Communication method and apparatus

By introducing a trusted execution environment between network function production entities and security function entities, and using asymmetric or symmetric key encryption technology, the problem of internal key theft in network elements in 3GPP architecture is solved, and the security of terminal communication is improved, and it is suitable for a variety of communication systems.

WO2025140141A1PCT designated stage expired Publication Date: 2025-07-03HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/141610
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-12-23
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In the prior art, there are security vulnerabilities within the network elements of the 3GPP architecture, and attackers can steal the terminal's keys, resulting in communication security risks, especially in the virtualized environment, where there are risks in key generation and transmission.

Method used

By introducing a trusted execution environment (TEE) between network function production entities and security function entities, we ensure that key generation and transmission are carried out in a safer operating environment. Attackers can only obtain ciphertext information but cannot steal plaintext keys. They use asymmetric or symmetric key encryption technology and combine verification mechanisms to ensure the security of the key.

Benefits of technology

It effectively prevents keys from being stolen by attackers, improves the security of terminal communications, and avoids the risk of key leakage. It is suitable for various communication systems such as Wi-Fi, V2X, D2D, 4G LTE, 5G NR and future communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024141610_03072025_PF_FP_ABST
    Figure CN2024141610_03072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a communication method and apparatus, which are used for preventing a key of a terminal from being stolen by an attacker, thereby ensuring the communication security of the terminal. The method comprises: a network function production entity serving a terminal sending a first message to a first security function entity, receiving a second message from the first security function entity, and sending ciphertext information to a network function consumption entity, wherein the network function production entity and the first security function entity are deployed in the same hardware environment, the network function production entity operates in a first operating environment, the first security function entity operates in a second operating environment, and the security level of the second operating environment is higher than the security level of the first operating environment; the first message is used for requesting the generation, for the network function consumption entity serving the terminal, of a key shared by the network function consumption entity and the terminal; and the second message comprises the ciphertext information, and the ciphertext information is ciphertext obtained by means of the first security function entity encrypting the key shared by the network function consumption entity and the terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 29, 2023, with application number 202311865444.7 and application name “Communication Method and Device,” the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communications, and in particular to a communication method and device. Background Art

[0003] The architecture defined by the 3rd Generation Partnership Project (3GPP) is based on a functional "network element box". 3GPP security is applied between network elements based on reference points. That is, security is established between network elements, and there are security vulnerabilities within the network elements. This security vulnerability may be exploited, and attackers may be able to access the memory of the network element and steal private information within the network element. Taking the key management scenario defined by 3GPP as an example, the network element can manage the key shared by the network element and the terminal, such as the terminal's key K SEAF , key K AUSF Or the key KgNB, etc. These keys are at risk of being stolen by attackers inside the network element, resulting in security risks for terminal communications. Summary of the Invention

[0004] The embodiments of the present application provide a communication method and apparatus to prevent the key of a terminal from being stolen by an attacker, thereby ensuring the communication security of the terminal.

[0005] To achieve the above objectives, this application adopts the following technical solutions:

[0006] In a first aspect, a communication method is provided, comprising: a network function production entity serving a terminal sends a first message to a first security function entity; the first security function entity receives the first message from the network function production entity; in response to the first message, the first security function entity generates a first key shared by a network function consumption entity serving the terminal and the terminal; the first security function entity encrypts the first key to obtain ciphertext information; the first security function entity sends a second message to the network function production entity, the second message including ciphertext information; the network function production entity receives the second message from the first security function entity; the network function production entity sends the ciphertext information to the network function consumption entity; the network function consumption entity receives the ciphertext information from the network function production entity; and the network function consumption entity obtains the first key based on the ciphertext information. The network function production entity and the first security function entity are deployed in the same hardware environment; the network function production entity operates in a first operating environment, and the first security function entity operates in a second operating environment, where the security level of the second operating environment is higher than the security level of the first operating environment.

[0007] According to the method described in the first aspect, the network function production entity can generate a key shared by the network function consumption entity and the terminal locally, and request a more secure operating environment than the first operating environment where the network function production entity is located, such as the first security function entity in the second operating environment to generate and encrypt the ciphertext information of the key. In this case, if an attacker attacks the network function production entity, the attacker can only obtain the ciphertext information and cannot steal the plaintext key. Alternatively, if the attacker attacks the first security function entity, the attacker cannot steal the plaintext key because he cannot access the more secure second operating environment. This can avoid the leakage of the terminal's key and ensure the terminal's communication security.

[0008] In one possible design, a network function production entity sends a first message to a first security function entity, and the first security function entity receives the first message from the network function production entity, including: the network function production entity sends the first message to the first security function entity via a first security interface, and the first security function entity receives the first message from the network function production entity via the first security interface; the first security function entity sends a second message to the network function production entity, and the network function production entity receives the second message from the first security function entity, including: the first security function entity sends the second message to the network function production entity via the first security interface, and the network function production entity receives the second message from the first security function entity via the first security interface. The first security interface is an interface opened by the first security function entity to the network function production entity for communication, that is, the first security interface can only be used by authorized network functions. Since an attacker does not have permission to use the first security interface, they cannot access the first security function entity and cannot steal the terminal's key.

[0009] In one possible design scheme, the network function production entity is an AUSF network element, and the network function production entity sends a first message to the first security function entity, including: the AUSF network element sends the first message to the first security function entity when the terminal authentication is passed, that is, the deduction and encryption scheme performed by the first security function entity can be reused in the existing authentication process to further enhance the security of the existing process, or it can also be applied to newly defined processes in the future, without limitation.

[0010] Optionally, the first message includes a second key, which is a key shared between the network function production entity and the terminal. In response to the first message, the first security function entity generates a first key shared between the network function consumption entity serving the terminal and the terminal, including: in response to the first message, the first security function entity generates the first key based on the second key. In other words, the second key can be provided by the network function production entity to the first security function entity as an input parameter for key derivation. In this case, even if an attacker steals the second key, since they cannot learn from the first security function entity how the second key is used in the derivation process, they cannot know the derived key. Of course, the second key can also be stored in the first security function entity by default, and the first message can carry information indicating the second key.

[0011] Furthermore, in the case where the first security function entity receives a first message from the network function production entity, the method described in the first aspect may also include: the first security function entity verifies whether the network function production entity is trustworthy; the first security function entity generates a first key based on the second key, including: the first security function entity generates the first key based on the second key when it determines that the network function production entity is trustworthy; otherwise, the first security function entity may not generate the first key to avoid the terminal's key from being stolen.

[0012] For example, the first security function entity verifies whether the network function production entity is trustworthy, including: the first security function entity determines whether the network function production entity is the network function entity bound to the first security function entity. If the network function production entity is the network function entity bound to the first security function entity, the network function production entity is trustworthy; if the network function production entity is not the network function entity bound to the first security function entity, the network function production entity is untrustworthy, so as to prevent the terminal's key from being stolen due to an untrustworthy network function entity accessing the first security function entity.

[0013] Optionally, the first message also includes the public key of the asymmetric key, and the first security function entity encrypts the first key to obtain ciphertext information, including: the first security function entity encrypts the first key using the public key of the asymmetric key to obtain ciphertext information. Alternatively, the first message also includes information about the network function message entity, and the first security function entity encrypts the first key to obtain ciphertext information, including: the first security function entity encrypts the first key using a symmetric key preconfigured by the first security function entity and information about the network function consumer entity to obtain ciphertext information. In other words, the first security function entity can select an encryption method based on the received information, such as selecting asymmetric encryption based on the received asymmetric key, or selecting symmetric encryption based on the received information about the network function message entity. This avoids the overhead associated with indicating the encryption method and improves communication efficiency.

[0014] Furthermore, the method described in the first aspect may also include: the network function consuming entity sends the public key of the asymmetric key to the network function producing entity, and the network function producing entity receives the public key of the asymmetric key from the network function consuming entity; or; the network function consuming entity sends indication information for obtaining the asymmetric key to the network function producing entity, and the network function producing entity obtains the public key of the asymmetric key based on the indication information received from the network function producing entity, that is, the public key of the asymmetric key can be provided on demand by the network function consuming entity without the need for maintenance by the network function producing entity, so as to reduce the overhead of the network function producing entity.

[0015] Alternatively, the network function production entity may also send indication information for obtaining an asymmetric key to the first security function entity, such as a first message carrying the indication information of the asymmetric key, or any other possible message carrying the indication information, so that the first security function entity can obtain the public key of the asymmetric key based on the indication information.

[0016] Furthermore, the method described in the first aspect may also include: the network function consumption entity sends information of the network function message entity to the network function production entity, and the network function production entity receives information of the network function message entity from the network function consumption entity. That is, the information of the network function message entity can also be provided on demand by the network function consumption entity, without the need for maintenance by the network function production entity, and can also reduce the overhead of the network function production entity.

[0017] In one possible design, a network function consuming entity obtains a first key based on ciphertext information, including: the network function consuming entity sends a third message to a second security function entity, where the network function consuming entity and the second security function entity are deployed in the same hardware environment; the network function consuming entity operates in a third operating environment, and the second security function entity operates in a fourth operating environment, where the security level of the fourth operating environment is higher than that of the third operating environment; the third message includes ciphertext information; the second security function entity receives the third message from the network function consuming entity; in response to the third message, the second security function entity decrypts the ciphertext information to obtain the first key; the second security function entity sends a fourth message to the network function producing entity, where the fourth message includes the first key; and the network function consuming entity receives the fourth message from the second security function entity. In other words, the network function consuming entity can perform decryption not locally but request a more secure operating environment than the third operating environment where the network function consuming entity resides, such as the second security function entity performing decryption in the fourth operating environment, thereby improving decryption security.

[0018] Optionally, the second key is the key K AUSF ; The network function consumption entity is the SEAF network element, and the first key is based on the key K AUSF Determined key K SEAF The SEAF network element can use the key K locally SEAF Derived key K AMF , and then the key K AMF Sent to the access and mobility management function AMF network element serving the terminal. Alternatively, the SEAF network element can also use the solution of this application to request the second security function entity to derive and encrypt the key K AMF The ciphertext is then converted by the SEAF network element into the key K AMF The ciphertext is sent to the AMF network element.

[0019] Furthermore, the second security function entity decrypts the ciphertext information to obtain the first key, including: the second security function entity uses the private key of the asymmetric key to decrypt the ciphertext information to obtain the first key; or, the second security function entity uses the symmetric key pre-configured by the second security function entity and the information of the network function consumption entity to decrypt the ciphertext information to obtain the first key.

[0020] Furthermore, the third message includes information of the network function consuming entity, that is, the information of the network function message entity can also be provided by the network function consuming entity, without the need for maintenance by the second security function entity, and can also reduce the overhead of the second security function entity.

[0021] It is understood that the decryption method of the second security function entity needs to match the encryption method of the first security function entity. The second security function entity and the first security function entity can pre-configure a symmetric key, or share a symmetric key. In this way, the first security function entity uses the symmetric key to encrypt the first key to obtain ciphertext information, and the second security function entity uses the symmetric key to decrypt the ciphertext information to obtain the first key. Alternatively, the first security function entity can encrypt using the public key of an asymmetric key and decrypt using the private key of the asymmetric key to achieve alignment. In this way, the first security function entity uses the public key of the asymmetric key to encrypt the first key to obtain ciphertext information, and the second security function entity uses the private key of the asymmetric key to decrypt the ciphertext information to obtain the first key.

[0022] Optionally, when the second security function entity receives a third message from the network function consuming entity, the method described in the first aspect may further include: the second security function entity verifies whether the network function consuming entity is trustworthy; the second security function entity decrypts the ciphertext information to obtain the first key, including: when the second security function entity determines that the network function consuming entity is trustworthy, the second security function entity decrypts the ciphertext information to obtain the first key; otherwise, the second security function entity may not decrypt the ciphertext information to avoid the terminal's key from being stolen.

[0023] For example, the second security function entity verifies whether the network function consuming entity is trustworthy, including: the second security function entity determines whether the network function consuming entity is a network function entity bound to the second security function entity. If the network function consuming entity is a network function entity bound to the second security function entity, the network function consuming entity is trustworthy; if the network function consuming entity is not a network function entity bound to the second security function entity, the network function production and consumption is untrustworthy, thereby preventing the terminal's key from being stolen due to an untrusted network function entity accessing the second security function entity.

[0024] In one possible design, the network function consuming entity sends a third message to the second security function entity, and the second security function entity receives the third message from the network function consuming entity, including: the network function consuming entity sends the third message to the second security function entity via a second security interface, and the second security function entity receives the third message from the network function consuming entity via the second security interface; the second security function entity sends a fourth message to the network function producing entity, and the network function consuming entity receives the fourth message from the second security function entity, including: the second security function entity sends the fourth message to the network function producing entity via the second security interface, and the network function consuming entity receives the fourth message from the second security function entity via the second security interface. The second security interface is an interface opened by the second security function entity to the network function consuming entity for communication, that is, the second security interface can only be used by authorized network functions. Since an attacker does not have permission to use the second security interface, they cannot access the second security function entity and cannot steal the terminal's key.

[0025] In a possible design scheme, the method described in the first aspect may also include: the network function production entity sends a capability query message to the network function consumption entity; the network function consumption entity receives the capability query message from the network function production entity; in response to the capability query message, the network function consumption entity sends a capability query response message to the network function production entity, and the capability query response message includes capability information; the network function production entity receives the capability query response message from the network function consumption entity; the network function production entity sends a first message to the first security function entity, including; in response to the capability information, the network function production entity sends a first message to the first security function entity.

[0026] That is to say, the network function production entity will only use the first network function production entity for encryption when the network function consumption entity supports the use of the second network function production entity for decryption, so as to avoid process failure due to the network function consumption entity being unable to use its corresponding security function entity for decryption.

[0027] Optionally, the capability information is used to indicate whether the network function consuming entity supports the security capability of processing information through the security function entity. For example, the capability information may be an information element of one or more bits, and the value combination of these bits may be used to indicate whether the network function consuming entity supports the security capability of processing information through the security function entity.

[0028] It is understood that if the network function consuming entity does not support the security capability of processing information through the security function entity, the network function producing entity may also use other methods to generate the first key. For example, the network function producing entity may generate the first key on its own, that is, using existing technologies, or may instruct other network elements other than the first security function entity to generate the first key. The specific method is not limited.

[0029] Furthermore, when the network function consumption entity supports processing information through the security function entity, the capability query response message includes the public key of the asymmetric key, or indication information for obtaining the asymmetric key, that is, the above-mentioned public key or indication information of the asymmetric key can be passed to the network function production entity by multiplexing the capability query response message to reduce the number of communication interactions, thereby reducing communication overhead.

[0030] In a possible design scheme, the method described in the first aspect may also include: the first security function entity generates verification information for the ciphertext information; the first security function entity sends the verification information to the network function production entity; the network function production entity receives the verification information from the first security function entity; the network function production entity sends the verification information to the network function consumption entity; the network function consumption entity receives the verification information from the network function production entity; the network function consumption entity uses the verification information to verify the ciphertext information; the network function consumption entity sends a third message to the second security function entity, including: the network function consumption entity sends the third message to the second security function entity when the ciphertext information verification is passed.

[0031] In a possible design scheme, the method described in the first aspect may also include: the first security function entity generates verification information for the ciphertext information; the first security function entity sends verification information to the network function production entity; the network function production entity receives verification information from the first security function entity; the network function production entity sends verification information to the network function consumption entity; the network function consumption entity receives verification information from the network function production entity; the network function consumption entity sends verification information to the second security function entity; the second security function entity receives verification information from the network function consumption entity; the second security function entity uses the verification information to verify the ciphertext information; the second security function entity decrypts the ciphertext information to obtain the first key, including: the second security function entity decrypts the ciphertext information to obtain the first key when the ciphertext information verification passes.

[0032] It is understood that the verification information can be a signature or integrity protection value (MAC) of the ciphertext information, and the specific implementation is not limited. The network function consuming entity or the second security function entity can use the verification information to verify the signature or perform an integrity protection check to determine whether the ciphertext information originated from the network function consuming entity and whether it has been tampered with by an attacker, and to determine whether the network function producing entity has been attacked, thereby ensuring communication security.

