Communication method and communication apparatus
Through negotiation and determining the key negotiation algorithm, the application scenario restriction caused by the fixed key exchange algorithm in the prior art is solved, and the security and flexibility of network access are improved.
Patent Information
- Application Number
- PCT/CN2025/072828
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-22
- Filing Date
- 2025-01-16
- Publication Date
- 2025-07-31
AI Technical Summary
In the prior art, the network side and the terminal use a fixed key exchange algorithm to generate shared keys, resulting in limited application scenarios and unable to adapt to the diverse needs of different security levels, computing complexity and terminal types.
By verifying the key negotiation algorithm between the network element and the communication device, selecting suitable key negotiation algorithms, such as the combination algorithm of ECDHE, PQC, ECDH, PQC and ECDHE, to improve the security and flexibility of key exchange.
It realizes the flexible selection of key negotiation algorithm, adapts to more application scenarios, and improves the security of network access and the efficiency of authentication process.
Smart Images

Figure CN2025072828_31072025_PF_FP_ABST
Abstract
Description
Communication method and communication device
[0001] This application claims priority to the Chinese patent application with application number 202410095116.1 filed with the State Intellectual Property Office of China on January 22, 2024, and priority to the Chinese patent application with the invention name “Communication Method and Communication Device”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and more particularly, to a communication method and a communication device. Background Art
[0003] In terms of network security, the network's tasks include authenticating and authorizing terminals accessing the network, enabling them to connect to the operator's network and initiating over-the-air encryption for their business communications. Currently, the terminal and the network use elliptic curve Diffie–Hellman (ECDH) key exchange to negotiate and generate a shared key. The terminal then transmits its identification information based on this shared key, allowing the network to obtain the root key corresponding to the terminal's identification information, thus completing mutual authentication. In this solution, the network and terminal use a fixed key exchange algorithm to generate the shared key, limiting its application scenarios. Summary of the Invention
[0004] The present application provides a communication method and a communication device, which can improve the flexibility of user access to the network.
[0005] On the first aspect, a communication method is provided. The method can be executed by a verification network element, or can also be executed by a component of the verification network element (such as a chip or circuit). There is no limitation on this. For the sake of ease of description, the following is explained using the execution by the verification network element as an example.
[0006] The method includes: receiving first indication information from a communication device, the first indication information indicating at least one key agreement algorithm; sending second indication information to the communication device, the second indication information indicating a first key agreement algorithm, the first key agreement algorithm being one of the at least one key agreement algorithm, the first key agreement algorithm being used to determine a first key, the first key being used to encrypt or decrypt messages transmitted between the communication device and the verification network element.
[0007] Based on the above scheme, the verification network element and the communication device can determine the key agreement algorithm in the authentication process through negotiation, so that the selection of the key agreement algorithm in the authentication process is more flexible and adaptable to more application scenarios. That is, the communication device indicates at least one key agreement algorithm to the verification network element, and the verification network element determines a first key agreement algorithm from the at least one key agreement algorithm, and the first key agreement algorithm is used for the first key.
[0008] In certain implementations of the first aspect, the first key agreement algorithm is determined based on first information and the first indication information, and the first information includes at least one of the following information: the security level corresponding to the key agreement algorithm, the computational complexity of the key agreement algorithm, the network standard, the type of the communication device, and the computing capability of the communication device.
[0009] Based on the above scheme, by determining the first key agreement algorithm according to the first information, the first key agreement algorithm can be adapted to at least one of different security levels, computational complexities, network standards, types of communication devices, and computing capabilities of the communication devices.
[0010] In certain implementations of the first aspect, the at least one key agreement algorithm includes at least one of the following: an elliptic curve Diffie–Hellman (ECDH) key agreement algorithm, an ephemeral elliptic curve Diffie–Hellman (ECDHE) key agreement algorithm, a key agreement algorithm based on post-quantum cryptography (PQC), a key agreement algorithm based on PQC and ECDH, a key agreement algorithm based on PQC and ECDHE, and a key agreement algorithm based on a pre-set key.
[0011] In some implementations of the first aspect, the first key is determined based on the first key agreement algorithm.
[0012] In certain implementations of the first aspect, the first key agreement algorithm is the ECDHE key agreement algorithm. In the ECDHE key agreement algorithm, the verification network element receives a first public key from the communication device, where the first public key is the public key in a first temporary public-private key pair generated by the communication device; the verification network element determines the first key based on the first public key and the second private key, where the second private key is the private key in a second temporary public-private key pair generated by the verification network element.
[0013] Based on the above solution, the verification network element and the communication device can negotiate and determine the use of the ECDHE key agreement algorithm. In the ECDHE key agreement algorithm, the verification network element and the communication device use the temporary public key generated by the other party to generate the first key, improving the security of key exchange. Secondly, the key agreement algorithm has low computational complexity and is suitable for communication scenarios with low computational complexity and high security requirements.
[0014] In certain implementations of the first aspect, the verification network element sends a second public key to the communication device, where the second public key is a public key in the second temporary public-private key pair. By sending the second public key to the communication device, the communication device can determine the first key based on the second public key.
[0015] In certain implementations of the first aspect, the first key agreement algorithm is the PQC-based key agreement algorithm. In the PQC-based key agreement algorithm, the verification network element receives a third public key from the communication device, where the third public key is the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; the verification network element inputs the third public key into the post-quantum algorithm to generate a ciphertext and the first key.
[0016] Based on the above solution, the verification network element and the communication device can negotiate and determine the use of a PQC-based key agreement algorithm. In the PQC-based key agreement algorithm, the verification network element and the communication device use PQC to generate the first key, which can improve the security of key exchange. This key agreement algorithm is applicable to communication scenarios with high security requirements.
[0017] In certain implementations of the first aspect, the verification network element sends the ciphertext to the communication device. By sending the ciphertext to the communication device, the communication device can determine the first key based on the ciphertext.
[0018] In certain implementations of the first aspect, the first key agreement algorithm is the key agreement algorithm based on PQC and ECDH. In the key agreement algorithm based on PQC and ECDH, the verification network element receives a first public key and a third public key from the communication device, the first public key being the public key in a first temporary public-private key pair generated by the communication device, and the third public key being the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; the verification network element determines the second key based on the first public key and the private key of the verification network element, and inputs the third public key into the post-quantum algorithm to generate a ciphertext and a third key; the verification network element determines the first key based on the second key and the third key.
[0019] Based on the above solution, the verification network element and the communication device can negotiate and determine the use of a key agreement algorithm based on PQC and ECDH. In this key agreement algorithm, the verification network element and the communication device can generate the first key based on a key generated by PQC and a key generated by ECDH, thereby improving the security of key exchange. Compared to the PQC-based key agreement algorithm, this key agreement algorithm is suitable for communication scenarios with higher security requirements.
[0020] In certain implementations of the first aspect, the verification network element sends the public key of the verification network element and the ciphertext to the communication device, and the public key of the verification network element and the ciphertext are used by the communication device to determine the first key.
[0021] In certain implementations of the first aspect, the first key agreement algorithm is the key agreement algorithm based on PQC and ECDHE. In the key agreement algorithm based on PQC and ECDHE, the verification network element receives a first public key and a third public key from the communication device, the first public key being the public key in a first temporary public-private key pair generated by the communication device, and the third public key being the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; the verification network element determines a second key based on the first public key and the second private key, the second private key being the private key in the second temporary public-private key pair generated by the verification network element, and inputting the third public key into the post-quantum algorithm to generate a ciphertext and a third key; the verification network element determines the first key based on the second key and the third key.
[0022] Based on the above solution, the verification network element and the communication device can negotiate and determine the use of a key agreement algorithm based on PQC and ECDHE. In the key agreement algorithm based on PQC and ECDH, the verification network element and the communication device can generate the first key based on the key generated by PQC and the key generated by ECDHE, thereby improving the security of key exchange. ECDHE has forward security and is suitable for communication scenarios with higher security requirements compared to key agreement algorithms based on PQC and ECDH.
[0023] In certain implementations of the first aspect, the verification network element sends a second public key and the ciphertext to the communication device, where the second public key is the public key in the second temporary public-private key pair. By sending the second public key and the ciphertext to the communication device, the communication device can determine the first key based on the second public key and the ciphertext.
[0024] In certain implementations of the first aspect, the verification network element sends a first digital signature to the communication device, where the first digital signature is a signature of the verification network element's private key on a first message, where the first message includes messages over which the verification network element and the communication device have interacted; and sends a certificate of the verification network element to the communication device, where the certificate includes the verification network element's public key, and the verification network element's public key is used by the communication device to verify the first digital signature.
[0025] Exemplarily, the messages that have been interacted between the verification network element and the communication device may include the most recent message sent by the verification network element to the terminal device, for example, the message carrying the first digital signature; or the interacted messages may include all messages that have been interacted with the communication device before the verification network element sends the most recent message to the communication device (for example, the communication device sends a message with the first public key or the third public key to the verification network element, recorded as message #1, and the verification network element sends a message with the first digital signature, recorded as message #2. The messages that have been interacted between the verification network element and the communication device may include message #1 and message #2). Optionally, before the verification network element sends the first digital signature to the communication device, the verification network element may store the messages that have been interacted with the communication device.
[0026] Exemplarily, verifying the messages exchanged between the network element and the communication device may further include sending the message with the first digital signature. For example, the message with the first digital signature is a radio resource control (RRC) message or a non-access stratum (NAS) message.
[0027] Based on the above solution, by sending the certificate of the verification network element and the first digital signature to the communication device, the communication device can authenticate the verification network element, simplifying the process of the communication device authenticating the verification network element and saving signaling overhead.
[0028] In certain implementations of the first aspect, a request message is received from the communication device, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, and the first identifier corresponds to the authentication information of the communication device; the verification network element obtains first authentication information in the authentication information based on the first identifier; and the communication device is authenticated based on the first authentication information.
[0029] Based on the above solution, the authentication network element obtains the authentication information required by the communication device corresponding to the first identifier based on the first identifier, and authenticates the communication device according to the authentication information, which can improve the flexibility of communication device authentication.
[0030] In certain implementations of the first aspect, before receiving the request message from the communication device, third indication information is received from the communication device, the third indication information indicating at least one authentication method, and the authentication information of the communication device indicated by each authentication method in the at least one authentication method is independent of each other; and fourth indication information is sent to the communication device, the fourth indication information indicating a first authentication method, the first authentication method being one of the at least one authentication method, and the first authentication method corresponding to the first authentication information.
[0031] Based on the above scheme, the verification network element and the communication device can determine the authentication method through negotiation, making the selection of the authentication method more flexible and adaptable to more application scenarios, that is, the communication device indicates at least one authentication method to the verification network element, and the verification network element determines the first authentication method from the at least one authentication method.
[0032] In certain implementations of the first aspect, the authentication information includes any one of the following information: a credential of the communication device, a cryptographic algorithm; wherein the credential of the communication device includes a public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.
[0033] Based on the above solution, by determining the first authentication method according to the third information, the first authentication method can be adapted to different credentials and cryptographic algorithms of the communication device.
[0034] In certain implementations of the first aspect, the type of the first identifier indicated by each of the at least one authentication method is different, and the first identifier includes at least one of the following: a first type of identifier of the communication device, a second type of identifier of the communication device, an identifier of a block or an identifier of a transaction, and a virtual identifier of the communication device; wherein the first type of identifier has a first corresponding relationship with a root key of the communication device, the second type of identifier has a second corresponding relationship with at least one certificate of the communication device, the identifier of the block or the identifier of the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.
[0035] Based on the above solution, the verification network element can obtain authentication information of the communication device based on different identifiers, making the authentication process applicable to various scenarios. For example, the first type of identifier is compatible with 5G communication systems; compared to the first type of identifier, the second type of identifier can be used in scenarios where services with high requirements for personal information confidentiality are required; in some scenarios, virtual identifiers can be used to further enhance communication security.
[0036] In certain implementations of the first aspect, the first authentication method is determined based on second information and the third indication information, and the second information includes at least one of the following information: the issuer of the certificate of the communication device, the security level of the certificate of the communication device, and the cryptographic algorithm corresponding to the certificate of the communication device.
[0037] Based on the above solution, the verification network element can make the authentication process more flexible based on at least one of the issuer of the certificate of the communication device used in the authentication process, the security level of the certificate of the communication device, and the cryptographic algorithm corresponding to the certificate of the communication device.
[0038] In certain implementations of the first aspect, the first authentication information includes a first credential of the communication device, and the first credential is verified based on the credential of the issuer of the first credential; a second digital signature is received from the communication device, and the second digital signature is a signature of a second message using a private key of the communication device, and the second message includes a message that the communication device has interacted with the verification network element; and the second digital signature is verified based on a public key corresponding to the first credential.
[0039] Exemplarily, the messages exchanged between the communication device and the verification network element may include the most recent message sent by the communication device to the verification network element, for example, the exchanged message may include a message carrying the second digital signature; or the exchanged message may include a message after the communication device sends the request message to the verification network element (including the request message) and before the most recent message sent to the verification network element (may include the most recent message sent to the verification network element), for example, the most recent message sent is a message carrying the second digital signature. Optionally, before the communication device sends the second digital signature to the verification network element, the communication device may store the messages exchanged with the verification network element.
[0040] The message carrying the first digital signature may be an RRC message or a NAS message.
[0041] Based on the above scheme, the verification network element can verify the communication device by using the first certificate to verify the signature of the communication device on the interacted message; verifying the first certificate through the certificate of the issuer of the first certificate can determine the security of the first certificate, thereby improving the security of the authentication process.
[0042] On the second aspect, a communication method is provided. The method can be executed by a verification network element, or it can also be executed by a component of the verification network element (such as a chip or circuit). There is no limitation on this. For the sake of convenience of description, the following is explained using the execution by the verification network element as an example.
[0043] The method includes: receiving a temporary public key from a communication device, where the temporary public key is a public key in a temporary public-private key pair generated by the communication device; authenticating the communication device based on a first key, where the first key is determined based on the temporary public key and a second private key, where the second private key is a private key of the verification network element or a private key in a temporary public-private key pair generated by the verification network element, or the first key is generated by inputting the temporary public key into a post-quantum algorithm.
[0044] Based on the above scheme, the verification network element can authenticate the communication device based on a first key, wherein the first key is determined based on the temporary public key of the communication device and the private key of the verification network element or the private key in the temporary public-private key pair generated by the verification network element, or the first key is generated by inputting the temporary public key into a post-quantum algorithm, thereby ensuring the security of the first key and improving the security of authenticating the communication device based on the first key.
[0045] In certain implementations of the second aspect, if the first key is determined based on the temporary public key and the second private key, the second private key is the private key in the temporary public-private key pair generated by the verification network element, and the verification network element sends the second public key to the communication device, and the second public key includes the public key in the temporary public-private key pair generated by the verification network element, and the second public key is used by the communication device to determine the first key.
[0046] Based on the above scheme, the verification network element sends the public key in the temporary public-private key pair generated by the verification network element to the communication device, so that the communication device can determine the first key based on the temporary public key, thereby improving the security of the first key determined by the communication device, thereby improving the security of authentication.
[0047] In certain implementations of the second aspect, the temporary public key is a third public key, which is a public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.
[0048] Based on the above solution, by inputting the temporary public key of the communication device into the post-quantum algorithm to obtain the first key, the security of the first key can be improved, thereby improving the security of authentication.
[0049] In certain implementations of the second aspect, a ciphertext is sent to the communication device, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext is used by the communication device to determine the first key.
[0050] Based on the above scheme, by sending a ciphertext to the communication device, the ciphertext is generated by inputting the third public key into the post-quantum algorithm, so that the communication device can generate the first key based on the ciphertext, which can improve the security of the first key and thus improve the security of the authentication.
[0051] In certain implementations of the second aspect, the temporary public key includes a first public key and a third public key, the first public key being the public key in a first temporary public-private key pair generated by the communication device, the third public key being the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, the first key being determined based on the second key and the third key, the second key being determined based on the second private key and the first public key, and the third key being generated by inputting the third public key into the post-quantum algorithm.
[0052] Based on the above scheme, the verification network element can generate a second key based on the first public key generated by the communication device, and generate a third key based on the third public key generated by the communication device based on the post-quantum algorithm. By generating the first key based on the second key and the third key, the security of the first key can be improved, thereby improving the security of the authentication.
[0053] In certain implementations of the second aspect, a ciphertext and a second public key are sent to the communication device, where the second public key includes the public key of the verification network element or the public key in a temporary public-private key pair generated by the verification network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext and the second public key are used by the communication device to determine the first key.
[0054] Based on the above solution, by sending the ciphertext and the second public key to the communication device, the communication device can generate the first key based on the ciphertext and the second public key, which can improve the security of the first key and thus improve the security of authentication.
[0055] In certain implementations of the second aspect, the temporary public key is sent based on second indication information, the second indication information indicates a first key agreement algorithm, and the first key agreement algorithm is one of at least one key agreement algorithm. Before receiving the temporary public key from the communication device, first indication information is received from the communication device, and the first indication information indicates the at least one key agreement algorithm; the second indication information is sent to the communication device.
[0056] Based on the above solution, the verification network element and the communication device can determine the key negotiation algorithm in the authentication process through negotiation, making the selection of the key negotiation algorithm in the authentication process more flexible and adaptable to more application scenarios.
[0057] In certain implementations of the second aspect, the first key agreement algorithm is determined based on the first information and the first indication information, and the first information includes at least one of the following information: the security level corresponding to the key agreement algorithm, the computational complexity of the key agreement algorithm, the network standard, the type of the communication device, and the computing capability of the communication device.
[0058] The at least one key agreement algorithm refers to the description in the first aspect.
[0059] In certain implementations of the second aspect, a first digital signature is sent to the communication device, where the first digital signature is a signature of a first message using a private key of the verification network element, where the first message includes messages exchanged between the verification network element and the communication device; and a certificate of the verification network element is sent to the communication device, where the certificate includes a public key of the verification network element, where the public key of the verification network element is used by the communication device to verify the first digital signature. The messages exchanged between the verification network element and the communication device may refer to the description of the first aspect.
[0060] Based on the above solution, by sending the first digital signature and the certificate of the verification network element to the communication device, the communication device can verify the first digital signature based on the certificate of the verification network element, and then verify the verification network element. This authentication method simplifies the authentication process and can save signaling overhead.
[0061] In certain implementations of the second aspect, a request message is received from the communication device, the request message being used to request access to the network, the request message including a first identifier encrypted by the first key, the first identifier corresponding to the authentication information of the communication device; the verification network element obtains first authentication information in the authentication information based on the first identifier; and the communication device is authenticated based on the first authentication information.
[0062] Based on the above solution, the authentication network element obtains the authentication information required by the communication device corresponding to the first identifier based on the first identifier, and authenticates the communication device according to the authentication information, which can improve the flexibility of communication device authentication.
[0063] In certain implementations of the second aspect, before receiving the request message from the communication device, third indication information is received from the communication device, the third indication information indicating at least one authentication method, and the authentication information corresponding to each authentication method in the at least one authentication method is independent of each other; and fourth indication information is sent to the communication device, the fourth indication information indicating a first authentication method, the first authentication method being one of the at least one authentication method, and the first authentication method corresponding to the first authentication information.
[0064] Based on the above scheme, the verification network element and the communication device can determine the authentication method through negotiation, making the selection of the authentication method more flexible and adaptable to more application scenarios, that is, the communication device indicates at least one authentication method to the verification network element, and the verification network element determines the first authentication method from the at least one authentication method.
[0065] In certain implementations of the second aspect, the authentication information indicates any one of the following information: a credential of the communication device, a cryptographic algorithm; wherein the credential of the communication device includes a public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.
[0066] Based on the above solution, by determining the first authentication method according to the third information, the first authentication method can be adapted to different credentials and cryptographic algorithms of the communication device.
[0067] In certain implementations of the second aspect, the type of the first identifier indicated by each of the at least one authentication method is different, and the first identifier includes at least one of the following: a first type of identifier of the communication device, a second type of identifier of the communication device, an identifier of a block or an identifier of a transaction, and a virtual identifier of the communication device; wherein the first type of identifier has a first corresponding relationship with a root key of the communication device, the second type of identifier has a second corresponding relationship with at least one certificate of the communication device, the identifier of the block or the identifier of the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.
[0068] Based on the above solution, the verification network element can obtain the authentication information of the communication device based on different identifiers, so that the authentication process can be applied to various scenarios.
[0069] In certain implementations of the second aspect, the first authentication method is determined based on the second information and the third indication information, and the second information includes at least one of the following information: the issuer of the certificate of the communication device, the security level of the certificate of the communication device, and the cryptographic algorithm corresponding to the certificate of the communication device.
[0070] Based on the above solution, the verification network element can make the authentication process more flexible based on at least one of the issuer of the certificate of the communication device used in the authentication process, the security level of the certificate of the communication device, and the cryptographic algorithm corresponding to the certificate of the communication device.
[0071] In certain implementations of the second aspect, the first authentication information includes a first credential of the communication device, the first credential is verified based on the credential of the issuer of the first credential; a second digital signature is received from the communication device, the second digital signature being a signature of the communication device on a second message, the second message including a message exchanged between the communication device and the verification network element; and the second digital signature is verified based on a public key corresponding to the first credential. The messages exchanged between the communication device and the verification network element may refer to the description of the first aspect.
[0072] Based on the above scheme, the verification network element can verify the communication device by using the first certificate to verify the signature of the communication device on the interacted message; verifying the first certificate through the certificate of the issuer of the first certificate can determine the security of the first certificate, thereby improving the security of the authentication process.
[0073] On the third aspect, a communication method is provided. The method can be executed by a communication device, or can also be executed by a component of the communication device (such as a chip or circuit). There is no limitation on this. For the sake of ease of description, the following is explained using the execution by a communication device as an example.
[0074] The method includes: sending first indication information to a verification network element, the first indication information indicating at least one key agreement algorithm; receiving second indication information from the verification network element, the second indication information indicating a first key agreement algorithm, the first key agreement algorithm being one of the at least one key agreement algorithm, the first key agreement algorithm being used to determine a first key, and the first key being used to encrypt or decrypt messages transmitted between the communication device and the verification network element.
[0075] Based on the above scheme, the verification network element and the communication device can determine the key agreement algorithm in the authentication process through negotiation, so that the selection of the key agreement algorithm in the authentication process is more flexible and adaptable to more application scenarios. That is, the communication device indicates at least one key agreement algorithm to the verification network element, and the verification network element determines a first key agreement algorithm from the at least one key agreement algorithm, and the first key agreement algorithm is used for the first key.
[0076] In certain implementations of the third aspect, the first key agreement algorithm is determined based on the first information and the first indication information, and the first information includes at least one of the following information: the security level corresponding to the key agreement algorithm, the computational complexity of the key agreement algorithm, the network standard, the type of the communication device, and the computing capability of the communication device.
[0077] Based on the above scheme, by determining the first key agreement algorithm according to the first information, the first key agreement algorithm can be adapted to at least one of different security levels, computational complexities, network standards, types of communication devices, and computing capabilities of the communication devices.
[0078] The at least one key agreement algorithm refers to the description in the first aspect.
[0079] In certain implementations of the third aspect, the first key is determined based on the first key agreement algorithm.
[0080] In certain implementations of the third aspect, the first key agreement algorithm is the ECDHE key agreement algorithm. In the ECDHE key agreement algorithm, a second public key is received from the verification network element, and the second public key is the public key in the second temporary public-private key pair generated by the verification network element; the first key is determined based on the second public key and the first private key, and the first private key is the private key in the first temporary public-private key pair generated by the communication device.
[0081] Based on the above scheme, the first key is determined according to the public key in the second temporary public-private key pair generated by the received verification network element and the private key in the first temporary public-private key pair generated by the communication device, which can improve the security of the first key and thus improve the security of the authentication.
[0082] In certain implementations of the third aspect, a first public key is sent to the verification network element, where the first public key is the public key in the first temporary public-private key pair, and the first public key is used by the verification network element to determine the first key.
