Information processing method, core network device, subscriber identity module, and mobile equipment

By performing a reduction in the number of bits or an exclusive-OR operation in the user identification module of the core network device and terminal to generate a third key suitable for the 256-bit user key, the problem of insufficient adaptability of the key processing mechanism under quantum threat is solved, and the security of the authentication process is improved.

WO2025152012A1PCT designated stage expired Publication Date: 2025-07-24BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/072412
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-15
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

The prior art cannot effectively adjust the key processing mechanism under quantum threat to meet the needs of 256-bit user keys, resulting in insufficient security of the authentication process.

Method used

By performing a reduction in the number of key bits or an exclusive-OR operation in the user identification module of the core network device and the terminal, a third key suitable for the 256-bit user key is generated for determining the fourth, fifth and/or sixth key.

Benefits of technology

It realizes adaptive adjustment of key processing under quantum threats to ensure the security and effectiveness of the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024072412_24072025_PF_FP_ABST
    Figure CN2024072412_24072025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an information processing method, a core network device, a subscriber identity module of a terminal, mobile equipment of a terminal, a communication system, and a storage medium. The method is executed by a core network device. The method comprises: determining a first key and a second key; and executing a first operation on the first key and the second key to obtain a third key, wherein the third key is used for determining a fourth key, a fifth key, and / or a sixth key, and the first operation comprises at least one of: an operation of reducing the number of bits of the first key and the second key, and an operation of performing an exclusive-OR operation on the first key and the second key. In this way, the technical solution provided by the embodiments of the present application enables key processing to adapt to scenarios in which user keys having a first number of bits are introduced.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, core network device, user identification module and mobile device Technical Field

[0001] The present disclosure relates to the field of communication technologies, and in particular to an information processing method, a core network device, a user identification module of a terminal, a mobile device of the terminal, a communication system, and a storage medium. Background Art

[0002] In the field of communication technology, in order to enable the authentication process to work under potential quantum threats, the algorithm set needs to support user keys of a first number of bits (for example, 256). After the user keys of the first number of bits are introduced, the processing mechanism of the relevant keys needs to be adaptively adjusted.

[0003] Summary of the Invention

[0004] In related technologies, after a user key with a first number of bits is introduced, the key processing mechanism needs to be adaptively adjusted.

[0005] According to a first aspect of an embodiment of the present disclosure, there is provided an information processing method, applied to a core network device, the method comprising:

[0006] determining a first key and a second key;

[0007] Performing a first operation on the first key and the second key to obtain a third key; wherein the third key is used to determine a fourth key, a fifth key, and / or a sixth key; and the first operation includes at least one of the following:

[0008] an operation of reducing the number of bits of the first key and the second key;

[0009] An exclusive OR operation is performed on the first key and the second key.

[0010] According to a second aspect of an embodiment of the present disclosure, there is provided an information processing method, which is applied to a user identification module of a terminal, the method comprising:

[0011] determining a first key and a second key;

[0012] The first key and the second key are sent to the mobile equipment ME of the terminal; wherein the first key and the second key are used by the ME to obtain a third key; and the third key is used to determine a fourth key, a fifth key and / or a sixth key.

[0013] According to a third aspect of an embodiment of the present disclosure, there is provided an information processing method, applied to an ME of a terminal, the method comprising:

[0014] Receiving a first key and a second key sent by a user identification module of a terminal;

[0015] The first key and the second key are used by the ME to obtain a third key; and the third key is used to determine a fourth key, a fifth key and / or a sixth key.

[0016] According to a fourth aspect of an embodiment of the present disclosure, a communication method is provided, the method comprising:

[0017] The user identification module of the terminal sends the first key and the second key to the mobile equipment ME of the terminal; wherein the first key and the second key are used to obtain the third key; the third key is used to determine the fourth key, the fifth key and / or the sixth key.

[0018] According to a fifth aspect of an embodiment of the present disclosure, a core network device is provided, the core network device including:

[0019] The processing module is configured to:

[0020] determining a first key and a second key;

[0021] Performing a first operation on the first key and the second key to obtain a third key; wherein the third key is used to determine a fourth key, a fifth key, and / or a sixth key; and the first operation includes at least one of the following:

[0022] an operation of reducing the number of bits of the first key and the second key;

[0023] An exclusive OR operation is performed on the first key and the second key.

[0024] According to a sixth aspect of an embodiment of the present disclosure, a user identification module of a terminal is provided, the user identification module of the terminal comprising: a processing module configured to: determine a first key and a second key;

[0025] The transceiver module is configured to: send the first key and the second key to the mobile equipment ME of the terminal; wherein the first key and the second key are used by the ME to obtain the third key; the third key is used to determine the fourth key, the fifth key and / or the sixth key.

[0026] According to a seventh aspect of an embodiment of the present disclosure, there is provided an ME of a terminal, characterized in that the ME of the terminal includes:

[0027] The transceiver module is configured as follows:

[0028] Receiving a first key and a second key sent by a user identification module of a terminal;

[0029] The first key and the second key are used by the ME to obtain a third key; and the third key is used to determine a fourth key, a fifth key and / or a sixth key.

[0030] According to an eighth aspect of an embodiment of the present disclosure, a communication system is provided, characterized in that the communication system includes a user identification module of a terminal and an ME of the terminal; the user identification module of the terminal is configured to implement the method described in the second aspect, and the ME of the terminal is configured to implement the method described in the third aspect.

[0031] According to a ninth aspect of an embodiment of the present disclosure, a core network device is provided, the core network device including:

[0032] one or more processors;

[0033] The core network device is used to execute the method described in the first aspect.

[0034] According to a tenth aspect of an embodiment of the present disclosure, a user identification module of a terminal is provided, the user identification module of the terminal including:

[0035] one or more processors;

[0036] Wherein, the user identification module of the terminal is used to execute the method described in the second aspect.

[0037] According to an eleventh aspect of an embodiment of the present disclosure, there is provided an ME of a terminal, the ME of the terminal including:

[0038] one or more processors;

[0039] The ME of the terminal is used to execute the method described in the third aspect.

[0040] According to a twelfth aspect of an embodiment of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions, and when the instructions are executed on a communication device, the communication device executes the method provided in the first aspect.

[0041] The technical solution provided by the embodiments of the present disclosure enables key processing to adapt to scenarios after the user key of the first number of bits is introduced.

[0042] It should be understood that the foregoing general description and the following detailed description are merely exemplary and explanatory and are not restrictive of the embodiments of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present invention and, together with the description, serve to explain the principles of the embodiments of the present invention.

[0044] FIG1a is a schematic diagram showing an architecture of a communication system according to an exemplary embodiment;

[0045] FIG2a is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0046] FIG2 b is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0047] FIG2c is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0048] FIG3a is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0049] FIG3 b is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0050] FIG4a is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0051] FIG4 b is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0052] FIG5a is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0053] FIG5 b is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0054] FIG6 a is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0055] FIG6 b is a schematic flow chart showing an information processing method according to an exemplary embodiment;

[0056] FIG7a is a schematic diagram of a terminal according to an exemplary embodiment;

[0057] FIG7b is a schematic diagram showing a network device according to an exemplary embodiment;

[0058] FIG8a is a schematic structural diagram of a UE according to an exemplary embodiment;

[0059] Fig. 8b is a schematic structural diagram of a communication device according to an exemplary embodiment. DETAILED DESCRIPTION

[0060] The embodiments of the present disclosure provide an information processing method, a core network device, a user identification module of a terminal, a mobile device of the terminal, a communication system, and a storage medium.

[0061] In a first aspect, an embodiment of the present disclosure provides an information processing method, characterized in that the method is performed by a core network device, and the method includes:

[0062] determining a first key and a second key;

[0063] Performing a first operation on the first key and the second key to obtain a third key; wherein the third key is used to determine a fourth key, a fifth key, and / or a sixth key; and the first operation includes at least one of the following:

[0064] an operation of reducing the number of bits of the first key and the second key;

[0065] An operation of performing an exclusive OR operation on the first key and the second key. In the above embodiment, an operation of reducing the number of bits of the first key and the second key or an operation of performing an exclusive OR operation on the first key and the second key can be performed to obtain a third key used to determine the fourth key, the fifth key, and / or the sixth key, thereby adjusting the first key and the second key, thereby adapting to a scenario where the number of bits of a user key is adjusted.

[0066] In combination with some embodiments of the first aspect, in some embodiments, the fourth key is a security key Kausf, the fifth key is a first encryption key CK', and the sixth key is a first integrity protection key IK'.

[0067] In combination with some embodiments of the first aspect, in some embodiments, the first key is a second encryption key CK, and the second key is a second integrity protection key IK.

[0068] In combination with some embodiments of the first aspect, in some embodiments, the first operation is: an operation of reducing the number of bits of the first key and the second key, and the third key includes: the first key after the number of bits is reduced and the second key after the number of bits is reduced.

[0069] In the above embodiment, in the scenario of reducing the number of bits of the first key and the second key, the third key includes the first key with the reduced number of bits and the second key with the reduced number of bits.