[0033] A second aspect provides a communication method, comprising: a network function production entity serving a terminal sends a first message to a first security function entity, receives a second message from the first security function entity, and sends ciphertext information to a network function consumption entity. The network function production entity and the first security function entity are deployed in the same hardware environment, the network function production entity operates in a first operating environment, and the first security function entity operates in a second operating environment, the security level of the second operating environment being higher than the security level of the first operating environment; the first message is used to request generation of a key shared between the network function consumption entity and the terminal for the network function consumption entity serving the terminal; and the second message includes ciphertext information, which is ciphertext obtained by encrypting the key shared between the network function consumption entity and the terminal by the first security function entity.

[0034] In one possible design scheme, the first message also includes a second key, where the second key is a key shared by the network function production entity and the terminal, and the second key is used to determine the key shared by the network function consumption entity and the terminal.

[0035] In a possible design scheme, the first message also includes a public key of an asymmetric key, and the public key of the asymmetric key is used to encrypt a key shared by the network function consumption entity and the terminal.

[0036] Optionally, the method described in the second aspect may also include: the network function production entity receiving the public key of the asymmetric key from the network function consumption entity; or; the network function production entity obtaining the public key of the asymmetric key based on the instruction information for obtaining the asymmetric key received from the network function production entity.

[0037] In a possible design scheme, the first message also includes information of the network function consuming entity, and the information of the network function consuming entity is used to encrypt a key shared by the network function consuming entity and the terminal.

[0038] Optionally, the method described in the second aspect may further include: the network function production entity receiving information about the network function consumption entity from the network function consumption entity.

[0039] In one possible design, the network function production entity is an authentication server function AUSF network element, and the network function production entity sends a first message to the first security function entity, including: the AUSF network element sends the first message to the first security function entity when the terminal authentication is successful. In this case, the first key is the key K AUSF .

[0040] In a possible design scheme, the method described in the second aspect may also include: the network function production entity sends a capability query message to the network function consumption entity, the capability query message is used to query the security capability of the network function consumption entity; the network function production entity receives a capability query response message from the network function consumption entity, the capability query response message includes capability information, and the capability information is used to indicate that the network function consumption entity supports the security capability of processing information through the security function entity; the network function production entity sends a first message to the first security function entity, including: in response to the capability information, the network function production entity sends the first message to the first security function entity.

[0041] In one possible design scheme, the network function production entity sends a first message to the first security function entity, including: the network function production entity sends the first message to the first security function entity through a first security interface, and the first security interface is an interface opened by the first security function entity to the network function production entity for communication; the network function production entity receives a second message from the first security function entity, including: the network function production entity receives the second message from the first security function entity through the first security interface.

[0042] In a possible design scheme, the method described in the second aspect may also include: the network function production entity receives verification information of the ciphertext information from the first security function entity, and sends the verification information to the network function consumption entity.

[0043] It can be understood that the technical effects of the method described in the second aspect can also refer to the relevant introduction of the method described in the first aspect above, and will not be repeated here.

[0044] In a third aspect, a communication method is provided, comprising: a first security function entity receiving a first message from a network function production entity serving a terminal; in response to the first message, the first security function entity generating a first key shared by a network function consumption entity serving the terminal and the terminal, encrypting the first key to obtain ciphertext information, and sending a second message to the network function production entity, the second message including the ciphertext information. The network function production entity and the first security function entity are deployed in the same hardware environment, the network function production entity operates in a first operating environment, and the first security function entity operates in a second operating environment, where the security level of the second operating environment is higher than the security level of the first operating environment.

[0045] In one possible design scheme, the first message includes a second key, which is a key shared by the network function production entity and the terminal. In response to the first message, the first security function entity generates a first key shared by the network function consumption entity serving the terminal and the terminal, including: in response to the first message, the first security function entity generates a first key based on the second key.

[0046] Optionally, when the first security function entity receives a first message from the network function production entity, the method described in the third aspect may also include: the first security function entity verifies whether the network function production entity is trustworthy; the first security function entity generates a first key based on the second key, including: the first security function entity generates the first key based on the second key when determining that the network function production entity is trustworthy.

[0047] In one possible design scheme, the first message also includes a public key of an asymmetric key, and the first security function entity encrypts the first key to obtain ciphertext information, including: the first security function entity uses the public key of the asymmetric key to encrypt the first key to obtain ciphertext information; or, the first message also includes information of a network function message entity, and the first security function entity encrypts the first key to obtain ciphertext information, including: the first security function entity uses the symmetric key pre-configured by the first security function entity and the information of the network function consumption entity to encrypt the first key to obtain ciphertext information.

[0048] In one possible design scheme, the first security function entity receives a first message from a network function production entity serving a terminal, including: the first security function entity receives the first message from the network function production entity through a first security interface, and the first security interface is an interface opened by the first security function entity to the network function production entity for communication; the first security function entity sends a second message to the network function production entity, including: the first security function entity sends the second message to the network function production entity through the first security interface.

[0049] In a possible design scheme, the method described in the third aspect may also include: the first security function entity generates verification information of the ciphertext information and sends the verification information to the network function production entity.

[0050] It can be understood that the technical effects of the method described in the third aspect can also refer to the relevant introduction of the method described in the first aspect above, and will not be repeated here.

[0051] In a fourth aspect, a communication method is provided, comprising: a network function consuming entity serving a terminal receives ciphertext information from a network function producing entity serving the terminal, sends a third message to a second security function entity, and receives a fourth message from the second security function entity. The network function consuming entity and the second security function entity are deployed in the same hardware environment, the network function consuming entity operates in a third operating environment, and the second security function entity operates in a fourth operating environment, the security level of the fourth operating environment being higher than the security level of the third operating environment. The third message includes ciphertext information; and the fourth message includes a first key shared by the network function producing entity and the terminal, the first key being a plaintext key obtained by the second security function entity to decrypt the ciphertext information.

[0052] In one possible design scheme, the third message also includes information of the network function consuming entity, and the information of the network function consuming entity is used to decrypt the ciphertext information.

[0053] In one possible design scheme, the network function consuming entity sends a third message to the second security function entity, including: the network function consuming entity sends the third message to the second security function entity through the second security interface, and the second security interface is an interface opened by the second security function entity to the network function consuming entity for communication; the network function consuming entity receives a fourth message from the second security function entity, including: the network function consuming entity receives the fourth message from the second security function entity through the second security interface.

[0054] In a possible design scheme, the method described in the fourth aspect may also include: the network function consumption entity sends the public key of the asymmetric key to the network function production entity, and the public key of the asymmetric key is used to encrypt the key shared by the network function consumption entity and the terminal; or; the network function consumption entity sends indication information for obtaining the public key of the asymmetric key to the network function production entity.

[0055] In one possible design scheme, the method described in the fourth aspect may also include: the network function consuming entity receives a capability query message from the network function producing entity; in response to the capability query message, the network function consuming entity sends a capability query response message to the network function producing entity, and the capability query response message includes capability information, and the capability information is used to indicate that the network function consuming entity supports the security capability of processing information through the security function entity.

[0056] In a possible design scheme, the method described in the fourth aspect may also include: the network function consuming entity receives verification information from the network function producing entity; the network function consuming entity uses the verification information to verify the ciphertext information; the network function consuming entity sends a third message to the second security function entity, including; the network function consuming entity sends the third message to the second security function entity when the ciphertext information verification is passed.

[0057] In a possible design scheme, the method described in the fourth aspect may also include: the network function consuming entity receives verification information for verifying the ciphertext information from the network function producing entity; and the network function consuming entity sends the verification information to the second security function entity.

[0058] It can be understood that the technical effects of the method described in the fourth aspect can also refer to the relevant introduction of the method described in the first aspect above, and will not be repeated here.

[0059] In a fifth aspect, a communication method is provided, comprising: a second security function entity receiving a third message from a network function consuming entity serving a terminal; in response to the third message, the second security function entity decrypting ciphertext information to obtain a first key shared by the network function producing entity and the terminal; and sending a fourth message to the network function consuming entity. The network function consuming entity and the second security function entity are deployed in the same hardware environment, the network function consuming entity operates in a third operating environment, and the second security function entity operates in a fourth operating environment, the security level of the fourth operating environment being higher than that of the third operating environment; the third message includes ciphertext information, and the fourth message includes the first key.

[0060] In one possible design scheme, the second security function entity decrypts the ciphertext information to obtain the first key shared by the network function production entity and the terminal, including: the second security function entity uses the private key of the asymmetric key to decrypt the ciphertext information to obtain the first key; or; the second security function entity uses the symmetric key pre-configured by the second security function entity and information of the network function consumption entity to decrypt the ciphertext information to obtain the first key.

[0061] Optionally, the third message includes information of the network function consuming entity.

[0062] In one possible design scheme, when the second security function entity receives a third message from the network function consuming entity, the method described in the fifth aspect may also include: the second security function entity verifies whether the network function consuming entity is trustworthy; the second security function entity decrypts the ciphertext information to obtain the first key, including: the second security function entity decrypts the ciphertext information to obtain the first key when determining that the network function consuming entity is trustworthy.

[0063] In one possible design scheme, the second security function entity receives a third message from a network function consuming entity serving the terminal, including: the second security function entity receives the third message from the network function consuming entity through a second security interface, and the second security interface is an interface opened by the second security function entity to the network function consuming entity for communication; the second security function entity sends a fourth message to the network function consuming entity, including: the second security function entity sends the fourth message to the network function consuming entity through the second security interface.

[0064] In a possible design scheme, the method described in the fifth aspect may also include: the second security function entity receives verification information from the network function consumption entity; the second security function entity uses the verification information to verify the ciphertext information; the second security function entity decrypts the ciphertext information to obtain the first key, including; the second security function entity decrypts the ciphertext information to obtain the first key when the ciphertext information verification is successful.

[0065] It can be understood that the technical effects of the method described in the fifth aspect can also refer to the relevant introduction of the method described in the first aspect above, and will not be repeated here.

[0066] In a sixth aspect, a communication device is provided, which includes a module for executing the method described in any one of the first to fifth aspects above.

[0067] In one possible design solution, the communication device described in the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the sixth aspect to communicate with other communication devices.

[0068] In one possible design, the communication device described in the sixth aspect may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store instructions related to the method of any one of the first to fifth aspects.

[0069] In an embodiment of the present application, the communication device described in the sixth aspect may be a network device, or a chip (system) or other parts or components that can be set in the network device, or a device that includes the network device.

[0070] It can be understood that the technical effects of the device described in the sixth aspect can also refer to the relevant introduction of the method in any of the first to fifth aspects above, and will not be repeated here.

[0071] In a seventh aspect, a communication device is provided, comprising: a processor coupled to a memory, the processor configured to execute instructions stored in the memory, so that the communication device executes the method described in any one of the first to fifth aspects.

[0072] In one possible design solution, the communication device described in the seventh aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the seventh aspect to communicate with other communication devices.

[0073] In an embodiment of the present application, the communication device described in the seventh aspect can be the network device described in any one of the first to fifth aspects, or a chip (system) or other parts or components that can be set in the network device, or a device that includes the network device.

[0074] In addition, the technical effects of the communication device described in the seventh aspect can refer to the technical effects of the methods described in any one of the first to fifth aspects, and will not be repeated here.

[0075] In an eighth aspect, a communication device is provided, comprising: a processor and a memory; the memory is used to store instructions, and when the processor executes the instructions, the communication device executes the method described in any one of the first to fifth aspects.

[0076] In one possible design solution, the communication device described in the eighth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the eighth aspect to communicate with other communication devices.

[0077] In an embodiment of the present application, the communication device described in aspect 8 may be the network device described in any one of aspects 1 to 5, or a chip (system) or other parts or components that may be set in the network device, or a device that includes the network device.

[0078] In addition, the technical effects of the communication device described in the eighth aspect can refer to the technical effects of the methods described in any one of the first to fifth aspects, and will not be repeated here.

[0079] In a ninth aspect, a chip is provided, comprising: a controller and an interface circuit, wherein the controller is used to interact with other devices through the interface circuit to execute the method described in any one of the first to fifth aspects.

[0080] In a tenth aspect, a communication system is provided. The communication system includes at least one of the following: a network function production entity for executing the method described in the first or second aspect, a network function consumption entity for executing the method described in the first or third aspect, a first security function entity for executing the method described in the fourth aspect, or a second security function entity for executing the method described in the fifth aspect.

[0081] In the eleventh aspect, a computer-readable storage medium is provided, which includes a computer program or instruction stored therein, and when the computer program or instruction is executed, the method described in any one of the first to fifth aspects is executed.

[0082] In a twelfth aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed, enables the method described in any one of the first to fifth aspects to be executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0083] Figure 1 is a schematic diagram of the architecture of REE and TEE;

[0084] Figure 2 is a schematic diagram of the structure of 5GS;

[0085] FIG3 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;

[0086] FIG4 is a schematic diagram of the architecture of the communication system at the NFVI layer provided in an embodiment of the present application;

[0087] FIG5 is a first interactive diagram of a communication system according to an embodiment of the present application;

[0088] FIG6 is a second interactive diagram of a communication system provided in an embodiment of the present application;

[0089] FIG7 is a flow chart of a communication method according to an embodiment of the present application;

[0090] FIG8 is a second flow chart of a communication method according to an embodiment of the present application;

[0091] FIG9 is a third flow chart of the communication method provided in an embodiment of the present application;

[0092] FIG10 is a fourth flow chart of a communication method according to an embodiment of the present application;

[0093] FIG11 is a fifth flow chart of a communication method according to an embodiment of the present application;

[0094] FIG12 is a first structural diagram of a communication device provided in an embodiment of the present application;

[0095] FIG13 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0096] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless network (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, fourth-generation (4G) mobile communication systems, such as long-term evolution (LTE) systems, world-wide interoperability for microwave access (WiMAX) communication systems, fifth-generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as 5.5G and sixth-generation (6G) mobile communication systems.

[0097] For ease of understanding, the technical terms involved in this application are first introduced below.

[0098] 1. Key protection technology based on secure element:

[0099] On traditional personal computers (PCs), cryptographic keys are typically stored directly on the hard drive. With the rise in popularity of mobile payments, this naked key storage method has gradually exposed various issues, leading to repeated problems with payment applications. The root cause is that cryptographic keys need to be stored in a trusted and secure environment. Due to the complexity of operating systems, this assumption is fundamentally untenable. This led to the development of the first generation of USB-shield products, which were among the earliest secure element concepts in China. Given the complexity of operating systems, a less complex system could be used to perform calculations, ensuring that the key does not leave the USB-shield, thereby ensuring key security. However, over time, it became apparent that USB-shields operating in a secure (slave) state are highly susceptible to spoofing. Virus programs can easily trick USB-shields into performing cryptographic calculations. Therefore, the first generation of USB-shields naturally transitioned to the second generation, which features display and verification capabilities. This means that users perform cryptographic calculations using a display and physical buttons that cannot be controlled by the operating system software, ensuring that the cryptographic device correctly interprets the user's intent. Secure element security requires more than just isolation; it also requires the correct execution of the user's intent.

[0100] We need stronger security assumptions to support the root of trust in systems requiring higher security levels. Storing keys in simple secure elements addresses the security risks of complex software that is uncontrollable and prone to vulnerabilities, making critical information vulnerable to theft and misuse. The secure element itself is also vulnerable to various other attacks. Because the software system is simple and the hardware components are relatively few, it is easier to establish physical protections and implement security measures, thereby improving the security strength of the secure element and enabling security systems with stronger security assumptions.

[0101] With the development of the mobile internet, the use of additional secure elements on mobile devices increases costs, and external secure elements can lead to a degraded user experience. We urgently need a more convenient, easy-to-use, and affordable key protection technology. The concept of a trusted execution environment (TEE) is gaining increasing attention.

[0102] 2. TEE-based key protection technology:

[0103] To address the inconvenience of deploying pure hardware security on mobile devices, the Open Mobile Devices Group proposed the concept and solution of a Trusted Execution Environment (TEE), a compromise between a pure software environment and a secure element. TEE aims to build a trusted execution environment (TEE), improving device security and enabling a wide range of application extensions, providing greater flexibility and flexibility for user use and service providers.

[0104] As shown in Figure 1, the architecture where the TEE is located includes a rich execution environment (REE) and TEE.

[0105] REE consists of a rich operating system (Rich OS), such as Linux, running on a general-purpose embedded processor, along with client applications. Despite numerous security measures implemented within REE, such as device access control, device data encryption, application runtime isolation, and permission-based access control, the security of sensitive data cannot be guaranteed.