[0083] In certain implementations of the third aspect, the first key agreement algorithm is the PQC-based key agreement algorithm. In the PQC-based key agreement algorithm, a ciphertext is received from the verification network element, where the ciphertext is generated by the verification network element based on a post-quantum algorithm; the ciphertext and a third private key are input into the post-quantum algorithm to generate the first key, where the third private key is the private key in a third temporary public-private key pair generated by the communication device based on the post-quantum algorithm.
[0084] Based on the above scheme, according to the ciphertext generated by the received verification network element, the communication device determines the first key based on the private key in the third temporary public-private key pair generated by the post-quantum algorithm, which can improve the security of the first key and thus improve the security of the authentication.
[0085] In certain implementations of the third aspect, a third public key is sent to the verification network element, where the third public key is the public key in the third temporary public-private key pair, and the third public key is used by the verification network element to determine the first key.
[0086] In certain implementations of the third aspect, the first key agreement algorithm is the key agreement algorithm based on PQC and ECDH. In the key agreement algorithm based on PQC and ECDH, the ciphertext from the verification network element and the public key of the verification network element are received, and the ciphertext is generated by the verification network element based on the post-quantum algorithm; the second key is determined based on the public key of the verification network element and the first private key, and the first private key is the private key in the first temporary public-private key pair generated by the communication device; the ciphertext and the third private key are input into the post-quantum algorithm to generate a third key, and the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; the first key is determined based on the second key and the third key.
[0087] Based on the above scheme, the second key is determined according to the public key of the received verification network element and the private key in the first temporary public-private key pair generated by the communication device, and the third key is determined according to the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm based on the ciphertext generated by the received verification network element; and the first key is determined based on the second key and the third key, which can improve the security of the first key and thus improve the security of authentication.
[0088] In certain implementations of the third aspect, the first key agreement algorithm is the key agreement algorithm based on PQC and ECDHE. In the key agreement algorithm based on PQC and ECDHE, a ciphertext and a second public key are received from the verification network element, where the ciphertext is generated by the verification network element based on a post-quantum algorithm, and the second public key is the public key in a second temporary public-private key pair generated by the verification network element; a second key is determined based on the second public key and the first private key, where the first private key is the private key in a first temporary public-private key pair generated by the communication device; the ciphertext and the third private key are input into the post-quantum algorithm to generate a third key, where the third private key is the private key in a third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; and the first key is determined based on the second key and the third key.
[0089] Based on the above scheme, the second key is determined according to the public key in the second temporary public-private key pair generated by the received verification network element and the private key in the first temporary public-private key pair generated by the communication device, and the third key is determined according to the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm based on the ciphertext generated by the received verification network element; and the first key is determined based on the second key and the third key, which can improve the security of the first key and thus improve the security of authentication.
[0090] In certain implementations of the third aspect, a first public key and a third public key are sent to the verification network element, where the first public key is the public key in the first temporary public-private key pair, and the third public key is the public key in the third temporary public-private key pair. The first public key and the third public key are used by the verification network element to determine the first key.
[0091] In certain implementations of the third aspect, a first digital signature is received from the verification network element, where the first digital signature is a signature of a first message using a private key of the verification network element, where the first message includes a message exchanged between the verification network element and the communication device; a certificate of the verification network element is received from the verification network element, where the certificate includes a public key of the verification network element; and the first digital signature is verified based on the public key of the verification network element. The messages exchanged between the verification network element and the communication device may refer to the description of the first aspect.
[0092] Based on the above solution, by receiving the certificate and the first digital signature of the verification network element, the communication device can authenticate the verification network element, simplifying the process of the communication device authenticating the verification network element and saving signaling overhead.
[0093] In certain implementations of the third aspect, a request message is sent to the verification network element, where the request message is used to request access to the network. The request message includes a first identifier encrypted by the first key, where the first identifier corresponds to the authentication information of the communication device, where the authentication information includes first authentication information, and where the first authentication information is used to authenticate the communication device.
[0094] Based on the above scheme, by sending the request message to the authentication network element, the authentication network element can obtain the authentication information required by the communication device corresponding to the first identifier based on the first identifier, and authenticate the communication device according to the authentication information, which can improve the flexibility of authenticating the communication device.
[0095] In certain implementations of the third aspect, before sending the request message to the verification network element, third indication information is sent to the verification network element, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other; and fourth indication information is received from the verification network element, where the fourth indication information indicates a first authentication method, where the first authentication method is one of the at least one authentication method, and the first authentication method corresponds to the first authentication information.
[0096] Based on the above scheme, the verification network element and the communication device can determine the authentication method through negotiation, making the selection of the authentication method more flexible and adaptable to more application scenarios, that is, the communication device indicates at least one authentication method to the verification network element, and the verification network element determines the first authentication method from the at least one authentication method.
[0097] In certain implementations of the third aspect, the authentication information includes any one of the following information: a certificate of the communication device, a cryptographic algorithm; wherein the certificate of the communication device includes a public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.
[0098] Based on the above solution, by determining the first authentication method according to the third information, the first authentication method can be adapted to different credentials and cryptographic algorithms of the communication device.
[0099] In certain implementations of the third aspect, the type of the first identifier indicated by each of the at least one authentication method is different, and the first identifier includes at least one of the following: a first type of identifier of the communication device, a second type of identifier of the communication device, an identifier of a block or an identifier of a transaction, and a virtual identifier of the communication device; wherein the first type of identifier has a first corresponding relationship with a root key of the communication device, the second type of identifier has a second corresponding relationship with at least one certificate of the communication device, the identifier of the block or the identifier of the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.
[0100] Based on the above solution, the verification network element can obtain the authentication information of the communication device based on different identifiers, so that the authentication process can be applied to multiple scenarios. The applicable scenarios of each identifier can refer to the description of the first aspect.
[0101] In certain implementations of the third aspect, the first authentication method is determined based on second information and the third indication information, and the second information includes at least one of the following information: the issuer of the certificate of the communication device, the security level of the certificate of the communication device, and the cryptographic algorithm corresponding to the certificate of the communication device.
[0102] Based on the above solution, the verification network element can make the authentication process more flexible based on at least one of the issuer of the certificate of the communication device used in the authentication process, the security level of the certificate of the communication device, and the cryptographic algorithm corresponding to the certificate of the communication device.
[0103] In certain implementations of the third aspect, a second digital signature is sent to the verification network element. The second digital signature is a signature of a second message using a private key of the communication device. The second message includes messages exchanged between the communication device and the verification network element. The second digital signature is used by the verification network element to authenticate the communication device. The messages exchanged between the communication device and the verification network element may refer to the description of the first aspect.
[0104] Based on the above scheme, by sending the second digital signature to the verification network element, the verification network element can verify the signature of the communication device on the interacted message by using the first certificate, thereby verifying the communication device; verifying the first certificate through the certificate of the issuer of the first certificate can determine the security of the first certificate, thereby improving the security of the authentication process.
[0105] In the fourth aspect, a communication method is provided. The method can be executed by a communication device, or it can be executed by a component of the communication device (such as a chip or circuit). There is no limitation on this. For the sake of convenience of description, the following is explained as an example of execution by a communication device.
[0106] The method includes: sending a temporary public key to the verification network element, where the temporary public key is the public key in a temporary public-private key pair generated by the communication device, and the temporary public key is used to determine a first key, which is used by the verification network element to authenticate the communication device; wherein the first key is determined based on the temporary public key and a second private key, and the second private key is the private key of the verification network element or the private key in the temporary public-private key pair generated by the verification network element; or, the first key is generated by inputting the temporary public key into a post-quantum algorithm.
[0107] Based on the above scheme, by sending a temporary public key to the verification network element, the verification network element can determine the first key based on the temporary public key and authenticate the communication device based on the first key, wherein the first key is determined based on the temporary public key of the communication device and the private key of the verification network element or the private key in the temporary public-private key pair generated by the verification network element, or the first key is generated by inputting the temporary public key into the post-quantum algorithm, thereby ensuring the security of the first key and improving the security of authenticating the communication device based on the first key.
[0108] In certain implementations of the fourth aspect, if the first key is determined based on the temporary public key of the communication device and the private key in the temporary public-private key pair generated by the verification network element, the method also includes: receiving a second public key from the verification network element, the second public key being the public key in the second temporary public-private key pair generated by the verification network element; determining the first key based on the first private key and the second public key, the first public key being the private key in the first temporary public-private key pair.
[0109] Based on the above solution, the device can determine the first key based on the temporary public key generated by the verification network element, thereby improving the security of the first key and thus improving the security of authentication.
[0110] In certain implementations of the fourth aspect, the temporary public key is a third public key, which is a public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.
[0111] Based on the above solution, by inputting the temporary public key of the communication device into the post-quantum algorithm to obtain the first key, the security of the first key can be improved, thereby improving the security of authentication.
[0112] In certain implementations of the fourth aspect, the method further includes: receiving a ciphertext from the verification network element, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm; inputting the ciphertext and the third private key into the post-quantum algorithm to generate the first key, where the third private key is the private key in the third temporary public-private key pair.
[0113] Based on the above solution, by sending a ciphertext to the communication device and inputting the ciphertext and the third private key into the post-quantum algorithm to generate the first key, the security of the first key can be improved, thereby improving the security of the authentication.
[0114] In certain implementations of the fourth aspect, the temporary public key includes a first public key and a third public key, the first public key being the public key in a first temporary public-private key pair generated by the communication device, the third public key being the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, the first key being determined based on the second key and the third key, the second key being determined based on the second private key and the first public key, and the third key being generated by inputting the third public key into the post-quantum algorithm.
[0115] Based on the above solution, by generating the first key based on the second key and the third key, the security of the first key can be improved, thereby improving the security of authentication.
[0116] In certain implementations of the fourth aspect, a ciphertext and a second public key are received from the verification network element, where the second public key includes the public key of the verification network element or the public key in a temporary public-private key generated by the verification network element, and the ciphertext is generated by inputting the third public key into the post-quantum algorithm; a second key is generated based on the first private key and the second public key, where the first private key is the private key in the first public-private key pair; the ciphertext and the third private key are input into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third public-private key pair; and the first key is determined based on the second key and the third key.
[0117] Based on the above scheme, the second key is determined according to the received public key of the verification network element or the public key in the temporary public-private key generated by the verification network element, and the private key in the first temporary public-private key pair generated by the communication device, and the third key is determined according to the ciphertext generated by the received verification network element and the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; and the first key is determined based on the second key and the third key, which can improve the security of the first key and thus improve the security of the authentication.
[0118] In certain implementations of the fourth aspect, the temporary public key is sent based on second indication information, the second indication information indicates a first key agreement algorithm, and the first key agreement algorithm is one of at least one key agreement algorithm. Before receiving the temporary public key from the communication device, the first indication information is sent to the verification network element, and the first indication information indicates the at least one key agreement algorithm; and the second indication information is received from the verification network element.
[0119] Based on the above solution, the verification network element and the communication device can determine the key negotiation algorithm in the authentication process through negotiation, making the selection of the key negotiation algorithm in the authentication process more flexible and adaptable to more application scenarios.
[0120] In certain implementations of the fourth aspect, the first key agreement algorithm is determined based on the first information and the first indication information, and the first information includes at least one of the following information: the security level corresponding to the key agreement algorithm, the computational complexity of the key agreement algorithm, the network standard, the type of the communication device, and the computing capability of the communication device.
[0121] The at least one key agreement algorithm refers to the description in the first aspect.
[0122] In certain implementations of the fourth aspect, the method further includes: receiving a first digital signature from the verification network element, the first digital signature being a signature of a first message using a private key of the verification network element, the first message including a message exchanged between the verification network element and the communication device; receiving a certificate of the verification network element from the verification network element, the certificate including a public key of the verification network element; and verifying the first digital signature based on the public key of the verification network element. The messages exchanged between the verification network element and the communication device may refer to the description of the first aspect.
[0123] Based on the above solution, by receiving the first digital signature from the verification network element and the certificate of the verification network element, the communication device can verify the first digital signature based on the certificate of the verification network element, thereby verifying the verification network element. This authentication method simplifies the authentication process and can save signaling overhead.
[0124] In certain implementations of the fourth aspect, a request message is sent to the verification network element, where the request message is used to request access to the network. The request message includes a first identifier encrypted by the communication device using the first key, where the first identifier corresponds to authentication information of the communication device, where the authentication information includes first authentication information, and where the first authentication information is used to authenticate the communication device.
[0125] Based on the above scheme, by sending a request message to the verification network element, the authentication network element can obtain the authentication information required by the communication device corresponding to the first identifier based on the first identifier, and authenticate the communication device according to the authentication information, which can improve the flexibility of authentication of the communication device.
[0126] In certain implementations of the fourth aspect, before sending the request message to the verification network element, third indication information is sent to the verification network element, the third indication information indicating at least one authentication method, and the authentication information corresponding to each authentication method in the at least one authentication method is independent of each other; and fourth indication information is received from the verification network element, the fourth indication information indicating a first authentication method, the first authentication method being one of the at least one authentication method, and the first authentication method corresponding to the first authentication information.
[0127] Based on the above scheme, the verification network element and the communication device can determine the authentication method through negotiation, making the selection of the authentication method more flexible and adaptable to more application scenarios, that is, the communication device indicates at least one authentication method to the verification network element, and the verification network element determines the first authentication method from the at least one authentication method.
[0128] In certain implementations of the fourth aspect, the authentication information indicates any one of the following information: a certificate of the communication device, a cryptographic algorithm; wherein the certificate of the communication device includes a public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.
[0129] Based on the above solution, by determining the first authentication method according to the third information, the first authentication method can be adapted to different credentials and / or cryptographic algorithms of the communication device.
[0130] In certain implementations of the fourth aspect, the type of the first identifier indicated by each of the at least one authentication method is different, and the first identifier includes at least one of the following: a first type of identifier of the communication device, a second type of identifier of the communication device, an identifier of a block or an identifier of a transaction, and a virtual identifier of the communication device; wherein the first type of identifier has a first corresponding relationship with a root key of the communication device, the second type of identifier has a second corresponding relationship with at least one certificate of the communication device, the identifier of the block or the identifier of the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.
[0131] Based on the above solution, authentication information of the communication device can be obtained based on different identifiers, which can make the authentication process applicable to various scenarios. The scenarios applicable to different types of identifiers can refer to the description of the first aspect.
[0132] In certain implementations of the fourth aspect, the first authentication method is determined based on the second information and the third indication information, and the second information includes at least one of the following information: the issuer of the certificate of the communication device, the security level of the certificate of the communication device, and the cryptographic algorithm corresponding to the certificate of the communication device.
[0133] In certain implementations of the fourth aspect, a second digital signature is sent to the verification network element. The second digital signature is a signature of a second message using a private key of the communication device. The second message includes messages exchanged between the communication device and the verification network element. The second digital signature is used by the verification network element to authenticate the communication device. The messages exchanged between the communication device and the verification network element may refer to the description of the first aspect.
[0134] Based on the above scheme, by sending a second digital signature to the verification network element, the verification network element can use the first certificate to verify the signature of the communication device on the interacted message, thereby verifying the communication device; verifying the first certificate through the certificate of the issuer of the first certificate can determine the security of the first certificate, thereby improving the security of the authentication process.
[0135] In the fifth aspect, a communication device is provided, which can be used for the verification network element of the first aspect. The communication device can be a verification network element, or a device in the verification network element (for example, a chip, or a chip system, or a circuit), or a device that can be used in combination with the verification network element, or a logical module or software that can realize all or part of the functions of the verification network element.
[0136] In one possible implementation, the communication device may include a module or unit corresponding to the method / operation / step / action described in the first aspect. The module or unit may be a hardware circuit, software, or a combination of hardware circuit and software.
[0137] In one possible implementation, the device includes a transceiver unit, which is used to: receive first indication information from a communication device, the first indication information indicating at least one key agreement algorithm; send second indication information to the communication device, the second indication information indicating a first key agreement algorithm, the first key agreement algorithm is one of the at least one key agreement algorithm, the first key agreement algorithm is used to determine a first key, and the first key is used to encrypt or decrypt messages transmitted between the communication device and the device.
[0138] In certain implementations of the fifth aspect, the first key agreement algorithm is determined based on the first information and the first indication information, and the first information refers to the description in the first aspect.
[0139] In certain implementations of the fifth aspect, the at least one key agreement algorithm refers to the description in the first aspect.
[0140] In certain implementations of the fifth aspect, the apparatus further includes a processing unit configured to determine the first key based on the first key agreement algorithm.
[0141] In certain implementations of the fifth aspect, the first key agreement algorithm is the ECDHE key agreement algorithm. In the ECDHE key agreement algorithm, the transceiver unit is specifically used to receive a first public key from the communication device, where the first public key is the public key in a first temporary public-private key pair generated by the communication device; the processing unit is specifically used to determine the first key based on the first public key and the second private key, where the second private key is the private key in a second temporary public-private key pair generated by the device.
[0142] In certain implementations of the fifth aspect, the transceiver unit is further configured to send a second public key to the communication device, where the second public key is a public key in the second temporary public-private key pair. By sending the second public key to the communication device, the communication device can determine the first key based on the second public key.
[0143] In certain implementations of the fifth aspect, the first key agreement algorithm is the PQC-based key agreement algorithm. In the PQC-based key agreement algorithm, the transceiver unit is specifically used to receive a third public key from the communication device, where the third public key is the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; the processing unit is specifically used to input the third public key into the post-quantum algorithm to generate a ciphertext and the first key.
[0144] In certain implementations of the fifth aspect, the transceiver unit is further configured to send the ciphertext to the communication device. By sending the ciphertext to the communication device, the communication device can determine the first key based on the ciphertext.
[0145] In certain implementations of the fifth aspect, the first key agreement algorithm is the key agreement algorithm based on PQC and ECDH. In the key agreement algorithm based on PQC and ECDH, the transceiver unit is specifically used to receive a first public key and a third public key from the communication device, the first public key being the public key in a first temporary public-private key pair generated by the communication device, and the third public key being the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; the processing unit is specifically used to determine the second key based on the first public key and the private key of the device, and to input the third public key into the post-quantum algorithm to generate a ciphertext and a third key; the processing unit is also used to determine the first key based on the second key and the third key.
[0146] In certain implementations of the fifth aspect, the transceiver unit is further used to send the public key of the device and the ciphertext to the communication device, and the public key of the device and the ciphertext are used by the communication device to determine the first key.
[0147] In certain implementations of the fifth aspect, the first key agreement algorithm is the key agreement algorithm based on PQC and ECDHE. In the key agreement algorithm based on PQC and ECDHE, the transceiver unit is specifically used to receive a first public key and a third public key from the communication device, the first public key being the public key in a first temporary public-private key pair generated by the communication device, and the third public key being the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; the processing unit is specifically used to determine a second key based on the first public key and the second private key, the second private key being the private key in the second temporary public-private key pair generated by the device, and inputting the third public key into the post-quantum algorithm to generate a ciphertext and a third key; the processing unit is also used to determine the first key based on the second key and the third key.
[0148] In certain implementations of the fifth aspect, the transceiver unit is also used to send a second public key and the ciphertext to the communication device, where the second public key is the public key in the second temporary public-private key pair. By sending the second public key and the ciphertext to the communication device, the communication device can determine the first key based on the second public key and the ciphertext.
[0149] In certain implementations of the fifth aspect, the transceiver unit is further used to send a first digital signature to the communication device, where the first digital signature is a signature of the device's private key on a first message, where the first message includes messages that the device and the communication device have interacted with; and to send the device's certificate to the communication device, where the certificate includes the device's public key, and the device's public key is used by the communication device to verify the first digital signature.
[0150] In certain implementations of the fifth aspect, the transceiver unit is further used to receive a request message from the communication device, the request message being used to request access to the network, the request message including a first identifier encrypted by the first key, the first identifier corresponding to the authentication information of the communication device; obtaining first authentication information in the authentication information according to the first identifier; and the processing unit being further used to authenticate the communication device based on the first authentication information.
[0151] In certain implementations of the fifth aspect, before receiving the request message from the communication device, the transceiver unit is further used to receive third indication information from the communication device, the third indication information indicating at least one authentication method, and the third information indicated by each authentication method in the at least one authentication method is different; the transceiver unit is also used to send fourth indication information to the communication device, the fourth indication information indicating a first authentication method, the first authentication method being one of the at least one authentication method, and the first authentication method corresponding to the first authentication information.
[0152] In certain implementations of the fifth aspect, the authentication information refers to the description in the first aspect.
[0153] In certain implementations of the fifth aspect, the type of the first identifier indicated by each of the at least one authentication method is different, and the first identifier is described with reference to the first aspect.
[0154] In certain implementations of the fifth aspect, the first authentication method is determined based on the second information and the third indication information, and the second information refers to the description in the first aspect.
[0155] In certain implementations of the fifth aspect, the first authentication information includes a first credential of the communication device, and the first credential is verified based on the credential of the issuer of the first credential; the transceiver unit is also used to receive a second digital signature from the communication device, the second digital signature being a signature of a second message using a private key of the communication device, the second message including a message between the communication device and the device; the processing unit is also used to verify the second digital signature based on a public key corresponding to the first credential.
[0156] In the sixth aspect, a communication device is provided, which can be used for the verification network element of the second aspect. The communication device can be a verification network element, or a device in the verification network element (for example, a chip, or a chip system, or a circuit), or a device that can be used in combination with the verification network element, or a logical module or software that can realize all or part of the functions of the verification network element.
[0157] In one possible implementation, the communication device may include a module or unit corresponding to the method / operation / step / action described in the second aspect. The module or unit may be a hardware circuit, software, or a combination of hardware circuit and software.
[0158] In one possible implementation, the device includes a transceiver unit and a processing unit, the transceiver unit is used to receive a temporary public key from a first communication device, the temporary public key is the public key in a temporary public-private key pair generated by the first communication device; the processing unit is used to authenticate the first communication device based on a first key, the first key is determined based on the temporary public key and a second private key, the second private key is the private key of the verification network element or the private key in the temporary public-private key pair generated by the verification network element, or the first key is generated by inputting the temporary public key into a post-quantum algorithm.
[0159] In certain implementations of the sixth aspect, if the first key is determined based on the temporary public key and the second private key, the second private key is the private key in the temporary public-private key pair generated by the verification network element, and the transceiver unit is also used to send the second public key to the first communication device, and the second public key includes the public key in the temporary public-private key pair generated by the verification network element, and the second public key is used by the first communication device to determine the first key.
[0160] In certain implementations of the sixth aspect, the temporary public key is a third public key, which is a public key in a third temporary public-private key pair generated by the first communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.
[0161] In certain implementations of the sixth aspect, the transceiver unit is further used to send a ciphertext to the first communication device, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext is used by the first communication device to determine the first key.
[0162] In certain implementations of the sixth aspect, the temporary public key includes a first public key and a third public key, the first public key being the public key in a first temporary public-private key pair generated by the first communication device, the third public key being the public key in a third temporary public-private key pair generated by the first communication device based on a post-quantum algorithm, the first key being determined based on the second key and the third key, the second key being determined based on the second private key and the first public key, and the third key being generated by inputting the third public key into the post-quantum algorithm.
[0163] In certain implementations of the sixth aspect, the transceiver unit is further used to send a ciphertext and a second public key to the first communication device, where the second public key includes the public key of the verification network element or the public key in a temporary public-private key pair generated by the verification network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext and the second public key are used by the first communication device to determine the first key.
[0164] In certain implementations of the sixth aspect, the temporary public key is sent based on second indication information, the second indication information indicates a first key agreement algorithm, and the first key agreement algorithm is one of at least one key agreement algorithm. Before receiving the temporary public key from the first communication device, the transceiver unit is also used to receive first indication information from the first communication device, and the first indication information indicates the at least one key agreement algorithm; the transceiver unit is also used to send the second indication information to the first communication device.
