generated based on the first random number, the serial number of the terminal device, and the first key.
2. The method according to claim 1, characterized in that The second message includes the first random number.
3. The method according to claim 1 or 2, characterized in that: The SUCI is also generated based on one or more of the following: a type of a subscription permanent identifier SUPI, a home network identifier of the terminal device, the first random number, or a message authentication code.
4. The method according to any one of claims 1 to 3, characterized in that The ciphertext is also generated based on a second random number.
5. The method according to claim 4, characterized in that The ciphertext is obtained by encrypting the concatenated serial number of the terminal device and the second random number based on a second key, where the second key is generated based on the first key and the first random number; Alternatively, the ciphertext is obtained by encrypting the concatenated serial number of the terminal device, the second random number, and the first random number based on the first key.
6. The method according to any one of claims 1 to 5, characterized in that The first message is a system information broadcast SIB message, and the SIB message is used to trigger the access process of the terminal device.
7. The method according to any one of claims 1 to 5, characterized in that The first message is a random access response or a radio resource control connection establishment message in an access process; Alternatively, the first message is a non-access stratum NAS message.
8. The method according to any one of claims 1 to 7, characterized in that Before the terminal device receives the first message, the method further includes: The terminal device receives a third message from the application function AF, where the third message includes the key identifier and the first key.
9. The method according to any one of claims 1 to 8, characterized in that The terminal device is an Internet of Things device.
10. The method according to any one of claims 1 to 9, characterized in that The serial number is a mobile subscriber identification code.
11. A communication method, characterized in that: include: The first network element sends a first random number to the terminal device through the access network device, where the first random number is used to generate a ciphertext; The first network element receives a second message from the terminal device, where the second message includes a subscription hidden identifier SUCI, where the SUCI is generated based on a key identifier and the ciphertext, where the key identifier is used to index a first key, and where the first key is used to decrypt the ciphertext to obtain a serial number of the terminal device.
12. The method according to claim 9, characterized in that Before the first network element sends the first random number to the terminal device through the access network device, the method further includes: The first network element receives a service request from an application function AF, where the service request includes a service indication or terminal device identification information, and the service indication or terminal device identification information is used to determine the terminal device.
13. The method according to claim 11 or 12, characterized in that: The second message includes the first random number.
14. The method according to any one of claims 11 to 13, characterized in that The SUCI is also generated based on one or more of the following: a type of a subscription permanent identifier SUPI, a home network identifier of the terminal device, the first random number, or a message authentication code.
15. The method according to any one of claims 11 to 14, characterized in that After the first network element receives the second message from the terminal device, the method further includes: When the first random number included in the second message is valid, the first network element sends an authentication request to the second network element, where the authentication request includes the SUCI, and the second network element determines based on the home network identifier of the terminal device in the SUCI.
16. The method according to claim 15, characterized in that The authentication request further includes one or more of the following: indication information, or the first random number; The indication information is used to indicate that the SUCI is an identifier of a low-power consumption device or a low-computing power device.
17. The method according to claim 12, characterized in that The service request also includes a key identifier.
18. The method according to claim 17, characterized in that After the first network element receives the second message from the terminal device, the method further includes: The first network element obtains, based on the key identifier, a key factor for deriving the first key from a key storage network element; The first network element determines the first key based on the key factor and the first random number.
19. The method according to claim 18, characterized in that The first network element determines the first key based on the key factor and the first random number, including: The first network element determines one or more valid random numbers, and determines one or more keys based on the key factor and the one or more random numbers; The first network element decrypts the ciphertext based on the one or more keys, and determines the key that successfully decrypts the ciphertext as the first key.
20. The method according to any one of claims 11 to 14 or 17 to 19, characterized in that After the first network element receives the second message from the terminal device, the method further includes: The first network element decrypts the ciphertext using the first key to obtain the serial number of the terminal device, where the serial number is used to determine the subscription permanent identifier SUPI of the terminal device.
21. The method according to claim 20, characterized in that After the first network element decrypts the ciphertext using the first key to obtain the serial number of the terminal device, the method further includes: The first network element determines a subscription permanent identifier SUPI of the terminal device based on the serial number of the terminal device.
22. The method according to claim 21, characterized in that After the first network element determines the subscription permanent identifier SUPI of the terminal device based on the serial number of the terminal device, the method further includes: The first network element sends a fourth message to the second network element, where the fourth message includes the SUPI, and the fourth message is used to trigger an authentication and key agreement AKA mechanism.
23. The method according to claim 22, characterized in that Before the first network element sends the fourth message to the second network element, the method further includes: The first network element determines, based on a correspondence between the key identifier and the SUPI, that the SUPI is valid; The first network element sending the fourth message to the second network element includes: when the SUPI is valid, the first network element sending the fourth message to the second network element.
24. The method according to any one of claims 11 to 23, characterized in that The serial number is a mobile subscriber identification code.