[0106] The TEE is an independent operating environment that runs outside of a standard operating system. It provides security services to standard operating systems and is isolated from them. Standard operating systems and applications running on them cannot directly access the TEE's hardware and software resources. The TEE's goal is to establish a trusted execution environment. A trusted operating system (Trust OS) runs within the TEE. The TEE provides a trusted operating environment for trusted applications (trusted software authorized by the TEE, also known as TAs), ensuring end-to-end security by protecting confidentiality, integrity, and controlling data access rights.

[0107] TEE runs in parallel with REE and communicates through secure APIs, such as the REE communication agent on REE and the TEE communication agent on TEE.

[0108] 3. Fifth generation (5G) mobile communication system (abbreviated as 5G system (5G system, 5GS)):

[0109] Figure 2 is a schematic diagram of the 5GS architecture. As shown in Figure 2, the 5GS includes an access network (AN) and a core network (CN), and may also include terminals.

[0110] The terminal may be a terminal with transceiver functions, or a chip or chip system that can be provided in the terminal. The terminal may also be referred to as user equipment (UE), access terminal, subscriber unit, subscriber station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. The terminal in the embodiments of the present application can be a mobile phone, a cellular phone, a smartphone, a tablet computer, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handheld device (handset), a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle-mounted terminal, a road side unit (RSU) with terminal function, etc. The terminal of the present application may also be an on-board module, on-board module, on-board component, on-board chip or on-board unit built into the vehicle as one or more components or units.

[0111] The AN implements access-related functions, providing network access for authorized users and determining transmission links of varying quality for user data based on user level and service requirements. The AN forwards control signals and user data between terminals and the CN. The AN may include access network equipment, also known as radio access network (RAN) equipment.

[0112] The CN is primarily responsible for maintaining mobile network subscription data and providing terminal functions such as session management, mobility management, policy management, and security authentication. The CN primarily includes all or part of the following functions: user plane function (UPF), authentication server function (AUSF), access and mobility management function (AMF), session management function (SMF), network slice selection function (NSSF), network exposure function (NEF), network repository function (NRF), policy control function (PCF), unified data management (UDM), unified data repository (UDR), and application function (AF).

[0113] As shown in Figure 2, the UE accesses the 5G network through the RAN equipment. The UE communicates with the AMF through the N1 interface (referred to as N1); the RAN communicates with the AMF through the N2 interface (referred to as N2); the RAN communicates with the UPF through the N3 interface (referred to as N3); the SMF communicates with the UPF through the N4 interface (referred to as N4), and the UPF accesses the data network (DN) through the N6 interface (referred to as N6). In addition, the control plane functions such as AUSF, AMF, SMF, NSSF, NEF, NRF, PCF, UDM, UDR or AF shown in Figure 2 interact using service-based interfaces. For example, the service interface provided by AUSF to the outside world is Nausf; the service interface provided by AMF to the outside world is Namf; the service interface provided by SMF to the outside world is Nsmf; the service interface provided by NSSF to the outside world is Nnssf; the service interface provided by NEF to the outside world is Nnef; the service interface provided by NRF to the outside world is Nnrf; the service interface provided by PCF to the outside world is Npcf; the service interface provided by UDM to the outside world is Nudm; the service interface provided by UDR to the outside world is Nudr; and the service interface provided by AF to the outside world is Naf.

[0114] RAN equipment can be equipment that provides access to terminals. For example, RAN equipment may include: a next-generation mobile communication system, such as an access network device of 6G, such as a 6G base station, or in the next-generation mobile communication system, the network equipment may also have other naming methods, which are all included in the protection scope of the embodiments of this application, and this application does not impose any restrictions on this. Alternatively, the RAN equipment may also include 5G, such as a gNB in ​​a new radio (NR) system, or one or a group of (including multiple antenna panels) antenna panels of a base station in 5G, or a network node constituting a gNB, a transmission point (TRP or transmission point, TP) or a transmission measurement function (TMF), such as a baseband unit (BBU), or a centralized unit (CU) or a distributed unit (DU), an RSU with base station function, or a wired access gateway, or a 5G core network. Alternatively, RAN devices may also include access points (APs) in wireless fidelity (WiFi) systems, wireless relay nodes, wireless backhaul nodes, various forms of macro base stations, micro base stations (also known as small stations), relay stations, access points, wearable devices, vehicle-mounted devices, and the like.

[0115] UPF is mainly responsible for user data processing (forwarding, receiving, billing, etc.). For example, UPF can receive user data from the data network (DN) and forward the user data to the terminal through the access network equipment. UPF can also receive user data from the terminal through the access network equipment and forward the user data to the DN. DN refers to the operator network that provides data transmission services to users. For example, Internet Protocol (IP) Multimedia Service (IMS), Internet, etc. DN can be an operator's external network or a network controlled by the operator, used to provide business services to the terminal. In the protocol data unit (PDU) session, the UPF directly connected to the DN through N6 is also called the protocol data unit session anchor (PSA).

[0116] AUSF is mainly used to perform terminal security authentication.

[0117] AMF is mainly used for mobility management in mobile networks, such as user location update, user network registration, and user handover.

[0118] The SMF is primarily used for session management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating Internet Protocol (IP) addresses to users and selecting the UPF that provides packet forwarding capabilities.

[0119] PCF mainly supports providing a unified policy framework to control network behavior, providing policy rules to the control layer network functions, and is responsible for obtaining user subscription information related to policy decisions. PCF can provide policies to AMF and SMF, such as quality of service (QoS) policy and slice selection policy.

[0120] NSSF is mainly used to select network slices for terminals.

[0121] NEF is mainly used to support the opening of capabilities and events.

[0122] UDM is mainly used to store user data, such as contract data, authentication / authorization data, etc.

[0123] UDR is mainly used to store structured data, including contract data and policy data, externally exposed structured data, and application-related data.

[0124] AF mainly supports interaction with CN to provide services, such as influencing data routing decisions, policy control functions, or providing some third-party services to the network side.

[0125] It can be understood that the functions mentioned in the embodiments of the present application can also be expressed as functional network elements or functional entities. For example, UPF can be expressed as UPF network element, AMF can be expressed as AMF network element, SMF can be expressed as SMF network element, PCF can be expressed as PCF network element, and so on, without limitation.

[0126] 4. Key derivation function (KDF):

[0127] Key derivation (including input parameter encoding) should use the KDF specified in the 3rd Generation Partnership Project (3GPP) TS 33.220, which specifies the construction of input string S and input key "KEY" for different KDFs. For example, with key K SEAF For example, when the key K AUSF Derived key K SEAFThe input S should be constructed from the following parameters as the input parameters of the KDF, as follows: FC = 0x6C; P0 = service network name; L0 = length of the service network name; the input key "KEY" should be the key K AUSF ; The service network name should be constructed according to TS33.5016.1.1.4.

[0128] According to the standard document TR 33.848, the 3GPP architecture (including 5G) is still based on functional "network element boxes." 3GPP security is applied between network elements based on reference points. In other words, security is established between network elements and cannot address issues within network elements. If 3GPP network elements are implemented in a common software host environment (e.g., with a common hypervisor, common compute, and common storage), transport layer security (TLS) and similar protocols are simplified to protect information transmitted between memory locations within a single logical memory block. Therefore, if an attacker (e.g., a hypervisor administrator) gains access to the memory running a set of virtual network functions (VNFs), relying on reference point-based security offers little protection beyond physically exposed hardware links. In other words, in virtualized scenarios, network elements may be able to directly access the memory of other network elements. This security vulnerability is susceptible to lateral attacks, such as an attacker attacking between virtual machines (VMs) to affect other VMs on the physical host. This type of attack can be carried out in various ways, such as exploiting network connections or shared resources between virtual machines, or by attacking other processes in the virtual machine to affect its behavior, resulting in data loss, system crashes, or business interruptions.

[0129] Therefore, the key derivation of 5GC cannot guarantee the security of keys in the scenario of virtualized lateral movement. For example, if a malicious NF and AUSF network element are located in the same real system (Host OS), the malicious NF may obtain the TLS certificate used by the AUSF network element to transmit keys through the real system (for example, obtaining hard disk read permission, or even the malicious NF and AUSF network element in the real system of the container (docker) may directly share a TLS certificate). The malicious NF can use the TLS certificate to obtain transport layer encrypted messages and intercept the key K subsequently transmitted by the AUSF network element. SEAF , which poses a hidden danger to UE communication.

[0130] 5. gNB key management:

[0131] Currently, 3GPP is discussing gNB key management, specifically including management and environmental requirements.

[0132] 1) Requirements for gNB internal key management:

[0133] Any part of the gNB involved in storing or processing keys in plain text should be protected from physical attack. Otherwise, the entire entity should be placed in a physically secure location, and keys in plain text should be stored and processed in a secure environment. Keys stored anywhere in the gNB in ​​a secure environment should not leave the secure environment, except where explicitly required by this or other standards.

[0134] 2) Requirements for the gNB security environment:

[0135] The security environment is a logical function defined within the gNB that protects all sensitive information and operations, preventing unauthorized access or disclosure. The security environment requirements are as follows: The security environment should support the secure storage of sensitive data, such as long-term keys and important configuration data. It should support the execution of sensitive functions, such as encryption / decryption of user data and protocol operations requiring long-term keys (e.g., authentication protocols). The security environment should support the execution of sensitive portions of the boot process. The integrity of the security environment should be maintained. Only authorized access is granted to the security environment, including the storage and use of data and the execution of functions within it.

[0136] As can be seen, although gNB keys must be managed in a secure environment, the gNB, as the network function producer (NFp), generates keys, and the network function consumer (NFc) cannot verify that the keys originate from a secure environment. Imagine a low-cost equipment vendor cutting corners at the NFp and failing to manage keys within the NFp's secure environment. Even if keys are subsequently generated and transmitted to subsequent NFcs, the NFcs cannot verify that the keys were securely generated, posing a security risk to UE communications.

[0137] In summary, the existing technology lacks protection for key generation, derivation, and management, resulting in the risk that the generation and transmission of keys for UE communication may be stolen in a virtualized environment.

[0138] In response to the above technical problems, the embodiments of the present application propose the following technical solutions.

[0139] The technical solution in this application will be described below with reference to the accompanying drawings.

[0140] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein there is an association relationship between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.

[0141] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0142] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. The sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.

[0143] In this application, "sending information" can be understood as one device sending information to another device, or as one logic module within a device sending information to another logic module. For example, "a network device sending information" can be understood as a network device sending information to another device (such as a terminal or other network device), or as logic module 1 within a network device sending information to logic module 2 within the network device.

[0144] In this application, "receiving information" can be understood as one device receiving information from another device, or it can also be understood as a logic module within a device receiving information from another logic module. For example, "a network device receiving information" can be understood as the network device receiving information from another device (such as a terminal or other network device), or it can be understood as logic module 1 in the network device receiving information from logic module 2 in the network device.

[0145] In this application, "sending information to... (e.g., a terminal)" or the related illustrations in the accompanying drawings can be understood as the destination end of the information being the terminal. This can include sending information to the terminal directly or indirectly. "Receiving information from... (e.g., a terminal)" or "receiving information from... (e.g., a terminal)" or "receiving information sent by (e.g., a terminal)", or the related illustrations in the accompanying drawings can be understood as the source end of the information being the terminal, which can include receiving information from the terminal directly or indirectly. The information may be processed as necessary between the source end and the destination end of the information transmission, such as format changes, etc., but the destination end can understand the valid information from the source end. Similar expressions in this application can be understood similarly and will not be repeated here.

[0146] "Pre-definition" or "pre-configuration" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.

[0147] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.

[0148] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.

[0149] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated with each other are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.

[0150] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0151] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail using a communication system as an example.

[0152] FIG3 is a schematic diagram of the architecture of a communication system. As shown in FIG3 , the communication system mainly includes: a network function entity and a security function entity.

[0153] A network function entity (or network element / network function) can be a network element in a 5G network, or a network element in a future network, such as a 6G network, and specifically a virtualized functional network (VNF). A VNF can run in a corresponding operating environment, which can be a normal environment or an untrusted environment, such as an REE or any similar environment. It is a software application that provides network functions (such as file sharing, directory services, and IP configuration). For the entire network element function facility, a VNF is a software group that provides network services and is deployed on virtual machines, containers, or physical machines using the infrastructure provided by the network functions virtualization infrastructure (NFVI).

[0154] The network function entity may include a network function producer (NFp) and a network function consumer (NFc). The network function producer and the network function consumer may serve the terminal and may be network elements related to the network security of the terminal. For example, the network function producer is an AUSF network element, and the network function consumer is a SEAF network element. For another example, the network function producer is a SEAF network element, and the network function consumer is a gNB network element. Alternatively, in future communication systems, any network element capable of implementing the network security function of the terminal may be understood as a network function consumer and a network function producer in the embodiments of the present application.

[0155] The security function entity can run in a corresponding operating environment, which can be a secure environment or a trusted environment, such as a TEE or any environment similar to a TEE that may be used to ensure information security, such as a hardware mediated execution enclave (HMEE), a root of trust (RoT), a hardware root of trust (HRoT), a root of trust for measurement (RTM), a root of trust for storage (RTS), or a root of trust for reporting (RTR). The secure environment (or the security function entity in the secure environment) can allow access to the network function bound to the security function entity. The security function entity can be used to ensure the communication security of the network function entity and prevent the user privacy of the network function entity, such as the user's key, from being stolen due to lateral attacks.

[0156] The security function entity may include a first security function entity and a second security function entity.

[0157] The first security function entity and the network function consumption entity can be deployed in the same hardware environment, such as within the same NFVI. Specifically, they can be located in the same real system (Host OS), or they can be located in different real systems, without limitation. The network function consumption entity can run in the first operating environment, and the first security function entity can run in the second operating environment. Because the first operating environment is a normal environment, such as REE1 described below, and the second operating environment is a secure environment, such as TEE1 described below, the security level of the second operating environment is higher than that of the first operating environment. In other words, the second operating environment is more secure than the first operating environment. For example, the network function generation entity in the first operating environment allows access to other network elements authenticated by the network in which the network function generation entity resides. The first security function entity in the second operating environment only allows access to network functions bound to the first security function entity (such as the network function generation entity). In other words, the first security function entity has stricter access restrictions, and fewer network elements can access the first security function entity. As a result, attackers may be unable to access the first security function entity because they are not bound to the first security function entity, thereby ensuring access security and preventing users' private information from being stolen by attackers.

[0158] The second security function entity and the network function production entity can also be deployed in the same hardware environment, such as within the same NFVI. Specifically, they can be located in the same real system, or in different real systems, without limitation. The network function consumption entity can operate in a third operating environment, and the second security function entity can operate in a fourth operating environment. Because the third operating environment is a normal environment, such as REE2 described below, and the fourth operating environment is a secure environment, such as TEE2 described below, the security level of the fourth operating environment is higher than that of the third operating environment. For example, the network function consumption entity in the third operating environment allows access to other network elements authenticated by the network in which the network function consumption entity resides, while the second security function entity in the fourth operating environment only allows access to network functions bound to the second security function entity (such as the network function consumption entity). In other words, the access restrictions on the second security function entity are stricter, and fewer network elements can access the second security function entity. This prevents attackers from accessing the second security function entity because they are not bound to the second security function entity, thereby ensuring access security and preventing users' private information from being stolen by attackers.

[0159] Figure 4 is a schematic diagram of the architecture of the communication system at the NFVI layer. As shown in Figure 4, the security function entity may include an encryption module, a decryption module, and a generation module. The encryption module may be used to encrypt, sign, or generate a checksum for transmitted plaintext information. The encryption module may be replaced by any other name, such as an execution module. The decryption module may be used to verify and decrypt transmitted ciphertext information. The decryption module may be replaced by any other name, such as a verification module. The generation module may be the execution unit of the chip, which is used to execute an algorithm, such as a KDF algorithm or other hash algorithm, to derive a second key from an input first key. The generation module may be replaced by any other name, such as a derivation module.

[0160] The network function entity may include a virtual machine module, which may be a virtual machine of part or all of the network element, for example, a VNF component (virtual network function component, VNFC) or a VNF component instance (virtual network function component instance, VNFCI). The specific technical implementation may be a virtual machine or container, and the embodiment of the present application does not impose the sole limitation. The virtual machine module can configure the NF configuration (NF profile) for the network function entity to implement the corresponding network function. For example, the NF configuration is the attribute and configuration file of the NF at the 3GPP layer, which contains one or more of the following NFs: the identifier of the network function entity, such as the NF instance ID (NF instance ID), the fully qualified domain name (fully qualified domain name, FQDN), the NF public key, and other contents. The NF configuration can be stored in the virtual machine module in the form of a file or program, or configured to the virtual machine module by the network element.