[0165] In certain implementations of the sixth aspect, the first key agreement algorithm is determined based on the first information and the first indication information, and the first information is described with reference to the second aspect.
[0166] The at least one key agreement algorithm refers to the description in the first aspect.
[0167] In certain implementations of the sixth aspect, the transceiver unit is further used to: send a first digital signature to the first communication device, where the first digital signature is a signature of the private key of the verification network element on the first message, and the first message includes messages that the verification network element and the first communication device have interacted with; send the certificate of the verification network element to the first communication device, where the certificate includes the public key of the verification network element, and the public key of the verification network element is used by the first communication device to verify the first digital signature.
[0168] In certain implementations of the sixth aspect, the transceiver unit is further used to receive a request message from the first communication device, the request message being used to request access to the network, the request message including a first identifier encrypted by the first communication device using the first key, the first identifier corresponding to the authentication information of the first communication device; the processing unit is further used to decrypt the encrypted first identifier based on the first key; obtain first authentication information in the authentication information based on the first identifier; and the processing unit is further used to authenticate the first communication device based on the first authentication information.
[0169] In certain implementations of the sixth aspect, before receiving the request message from the first communication device, the transceiver unit is further used to receive third indication information from the first communication device, the third indication information indicating at least one authentication method, and the authentication information corresponding to each authentication method in the at least one authentication method is independent of each other; the transceiver unit is also used to send fourth indication information to the first communication device, the fourth indication information indicating a first authentication method, the first authentication method being one of the at least one authentication method, and the first authentication method corresponding to the first authentication information.
[0170] In certain implementations of the sixth aspect, the authentication information refers to the description in the second aspect.
[0171] In certain implementations of the sixth aspect, the type of the first identifier indicated by each of the at least one authentication method is different, and the first identifier can refer to the description of the second aspect.
[0172] In certain implementations of the sixth aspect, the first authentication method is determined based on the second information and the third indication information, and the second information refers to the description in the second aspect.
[0173] In certain implementations of the sixth aspect, the first authentication information includes a first certificate of the first communication device, and the first certificate is verified based on the certificate of the issuer of the first certificate; the transceiver unit is also used to receive a second digital signature from the first communication device, and the second digital signature is a signature of the first communication device on a second message, and the second message includes a message that the first communication device has interacted with the verification network element; the processing unit is also used to verify the second digital signature based on the public key corresponding to the first certificate.
[0174] In the seventh aspect, a communication device is provided, which can be used for the communication device of the third aspect. The communication device can be a terminal device, or a device in the terminal device (for example, a chip, or a chip system, or a circuit), or a device that can be used in combination with the terminal device, or a logic module or software that can realize all or part of the functions of the terminal device.
[0175] In one possible implementation, the communication device may include a module or unit corresponding to the method / operation / step / action described in the third aspect. The module or unit may be a hardware circuit, software, or a combination of hardware circuit and software.
[0176] In one possible implementation, the device includes a transceiver unit, which is used to send first indication information to the verification network element, and the first indication information indicates at least one key negotiation algorithm; the transceiver unit is also used to receive second indication information from the verification network element, and the second indication information indicates a first key negotiation algorithm, and the first key negotiation algorithm is one of the at least one key negotiation algorithm, and the first key negotiation algorithm is used to determine a first key, and the first key is used to encrypt or decrypt messages transmitted between the communication device and the verification network element.
[0177] In certain implementations of the seventh aspect, the first key agreement algorithm is determined based on the first information and the first indication information, and the first information includes at least one of the following information: the security level corresponding to the key agreement algorithm, the computational complexity of the key agreement algorithm, the network standard, the type of the communication device, and the computing capability of the communication device.
[0178] The at least one key agreement algorithm refers to the description in the first aspect.
[0179] In certain implementations of the seventh aspect, the apparatus further includes a processing unit configured to determine the first key based on the first key agreement algorithm.
[0180] In certain implementations of the seventh aspect, the first key agreement algorithm is the ECDHE key agreement algorithm. In the ECDHE key agreement algorithm, the transceiver unit is also used to receive a second public key from the verification network element, where the second public key is the public key in a second temporary public-private key pair generated by the verification network element; the processing unit is specifically used to determine the first key based on the second public key and the first private key, where the first private key is the private key in the first temporary public-private key pair generated by the communication device.
[0181] In certain implementations of the seventh aspect, the transceiver unit is further used to send a first public key to the verification network element, where the first public key is the public key in the first temporary public-private key pair, and the first public key is used by the verification network element to determine the first key.
[0182] In certain implementations of the seventh aspect, the first key agreement algorithm is the PQC-based key agreement algorithm. In the PQC-based key agreement algorithm, the transceiver unit is also used to receive a ciphertext from the verification network element, where the ciphertext is generated by the verification network element based on a post-quantum algorithm; the processing unit is also used to input the ciphertext and a third private key into the post-quantum algorithm to generate the first key, where the third private key is a private key in a third temporary public-private key pair generated by the communication device based on the post-quantum algorithm.
[0183] In certain implementations of the seventh aspect, the transceiver unit is further used to send a third public key to the verification network element, where the third public key is the public key in the third temporary public-private key pair, and the third public key is used by the verification network element to determine the first key.
[0184] In certain implementations of the seventh aspect, the first key agreement algorithm is the key agreement algorithm based on PQC and ECDH. In the key agreement algorithm based on PQC and ECDH, the transceiver unit is also used to receive the ciphertext from the verification network element and the public key of the verification network element, and the ciphertext is generated by the verification network element based on the post-quantum algorithm; the processing unit is also used to determine the second key based on the public key of the verification network element and the first private key, and the first private key is the private key in the first temporary public-private key pair generated by the communication device; the ciphertext and the third private key are input into the post-quantum algorithm to generate a third key, and the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; the processing unit is also used to determine the first key based on the second key and the third key.
[0185] In certain implementations of the seventh aspect, the first key agreement algorithm is the key agreement algorithm based on PQC and ECDHE. In the key agreement algorithm based on PQC and ECDHE, the transceiver unit is also used to receive the ciphertext and the second public key from the verification network element, the ciphertext is generated by the verification network element based on the post-quantum algorithm, and the second public key is the public key in the second temporary public-private key pair generated by the verification network element; the processing unit is also used to determine the second key based on the second public key and the first private key, and the first private key is the private key in the first temporary public-private key pair generated by the communication device; the processing unit is also used to input the ciphertext and the third private key into the post-quantum algorithm to generate a third key, and the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; and determine the first key based on the second key and the third key.
[0186] In certain implementations of the seventh aspect, the transceiver unit is also used to send a first public key and a third public key to the verification network element, where the first public key is the public key in the first temporary public-private key pair, and the third public key is the public key in the third temporary public-private key pair. The first public key and the third public key are used by the verification network element to determine the first key.
[0187] In certain implementations of the seventh aspect, the transceiver unit is further used to: receive a first digital signature from the verification network element, the first digital signature being a signature of the verification network element's private key on a first message, the first message including messages exchanged between the verification network element and the communication device; receive a certificate of the verification network element from the verification network element, the certificate including the public key of the verification network element; the processing unit is further used to verify the first digital signature based on the public key of the verification network element.
[0188] In certain implementations of the seventh aspect, the transceiver unit is also used to send a request message to the verification network element, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, and the first identifier corresponds to the authentication information of the communication device, and the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.
[0189] In certain implementations of the seventh aspect, before sending the request message to the verification network element, the transceiver unit is further used to: send third indication information to the verification network element, the third indication information indicating at least one authentication method, the authentication information indicated by each authentication method in the at least one authentication method being independent of each other; and receive fourth indication information from the verification network element, the fourth indication information indicating a first authentication method, the first authentication method being one of the at least one authentication method, and the first authentication method corresponding to the first authentication information.
[0190] The authentication information refers to the description of the third aspect.
[0191] In certain implementations of the seventh aspect, the type of the first identifier indicated by each of the at least one authentication method is different, and the types of the first identifier are described with reference to the third aspect.
[0192] In certain implementations of the seventh aspect, the first authentication method is determined based on second information and the third indication information. The second information is described in the third aspect.
[0193] In certain implementations of the seventh aspect, the transceiver unit is further used to: send a second digital signature to the verification network element, where the second digital signature is a signature of the second message using the private key of the communication device, and the second message includes a message that the communication device has interacted with the verification network element, and the second digital signature is used by the verification network element to authenticate the communication device.
[0194] In an eighth aspect, a communication device is provided, which can be used for the communication device of the fourth aspect. The communication device can be a terminal device, or a device in the terminal device (for example, a chip, or a chip system, or a circuit), or a device that can be used in combination with the terminal device, or a logic module or software that can realize all or part of the functions of the terminal device.
[0195] In one possible implementation, the communication device may include a module or unit corresponding to the method / operation / step / action described in the fourth aspect. The module or unit may be a hardware circuit, software, or a combination of hardware circuit and software.
[0196] In one possible implementation, the device includes a transceiver unit, which is used to: send a temporary public key to the verification network element, where the temporary public key is the public key in a temporary public-private key pair generated by the communication device, and the temporary public key is used to determine a first key, which is used by the verification network element to authenticate the communication device; wherein the first key is determined based on the temporary public key and a second private key, and the second private key is the private key of the verification network element or the private key in the temporary public-private key pair generated by the verification network element; or, the first key is generated by inputting the temporary public key into a post-quantum algorithm.
[0197] In certain implementations of the eighth aspect, if the first key is determined based on the temporary public key of the communication device and the private key in the temporary public-private key pair generated by the verification network element, the transceiver unit is also used to: receive a second public key from the verification network element, the second public key being the public key in the second temporary public-private key pair generated by the verification network element; the device also includes a processing unit, which is used to determine the first key based on the first private key and the second public key, the first public key being the private key in the first temporary public-private key pair.
[0198] In certain implementations of the eighth aspect, the temporary public key is a third public key, which is a public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.
[0199] In certain implementations of the eighth aspect, the transceiver unit is further used to receive ciphertext from the verification network element, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm; the processing unit is further used to input the ciphertext and the third private key into the post-quantum algorithm to generate the first key, where the third private key is the private key in the third temporary public-private key pair.
[0200] In certain implementations of the eighth aspect, the temporary public key includes a first public key and a third public key, the first public key being the public key in a first temporary public-private key pair generated by the communication device, the third public key being the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, the first key being determined based on the second key and the third key, the second key being determined based on the second private key and the first public key, and the third key being generated by inputting the third public key into the post-quantum algorithm.
[0201] In certain implementations of the eighth aspect, the transceiver unit is further used to receive a ciphertext and a second public key from the verification network element, where the second public key includes the public key of the verification network element or the public key in a temporary public-private key generated by the verification network element, and the ciphertext is generated by inputting the third public key into the post-quantum algorithm; the processing unit is further used to: generate a second key based on the first private key and the second public key, where the first private key is the private key in the first public-private key pair; input the ciphertext and the third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third public-private key pair; and determine the first key based on the second key and the third key.
[0202] In certain implementations of the eighth aspect, the temporary public key is sent based on second indication information, the second indication information indicates a first key agreement algorithm, and the first key agreement algorithm is one of at least one key agreement algorithm. Before receiving the temporary public key from the communication device, the transceiver unit is also used to: send first indication information to the verification network element, the first indication information indicating the at least one key agreement algorithm; and receive the second indication information from the verification network element.
[0203] In certain implementations of the eighth aspect, the first key agreement algorithm is determined based on the first information and the first indication information, and the first information refers to the description in the fourth aspect.
[0204] The at least one key agreement algorithm refers to the description in the first aspect.
[0205] In certain implementations of the eighth aspect, the transceiver unit is further used to: receive a first digital signature from the verification network element, the first digital signature being a signature of a first message using the private key of the verification network element, the first message including messages exchanged between the verification network element and the communication device; receive a certificate of the verification network element from the verification network element, the certificate including the public key of the verification network element; the processing unit is further used to: verify the first digital signature based on the public key of the verification network element.
[0206] In certain implementations of the eighth aspect, the transceiver unit is further used to: send a request message to the verification network element, the request message is used to request access to the network, the request message includes a first identifier encrypted by the communication device using the first key, the first identifier has a corresponding relationship with the authentication information of the communication device, the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.
[0207] In certain implementations of the eighth aspect, before sending the request message to the verification network element, the transceiver unit is further used to: send third indication information to the verification network element, the third indication information indicating at least one authentication method, and the authentication information corresponding to each authentication method in the at least one authentication method is independent of each other; receive fourth indication information from the verification network element, the fourth indication information indicating a first authentication method, the first authentication method being one of the at least one authentication method, and the first authentication method corresponding to the first authentication information.
[0208] The authentication information refers to the description in the fourth aspect.
[0209] In certain implementations of the eighth aspect, the type of the first identifier indicated by each of the at least one authentication method is different, and the types of the first identifier are described with reference to the fourth aspect.
[0210] In certain implementations of the eighth aspect, the first authentication method is determined based on the second information and the third indication information, and the second information refers to the description in the fourth aspect.
[0211] In certain implementations of the eighth aspect, the transceiver unit is further used to: send a second digital signature to the verification network element, where the second digital signature is a signature of the second message using the private key of the communication device, and the second message includes a message that the communication device has interacted with the verification network element, and the second digital signature is used by the verification network element to authenticate the communication device.
[0212] In a ninth aspect, a communication device is provided, which includes a processor, and the processor is used to enable the device to implement any aspect of the above-mentioned first to fourth aspects, and any possible implementation method of the first to fourth aspects, by executing a computer program (or computer executable instructions) stored in a memory, and / or through a logic circuit.
[0213] Optionally, the device further includes a memory, which may be deployed separately from the processor or may be deployed centrally.
[0214] Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface. The communication interface may be a transceiver or an input / output interface.
[0215] In one implementation, the device is a verification network element, or a chip configured in the verification network element. It can also be a logic module or software that can implement all or part of the functions of the verification network element. When the device is a chip, the communication interface can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processor can also be embodied as a processing circuit or a logic circuit.
[0216] In another implementation, the apparatus is a terminal device, or a chip configured in the terminal device, or a logic module or software that implements all or part of the terminal device's functions. When the apparatus is a chip, the communication interface may be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processor may also be embodied as a processing circuit or a logic circuit.
[0217] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.
[0218] In a specific implementation, the processor may be one or more chips, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be, but is not limited to, received and input by a receiver, and the signal output by the output circuit may be, but is not limited to, output to and transmitted by a transmitter. The input circuit and the output circuit may be the same circuit, which functions as an input circuit and an output circuit at different times. The embodiments of the present application do not limit the specific implementation of the processor and various circuits.
[0219] In the tenth aspect, a chip system is provided, wherein the processor is used to execute the computer program or instructions in the memory, so that the chip system implements any aspect of the above-mentioned first to fourth aspects, and the method in any possible implementation method of the first to fourth aspects.
[0220] In the eleventh aspect, a communication system is provided, comprising: at least one of a verification network element and a terminal device, the verification network element being used to execute the above-mentioned first and second aspects, and the method in any possible implementation of the first and second aspects; the terminal device being used to execute the above-mentioned third and fourth aspects, and the method in any possible implementation of the third and fourth aspects.
[0221] In the twelfth aspect, a computer-readable storage medium is provided, which stores a computer program (also referred to as code, or instructions). When the computer-readable storage medium is run on a computer, the computer executes any one of the above-mentioned first and second aspects, as well as any possible implementation of the first and second aspects.
[0222] In the thirteenth aspect, a computer program product is provided, which includes a computer program (also referred to as code, or instructions). When the computer program is run, it enables the computer to execute any aspect of the above-mentioned first to fourth aspects, as well as the method in any possible implementation of the first to fourth aspects.
[0223] The beneficial effects brought about by the above-mentioned fifth to thirteenth aspects can be referred to the description of the beneficial effects in the first to fourth aspects, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0224] FIG1 is a schematic diagram of a communication network architecture applicable to an embodiment of the present application.
[0225] FIG2 is a schematic diagram of the architecture of a communication system applicable to an embodiment of the present application.
[0226] FIG3 is a schematic flow chart of an authentication process based on the EAP-AKA' architecture.
[0227] FIG4 is a schematic flow chart of a communication method 400 provided in this application.
[0228] FIG5 is a schematic flowchart of the key negotiation method provided in the present application.
[0229] FIG6 is a schematic flowchart of a communication method 600 provided in this application.
[0230] FIG7 is a schematic block diagram of a communication device 700 provided in this application.
[0231] FIG8 is a schematic block diagram of a communication device 800 provided in this application.
[0232] FIG9 is a schematic block diagram of a chip system 900 provided in this application. DETAILED DESCRIPTION
[0233] The technical solution in this application will be described below with reference to the accompanying drawings.
[0234] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, fifth generation (5G) systems, sixth generation (6G) systems, and other communication systems that have evolved after 5G.
[0235] Figure 1 is a schematic diagram of a communication network architecture applicable to an embodiment of the present application. As shown in Figure 1, the various parts involved in the network architecture are described below.
[0236] Terminal equipment 110: The terminal equipment in the embodiment of the present application may refer to a device that provides voice and / or data connectivity to a user, or a handheld device with wireless connection function, or other processing device connected to a wireless modem.
[0237] A terminal device may also be referred to as a terminal, access terminal, subscriber unit, user equipment (UE), subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent, or user device. A terminal device is a device that includes wireless communication capabilities (providing voice / data connectivity to the user). For example, a handheld device with wireless connectivity or an in-vehicle device may be used. The terminal in the embodiments of the present application can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a train, an airplane, a mobile internet device (MID), a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a light terminal device (light UE), a reduced capability UE (REDCAP UE), a wireless terminal in industrial control (such as a robot, etc.), a wireless terminal in the Internet of Vehicles (such as an on-board device, a whole vehicle device, an on-board module, a vehicle, an on-board chip, an on-board unit (OBU) or a telematics box (T-BOX), etc.), a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, etc. The present invention relates to wireless terminals in a smart city, wireless terminals in a smart city, wireless terminals in a smart home, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, wearable devices, terminals in a 5G network or terminals in a network evolved after 5G, etc. It will be understood that all or part of the functions of the terminal device in this application may also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (such as a cloud platform).
[0238] Wearable devices, also known as wearable smart devices, are a general term for wearable devices that use wearable technology to intelligently design and develop wearable devices for daily wear, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not just hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. In a broad sense, wearable smart devices include those that are fully functional, large in size, and can achieve full or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0239] The terminal device of the present application may also be a module or unit for implementing terminal functions, such as a universal integrated circuit card (UICC). It should be understood that the UICC card is used for example only. In actual implementation, the UICC card can also be replaced with a device with similar functions to the UICC card, such as an embedded universal integrated circuit card (eUICC). In addition, the UICC card can also be called by other names, such as a blockchain universal integrated circuit card (B-UICC), which is not limited in the present application.
[0240] Radio access network (R)AN node 120: Provides network access for terminal devices in a specific area and uses transmission tunnels of varying quality based on the device level and service requirements. RAN nodes manage radio resources, provide access services to terminal devices, and forward control signals and terminal data between the device and the core network.
[0241] In one possible scenario, the RAN node may be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), a base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system. The RAN node may be a macro base station, a micro base station or an indoor station, a relay node or a donor node, or a wireless controller in a cloud radio access network (CRAN) scenario. Optionally, the RAN node may also be a server, a wearable device, a vehicle or an on-board device, etc. For example, the access network device in the V2X technology may be a road side unit (RSU). All or part of the functions of the RAN node in this application may also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (e.g., a cloud platform). The RAN node in this application may also be a logical node, a logical module or software that can implement all or part of the functions of the RAN node.
[0242] In another possible scenario, multiple RAN nodes collaborate to assist the terminal in achieving wireless access, and different RAN nodes respectively implement part of the functions of the base station. For example, the RAN node can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0243] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (O-RAN) system, CU may also be referred to as an open-central unit (O-CU); DU may also be referred to as an open-distributed unit (O-DU); CU-CP may also be referred to as O-CU-CP, CU-UP may also be referred to as O-CU-UP, and RU may also be referred to as O-RU. For the sake of convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any of the CU (or CU-CP, CU-UP), DU and RU in this application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0244] User plane network element 130: used for packet routing and forwarding, and quality of service (QoS) processing of user plane data.
[0245] In a 5G communication system, the user plane network element may be a user plane function (UPF) network element. In a communication system evolved after 5G, the user plane network element may still be a UPF network element, or may have other names, which are not limited in this application.
[0246] Data network (DN) 140: This is the data network that provides services to users. Typically, the client is located in the UE, and the server is located in the data network. A data network can be a private network, such as a local area network (LAN), an external network not controlled by the operator, such as the Internet, or a proprietary network jointly deployed by operators, such as a network that provides Internet Protocol (IP) Multimedia Subsystem (IMS) services.
[0247] In communication systems that evolve after 5G, the DN in the 5G communication system can be used, and entities with similar functions may be replaced with other names, which is not limited in this application.
[0248] Authentication server 150: used for authentication services, generating keys to implement two-way authentication of terminal devices, and supporting a unified authentication framework.
[0249] In a 5G communication system, the authentication server may be an authentication server function (AUSF) network element. In a communication system evolved after 5G, the authentication server function network element may still be an AUSF network element, or may have other names, which are not limited in this application.
[0250] Access management network element 160: mainly used for mobility management and access management, such as access authorization / authentication.
[0251] In a 5G communication system, the access management network element may be an access management function (AMF) network element. In a communication system evolved after 5G, the access management network element may still be an AMF network element, or may have other names, which are not limited in this application.
[0252] Session management network element 170: mainly used for session management, allocation and management of Internet Protocol (IP) addresses of terminal devices, selection of endpoints for manageable user plane functions, policy control and charging function interfaces, and downlink data notification.
[0253] In a 5G communication system, the session management network element may be a session management function (SMF) network element. In communication systems evolved after 5G, the session management network element may still be an SMF network element, or may have other names, which are not limited in this application.
[0254] Slice selection network element 180: used to select a group of network slice instances for serving terminal devices and determine a group of access management network elements for serving terminal devices.
[0255] In a 5G communication system, the network open network element may be a network slice selection function (NSSF) network element. In a communication system evolved after 5G, the network open network element may still be an NSSF network element, or may have other names, which are not limited in this application.
[0256] Network exposure network element 190: used to expose network capabilities to third-party applications, enabling friendly docking of network capabilities with business requirements.
[0257] In a 5G communication system, the network exposure element may be a network exposure function (NEF) element. In a communication system evolving beyond 5G, the network exposure element may still be an NEF element, or may have other names, which are not limited in this application.
[0258] Network repository NE 1100: used to maintain real-time information of all network function services in the network.
[0259] In a 5G communication system, the network storage network element may be a network repository function (NRF) network element. In a communication system evolved after 5G, the network storage network element may still be an NRF network element, or may have other names, which are not limited in this application.
[0260] Policy control network element 1110: A unified policy framework used to guide network behavior and provide policy rule information to control plane functional network elements (such as AMF, SMF network elements, etc.).
[0261] In a 4G communication system, the policy control network element may be a policy and charging rules function (PCRF) network element. In a 5G communication system, the policy control network element may be a policy control function (PCF) network element. In a communication system evolved after 5G, the policy control network element may still be a PCF network element, or may have other names, which are not limited in this application.
[0262] Data management network element 1120: used to process terminal device identification, access authentication, registration, and mobility management.
[0263] In a 5G communication system, the data management network element may be a unified data management (UDM) network element. In a communication system that evolves after 5G, the unified data management may still be a UDM network element, or may have other names, which are not limited in this application.
[0264] Application network element 1130: used for data routing affected by the application, network access, interaction with the policy framework for policy control, etc.
[0265] In a 5G communication system, the application network element may be an application function (AF) network element. In a communication system evolved after 5G, the application network element may still be an AF network element, or may have other names, which are not limited in this application.