[0070] In combination with some embodiments of the first aspect, in some embodiments, the number of bits of the first key before the bit number is reduced is 256, the number of bits of the second key before the bit number is reduced is 256, the number of bits of the first key after the bit number is reduced is 128, and the number of bits of the second key after the bit number is reduced is 128.

[0071] In the above embodiment, it can be adapted to the scenario where the first key and the second key are both 256 bits.

[0072] In combination with some embodiments of the first aspect, in some embodiments, the first operation is: performing an XOR operation on the first key and the second key, and the third key includes: the result obtained after performing an XOR operation on the first key and the second key.

[0073] In the above embodiment, in a scenario where an exclusive OR operation is performed on the first key and the second key, the third key includes a result obtained by performing the exclusive OR operation on the first key and the second key.

[0074] In combination with some embodiments of the first aspect, in some embodiments, the number of bits of the first key is 256, the number of bits of the second key is 256, and the number of bits of the third key is 256.

[0075] The above embodiment can be adapted to the scenario where the first key and the second key are 256 bits.

[0076] In combination with some embodiments of the first aspect, in some embodiments, the fourth key is Kausf; and the third key is used to determine the input key of the key derivation function KDF of Kausf.

[0077] In the above embodiment, the third key may be input into KDF to obtain Kausf.

[0078] In combination with some embodiments of the first aspect, in some embodiments, the fifth key is the first encryption key CK'; and the third key is used to determine the input key of the key derivation function KDF of the first encryption key CK'.

[0079] In the above embodiment, the third key may be input into the KDF to obtain the first encryption key CK'.

[0080] In combination with some embodiments of the first aspect, in some embodiments, the sixth key is the first integrity protection key IK'; and the third key is used to determine the input key of a key derivation function KDF of the first integrity protection key IK'.

[0081] In the above embodiment, the third key may be input into the KDF to obtain the first integrity protection key IK'.

[0082] In conjunction with some embodiments of the first aspect, in some embodiments, determining the first key and the second key includes:

[0083] The first key and the second key are determined based on a subscriber key K.

[0084] In the above embodiment, the first key and the second key may be determined based on K.

[0085] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0086] Determining an algorithm set based on the number of bits of K;

[0087] The algorithm set is used to determine the first key and the second key.

[0088] In the above embodiment, the algorithm set for determining the first key and the second key may be determined based on the number of bits of K.

[0089] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0090] Determine the number of bits of K to be a first number, and determine the algorithm set to be at least one of the following:

[0091] MILENAGE-256-R algorithm suite;

[0092] MILENAGE-256-A algorithm suite;

[0093] ZUC based 256-bits algorithm set;

[0094] Tuak algorithm suite.

[0095] In the above embodiment, when the number of bits of K is the first number, the algorithm set is determined to be the MILENAGE-256-R algorithm set, the MILENAGE-256-A algorithm set, the ZUC-based 256-bit algorithm set and / or the Tuak algorithm set.

[0096] In a second aspect, an embodiment of the present disclosure provides an information processing method, the method being executed by a user identification module of a terminal, the method comprising:

[0097] determining a first key and a second key;

[0098] The first key and the second key are sent to the mobile equipment ME of the terminal; wherein the first key and the second key are used by the ME to obtain a third key; and the third key is used to determine a fourth key, a fifth key and / or a sixth key.

[0099] In conjunction with some embodiments of the second aspect, in some embodiments, the first key sent to the ME is a key processed by a first operation; the second key sent to the ME is a key processed by the first operation; wherein the first operation includes an operation of reducing the number of bits of the first key and the second key;

[0100] The first operation includes reducing the number of bits of the first key and the second key.

[0101] In combination with some embodiments of the second aspect, in some embodiments, the fourth key is a security key Kausf; the fifth key is a first encryption key CK'; and the sixth key is a first integrity protection key IK'.

[0102] In combination with some embodiments of the second aspect, in some embodiments, the first key is a second encryption key CK, and the second key is a second integrity protection key IK.

[0103] In combination with some embodiments of the second aspect, in some embodiments, the number of bits of the first key before the bit number is reduced is 256, the number of bits of the second key before the bit number is reduced is 256, the number of bits of the first key after the bit number is reduced is 128, and the number of bits of the second key after the bit number is reduced is 128.

[0104] In conjunction with some embodiments of the second aspect, in some embodiments, determining the first key and the second key includes:

[0105] The first key and the second key are determined based on a subscriber key K.

[0106] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0107] Determining an algorithm set based on the number of bits of K;

[0108] The algorithm set is used to determine the first key and the second key.

[0109] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0110] Determine the number of bits of K to be a first number, and determine the algorithm set to be at least one of the following:

[0111] MILENAGE-256-R algorithm suite;

[0112] MILENAGE-256-A algorithm suite;

[0113] 256-bit algorithm set based on ZUC;

[0114] Tuak algorithm suite.

[0115] In a third aspect, an embodiment of the present disclosure provides an information processing method, which is executed by an ME of a terminal, and includes:

[0116] Receiving a first key and a second key sent by a user identification module of a terminal;

[0117] The first key and the second key are used by the ME to obtain a third key; and the third key is used to determine a fourth key, a fifth key and / or a sixth key.

[0118] In combination with some embodiments of the third aspect, in some embodiments, the first key and the second key are keys obtained after the user identification module is processed by a first operation; the first operation is an operation to reduce the number of bits of the first key and the second key.

[0119] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes:

[0120] A first operation is performed on the first key and the second key to obtain the third key; wherein the first operation includes at least one of the following: an operation of reducing the number of bits of the first key and the second key; an operation of performing an exclusive OR operation on the first key and the second key.

[0121] In combination with some embodiments of the third aspect, in some embodiments, the fourth key is a security key Kausf; the fifth key is a first encryption key CK'; and the sixth key is a first integrity protection key IK'.

[0122] In combination with some embodiments of the third aspect, in some embodiments, the first key is a second encryption key CK, and the second key is a second integrity protection key IK.

[0123] In combination with some embodiments of the third aspect, in some embodiments, the first operation is: an operation of reducing the number of bits of the first key and the second key, and the third key includes: the first key after the number of bits is reduced and the second key after the number of bits is reduced.

[0124] In combination with some embodiments of the third aspect, in some embodiments, the number of bits of the first key before the bit number is reduced is 256, the number of bits of the second key before the bit number is reduced is 256, the number of bits of the first key after the bit number is reduced is 128, and the number of bits of the second key after the bit number is reduced is 128.

[0125] In combination with some embodiments of the third aspect, in some embodiments, the first operation is: performing an XOR operation on the first key and the second key, and the third key includes: the result obtained after performing an XOR operation on the first key and the second key.

[0126] In combination with some embodiments of the third aspect, in some embodiments, the first operation is an operation of performing an exclusive OR operation on the first key and the second key; the number of bits of the first key is 256; the number of bits of the second key is 256, and the number of bits of the third key is 256.

[0127] In combination with some embodiments of the third aspect, in some embodiments, the fourth key is Kausf; the third key is used to determine the input key of the key derivation function KDF of the Kausf.

[0128] In combination with some embodiments of the third aspect, in some embodiments, the fifth key is the first encryption key CK'; the third key is used to determine the input key of the key derivation function KDF of the first encryption key CK'.

[0129] In conjunction with some embodiments of the third aspect, in some embodiments, the sixth key is a first integrity protection key IK'; the third key is used to determine the input key of a key derivation function KDF of the first integrity protection key IK'. In a fourth aspect, an embodiment of the present disclosure provides an information indication method, the method comprising:

[0130] The user identification module of the terminal sends the first key and the second key to the mobile equipment ME of the terminal; wherein the first key and the second key are used to obtain the third key; the third key is used to determine the fourth key, the fifth key and / or the sixth key.

[0131] In a fifth aspect, an embodiment of the present disclosure provides a core network device, the core network device including:

[0132] The processing module is configured to:

[0133] determining a first key and a second key;

[0134] Performing a first operation on the first key and the second key to obtain a third key; wherein the third key is used to determine a fourth key, a fifth key, and / or a sixth key; and the first operation includes at least one of the following:

[0135] an operation of reducing the number of bits of the first key and the second key;

[0136] An exclusive OR operation is performed on the first key and the second key.

[0137] In a sixth aspect, an embodiment of the present disclosure provides a user identification module of a terminal, the user identification module of the terminal comprising: a processing module configured to: determine a first key and a second key;

[0138] The transceiver module is configured to: send the first key and the second key to the mobile equipment ME of the terminal; wherein the first key and the second key are used by the ME to obtain the third key; the third key is used to determine the fourth key, the fifth key and / or the sixth key.

[0139] In a seventh aspect, an embodiment of the present disclosure provides an ME of a terminal, the ME of the terminal including:

[0140] The transceiver module is configured as follows:

[0141] Receiving a first key and a second key sent by a user identification module of a terminal;

[0142] The first key and the second key are used by the ME to obtain a third key; and the third key is used to determine a fourth key, a fifth key and / or a sixth key.

[0143] In the eighth aspect, an embodiment of the present disclosure provides a communication system, which includes a user identification module of a terminal and an ME of the terminal; the user identification module of the terminal is configured to implement the method described in the second aspect, and the ME of the terminal is configured to implement the method described in the third aspect.