[0161] It is understood that the virtual machine module is an exemplary name and can be replaced by any other possible name, such as VNFC or VNFCI, without limitation. The security function entity is an exemplary name and can be replaced by any other possible name, without limitation.

[0162] It can also be understood that the security function entity includes an encryption module, a decryption module, and a generation module as an example. The names of these modules can be replaced, and these modules can also be merged with each other to be presented in the form of a smaller number of modules, such as the encryption module and the decryption module are merged into an encryption and decryption module, or the encryption module and the generation module are merged into an encryption processing module, etc., and there is no limitation on this.

[0163] The security function entity may have a security barrier and be separated from the network function entity hardware and / or software, so the network function entity and the security function entity usually interact through a secure interface. The security interface may be a TEE agent entity (TEE agent) or any possible form of communication agent entity similar to the TEE agent entity. Taking the TEE agent entity as an example, the TEE agent entity is usually composed of two parts: a TEE communication agent entity (TEE communication agent) deployed in a secure environment, such as a TEE, and a REE communication agent entity (REE communication agent) deployed in a common environment, such as a REE. In the embodiments of the present application, the functions implemented by the TEE agent entity, unless otherwise specified, can be understood as being implemented by the TEE communication agent entity, or can also be understood as being implemented by the REE communication agent entity, without specific limitation. Since part of the TEE agent entity and the security function entity are both located in a secure environment, in the secure environment, the TEE agent entity and the security function entity can be regarded as a whole, that is, the TEE agent entity can be understood as a part of the function of the security function entity, or the TEE agent entity and the security function entity can also be decoupled and each can be regarded as a separate functional entity.

[0164] For example, a first security interface, such as TEE agent entity 1, is provided within the second operating environment. The first security interface can be an interface that the first security function entity opens to the network function production entity for communication. The first security function entity can communicate and interact with the network function production entity through the first security interface to access the first security function entity. In other words, the first security interface can only be used by authorized network functions. Since an attacker may not have permission to use the first security interface, they cannot access the first security function entity and thus cannot steal the user's private information.

[0165] For another example, a second security interface, such as TEE agent entity 2, is provided within the fourth operating environment. This second security interface can be an interface that the second security function entity opens to the network function production entity for communication. The second security function entity can communicate and interact with the network function production entity through the second security interface to access the second security function entity. In other words, the second security interface is only accessible to authorized network functions. Since an attacker may not have permission to use the second security interface, they cannot access the second security function entity and thus cannot steal the user's private information.

[0166] As shown in Figure 5, the network function production entity can send a second key to the first security function entity. The second key can be a key shared by the network function production entity and the terminal served by the network function production entity. The first security function entity (such as a generation module) can use the first key as the input of the key derivation algorithm, that is, the upper key, perform key derivation, and obtain the first key. That is, the first key can be the output of the key derivation algorithm, that is, the lower key. The first key can be a key shared by the network function consumption entity and the terminal. The first security function entity (such as an encryption module) can also encrypt the second key to obtain ciphertext information, and send the ciphertext information to the network function production entity, so that the network function entity can send the ciphertext information to the network function consumption entity.

[0167] As shown in Figure 6, when the network function consumption entity obtains the above-mentioned ciphertext information, it can send the ciphertext information to the second security function entity. The second security function entity (such as a decryption module) can decrypt the ciphertext information, obtain the first key in plain text, and return the first key to the network function entity.

[0168] It is understandable that the network function production entity may not generate the key shared by the network function consumption entity and the terminal locally, but instead request a more secure operating environment than the first operating environment where the network function production entity resides, such as the first security function entity in the second operating environment, to generate and encrypt the ciphertext information of the key. In this case, if an attacker launches an attack on the network function production entity, the attacker can only obtain the ciphertext information and cannot steal the plaintext key. Alternatively, if an attacker launches an attack on the first security function entity, the attacker will not be able to steal the plaintext key because they cannot access the more secure second operating environment. This can prevent the leakage of the terminal's key and ensure the terminal's communication security.

[0169] It can also be understood that, since the network function production entity may not be aware of the existence of the first security function entity, communication between the network function production entity and the first security function entity can also be considered as communication between the network function production entity and the second operating environment, or access to the second operating environment. Similarly, since the network function consumption entity may also be unaware of the existence of the second security function entity, communication between the network function consumption entity and the second security function entity can also be considered as communication between the network function consumption entity and the fourth operating environment, or access to the fourth operating environment.

[0170] The following method embodiments will specifically introduce the interaction process between the network elements / devices in the above communication system. The communication method provided in the embodiment of the present application can be applied to the above communication system and specifically applied to various scenarios mentioned in the above communication system, which will be described in detail below.

[0171] In a specific scenario, the network function entity may include a security anchor function (SEAF) network element (as a network function consumption entity) and an AUSF network element (as a network function providing entity). The AUSF network element may run in a first operating environment, such as REE1, and the SEAF network element may run in a third operating environment, such as REE2. The AUSF network element and the SEAF network element may be located in different operator networks, such as the AUSF network element is located in the public land mobile network (PLMN) 1, and the SEAF network element is located in PLMN1. In this case, it can also be understood that REE1 and REE2 are also located in different operator networks.

[0172] There may be multiple security function entities, such as security function entity 1 (the first security function entity mentioned above) and security function entity 2 (the second security function entity mentioned above). Security function entity 1 and AUSF network element are deployed in the same hardware environment. Security function entity 1 runs in a second operating environment, which may be TEE1. Security function entity 1 may specifically include an encryption module and a generation module. AUSF network element can interact with security function entity 1 through TEE agent entity 1 (the first security interface mentioned above). Security function entity 2 and SEAF network element are deployed in the same hardware environment. Security function entity 2 runs in a fourth operating environment, which may be TEE2. Security function entity 2 may specifically include a decryption module. SEAF network element can interact with security function entity 2 through TEE agent entity 2 (the second security interface mentioned above).

[0173] The following three scenarios are introduced.

[0174] Scenario 1

[0175] FIG7 is a flow chart of a communication method according to an embodiment of the present application. For example, the generation module of the security function entity 1 can generate a second key (key K) provided by the AUSF network element. AUSF ) generates the first key (the above key K SEAF ). The encryption module of the security function entity 1 can use the public key of the asymmetric key to SEAF Encrypt and obtain ciphertext information (such as cipher_K SEAF ), signs the ciphertext to obtain a signature for the ciphertext. The ciphertext and the signature can be sent by the AUSF network element to the SEAF network element, which then sends them to the decryption module of security function entity 2. If the signature is verified, the decryption module of security function entity 2 decrypts the ciphertext using the private key of the asymmetric key to obtain a first key, which is then returned to the SEAF network element.

[0176] Specifically, as shown in FIG7 , the process of the communication method is as follows:

[0177] S700a, the decryption module pre-configures a verification certificate (Cert(Ksign)) and a private key (sk1) of the asymmetric key.

[0178] The verification certificate can be used to perform signature algorithm verification, or to implement signature verification. For example, the signature algorithm can be the elliptic curve digital signature algorithm (ECDSA) or the commercial cryptography 2 (SM2). The private key of the asymmetric key can be used to perform asymmetric encryption algorithms such as the RSA algorithm and the elliptic curve cryptography (ECC) encryption algorithm to achieve decryption. The private key of the asymmetric key should be used in TEE2 and can also be called the TEE2 private key, or any other possible name.

[0179] S700b, the encryption module pre-configures a signature key (Ksign).

[0180] The signing key can be used to execute the above signing algorithm to obtain a signature.

[0181] The execution order of S700a and S700b is not limited.

[0182] S700c, the AUSF network element sends a capability query message to the SEAF network element.

[0183] The capability query message may be used to request the capabilities of the SEAF network element, which may specifically be security capabilities, or any possible capabilities, without limitation.

[0184] For example, the PLMN1 where the AUSF network element is located is the UE's home public land mobile network (HPLMN), and the PLMN2 where the SEAF network element is located is the UE's visited public land mobile network (VPLMN). The AUSF network element can send the capability query message to indicate that the service network element of the VPLMN needs to have TEE capability to ensure the data security of the UE of the HPLMN.

[0185] The AUSF network element may send a capability query message to the SEAF network element during the process of establishing a TLS connection with the SEAF network element, such as when the TLS connection is started. Alternatively, the AUSF network element may send a capability query message to the SEAF network element when the TLS connection with the SEAF network element is established, such as when the TLS connection is successfully established. Alternatively, the AUSF network element may send a capability query message to the SEAF network element at any possible time, without limitation.

[0186] It can be understood that the capability query message is only an exemplary name and can also be replaced by the name of any other existing message or newly defined message, such as security capability request message or security environment capability request message, etc., without specific limitation.

[0187] S700d, the SEAF network element sends a capability query response message / capability indication message to the AUSF network element.

[0188] The capability query response message / capability indication message may include capability information.

[0189] The capability information may be used to indicate whether the SEAF network element has TEE capability (or TEE environment). TEE capability may refer to the security capability of the SEAF network element to support information processing through a security function entity, or the security capability of the SEAF network element to support information processing in a TEE environment to ensure data security. For example, the capability information may be an information element of one or more bits, and the values ​​or combinations of values ​​of these bits may be used to indicate whether the SEAF network element has TEE capability, that is, whether it supports the security capability of information processing through a security function entity.

[0190] If the SEAF network element has TEE capability, the capability query response message / capability indication message may include the public key of the asymmetric key. The public key of the asymmetric key corresponds to the private key of the above-mentioned asymmetric key, that is, it can be a public-private key pair of the asymmetric key, which can also be called a TEE2 public key, or any other possible naming. Alternatively, if the SEAF network element has TEE capability, the capability query response message / capability indication message may also include indication information for indicating the asymmetric key (that is, the public key of the asymmetric key), which can be called public key indication information. For example, the public key indication information may be an NF identifier (such as NF instance ID), and the NF may be an NF different from the SEAF network element, so that the AUSF network element can obtain the public key of the asymmetric key from the NF based on the NF identifier. For details, please refer to the relevant introduction of S704 below, which will not be repeated here. For another example, the public key indication information may also be the address of the sending end NF, that is, the address of the SEAF network element, so that the AUSF network element can obtain the public key of the asymmetric key from the public key infrastructure (PKI) according to the address of the SEAF network element. For details, please refer to the relevant introduction of S704 below, which will not be repeated here.

[0191] It can be understood that the above-mentioned capability information is an optional information element. For example, in the absence of capability information, whether the capability is available can be implicitly indicated by whether the capability query response message / capability indication message carries the public key of the asymmetric key or public key indication information. Alternatively, the capability query response message / capability indication message can also be replaced with other named messages to indicate whether the SEAF network element has TEE capability through the name of the message. For example, if the SEAF network element sends a capability query success message, it means that the SEAF network element has TEE capability. If the SEAF network element sends a capability query failure message, it means that the SEAF network element does not have TEE capability. In addition, the capability query response message / capability indication message is only an exemplary name, which can also be replaced by the name of any other existing message or newly defined message, such as a secure environment capability feedback message / secure environment capability indication message, etc., without specific limitation.

[0192] It can also be understood that S700c is an optional step, and the SEAF network element can execute S704 by default. For example, the SEAF network element, as a network function consumption entity, requests the AUSF network element, that is, the network function providing entity, to provide additional protection for the information it transmits by executing S704. At this time, the timing of the SEAF network element sending the security environment capability indication message is similar to the above-mentioned S700c, which can be understood by reference and will not be repeated. In the case where S700c is executed, the message sent by the SEAF network element in S700d can be a capability query response message to respond to the capability query message, otherwise, it can be a capability indication message. Of course, regardless of whether S700c is executed, the role of S700d is to provide the public key of the asymmetric key or the public key indication information to the AUSF network element so that the AUSF can provide additional protection for the information it transmits.

[0193] S701: UE sends a registration request message to the SEAF network element.

[0194] S702, the SEAF network element sends a UE authentication message to the AUSF network element.

[0195] S703, the AUSF network element triggers the UE authentication process.

[0196] Among them, the specific implementation of S701-S703 can refer to the relevant introduction in TS33.501, which will not be repeated here.

[0197] S704, the AUSF network element obtains the second key and the public key of the asymmetric key.

[0198] The second key can be a key shared by the AUSF network element and the UE served by the AUSF network element, or can be understood as a key used by the UE for communication. Specifically, it can be a key K AUSF , or any other possible key. In the UE authentication process, the AUSF network element may determine that the UE authentication is successful, such as obtaining it from the UDM network element or the AUSF network element determining it on its own, to trigger the AUSF network element to generate and obtain the second key locally, or obtain the second key from other network elements, such as the UDM network element.

[0199] If the capability query response message / capability indication message carries the public key of an asymmetric key, the AUSF network element can save the public key of the asymmetric key locally after receiving the capability query response message / capability indication message. When the UE authentication is successful, the AUSF network element obtains the public key of the asymmetric key locally. Alternatively, if the capability query response message / capability indication message carries public key indication information, when the UE authentication is successful, the AUSF network element can obtain the public key of the asymmetric key based on the public key indication information. For example, the public key indication information is the NF identifier, and the AUSF network element can obtain the policy of the NF from the NF based on the NF identifier. The policy of the NF contains the public key field of the NF, specifically the public key of the asymmetric key. The AUSF network element can obtain the public key of the asymmetric key from the policy of the NF. For another example, the public key indication information is the address of the sending NF, and the AUSF network element can obtain the public key certificate from the PKI based on the address of the sending NF, and further obtain the public key of the asymmetric key from the public key certificate.

[0200] S705, the AUSF network element sends a UE key generation request message to the TEE proxy entity 1.

[0201] The UE key generation request message can be used to request TEE1 to generate a key shared by the SEAF network element and the UE. For example, the UE key generation request message may include the second key and the public key of the asymmetric key. In addition, the UE key generation request message is only an exemplary name and can be replaced by any other existing message or newly defined message name without specific limitation.

[0202] It can be understood that since S704-S705 are triggered when the UE authentication is successful, it can also be considered that the AUSF network element sends a UE key generation request message to the security function entity 1 when the UE authentication is successful.

[0203] It can also be understood that when the SEAF network element has TEE capability, that is, it supports the security capability of processing information through security function entities, the AUSF network element can trigger S704-S705, which can also be considered as response capability information. The AUSF network element sends a UE key generation request message to the security function entity 1 so that the first key can be generated subsequently using the method of the embodiment of the present application. For details, please refer to the relevant introduction below and will not be repeated here. When the SEAF network element does not have TEE capability, that is, it does not support the security capability of processing information through security function entities, the AUSF network element can also use other methods to generate the first key subsequently. For example, the AUSF network element can generate the first key by itself, that is, using the existing technology, or it can also instruct other network elements other than the security function entity 1 to generate the first key. The specific method is not limited.

[0204] S706, TEE agent entity 1 performs verification on the AUSF network element.

[0205] The TEE proxy entity 1 and the AUSF network element can be deployed on the same real system (Host OS). It can be considered that the TEE proxy entity 1 and the AUSF network element are bound together through a driver program, etc., so that the TEE proxy entity 1 can perform verification of the AUSF network element. If the verification is successful, continue to execute S706, otherwise, the process fails.

[0206] It is understandable that S706 is optional. For example, the TEE proxy entity 1 may assume that the AUSF network element is trustworthy. In this case, S706 is not executed. In addition, the specific implementation principle of the TEE proxy entity 1 performing verification on the AUSF network element can refer to the relevant introduction of Figure 9 below, which will not be repeated here.

[0207] S707, TEE agent entity 1 sends a generation module call request message to the generation module.

[0208] The Generate Module Invocation Request message is used to request the Generation Module to generate a key shared between the SEAF network element and the UE. For example, the Generate Module Invocation Request message may include the second key and the public key of the asymmetric key. Furthermore, the Generate Module Invocation Request message is merely an exemplary name and may be replaced with any other existing message or newly defined message name, without limitation.

[0209] S708: The generation module generates a first key based on the second key.

[0210] The first key may be a key shared by the SEAF network element and the UE served by the SEAF network element, or may be understood as a key used by the UE for communication. Specifically, the first key may be a key K SEAF It should be understood that the first key can be used as a subordinate key of the second key.