[0266] The above network architecture may also include an authentication credential repository and processing function (ARPF) network element and a security anchor function (SEAF) network element (not shown in the figure). The ARPF is primarily used to store the user's root key and related authentication subscription data, and to calculate the 5G authentication vector. The SEAF is primarily used to derive the underlying non-access stratum (NAS) and access stratum (AS) keys based on the anchor key, and to compare authentication results.
[0267] In the above network architecture, N1, N2, N3, N4, N6, Nnssf, Nnef, Nnrf, Npcf, Nudm, Naf, Nausf, Namf, and Nsmf are interface sequence numbers. The meanings of the above interface sequence numbers can be found in the meanings defined in the 3GPP standard protocol, and this application does not limit the meanings of the above interface sequence numbers.
[0268] For example, the N2 interface is the interface between the RAN and the access management network element, used for transmitting radio parameters and NAS signaling; the N3 interface is the interface between the RAN and the user plane function network element, used for transmitting user plane data; the N4 interface is the interface between the session management function network element and the user plane function network element, used for transmitting information such as service policies, tunnel identification information of the N3 connection, data cache indication information, and downlink data notification messages. The N6 interface is the interface between the DN and the user plane function network element, used for transmitting user plane data.
[0269] Nnssf, Nnef, Nnrf, Npcf, Nudm, Naf, Nausf, Namf, and Nsmf are service-oriented interfaces, through which network elements can exchange information.
[0270] It should be noted that the interface names between the various network functions in the figure are merely examples. In specific implementations, the interface names of the system architecture may also be other names, and this application does not limit this. In addition, the names of the messages (or signaling) transmitted between the above-mentioned network elements are merely examples and do not constitute any limitation on the functions of the messages themselves.
[0271] It should be understood that the above-mentioned network architecture applied to the embodiment of the present application is only an example of the network architecture described from the perspective of traditional point-to-point architecture and service-oriented architecture. The network architecture applicable to the embodiment of the present application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiment of the present application.
[0272] It should be noted that the names of the various network elements and interfaces in this application are only examples, and this application does not exclude the possibility that the network elements may be named differently in the future, or that the functions of the network elements may be merged. As communication systems evolve, any device or network element that can implement the functions of the aforementioned network elements will fall within the scope of protection of this application.
[0273] It is understood that the aforementioned network elements or functions can be network components in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). The aforementioned network elements or functions can be divided into one or more services, and further, services that exist independently of the network functions may also appear.
[0274] FIG2 is a schematic diagram of the architecture of a communication system applicable to an embodiment of the present application.
[0275] As shown in FIG. 2 , the communication system includes at least one node (nodes 101 a to 101 i ) and a storage system 102 .
[0276] The storage system 102 may include one or more storage nodes.
[0277] The storage system 102 may include one or more of the following: a blockchain system, a distributed storage system, or a communication system.
[0278] Among them, the blockchain system may include one or more blockchain nodes, that is, the storage node corresponding to the blockchain system can be a blockchain node; the distributed storage system may include one or more distributed storage devices, that is, the storage node corresponding to the distributed storage system can be a distributed storage device; the communication system may include the communication equipment corresponding to the operator, that is, the storage node corresponding to the communication system can be the communication equipment corresponding to the operator.
[0279] It should be understood that blockchain nodes, storage devices in distributed storage systems, and communication devices can be terminal devices or network devices.
[0280] Each node in the at least one node (nodes 101a to 101i) can exchange information with the storage system 102. Optionally, if the at least one node includes multiple nodes, the nodes in the multiple nodes can directly exchange information with each other. The nodes in the at least one node (nodes 101a to 101i) can include terminal devices and / or network devices. Among them, the terminal device can be a device corresponding to the user; the network device can be a device corresponding to the card manufacturer or terminal manufacturer, a device corresponding to a trusted third party, an air card writing server, a device corresponding to the operator, or a device corresponding to an authoritative agency. The terminal manufacturer can also be called an equipment manufacturer, an equipment provider, etc.
[0281] Among them, the equipment corresponding to the card dealer or terminal manufacturer can be the equipment used to realize the business of the card dealer or terminal manufacturer, such as the equipment used by the card dealer or terminal manufacturer to write cards; the equipment corresponding to the operator is the equipment used to provide the operator's business, such as the operator's server, the operator's core network element, or access network equipment, etc.; the equipment corresponding to the authoritative organization is the equipment that can be used to provide the business of the authoritative organization, such as the server or host belonging to the authoritative organization; the equipment corresponding to the trusted third party can be the equipment that can be used to provide the business of the third-party trusted organization, such as the server or host belonging to the third-party trusted organization.
[0282] It is understandable that card vendors, terminal manufacturers, trusted third parties, operators or authoritative institutions are all used as examples, and in actual implementation, other organizations or institutions may also exist.
[0283] In order to facilitate understanding of the technical solutions of the embodiments of the present application, some terms or concepts that may be involved in the embodiments of the present application are first briefly described.
[0284] 1. Key
[0285] A key is a parameter that is input into an algorithm that converts plaintext to ciphertext or vice versa.
[0286] 2. Public and private keys
[0287] A public key and a private key are a key pair (one public key and one private key) derived through an algorithm. One key is publicly available, called the public key; the other is kept private, called the private key. This algorithm-derived key pair is guaranteed to be unique worldwide. When using this key pair, if one key is used to encrypt data, the other key must be used to decrypt it. For example, if data is encrypted using the public key of the key pair, it must be decrypted using the private key, and vice versa; otherwise, decryption will fail.
[0288] 3. Blockchain (BC)
[0289] Transactions on the network are generated and stored in blocks, linked chronologically to form a chain structure. Confirmed and proven transactions on the network are linked from the beginning of the blockchain to the latest block. The ledger formed by linking multiple blocks together is called a blockchain.
[0290] Blockchain technology implements a chained data structure that connects blocks of data and information in chronological order, using cryptographic methods to ensure tamper-proof and unforgeable distributed storage. Generally, the data and information in a blockchain can be referred to as a "transaction."
[0291] Blockchain technology is not a single technology, but a system that integrates point-to-point transmission, consensus mechanism, distributed data storage and cryptographic principles. The system has the technical characteristics of full disclosure and tamper-proof.
[0292] 1) Peer-to-peer transmission: Nodes participating in the blockchain are independent and peer-to-peer, and data and information are synchronized between nodes using peer-to-peer transmission technology. Nodes can be different physical machines or different instances in the cloud.
[0293] 2) Consensus Mechanism: The blockchain consensus mechanism refers to the process by which multiple participating nodes reach consensus on specific data and information through interaction under pre-set logical rules. Consensus mechanisms rely on well-designed algorithms, resulting in varying performance (e.g., transaction throughput (transactions per second, TPS), latency to reach consensus, and computational and transmission resource consumption) across different consensus mechanisms.
[0294] 3) Distributed Data Storage: Distributed storage in blockchains means that each participating node stores independent and complete data, ensuring that data storage is fully transparent across nodes. Unlike traditional distributed data storage, which divides data into multiple copies for backup or synchronous storage according to specific rules, blockchain distributed data storage relies on consensus among independent, equal-status nodes within the blockchain to achieve highly consistent data storage.
[0295] 4) Cryptography principles: Blockchain is usually based on asymmetric encryption technology to achieve trusted information dissemination, verification, etc.
[0296] The concept of a "block" is to organize one or more data records into "blocks," the size of which can be customized based on the specific application scenario. A "chain" is a data structure that connects these blocks of data records in chronological order using hashing technology. In a blockchain, each block consists of a "block header" and a "block body." The "block body" contains the transaction records packaged into the block, while the "block header" contains the root hash of all transactions in the block and the hash of the previous block. The blockchain's data structure ensures that the data stored on the blockchain is tamper-proof.
[0297] 4. Information / data on-chain
[0298] Information / data on-chain means that information / data is packaged in a block through a consensus mechanism to become a new block, and is linked to the previous block, becoming tamper-proof information / data on the chain.
[0299] 5. Smart Contracts
[0300] A smart contract is a computer protocol designed to communicate, verify, or execute contracts in an informational manner. Blockchain-based smart contracts are visible to all users on the blockchain. However, this makes vulnerabilities, including security vulnerabilities, visible and potentially difficult to fix quickly.
[0301] Smart contracts in the blockchain field have the following characteristics:
[0302] The rules are open and transparent, and the rules and data in the contract are visible to the outside world; all transactions are publicly visible, and there will be no false or hidden transactions.
[0303] Blockchain technology's qualities of transparency and immutability are inherent to smart contracts. Smart contracts allow for trusted, traceable, and irreversible transactions without a third party. Based on immutable data, smart contracts can automatically enforce predefined rules and terms.
[0304] 6. Self-control identity (scID)
[0305] The scID can be used to identify the identity information of a first node (e.g., any of nodes 101a to 101i). The scID can be decentralized root credentials / credentials (DRC), decentralized identity credentials / credentials (DIC), or decentralized self-control credentials (DSCC). The scID can be generated by the first node or a node other than the first node. For example, if the scID is DRC, the DRC can be generated by a trusted node other than the first node; if the scID is DIC or DSCC, the DSCC can be generated by the first node.
[0306] scID can correspond to different business scenarios. For example, in business scenarios with high requirements for personal information confidentiality, the scID can be DRC, which means that the business can be completed using DRC. For another example, in scenarios with low requirements for trust in the first node, the SID can be DIC or DSCC, which means that the business can be completed using DIC or DSCC.
[0307] In the current mobile communication network, the network side authenticates the UE before the UE accesses the network. Exemplarily, the UE and the network use ECDH key negotiation to generate a key k. The principle of ECDH is that the public key of the network is preset inside the UE. Before the UE accesses the network, the UE generates a temporary public-private key pair for the UE; the UE uses the temporary private key of the UE and the public key of the network to calculate the key k; the UE uses the key k to encrypt the user permanent identifier (SUPI), and sends the ciphertext of the SUPI and the temporary public key of the UE, the user concealed identifier (SUCI), to the network side; the network side uses the private key of the network and the temporary public key of the UE to calculate the key k. Subsequently, the network side uses the key k to decrypt the SUCI to obtain the SUPI, and queries the root key corresponding to the SUPI, and uses the root key for identity authentication in both directions (for details, please refer to the description of Figure 3).
[0308] Figure 3 is a schematic flow chart of an authentication process based on the Extensible Authentication Protocol (EAP) AKA'. The authentication process includes the following contents.
[0309] S301, UDM / ARPF determines an authentication vector (AV).
[0310] After the UDM / ARPF receives the UE ID and service network name (SN name) sent by the AUSF, it determines the AV based on the received information. The AV may include a five-tuple: an authentication random number (RAND), an authentication token (AUTN), an expected response parameter (XRES), an encryption key (CK), and an integrity key (IK). The AV parameter generation process is shown in Figure 6. The specific process can be found in the existing process and will not be repeated here.
[0311] Next, UDM / ARPF updates the AV according to the SN name and the key derivation function (KDF) algorithm. Specifically, it calculates CK' and IK' according to the SN name and the KDF algorithm, and uses the CK' and IK' to replace the CK and IK in the original AV.
[0312] S302, UDM / ARPF sends a UE identity authentication response to AUSF.
[0313] The UE authentication response sent by UDM / ARPF to AUSF may be Nudm_UEAuthentication_Get Response, which may include an updated authentication vector (denoted as AV'). The parameters used for authentication included in AV' may include (RAND, AUTN, XRES, CK', IK').
[0314] S303, AUSF sends a UE identity authentication response to SEAF.
[0315] The UE identity authentication response sent by the AUSF to the SEAF may be an EAP request message or an AKA'-challenge message, and the EAP-request or AKA'-challenge includes RAND and AUTN.
[0316] S304: SEAF sends an authentication request to the UE.
[0317] The authentication request (authentication request) sent by SEAF to the UE may be the forwarded EAP-request or AKA'-challenge received in step S303, where the EAP-request or AKA'-challenge includes RAND and AUTN.
[0318] Specifically, SEAF forwards the EAP-request or AKA'-challenge to the USIM of the UE.
[0319] S305: The UE calculates an authentication response.
[0320] Specifically, after the UE's USIM receives the RAND and AUTN in the EAP-request or AKA'-challenge, it verifies whether the AUTN is correct. If correct, the USIM calculates the reply RES, CK, and IK, and then sends RES, CK, and IK to the UE's ME. The ME then calculates CK' and IK' based on the SN name and the KDF algorithm. CK' and IK' can be used by the UE to generate a key corresponding to the AUSF's key.
[0321] S306: The UE sends an authentication response to the SEAF.
[0322] The authentication response sent by the UE to the SEAF may be an EAP response (EAP-response) message or an AKA'-challenge (AKA'-challenge) message, and the EAP-response and AKA'-challenge include RES.
[0323] S307, SEAF forwards the message received in step S306 to AUSF.
[0324] S308, AUSF verification response.
[0325] Among them, AUSF can compare RES with its own stored RES to see if they are equal. If they are equal, AUSF verifies the UE successfully.
[0326] Optionally, the AUSF and the UE may further exchange EAP-request / AKA'-notification messages and EAP-response / AKA'-notification messages in step S309.
[0327] S310, AUSF sends a UE identity authentication response to SEAF.
[0328] AUSF can generate an extended master session key (EMSK) from CK' and IK', and use the first 256 bits of EMSK as the AUSF key (denoted as K AUSF ), then according to K AUSF Derived SEAF key K SEAFand send the EAP success message and K SEAF Sent to SEAF.
[0329] S311, SEAF sends an N1 message to the UE.
[0330] The N1 message may be an EAP success message.
[0331] In the above solution, the network and the terminal use a fixed key exchange algorithm to generate a shared key, which limits its application scenarios. For example, ECDH key agreement has a high computational complexity for some low-power terminal devices. Another example is that ECDH key agreement may not be suitable for applications with high security requirements. Specifically, during the ECDH key agreement process, the terminal uses the network's fixed public key to calculate the shared key, so this key agreement algorithm lacks forward security.
[0332] As the number of application scenarios (eg, different security requirements) of terminals and networks in mobile communication systems increases, how to improve the flexibility of authentication processes of terminals and networks becomes an issue that needs to be considered.
[0333] In view of this, the present application proposes a communication method and a communication device, which are beneficial to improving or solving the above-mentioned problems.
[0334] In order to facilitate understanding of the embodiments of the present application, the following explanations are made.
[0335] First, in this application, "used to indicate" can be understood as "enabling," and "enabling" can include both direct and indirect enabling. When describing information as enabling A, it can include the information directly enabling A or indirectly enabling A, but it does not necessarily mean that the information contains A.
[0336] The information enabled by the information is called information to be enabled. In the specific implementation process, there are many ways to enable the enabled information, such as but not limited to, directly enabling the information to be enabled, such as the information to be enabled itself or the index of the information to be enabled. The information to be enabled can also be indirectly enabled by enabling other information, wherein there is an association between the other information and the information to be enabled. It is also possible to enable only a part of the information to be enabled, while the other parts of the information to be enabled are known or agreed in advance. For example, it is also possible to enable specific information with the help of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the enabling overhead to a certain extent. At the same time, it is also possible to identify the common parts of each piece of information and enable them uniformly to reduce the enabling overhead caused by enabling the same information separately.
[0337] Second, the first, second, and various numerical numbers (e.g., "#1," "#2," etc.) shown in this application are merely for ease of description and are used to distinguish between objects. They are not intended to limit the scope of the embodiments of this application. For example, they are used to distinguish between different messages, etc. They are not intended to describe a specific order or precedence. It should be understood that the objects described in this manner can be interchanged where appropriate to describe solutions beyond the embodiments of this application.
[0338] Third, in this application, "pre-configuration" may include pre-definition, such as protocol definition. This "pre-definition" may be implemented by pre-storing corresponding codes, tables, or other methods that can be used to indicate relevant information in a device (e.g., including various network elements). This application does not limit the specific implementation method.
[0339] Fourth, the term "and / or" in this document simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0340] Fifth, in the embodiments of the present application, one information (e.g., information #1) "includes" another information (e.g., information #2), which can be understood as the information #1 explicitly carrying or implicitly carrying the information #2. For example, the information #1 directly carries the information #2; for example, the information #1 carries indication information indicating the information #2, and the receiving device receiving the information #1 can obtain the information #2 based on the indication information, and the indication information used to indicate the information #2 can be predefined or specified by the protocol, or it can be an explicit or implicit indication.
[0341] Below, without loss of generality, the communication method provided in the embodiment of the present application is described in detail by taking the interaction between network elements as an example.
[0342] Figure 4 is a schematic flow chart of a communication method provided by an embodiment of the present application. As shown in Figure 4 (a), the method may include the following steps.
[0343] S410: The terminal device (an example of a communication apparatus) and the verification network element negotiate to determine a first key agreement algorithm.
[0344] The verification network element may be an access network device that provides services to the terminal device, or, if the CU and DU of the access network device are separated, the verification network element may be the CU of the access network device; or the verification network element may be an edge computing node, such as an edge application server (EAS) deployed in an edge data network (EDN), or a core network element belonging to operator #1, such as AMF, AUSF, UDM, etc. Operator #1 may be the operator contracted by the terminal device or another operator, without limitation.
[0345] The first key agreement algorithm is one of at least one key agreement algorithm. The first key agreement algorithm is used by the terminal device and the verification network element to subsequently perform key agreement to determine a first key. The first key can be used to encrypt or decrypt messages transmitted between the terminal device and the verification network element.
[0346] Exemplarily, the at least one key agreement algorithm may include at least one of the following algorithms:
[0347] Elliptic curve Diffie–Hellman (ECDH) key agreement algorithm, ephemeral elliptic curve Diffie–Hellman (ECDHE) key agreement algorithm, key agreement algorithm based on post-quantum cryptography (PQC), key agreement algorithm based on PQC and ECDH, key agreement algorithm based on PQC and ECDHE, and key agreement algorithm based on pre-shared key (PSK).
[0348] That is, the first key agreement algorithm determined by negotiation between the terminal device and the verification network element is any one of the above key agreement algorithms.
[0349] It is understood that for the at least one key agreement algorithm, the security level and computational complexity corresponding to the algorithm are different. For example, the security level of the algorithms can be ranked from high to low as follows: key agreement algorithm based on PQC and ECDHE, key agreement algorithm based on PQC and ECDH, key agreement algorithm based on PQC, ECDHE key agreement algorithm, ECDH key agreement algorithm, and key agreement algorithm based on PSK. The ranking of the computational complexity corresponding to the algorithms is similar to the ranking of the security level corresponding to the algorithms.
[0350] Optionally, the at least one key agreement algorithm may also correspond to different network standards, or in other words, each key agreement algorithm in the at least one key agreement algorithm may be applicable to one or more network standards.
[0351] For example, the 5G network can correspond to the ECDH key agreement algorithm, the ECDHE key agreement algorithm, and the PSK-based key agreement algorithm; the network in the communication system evolved after 5G, such as the 6G network, can correspond to the ECDHE key agreement algorithm, the PQC-based key agreement algorithm, the PQC and ECDH-based key agreement algorithm, and the PQC and ECDHE-based key agreement algorithm.
[0352] For another example, the 5G network can correspond to the ECDH key agreement algorithm, the ECDHE key agreement algorithm, and the PSK-based key agreement algorithm; the network in the communication system evolved after 5G, such as the 6G network, can correspond to the PQC-based key agreement algorithm, the PQC and ECDH-based key agreement algorithm, and the PQC and ECDHE-based key agreement algorithm.
[0353] It should be understood that the above correspondence between the key negotiation algorithm and the network standard is only an example and this application does not limit it.
[0354] Specifically, the terminal device and the verification network element may negotiate and determine the first key agreement algorithm in the following manner:
[0355] Method 1: The verification network element determines the first key agreement algorithm from the at least one key agreement algorithm. The specific process may include S411a and S412a.
[0356] S411a: The terminal device sends indication information #1 (an example of first indication information) to the verification network element. Correspondingly, the verification network element receives the first indication information from the terminal device.
[0357] The indication information #1 indicates at least one key agreement algorithm, or the indication information #1 indicates determining a first key agreement algorithm from at least one key agreement algorithm.
[0358] Optionally, the indication information #1 may also indicate determining the first key agreement algorithm.
[0359] S412a: The verification network element sends indication information #2 (an example of second indication information) to the terminal device. Correspondingly, the terminal device receives indication information #2 from the verification network element.
[0360] The indication information #2 indicates the first key agreement algorithm, where the first key agreement algorithm is one of the at least one key agreement algorithm mentioned above.
[0361] Specifically, the verification network element determines the first key agreement algorithm from at least one key agreement algorithm, and indicates the first key agreement algorithm to the terminal device.
[0362] Exemplarily, the verification network element may determine the first key agreement algorithm based on the first information and the indication information #1.
[0363] The first information may include at least one of the following information: the security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network standard, the type of the terminal device, and the computing capability of the terminal device.
[0364] Exemplarily, the verification network element may determine the first key agreement algorithm based on an item in the first information.
[0365] For example, if it is determined that the security level requirement for the current communication between the terminal device and the verification network element is low, the verification network element may select a key agreement algorithm with a lower security level, such as an ECDH key agreement algorithm.
[0366] For another example, if it is determined that the computing power of the terminal device is low, or the terminal device is a low-power terminal device, the verification network element can select a key exchange algorithm with lower computational complexity, such as the ECDH key agreement algorithm or a PSK-based key agreement algorithm.
[0367] For another example, if the current network is a 5G network, the verification network element can select a key agreement algorithm corresponding to the 5G network, such as one of the ECDH key agreement algorithm, the ECDHE key agreement algorithm, and the PSK-based key agreement algorithm; if the current network is a network in a communication system evolved after 5G, the verification network element can select one of the ECDH key agreement algorithm, the ECDHE key agreement algorithm, and the PQC-based key agreement algorithm, the PQC and ECDH-based key agreement algorithm, and the PQC and ECDHE-based key agreement algorithm.
[0368] Alternatively, the verification network element determines the first key agreement algorithm based on multiple information in the first information.
[0369] For example, the verification network element can determine the current network standard and select a key agreement algorithm that is compatible with that network standard. Based on this, it can select a key agreement algorithm with a higher security level or a key agreement algorithm with lower computational complexity, depending on the security level requirements or the computing power of the terminal device. For example, if the current network is determined to be a 5G network, the verification network element can select the ECDHE key agreement algorithm with a higher security level to ensure communication security, or select the PSK-based key agreement algorithm with a lower computational complexity to reduce power consumption of the terminal device.
[0370] In the second method, the terminal device determines a first key agreement algorithm from at least one key agreement algorithm and indicates the first key agreement algorithm to the verification network element. The specific process may include S411b and S412b.
[0371] S411b: The terminal device sends indication information #3 to the verification network element. Correspondingly, the verification network element receives indication information #3 from the terminal device.
[0372] The indication information #3 indicates the first key agreement algorithm, or the indication information #3 indicates confirmation of whether to use the first key agreement algorithm.
[0373] Specifically, the terminal device determines the first key agreement algorithm from at least one key agreement algorithm, and indicates the first key agreement algorithm to the verification network element.
[0374] Exemplarily, the terminal device may determine the first key agreement algorithm from at least one key agreement algorithm based on the first information. The first information may refer to the description in S411a.
[0375] For a specific example of the terminal device determining the first key agreement algorithm based on the first information, see S411a. For example, the terminal device may select a key agreement algorithm corresponding to the security level of the current communication. For another example, the terminal device may select a key agreement algorithm corresponding to its computing capability or type based on its computing capability. For another example, the terminal device may select a key agreement algorithm corresponding to the network standard based on the network standard.
[0376] Optionally, in S412b, the verification network element sends a message #1 to the terminal device. Correspondingly, the terminal device receives the message #1 from the verification network element.
[0377] Message #1 can be a confirmation message or a rejection message. Message #1 is sent based on indication #3, i.e., the verification network element determines whether to use the first key agreement algorithm indicated in indication #3. If the first key agreement algorithm is confirmed to be used, the confirmation message can be sent to the terminal device; otherwise, the rejection message is sent to the terminal device.