[0144] In a ninth aspect, an embodiment of the present disclosure provides a core network device, the core network device including:

[0145] one or more processors;

[0146] The core network device is used to execute the method described in the first aspect.

[0147] In a tenth aspect, an embodiment of the present disclosure provides a user identification module of a terminal, the user identification module of the terminal including:

[0148] one or more processors;

[0149] Wherein, the user identification module of the terminal is used to execute the method described in the second aspect.

[0150] In an eleventh aspect, an embodiment of the present disclosure provides an ME of a terminal, the ME of the terminal including:

[0151] one or more processors;

[0152] The ME of the terminal is used to execute the method described in the third aspect.

[0153] In the twelfth aspect, an embodiment of the present disclosure provides a storage medium, wherein the storage medium stores instructions, which, when the instructions are executed on a communication device, enable the communication device to execute the method described in the optional implementation of the first aspect, the second aspect and / or the third aspect.

[0154] In a thirteenth aspect, an embodiment of the present disclosure proposes a program product. When the program product is executed by a communication device, the communication device executes the method described in the optional implementation of the first aspect, the second aspect and / or the third aspect.

[0155] In a fourteenth aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the optional implementation of the first aspect, the second aspect and / or the third aspect.

[0156] In a fifteenth aspect, an embodiment of the present disclosure provides a chip or a chip system, wherein the chip or chip system includes a processing circuit configured to execute the method described in the optional implementation of the first aspect, the second aspect, and / or the third aspect.

[0157] It is understandable that the user identification module of the terminal, the mobile device of the terminal, the storage medium, the program product, the computer program, the chip or the chip system are all used to perform the method proposed in the embodiment of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method and will not be repeated here.

[0158] The present disclosure provides an information processing method, a core network device, a user identification module of a terminal, a mobile device of the terminal, a communication system, and a storage medium. In some embodiments, the terms information processing method, information indication method, communication method, and information transmission method are interchangeable, and the terms communication system and information processing system are interchangeable.

[0159] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0160] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.

[0161] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0162] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0163] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0164] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.

[0165] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.

[0166] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.

[0167] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.

[0168] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0169] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0170] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0171] In some embodiments, devices and equipment can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they can also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", etc.

[0172] In some embodiments, "network" can be interpreted as devices included in the network, such as access network equipment, core network equipment, etc.

[0173] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", and in some embodiments may also be understood as "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission and / or reception point (TRP)" "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)", etc.

[0174] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)", "user terminal" "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc.

[0175] In some embodiments, the terminal includes a mobile equipment (ME) and a universal subscriber identity module (USIM).

[0176] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0177] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0178] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.

[0179] FIG1a is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.

[0180] As shown in FIG. 1 a , a communication system 100 includes a terminal 101 and a network device 102 .

[0181] In some embodiments, the network device 102 may include at least one of an access network device and a core network device.

[0182] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.

[0183] In some embodiments, the access network device may be, for example, a node or device that accesses a terminal to a wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.

[0184] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0185] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0186] In some embodiments, a core network device may be a device including one or more network elements, or may be multiple devices or device groups, each including all or part of the one or more network elements. The network element may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).

[0187] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.

[0188] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1a, or a portion thereof, but are not limited thereto. The entities shown in FIG1a are illustrative only. The communication system may include all or a portion of the entities shown in FIG1a, or may include other entities other than those shown in FIG1a. The number and form of the entities may be arbitrary. The connection relationship between the entities is illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.

[0189] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).

[0190] To better understand the embodiments of the present disclosure, first, some exemplary embodiments are used to illustrate relevant scenarios.

[0191] In some embodiments, a quantum computer is a computer that exploits quantum mechanical effects. These effects include superposition, which allows quantum bits to exist in a combination of several states simultaneously, and entanglement, which allows independent quantum systems to be linked so that they cannot be described independently. Quantum algorithms exist that exploit these effects to solve certain cryptographic problems more efficiently than they can on classical computers.

[0192] In some embodiments, Grover's search algorithm provides a theoretical quadratic speedup for unstructured search problems. This applies to symmetric key encryption because using Grover's algorithm, the O(2 N / 2 )Serial quantum operations are used to recover the N-bit key of the cryptography.

[0193] In some embodiments, to counter the threat of quantum computers to symmetric cryptography, it is sufficient to double the key size of the algorithm, thereby doubling the number of bits of classical security.

[0194] In some embodiments, 3GPP provides two symmetric cryptographic algorithm sets that meet the authentication requirements. One is called MILENAGE, and the other is called Tuak. Both algorithm sets only support 128-bit subscriber keys (i.e., the length of K is 128 bits).

[0195] In some embodiments, in order for the authentication process to work under potential quantum threats, the algorithm set must support 256-bit subscriber keys.

[0196] In some embodiments, SAGE provides two mitigation algorithm suites (i.e., MILENAGE-256-R and MILENAGE-256-A). MILENAGE-256-R is based on the Rijndael block cipher with a 256-bit key and block size. MILENAGE-256-A is based on the Advanced Encryption Standard (AES) block cipher with a 256-bit key size (and a standard 128-bit block size). The input and output sizes of the algorithm are the same as the block size. Therefore, for MILENAGE-256-R, its output size is 256 bits. Considering that IK and CK are outputs of the algorithm suite, if MILENAGE-256-R is selected, the integrity protection key (IK, Cipher Key or Confidentiality Key) and the encryption key (CK, Integrity Key) are 256 bits in length.

[0197] In some embodiments, if Tuak is adjusted to support 256-bit user keys, the lengths of IK and CK may also be 256 bits.

[0198] In some embodiments, in the 5G Authentication and Key Agreement (AKA) or Extensible Authentication Protocol AKA (EAP-AKA', Extensible Authentication Protocol AKA) process, in order to generate K AUSF , 128-bit CK and 128-bit IK should be concatenated as a 256-bit input key to the Key Derivation Function (KDF). When each of CK and IK grows to 256 bits, the concatenation of CK and IK will become 512 bits, which is not suitable for generating K. AUSF The 256-bit input key.

[0199] In some embodiments, for 256-bit CK and 256-bit IK, 5G AKA or EAP-AKA′ cannot provide a method for generating K. AUSF The 256-bit input key.

[0200] In the embodiment of the present disclosure, 5G AKA or EAP-AKA' calculates 256-bit CK and 256-bit IK to generate K AUSF The 256-bit input key.

[0201] FIG2a is an interactive diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG2a, the present disclosure embodiment relates to an information processing method for a communication system 100, the method comprising:

[0202] Step S2101: The core network device determines a first key and a second key.

[0203] In some embodiments, the core network device may be a Unified Data Management (UDM) or an Authentication Credential Repository and Processing Function (ARPF), but is not limited thereto.

[0204] In some embodiments, in the 5G AKA-based authentication process, the core network device determines the first key and the second key.

[0205] In some embodiments, in an authentication process based on EAP-AKA′, the core network device determines a first key and a second key.

[0206] In some embodiments, the first key is a second encryption key (CK, Cipher Key or Confidentiality Key), and the second key is a second integrity protection key (IK, Integrity Key).

[0207] In some embodiments, the core network device determines the first key and the second key based on a subscriber key K.

[0208] In some embodiments, the core network device may receive identification information sent by the terminal, and the core network device determines K based on the identification information.

[0209] In some embodiments, the core network device determines a first key with a number of 256 bits and a second key with a number of 256 bits based on a subscriber key K with a number of 256 bits.

[0210] In some embodiments, the core network device may determine the algorithm set based on the number of bits of K.

[0211] In some embodiments, the set of algorithms is used to determine the first key and the second key.

[0212] In some embodiments, the core network device determines that the number of bits of K is a first number, and the core network device determines that the algorithm set is at least one of the following:

[0213] MILENAGE-256-R algorithm suite;

[0214] MILENAGE-256-A algorithm suite;

[0215] 256-bit algorithm set based on ZUC;

[0216] Tuak algorithm suite.

[0217] In some embodiments, the first number is 256.

[0218] Step S2102: The core network device performs a first operation.

[0219] In some embodiments, in the 5G AKA-based authentication process, the core network device performs a first operation.

[0220] In some embodiments, in an EAP-AKA'-based authentication process, the core network device performs a first operation.

[0221] In some embodiments, the core network device performs a first operation on the first key and the second key.

[0222] In some embodiments, the core network device performs a first operation on the first key and the second key to obtain a third key.

[0223] In some embodiments, the third key is used to determine the fourth key.

[0224] In some embodiments, the fourth key is a security key Kausf;

[0225] In some embodiments, the fifth key is the first encryption key CK'; it should be noted that the first encryption key CK' may also be referred to as the "first encryption key CK" in some scenarios, and the two may be interchangeable and are not limited here.

[0226] In some embodiments, the sixth key is the first integrity protection key IK'; it should be noted that the first integrity protection key IK' may also be referred to as the "first integrity protection key IK" in some scenarios, and the two may be interchangeable and are not limited here.

[0227] In some embodiments, the first operation is an operation of reducing the number of bits of the first key and the second key.