[0211] There are many ways for the generation module to generate the first key based on the second key. For example, the generation module can use the second key as an input parameter, execute the KDF algorithm on the input parameter, and derive the first key. Specifically, for a known KDF generation function, such as KDF(), the second key is denoted as K1, the first key is denoted as K2, and K2 = KDF(K1). For another example, the second key can be used as the key of the AES algorithm. The generation module can use a random or preconfigured method to determine a string, such as str, the second key is denoted as K1, the first key is denoted as K2, K2 = AES_K1(str), that is, the first key is the ciphertext obtained by the AES algorithm using the second key to encrypt the string.

[0212] Optionally, the input parameters may also include other parameters, such as the serial number name (SN name) or the message count value (count), etc. These parameters may be carried in the same message as the second key, or may be sent separately by the AUSF network element to the generation module through the TEE proxy entity 1. The information element transmission is more flexible and is not limited in the embodiment of the present application. In addition, the key K is generated. SEAF The specific implementation can also refer to the relevant introduction of "4. Key Generation Function" above, which will not be repeated here.

[0213] S709: The generation module sends an encryption module call request message to the encryption module.

[0214] The encryption module call request message can be used to request that the first key be encrypted. For example, the encryption module call request message can include the first key and the public key of the asymmetric key. It is understandable that the encryption module call request message may not be sent directly to the encryption module by the generation module. For example, the encryption module may also return the first key to the TEE agent entity 1, triggering the TEE agent entity 1 to send the encryption module call request message. Of course, in this case, the TEE agent entity 1 may not send the public key of the asymmetric key to the generation module in advance. In addition, the encryption module call request message is only an exemplary name, and it can also be replaced by the name of any other existing message or newly defined message, without specific limitation.

[0215] S710: The encryption module encrypts and signs the first key.

[0216] The encryption module may use the public key of the asymmetric key to perform an asymmetric encryption algorithm, such as an RSA algorithm or ECC, on the first key and some optional plaintext parameters to obtain ciphertext information.

[0217] The specific selection of the RSA algorithm or ECC by the encryption module can be pre-configured, or dynamically determined by the encryption module, such as determining to use different algorithms based on different message names. In addition, the embodiments of the present application do not limit the specific implementation of the plaintext parameters, which can be any possible parameters required for encryption. The plaintext parameters can be carried in the same message as the first key, or can be obtained by the encryption module separately from the generation module or any other possible module before encryption, which is not limited by the embodiments of the present application.

[0218] The encryption module can perform a signature on the ciphertext to obtain a signature (K2 signature) of the ciphertext, which can be a string or data. For example, the encryption module can use the signature key to perform a signature algorithm, such as ECDSA or SM2, on the ciphertext to obtain the signature of the ciphertext.

[0219] S711, the encryption module sends an encryption module call response message to the generation module.

[0220] The encryption module call response message may be used to respond to the encryption module call request message, such as carrying ciphertext information and a signature of the ciphertext information.

[0221] S712, the generation module sends a generation module call response message to the TEE agent entity 1.

[0222] The Generate Module Call Response message can be used to respond to the Generate Module Call Request message, for example, carrying ciphertext information and the signature of the ciphertext information. In other words, the Generate Module can obtain the ciphertext information and the signature of the ciphertext information from the Cryptographic Module Call Response message and encapsulate them into the Generate Module Call Response message.

[0223] It can be understood that if the TEE proxy entity 1 directly sends an encryption module call request message to the encryption module, the encryption module can also directly respond to the TEE proxy entity 1, such as sending an encryption module call response message. In this case, S712 is not executed, and S713 is executed after S711.

[0224] S713, TEE proxy entity 1 sends a UE key generation response message to the AUSF network element.

[0225] The UE key generation response message can be used to respond to the UE key generation request message, such as carrying ciphertext information and the signature of the ciphertext information. In other words, the TEE agent entity 1 can obtain the ciphertext information and the signature of the ciphertext information from the generation module call response message and encapsulate them into the UE key generation response message.

[0226] It can be understood that for the above S705-S713, the interaction between the TEE agent entity 1, the generation module, and the encryption module can be understood as being performed as a whole by the security function entity 1, that is, the security function entity 1 executes S705-S713, or it can be understood as the interaction between the TEE agent entity 1 and the security function entity 1 (including the generation module and the encryption module). In addition, the above example uses the security function entity 1 including the generation module and the encryption module as an example. The security function entity 1 can also include other modules, such as a decryption module.

[0227] S714, the AUSF network element sends a UE authentication success message to the SEAF network element.

[0228] The UE authentication success message can be used to respond to the UE authentication message, indicating that the two-way authentication between the UE and the network is successful. The UE authentication success message may include ciphertext information and the signature of the ciphertext information, that is, the AUSF network element can reuse the existing messages of the authentication process, and pass the ciphertext information and the signature of the ciphertext information obtained from the UE key generation response message to the SEAF network element through the UE authentication success message. Alternatively, the AUSF network element can also reuse the newly defined message implementation, such as carrying the ciphertext information and the signature of the ciphertext information in the UE key transfer message sent to the SEAF network element. Of course, the UE key transfer message is only an exemplary name, which can also be replaced by any other possible name, without specific limitation.

[0229] S715 , the SEAF network element sends a UE key decryption request message to the TEE proxy entity 2 .

[0230] The UE key decryption request message can be used to request TEE2 to decrypt the ciphertext of the key used for UE communication. For example, the UE key decryption request message may include ciphertext information and the signature of the ciphertext information. In other words, the SEAF network element can obtain the ciphertext information and the signature of the ciphertext information from the UE authentication success message and encapsulate them into the UE key decryption request message. Of course, the UE key decryption request message is only an exemplary name and can be replaced by any other possible name without specific limitation.

[0231] S716, TEE agent entity 2 performs verification on the SEAF network element.

[0232] The TEE agent entity 2 and the SEAF network element can also be deployed on the same real system (Host OS). It can also be considered that the TEE agent entity 2 and the SEAF network element are bound through a driver, etc., so that the TEE agent entity 2 can perform verification of the SEAF network element. If the verification is successful, continue to S717; otherwise, the process fails.

[0233] It is understood that S716 is optional. For example, the TEE agent entity 2 may assume that the SEAF network element is trustworthy. In this case, S716 is not executed. In addition, the specific implementation principle of the TEE agent entity 2 performing verification on the SEAF network element can be referred to the relevant description of Figure 10 below, which will not be repeated here.

[0234] S717, TEE agent entity 2 sends a decryption module call request message to the decryption module.

[0235] The decryption module call request message can be used to request the decryption module to decrypt the ciphertext of the key used for UE communication. For example, the decryption module call request message may include the ciphertext information and the signature of the ciphertext information. In other words, the TEE agent entity 2 can obtain the ciphertext information and the signature of the ciphertext information from the UE key decryption request message and encapsulate them into the decryption module call request message.

[0236] In addition, the UE key decryption request message is only an exemplary name, or it can be replaced by the name of any other existing message or newly defined message, without specific limitation.

[0237] S718: The decryption module performs signature verification and decryption.

[0238] The decryption module can perform signature verification on the signature of the ciphertext information. For example, the decryption module can use the verification certificate to perform signature algorithm verification on the signature of the ciphertext information. If the verification fails, the process fails. At this time, the decryption module can inform the SEAF network element through the TEE agent entity 2, triggering the SEAF network element to request the AUSF network element to regenerate the key shared by the SEAF network element and the UE, that is, return to execute S705, or the process ends. If the verification passes, the decryption module can decrypt the ciphertext information. For example, the decryption module can use the private key of the asymmetric key to perform an asymmetric encryption algorithm on the ciphertext information, such as the RSA algorithm or ECC, to obtain the first key of the plaintext. Among them, the specific selection of the RSA encryption algorithm or ECC by the decryption module can be pre-configured, or the decryption module can determine it dynamically, such as determining to use different algorithms according to different message names.

[0239] It can be understood that the above is an example of transmitting ciphertext information and signature together. The transmission of ciphertext information and signature can also be coupled, and each is independently transmitted from the generation module to the decryption module in sequence.

[0240] S719, the decryption module sends a decryption module call response message to TEE agent entity 2.

[0241] The decryption module call response message may be used to respond to the decryption module call request message. For example, the decryption module call response message may carry the first key.

[0242] S720, TEE agent entity 2 sends a UE key decryption response message to the SEAF network element.

[0243] The UE Key Decryption Response message can be used to respond to the UE Key Decryption Request message. For example, the UE Key Decryption Response message can include the first key. That is, the TEE agent entity 2 can obtain the first key from the decryption module call response message and encapsulate it into the UE Key Decryption Response message. In this way, the SEAF network element can obtain the first key and trigger subsequent processes, such as sending an N1 message to the UE to indicate that the UE registration is successful.

[0244] It can be understood that for the above S715-S720, the interaction between the TEE proxy entity 2 and the decryption module can be understood as being performed as a whole by the security function entity 2, that is, the security function entity 2 performs S715-S720, or it can also be understood as the interaction between the TEE proxy entity 2 and the security function entity 2 (including the decryption module). In addition, the above example uses the security function entity 2 including the decryption module as an example. The security function entity 2 can also include other modules, such as a generation module and an encryption module.

[0245] Scenario 2:

[0246] FIG8 is a flow chart of the communication method according to an embodiment of the present application. For example, the generation module of the security function entity 1 can generate a second key (key K) according to the second key provided by the AUSF network element. AUSF ) Generate the first key (key K SEAF The encryption module of the security function entity 1 can use the symmetric key to encrypt the first key to obtain the ciphertext information (cipher_K SEAF ). The encrypted information can be sent by the AUSF network element to the SEAF network element, and then sent by the SEAF network element to the decryption module of the security function entity 2. The decryption module can use the symmetric key to decrypt the encrypted information to obtain the first key and return it to the SEAF network element.

[0247] Specifically, as shown in FIG8 , the process of the communication method is as follows:

[0248] S800a: The decryption module pre-configures a symmetric key.

[0249] The symmetric key (also known as the key KTEE) can be used to perform decryption of a symmetric encryption algorithm to achieve decryption. The symmetric encryption algorithm can be the ZUC algorithm (Zuc Stream Cipher, ZUC), the Commercial Cryptography Algorithm 4 (Shangmi4, SM4) algorithm, or the Advanced Encryption Standard (AES) algorithm.

[0250] S800b, the encryption module pre-configures a symmetric key.

[0251] The symmetric key of S800b can be matched with the symmetric key of S800a and can be used to execute a symmetric encryption algorithm to achieve encryption.

[0252] Afterwards, when the AUSF network element establishes a TLS connection with the SEAF network element, S801 is executed.

[0253] S801: UE sends a registration request message to the SEAF network element.

[0254] S802, the SEAF network element sends a UE authentication message to the AUSF network element.

[0255] The UE authentication message can be used to indicate the information of the SEAF network element, which is recorded as the network function consuming entity's information #1. For example, the network function consuming entity's information #1 can be explicitly indicated by the UE authentication message. Exemplarily, the network function consuming entity's information #1 is the NF configuration, which can specifically include at least one of the following information: the NF ID (SEAF network element ID), or the NF type (SEAF network element type), etc. The SEAF network element can directly carry this information. Alternatively, the network function consuming entity's information #1 can also be implicitly indicated by the UE authentication message. Exemplarily, the UE authentication message can include the name of the message or the source address of the message. The AUSF network element can determine, based on the name of the message, that the network element requested by the other party should be the SEAF network element, and obtain the ID of the SEAF network element pre-configured locally.

[0256] S803, the AUSF network element triggers the UE authentication process.

[0257] In addition, the specific implementation of S801-S803 can also refer to the relevant introduction in TS33.501, which will not be repeated here.

[0258] S804, the AUSF network element obtains the second key.

[0259] The specific implementation principle of the AUSF network element obtaining the second key can refer to the relevant introduction in the above S704 and will not be repeated here.

[0260] S805, the AUSF network element sends a UE key generation request message to the TEE proxy entity 1.

[0261] The UE key generation request message can be used to request TEE1 to generate a key shared by the SEAF network element and the UE. For example, the UE key generation request message may include the second key and information about the SEAF network element, recorded as information #2 of the network function consuming entity. Information #2 of the network function consuming entity may be the same information as information #1 of the network function consuming entity, or may be different information. For example, information #1 of the network function consuming entity may be the NF configuration, and information #2 of the network function consuming entity may be the ID of the SEAF network element. That is, the AUSF network element may determine at least part of the information in information #1 of the network function consuming entity as information #2 of the network function consuming entity.

[0262] S806, TEE agent entity 1 performs verification on the AUSF network element.

[0263] The specific implementation principle of S806 is similar to that of the above-mentioned S706. Please refer to the relevant introduction of Figure 9 below, and will not be repeated here.

[0264] S807, TEE agent entity 1 sends a generation module call request message to the generation module.

[0265] The generation module invocation request message may be used to request the generation module to generate a key shared by the SEAF network element and the UE. For example, the generation module invocation request message may include the second key.

[0266] S808: The generation module generates a first key based on the second key.

[0267] The specific implementation principle of S808 is similar to that of the above-mentioned S708, which can be understood by reference and will not be repeated here.

[0268] S809, the generation module sends a generation module call response message to the TEE agent entity 1.

[0269] The generation module call response message may be used to respond to the generation module call request message, such as including the first key.

[0270] S810, TEE agent entity 1 sends an encryption module call request message to the encryption module.

[0271] The encryption module call request message can be used to request the encryption module to encrypt the key used for UE communication, such as information #2 including the first key and the network function consumption entity.

[0272] It should be understood that the aforementioned method of the generation module first returning the first key to TEE agent entity 1, and then having TEE agent entity 1 send the encryption module call request message to the encryption module, is merely an example. For example, if TEE agent entity 1 has previously sent the network function consumer entity's information #2 to the generation module, the generation module can directly send the encryption module call request message after generating the first key.

[0273] S811, the encryption module encrypts the first key to obtain ciphertext information.

[0274] The encryption module can use the symmetric key and the information #2 of the network function consumption entity to perform a symmetric encryption algorithm on the first key, such as the ZUC algorithm, the SM4 algorithm or the AES algorithm, to obtain ciphertext information. For example, the encryption module can determine (such as deduce) the key used for encryption based on the symmetric key and the information #2 of the network function consumption entity, and record it as the encryption key (KNF). Exemplarily, the encryption module can use the symmetric key and the information #2 of the network function consumption entity as input parameters, and perform the KDF algorithm on the input parameters to obtain the encryption key. It can be understood that the input parameters can also include any other possible parameters, and this is not limited. Alternatively, the encryption module can also call the generation module to generate an encryption key, such as sending the symmetric key and the information #2 of the network function consumption entity to the generation module to receive the encryption key returned by the generation module. In this way, the encryption module can use the encryption key to perform a symmetric encryption algorithm on the first key to obtain ciphertext information.

[0275] Optionally, the encryption module may also perform integrity protection on the ciphertext information to obtain a message authentication code (MAC) #1. For example, the encryption module may use the encryption key and ciphertext information as input parameters and perform an integrity protection algorithm on the input parameters to obtain MAC #1. For another example, the encryption module may use the network function consumer entity's information #2 and ciphertext information as input parameters and perform an integrity protection algorithm on the input parameters to obtain MAC #1. Furthermore, the input parameters for the integrity protection algorithm may include other parameters, which are not limited in the embodiments of the present application.

[0276] S812, the encryption module sends an encryption module call response message to TEE agent entity 1.

[0277] The encryption module call response message may be used to respond to the encryption module call request message. For example, the encryption module call response message carries ciphertext information and MAC#1.

[0278] It can be understood that if the above is that the generation module directly sends an encryption module call request message to the encryption module, the encryption module can first send an encryption module call response message carrying ciphertext information and MAC#1 to the generation module, and then the generation module sends the generation module call request message carrying ciphertext information and MAC#1 to TEE agent entity 1.

[0279] S813, TEE proxy entity 1 sends a UE key generation response message to the AUSF network element.

[0280] The UE Key Generation Response message can be used to respond to the UE Key Generation Request message. For example, the UE Key Generation Response message carries ciphertext information and MAC#1. That is, TEE agent entity 1 can obtain the ciphertext information and MAC#1 from the Generation Module Call Response message and encapsulate them into the UE Key Generation Response message.