[0378] For example, if the first key agreement algorithm selected by the terminal device meets the network's established security level, network standard, etc., a confirmation message is sent to the terminal device; otherwise, a rejection message may be sent to the terminal device.
[0379] Optionally, if the verification network element sends a rejection message to the terminal device, the rejection message may also carry the reason for the rejection. For example, the reason for the rejection may be that the security level is not enough, or the requirements of the network standard are not met, etc. After receiving the rejection message, the terminal device may re-determine the first key negotiation algorithm based on the reason for the rejection.
[0380] Optionally, the method further includes:
[0381] S420: The verification network element and the terminal device determine the first key based on the first key agreement algorithm.
[0382] Exemplarily, when the first key agreement algorithm is the ECDH key agreement algorithm, the terminal device sends the public key (referred to as the first public key) in the first temporary public-private key pair generated by the terminal device to the verification network element; the verification network element determines the first key based on the first public key and the private key of the verification network element.
[0383] Optionally, the verification network element sends the public key of the verification network element to the terminal device, or the public key of the verification network element can be pre-set in the terminal device; the terminal device generates the first key based on the private key in the generated first temporary public-private key pair (recorded as the first private key) and the public key of the verification network element.
[0384] The specific process of the verification network element and the terminal device generating the first key based on the ECDHE key agreement algorithm can be referred to the description in (a) of Figure 5.
[0385] When the first key agreement algorithm is the ECDHE key agreement algorithm, the terminal device sends the first public key in the first temporary public-private key pair generated by the terminal device to the verification network element; the verification network element determines the first key based on the first public key and the private key in the second temporary public-private key pair generated by the verification network element (recorded as the second private key).
[0386] Optionally, the verification network element sends the public key in the second temporary public-private key pair (referred to as the second public key) to the terminal device; the terminal device generates the first key based on the second public key and the first private key in the first temporary public-private key pair.
[0387] The specific process of the verification network element and the terminal device generating the first key based on the ECDHE key agreement algorithm can be referred to the description in (b) of Figure 5.
[0388] When the first key agreement algorithm is the PQC-based key agreement algorithm, the terminal device sends the public key (referred to as the third public key) in the third temporary public-private key pair generated based on the post-quantum algorithm to the verification network element; the verification network element inputs the third public key into the post-quantum algorithm to generate the ciphertext and the first key.
[0389] Optionally, the verification network element sends the ciphertext to the terminal device; the terminal device inputs the ciphertext and the third private key into the post-quantum algorithm to obtain the first key.
[0390] For the specific process of the verification network element and the terminal device generating the first key according to the PQC-based key agreement algorithm, reference may be made to the description in (c) of FIG. 5 .
[0391] When the first key agreement algorithm is the key agreement algorithm based on PQC and ECDH, the terminal device sends the first public key and the third public key to the verification network element, and the first public key and the third public key refer to the description above; the verification network element determines the second key based on the first public key and the private key of the verification network element, and inputs the third public key into the post-quantum algorithm to generate ciphertext and the third key; the verification network element determines the first key based on the second key and the third key.
[0392] Optionally, the verification network element sends the public key of the verification network element and the ciphertext to the terminal device; the terminal device generates the second key based on the first private key and the public key of the verification network element, and inputs the ciphertext and the third private key into the post-quantification algorithm to obtain the third key; the terminal device determines the first key based on the second key and the third key.
[0393] The specific process of the verification network element and the terminal device generating the first key according to the key agreement algorithm based on PQC and ECDH can be referred to the description in (d) of Figure 5.
[0394] When the first key agreement algorithm is the key agreement algorithm based on PQC and ECDHE, the terminal device sends the first public key and the third public key to the verification network element, and the first public key and the third public key refer to the description above; the verification network element determines the second key based on the first public key and the second private key, and inputs the third public key into the post-quantum algorithm to generate ciphertext and a third key, wherein the second private key refers to the description above; the verification network element determines the first key based on the second key and the third key.
[0395] Optionally, the verification network element sends a second public key and the ciphertext to the terminal device; the terminal device generates the second key based on the first private key and the second public key, and inputs the ciphertext and the third private key into the post-quantification algorithm to obtain the third key; and the terminal device determines the first key based on the second key and the third key. The second public key and the first private key are described above.
[0396] The specific process of the verification network element and the terminal device generating the first key according to the key agreement algorithm based on PQC and ECDHE can be referred to the description in (e) of Figure 5.
[0397] When the first key agreement algorithm is the PSK-based key agreement algorithm, before key agreement, at least one key is pre-set in the terminal device and the verification network element, and the at least one key corresponds to the at least one identifier. In other words, a correspondence between the at least one key and the at least one identifier is pre-set in the terminal device and the verification network element (recorded as correspondence relationship #2). The terminal device sends the identifier corresponding to the first key to the verification network element, where the first key is one of the at least one keys; the verification network element determines the first key based on the identifier of the first key and the correspondence relationship #2.
[0398] The specific process of the verification network element and the terminal device generating the first key according to the PSK-based key agreement algorithm can be referred to the description in (f) of Figure 5.
[0399] Optionally, the method further includes: the verification network element sending a certificate of the verification network element to the terminal device (or the certificate of the verification network element is pre-set in the terminal device), and a digital signature of the first message using the private key of the verification network element (an example of a first digital signature). The first message may include messages that the verification network element has interacted with the terminal device; the terminal device verifies the first digital signature based on the certificate of the verification network element, thereby verifying the verification network element.
[0400] Exemplarily, if the certificate of the verification network element is issued by the operator, or in other words, the signature of the verification network element certificate is generated using the operator's private key, the terminal device can verify the certificate of the verification network element based on the operator's certificate. Furthermore, the terminal device verifies the first digital signature based on the public key in the certificate of the verification network element, thereby authenticating the verification network element.
[0401] For example, the terminal device may pre-install the operator's certificate or receive the operator's certificate from the verification network element. The operator's certificate includes the operator's public key. The terminal device may use the public key in the operator's certificate to verify the operator's private key signature on the verification network element certificate. Furthermore, the terminal device may verify the first digital signature based on the verification network element's public key. If all of the above processes are successfully verified, it indicates that the terminal device has successfully authenticated the verification network element.
[0402] Alternatively, the terminal device may verify the first digital signature based on the public key in the certificate of the verification network element, thereby authenticating the verification network element.
[0403] It should be understood that the verification network element may send the verification network element's certificate and / or the first digital signature to the terminal device during the key negotiation process. For example, the verification network element may send the verification network element's certificate and / or the first digital signature to the terminal device at the same time as the verification network element sends the verification network element's public key or the second public key or the ciphertext to the terminal device. Alternatively, the process may be independent of the key negotiation process, which is not limited in this application.
[0404] Among them, the certificate of the verification network element may include the identification of the verification network element, the public key of the verification network element, the information of the issuer of the certificate, such as the identification of the issuer, the signature of the issuer, etc., and the information of the certificate, such as the validity period and version number of the certificate.
[0405] It should be understood that if the certificate of the verification network element is pre-set in the terminal device, the step of the verification network element sending the certificate of the verification network element to the terminal device may not be performed.
[0406] It should be understood that the certificate of the verification network element and the first digital signature can be carried in the same message or sent separately, without limitation, for example, via an RRC message or a NAS message, or other downlink signaling, without limitation.
[0407] Optionally, the method further includes:
[0408] S430: The terminal device and the verification network element negotiate to determine a first authentication method.
[0409] The first authentication method is one of at least one authentication method. The authentication information corresponding to each authentication method in the at least one authentication method is independent of each other. For example, the authentication information corresponding to each authentication method is different, and / or the authentication process corresponding to each authentication method is different.
[0410] Exemplarily, the authentication information may include at least one of the following information: credentials of the terminal device, and a cryptographic algorithm.
[0411] The terminal device's credentials may include at least one verifiable credential (VC) or at least one verifiable attestation (VA) of the terminal device. Different credentials correspond to different credential information. The credential information may include information about the issuer of the credential, the public key of the terminal device, the validity period of the credential, etc.
[0412] The information of the certificate issuer may include the public key of the certificate issuer, the identification and / or name of the certificate issuer. For example, the certificate issuer may be a different operator, card merchant, terminal manufacturer, authority, third-party trusted organization or air card writing server, etc.
[0413] The cryptographic algorithm may also be referred to as a cryptographic suite, and includes at least one of the following: key length, encryption algorithm, decryption algorithm, signature algorithm, or public parameters.
[0414] Alternatively, the authentication information may include the root key of the terminal device, the authentication vector (AV) of the terminal device, or the address of the smart contract. The authentication vector is determined based on the root key of the terminal device; the address of the smart contract can be used to obtain the authentication vector of the terminal device stored in the smart contract. For example, the authentication vector may be an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) AV or a 5G Home Environment Authentication Vector (5G HE AV).
[0415] It should be understood that the above authentication vectors are only examples and the present application is not limited thereto.
[0416] Optionally, the type of the first identifier indicated by each authentication method in the at least one authentication method is different.
[0417] The first identifier has a corresponding relationship with the authentication information of the terminal device (denoted as corresponding relationship #1), and the first identifier can be used to obtain the authentication information of the terminal device.
[0418] Exemplarily, the corresponding relationship #1 can be stored in a storage system, such as the storage system 102 mentioned above. Specifically, it can be stored in a storage node corresponding to the storage system. For example, if the storage system is a blockchain system, the storage node can be a blockchain node. For example, the corresponding relationship can be stored on the blockchain node in the form of blocks or transactions, that is, the information is on the chain; if the storage system is a distributed storage system, the storage node can be a node in the distributed storage system. In some possible scenarios, the distributed storage node can be a blockchain node; if the storage system is a communication system, the storage node can be a communication device in the communication system, such as a functional network element that can store the contract data of a terminal device.
[0419] The type of the first identifier may be any one of the following, or in other words, the first identifier may include any one of the following types of identifiers: a first type of identifier, a second type of identifier, a block identifier or a transaction identifier, and a pseudo identifier.
[0420] The first type of identification includes but is not limited to the following:
[0421] Subscription permanent identifier (SUPI), subscription concealed identifier (SUCI), generic public subscription identifier (GPSI), permanent equipment identifier (PEI) or mobile subscriber international ISDN / PSTN number (MSISDN). ISDN stands for Integrated Service Digital Network and PSTN stands for Public Switched Telephone Network.
[0422] The second type of identifier is the scID of the terminal device, and the second type of identifier may be DRC, DIC, or DSCC.
[0423] Among them, the first type of identification can be understood as an identification assigned to the terminal device by the network side or the access network side, or a permanent identification of the terminal device. The first type of identification is universal and can be applied to the authentication of terminal devices in 5G communication systems or communication systems before 5G; the second type of identification can be generated by the terminal device or other trusted nodes other than the terminal device (for example, the storage node shown in Figure 2). Compared with the first type of identification, the generation of the second type of identification is more flexible. Secondly, the second type of identification can be applied to business scenarios with high requirements for confidentiality of personal information.
[0424] The block identifier or the transaction identifier can be used to obtain the corresponding relationship #1 stored on the blockchain. In other words, when the first identifier is the block identifier or the transaction identifier, the corresponding relationship #1 stored on the blockchain can be obtained through the first identifier.
[0425] The virtual identifier has a corresponding relationship with the second type of identifier. That is, when the first identifier is a virtual identifier, the second type of identifier is determined based on the corresponding relationship between the virtual identifier and the second type of identifier. Compared to directly using the second type of identifier, using a virtual identifier can further improve communication security.
[0426] Specifically, the terminal device and the verification network element may negotiate and determine the first authentication method in the following manner:
[0427] Method 1: The verification network element determines the first authentication method from the at least one authentication method. The specific process may include S431a and S432a.
[0428] S431a: The terminal device sends instruction information #4 (an example of the third instruction information) to the verification network element. Correspondingly, the verification network element receives the instruction information #4 from the terminal device.
[0429] The indication information #4 may indicate at least one authentication method, or in other words, the indication information #4 may indicate determining a first authentication method from the at least one authentication method.
[0430] Alternatively, the instruction information #4 indicates to determine the first authentication method.
[0431] S432a, the verification network element sends instruction information #5 (an example of the fourth instruction information) to the terminal device. Correspondingly, the terminal device receives the instruction information #5 from the verification network element.
[0432] Among them, indication information #5 indicates the first authentication method.
[0433] Specifically, the verification network element may determine the first authentication method from at least one authentication method based on the second information.
[0434] The second information may include at least one of the following information: information of the issuer of the certificate, the security level of the certificate, the security level of the cryptographic algorithm, and the computational complexity of the cryptographic algorithm.
[0435] For example, if the terminal device's credentials include a certificate issued by a card merchant and a certificate issued by an operator, the verification network element may select the certificate issued by the operator of the network being accessed for verification. That is, the first authentication method may correspond to the certificate issued by the operator of the network being accessed.
[0436] For another example, if the terminal device has two certificates, one is a post-quantum certificate and the other is a non-post-quantum certificate (such as a Rivest-Shamir-Adleman (RSA) certificate or an Elliptic Curve Digital Signature Algorithm (ECDSA) certificate), the verification network element can select the certificate with a higher security level (e.g., a post-quantum certificate) based on the security level of the certificate. That is, the first authentication method can correspond to the post-quantum certificate of the terminal device.
[0437] Method 2: The terminal device determines the first authentication method from the at least one authentication method and indicates the first authentication method to the verification network element. The specific determination method may include S431b and S432b:
[0438] S431b: The terminal device sends indication information #6 to the verification network element. Correspondingly, the verification network element receives indication information #6 from the terminal device.
[0439] The indication information #6 indicates the first authentication method, or the indication information #6 indicates confirmation of whether to use the first authentication method.
[0440] Specifically, the terminal device determines the first authentication method from the at least one authentication method according to the second information, and sends the indication information #6 to the verification network element.
[0441] For a specific example of the terminal device determining the first authentication method based on the second information, refer to the description in S432a.
[0442] Optionally, in S432b, the verification network element sends message #2 to the terminal device. Correspondingly, the terminal device receives message #2 from the verification network element.
[0443] Message #2 can be a confirmation message or a rejection message. Message #2 is sent based on instruction #6, i.e., the verification network element determines whether to use the first authentication method indicated in instruction #6. If the first authentication method is confirmed, the confirmation message can be sent to the terminal device; otherwise, the rejection message is sent to the terminal device.
[0444] For example, when the second information corresponding to the first authentication method selected by the terminal device meets the network's established requirements (for example, the issuer of the required certificate, the required security level of the certificate, etc.), a confirmation message is sent to the terminal device; otherwise, a rejection message can be sent to the terminal device.
[0445] Optionally, if the verification network element sends a rejection message to the terminal device, the rejection message may also carry the reason for the rejection. For example, the reason for the rejection may be that the security level of the credential is not enough, or the credential is not required to be issued by the party, etc. After receiving the rejection message, the terminal device may re-determine the first authentication method based on the reason for the rejection.
[0446] It should be understood that the present application does not limit the timing of determining the execution of the authentication method, that is, does not limit the execution timing of S430. For example, S430 can be executed before or after S410.
[0447] Optionally, the method further includes:
[0448] S440: The terminal device sends a request message to the verification network element. Correspondingly, the verification network element receives the request message from the terminal device.
[0449] The request message is used to request access to the network, and the request message includes the first identifier encrypted by the first key (ie, the key determined by the terminal device according to the first key agreement algorithm).
[0450] Exemplarily, the format of the request message may be as shown in (b) of Figure 4. The request message may include a plaintext part and a ciphertext part.
[0451] Among them, the plaintext part can carry the type of the first identifier, and the type of the first identifier can be any one of the above-mentioned first type, second type or virtual identifier type. It can be understood that the type of the first identifier can be determined by the first authentication method; the network identifier (network identifier) (for example, the network identifier is the identifier of the operator contracted by the terminal device); the public key on the network side (or the identifier of the network side public key), that is, the public key of the verification network element used by the terminal device, for example, the public key of the verification network element is the public key of the verification network element used by the terminal device in the ECDH key agreement algorithm, the ECDHE key agreement algorithm, the key agreement algorithm based on PQC and ECDH, and the key agreement algorithm based on PQC and ECDHE; the temporary public key of the terminal device, for example, the temporary public key is the public key of the verification network element used in the ECDH key agreement algorithm, ECDHE The temporary public key (for example, the first public key or the third public key) used by the terminal device in the key agreement algorithm, the key agreement algorithm based on PQC, the key agreement algorithm based on PQC and ECDH, and the key agreement algorithm based on PQC and ECDHE, or the temporary public key is the key preset on the terminal device side in the PSK-based key agreement algorithm; optionally, the plaintext part also includes the blockchain identifier, that is, when the authentication information of the terminal device is stored on the blockchain, and there are multiple blockchains, the blockchain identifier is used to identify the blockchain where the authentication information of the current terminal device is located. The ciphertext part of the request message may include the encrypted first identifier. Optionally, the ciphertext part may also include a session identifier to identify this key negotiation.
[0452] Optionally, the terminal device sends a second digital signature to the verification network element, where the second digital signature is a signature of the terminal device's private key on the second message or a hash value of the second message. The second message may include a message that the terminal device and the verification network element have interacted with.
[0453] Exemplarily, the messages that have been interacted between the terminal device and the verification network element may include the most recent message sent by the terminal device to the verification network element, for example, the interacted messages may include the message carrying the second digital signature; or the interacted messages may include messages after the terminal device sends the request message to the verification network element (including the request message) and before the most recent message sent to the verification network element (may include the most recent message sent to the verification network element), for example, the most recent message sent is a message carrying the second digital signature. Optionally, before the terminal device sends the second digital signature to the verification network element, the terminal device may store the messages that have been interacted with the verification network element.
[0454] The message carrying the first digital signature may be an RRC message or a NAS message.
[0455] Exemplarily, the terminal device may determine the private key of the terminal device corresponding to the first authentication method based on the first authentication method, and use the private key to sign the second message or the hash value of the second message. The terminal device may also determine the signature algorithm used for the signature based on the first authentication method.
[0456] The second digital signature may be carried in the request message or other uplink messages, without limitation.
[0457] S450: The verification network element obtains first authentication information of the terminal device according to the first identifier.
[0458] Specifically, after receiving the request message from the terminal device, the verification network element can decrypt the first identifier based on the first key (that is, the key determined by the verification network element according to the first key agreement algorithm) and obtain the first authentication information of the terminal device based on the first identifier.
[0459] Exemplarily, if the first identifier is an identifier of the first type, the verification network element may obtain the root key of the terminal device based on the user permanent identifier, or obtain the authentication vector of the terminal device. That is, the first authentication information may include the root key or authentication vector of the terminal device.
[0460] If the first identifier is an identifier of the second type, the verification network element obtains a first credential of the terminal device based on the identifier of the second type and the correspondence #1, where the first credential is one of the at least one credential of the terminal device. Exemplarily, the verification network element may determine the first credential from the at least one credential based on the first authentication method. That is, the first authentication information may include the first credential.
[0461] If the first identifier is a block identifier or a transaction identifier, the verification network element obtains the corresponding relationship #1 stored on the blockchain based on the block identifier or the transaction identifier, and selects the first credential from the at least one credential of the terminal device. Exemplarily, the verification network element may determine the first credential from the at least one credential based on the first authentication method. That is, the first authentication information may include the first credential.
[0462] If the first identifier is a virtual identifier, the verification network element determines the second type of identifier based on the virtual identifier and the correspondence between the virtual identifier and the second type of identifier. Furthermore, the verification network element obtains the first credential based on the second type of identifier and the correspondence #1. Exemplarily, the verification network element may determine the first credential from the at least one credential based on the first authentication method. That is, the first authentication information may include the first credential.
[0463] S460: The verification network element authenticates the communication device based on the first authentication information.
[0464] In a possible implementation, the verification network element authenticates the terminal device based on a root key or an authentication vector of the terminal device.
[0465] For example, the verification network element can generate an authentication vector based on the root key; the verification network element sends some parameters in the authentication vector to the terminal device so that the terminal device determines other partial parameters in the authentication vector; the verification network element can compare the other partial parameters in the saved authentication vector with the other partial parameters determined by the terminal device, so as to determine whether the authentication of the terminal device is successful.
[0466] In another possible implementation, the verification network element authenticates the terminal device based on the first credential.
[0467] Exemplarily, the verification network element can verify the first certificate based on the certificate of the first certificate issuer (including the public key of the certificate issuer), that is, verify the signature of the first certificate issuer on the first certificate through the public key of the first certificate issuer; if the verification is successful, the verification network element further verifies the second digital signature based on the public key corresponding to the first certificate, thereby determining whether the authentication of the terminal device is successful.
[0468] Optionally, the verification network element may directly verify the second digital signature based on the public key corresponding to the first credential, thereby determining whether the authentication of the terminal device is successful.
[0469] The following describes the specific method for determining the first key when the first key agreement algorithm is different algorithms in conjunction with Figure 5. It should be understood that this application does not limit the specific names of the following algorithms.
[0470] FIG5(a) shows a method for determining the first key based on the ECDH key agreement algorithm, that is, the first key agreement algorithm is the ECDH key agreement algorithm. As shown in FIG5(a), determining the first key based on the first key agreement algorithm may include the following steps:
[0471] S501a: The terminal device sends a first public key to the verification network element. Correspondingly, the verification network element receives the first public key from the communication device.
[0472] Exemplarily, the terminal device generates a temporary public-private key pair (referred to as a first temporary public-private key pair), and the terminal device sends the public key in the first temporary public-private key pair to the verification network element. That is, the first public key is the public key in the first temporary public-private key pair.
[0473] For example, the terminal device can generate a random number (denoted as random number #1) as the private key in the first public-private key pair (denoted as the first private key), and generate the public key in the first public-private key pair based on the elliptic curve algorithm, that is, the first public key.
[0474] Exemplarily, the first public key may be carried in message #1, and the message #1 may be an RRC message or a NAS message, or other uplink signaling, which is not limited in this application.
[0475] Optionally, the terminal device sends an identifier #1 to the verification network element. Identifier #1 is used to identify this key exchange, or in other words, identifier #1 can be used as a unique identifier for this key exchange process.
[0476] Exemplarily, the identifier #1 and the first public key may be carried in the message #1 at the same time, or may be sent separately, which is not limited in this application.
[0477] S502 a. The verification network element determines the first key based on the first public key and the private key of the verification network element (denoted as private key #1).
[0478] Exemplarily, the private key #1 may be the private key of the verification network element. The public key of the verification network element corresponding to the private key #1 (denoted as public key #1) may be pre-set in the terminal device. The public key #1 is the public key of the verification network element pre-set in the terminal device.
[0479] Optionally, the verification network element sends a certificate of the verification network element to the terminal device. For example, the certificate of the verification network element can refer to the description in S420.
[0480] Optionally, the certificate of the verification network element may also be pre-installed in the terminal device. It should be understood that if the certificate of the verification network element is pre-installed in the terminal device, the step of the verification network element sending the certificate of the verification network element to the terminal device may not be performed.
[0481] Optionally, in S503a, the verification network element sends a first digital signature to the terminal device.
[0482] The first digital signature is a digital signature of the private key of the verification network element on the first message. The first message may include a message that the verification network element has interacted with the terminal device, for example, message #1.
[0483] The certificate of the verification network element and the signature of the first message by the verification network element's private key may be carried in message #2 simultaneously or sent separately, without limitation. Message #2 may be an RRC message, a NAS message, or other downlink signaling, without limitation.
[0484] S504 a. The terminal device determines a first key based on the public key #1 and the first private key.
[0485] Optionally, S505a, the terminal device verifies the first digital signature based on the public key of the verification network element, thereby authenticating the verification network element.
[0486] Based on the above scheme, the computational complexity of the key negotiation process can be reduced by using the ECDH key agreement algorithm, that is, the terminal device uses the public key of the verification network element and the private key in the temporary public-private key pair generated by the terminal device to generate the first key, and the verification network element generates the first key based on the private key of the verification network element and the temporary public key generated by the terminal device, which can reduce the computational complexity.