[0228] Exemplarily, the operation of reducing the number of bits of the first key and the second key may be to shorten or truncate the first key and the second key. For example, the core network device truncates the 256-bit CK and the 256-bit IK to 128 bits. For example, the 128 most or least significant bits (most / least significant 128 bits) of the 256-bit CK can be used as the 128-bit CK; and the 128 most or least significant bits (most / least significant 128 bits) of the 256-bit IK can be used as the 128-bit IK.

[0229] Exemplarily, the operation of reducing the number of bits of the first key and the second key may be selecting 128 bits of data from a 256-bit CK and using the 128 bits of data as a 128-bit CK.

[0230] Exemplarily, the operation of reducing the number of bits of the first key and the second key may be selecting 128 bits of data from the 256-bit IK and using the 128 bits of data as the 128-bit IK.

[0231] In some embodiments, an exclusive-OR operation is performed on the first key and the second key.

[0232] In some embodiments, the first operation is an operation of reducing the number of bits of the first key and the second key, and the third key includes: the first key with reduced bit numbers and the second key with reduced bit numbers.

[0233] Illustratively, the number of bits of the first key before bit reduction is 256, the number of bits of the second key before bit reduction is 256, the number of bits of the first key after bit reduction is 128, and the number of bits of the second key after bit reduction is 128.

[0234] In some embodiments, the first operation is: performing an exclusive OR operation on the first key and the second key, and the third key includes: a result obtained by performing an exclusive OR operation on the first key and the second key.

[0235] Exemplarily, the number of bits of the first key is 256, the number of bits of the second key is 256, and the number of bits of the third key is 256.

[0236] In some embodiments, the fourth key is Kausf; the third key is used to determine the input key of the key derivation function KDF of the Kausf.

[0237] In some embodiments, the fifth key is the first encryption key CK'; and the third key is used to determine an input key of a key derivation function KDF of the first encryption key CK'.

[0238] Exemplarily, the fifth key is the most significant 128 bits of the KDF output data.

[0239] In some embodiments, the sixth key is a first integrity protection key IK'; and the third key is used to determine an input key of a key derivation function KDF of the first integrity protection key IK'.

[0240] Exemplarily, the sixth key is the least significant 128 bits of the KDF output data.

[0241] In some embodiments, the term "information" can be interchangeable with terms such as "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", and "data".

[0242] In some embodiments, the term "send" can be interchanged with terms such as "transmit", "report", and "transmit".

[0243] The information indication method involved in the embodiment of the present disclosure may include at least one of step S2101 to step S2102. For example, step S2101 may be implemented as an independent embodiment, and step S2102 may be implemented as an independent embodiment, but is not limited thereto.

[0244] FIG2b is an interactive diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG2b , the present disclosure embodiment relates to an information processing method for a communication system 100, the method comprising:

[0245] Step S2201: The user identification module of the terminal determines a first key and a second key.

[0246] In some embodiments, the terminal includes a user identification module and a mobile equipment (ME). It can be understood that the part of the terminal other than the user identification module can be called ME, and information can be exchanged between the user identification module and the ME.

[0247] In some embodiments, the user identification module of the terminal may be a Universal Subscriber Identity Module (USIM), but is not limited thereto.

[0248] In some embodiments, in a 5G AKA-based authentication process, the user identification module determines the first key and the second key.

[0249] In some embodiments, during an authentication procedure based on EAP-AKA′, the subscriber identity module determines a first key and a second key.

[0250] In some embodiments, the first key is a second encryption key (CK, Cipher Key or Confidentiality Key), and the second key is a second integrity protection key (IK, Integrity Key).

[0251] In some embodiments, the user identification module determines the first key and the second key based on a subscriber key K.

[0252] In some embodiments, the user identification module determines a first key with 256 bits and a second key with 256 bits based on a subscriber key K with 256 bits.

[0253] In some embodiments, the user identification module may determine the algorithm set based on the number of bits of K.

[0254] In some embodiments, the set of algorithms is used to determine the first key and the second key.

[0255] In some embodiments, the user identification module determines that the number of bits of K is a first number, and the user identification module determines that the algorithm set is at least one of the following:

[0256] MILENAGE-256-R algorithm suite;

[0257] MILENAGE-256-A algorithm suite;

[0258] 256-bit algorithm set based on ZUC;

[0259] Tuak algorithm suite.

[0260] In some embodiments, the first number is 256.

[0261] In some embodiments, the user identification module determines a first key with 256 bits and a second key with 256 bits based on a subscriber key K with 256 bits.

[0262] Step S2202: The user identification module of the terminal sends a first key and a second key to a mobile equipment (ME) of the terminal.

[0263] In some embodiments, in the 5G AKA-based authentication process, the user identification module sends the first key and the second key to the ME of the terminal.

[0264] In some embodiments, in an authentication process based on EAP-AKA′, the subscriber identity module sends the first key and the second key to the ME of the terminal.

[0265] In some embodiments, in an authentication process based on 5G AKA, the user identification module sends a first key with a bit number of 256 bits and a second key with a bit number of 256 bits to the ME of the terminal.

[0266] In some embodiments, in an EAP-AKA'-based authentication process, the SIM sends a 256-bit first key and a 256-bit second key to the ME of the terminal. In some embodiments, the ME receives the first key and the second key sent by the SIM.

[0267] In some embodiments, the first key and the second key are used by the ME to obtain a third key.

[0268] In some embodiments, the third key is used to determine the fourth key, the fifth key, and / or the sixth key.

[0269] In some embodiments, the fourth key is a security key Kausf.

[0270] In some embodiments, the fifth key is the first encryption key CK'.

[0271] In some embodiments, the sixth key is the first integrity protection key IK'.

[0272] In some embodiments, before sending the first key and the second key to the mobile equipment ME of the terminal, a first operation is performed on the first key and the second key to obtain the first key processed by the first operation and the second key processed by the first operation.

[0273] In some embodiments, the first key sent to the ME is a key processed by a first operation; the second key sent to the ME is a key processed by the first operation; wherein the first operation includes an operation of reducing the number of bits of the first key and the second key.

[0274] In some embodiments, the first operation includes an operation to reduce the number of bits of the first key and the second key.

[0275] Illustratively, the operation of reducing the number of bits of the first key and the second key may be to shorten or truncate the first key and the second key. For example, the user identification module truncates the 256-bit CK and the 256-bit IK to 128 bits. For example, the 128 most or least significant bits (most / least significant 128 bits) of the 256-bit CK can be used as the 128-bit CK; and the 128 most or least significant bits (most / least significant 128 bits) of the 256-bit IK can be used as the 128-bit IK.

[0276] Exemplarily, the operation of reducing the number of bits of the first key and the second key may be selecting 128 bits of data from a 256-bit CK and using the 128 bits of data as a 128-bit CK.

[0277] Exemplarily, the operation of reducing the number of bits of the first key and the second key may be selecting 128 bits of data from the 256-bit IK and using the 128 bits of data as the 128-bit IK.

[0278] In some embodiments, an exclusive-OR operation is performed on the first key and the second key.

[0279] In some embodiments, the first operation is an operation of reducing the number of bits of the first key and the second key, and the third key includes: the first key with reduced bit numbers and the second key with reduced bit numbers.

[0280] Illustratively, the number of bits of the first key before bit reduction is 256, the number of bits of the second key before bit reduction is 256, the number of bits of the first key after bit reduction is 128, and the number of bits of the second key after bit reduction is 128.

[0281] It should be noted that the first operation is an operation of performing an exclusive-OR operation on the first key and the second key. The user identification module may also send the result of the exclusive-OR operation to the ME, and the result may be used by the ME to directly determine the third key. The third key includes a result obtained by performing an exclusive-OR operation on the first key and the second key. This is not limited here.

[0282] In some embodiments, the term "information" can be interchangeable with terms such as "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", and "data".

[0283] In some embodiments, the term "send" can be interchanged with terms such as "transmit", "report", and "transmit".

[0284] The information indication method involved in the embodiment of the present disclosure may include at least one of step S2201 to step S2202. For example, step S2201 may be implemented as an independent embodiment, and step S2202 may be implemented as an independent embodiment, but the present invention is not limited thereto.

[0285] FIG2c is an interactive diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG2c, the present disclosure embodiment relates to an information processing method for a communication system 100, the method comprising:

[0286] Step S2301: Mobile Equipment (ME) receives a first key and a second key sent by a user identification module of a terminal.

[0287] In some embodiments, the terminal includes a user identification module and a mobile equipment (ME). It can be understood that the part of the terminal other than the user identification module can be called ME, and information can be exchanged between the user identification module and the ME.

[0288] In some embodiments, the user identification module of the terminal may be a Universal Subscriber Identity Module (USIM), but is not limited thereto.

[0289] In some embodiments, in the 5G AKA-based authentication process, the ME receives a 256-bit first key and a 256-bit second key sent by the user identification module.

[0290] In some embodiments, in the 5G AKA-based authentication process, the ME receives the first key and the second key sent by the user identification module.

[0291] In some embodiments, in an authentication process based on EAP-AKA′, the ME receives the first key and the second key sent by the subscriber identity module.

[0292] In some embodiments, in the 5G AKA-based authentication process, the ME receives a 256-bit first key and a 256-bit second key sent by the user identification module.