[0281] It is understood that for the above S805-S813, the interaction between the TEE agent entity 1, the generation module, and the encryption module can be understood as being performed as a whole by the security function entity 1, that is, the security function entity 1 executes S805-S813, or it can be understood as the interaction between the TEE agent entity 1 and the security function entity 1 (including the generation module and the encryption module). In addition, the above example uses the security function entity 1 including the generation module and the encryption module as an example. The security function entity 1 can also include other modules, such as a decryption module.

[0282] S814, the AUSF network element sends a UE authentication success message to the SEAF network element.

[0283] The UE authentication success message may include ciphertext information and MAC#1. For the specific implementation principle, please refer to the relevant introduction of S714 above, which will not be repeated here.

[0284] S815, the SEAF network element sends a UE key decryption request message to the TEE proxy entity 2.

[0285] The UE key decryption request message can be used to request TEE2 to decrypt the ciphertext of the key used for UE communication. For example, the UE key decryption request message may include ciphertext information and MAC#1.

[0286] It can be understood that since TEE1 needs to use the information #2 of the network function consumption entity to generate ciphertext information, which is known in advance by the SEAF network element, such as pre-configuration or protocol pre-definition, in order to ensure that TEE2 can successfully decrypt the ciphertext information, the SEAF network element can also send the information #2 of the network function consumption entity to the TEE agent entity 2, such as sending it together with the ciphertext information and MAC #1, or sending it separately, without limitation.

[0287] S816, TEE agent entity 2 performs verification on the SEAF network element.

[0288] The specific implementation principle of S816 is similar to that of the above-mentioned S806. Please refer to the relevant introduction of Figure 10 below, and will not be repeated here.

[0289] S817, TEE agent entity 2 sends a decryption module call request message to the decryption module.

[0290] The decryption module call request message can be used to request the decryption module to decrypt the ciphertext of the key used for UE communication. For example, the decryption module call request message can include ciphertext information and MAC#1. In other words, TEE agent entity 2 can obtain the ciphertext information and MAC#1 from the UE key decryption request message and encapsulate them into the decryption module call request message.

[0291] Optionally, the decryption module calling request message may further include the information #2 of the network function consuming entity, or the information #2 of the network function consuming entity may also be delivered to the decryption module separately through other messages.

[0292] S818: The decryption module performs decryption.

[0293] The decryption module can use the symmetric key and the network function consumer entity's information #2 to perform a symmetric encryption algorithm, such as the ZUC algorithm, the SM4 algorithm, or the AES algorithm, on the ciphertext information to obtain the first key for the plaintext. For example, the decryption module can generate the decryption key used for decryption based on the symmetric key and the network function consumer entity's information #2. Exemplarily, the decryption module can use the symmetric key and the network function consumer entity's information #2 as input parameters, perform a KDF algorithm on the input parameters, and obtain a decryption key (such as the key KNF, which matches the above-mentioned encryption key). Alternatively, the decryption module can also call a generation module (different from the above-mentioned generation module, the generation module called by the decryption module is the generation module of TEE2) to generate the decryption key, such as sending the symmetric key and the network function consumer entity's information #2 to the generation module of TEE2 to receive the decryption key returned by the generation module of TEE2. In this way, the decryption module can use the decryption key to perform a symmetric encryption algorithm on the ciphertext information to obtain the first key for the plaintext.

[0294] Optionally, if the decryption module obtains MAC#1, the decryption module may first use MAC#1 to perform an integrity check on the ciphertext information. If the check passes, decryption is performed; otherwise, the process fails. For example, the decryption module may use the encryption key and ciphertext information as input parameters, and perform an integrity protection algorithm on the input parameters to obtain MAC#2. For another example, the decryption module may also use the network function consumer entity's information #2 and ciphertext information as input parameters, and perform an integrity protection algorithm on the input parameters to obtain MAC#2. The encryption key or the network function consumer entity's information #2 may be pre-configured locally in the decryption module, or the decryption module may obtain it in advance from another network element, such as a SEAF network element. The decryption module may use MAC#2 to perform an integrity check, such as verifying whether MAC#2 is consistent with MAC#1. If MAC#2 is consistent with MAC#1, the integrity check passes; otherwise, the integrity check fails.

[0295] It can be understood that the integrity check performed by the decryption module is only an example and is not intended to be limiting.

[0296] For example, when the SEAF network element obtains the ciphertext information and MAC#1, the SEAF network element can use the decryption key and the ciphertext information to generate MAC#2 and perform integrity verification. At this time, the decryption key can be a node-level key for the SEAF network element, specifically the key currently used by the SEAF network element, which is used by the SEAF network element to perform verification. The decryption key can be derived by the SEAF network element based on the pre-configured local symmetric key and the network function consumer entity's information #2, or it can be pre-configured directly in the SEAF network element, or the SEAF network element can obtain it from other network elements in advance, such as from a third-party PKI based on the ID of the AUSF network element.

[0297] For another example, the integrity verification performed by the decryption module in S818 is an example and is not intended to be limiting. The integrity verification may also be performed by the SEAF network element in S815. For example, in S811, the encryption module may not use the symmetric key shared by TEE1 and TEE2 when generating MAC#1. For example, the encryption module may use the secure hash algorithm 1 (SHA-1) or other similar algorithms to calculate the ciphertext information to obtain MAC#1. Then, in S815, the SEAF network element may use the secure hash algorithm 1 (SHA-1) or other similar algorithms to calculate the ciphertext information obtained by the SEAF network element to obtain MAC#2. In this way, the SEAF network element can verify whether MAC#2 is consistent with MAC#1. If MAC#2 is consistent with MAC#1, the integrity check passes; otherwise, the integrity check fails. In the event that the integrity check fails, the SEAF network element returns a failure message to the AUSF network element, so that the AUSF network element ends the process, or returns to execute S805 and re-requests to generate a key shared by the SEAF network element and the UE.

[0298] S819, the decryption module sends a decryption module call response message to TEE agent entity 2.

[0299] S820, TEE proxy entity 2 sends a UE key decryption response message to the SEAF network element.

[0300] Among them, the specific implementation principles of S819-S820 can refer to the relevant introduction of S719-S720 above, which will not be repeated here.

[0301] It is understood that the above is an example of transmitting ciphertext information and MAC#1 together. The transmission of ciphertext information and MAC#1 can also be coupled, and each is independently transmitted from the generation module to the decryption module in sequence.

[0302] It can be understood that for the above S815-S820, the interaction between the TEE proxy entity 2 and the decryption module can be understood as being performed entirely by the security function entity 2, that is, the security function entity 2 executes S815-S820, or it can also be understood as the interaction between the TEE proxy entity 2 and the security function entity 2 (including the decryption module). In addition, the above example uses the security function entity 2 including the decryption module as an example. The security function entity 2 can also include other modules, such as a generation module and an encryption module.

[0303] Scenario 3:

[0304] Figure 9 is a flow chart of the communication method provided in an embodiment of the present application. For example, scenario 3 can be implemented in combination with scenario 1 or scenario 2. The AUSF network element can be registered with the TEE proxy entity 1 in advance. In scenario 1 or scenario 2, if the AUSF network element requests the security function entity 1 to generate a key for the UE, the TEE proxy entity 1 can verify the AUSF network element to determine whether the AUSF network element is trustworthy.

[0305] Specifically, as shown in FIG9 , the process of the communication method is as follows:

[0306] S900: AUSF network element is instantiated.

[0307] As a VNF, the AUSF network element can be instantiated by a virtual management system such as operation administration and maintenance (OAM) to receive or generate the NF configuration of the AUSF network element from the virtual management system (recorded as NF configuration #1). The NF configuration #1 can be used for the AUSF network element to implement the corresponding network function. The specific implementation principle can also refer to the relevant introduction of the above NF configuration, which will not be repeated here. NF configuration #1 can be configured to the VNF component associated with the AUSF network element in the NFVI, such as VNFC1. The VNFC1 can be the VNFC used by the AUSF network element to interact with the TEE agent entity 1, and VNFC1 can also be understood as part or all of the AUSF network element. Of course, NF configuration #1 may also be configured to other VNFCs associated with the AUSF network element in the NFVI, or to the AUSF network element locally, and there is no limitation on this.

[0308] S901, the AUSF network element sends a TEE binding request message #1 to VNFC1.

[0309] TEE Binding Request Message #1 is used to request the TEE to bind the AUSF network element. For example, TEE Binding Request Message #1 may include NF Configuration #1. For example, the AUSF network element may obtain NF Configuration #1 from the AUSF network element locally or from another VNFC and include it in the TEE Binding Request Message. Alternatively, if NF Configuration #1 is pre-configured locally in VNFC1, TEE Binding Request Message #1 may not include NF Configuration #1.

[0310] S902, VNFC1 sends TEE binding request message #2 to TEE proxy entity 1.

[0311] TEE binding request message #2 may include the NF configuration of the AUSF network element (denoted as NF configuration #2). NF configuration #2 may be the same as NF configuration #1, or may be different, such as NF configuration #2 is part of the information of NF configuration #1, such as the identifier of the AUSF network element.

[0312] Optionally, TEE binding request message #2 may also include inherent information of VNFC1, such as inherent registration information. The inherent registration information of VNFC1 is information that is unique to VNFC1 and is generally not imitable by an adversary. For example, the inherent registration information of VNFC1 is the instantiation random serial number generated by VNFC during the instantiation process. For another example, the inherent registration information of VNFC1 may be some operating parameters of VNFC1 during operation, such as the port number occupied by VNFC1 during the communication process, which cannot be occupied by other VNFCs after being occupied by VNFC1, or one or more information such as the process ID of VNFC1 or the real hash value of VNFC1. This information generally does not change before the instance is destroyed and is also difficult to be modified by other abnormal VNFCs or malicious processes.

[0313] S903, TEE agent entity 1 registers the AUSF network element.

[0314] The TEE proxy entity 1 may record the NF configuration #2 of VNFC1. Optionally, when the inherent registration information of VNFC1 is obtained, the TEE proxy entity 1 may also record the inherent registration information of VNFC1.

[0315] Afterwards, S701-S705 of scenario 1 or S801-S805 of scenario 2 are executed.

[0316] S904, TEE agent entity 1 performs verification on the AUSF network element.

[0317] S904 is equivalent to S706 in Scenario 1 or S806 in Scenario 2. TEE proxy entity 1 can verify whether the AUSF network element that sent the UE key generation request message is the AUSF network element registered in S903. For example, TEE proxy entity 1 can determine whether the NF configuration carried in the UE key generation request message is NF configuration #2 recorded in S903. Optionally, TEE proxy entity 1 can also obtain VNFC's inherent registration information based on the UE key generation request message, such as obtaining the VNFC's inherent registration information corresponding to the UE key generation request message from NFVI, and determine whether the VNFC's inherent registration information is the inherent registration information of VNFC1 recorded in S903. If the NF configuration carried in the UE key generation request message is NF configuration #2, and the VNFC's inherent registration information corresponding to the UE key generation request message is the inherent registration information of VNFC1 (optional), then TEE proxy entity 1 succeeds in verifying the AUSF network element; otherwise, verification fails. Because VNFC1's inherent registration information is not easily counterfeited or stolen by other network elements, the security of the verification process is improved. Of course, using the inherent registration information of VNFC1 for verification is only an exemplary implementation method. Any information of VNFC1 that is difficult to be counterfeited or stolen by other network elements can be used in the solution of this application.

[0318] It is understandable that the UE key generation request message may also carry an information element for indicating verification, and the TEE proxy entity 1 triggers verification of the AUSF network element based on the information element. Alternatively, the UE key generation request message may also not carry the information element, and the TEE proxy entity 1 performs verification on the AUSF network element by default.

[0319] If the verification is successful, continue with the subsequent process of scenario 1 or scenario 2.

[0320] Optionally, in combination with scenario 2, if the verification is passed, the TEE agent entity 1 can send a key indication to the encryption module, such as carried in the generation module call response message of the above S809, or sent to the encryption module separately to indicate that the key used for encryption by the encryption module is a symmetric key.

[0321] Scenario 4:

[0322] Figure 10 is a fourth flow chart of the communication method provided in an embodiment of the present application. For example, scenario 4 can be implemented in combination with scenario 1 or scenario 2. The SEAF network element can be registered with the TEE agent entity 2 in advance. In scenario 1 or scenario 2, if the SEAF network element requests the security function entity 2 to perform decryption, the TEE agent entity 2 can verify the SEAF network element to determine whether the SEAF network element is trustworthy.

[0323] Specifically, as shown in FIG10 , the process of the communication method is as follows:

[0324] S1000: The SEAF network element is instantiated.

[0325] S1001, SEAF network element sends TEE binding request message #3 to VNFC2.

[0326] S1002, VNFC2 sends TEE binding request message #4 to TEE proxy entity 2.

[0327] S1003, TEE agent entity 2 registers the SEAF network element.

[0328] S1004, TEE agent entity 2 performs verification on the SEAF network element.

[0329] Among them, the specific implementation of S1000-S1004 is similar to that of S900-S904, which can be referred to for understanding and will not be repeated here.

[0330] The above describes in detail the process of the communication method in specific scenarios in conjunction with Figures 7 to 10. The following describes the overall process of the communication method in conjunction with Figure 11.

[0331] Figure 11 is a flow chart 5 of the communication method provided in an embodiment of the present application. This communication method is applicable to the above-mentioned communication system and involves interaction between a network function production entity, a network function consumption entity, and a first security function entity.

[0332] Specifically, as shown in FIG11 , the process of the communication method is as follows.

[0333] S1101: A network function production entity serving a terminal sends a first message to a first security function entity. Correspondingly, the first security function entity receives the first message from the network function production entity.

[0334] The network function production entity and the first security function entity (such as the security function entity 1 mentioned above) are deployed in the same hardware environment. The network function production entity runs in the first operating environment, and the first security function entity runs in the second operating environment. The security level of the second operating environment is higher than the security level of the first operating environment. The specific implementation principle can refer to the relevant introduction in the above communication system, and will not be repeated here.

[0335] The first message can be used to request the generation of a key shared by the network function consuming entity and the terminal for the network function consuming entity serving the terminal. The first message can specifically be the above-mentioned UE key generation request message, or any other possible named message, which is not specifically limited. For example, the first message can specifically be used to request the use of a second key to generate a key shared by the network function consuming entity and the terminal for the network function consuming entity serving the terminal. The second key is a key shared by the network function producing entity and the terminal. In one possible manner, the first message may include the second key. For example, the network function producing entity is an AUSF network element, and the second key may be the key K obtained by the AUSF network element in the authentication process of the terminal. AUSF , AUSF network element and terminal share the key K AUSF . The AUSF network element can send a first message to the first security function entity when the terminal authentication is passed. That is, the derivation and encryption scheme performed by the first security function entity can be reused in the existing authentication process to further enhance the security of the existing process, or can also be applied to newly defined processes in the future, without limitation.

[0336] As can be seen, the second key can be provided by the network function production entity to the first security function entity as an input parameter for key derivation. In this case, even if an attacker steals the second key, they cannot learn from the first security function entity how the second key is used in the derivation process and therefore cannot determine the derived key. Of course, the second key can also be stored in the first security environment by default, and the first message can carry information indicating the second key, which the first security function entity can use to obtain the second key.

[0337] An optional way of delivering the first message is: the network function production entity can send the first message to the first security function entity through the first security interface, and the first security function entity can receive the first message from the network function production entity through the first security interface. The first security interface (such as the above-mentioned TEE agent entity 1) is an interface opened by the first security function entity to the network function production entity for communication, that is, the first security interface can only be used by authorized network functions. Since the attacker does not have the right to use the first security interface, he cannot access the first security function entity and cannot steal the key of the terminal. Alternatively, the first message can also be delivered in any other possible way, for example, the network function production entity directly sends the first message to the first security function entity without going through the security interface.

[0338] It can be understood that the specific implementation principle of the first message can also refer to the relevant introduction of S705 / S805 above, which will not be repeated here.