[0487] FIG5(b) shows a method for determining the first key based on the ECDHE key agreement algorithm, that is, the first key agreement algorithm is the ECDHE key agreement algorithm. As shown in FIG5(b), determining the first key based on the first key agreement algorithm may include the following steps:
[0488] S501b: The terminal device sends the first public key to the verification network element. Correspondingly, the verification network element receives the first public key from the communication device.
[0489] For details of this step, please refer to the description of S501a.
[0490] S502b: The verification network element determines the first key based on the first public key and the second private key.
[0491] Exemplarily, the verification network element generates a temporary public-private key pair (denoted as a second temporary public-private key pair), where the second private key is the private key in the second public-private key pair; the verification network element calculates the first key based on the first public key and the second private key.
[0492] For example, the verification network element can generate a random number (recorded as random number #2) as the private key in the second public-private key pair, that is, the second private key, and generate the public key in the second public-private key pair based on the elliptic curve algorithm (recorded as the second public key).
[0493] S503 b: The verification network element sends the second public key to the terminal device. Correspondingly, the terminal device receives the second public key from the verification network element.
[0494] Exemplarily, the second public key may be carried in message #3, and the message #3 may be a NAS message, an RRC message, or other downlink signaling, without limitation.
[0495] Optionally, the verification network element sends a certificate of the verification network element to the terminal device. The certificate of the verification network element can refer to the description in S502a.
[0496] Optionally, the verification network element sends a digital signature of the verification network element's private key to the terminal device for the first message. The first message may include messages that the verification network element has interacted with the terminal device, such as message #1 and / or message #3.
[0497] S504b: The terminal device determines the first key based on the second public key and the first private key.
[0498] That is, the terminal device calculates the first key based on the public key in the temporary public-private key pair generated by the received verification network element and the private key in the temporary public-private key pair generated by the terminal device.
[0499] Optionally, the terminal device verifies the first digital signature based on the certificate of the verification network element, thereby authenticating the verification network element.
[0500] Based on the above solution, by using the ECDHE key agreement algorithm, the verification network element and terminal device use the temporary public key generated by each other to generate the first key, thereby improving the security of key exchange. Secondly, the key agreement algorithm has low computational complexity and is suitable for communication scenarios with low computational complexity and high security requirements. At the same time, the key agreement algorithm is compatible with 5G communication systems and communication systems before 5G.
[0501] FIG5(c) shows a method for determining the first key using a PQC-based key agreement algorithm, that is, the first key agreement algorithm is a PQC-based key agreement algorithm. As shown in FIG5(c), determining the first key using a PQC-based key agreement algorithm may include the following steps:
[0502] S501c: The terminal device sends a third public key to the verification network element. Correspondingly, the verification network element receives the third public key from the terminal device.
[0503] Exemplarily, the terminal device generates a temporary public-private key pair (referred to as a third temporary public-private key pair) based on a post-quantum algorithm, and the terminal device sends the public key in the third temporary public-private key pair to the verification network element. That is, the third public key is the public key in the third temporary public-private key pair.
[0504] Exemplarily, the third public key may be carried in message #3, and the message #3 may be an RRC message or a NAS message, or other uplink signaling, which is not limited in this application.
[0505] Optionally, the terminal device sends an identifier #1 to the verification network element. Identifier #1 is used to identify this key exchange. Exemplarily, identifier #1 and the first public key can be carried in message #1 at the same time, or sent separately, which is not limited in this application.
[0506] S502c: The verification network element generates a ciphertext and the first key based on the post-quantum algorithm and the third public key.
[0507] Exemplarily, the verification network element uses the third public key as input to the post-quantum algorithm to obtain the ciphertext and the first key. In a specific calculation process, the verification network element randomly selects an m, encrypts m to obtain the ciphertext, and performs a hash operation on the ciphertext and a random number to obtain the first key.
[0508] S503c: The verification network element sends the ciphertext to the terminal device. Correspondingly, the terminal device receives the ciphertext from the verification network element.
[0509] Exemplarily, the first ciphertext may be carried in message #4, and message #4 may be a NAS message, an RRC message, or other downlink signaling, without limitation.
[0510] Optionally, the verification network element sends a certificate of the verification network element to the terminal device. The certificate of the verification network element can be used by the terminal device to verify the authentication network element. Alternatively, the certificate of the verification network element can also be pre-set in the terminal device. The certificate can be described in S3 of (b) of Figure 5.
[0511] Optionally, the verification network element sends a digital signature of a first message using a private key of the verification network element to the terminal device. The first message may include messages that the verification network element has interacted with the terminal device, for example, message #1.
[0512] The certificate of the verification network element and the signature of the first message by the private key of the verification network element may be carried in the message #4 at the same time, or sent separately, without limitation.
[0513] S504c: The terminal device generates a first key based on the ciphertext and a post-quantum algorithm.
[0514] Exemplarily, the terminal device uses the ciphertext and the private key in the third temporary public-private key (referred to as the third private key) as input of the post-quantum algorithm to calculate the first key.
[0515] Optionally, the terminal device verifies the first digital signature based on the certificate of the verification network element, thereby authenticating the verification network element.
[0516] Based on the above solution, by using a PQC-based key agreement algorithm, the verification network element and the terminal device can use PQC to generate the first key, which can improve the security of key exchange. This key agreement algorithm is applicable to communication scenarios with high security requirements.
[0517] FIG5(d) shows a method for determining the first key using a key agreement algorithm based on PQC and ECDH (or a key agreement algorithm combining PQC and ECDH). That is, the first key agreement algorithm is a key agreement algorithm based on PQC and ECDH. As shown in FIG5(d), the key agreement algorithm based on PQC and ECDHE may include the following steps:
[0518] S501d: The terminal device sends the first public key and the third public key to the verification network element. Correspondingly, the verification network element receives the first public key and the third public key from the terminal device.
[0519] Exemplarily, the first public key is the public key in the first temporary public-private key pair; the third public key is the public key in the third temporary public-private key pair.
[0520] Among them, the first temporary public-private key pair is the public key in the temporary public-private key pair generated by the terminal device based on the elliptic curve algorithm, and the specific reference is to the first public key in S501b; the third public key is the public key in the temporary public-private key pair generated by the terminal device based on the post-quantum algorithm, and the specific reference is to the third public key in S501c.
[0521] S502d: The verification network element generates a second key based on the first public key and the private key of the verification network element, and generates a third key based on the third public key.
[0522] The public key of the verification network element (denoted as public key #1) corresponding to the private key of the verification network element can be preset in the terminal device.
[0523] The verification network element uses the third public key as input to the post-quantum algorithm to obtain the ciphertext and the third key. For details, please refer to the description of generating the first key based on the third public key in S502c.
[0524] S503d: The verification network element generates the first key based on the second key and the third key.
[0525] S504d: The verification network element sends the ciphertext to the terminal device. Correspondingly, the terminal device receives the ciphertext from the verification network element.
[0526] For this step, please refer to the description in S503c.
[0527] Optionally, if public key #1 is not pre-set in the terminal device, the verification network element sends the public key #1 to the terminal device.
[0528] Optionally, the verification network element sends a certificate of the verification network element to the terminal device. The certificate of the verification network element can be used by the terminal device to verify the authentication network element. Alternatively, the certificate of the verification network element can also be pre-set in the terminal device. The certificate can be described in S3 of (a) of Figure 5.
[0529] Optionally, the verification network element sends a digital signature of a first message using a private key of the verification network element to the terminal device. The first message may include messages that the verification network element has interacted with the terminal device.
[0530] S505d: The terminal device generates a first key based on the ciphertext and the post-quantum algorithm.
[0531] Exemplarily, the terminal device generates the second key based on the first private key and the public key of the verification network element, namely public key #1. The first private key is the private key in the first temporary public-private key pair.
[0532] The terminal device uses the ciphertext and the third private key as inputs of the post-quantum algorithm to calculate the third key. Further, the terminal device generates the first key based on the second key and the third key.
[0533] Optionally, the terminal device verifies the first digital signature based on the certificate of the verification network element, thereby authenticating the verification network element.
[0534] Based on the above solution, by using a key agreement algorithm based on PQC and ECDH, the verification network element and the communication device can generate the first key based on a key generated by PQC and a key generated by ECDH. This further improves the security of key exchange compared to the PQC-based key agreement algorithm. This key agreement algorithm is suitable for communication scenarios with higher security requirements.
[0535] FIG5(e) shows a method for determining the first key using a key agreement algorithm based on PQC and ECDHE (or a key agreement algorithm combining PQC and ECDHE). That is, the first key agreement algorithm is a key agreement algorithm based on PQC and ECDHE. As shown in FIG5(d), the key agreement algorithm based on PQC and ECDHE may include the following steps:
[0536] S501e: The terminal device sends the first public key and the third public key to the verification network element. Correspondingly, the verification network element receives the first public key and the third public key from the terminal device.
[0537] This step may refer to S501d.
[0538] S502e: The verification network element generates a second key based on the first public key and the second private key, and generates a third key based on the third public key.
[0539] The second private key may be a private key in a temporary public-private key pair generated by the verification network element.
[0540] For the specific process of the verification network element generating the third secret key based on the third public key, reference may be made to the description of generating the first secret key based on the third public key in S502c.
[0541] S503e: The verification network element generates the first key based on the second key and the third key.
[0542] S504e: The verification network element sends the ciphertext and the second public key to the terminal device. Correspondingly, the terminal device receives the ciphertext and the second public key from the verification network element.
[0543] The second public key may be a public key in a temporary public-private key pair generated by the verification network element.
[0544] Optionally, the verification network element sends a certificate of the verification network element to the terminal device. The certificate of the verification network element can be used by the terminal device to verify the authentication network element. Alternatively, the certificate of the verification network element can also be pre-set in the terminal device. The certificate can be described in S3 of (a) of Figure 5.
[0545] Optionally, the verification network element sends a digital signature (an example of a first digital signature) of the first message using the private key of the verification network element to the terminal device. The first message may include messages that the verification network element has interacted with the terminal device.
[0546] S505e: The terminal device generates a first key based on the ciphertext and the post-quantum algorithm.
[0547] Exemplarily, the terminal device generates the second key based on the first private key and the second public key. The first private key is the private key in the first temporary public-private key pair.
[0548] The terminal device uses the ciphertext and the third private key as inputs of the post-quantum algorithm to calculate the third key. Further, the terminal device generates the first key based on the second key and the third key.
[0549] Optionally, the terminal device verifies the first digital signature based on the certificate of the verification network element, thereby authenticating the verification network element.
[0550] Based on the above solution, by using a key agreement algorithm based on PQC and ECDHE, the verification network element and the terminal device can generate the first key based on the key generated by PQC and the key generated by ECDHE. ECDHE has forward security and is suitable for communication scenarios with higher security requirements than key agreement algorithms based on PQC and ECDH.
[0551] Figure 5(f) shows how the first key is determined using a PSK-based key agreement algorithm. That is, the first key agreement algorithm is a PSK-based key agreement algorithm. Prior to key agreement, at least one key is pre-set in the terminal device and the verification network element. The at least one key corresponds to at least one identifier, or in other words, a correspondence between the at least one key and the at least one identifier is pre-set in the terminal device and the verification network element (denoted as correspondence #2).
[0552] For example, when the terminal device and the operator sign a contract, the operator node can write the corresponding relationship #2 into the terminal device by writing the card over the air.
[0553] S501f: The terminal device sends an identifier #1 to the verification network element. Correspondingly, the verification network element receives the identifier #1 from the terminal device.
[0554] The identifier #1 is one of the at least one identifier, and the identifier #1 is used to identify a key (denoted as key k) in the at least one key. It can be understood that the key k is the first key determined by the terminal device.
[0555] S502 f. The verification network element determines the first key based on the identifier #1 and the corresponding relationship #1.
[0556] Exemplarily, the verification network element may query the key corresponding to the identifier #1 from the corresponding relationship #1 based on the identifier #1, that is, the verification network element determines the first key.
[0557] Based on the above scheme, by using a PSK-based key negotiation algorithm, the verification network element and the terminal device can use a preset key to generate the first key. The computational complexity of the key negotiation algorithm is low and can be applied to communication scenarios with low computational complexity of the key negotiation algorithm.
[0558] Figure 6 is a schematic flow chart of a communication method provided in an embodiment of the present application. The method may include the following steps.
[0559] S610: The terminal device (an example of a terminal device) sends a temporary public key to the verification network element. Correspondingly, the verification network element receives the temporary public key from the terminal device.
[0560] The temporary public key is a public key in a temporary public-private key pair generated by the terminal device. The temporary public-private key pair may include a first temporary public-private key pair and / or a third temporary public-private key pair, as described in S501b and S501c, respectively. Accordingly, the temporary public key may include the first public key and / or the third public key, as described above, respectively.
[0561] Optionally, the method further includes: the verification network element determining the first key based on the temporary public key. The verification network element determining the first key based on the temporary public key may include the following examples:
[0562] Example #1, the temporary public key is the first public key, and the verification network element determines the first key based on the ECDH key agreement algorithm.
[0563] In this example, the verification network element determines the first secret key based on the first public key and the private key of the verification network element.
[0564] Optionally, the verification network element sends the public key of the verification network element to the terminal device; the terminal device determines the first key based on the first private key and the public key of the verification network element, and the first private key is the private key in the first temporary public-private key pair.
[0565] The specific process of the verification network element and the terminal device determining the first key can be referred to the description in (a) of Figure 5.
[0566] Example #2: The temporary public key is the first public key, and the verification network element determines the first key based on the ECDHE key agreement algorithm.
[0567] In this example, the verification network element determines the first key based on the first public key and the private key in a second temporary public-private key pair generated by the verification network element.
[0568] Optionally, the verification network element sends a second public key to the terminal device, where the second public key is the public key in the second temporary public-private key pair; the terminal device determines the first key based on the second public key.
[0569] The specific process of the verification network element and the terminal device determining the first key can be referred to the description in (b) of Figure 5.
[0570] Example #3: The temporary public key is the third public key, and the verification network element determines the first key based on the PQC key agreement algorithm.
[0571] In this example, the verification network element inputs the third public key into the post-quantum algorithm to generate ciphertext and the first key.
[0572] Optionally, the verification network element sends the ciphertext to the terminal device; the terminal device obtains the first key by inputting the third private key and the ciphertext into the post-quantum algorithm.
[0573] The specific process of the verification network element and the terminal device determining the first key can be referred to the description in (c) of Figure 5.
[0574] Example #4: The temporary public key includes a first public key and a third public key, and the verification network element determines the first key based on PQC and ECDH key agreement algorithms.
[0575] In this example, the verification network element determines the second key based on the first public key and the private key of the verification network element, and inputs the third public key into the post-quantum algorithm to generate ciphertext and a third key; the verification network element determines the first key based on the second key and the third key.
[0576] Optionally, the verification network element sends the public key of the verification network element and the ciphertext to the terminal device; the terminal device can generate the second key based on the public key of the verification network element and the first private key (refer to the description above), and input the third private key (refer to the description above) and the ciphertext into the post-quantum algorithm to obtain the third key; the terminal device determines the first key based on the second key and the third key.
[0577] The specific process of the verification network element and the terminal device determining the first key can be referred to the description in (d) of Figure 5.
[0578] Example #5: The temporary public key includes a first public key and a third public key, and the verification network element determines the first key based on PQC and ECDHE key agreement algorithms.
[0579] In this example, the verification network element determines the second key based on the first public key and the second private key, and inputs the third public key into the post-quantum algorithm to generate a ciphertext and a third key, wherein the second private key refers to the description above; the verification network element determines the first key based on the second key and the third key.
[0580] Optionally, the verification network element sends a second public key and the ciphertext to the terminal device; the terminal device can generate the second key based on the second public key and the first private key (refer to the description above), and input the third private key (refer to the description above) and the ciphertext into the post-quantum algorithm to obtain a third key; the terminal device determines the first key based on the second key and the third key.
[0581] The specific process of the verification network element and the terminal device determining the first key can be referred to the description in (e) of Figure 5.
[0582] Optionally, the terminal device indicates to the verification network element an identifier corresponding to key k (an example of a first key), where key k is one of at least one key preset in the terminal device, and the at least one key has a corresponding relationship with at least one identifier (denoted as corresponding relationship #2); the verification network element determines the first key based on the PSK key agreement algorithm. Specifically, the corresponding relationship #2 can be preset in the verification network element; the verification network element determines the first key based on the identifier of key k and the corresponding relationship #2. For the specific process, please refer to the description in (f) of Figure 5.
[0583] Exemplarily, the terminal device may determine to send the temporary public key based on second indication information. The second indication information comes from the verification network element; the second indication information indicates a first key agreement algorithm, which is one of at least one key agreement algorithm. The at least one key agreement algorithm is described in S410.
[0584] Specifically, the terminal device and the verification network element may negotiate to determine the first key agreement algorithm. That is, during the negotiation of the first key agreement algorithm, the terminal device receives the second indication information from the verification network element. The specific process of the terminal device and the verification network element negotiating to determine the first key agreement algorithm is described in S410 and will not be repeated here.
[0585] S620: The verification network element authenticates the terminal device based on the first key.
[0586] Specifically, the verification network element receives a request message from the terminal device, the request message being used to request network access, the request message including a first identifier of the terminal device encrypted using the first key. The verification network element decrypts the encrypted first identifier based on the first key and obtains first authentication information based on the first identifier; the verification network element authenticates the terminal device based on the first authentication information.
[0587] The specific implementation of the above steps can refer to the description in S440 to S460 and will not be repeated here.
[0588] The first authentication information is authentication information corresponding to the first authentication method. Before sending the request message to the verification network element, the terminal device and the verification network element negotiate to determine the first authentication method. For the specific process, please refer to the description in S430.
[0589] Exemplarily, the first authentication information includes a first credential of the terminal device, and the verification network element authenticates the terminal device based on the first credential. The specific manner in which the verification network element authenticates the terminal device based on the first credential is described in S460.
[0590] Optionally, the method further includes S630 and S640:
[0591] S630: The verification network element sends a first digital signature to the terminal device. Correspondingly, the terminal device receives the first digital signature from the verification network element.
[0592] The first digital signature is a signature of the private key of the verification network element on the first message, and the first message includes the message exchanged between the verification network element and the terminal device.
[0593] Optionally, if the terminal device does not pre-set the certificate of the verification network element, the verification network element sends the certificate of the verification network element to the terminal device, where the certificate includes the public key of the verification network element, and the public key of the verification network element is used by the terminal device to verify the first digital signature.
[0594] It should be understood that the verification network element may send the verification network element's certificate and / or the first digital signature to the terminal device during the key negotiation process. For example, the verification network element may send the verification network element's certificate and / or the first digital signature to the terminal device at the same time as the verification network element sends the verification network element's public key or the second public key or the ciphertext to the terminal device. Alternatively, the process may be independent of the key negotiation process, which is not limited in this application.
[0595] S640, the terminal device verifies the first digital signature according to the certificate of the verification network element.
[0596] That is, the terminal device verifies the first digital signature according to the certificate of the verification network element, thereby verifying the verification network element. The process of the terminal device verifying the verification network element can refer to the description in S420.
[0597] The communication method provided in the embodiments of the present application is described in detail above in conjunction with Figures 4 to 6. It should be understood that the order of the sequence numbers of the above-mentioned processes does not necessarily indicate the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0598] It should also be understood that in the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.
[0599] It is understandable that in the above-mentioned various method embodiments, the methods and operations implemented by devices (such as the above-mentioned verification network elements and terminal devices, etc.) can also be implemented by components of the devices (such as chips or circuits).
[0600] The above communication method is mainly introduced from the perspective of interaction between various network elements. It is understandable that, in order to implement the above functions, each network element includes a hardware structure and / or software module that performs the corresponding function.
[0601] The communication device provided in the embodiment of the present application is described in detail below with reference to Figures 7 to 9. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for matters not described in detail, reference can be made to the method embodiment above. For the sake of brevity, they will not be repeated here.
[0602] FIG7 shows a schematic diagram of a communication device 700 provided in an embodiment of the present application.
[0603] The device 700 includes an interface unit 710, which can be used to implement corresponding communication functions. The interface unit 710 can also be called a communication interface, a communication unit, or a transceiver unit.
[0604] Optionally, the apparatus 700 may further include a processing unit 720 , which may be configured to perform data processing.
[0605] Optionally, the device 700 also includes a storage unit, which can be used to store instructions and / or data. The processing unit 720 can read the instructions and / or data in the storage unit so that the device can implement the actions of different devices in the aforementioned method embodiments.
[0606] In one possible design, the device 700 may be the verification network element in the aforementioned embodiment, or may be a component (e.g., a chip) of the verification network element. The device 700 may implement steps or processes corresponding to those performed by the verification network element in the above method embodiment. The interface unit 710 may be configured to perform operations related to the transmission and reception of the verification network element in the above method embodiment; and the processing unit 720 may be configured to perform operations related to the processing of the verification network element in the above method embodiment.
[0607] In another possible design, the apparatus 700 may be the terminal device in the aforementioned embodiment, or a component (e.g., a chip) of the terminal device. The apparatus 700 may implement the steps or processes corresponding to those performed by the terminal device in the above method embodiment. The interface unit 710 may be configured to perform the operations related to transmission and reception of the terminal device in the above method embodiment; and the processing unit 720 may be configured to perform the operations related to processing of the terminal device in the above method embodiment.
[0608] FIG8 is a schematic block diagram of a communication device 800 provided in an embodiment of the present application.
[0609] The apparatus 800 includes a processor 810 coupled to a memory 820. Optionally, the apparatus 800 further includes the memory 820. The memory 820 is configured to store computer programs or instructions and / or data. The processor 810 is configured to execute the computer programs or instructions stored in the memory 820, or read data stored in the memory 820, to perform the methods in the above method embodiments.
[0610] Optionally, there are one or more processors 810 .
[0611] Optionally, there are one or more memories 820 .
[0612] Optionally, the memory 820 is integrated with the processor 810 or provided separately.
[0613] Optionally, as shown in Figure 8, the apparatus 800 further includes a communication interface 830, which is used to receive and / or send signals. For example, the processor 810 is used to control the communication interface 830 to receive and / or send signals.
[0614] For example, the communication interface 830 may be a transceiver, a circuit, a bus, a module, or other types of communication interfaces. The communication interface 830 may also be referred to as an interface.
[0615] As a solution, the apparatus 800 is used to implement the operations performed by the verification network element in each of the above method embodiments.
[0616] For example, the processor 810 is configured to execute the computer program or instructions stored in the memory 820 to implement the relevant operations of verifying the network element in the above various method embodiments.
[0617] As another solution, the apparatus 800 is used to implement the operations performed by the terminal device in the above various method embodiments.
[0618] For example, the processor 810 is configured to execute computer programs or instructions stored in the memory 820 to implement relevant operations of the terminal device in the above various method embodiments.
[0619] During implementation, each step of the above method can be completed by an integrated logic circuit of the hardware in the processor 810 or by instructions in the form of software. The method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 820, and the processor 810 reads the information in the memory 820 and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
[0620] It should be understood that in the embodiments of the present application, the processor may be one or more integrated circuits for executing relevant programs to execute the method embodiments of the present application.
[0621] A processor (e.g., processor 810) may include one or more processors and be implemented as a combination of computing devices. The processor may include one or more of the following: a microprocessor, a microcontroller, a digital signal processor (DSP), a digital signal processing device (DSPD), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a programmable logic device (PLD), gating logic, transistor logic, discrete hardware circuits, processing circuits, or other suitable hardware, firmware, and / or a combination of hardware and software to perform the various functions described in this disclosure. The processor may be a general-purpose processor or a special-purpose processor. For example, processor 810 may be a baseband processor or a central processing unit. A baseband processor may be used to process communication protocols and communication data. A central processing unit may be used to enable the device to execute software programs and process data in the software programs. In addition, a portion of the processor may also include non-volatile random access memory. For example, the processor may also store information about the device type.