[0293] In some embodiments, in an authentication process based on EAP-AKA′, the ME receives a 256-bit first key and a 256-bit second key sent by the subscriber identity module.

[0294] In some embodiments, the first key and the second key are used by the ME to obtain a third key.

[0295] In some embodiments, the third key is used to determine the fourth key, the fifth key, and / or the sixth key.

[0296] In some embodiments, the fourth key is a security key Kausf.

[0297] In some embodiments, the fifth key is the first encryption key CK'.

[0298] In some embodiments, the sixth key is the first integrity protection key IK'.

[0299] In some embodiments, the first key is a second encryption key (CK, Cipher Key or Confidentiality Key), and the second key is a second integrity protection key (IK, Integrity Key).

[0300] In some embodiments, the user identification module determines the first key and the second key based on a subscriber key K.

[0301] In some embodiments, the subscriber key K has 256 bits.

[0302] In some embodiments, the user identification module determines a first key with 256 bits and a second key with 256 bits based on a subscriber key K with 256 bits.

[0303] In some embodiments, the first key and the second key are keys obtained after the user identification module is processed by a first operation; the first operation is an operation of reducing the number of bits of the first key and the second key.

[0304] In some embodiments, the ME performs a first operation on the first key and the second key to obtain the third key; wherein the third key is used to determine the fourth key, the fifth key and / or the sixth key; the first operation includes at least one of the following: an operation of reducing the number of bits of the first key and the second key; an operation of performing an exclusive OR operation on the first key and the second key.

[0305] In some embodiments, the first operation is an operation of reducing the number of bits of the first key and the second key, and the third key includes: the first key with reduced bit numbers and the second key with reduced bit numbers.

[0306] Illustratively, the operation of reducing the number of bits of the first key and the second key may be to shorten or truncate the first key and the second key. For example, a 256-bit CK and a 256-bit IK may be truncated to 128 bits. For example, the 128 most or least significant bits (most / least significant 128 bits) of the 256-bit CK may be used as the 128-bit CK; and the 128 most or least significant bits (most / least significant 128 bits) of the 256-bit IK may be used as the 128-bit IK.

[0307] Exemplarily, the operation of reducing the number of bits of the first key and the second key may be selecting 128 bits of data from a 256-bit CK and using the 128 bits of data as a 128-bit CK.

[0308] Exemplarily, the operation of reducing the number of bits of the first key and the second key may be selecting 128 bits of data from the 256-bit IK and using the 128 bits of data as the 128-bit IK.

[0309] In some embodiments, the number of bits of the first key before the bit number reduction is 256, the number of bits of the second key before the bit number reduction is 256, the number of bits of the first key after the bit number reduction is 128, and the number of bits of the second key after the bit number reduction is 128.

[0310] In some embodiments, the first operation is: performing an exclusive OR operation on the first key and the second key, and the third key includes: a result obtained by performing an exclusive OR operation on the first key and the second key.

[0311] It should be noted that the ME may also receive the result directly sent by the user identification module after performing an exclusive OR operation on the first key and the second key. In this case, the ME may not perform the exclusive OR operation.

[0312] In some embodiments, the first operation is an operation of performing an exclusive OR operation on the first key and the second key; the number of bits of the first key is 256; the number of bits of the second key is 256, and the number of bits of the third key is 256.

[0313] Step S2302: The ME determines a fourth key, a fifth key and / or a sixth key based on the third key.

[0314] In some embodiments, the third key is the Kausf. The third key is input as an input key into a key derivation function KDF of the Kausf to obtain the Kausf.

[0315] In some embodiments, the fifth key is the first encryption key CK'; and the third key is used to determine an input key of a key derivation function KDF of the first encryption key CK'.

[0316] Exemplarily, the fifth key is the most significant 128 bits of the KDF output data.

[0317] In some embodiments, the sixth key is a first integrity protection key IK'; and the third key is used to determine an input key of a key derivation function KDF of the first integrity protection key IK'.

[0318] Exemplarily, the sixth key is the least significant 128 bits of the KDF output data.

[0319] In some embodiments, the term "information" can be interchangeable with terms such as "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", and "data".

[0320] In some embodiments, the term "send" can be interchanged with terms such as "transmit", "report", and "transmit".

[0321] The information indication method involved in the embodiment of the present disclosure may include at least one of step S2301 to step S2302. For example, step S2301 may be implemented as an independent embodiment, and step S2302 may be implemented as an independent embodiment, but is not limited thereto.

[0322] Figure 3a is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in Figure 3a, the embodiment of the present disclosure relates to an information processing method, which is executed by a core network device. The method includes:

[0323] Step S3101: Determine the first key and the second key.

[0324] In some embodiments, the optional implementation of step S3101 can refer to the optional implementation of step S2101 in Figure 2a and other related parts of the embodiment involved in Figure 2a, which will not be repeated here.

[0325] Step S3102: The core network device performs a first operation.

[0326] In some embodiments, the optional implementation of step S3102 can refer to the optional implementation of step S2102 in Figure 2a and other related parts of the embodiment involved in Figure 2a, which will not be repeated here.

[0327] The information indication method involved in the embodiment of the present disclosure may include at least one of step S3101 to step S3102. For example, step S3101 may be implemented as an independent embodiment, and step S3102 may be implemented as an independent embodiment, but is not limited thereto.

[0328] Figure 3b is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in Figure 3b, the embodiment of the present disclosure relates to an information processing method, which is executed by a core network device. The method includes:

[0329] Step S3201: Determine the first key and the second key.

[0330] In some embodiments, the optional implementation of step S3201 can refer to the optional implementation of step S2101 in Figure 2a and other related parts of the embodiment involved in Figure 2a, which will not be repeated here.

[0331] Step S3202: Perform a first operation on the first key and the second key to obtain a third key.

[0332] In some embodiments, the third key is used to determine a fourth key, a fifth key, and / or a sixth key; and the first operation includes at least one of the following:

[0333] an operation of reducing the number of bits of the first key and the second key;

[0334] An exclusive OR operation is performed on the first key and the second key.

[0335] In some embodiments, the optional implementation of step S3202 can refer to the optional implementation of step S2102 in Figure 2a and other related parts of the embodiment involved in Figure 2a, which will not be repeated here.

[0336] In some embodiments, the fourth key is a security key Kausf, the fifth key is a first encryption key CK', and the sixth key is a first integrity protection key IK'.

[0337] In some embodiments, the first key is a second encryption key CK, and the second key is a second integrity protection key IK.

[0338] In some embodiments, the first operation is an operation of reducing the number of bits of the first key and the second key, and the third key includes: the first key with reduced bit numbers and the second key with reduced bit numbers.

[0339] In some embodiments, the number of bits of the first key before the bit number reduction is 256, the number of bits of the second key before the bit number reduction is 256, the number of bits of the first key after the bit number reduction is 128, and the number of bits of the second key after the bit number reduction is 128.

[0340] In some embodiments, the first operation is: performing an exclusive OR operation on the first key and the second key, and the third key includes: a result obtained by performing an exclusive OR operation on the first key and the second key.

[0341] In some embodiments, the number of bits of the first key is 256, the number of bits of the second key is 256, and the number of bits of the third key is 256.

[0342] In some embodiments, the fourth key is Kausf; the third key is used to determine the input key of the key derivation function KDF of the Kausf.

[0343] In some embodiments, the fifth key is the first encryption key CK'; and the third key is used to determine an input key of a key derivation function KDF of the first encryption key CK'.

[0344] In some embodiments, the sixth key is a first integrity protection key IK'; and the third key is used to determine an input key of a key derivation function KDF of the first integrity protection key IK'.

[0345] In some embodiments, determining the first key and the second key includes:

[0346] The first key and the second key are determined based on a subscriber key K.

[0347] In some embodiments, the method further comprises:

[0348] Determining an algorithm set based on the number of bits of K;

[0349] The algorithm set is used to determine the first key and the second key.

[0350] In some embodiments, the method further comprises:

[0351] Determine the number of bits of K to be a first number, and determine the algorithm set to be at least one of the following:

[0352] MILENAGE-256-R algorithm suite;

[0353] MILENAGE-256-A algorithm suite;

[0354] 256-bit algorithm set based on ZUC;

[0355] Tuak algorithm suite.

[0356] In some embodiments, the method further comprises:

[0357] Determine that the number of bits of K is 256, and determine that the algorithm set is at least one of the following:

[0358] MILENAGE-256-R algorithm suite;

[0359] MILENAGE-256-A algorithm suite;

[0360] 256-bit algorithm set based on ZUC;

[0361] Tuak algorithm suite.

[0362] Figure 4a is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in Figure 4a, the present disclosure embodiment relates to an information processing method, which is executed by a user identification module of a terminal. The method includes:

[0363] Step S4101: Determine the first key and the second key.

[0364] In some embodiments, the optional implementation of step S4101 can refer to the optional implementation of step S2201 in Figure 2b and other related parts of the embodiment involved in Figure 2b, which will not be repeated here.

[0365] Step S4102: Send the first key and the second key to the mobile equipment (ME) of the terminal.

[0366] In some embodiments, the optional implementation of step S4102 can refer to the optional implementation of step S2202 in Figure 2b and other related parts of the embodiment involved in Figure 2b, which will not be repeated here.