[0339] Optionally, the first message may also include a public key of an asymmetric key, which is used to encrypt a key shared by the network function consuming entity and the terminal. For example, before S1101, the network function consuming entity may also send the public key of the asymmetric key to the network function producing entity (such as through a TSL connection that has been established between the network function consuming entity and the network function producing entity), and accordingly, the network function producing entity may receive the public key of the asymmetric key from the network function consuming entity. Alternatively, the network function consuming entity sends (through the TSL connection) indication information for obtaining an asymmetric key (such as the above-mentioned public key indication information) to the network function producing entity, and the network function producing entity obtains the public key of the asymmetric key based on the indication information received from the network function producing entity. That is, the public key of the asymmetric key can be provided on demand by the network function consuming entity without the need for maintenance by the network function producing entity, so as to reduce the overhead of the network function producing entity. The public key of the asymmetric key or the instruction information for obtaining the asymmetric key can be carried in any possible message exchanged between the network function consuming entity and the network function consuming entity. A specific implementation principle can be referred to the relevant description of S700c-700d and S704 above, and will not be repeated here. In this way, the network function producing entity can send the public key of the asymmetric key to the first security function entity by carrying it in the first message, or the public key of the asymmetric key can also be carried in other messages sent by the network function producing entity to the first security function entity, thereby achieving decoupling from the first message.

[0340] Alternatively, the network function production entity may also send indication information for obtaining an asymmetric key to the first security function entity, such as a first message carrying the indication information of the asymmetric key, or any other possible message carrying the indication information, so that the first security function entity can obtain the public key of the asymmetric key based on the indication information. The specific acquisition method is similar to that of the network function production entity, and you can refer to it for understanding and will not repeat it here.

[0341] Optionally, the first message may also include information about the network function message entity (such as the information #2 of the network function message entity described above). For example, before S1101, the network function consuming entity may also send information about the network function message entity (the information #1 of the network function message entity described above) to the network function producing entity (such as through a TSL connection that has been established between the network function consuming entity and the network function producing entity). Accordingly, the network function producing entity receives information about the network function message entity from the network function consuming entity. That is, the information about the network function message entity may also be provided on demand by the network function consuming entity without the need for maintenance by the network function producing entity, and the overhead of the network function producing entity may also be reduced. It is understandable that the information #1 of the network function message entity may be the same as the information #2 of the network function message entity. If the information #1 of the network function message entity and the information #2 of the network function message entity are different information, the network function producing entity may obtain the information #2 of the network function message entity based on the information #1 of the network function message entity, such as obtaining the information #2 of the network function message entity from the information #1 of the network function message entity. The information of the network function message entity can be carried in any possible message exchanged between the network function consuming entity and the network function consuming entity. A specific implementation principle can be referred to the relevant description of S802 and S804 above, which will not be repeated here. In this way, the network function producing entity can carry the information of the network function message entity in the first message and send it to the first security function entity, or the information of the network function message entity can also be carried in other messages sent by the network function producing entity to the first security function entity, thereby achieving decoupling from the first message.

[0342] S1102 : In response to the first message, the first security function entity generates a first key shared by the network function consuming entity serving the terminal and the terminal.

[0343] In response to the first message, the first security function entity may generate the first key based on the second key. For example, the first security function entity may use the first key as an input parameter (which may be a portion of the input parameter) to perform key derivation to obtain the second key. The specific implementation principle can be referred to the relevant description in S707-S708 above, or the relevant description in S807-S809, and will not be repeated here.

[0344] S1103: The first security function entity determines the ciphertext information based on the first key.

[0345] The first security function entity may directly encrypt the first key to obtain ciphertext information, or the first security function entity may use the first key in an encryption operation to obtain ciphertext information.

[0346] In one possible method, when the first security function entity obtains the public key of the asymmetric key, the first security function entity can use the public key of the asymmetric key to encrypt the first key to obtain ciphertext information. The specific implementation principle can be referred to the relevant introduction in S709-S712 above, and will not be repeated here.

[0347] In another possible approach, when the first security function entity obtains information about the network function message entity, the first security function entity may use a symmetric key preconfigured by the first security function entity and information about the network function consumer entity to encrypt the first key to obtain ciphertext information. For example, the first network security entity may also derive an encryption key based on the symmetric key and information about the network function consumer entity, and use the encryption key to encrypt a second key to obtain ciphertext information, thereby increasing the complexity of the encryption and further improving the security of the encryption. The specific implementation principles can be found in the relevant descriptions in S810-S912 above and will not be repeated here. Of course, the first network security entity may also use other encryption methods, such as using only a symmetric key to encrypt the first key to obtain ciphertext information, and the specific implementation is not limited.

[0348] It can be seen that the first security function entity can select the encryption method according to the received information, such as selecting asymmetric encryption according to the key of the received asymmetric key, or selecting symmetric encryption according to the information received from the network function message entity. In this way, the overhead caused by indicating the encryption method can be avoided and the communication efficiency can be improved.

[0349] It can be understood that in S1102-S1103, the first security function entity performs the above-mentioned key deduction and encryption, which can be performed by different modules in the first security function entity, or can be performed by the same module in the first security function entity. There is no limitation on this. For the specific implementation principles, please refer to the relevant introduction of S707-S712, or refer to the relevant introduction of S807-S812, which will not be repeated here.

[0350] S1104: The first security function entity sends a second message to the network function production entity. Correspondingly, the network function production entity receives the second message from the first security function entity.

[0351] The second message may include ciphertext information to respond to the first message. For example, the second message may be the aforementioned UE key generation response message, or any other message that may be named, which is not specifically limited.

[0352] An optional method for transmitting the second message is as follows: the first security function entity may send the second message to the network function production entity via the first security interface, and the network function production entity may receive the second message from the first security function entity via the first security interface. Alternatively, the second message may be transmitted via any other possible method, for example, the first security function entity may send the second message directly to the network function production entity without using the security interface.

[0353] S1105 , the network function production entity sends ciphertext information to the network function consumption entity, and the network function consumption entity receives the ciphertext information from the network function production entity.

[0354] The network function producer sends encrypted information to the network function consumer over a TLS connection. Conversely, the network function consumer receives encrypted information from the network function producer over a TLS connection. This means reusing existing connections to transfer encrypted information reduces implementation complexity. Alternatively, a newly defined connection can be used to decouple encrypted information from existing communications, allowing for more flexible information transfer. The specific implementation principles can be found in the description of S714 or S814 above and will not be elaborated here.

[0355] S1106: The network function consumption entity obtains the first key according to the ciphertext information.

[0356] In one possible approach, the network function consuming entity can request the second security function entity to decrypt the ciphertext information and obtain the first key. In other words, the network function consuming entity can request the second security function entity to perform decryption in a third operating environment, such as a fourth operating environment, which is more secure than the network function consuming entity's location, rather than performing decryption locally. This can improve decryption security. This is described in detail below.

[0357] First, the network function consuming entity may send a third message to the second security function entity, and correspondingly, the second security function entity receives the third message from the network function consuming entity.

[0358] The network function consumption entity and the second security function entity (such as the above-mentioned security function entity 2) are deployed in the same hardware environment. The network function consumption entity runs in the third operating environment, and the second security function entity runs in the fourth operating environment. The security level of the fourth operating environment is higher than the security level of the third operating environment. The specific implementation principle can refer to the relevant introduction in the above-mentioned communication system, and will not be repeated here.

[0359] The third message can be used to request decryption of ciphertext information. For example, the third message can include ciphertext information. The third message can be the above-mentioned UE key decryption request message, or it can be any possible message. An optional transmission method of the third message is: the network function consumption entity sends the third message to the second security function entity through the second security interface, and the second security function entity receives the third message from the network function consumption entity through the second security interface. The second security interface is an interface opened by the second security function entity to the network function consumption entity for communication, that is, the second security interface can only be used by authorized network functions. Since the attacker does not have the right to use the second security interface, he cannot access the second security function entity and cannot steal the terminal's key. The specific implementation principle can also refer to the relevant introduction of S715 or S815 above, which will not be repeated here. Alternatively, the third message can also be transmitted in any other possible way, for example, the network function consumption entity directly sends the third message to the first security function entity without going through the security interface.

[0360] Afterwards, in response to the third message, the second security function entity decrypts the ciphertext information to obtain the first key.

[0361] The second security function entity can use the private key of the asymmetric key to decrypt the ciphertext information to obtain the first key; alternatively, the second security function entity can use the symmetric key pre-configured by the second security function entity and the information of the network function consumer entity to decrypt the ciphertext information to obtain the first key. For example, the second security function entity can also determine the decryption key based on the symmetric key and the information of the network function consumer entity, and use the decryption key to decrypt the ciphertext information to obtain the plaintext first key, thereby increasing the complexity of decryption and further improving the security of decryption. The specific implementation principle can be referred to the relevant introduction of S817-S819 above and will not be repeated here. Alternatively, the second security function entity can also use other decryption methods, such as directly using the symmetric key to decrypt the ciphertext information to obtain the plaintext key, and there is no limitation on this.

[0362] The network function consuming entity's information can be pre-configured locally with the second security function entity. Alternatively, the network function consuming entity's information can be obtained in advance from the network function consuming entity. For example, the third message can also include information about the network function consuming entity. That is, the information of the network function message entity can also be provided by the network function consuming entity, eliminating the need for the second security function entity to maintain it and reducing the overhead of the second security function entity. Of course, the network function consuming entity can also send the network function consuming entity's information to the second security function entity via other messages to achieve decoupling from the third message, and this is not limited to this.

[0363] It is understood that the decryption method of the second security function entity needs to match the encryption method of the first security function entity. The second security function entity and the first security function entity can pre-configure a symmetric key, or share a symmetric key. In this way, the first security function entity uses the symmetric key to encrypt the first key to obtain ciphertext information, and the second security function entity uses the symmetric key to decrypt the ciphertext information to obtain the first key. Alternatively, the first security function entity can encrypt using the public key of an asymmetric key and decrypt using the private key of the asymmetric key to achieve alignment. In this way, the first security function entity uses the public key of the asymmetric key to encrypt the first key to obtain ciphertext information, and the second security function entity uses the private key of the asymmetric key to decrypt the ciphertext information to obtain the first key.

[0364] It can also be understood that the decryption of the above-mentioned key by the second security function entity can be performed by different modules in the second security function entity, or it can be performed by the same module in the second security function entity. There is no limitation to this. For the specific implementation principles, please refer to the relevant introduction of S717-S719, or refer to the relevant introduction of S817-S819, which will not be repeated here.

[0365] Finally, the second security function entity may send a fourth message to the network function production entity, and correspondingly, the network function consumption entity receives the fourth message from the second security function entity.

[0366] The fourth message may include the first key to respond to the third message. For example, the fourth message may specifically be the above-mentioned UE key decryption response message, or any other message that may be named, and there is no specific limitation on this. An optional transmission method of the fourth message is: the second security function entity may send the fourth message to the network function consumption entity through the second security interface, and the network function consumption entity may receive the fourth message from the second security function entity through the second security interface. The specific implementation principle may also refer to the relevant introduction of S720 or S820 above, which will not be repeated here. Alternatively, the fourth message may also be transmitted in any other possible manner, for example, the second security function entity directly sends the second message to the network function consumption entity without going through the security interface.

[0367] Of course, when the second security function entity obtains the first key, the second security function entity can also continue to deduce the first key to obtain a lower-level key, and encrypt the lower-level key to obtain a new ciphertext, and then return the ciphertext to the network function consumption entity. The specific implementation principle is similar to S1102-S1103, which can be used as a reference for understanding and will not be repeated here.

[0368] In another possible manner, the network function consumption entity may decrypt the encrypted information locally, such as performing an operation similar to that of the second security function entity described above, to obtain the first key.

[0369] It can also be understood that since the second key can be the key K AUSF , the network function consumption entity is a SEAF network element, then the first key can be based on the key K AUSF Determined key K SEAF After that, the SEAF network element can use the key K SEAF Derived key K AMF , and then the key K AMF Alternatively, the SEAF network element can also use the solution of this application to request the second security function entity to derive and encrypt the key K AMF The ciphertext is then converted by the SEAF network element into the key K AMF The ciphertext is sent to the AMF network element.

[0370] In summary, the network function production entity can generate the key shared between the network function consumption entity and the terminal locally, but instead request a more secure operating environment than the first operating environment where the network function production entity resides, such as the first security function entity in the second operating environment, to generate and encrypt the ciphertext information of the key. In this case, if an attacker launches an attack on the network function production entity, the attacker can only obtain the ciphertext information and cannot steal the plaintext key. Alternatively, if an attacker launches an attack on the first security function entity, the attacker will not be able to steal the plaintext key because they cannot access the more secure second operating environment. This can prevent the leakage of the terminal's key and ensure the terminal's communication security.

[0371] It can also be understood that since the network function production entity and the network function consumption entity can be located in different security domains respectively, such as the network function production entity is located in the HPLMN of the terminal served by the network function production entity, and the network function consumption entity is located in the VPLMN of the terminal; or the network function production entity is located in the access network of the terminal, and the network function consumption entity is located in the core network of the terminal, in this scenario, cross-domain key transmission is required, which requires the participation of the first security public entity in derivation and encryption, thereby transmitting encrypted ciphertext information to improve the security of key generation and transmission.

[0372] In a first possible design, in combination with the above method, before S1101, the network function producing entity may further send a capability query message to the network function consuming entity. In response, the network function consuming entity receives the capability query message from the network function producing entity. The capability query message may be used to query the security capabilities of the network function consuming entity.

[0373] In response to the capability query message, the network function consuming entity sends a capability query response message to the network function producing entity, and accordingly, the network function producing entity receives the capability query response message from the network function consuming entity. The capability query response message includes capability information, and the capability information can be used to indicate that the network function consuming entity supports the security capability of processing information through the security function entity. For example, the capability information can be an information element of one or more bits, and the value combination of these bits can be used to indicate whether the network function consuming entity supports the security capability of processing information through the security function entity. In this way, S1101 can be that in response to the capability information, the network function producing entity sends a first message to the first security function entity. That is, only when the network function consuming entity supports the use of the second network function producing entity for decryption, the network function producing entity uses the first network function producing entity for encryption, so as to avoid process failure due to the network function consuming entity being unable to use its corresponding security function entity for decryption.

[0374] It is understood that if the network function consuming entity does not support the security capability of processing information through the security function entity, the network function producing entity may also use other methods to generate the first key. For example, the network function producing entity may generate the first key on its own, that is, using existing technologies, or may instruct other network elements other than the first security function entity to generate the first key. The specific method is not limited.

[0375] Optionally, when the network function consumption entity supports processing information through the security function entity, the capability query response message includes the public key of the asymmetric key, or indication information for obtaining the asymmetric key, that is, the above-mentioned public key of the asymmetric key or indication information can be passed to the network function production entity by multiplexing the capability query response message to reduce the number of communication interactions and thus reduce communication overhead.

[0376] It can be understood that the specific implementation principle of the first possible design solution can also refer to the relevant introduction of S700c-S700d above, and will not be repeated here.

[0377] In the second possible design scheme, in combination with the above method, when the first security function entity receives the first message from the network function production entity, the first security function entity can also verify (such as through the first security interface verification) whether the network function production entity is trustworthy. For example, the first security function entity determines whether the network function production entity is the network function entity bound to the first security function entity. If the network function production entity is the network function entity bound to the first security function entity, then the network function production entity is trustworthy. If the network function production entity is not the network function entity bound to the first security function entity, then the network function production entity is untrustworthy, so as to avoid the theft of the terminal's key due to the untrustworthy network function entity accessing the first security function entity. The specific implementation principle can also refer to the relevant introduction of Figure 9 above, which will not be repeated here. Alternatively, the first security function entity can also verify whether the network function production entity is trustworthy through other modules of the first security function entity other than the first security interface. The verification principle is similar and the specific implementation is not limited.

[0378] In this way, the first security function entity can generate the first key based on the second key when it is determined that the network function production entity is trustworthy. Otherwise, the first security function entity may not generate the first key to prevent the terminal's key from being stolen.

[0379] In a third possible design scheme, in combination with the above method, when the second security function entity receives the third message from the network function consuming entity, the second security function entity may also verify (such as through the second security interface verification) whether the network function consuming entity is trustworthy. For example, the second security function entity determines whether the network function consuming entity is a network function entity bound to the second security function entity. If the network function consuming entity is a network function entity bound to the second security function entity, then the network function consuming entity is trustworthy. If the network function consuming entity is not a network function entity bound to the second security function entity, then the network function production and consumption is untrustworthy, so as to avoid the theft of the terminal's key due to the access of the untrusted network function entity to the second security function entity. The specific implementation principle can also refer to the relevant introduction of Figure 10 above, which will not be repeated here. Alternatively, the second security function entity can also verify whether the network function producing entity is trustworthy through other modules of the second security function entity other than the second security interface. The verification principle is similar and the specific implementation is not limited.