[0622] In this application, the term "program" is used broadly to refer to software. Non-limiting examples of software include program code, program, subroutine, instruction, instruction set, code, code segment, software module, application, or software application. The program can be executed in a processor and / or computer to cause the device to perform the various functions and / or processes described in this application.
[0623] The memory (e.g., memory 820) can store data required by the processor (e.g., processor 810) when executing software. The memory can be implemented using any suitable storage technology. For example, the memory can be any available storage medium that can be accessed by the processor and / or computer. Non-limiting examples of storage media include random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM), removable media, optical disk storage, magnetic disk storage media, magnetic storage devices, flash memory, registers, state memory, remotely mounted storage, local or remote memory components, or any other medium capable of carrying or storing software, data, or information and accessible by a processor / computer. It should be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0624] The memory (e.g., memory 820) and the processor (e.g., processor 810) may be provided separately or integrated together. The memory may be used to connect to the processor so that the processor can read information from the memory and store and / or write information in the memory. The memory may be integrated into the processor. The memory and the processor may be provided in an integrated circuit (e.g., the integrated circuit may be provided in a UE or other network node).
[0625] 9 is a schematic block diagram of a chip system 900 provided in an embodiment of the present application. The chip system 900 (or also referred to as a processing system) includes a logic circuit 910 and an input / output interface 920.
[0626] The logic circuit 910 may be a processing circuit in the chip system 900. The logic circuit 910 may be coupled to a storage unit and call instructions in the storage unit so that the chip system 900 can implement the methods and functions of the various embodiments of the present application. The input / output interface 920 may be an input / output circuit in the chip system 900, outputting information processed by the chip system 900 or inputting data or signaling information to be processed into the chip system 900 for processing.
[0627] As a solution, the chip system 900 is used to implement the operations performed by the verification network element in the above various method embodiments.
[0628] For example, the logic circuit 910 is used to implement the processing-related operations performed by the verification network element in the above method embodiment; the input / output interface 920 is used to implement the sending and / or receiving-related operations performed by the verification network element in the above method embodiment.
[0629] As another solution, the chip system 900 is used to implement the operations performed by the terminal device in the above various method embodiments.
[0630] For example, the logic circuit 910 is used to implement the processing-related operations performed by the terminal device in the above method embodiment; the input / output interface 920 is used to implement the sending and / or receiving-related operations performed by the terminal device in the above method embodiment.
[0631] An embodiment of the present application also provides a computer-readable storage medium on which computer instructions for implementing the methods executed by a communication device (such as a verification network element, a terminal device) in the above-mentioned method embodiments are stored.
[0632] An embodiment of the present application also provides a computer program product, comprising instructions, which, when executed by a computer, implement the methods performed by a communication device (such as a verification network element or a terminal device) in the above-mentioned method embodiments.
[0633] An embodiment of the present application also provides a communication system, which includes at least one of the verification network element and terminal device in the above embodiments.
[0634] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above, which will not be repeated here.
[0635] In the above-mentioned embodiments, unless otherwise specified or provided for, the terms and / or descriptions of the different embodiments are consistent and can be referenced to each other. The technical features of the different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0636] In the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as an "exemplary" in this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.
[0637] It should be understood that references to "embodiments" throughout this specification mean that a particular feature, structure, or characteristic associated with the embodiment is included in at least one embodiment of the present application. Therefore, various embodiments throughout this specification do not necessarily refer to the same embodiment. Furthermore, these particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0638] It should be understood that in the various embodiments of the present application, the size of the sequence number of each process does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. The names of all nodes and messages in this application are merely names set by this application for the convenience of description. The names in the actual network may be different. It should not be understood that this application limits the names of various nodes and messages. On the contrary, any name with the same or similar function as the node or message used in this application is regarded as the method or equivalent replacement of this application, and is within the scope of protection of this application.
[0639] It should also be understood that in this application, "when", "if" and "if" all mean that the network element will make corresponding processing under certain objective circumstances, which is not a time limit, and does not require the network element to make judgment actions when implementing it, nor does it mean that there are other limitations.
[0640] It should be noted that in the embodiments of the present application, "pre-setting", "pre-configuration", etc. can be achieved by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in a device (for example, a terminal device). This application does not limit its specific implementation method, such as the preset rules, preset constants, etc. in the embodiments of the present application.
[0641] Additionally, the terms "system" and "network" are often used interchangeably herein.
[0642] As used herein, the term "at least one of" or "at least one of" refers to all or any combination of the listed items. For example, "at least one of A, B, and C" can mean: A alone, B alone, C alone, A and B together, B and C together, and A, B, and C together. As used herein, "at least one" means one or more. "A plurality" means two or more.
[0643] It should be understood that in each embodiment of the present application, "B corresponding to A" means that B is associated with A and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B based solely on A, but B can also be determined based on A and / or other information.
[0644] In addition, "of", "corresponding", "relevant", "corresponding" and "associated" are sometimes used interchangeably. It should be noted that when the distinction is not emphasized, the meanings they intend to express are consistent. The terms "include", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized.
[0645] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0646] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0647] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0648] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0649] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0650] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.
[0651] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that, Applied to an authentication network element, the method includes: Receiving first indication information from a communication device, the first indication information indicating at least one key negotiation algorithm; Sending second indication information to the communication device, the second indication information indicating a first key negotiation algorithm, the first key negotiation algorithm being one of the at least one key negotiation algorithm, the first key negotiation algorithm being used to determine a first key, the first key being used to encrypt or decrypt messages transmitted between the communication device and the authentication network element.
2. The method according to claim 1, characterized in that, The first key negotiation algorithm is determined according to first information, the first information including at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, the computational ability of the communication device.
3. The method according to claim 1 or 2, characterized in that, The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on Post-Quantum Cryptography (PQC), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Elliptic Curve Diffie-Hellman (ECDH), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Ephemeral Elliptic Curve Diffie-Hellman (ECDHE), and key negotiation algorithm based on a pre-set key.
4. The method according to claim 3, characterized in that The method further includes: Determining the first key based on the first key negotiation algorithm.
5. The method according to claim 4, characterized in that, The first key negotiation algorithm is the ECDHE key negotiation algorithm, and determining the first key based on the first key negotiation algorithm includes: Receiving a first public key from the communication device, the first public key being the public key in a first ephemeral public-private key pair generated by the communication device; Determining the first key based on the first public key and a second private key, the second private key being the private key in a second ephemeral public-private key pair generated by the authentication network element.
6. The method according to claim 5, wherein The method further includes: Sending a second public key to the communication device, the second public key being the public key in the second ephemeral public-private key pair, the second public key being used by the communication device to determine the first key.
7. The method according to claim 4, characterized in that The first key negotiation algorithm is the key negotiation algorithm based on PQC, and determining the first key based on the first key negotiation algorithm includes: Receiving a third public key from the communication device, the third public key being the public key in a third ephemeral public-private key pair generated by the communication device based on a post-quantum algorithm; Inputting the third public key into the post-quantum algorithm to generate a ciphertext and the first key.
8. The method according to claim 7, characterized in that, The method further includes: Sending the ciphertext to the communication device, the ciphertext being used by the communication device to determine the first key.
9. The method according to claim 4, characterized in that, The first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDH, and determining the first key based on the first key negotiation algorithm includes: Receive a first public key and a third public key from the communication device, where the first public key is the public key in the first temporary public-private key pair generated by the communication device, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; Determine a second key based on the first public key and the private key of the authentication network element; Input the third public key into the post-quantum algorithm to generate a ciphertext and a third key; Determine the first key based on the second key and the third key.
10. The method according to claim 9, characterized in that The method further includes: Send the public key of the authentication network element and the ciphertext to the communication device, where the public key of the authentication network element and the ciphertext are used by the communication device to determine the first key.
11. The method according to claim 4, characterized in that The first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. Determining the first key based on the first key negotiation algorithm includes: Receive a first public key and a third public key from the communication device, where the first public key is the public key in the first temporary public-private key pair generated by the communication device, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm; Determine a second key based on the first public key and a second private key, where the second private key is the private key in the second temporary public-private key pair generated by the authentication network element; Input the third public key into the post-quantum algorithm to generate a ciphertext and a third key; Determine the first key based on the second key and the third key.
12. The method according to claim 11, wherein The method further includes: Send a second public key and the ciphertext to the communication device, where the second public key is the public key in the second temporary public-private key pair, and the second public key and the ciphertext are used by the communication device to determine the first key.
13. The method according to any one of claims 1 to 12, characterized in that, The method further includes: Send a first digital signature to the communication device, where the first digital signature is the signature of the first message by the private key of the authentication network element, and the first message includes the messages exchanged between the authentication network element and the communication device; Send the certificate of the authentication network element to the communication device, where the certificate includes the public key of the authentication network element, and the public key of the authentication network element is used by the communication device to verify the first digital signature.
14. The method according to any one of claims 1 to 13, characterized in that, The method further includes: Receive a request message from the communication device, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, and the first identifier has a corresponding relationship with the authentication information of the communication device; Obtain the first authentication information in the authentication information according to the first identifier; Authenticate the communication device based on the first authentication information.
15. The method according to claim 14, characterized in that, Before receiving the request message from the communication device, the method further includes: Receive third indication information from the communication device, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other; Send fourth indication information to the communication device, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.
16. The method according to claim 14 or 15, characterized in that, The authentication information includes any one of the following information: The credential of the communication device, the cryptographic algorithm; Wherein, the credential of the communication device includes the public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.
17. The method according to claim 15 or 16, characterized in that, The types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier includes at least one of the following: The first type of identifier of the communication device, the second type of identifier of the communication device, the identifier of the block or the identifier of the transaction, the virtual identifier of the communication device; Wherein, the first type of identifier has a first correspondence relationship with the root key of the communication device, the second type of identifier has a second correspondence relationship with at least one credential of the communication device, the identifier of the block or the identifier of the transaction is used to obtain the second correspondence relationship stored on the blockchain, and the virtual identifier has a correspondence relationship with the second type of identifier.
18. The method according to any one of claims 15 to 17, characterized in that, The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the credential of the communication device, the security level of the credential of the communication device, the cryptographic algorithm corresponding to the credential of the communication device.
19. The method according to any one of claims 14 to 18, characterized in that, The first authentication information includes the first credential of the communication device, and authenticating the communication device based on the first authentication information includes: Verifying the first credential based on the credential of the issuer of the first credential; Receiving a second digital signature from the communication device, where the second digital signature is a signature of the second message by the private key of the communication device, and the second message includes the message that the communication device has interacted with the verification network element; Verifying the second digital signature based on the public key corresponding to the first credential.
20. A communication method, characterized in that, Applied to a verification network element, the method includes: Receiving a temporary public key from a communication device, where the temporary public key is the public key in a temporary public-private key pair generated by the communication device; Authenticating the communication device based on a first key, where the first key is determined based on the temporary public key and a second private key, the second private key is the private key of the verification network element or the private key in a temporary public-private key pair generated by the verification network element, or the first key is generated by inputting the temporary public key into a post-quantum algorithm.
21. The method according to claim 20, wherein If the first key is determined based on the temporary public key and the second private key, and the second private key is the private key in a temporary public-private key pair generated by the verification network element, the method further includes: Sending a second public key to the communication device, where the second public key includes the public key in the temporary public-private key pair generated by the verification network element, and the second public key is used for the communication device to determine the first key.
22. The method according to claim 20, wherein The temporary public key is a third public key, where the third public key is the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.
23. The method according to claim 22, characterized in that, The method further includes: Sending a ciphertext to the communication device, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext is used for the communication device to determine the first key.
24. The method according to claim 20, wherein The temporary public key includes a first public key and a third public key. The first public key is the public key in a first temporary public-private key pair generated by the communication device, and the third public key is the public key in a third temporary public-private key pair generated by the communication device based on a post-quantum algorithm. The first key is determined based on the temporary public key and a second private key, and includes: The first key is determined based on a second key and a third key. The second key is determined according to the second private key and the first public key, and the third key is generated by inputting the third public key into the post-quantum algorithm.
25. The method according to claim 24, wherein The method further includes: Sending a ciphertext and a second public key to the communication device. The second public key includes the public key of the authentication network element or the public key in a temporary public-private key pair generated by the authentication network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm. The ciphertext and the second public key are used by the communication device to determine the first key.
26. The method according to any one of claims 20 to 25, characterized in that The temporary public key is sent according to second indication information, and the second indication information indicates a first key negotiation algorithm. The first key negotiation algorithm is one of at least one key negotiation algorithm. Before receiving the temporary public key from the communication device, the method further includes: Receiving first indication information from the communication device, and the first indication information indicates the at least one key negotiation algorithm; Sending the second indication information to the communication device.
27. The method according to claim 26, wherein The first key negotiation algorithm is determined according to first information and the first indication information. The first information includes at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.
28. The method according to claim 26 or 27, characterized in that, The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on Post-Quantum Cryptography (PQC), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Elliptic Curve Diffie-Hellman (ECDH), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Ephemeral Elliptic Curve Diffie-Hellman (ECDHE), and key negotiation algorithm based on a pre-set key.
29. The method according to any one of claims 20 to 28, characterized in that, The method further includes: Sending a first digital signature to the communication device. The first digital signature is the signature of a first message by the private key of the authentication network element. The first message includes the messages interacted between the authentication network element and the communication device; Sending the certificate of the authentication network element to the communication device. The certificate includes the public key of the authentication network element, and the public key of the authentication network element is used by the communication device to verify the first digital signature.
30. The method according to any one of claims 20 to 29, characterized in that, Authenticating the communication device based on the first key includes: Receiving a request message from the communication device. The request message is used to request access to the network, and the request message includes a first identifier encrypted by the communication device using the first key. The first identifier has a corresponding relationship with the authentication information of the communication device; Decrypt the encrypted first identifier based on the first key; Obtain the first authentication information in the authentication information according to the first identifier; Authenticate the communication device based on the first authentication information.
31. The method according to claim 30, wherein Before receiving the request message from the communication device, the method further includes: Receiving third indication information from the communication device, the third indication information indicating at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method being different; Sending fourth indication information to the communication device, the fourth indication information indicating a first authentication method, the first authentication method being one of the at least one authentication methods, and the first authentication method corresponding to the first authentication information.
32. The method according to claim 30 or 31, characterized in that, The authentication information includes any one of the following information: The credential of the communication device, a cryptographic algorithm; Wherein, the credential of the communication device includes the public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.
33. The method according to claim 31 or 32, characterized in that, The types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier includes at least one of the following: The first type of identifier of the communication device, the second type of identifier of the communication device, the identifier of a block or a transaction, the virtual identifier of the communication device; Wherein, the first type of identifier has a first corresponding relationship with the root key of the communication device, the second type of identifier has a second corresponding relationship with at least one credential of the communication device, the identifier of the block or the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.
34. The method according to any one of claims 31 to 33, characterized in that, The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the credential of the communication device, the security level of the credential of the communication device, the cryptographic algorithm corresponding to the credential of the communication device.
35. The method according to any one of claims 30 to 34, characterized in that, The authentication information includes the first credential of the communication device, and authenticating the communication device based on the first authentication information includes: Verifying the first credential based on the credential of the issuer of the first credential; Receiving a second digital signature from the communication device, the second digital signature being the signature of the communication device on a second message, and the second message including the messages interacted between the communication device and the verification network element; Verifying the second digital signature based on the public key corresponding to the first credential.
36. A communication method, characterized in that, Applied to a communication device, the method includes: Sending first indication information to a verification network element, the first indication information indicating at least one key negotiation algorithm; Receiving second indication information from the verification network element, the second indication information indicating a first key negotiation algorithm, the first key negotiation algorithm being one of the at least one key negotiation algorithms, and the first key negotiation algorithm being used to determine a first key, and the first key being used to encrypt or decrypt the messages transmitted between the communication device and the verification network element.
37. The method according to claim 36, wherein The first key negotiation algorithm is determined according to the first information and the first indication information, where the first information includes at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.
38. The method according to claim 36 or 37, characterized in that The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on Post-Quantum Cryptography (PQC), key negotiation algorithm based on PQC and ECDH, key negotiation algorithm based on PQC and ECDHE, and key negotiation algorithm based on a pre-shared key.
39. The method according to claim 22, wherein The method further includes: Determining the first key based on the first key negotiation algorithm.
40. The method according to claim 23, wherein When the first key negotiation algorithm is the ECDHE key negotiation algorithm, determining the first key based on the first key negotiation algorithm includes: Receiving a second public key from the authentication network element, where the second public key is the public key in a second ephemeral public-private key pair generated by the authentication network element; Determining the first key based on the second public key and a first private key, where the first private key is the private key in a first ephemeral public-private key pair generated by the communication device.
41. The method according to claim 22 or 23, characterized in that, Before determining the first key based on the first key negotiation algorithm, the method further includes: Sending a first public key to the authentication network element, where the first public key is the public key in a first ephemeral public-private key pair generated by the communication device, and the first public key is used by the authentication network element to determine the first key.
42. The method according to claim 23, wherein When the first key negotiation algorithm is the key negotiation algorithm based on PQC, determining the first key based on the first key negotiation algorithm includes: Receiving a ciphertext from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm; Inputting the ciphertext and a third private key into the post-quantum algorithm to generate the first key, where the third private key is the private key in a third ephemeral public-private key pair generated by the communication device based on the post-quantum algorithm.
43. The method according to claim 26, wherein, Before determining the first key based on the first key negotiation algorithm, the method further includes: Sending a third public key to the authentication network element, where the third public key is the public key in the third ephemeral public-private key pair, and the third public key is used by the authentication network element to determine the first key.
44. The method according to claim 23, wherein When the first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDH, determining the first key based on the first key negotiation algorithm includes: Receiving a ciphertext and the public key of the authentication network element from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm; Determining a second key based on the public key of the authentication network element and a first private key, where the first private key is the private key in a first ephemeral public-private key pair generated by the communication device; Input the ciphertext and the third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; Determine the first key based on the second key and the third key.
45. The method according to claim 23, wherein The first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. Determining the first key based on the first key negotiation algorithm includes: Receive the ciphertext and the second public key from the authentication network element. The ciphertext is generated by the authentication network element based on the post-quantum algorithm, and the second public key is the public key in the second temporary public-private key pair generated by the authentication network element; Determine a second key based on the second public key and the first private key, where the first private key is the private key in the first temporary public-private key pair generated by the communication device; Input the ciphertext and the third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; Determine the first key based on the second key and the third key.
46. The method according to claim 28 or 29, characterized in that, Before determining the first key based on the first key negotiation algorithm, the method further includes: Send a first public key and a third public key to the authentication network element. The first public key is the public key in the first temporary public-private key pair, and the third public key is the public key in the third temporary public-private key pair. The first public key and the third public key are used by the authentication network element to determine the first key.
47. The method according to any one of claims 20 to 30, characterized in that, The method further includes: Receive a first digital signature from the authentication network element. The first digital signature is the signature of the first message by the private key of the authentication network element, and the first message includes the messages exchanged between the authentication network element and the communication device; Receive the certificate of the authentication network element from the authentication network element. The certificate includes the public key of the authentication network element; Verify the first digital signature based on the public key of the authentication network element.
48. The method according to any one of claims 20 to 31, characterized in that, The method further includes: Send a request message to the authentication network element. The request message is used to request access to the network. The request message includes a first identifier encrypted by the first key. The first identifier has a corresponding relationship with the authentication information of the communication device. The authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.
49. The method according to claim 32, characterized in that, Before sending the request message to the authentication network element, the method further includes: Send third indication information to the authentication network element. The third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other; Receive fourth indication information from the authentication network element. The fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication methods. The first authentication method corresponds to the first authentication information.
50. The method according to claim 32 or 33, characterized in that, The authentication information includes any one of the following information: Credentials of the communication device, cryptographic algorithms; Wherein, the credentials of the communication device include the public key of the communication device, and the cryptographic algorithms include signature algorithms applicable to the communication device.
51. The method according to claim 33 or 34, characterized in that, The types of the first identifiers indicated by each of the at least one authentication method are different, and the first identifier includes at least one of the following: The identifier of the first type of the communication device, the identifier of the second type of the communication device, the identifier of the block or the transaction, the virtual identifier of the communication device; Wherein, the identifier of the first type has a first corresponding relationship with the root key of the communication device, the identifier of the second type has a second corresponding relationship with at least one credential of the communication device, the identifier of the block or the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the identifier of the second type.
52. The method according to any one of claims 33 to 35, characterized in that, The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the credential of the communication device, the security level of the credential of the communication device, the cryptographic algorithm corresponding to the credential of the communication device.
53. The method according to any one of claims 32 to 36, characterized in that, The method further includes: Sending a second digital signature to the verification network element, where the second digital signature is the signature of the second message by the private key of the communication device, the second message includes the messages interacted between the communication device and the verification network element, and the second digital signature is used for the verification network element to authenticate the communication device.
54. A communication method, characterized in that, Applied to a communication device, the method includes: Sending a temporary public key to the verification network element, where the temporary public key is the public key in the temporary public-private key pair generated by the communication device, and the temporary public key is used to determine a first key, and the first key is used for the verification network element to authenticate the communication device; Wherein, the first key is determined based on the temporary public key and a second private key, and the second private key is the private key of the verification network element or the private key in the temporary public-private key pair generated by the verification network element; or, the first key is generated by inputting the temporary public key into a post-quantum algorithm.
55. The method according to claim 54, characterized in that, If the first key is determined based on the temporary public key and the second private key, and the second private key is the private key in the temporary public-private key pair generated by the verification network element, the method further includes: Receiving a second public key from the verification network element, where the second public key is the public key in the temporary public-private key pair generated by the verification network element; Determining the first key based on a first private key and the second public key, and the first public key is the private key in the temporary public-private key pair generated by the communication device.
56. The method according to claim 54, wherein The temporary public key is a third public key, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.
57. The method according to claim 56, characterized in that, The method further includes: Receiving a ciphertext from the verification network element, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm; Inputting the ciphertext and a third private key into the post-quantum algorithm to generate the first key, and the third private key is the private key in the third temporary public-private key pair.
58. The method according to claim 54, wherein The temporary public key includes a first public key and a third public key. The first public key is the public key in the first temporary public-private key pair generated by the communication device. The third public key is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm. The first key is determined based on the temporary public key and a second private key, and includes: The first key is determined based on a second key and a third key. The second key is determined according to the second private key and the first public key. The third key is generated by inputting the third public key into the post-quantum algorithm.
59. The method according to claim 58, wherein The method further includes: Receiving a ciphertext and a second public key from the authentication network element. The second public key includes the public key of the authentication network element or the public key in the temporary public-private key pair generated by the authentication network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm; Generating a second key based on a first private key and the second public key. The first private key is the private key in the first public-private key pair; Inputting the ciphertext and a third private key into the post-quantum algorithm to generate a third key. The third private key is the private key in the third public-private key pair; Determining the first key based on the second key and the third key.
60. The method according to any one of claims 54 to 59, characterized in that, The temporary public key is sent according to second indication information, and the second indication information indicates a first key negotiation algorithm. The first key negotiation algorithm is one of at least one key negotiation algorithm. Before receiving the temporary public key from the communication device, the method further includes: Sending first indication information to the authentication network element. The first indication information indicates the at least one key negotiation algorithm; Receiving the second indication information from the authentication network element.
61. The method according to claim 60, wherein The first key negotiation algorithm is determined according to first information and the first indication information. The first information includes at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.
62. The method according to claim 60 or 61, characterized in that, The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on Post-Quantum Cryptography (PQC), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Elliptic Curve Diffie-Hellman (ECDH), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Ephemeral Elliptic Curve Diffie-Hellman (ECDHE), and key negotiation algorithm based on a pre-shared key.