[0367] The information indication method involved in the embodiment of the present disclosure may include at least one of step S4101 to step S4102. For example, step S4101 may be implemented as an independent embodiment, and step S4102 may be implemented as an independent embodiment, but is not limited thereto.

[0368] Figure 4b is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in Figure 4b, the present disclosure embodiment relates to an information processing method, which is executed by a user identification module of a terminal, and the method includes:

[0369] Step S4201: Determine the first key and the second key.

[0370] In some embodiments, the optional implementation of step S4201 can refer to the optional implementation of step S2201 in Figure 2b and other related parts of the embodiment involved in Figure 2b, which will not be repeated here.

[0371] Step S4202: Send the first key and the second key to the mobile equipment ME of the terminal.

[0372] In some embodiments, the first key and the second key are used by the ME to obtain a third key; the third key is used to determine a fourth key, a fifth key and / or a sixth key.

[0373] In some embodiments, the optional implementation of step S4202 can refer to the optional implementation of step S2202 in Figure 2b and other related parts of the embodiment involved in Figure 2b, which will not be repeated here.

[0374] In some embodiments, the first key sent to the ME is a key processed by a first operation; the second key sent to the ME is a key processed by the first operation; wherein the first operation includes an operation of reducing the number of bits of the first key and the second key; wherein the first operation includes an operation of reducing the number of bits of the first key and the second key.

[0375] In some embodiments, the fourth key is a security key Kausf; the fifth key is a first encryption key CK'; and the sixth key is a first integrity protection key IK'.

[0376] In some embodiments, the first key is a second encryption key CK, and the second key is a second integrity protection key IK.

[0377] In some embodiments, the number of bits of the first key before the bit number reduction is 256, the number of bits of the second key before the bit number reduction is 256, the number of bits of the first key after the bit number reduction is 128, and the number of bits of the second key after the bit number reduction is 128.

[0378] In some embodiments, determining the first key and the second key includes:

[0379] The first key and the second key are determined based on a subscriber key K.

[0380] In some embodiments, the method further comprises:

[0381] Determining an algorithm set based on the number of bits of K;

[0382] The algorithm set is used to determine the first key and the second key.

[0383] In some embodiments, the method further comprises:

[0384] Determine the number of bits of K to be a first number, and determine the algorithm set to be at least one of the following:

[0385] MILENAGE-256-R algorithm suite;

[0386] MILENAGE-256-A algorithm suite;

[0387] 256-bit algorithm set based on ZUC;

[0388] Tuak algorithm suite.

[0389] In some embodiments, the method further comprises:

[0390] Determine that the number of bits of K is 256, and determine that the algorithm set is at least one of the following:

[0391] MILENAGE-256-R algorithm suite;

[0392] MILENAGE-256-A algorithm suite;

[0393] 256-bit algorithm set based on ZUC;

[0394] Tuak algorithm suite.

[0395] Figure 5a is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in Figure 5a, the present disclosure embodiment relates to an information processing method, which is executed by the ME of the terminal, and the method includes:

[0396] Step S5101: Receive a first key and a second key sent by a user identification module of a terminal.

[0397] In some embodiments, the optional implementation of step S5101 can refer to the optional implementation of step S2301 in Figure 2c and other related parts of the embodiment involved in Figure 2c, which will not be repeated here.

[0398] Step S5102: Determine the fourth key, the fifth key and / or the sixth key based on the third key.

[0399] In some embodiments, the optional implementation of step S5102 can refer to the optional implementation of step S2302 in Figure 2c and other related parts of the embodiment involved in Figure 2c, which will not be repeated here.

[0400] The information indication method involved in the embodiment of the present disclosure may include at least one of step S5101 to step S5102. For example, step S5101 may be implemented as an independent embodiment, and step S5102 may be implemented as an independent embodiment, but is not limited thereto.

[0401] Figure 5b is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in Figure 5b, the present disclosure embodiment relates to an information processing method, which is executed by the ME of the terminal, and the method includes:

[0402] Step S5201: Receive a first key and a second key sent by a user identification module of a terminal.

[0403] In some embodiments, the first key and the second key are used by the ME to obtain a third key; the third key is used to determine a fourth key, a fifth key and / or a sixth key.

[0404] In some embodiments, the optional implementation of step S5201 can refer to the optional implementation of step S2301 in Figure 2c and other related parts of the embodiment involved in Figure 2c, which will not be repeated here.

[0405] In some embodiments, the first key and the second key are keys obtained after the user identification module is processed by a first operation; the first operation is an operation of reducing the number of bits of the first key and the second key.

[0406] In some embodiments, the method further comprises:

[0407] A first operation is performed on the first key and the second key to obtain the third key; wherein the first operation includes at least one of the following: an operation of reducing the number of bits of the first key and the second key; an operation of performing an exclusive OR operation on the first key and the second key.

[0408] In some embodiments, the fourth key is a security key Kausf; the fifth key is a first encryption key CK'; and the sixth key is a first integrity protection key IK'.

[0409] In some embodiments, the first key is a second encryption key CK, and the second key is a second integrity protection key IK.

[0410] In some embodiments, the first operation is an operation of reducing the number of bits of the first key and the second key, and the third key includes: the first key with reduced bit numbers and the second key with reduced bit numbers.

[0411] In some embodiments, the number of bits of the first key before the bit number reduction is 256, the number of bits of the second key before the bit number reduction is 256, the number of bits of the first key after the bit number reduction is 128, and the number of bits of the second key after the bit number reduction is 128.

[0412] In some embodiments, the first operation is: performing an exclusive OR operation on the first key and the second key, and the third key includes: a result obtained by performing an exclusive OR operation on the first key and the second key.

[0413] In some embodiments, the first operation is an operation of performing an exclusive OR operation on the first key and the second key; the number of bits of the first key is 256; the number of bits of the second key is 256, and the number of bits of the third key is 256.

[0414] In some embodiments, the fourth key is Kausf; the third key is used to determine the input key of the key derivation function KDF of the Kausf.

[0415] In some embodiments, the fifth key is the first encryption key CK'; and the third key is used to determine an input key of a key derivation function KDF of the first encryption key CK'.

[0416] In some embodiments, the sixth key is a first integrity protection key IK'; and the third key is used to determine an input key of a key derivation function KDF of the first integrity protection key IK'.

[0417] In order to better understand the embodiments of the present disclosure, the technical solution of the present disclosure is further described below through two exemplary embodiments:

[0418] Example 1, authentication process applied to 5G AKA:

[0419] Referring to FIG. 6a , an embodiment of the present disclosure provides an information indication method, the method comprising:

[0420] Step S6101: UDM or ARPF generates AV;

[0421] Exemplarily, if the number of bits of the subscriber key (K) obtained by the UDM or ARPF is 256, the UDM or ARPF should select the MILENAGE-256-R algorithm set, the MILENAGE-256-A algorithm set, the ZUC-based 256-bit algorithm set and / or the Tuak algorithm set. For each Nudm_Authenticate_Get request, the UDM or ARPF will create a 5G HE AV. By using MILENAGE-256-R or Tuak (it should be noted that in some embodiments, if the number of bits of the subscriber key is 256, the UDM / ARPF selects the Tuak algorithm and obtains a 256-bit CK and a 256-bit IK based on the Tuak algorithm), the number of bits of CK and IK in the 5G HE authentication vector (AV, Authenticate Vector) is 256. Then, the UDM or ARPF will derive K AUSF And calculate XRES*. Finally, UDM or ARPF will be based on RAND, AUTN, XRES* (expected response value) and KAUSF To create 5G HE AV. Specifically, to generate K AUSF , UDM or ARPF should truncate the 256-bit CK to generate a 128-bit CK. AUSF , the UDM or ARPF shall truncate the 256-bit IK to generate a 128-bit IK. For example, the 128 most or least significant bits of the 256-bit CK or the 256-bit IK can be used as the 128-bit CK or the 128-bit IK. The UDM or ARPF uses the truncated CK (i.e., the 128-bit CK) and IK (i.e., the 128-bit IK) to construct the 256-bit input key of the KDF. The UDM or ARPF then generates the KDF based on the newly derived 256-bit input key. AUSF .

[0422] Step S6102: The UDM or ARPF sends Nudm_UEAuthentication_Get Response (response message) to the Authentication Server Function (AUSF);

[0423] For example, Nudm_UEAuthentication_Get Response may include:

[0424] (5G HE AV,[SUPI],[AKMA indication],[Routing indicator]).

[0425] Illustratively, the UDM will return the 5G HE AV to the AUSF in the Nudm_UEAuthentication_Get response together with an indication that the 5G HE AV will be used for 5G AKA.

[0426] Step S6103: AUSF stores XRES* (response parameter value);

[0427] Step S6104: AUSF calculates HXRES* (response parameter value);

[0428] Step S6105: AUSF sends Nausf_UEAuthentication_Authenticate Response (response message) to SEAF;

[0429] For example, Nausf_UEAuthentication_Authenticate Response may include:

[0430] (5G SE AV).

[0431] Step S6106: SEAF sends an Authentication Request to the UE.