[0380] In this way, the second security function entity can decrypt the ciphertext information and obtain the first key if it is determined that the network function consuming entity is trustworthy. Otherwise, the second security function entity may not decrypt the ciphertext information to prevent the terminal's key from being stolen.

[0381] In a fourth possible design, in combination with the above method, the first security function entity generates verification information for the ciphertext information. The first security function entity sends the verification information to the network function production entity. The network function production entity receives the verification information from the first security function entity. The network function production entity sends the verification information to the network function consumption entity. The network function consumption entity receives the verification information from the network function production entity. The verification information may be a signature or a MAC value (MAC) for the ciphertext information, and the specific implementation is not limited thereto.

[0382] After obtaining the verification information, the network function consuming entity can perform verification on its own. For example, the network function consuming entity can use the verification information to verify the ciphertext information, such as verifying the signature or performing integrity protection verification, to determine whether the ciphertext information originates from the network function consuming entity and whether it has been tampered with by an attacker, and to determine whether the network function producing entity has been attacked, thereby ensuring communication security. In this way, the network function consuming entity can send the third message to the second security function entity if the ciphertext information verification passes, otherwise, the third message will not be sent.

[0383] After obtaining verification information, the network function consuming entity may also request the second security function entity to perform verification. For example, the network function consuming entity sends verification information to the second security function entity, which then receives the verification information from the network function consuming entity. The second security function entity then uses the verification information to verify the ciphertext information, such as verifying the signature or performing an integrity check, to determine whether the ciphertext information originated from the network function consuming entity and whether it has been tampered with by an attacker. It also determines whether the network function producing entity has been attacked, thereby ensuring communication security. In this manner, if the ciphertext information passes verification, the second security function entity decrypts the ciphertext information to obtain the first key; otherwise, decryption is not performed.

[0384] It can be understood that the specific implementation principle of the fourth possible design scheme can also refer to the relevant introduction of S710-S713 or S810-S813 above, and will not be repeated here.

[0385] The communication method provided in the embodiment of the present application is described in detail above in conjunction with Figures 7 to 11. The communication device for executing the communication method provided in the embodiment of the present application is described in detail below in conjunction with Figures 12 to 13.

[0386] Figure 12 is a structural diagram of a communication device according to an embodiment of the present application. As shown in Figure 12, the communication device 1200 includes a transceiver module 1201 and a processing module 1202. For ease of illustration, Figure 12 only shows the main components of the communication device.

[0387] The transceiver module 1201 is used to perform the transceiver function of the method shown in FIG. 7 to FIG. 11 , and the processing module 1202 is used to perform other functions of the method shown in FIG. 7 to FIG. 11 except the transceiver function.

[0388] Optionally, the transceiver module 1201 may include a sending module (not shown in FIG12 ) and a receiving module (not shown in FIG12 ). The sending module is used to implement the sending function of the communication device 1200 , and the receiving module is used to implement the receiving function of the communication device 1200 .

[0389] Optionally, the communication device 1200 may further include a storage module (not shown in FIG. 12 ) storing a program or instruction. When the processing module 1202 executes the program or instruction, the communication device 1200 may perform the functions of the method shown in FIG. 7 to FIG. 11 .

[0390] It can be understood that the communication device 1200 can be a terminal or a network device, or a chip (system) or other parts or components that can be set in a terminal or a network device, or a device that includes a terminal or a network device. This application does not limit this.

[0391] In addition, the technical effects of the communication device 1200 can refer to the technical effects of the communication method shown in Figures 7 to 11, and will not be repeated here.

[0392] Figure 13 is a second structural diagram of a communication device provided in an embodiment of the present application. Exemplarily, the communication device may be a terminal, or a chip (system) or other component or assembly that can be provided in a terminal. As shown in Figure 13, the communication device 1300 may include a processor 1301. Optionally, the communication device 1300 may further include a memory 1302 and / or a transceiver 1303. The processor 1301 is coupled to the memory 1302 and the transceiver 1303, such as by a communication bus.

[0393] The following is a detailed introduction to the various components of the communication device 1300 with reference to FIG13:

[0394] The processor 1301 is the control center of the communication device 1300 and can be a single processor or a collective term for multiple processing elements. For example, the processor 1301 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0395] Optionally, the processor 1301 can execute various functions of the communication device 1300 by running or executing software programs stored in the memory 1302 and calling data stored in the memory 1302, such as executing the communication method shown in Figures 7 to 11 above.

[0396] In a specific implementation, as an embodiment, the processor 1301 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG13 .

[0397] In a specific implementation, as an embodiment, the communication device 1300 may also include multiple processors, such as the processor 1301 and the processor 1304 shown in Figure 13. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor here can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions). Among them, the memory 1302 is used to store the software program that executes the solution of the present application, and is controlled by the processor 1301 to execute. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0398] Alternatively, the memory 1302 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1302 may be integrated with the processor 1301 or exist independently and be coupled to the processor 1301 via an interface circuit (not shown in FIG. 13 ) of the communication device 1300. This embodiment of the present application does not specifically limit this.

[0399] Transceiver 1303 is used for communication with other communication devices. For example, if communication device 1300 is a terminal, transceiver 1303 can be used to communicate with a network device or another terminal device. For another example, if communication device 1300 is a network device, transceiver 1303 can be used to communicate with a terminal or another network device.

[0400] Optionally, the transceiver 1303 may include a receiver and a transmitter (not shown separately in FIG13 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0401] Optionally, the transceiver 1303 can be integrated with the processor 1301, or can exist independently and be coupled to the processor 1301 through the interface circuit of the communication device 1300 (not shown in Figure 13). This embodiment of the present application does not specifically limit this.

[0402] It is understandable that the structure of the communication device 1300 shown in FIG13 does not constitute a limitation on the communication device, and an actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0403] In addition, the technical effects of the communication device 1300 can refer to the technical effects of the methods described in the above method embodiments, and will not be repeated here.

[0404] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0405] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0406] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0407] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0408] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0409] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0410] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0411] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0412] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0413] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, the functional units in the various embodiments of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0414] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk. The above is only a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A communication method, characterized in that, Including: A network function production entity serving a terminal sends a first message to a first security function entity. The network function production entity and the first security function entity are deployed in the same hardware environment. The network function production entity runs in a first operating environment, and the first security function entity runs in a second operating environment. The security level of the second operating environment is higher than that of the first operating environment. The first message is used to request the generation of a key shared by the network function consumption entity serving the terminal and the terminal. The network function production entity receives a second message from the first security function entity. The second message includes ciphertext information, which is the ciphertext obtained by the first security function entity encrypting the key shared by the network function consumption entity and the terminal. The network function production entity sends the ciphertext information to the network function consumption entity.

2. The method according to claim 1, characterized in that, The first message further includes a second key, which is the key shared by the network function production entity and the terminal. The second key is used to determine the key shared by the network function consumption entity and the terminal.

3. The method according to claim 1 or 2, characterized in that, The first message further includes the public key of an asymmetric key, which is used to encrypt the key shared by the network function consumption entity and the terminal.

4. The method according to claim 3, characterized in that, The method further includes; The network function production entity receives the public key of the asymmetric key from the network function consumption entity. Or; The network function production entity obtains the public key of the asymmetric key according to the indication information for obtaining the asymmetric key received from the network function production entity.

5. The method according to claim 1 or 2, characterized in that The first message further includes information of the network function consumption entity, which is used to encrypt the key shared by the network function consumption entity and the terminal.

6. The method according to claim 5, wherein The method further includes; The network function production entity receives the information of the network function consumption entity from the network function consumption entity.

7. The method according to any one of claims 1-6, characterized in that, The network function production entity is an Authentication Server Function (AUSF) network element. When the network function production entity sends a first message to the first security function entity, it includes: The AUSF network element sends the first message to the first security function entity when the authentication of the terminal is passed.

8. The method according to any one of claims 1-6, characterized in that, The method further includes; The network function production entity sends a capability query message to the network function consumption entity. The capability query message is used to query the security capabilities of the network function consumption entity. The network function production entity receives a capability query response message from the network function consumption entity. The capability query response message includes capability information, which is used to indicate the security capabilities of the network function consumption entity to support processing information through the security function entity. When the network function production entity sends a first message to the first security function entity, it includes; In response to the capability information, the network function production entity sends the first message to the first security function entity.

9. The method according to any one of claims 1-6, characterized in that, When the network function production entity sends a first message to the first security function entity, it includes: The network function production entity sends the first message to the first security function entity through a first security interface, where the first security interface is an interface opened by the first security function entity for communication with the network function production entity; The network function production entity receives a second message from the first security function entity, including; The network function production entity receives the second message from the first security function entity through the first security interface.

10. The method according to any one of claims 1-9, characterized in that, The method further includes: The network function production entity receives verification information of the ciphertext information from the first security function entity; The network function production entity sends the verification information to the network function consumption entity.

11. A communication method, characterized in that, Including: The first security function entity receives a first message from a network function production entity serving a terminal. The network function production entity and the first security function entity are deployed in the same hardware environment. The network function production entity runs in a first operating environment, and the first security function entity runs in a second operating environment. The security level of the second operating environment is higher than that of the first operating environment; In response to the first message, the first security function entity generates a first key shared by the network function consumption entity serving the terminal and the terminal; The first security function entity encrypts the first key to obtain ciphertext information; The first security function entity sends a second message to the network function production entity, where the second message includes the ciphertext information.

12. The method according to claim 11, wherein The first message includes a second key, which is a key shared by the network function production entity and the terminal. In response to the first message, the first security function entity generates a first key shared by the network function consumption entity serving the terminal and the terminal, including; In response to the first message, the first security function entity generates the first key according to the second key.

13. The method according to claim 12, wherein When the first security function entity receives the first message from the network function production entity, the method further includes: The first security function entity verifies whether the network function production entity is trustworthy; The first security function entity generates the first key according to the second key, including: The first security function entity generates the first key according to the second key when determining that the network function production entity is trustworthy.

14. The method according to any one of claims 11-13, characterized in that, The first message further includes the public key of an asymmetric key. The first security function entity encrypts the first key to obtain the ciphertext information, including; The first security function entity encrypts the first key using the public key of the asymmetric key to obtain the ciphertext information; Alternatively, the first message further includes information of the network function message entity. The first security function entity encrypts the first key to obtain the ciphertext information, including; The first security function entity encrypts the first key using a symmetric key pre-configured by the first security function entity and information of the network function consumption entity to obtain the ciphertext information.

15. The method according to any one of claims 11-14, characterized in that, The first security function entity receives a first message from a network function production entity serving a terminal, including: The first security function entity receives the first message from the network function production entity through a first security interface, where the first security interface is an interface opened by the first security function entity for communication with the network function production entity; The first security function entity sends a second message to the network function production entity, including; The first security function entity sends the second message to the network function production entity through the first security interface.

16. The method according to any one of claims 11-15, characterized in that, The method further includes: The first security function entity generates verification information for the ciphertext information; The first security function entity sends the verification information to the network function production entity.

17. A communication method, characterized in that, Including: A network function consumption entity serving the terminal receives ciphertext information from a network function production entity serving the terminal; The network function consumption entity sends a third message to a second security function entity. The network function consumption entity and the second security function entity are deployed in the same hardware environment. The network function consumption entity runs in a third operating environment, and the second security function entity runs in a fourth operating environment. The security level of the fourth operating environment is higher than that of the third operating environment. The third message includes the ciphertext information; The network function consumption entity receives a fourth message from the second security function entity. The fourth message includes a first key shared by the network function production entity and the terminal, and the first key is the key of the plaintext obtained by the second security function entity decrypting the ciphertext information.

18. The method according to claim 17, characterized in that, The third message further includes information of the network function consumption entity, and the information of the network function consumption entity is used to decrypt the ciphertext information.

19. The method according to claim 17 or 18, characterized in that, The network function consumption entity sends a third message to the second security function entity, including: The network function consumption entity sends the third message to the second security function entity through a second security interface, where the second security interface is an interface opened by the second security function entity for communication with the network function consumption entity; The network function consumption entity receives the fourth message from the second security function entity, including; The network function consumption entity receives the fourth message from the second security function entity through the second security interface.

20. The method according to any one of claims 17-19, characterized in that The method further includes: The network function consumption entity sends a public key of an asymmetric key to the network function production entity, and the public key of the asymmetric key is used to encrypt the key shared by the network function consumption entity and the terminal; Or; The network function consumption entity sends indication information for obtaining the public key of the asymmetric key to the network function production entity.

21. The method according to any one of claims 17-20, characterized in that, The method further includes: The network function consumption entity receives a capability query message from the network function production entity; In response to the capability query message, the network function consuming entity sends a capability query response message to the network function producing entity, and the capability query response message includes capability information, where the capability information is used to indicate the security capability of the network function consuming entity to support processing information through the security function entity.

22. The method according to any one of claims 17 - 21, characterized in that The method further includes; The network function consuming entity receives verification information from the network function producing entity; The network function consuming entity uses the verification information to verify the ciphertext information; The network function consuming entity sends a third message to the second security function entity, including; When the ciphertext information is verified successfully, the network function consuming entity sends the third message to the second security function entity.

23. The method according to any one of claims 17 - 21, characterized in that The method further includes: The network function consuming entity receives verification information from the network function producing entity for verifying the ciphertext information; The network function consuming entity sends the verification information to the second security function entity.

24. A communication method, characterized in that, Including: The second security function entity receives a third message from the network function consuming entity serving the terminal. The network function consuming entity and the second security function entity are deployed in the same hardware environment. The network function consuming entity runs in the third operating environment, and the second security function entity runs in the fourth operating environment. The security level of the fourth operating environment is higher than that of the third operating environment. The third message includes the ciphertext information; In response to the third message, the second security function entity decrypts the ciphertext information to obtain the first key shared by the network function producing entity and the terminal; The second security function entity sends a fourth message to the network function consuming entity, and the fourth message includes the first key.

25. The method according to claim 24, wherein The second security function entity decrypts the ciphertext information to obtain the first key shared by the network function producing entity and the terminal, including; The second security function entity uses the private key of the asymmetric key to decrypt the ciphertext information to obtain the first key; Or; The second security function entity uses the symmetric key pre-configured in the second security function entity and the information of the network function consuming entity to decrypt the ciphertext information to obtain the first key.

26. The method according to claim 25, characterized in that, The third message includes the information of the network function consuming entity.

27. The method according to any one of claims 24 - 26, characterized in that, When the second security function entity receives the third message from the network function consuming entity, the method further includes; The second security function entity verifies whether the network function consuming entity is trustworthy; The second security function entity decrypts the ciphertext information to obtain the first key, including: When the second security function entity determines that the network function consuming entity is trustworthy, it decrypts the ciphertext information to obtain the first key.

28. The method according to any one of claims 24-27, characterized in that, The second security function entity receives a third message from the network function consuming entity serving the terminal, including: The second security function entity receives a third message from the network function consuming entity through a second security interface, where the second security interface is an interface opened by the second security function entity for communication with the network function consuming entity; The second security function entity sends a fourth message to the network function consuming entity, including; The second security function entity sends a fourth message to the network function consuming entity through the second security interface.

29. The method according to any one of claims 24-28, characterized in that, The method further includes; The second security function entity receives verification information from the network function consuming entity; The second security function entity uses the verification information to verify the ciphertext information; The second security function entity decrypts the ciphertext information to obtain the first key, including; The second security function entity decrypts the ciphertext information to obtain the first key when the ciphertext information passes the verification.

30. A communication device, characterized in that, The device includes a module for performing the method according to any one of claims 1-29.

31. A communication device, characterized in that, The communication device includes a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the communication device is caused to perform the method according to any one of claims 1-29.

32. A communication system, characterized in that, The system includes at least one of the following: a network function production entity for performing the method according to any one of claims 1-10, a first security function entity for performing the method according to any one of claims 11-16, a network function consuming entity for performing the method according to any one of claims 17-23, or a second security function entity for performing the method according to any one of claims 24-29.

33. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a computer program or instruction, and when the computer program or instruction runs on a computer, the computer is caused to perform the method according to any one of claims 1-29.

Citation Information

Patent Citations

  • Method and device for obtaining user identifier

    CN110062381A

  • 5G network authentication method and system based on DH ratchet algorithm

    CN112399407A

  • Communication method and related product

    CN113228721A

  • 5G authentication method based on terminal identifier update

    CN115767539A

  • Secure user equipment capability transfer for user equipment with no access stratum security

    US20210021994A1