25. A communication method, characterized in that: include: The second network element receives an authentication request from the first network element, where the authentication request includes a subscription hidden identifier SUCI, where the SUCI is generated based on a key identifier and a ciphertext, where the key identifier is used to index the first key; The second network element decrypts the ciphertext using the first key to obtain the serial number of the terminal device; The second network element determines a subscription permanent identification SUPI of the terminal device based on the serial number of the terminal device.
26. The method according to claim 25, characterized in that The second network element determines the subscription permanent identification SUPI of the terminal device based on the serial number of the terminal device, including: The second network element recombines and splices the serial number of the terminal device and the plain text in the SUCI to obtain the SUPI of the terminal device.
27. The method according to claim 26, characterized in that The plain text in the SUCI includes one or more of the following: the type of SUPI, the home network identifier of the terminal device, a routing indicator, the key identifier, or a first random number; the first random number is used to generate the ciphertext.
28. The method according to any one of claims 25 to 27, characterized in that After the second network element decrypts the ciphertext using the first key to obtain the serial number of the terminal device, the method further includes: The second network element generates an authentication vector based on a master key corresponding to the SUPI, and performs an authentication and key agreement AKA mechanism.
29. The method according to claim 28, characterized in that Before the second network element generates an authentication vector based on a master key corresponding to the SUPI, the method further includes: The second network element determines, based on a preconfigured correspondence between the key identifier and the SUPI, that the SUPI is valid.
30. The method according to any one of claims 25 to 29, characterized in that Before the second network element receives the authentication request from the first network element, the method further includes: The second network element receives a key generation request from the application function AF, where the key generation request includes the key identifier; The second network element generates one or more keys based on the key identifier; The second network element sends a key generation response to the AF, where the key generation response includes the one or more keys, and the one or more keys include the first key.
31. A communication method, characterized in that: include: The first network element sends a first random number to the terminal device through the access network device; The terminal device sends a second message to the first network element, where the second message includes a subscription hidden identifier SUCI, where the SUCI is generated based on a key identifier and a ciphertext, where the key identifier is used to index a first key, and where the ciphertext is generated based on the first random number, the serial number of the terminal device, and the first key.
32. The method according to claim 31, characterized in that The second message includes the first random number.
33. The method according to claim 31 or 32, characterized in that The SUCI is also generated based on one or more of the following: a type of a subscription permanent identifier SUPI, a home network identifier of the terminal device, the first random number, or a message authentication code.
34. The method according to any one of claims 31 to 33, characterized in that Before the first network element sends the first random number to the terminal device through the access network device, the method further includes: The first network element receives a service request from an application function AF, where the service request includes a service indication or terminal device identification information, and the service indication or terminal device identification information is used to determine the terminal device.
35. The method according to any one of claims 31 to 34, characterized in that After the terminal device sends the second message to the first network element, the method further includes: If the first random number included in the second message is valid, the first network element sends an authentication request to the second network element, the authentication request includes the SUCI, and the second network element determines based on the home network identifier of the terminal device in the SUCI; The second network element decrypts the ciphertext using the first key to obtain the serial number of the terminal device; The second network element determines a subscription permanent identification SUPI of the terminal device based on the serial number of the terminal device.
36. The method according to claim 35, characterized in that The authentication request further includes one or more of the following: indication information, or the first random number; The indication information is used to indicate that the SUCI is an identifier of a low-power consumption device or a low-computing power device.
37. The method according to any one of claims 32 to 36, characterized in that After the terminal device sends the second message to the first network element, the method further includes: The first network element sends a fourth message to the second network element, where the fourth message includes the SUPI, and the fourth message is used to trigger an authentication and key agreement AKA mechanism; The second network element generates an authentication vector based on a master key corresponding to the SUPI, and performs an authentication and key agreement AKA mechanism.
38. [Corrected 12.12.2024 in accordance with Rule 26] A method according to claim 37, characterized in that Before the first network element sends the fourth message to the second network element, the method further includes: The first network element determines, based on a correspondence between the key identifier and the SUPI, that the SUPI is valid.
39. A communication device, characterized in that: Comprising units or modules for executing the method according to any one of claims 1 to 30.
40. A readable storage medium, characterized in that: The readable storage medium stores program instructions, and when the program instructions are executed on a communication device, the communication device executes the method according to any one of claims 1 to 30.
41. A communication system, characterized in that: It includes one or more of the following: a terminal device for executing the method described in any one of claims 1 to 10, a first network element for executing the method described in any one of claims 11 to 24, or a second network element for executing the method described in any one of claims 25 to 30.
42. A program product, characterized in that The method comprises instructions which, when executed, cause the method according to any one of claims 1 to 30 to be performed.
43. A communication device, characterized in that: The device comprises a processor, wherein the processor is used to read and execute a program stored in a memory to perform the method according to any one of claims 1 to 30.
Citation Information
Patent Citations
Communication method and device and readable storage medium
CN117544947A
Secret key determination method and device
CN111641498A
Signed hidden identifier generation method, signed hidden identifier decryption method and related device
CN113556733A
Registering a user equipment to a communication network
US20230292115A1