[0432] Step S6107: UE calculates Authentication Response (RES*);

[0433] The USIM calculates the response RES, 256-bit CK and 256-bit IK by using MILENAGE-256-R. The USIM may return the RES, 256-bit CK and 256-bit IK to the ME. Alternatively, before returning the RES, 128-bit CK and 128-bit IK to the ME, the USIM may truncate the 256-bit CK and 256-bit IK to 128-bit CK and 238-bit IK in the same way as the UDM or ARPF side. In order to generate K AUSF If a 256-bit CK and a 256-bit IK are received from the USIM, the ME shall truncate the 256-bit CK and 256-bit IK to 128-bit CK and 128-bit IK in the same manner as the UDM or ARPF side. The ME uses the truncated CK (i.e., 128-bit CK) and IK (i.e., 128-bit IK) to generate the 256-bit input key of the KDF. The ME then uses the derived 256-bit input key to generate the KDF. AUSF . ME should be from K AUSF Calculate K SEAF .

[0434] Step S6108: UE sends Authentication Response to SEAF;

[0435] Step S6109: SEAF calculates HRES* and compares it with HXRES*;

[0436] Step S6110: SEAF sends Nausf_UEAuthentication_Authenticate Request (authentication request) to AUSF;

[0437] Illustratively, Nausf_UEAuthentication_Authenticate Request includes:

[0438] (RES*)

[0439] Step S6111: AUSF performs RES* verification;

[0440] Step S6112: AUSF sends Nausf_UEAuthentication_Authenticate Response (authentication response) to SEAF;

[0441] Illustratively, Nausf_UEAuthentication_Authenticate Response includes:

[0442] (Result,[SUPI],KSEAF)

[0443] Example 2, applied to the EAP-AKA authentication process:

[0444] Referring to FIG. 6 b , an embodiment of the present disclosure provides an information indication method, the method comprising:

[0445] Step S6201: UDM or ARPF generates AV;

[0446] If the number of bits of the subscriber key (K) obtained by the UDM or ARPF is 256, the UDM or ARPF should select the MILENAGE-256-R algorithm set, the MILENAGE-256-A algorithm set, the ZUC-based 256-bit algorithm set, and / or the Tuak algorithm set. By using MILENAGE-256-R or Tuak (it should be noted that in some embodiments, if the number of bits of the subscriber key is 256, the UDM / ARPF selects the Tuak algorithm and obtains a 256-bit CK and a 256-bit IK based on the Tuak algorithm), the number of bits of CK and IK in the authentication vector is 256. The UDM or ARPF will then calculate CK' and IK' and replace CK and IK with CK' and IK'. To generate CK' and IK', the UDM or ARPF should truncate the 256-bit CK to generate a 128-bit CK. To generate CK' and IK', the UDM or ARPF truncates the 256-bit IK to generate a 128-bit IK. For example, the 128 most or least significant bits of the 256-bit CK or 256-bit IK can be used as the 128-bit CK or 128-bit IK. The UDM or ARPF uses the truncated CK (i.e., 128-bit CK) and IK (i.e., 128-bit IK) to generate the 256-bit input key for the KDF. The UDM or ARPF then uses the derived 256-bit input key to generate CK' and IK'.

[0447] Step S6202: UDM or ARPF sends Nudm_UEAuthentication_Get Response (authentication response message) to AUSF;

[0448] For example, Nudm_UEAuthentication_Get Response may include:

[0449] (EAP-AKA′AV,[SUPI],[AKMA indication],[Routing indicator]).

[0450] Step S6203: AUSF sends Nausf_UEAuthentication_Authenticate Response (authentication response message) to the Security Anchor Function (SEAF);

[0451] Illustratively, Nausf_UEAuthentication_Authenticate Response includes:

[0452] [EAP Request / AKA′-Challenge].

[0453] Step S6204: SEAF sends Auth-Req to UE;

[0454] For example, the Auth-Req contains:

[0455] [EAP Request / AKA′-Challenge,ngKSI,ABBA];

[0456] Step S6205: Calculate Auth.Response (authentication response message);

[0457] Exemplarily, the USIM calculates the response RES. The USIM generates a 256-bit IK and a 256-bit CK using MILENAGE-256-R. The USIM may return the RES, 256-bit CK, and 256-bit IK to the ME. Alternatively, the USIM truncates the 256-bit CK or 256-bit IK to 128 bits in the same manner as the UDM or ARPF side, and returns the RES, 128-bit CK, and 128-bit IK to the ME. The ME shall derive CK' and IK'. If a 256-bit CK is received from the USIM, the ME shall truncate the 256-bit CK to a 128-bit CK in the same manner as the UDM or ARPF side. If a 256-bit IK is received from the USIM, the ME shall truncate the 256-bit IK to a 128-bit IK in the same manner as the UDM or ARPF side. The ME generates IK' and CK' based on the 128-bit IK and 128-bit CK obtained after truncation.

[0458] Step S6206: UE sends Auth-Resp (authentication response message) to SEAF;

[0459] For example, the Auth-Resp contains:

[0460] [EAP Response / AKA′-Challenge];

[0461] Step S6207: SEAF sends Nausf_UEAuthentication_Authenticate Request (authentication response message) to AUSF;

[0462] In some embodiments, the Nausf_UEAuthentication_Authenticate Request includes:

[0463] [EAP Response / AKA′-Challenge];

[0464] Step S6208: AUSF verifies Response;

[0465] Step S6209: performing optional further EAP message exchange between the UE and the AUSF;

[0466] Step S6210: AUSF sends Nausf_UEAuthentication_Authenticate Response (authentication response message) to SEAF;

[0467] Illustratively, Nausf_UEAuthentication_Authenticate Response includes:

[0468] [EAP Success||Anchor Key];

[0469] [SUPI].

[0470] Step S6211: SEAF sends N1 message to UE;

[0471] For example, the N1 message includes:

[0472] [EAP Success,ngKSI,ABBA].

[0473] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0474] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0475] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0476] Figure 7a is a schematic structural diagram of a terminal 7100 proposed in an embodiment of the present disclosure. The terminal 7100 may include a user identification module and an ME. As shown in Figure 7a, the terminal 7100 (which may also be a user identification module and an ME) may include: at least one of a transceiver module 7101 and a processing module 7102. In some embodiments, the transceiver module 7101 is used to send and receive information. Optionally, the transceiver module 7101 is used to execute at least one of the communication steps such as sending and / or receiving executed by the terminal in any of the above methods, which will not be described in detail here. Optionally, the processing module 7102 is used to execute at least one of the other steps executed by the terminal in any of the above methods, which will not be described in detail here.

[0477] Figure 7b is a schematic diagram of the structure of a network device 7200 (which may be a core network device) proposed in an embodiment of the present disclosure. As shown in Figure 7b, the network device 7200 may include: at least one of a transceiver module 7201, a processing module 7202, etc. In some embodiments, the transceiver module 7201 is used to send and receive information. Optionally, the transceiver module 7201 is used to perform at least one of the communication steps such as sending and / or receiving performed by the network device in any of the above methods, which will not be repeated here. Optionally, the processing module 7202 is used to perform at least one of the other steps performed by the network device in any of the above methods, which will not be repeated here.

[0478] Figure 8a is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure. Communication device 8100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 8100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0479] As shown in Figure 8a, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, baseband chip, terminal device, terminal device chip, DU or CU, etc.), execute programs, and process program data. The communication device 8100 is used to perform any of the above methods.

[0480] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may be located outside the communication device 8100.

[0481] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceiver 8103 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processor 8101 performs at least one of the other steps.

[0482] In some embodiments, a transceiver may include a receiver and / or a transmitter. The receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.

[0483] In some embodiments, the communication device 8100 may include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected to the memory 8102. The interface circuit 8104 may be configured to receive signals from the memory 8102 or other devices, and may be configured to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 may read instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0484] The communication device 8100 described in the above embodiment may be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8a. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0485] FIG8b is a schematic diagram of the structure of a chip 8200 according to an embodiment of the present disclosure. If the communication device 8100 can be a chip or a chip system, reference can be made to the schematic diagram of the structure of the chip 8200 shown in FIG8b, but the present disclosure is not limited thereto.

[0486] The chip 8200 includes one or more processors 8201 , and the chip 8200 is configured to execute any of the above methods.

[0487] In some embodiments, the chip 8200 further includes one or more interface circuits 8202. Optionally, the interface circuit 8202 is connected to the memory 8203. The interface circuit 8202 can be used to receive signals from the memory 8203 or other devices, and can be used to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201.

[0488] In some embodiments, the interface circuit 8202 executes at least one of the communication steps such as sending and / or receiving in the above method (for example, step S2101, step S3101, but not limited thereto), and the processor 8201 executes at least one of the other steps.

[0489] In some embodiments, terms such as interface circuit, interface, transceiver pin, and transceiver may be used interchangeably.

[0490] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Alternatively, all or part of the memories 8203 may be outside the chip 8200.

[0491] The present disclosure also proposes a storage medium having instructions stored thereon, which, when executed on the communication device 8100, causes the communication device 8100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto, and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto, and may also be a temporary storage medium.

[0492] The present disclosure also provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0493] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.

Claims

1. An information processing method, characterized in that, The method is executed by a core network device, and the method includes: Determine a first key and a second key; Perform a first operation on the first key and the second key to obtain a third key; wherein, the third key is used to determine a fourth key, a fifth key, and / or a sixth key; the first operation includes at least one of the following: An operation to reduce the number of bits of the first key and the second key; An operation to perform an exclusive OR operation on the first key and the second key.

2. The method according to claim 1, characterized in that The fourth key is the security key Kausf, the fifth key is the first encryption key CK', and the sixth key is the first integrity protection key IK'.

3. The method according to claim 1, wherein The first key is the second encryption key CK, and the second key is the second integrity protection key IK.

4. The method according to claim 1, wherein The first operation is: an operation to reduce the number of bits of the first key and the second key, and the third key includes: the first key with the reduced number of bits and the second key with the reduced number of bits.

5. The method according to claim 4, characterized in that, The number of bits of the first key before the reduction of the number of bits is 256, the number of bits of the second key before the reduction of the number of bits is 256, the number of bits of the first key after the reduction of the number of bits is 128, and the number of bits of the second key after the reduction of the number of bits is 128.

6. The method according to claim 1, wherein The first operation is: an operation to perform an exclusive OR operation on the first key and the second key, and the third key includes: the result obtained by performing an exclusive OR operation on the first key and the second key.

7. The method according to claim 6, characterized in that The number of bits of the first key is 256, the number of bits of the second key is 256, and the number of bits of the third key is 256.

8. The method according to claim 1, wherein The fourth key is Kausf; the third key is used to determine the input key of the key derivation function KDF of the Kausf.

9. The method according to claim 1, characterized in that, The fifth key is the first encryption key CK'; the third key is used to determine the input key of the key derivation function KDF of the first encryption key CK'.

10. The method according to claim 1, characterized in that, The sixth key is the first integrity protection key IK'; the third key is used to determine the input key of the key derivation function KDF of the first integrity protection key IK'.

11. The method according to any one of claims 1 to 10, characterized in that, The determination of the first key and the second key includes: Determine the first key and the second key based on the subscription user key K.

12. The method according to claim 11, wherein The method further includes: Determine an algorithm set based on the number of bits of the K; wherein, the algorithm set is used to determine the first key and the second key.

13. The method according to claim 12, wherein The method further includes: Determine that the number of bits of the K is a first quantity, and determine that the algorithm set is at least one of the following: MILENAGE-256-R algorithm set; MILENAGE-256-A algorithm set; 256-bit algorithm set based on ZUC; Tuak algorithm set.

14. An information processing method, characterized in that, The method is executed by the user identification module of the terminal, and the method includes: Determine a first key and a second key; Send the first key and the second key to the mobile device ME of the terminal; wherein, the first key and the second key are used for the ME to obtain a third key; the third key is used to determine a fourth key, a fifth key, and / or a sixth key.

15. The method according to claim 14, wherein The first key sent to the ME is the key processed by a first operation; the second key sent to the ME is the key processed by the first operation; wherein, the first operation includes an operation of reducing the number of bits of the first key and the second key.

16. The method according to claim 14, characterized in that, The fourth key is the security key Kausf; the fifth key is the first encryption key CK'; the sixth key is the first integrity protection key IK'.

17. The method according to claim 14, wherein The first key is the second encryption key CK, and the second key is the second integrity protection key IK.

18. The method according to claim 15, wherein The number of bits of the first key before the reduction of the number of bits is 256, the number of bits of the second key before the reduction of the number of bits is 256, the number of bits of the first key after the reduction of the number of bits is 128, and the number of bits of the second key after the reduction of the number of bits is 128.

19. The method according to any one of claims 14 to 18, characterized in that Determining the first key and the second key includes: Determining the first key and the second key based on the subscriber key K.

20. The method according to claim 19, characterized in that, The method further includes: Determining an algorithm set based on the number of bits of the K; wherein, the algorithm set is used to determine the first key and the second key.

21. The method according to claim 18, wherein The method further includes: Determining that the number of bits of the K is a first quantity, and determining that the algorithm set is at least one of the following: MILENAGE-256-R algorithm set; MILENAGE-256-A algorithm set; 256-bit algorithm set based on ZUC; Tuak algorithm set.

22. An information processing method, characterized in that, The method is executed by the ME of the terminal, and the method includes: Receiving a first key and a second key sent by the user identification module of the terminal; wherein, the first key and the second key are used for the ME to obtain a third key; the third key is used to determine a fourth key, a fifth key and / or a sixth key.

23. The method according to claim 22, characterized in that, The first key and the second key are the keys obtained by the user identification module after being processed by a first operation; the first operation is an operation of reducing the number of bits of the first key and the second key.

24. The method according to claim 22, wherein The method further includes: Performing a first operation on the first key and the second key to obtain the third key; wherein, the first operation includes at least one of the following: an operation of reducing the number of bits of the first key and the second key; an operation of performing an exclusive OR operation on the first key and the second key.

25. The method according to claim 22, wherein The fourth key is the security key Kausf; the fifth key is the first encryption key CK'; the sixth key is the first integrity protection key IK'.

26. The method according to claim 22, wherein The first key is the second encryption key CK, and the second key is the second integrity protection key IK.

27. The method according to claim 23 or 24, characterized in that The first operation is: an operation of reducing the number of bits of the first key and the second key, and the third key includes: the first key after the reduction of the number of bits and the second key after the reduction of the number of bits.

28. The method according to claim 27, wherein The number of bits of the first key before the reduction of the number of bits is 256, the number of bits of the second key before the reduction of the number of bits is 256, the number of bits of the first key after the reduction of the number of bits is 128, and the number of bits of the second key after the reduction of the number of bits is 128.

29. The method according to claim 24, wherein The first operation is: an operation of performing an exclusive OR operation on the first key and the second key, and the third key includes: the result obtained after performing an exclusive OR operation on the first key and the second key.

30. The method according to claim 29, wherein The first operation is an operation of performing an exclusive OR operation on the first key and the second key; the number of bits of the first key is 256; the number of bits of the second key is 256, and the number of bits of the third key is 256.

31. The method according to claim 22, wherein The fourth key is Kausf; the third key is used as the input key of a key derivation function KDF for determining the key of Kausf.

32. The method according to claim 22, wherein The fifth key is the first encryption key CK'; the third key is used as the input key of a key derivation function KDF for determining the key of the first encryption key CK'.

33. The method according to claim 22, wherein The sixth key is the first integrity protection key IK'; the third key is used as the input key of a key derivation function KDF for determining the key of the first integrity protection key IK'.

34. An information indication method, characterized in that The method includes: A user identification module of a terminal sends the first key and the second key to a mobile device ME of the terminal; wherein, the first key and the second key are used to obtain a third key; the third key is used to determine a fourth key, a fifth key, and / or a sixth key. key.

35. A core network device, characterized in that, The core network device includes: A processing module, configured to: Determine a first key and a second key; Perform a first operation on the first key and the second key to obtain a third key; wherein, the third key is used to determine a fourth key, a fifth key, and / or a sixth key; the first operation includes at least one of the following: An operation of reducing the number of bits of the first key and the second key; An operation of performing an exclusive OR operation on the first key and the second key.

36. A user identification module of a terminal, characterized in that, The user identification module of the terminal includes: a processing module, configured to: determine a first key and a second key; A transceiver module, configured to: send the first key and the second key to a mobile device ME of the terminal; wherein, the first key and the second key are used for the ME to obtain a third key; the third key is used to determine a fourth key, a fifth key, and / or a sixth key.

37. The ME of a terminal, characterized in that, The ME of the terminal includes: A transceiver module, configured to: Receive the first key and the second key sent by the user identification module of the terminal; Wherein, the first key and the second key are used for the ME to obtain a third key; the third key is used to determine a fourth key, a fifth key, and / or a sixth key.

38. A communication system, characterized in that, The communication system includes a user identification module of a terminal and the ME of the terminal; the user identification module of the terminal is configured to implement the method according to any one of claims 14 to 21, and the ME of the terminal is configured to implement the method according to any one of claims 22 to 33.

39. A core network device, characterized in that, The core network device includes: One or more processors; Wherein, the core network device is used to execute the method according to any one of claims 1 to 13.

40. A user identification module of a terminal, characterized in that, The user identification module of the terminal includes: One or more processors; Wherein, the user identification module of the terminal is used to execute the method according to any one of claims 14 to 21.

41. The ME of a terminal, characterized in that, The ME of the terminal includes: One or more processors; Wherein, the ME of the terminal is used to execute the method described in any one of claims 22 to 33.

42. A storage medium, characterized in that, The storage medium stores instructions, which, when running on a communication device, cause the communication device to execute the method described in any one of claims 1 to 13, claims 14 to 21, and claims 22 to 33.

Citation Information

Patent Citations

  • Improved installation of a terminal in a secure system

    CN107210911A

  • Method, device and equipment for generating secret key and storage medium

    CN112039657A

  • Key derivation algorithm negotiation method and apparatus

    US20200221297A1

  • Encrypting discovery messages

    US20230362633A1

  • Secure information pushing by service applications in communication networks

    WO2023082161A1