63. The method according to any one of claims 54 to 62, characterized in that, The method further includes: Receiving a first digital signature from the authentication network element. The first digital signature is the signature of the first message by the private key of the authentication network element. The first message includes the messages interacted between the authentication network element and the communication device; Receiving the certificate of the authentication network element from the authentication network element. The certificate includes the public key of the authentication network element; Verifying the first digital signature based on the public key of the authentication network element.
64. The method according to any one of claims 54 to 63, characterized in that, The method further includes: Send a request message to the verification network element, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the communication device using the first key. The first identifier has a corresponding relationship with the authentication information of the communication device, and the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.
65. The method according to claim 64, wherein Before sending the request message to the verification network element, the method further includes: Send third indication information to the verification network element, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is different; Receive fourth indication information from the verification network element, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication method, and the first authentication method corresponds to the first authentication information.
66. The method according to claim 64 or 65, characterized in that, The authentication information indicates any one of the following information: The credential of the communication device, the cryptographic algorithm; Wherein, the credential of the communication device includes the public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device.
67. The method according to claim 66, wherein The type of the first identifier indicated by each authentication method in the at least one authentication method is different, and the first identifier includes at least one of the following: The first type of identifier of the communication device, the second type of identifier of the communication device, the identifier of the block or the transaction, the virtual identifier of the communication device; Wherein, the first type of identifier has a first corresponding relationship with the root key of the communication device, the second type of identifier has a second corresponding relationship with at least one credential of the communication device, the identifier of the block or the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.
68. The method according to any one of claims 65 to 67, characterized in that, The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the credential of the communication device, the security level of the credential of the communication device, the cryptographic algorithm corresponding to the credential of the communication device.
69. The method according to any one of claims 64 to 68, characterized in that, The method further includes: Send a second digital signature to the verification network element, where the second digital signature is the signature of the private key of the communication device on the second message, and the second message includes the messages interacted between the communication device and the verification network element, and the second digital signature is used for the verification network element to authenticate the communication device.
70. A communication device, characterized in that, The communication device includes a transceiver unit, and the transceiver unit is used for: Receive first indication information from a first device, where the first indication information indicates at least one key negotiation algorithm; Send second indication information to the first device, where the second indication information indicates a first key negotiation algorithm, and the first key negotiation algorithm is one of the at least one key negotiation algorithm, and the first key negotiation algorithm is used to determine a first key, and the first key is used to encrypt or decrypt the messages transmitted between the first device and the communication device.
71. The communication device according to claim 70, wherein The first key negotiation algorithm is determined according to the first information and the first indication information, where the first information includes at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the first device, and the computing power of the first device.
72. The communication device according to claim 70 or 71, characterized in that, The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on Post-Quantum Cryptography (PQC), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Elliptic Curve Diffie-Hellman (ECDH), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Ephemeral Elliptic Curve Diffie-Hellman (ECDHE), and key negotiation algorithm based on a pre-shared key.
73. The communication device according to claim 72, characterized in that, The communication device further includes a processing unit, and the processing unit is configured to: Determine the first key based on the first key negotiation algorithm.
74. The communication device according to claim 73, characterized in that, The first key negotiation algorithm is the ECDHE key negotiation algorithm. The transceiver unit is further configured to receive a first public key from the first device, where the first public key is the public key in the first temporary public-private key pair generated by the first device. Specifically, the processing unit is configured to determine the first key based on the first public key and a second private key, where the second private key is the private key in the second temporary public-private key pair generated by the communication device.
75. The communication device according to claim 74, wherein, The transceiver unit is further configured to: Send a second public key to the first device, where the second public key is the public key in the second temporary public-private key pair, and the second public key is used by the first device to determine the first key.
76. The communication device according to claim 73, characterized in that, The first key negotiation algorithm is the key negotiation algorithm based on PQC. The transceiver unit is further configured to receive a third public key from the first device, where the third public key is the public key in the third temporary public-private key pair generated by the first device based on a post-quantum algorithm. Specifically, the processing unit is configured to input the third public key into the post-quantum algorithm to generate a ciphertext and the first key.
77. The communication device according to claim 76, wherein, The transceiver unit is further configured to: Send the ciphertext to the first device, and the ciphertext is used by the first device to determine the first key.
78. The communication device according to claim 73, characterized in that, The first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDH. The transceiver unit is further configured to receive a first public key and a third public key from the first device, where the first public key is the public key in the first temporary public-private key pair generated by the first device, and the third public key is the public key in the third temporary public-private key pair generated by the first device based on a post-quantum algorithm. Specifically, the processing unit is configured to: Determine a second key based on the first public key and the private key of the communication device; Input the third public key into the post-quantum algorithm to generate a ciphertext and a third key; Determine the first key based on the second key and the third key.
79. The communication device according to claim 78, characterized in that, The transceiver unit is further configured to: Send the public key of the communication device and the ciphertext to the first device, and the public key of the communication device and the ciphertext are used by the first device to determine the first key.
80. The communication device according to claim 73, characterized in that, The first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. The transceiver unit is further configured to receive a first public key and a third public key from the first device, where the first public key is the public key in the first temporary public-private key pair generated by the first device, and the third public key is the public key in the third temporary public-private key pair generated by the first device based on the post-quantum algorithm. The processing unit is specifically configured to: Determine a second key based on the first public key and the second private key, where the second private key is the private key in the second temporary public-private key pair generated by the communication device. Input the third public key into the post-quantum algorithm to generate a ciphertext and a third key. Determine the first key based on the second key and the third key.
81. The communication device according to claim 80, wherein The transceiver unit is further configured to: Send the second public key and the ciphertext to the first device, where the second public key is the public key in the second temporary public-private key pair, and the second public key and the ciphertext are used by the first device to determine the first key.
82. The communication device according to any one of claims 70 to 81, characterized in that, The transceiver unit is further configured to: Send a first digital signature to the first device, where the first digital signature is the signature of the first message by the private key of the communication device, and the first message includes the messages exchanged between the communication device and the first device. Send the certificate of the communication device to the first device, where the certificate includes the public key of the communication device, and the public key of the communication device is used by the first device to verify the first digital signature.
83. The communication device according to any one of claims 70 to 82, characterized in that, The communication device further includes a processing unit. The transceiver unit is further configured to receive a request message from the first device, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, and the first identifier has a corresponding relationship with the authentication information of the first device. The processing unit is configured to: Obtain the first authentication information in the authentication information according to the first identifier. Authenticate the first device based on the first authentication information.
84. The communication device according to claim 83, wherein The transceiver unit is further configured to: Receive third indication information from the first device, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other. Send fourth indication information to the first device, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication methods, and the first authentication method corresponds to the first authentication information.
85. The communication device according to claim 83 or 84, characterized in that, The authentication information includes any one of the following information: The certificate of the first device, cryptographic algorithms. Wherein, the certificate of the first device includes the public key of the first device, and the cryptographic algorithms include signature algorithms applicable to the first device.
86. The communication device according to claim 84 or 85, characterized in that, The type of the first identifier indicated by each authentication method in the at least one authentication method is different, and the first identifier includes at least one of the following: The first type of identifier of the first device, the second type of identifier of the first device, the identifier of a block or a transaction, the virtual identifier of the first device. Among them, the identifier of the first type has a first corresponding relationship with the root key of the first device, the identifier of the second type has a second corresponding relationship with at least one credential of the first device, the identifier of the block or the identifier of the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the identifier of the second type.
87. The communication device according to any one of claims 84 to 86, characterized in that, The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the credential of the first device, the security level of the credential of the first device, the cryptographic algorithm corresponding to the credential of the first device.
88. The communication device according to any one of claims 83 to 87, characterized in that, The first authentication information includes the first credential of the first device. The processing unit is specifically configured to verify the first credential based on the credential of the issuer of the first credential. The transceiver unit is further configured to receive a second digital signature from the first device, where the second digital signature is a signature of the second message by the private key of the first device, and the second message includes the messages interacted between the first device and the communication device. The processing unit is further configured to verify the second digital signature based on the public key corresponding to the first credential.
89. A communication device, characterized in that, The communication device includes a transceiver unit and a processing unit. The transceiver unit is configured to receive a temporary public key from the first device, where the temporary public key is the public key in the temporary public-private key pair generated by the first device. The processing unit is configured to authenticate the first device based on the first key, where the first key is determined based on the temporary public key and the second private key, the second private key is the private key of the communication device or the private key in the temporary public-private key pair generated by the communication device, or the first key is generated by inputting the temporary public key into a post-quantum algorithm.
90. The communication device according to claim 89, characterized in that, If the first key is determined based on the temporary public key and the second private key, and the second private key is the private key in the temporary public-private key pair generated by the communication device, the transceiver unit is further configured to: Send a second public key to the first device, where the second public key includes the public key in the temporary public-private key pair generated by the communication device, and the second public key is used for the first device to determine the first key.
91. The communication device according to claim 89, characterized in that, The temporary public key is a third public key, the third public key is the public key in the third temporary public-private key pair generated by the first device based on the post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.
92. The communication device according to claim 91, characterized in that, The transceiver unit is further configured to: Send a ciphertext to the first device, where the ciphertext is generated by inputting the third public key into the post-quantum algorithm, and the ciphertext is used for the first device to determine the first key.
93. The communication device according to claim 89, characterized in that, The temporary public key includes a first public key and a third public key, the first public key is the public key in the first temporary public-private key pair generated by the first device, the third public key is the public key in the third temporary public-private key pair generated by the first device based on the post-quantum algorithm, and the first key is determined based on the temporary public key and the second private key, including: The first key is determined based on a second key and a third key. The second key is determined according to the second private key and the first public key. The third key is generated by inputting the third public key into the post-quantum algorithm.
94. The communication device according to claim 93, characterized in that, The transceiver unit is further configured to: Send a ciphertext and a second public key to the first device. The second public key includes the public key of the communication device or the public key in the temporary public-private key pair generated by the communication device. The ciphertext is generated by inputting the third public key into the post-quantum algorithm. The ciphertext and the second public key are used for the first device to determine the first key.
95. The communication device according to any one of claims 89 to 94, characterized in that The temporary public key is sent according to second indication information. The second indication information indicates a first key negotiation algorithm. The first key negotiation algorithm is one of at least one key negotiation algorithm. The transceiver unit is further configured to: Receive first indication information from the first device. The first indication information indicates the at least one key negotiation algorithm; Send the second indication information to the first device.
96. The communication device according to claim 95, wherein The first key negotiation algorithm is determined according to first information and the first indication information. The first information includes at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the first device, and the computing power of the first device.
97. The communication device according to claim 95 or 96, characterized in that, The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on Post-Quantum Cryptography (PQC), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Elliptic Curve Diffie-Hellman (ECDH), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Ephemeral Elliptic Curve Diffie-Hellman (ECDHE), and key negotiation algorithm based on a pre-set key.
98. The communication device according to any one of claims 89 to 97, characterized in that, The transceiver unit is further configured to: Send a first digital signature to the first device. The first digital signature is the signature of the first message by the private key of the communication device. The first message includes the messages exchanged between the communication device and the first device; Send the certificate of the communication device to the first device. The certificate includes the public key of the communication device. The public key of the communication device is used by the first device to verify the first digital signature.
99. The communication device according to any one of claims 89 to 98, wherein The transceiver unit is further configured to receive a request message from the first device. The request message is used to request access to the network. The request message includes a first identifier encrypted by the first device using the first key. The first identifier has a corresponding relationship with the authentication information of the first device; The processing unit is specifically configured to: Decrypt the encrypted first identifier based on the first key; Obtain the first authentication information in the authentication information according to the first identifier; Authenticate the first device based on the first authentication information.
100. The communication device according to claim 99, wherein, The transceiver unit is further configured to: Receive third indication information from the first device, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is different; Send fourth indication information to the first device, where the fourth indication information indicates a first authentication method, the first authentication method is one of the at least one authentication method, and the first authentication method corresponds to the first authentication information.
101. The communication device according to claim 99 or 100, characterized in that, The authentication information includes any one of the following information: The credential of the first device, a cryptographic algorithm; Wherein, the credential of the first device includes the public key of the first device, and the cryptographic algorithm includes a signature algorithm applicable to the first device.
102. The communication device according to claim 100 or 101, characterized in that, The types of the first identifiers indicated by each authentication method in the at least one authentication method are different, and the first identifier includes at least one of the following: The first type of identifier of the first device, the second type of identifier of the first device, the identifier of a block or a transaction, the virtual identifier of the first device; Wherein, the first type of identifier has a first corresponding relationship with the root key of the first device, the second type of identifier has a second corresponding relationship with at least one credential of the first device, the identifier of the block or the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier.
103. The communication device according to any one of claims 100 to 102, characterized in that, The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the credential of the first device, the security level of the credential of the first device, the cryptographic algorithm corresponding to the credential of the first device.
104. The communication device according to any one of claims 99 to 103, characterized in that, The authentication information includes the first credential of the first device, The processing unit is specifically configured to verify the first credential based on the credential of the issuer of the first credential; The transceiver unit is further configured to receive a second digital signature from the first device, where the second digital signature is a signature of the first device on a second message, and the second message includes the messages interacted between the first device and the communication device; The processing unit is further configured to verify the second digital signature based on the public key corresponding to the first credential.
105. A communication device, characterized in that, The communication device includes a transceiver unit, and the transceiver unit is configured to: Send first indication information to a verification network element, where the first indication information indicates at least one key negotiation algorithm; Receive second indication information from the verification network element, where the second indication information indicates a first key negotiation algorithm, the first key negotiation algorithm is one of the at least one key negotiation algorithm, and the first key negotiation algorithm is used to determine a first key, and the first key is used to encrypt or decrypt the messages transmitted between the communication device and the verification network element.
106. The communication device according to claim 105, characterized in that, The first key negotiation algorithm is determined according to the first information and the first indication information, and the first information includes at least one of the following information: The security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, the computing power of the communication device.
107. The communication device according to claim 105 or 106, characterized in that, The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on Post-Quantum Cryptography (PQC), key negotiation algorithm based on PQC and ECDH, key negotiation algorithm based on PQC and ECDHE, and key negotiation algorithm based on a pre-shared key.
108. The communication device according to claim 107, wherein, The communication device further includes a processing unit, and the processing unit is configured to: Determine the first key based on the first key negotiation algorithm.
109. The communication device according to claim 108, characterized in that, The first key negotiation algorithm is the ECDHE key negotiation algorithm. The transceiver unit is further configured to receive a second public key from the authentication network element, where the second public key is the public key in a second ephemeral public-private key pair generated by the authentication network element. Specifically, the processing unit is configured to: Determine the first key based on the second public key and a first private key, where the first private key is the private key in a first ephemeral public-private key pair generated by the communication device. The communication device according to claim 107 or 108, characterized in that, The transceiver unit is further configured to: Send a first public key to the authentication network element, where the first public key is the public key in a first ephemeral public-private key pair generated by the communication device, and the first public key is used by the authentication network element to determine the first key.
111. The communication device according to claim 108, characterized in that, The first key negotiation algorithm is the key negotiation algorithm based on PQC. The transceiver unit is further configured to receive a ciphertext from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm. Specifically, the processing unit is configured to input the ciphertext and a third private key into the post-quantum algorithm to generate the first key, where the third private key is the private key in a third ephemeral public-private key pair generated by the communication device based on the post-quantum algorithm.
112. The communication device according to claim 111, characterized in that, The transceiver unit is further configured to: Send a third public key to the authentication network element, where the third public key is the public key in the third ephemeral public-private key pair, and the third public key is used by the authentication network element to determine the first key.
113. The communication device according to claim 108, characterized in that, The first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDH. The transceiver unit is further configured to receive a ciphertext and the public key of the authentication network element from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm. Specifically, the processing unit is configured to: Determine a second key based on the public key of the authentication network element and a first private key, where the first private key is the private key in a first ephemeral public-private key pair generated by the communication device. Input the ciphertext and a third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in a third ephemeral public-private key pair generated by the communication device based on the post-quantum algorithm. Determine the first key based on the second key and the third key.
114. The communication device according to claim 108, wherein The first key negotiation algorithm is the key negotiation algorithm based on PQC and ECDHE. The transceiver unit is further configured to receive a ciphertext and a second public key from the authentication network element, where the ciphertext is generated by the authentication network element based on a post-quantum algorithm, and the second public key is the public key in the second temporary public-private key pair generated by the authentication network element; Specifically, the processing unit is configured to: Determine a second key based on the second public key and a first private key, where the first private key is the private key in the first temporary public-private key pair generated by the communication device; Input the ciphertext and a third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm; Determine the first key based on the second key and the third key.
115. The communication device according to claim 113 or 114, characterized in that, The transceiver unit is further configured to: Send a first public key and a third public key to the authentication network element, where the first public key is the public key in the first temporary public-private key pair, and the third public key is the public key in the third temporary public-private key pair, and the first public key and the third public key are used by the authentication network element to determine the first key.
116. The communication device according to any one of claims 105 to 115, characterized in that The transceiver unit is further configured to receive a first digital signature from the authentication network element, where the first digital signature is a signature of a first message by the private key of the authentication network element, and the first message includes messages exchanged between the authentication network element and the communication device; The transceiver unit is further configured to receive a certificate of the authentication network element from the authentication network element, where the certificate includes the public key of the authentication network element; The processing unit is further configured to verify the first digital signature based on the public key of the authentication network element.
117. The communication device according to any one of claims 105 to 116, characterized in that, The transceiver unit is further configured to: Send a request message to the authentication network element, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the first key, and the first identifier has a corresponding relationship with the authentication information of the communication device, and the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.
118. The communication device according to claim 117, characterized in that, The transceiver unit is further configured to: Send third indication information to the authentication network element, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is independent of each other; Receive fourth indication information from the authentication network element, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication method, and the first authentication method corresponds to the first authentication information.
119. The communication device according to claim 117 or 118, characterized in that, The authentication information includes any one of the following information: The credential of the communication device, a cryptographic algorithm; Wherein, the credential of the communication device includes the public key of the communication device, and the cryptographic algorithm includes a signature algorithm applicable to the communication device. The communication device according to claim 118 or 119, characterized in that, The type of the first identifier indicated by each authentication method in the at least one authentication method is different, and the first identifier includes at least one of the following: A first type of identifier of the communication device, a second type of identifier of the communication device, an identifier of a block or a transaction, a virtual identifier of the communication device; Among them, the identifier of the first type has a first corresponding relationship with the root key of the communication device, the identifier of the second type has a second corresponding relationship with at least one credential of the communication device, the identifier of the block or the identifier of the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the identifier of the second type.
121. The communication device according to any one of claims 118 to 120, characterized in that, The first authentication method is determined according to the second information and the third indication information, and the second information includes at least one of the following information: The issuer of the credential of the communication device, the security level of the credential of the communication device, the cryptographic algorithm corresponding to the credential of the communication device.
122. The communication device according to any one of claims 117 to 121, characterized in that, The transceiver unit is further configured to: Send a second digital signature to the verification network element, where the second digital signature is a signature of the second message by the private key of the communication device, and the second message includes the messages interacted between the communication device and the verification network element, and the second digital signature is used for the verification network element to authenticate the communication device.
123. A communication device, characterized in that, The communication device includes a transceiver unit, and the transceiver unit is configured to: Send a temporary public key to the verification network element, where the temporary public key is the public key in the temporary public-private key pair generated by the communication device, and the temporary public key is used to determine a first key, and the first key is used for the verification network element to authenticate the communication device; Among them, the first key is determined based on the temporary public key and the second private key, and the second private key is the private key of the verification network element or the private key in the temporary public-private key pair generated by the verification network element; or, the first key is generated by inputting the temporary public key into a post-quantum algorithm.
124. The communication device according to claim 123, wherein The communication device further includes a processing unit. If the first key is determined based on the temporary public key and the second private key, and the second private key is the private key in the temporary public-private key pair generated by the verification network element, The transceiver unit is further configured to receive a second public key from the verification network element, where the second public key is the public key in the temporary public-private key pair generated by the verification network element; The processing unit is configured to determine the first key based on the first private key and the second public key, where the first public key is the private key in the temporary public-private key pair generated by the communication device.
125. The communication device according to claim 123, characterized in that, The temporary public key is a third public key, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on the post-quantum algorithm, and the first key is generated by inputting the third public key into the post-quantum algorithm.
126. The communication device according to claim 125, wherein The communication device further includes a processing unit, The transceiver unit is further configured to receive a ciphertext from the verification network element, and the ciphertext is generated by inputting the third public key into the post-quantum algorithm; The processing unit is configured to input the ciphertext and the third private key into the post-quantum algorithm to generate the first key, where the third private key is the private key in the third temporary public-private key pair. The communication device according to claim 123, characterized in that, The temporary public key includes a first public key and a third public key. The first public key is the public key in the first temporary public-private key pair generated by the communication device, and the third public key is the public key in the third temporary public-private key pair generated by the communication device based on a post-quantum algorithm. The first key is determined based on the temporary public key and a second private key, and includes: The first key is determined based on a second key and a third key. The second key is determined according to the second private key and the first public key, and the third key is generated by inputting the third public key into the post-quantum algorithm.
128. The communication device according to claim 127, wherein, The communication device further includes a processing unit. The communication device further includes a processing unit, which receives a ciphertext and a second public key from the verification network element. The second public key includes the public key of the verification network element or the public key in the temporary public-private key pair generated by the verification network element. The ciphertext is generated by inputting the third public key into the post-quantum algorithm. The processing unit is configured to: generate a second key based on a first private key and the second public key, where the first private key is the private key in the first public-private key pair; input the ciphertext and a third private key into the post-quantum algorithm to generate a third key, where the third private key is the private key in the third public-private key pair; determine the first key based on the second key and the third key.
129. The communication device according to any one of claims 123 to 128, characterized in that, The temporary public key is sent according to second indication information, and the second indication information indicates a first key negotiation algorithm, where the first key negotiation algorithm is one of at least one key negotiation algorithm. The transceiver unit is further configured to: send first indication information to the verification network element, where the first indication information indicates the at least one key negotiation algorithm; receive the second indication information from the verification network element.
130. The communication device according to claim 129, characterized in that, The first key negotiation algorithm is determined according to first information and the first indication information. The first information includes at least one of the following information: the security level corresponding to the key negotiation algorithm, the computational complexity of the key negotiation algorithm, the network mode, the type of the communication device, and the computing power of the communication device.
131. The communication device according to claim 129 or 130, characterized in that, The at least one key negotiation algorithm includes at least one of the following: Elliptic Curve Diffie-Hellman (ECDH) key negotiation algorithm, Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) key negotiation algorithm, key negotiation algorithm based on Post-Quantum Cryptography (PQC), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Elliptic Curve Diffie-Hellman (ECDH), key negotiation algorithm based on Post-Quantum Cryptography (PQC) and Ephemeral Elliptic Curve Diffie-Hellman (ECDHE), and key negotiation algorithm based on a pre-shared key.
132. The communication device according to any one of claims 123 to 131, characterized in that, The communication device further includes a processing unit. The transceiver unit is further configured to receive a first digital signature from the verification network element. The first digital signature is the signature of the first message by the private key of the verification network element, and the first message includes the messages exchanged between the verification network element and the communication device. The transceiver unit is further configured to receive the certificate of the verification network element from the verification network element, and the certificate includes the public key of the verification network element. The processing unit is configured to verify the first digital signature based on the public key of the verification network element. The communication device according to any one of claims 123 to 132, characterized in that The transceiver unit is further configured to: Send a request message to the verification network element, where the request message is used to request access to the network, and the request message includes a first identifier encrypted by the communication device using the first key. The first identifier has a corresponding relationship with the authentication information of the communication device, and the authentication information includes first authentication information, and the first authentication information is used to authenticate the communication device.
134. The communication device according to claim 133, wherein, The transceiver unit is further configured to: Send third indication information to the verification network element, where the third indication information indicates at least one authentication method, and the authentication information indicated by each authentication method in the at least one authentication method is different; Receive fourth indication information from the verification network element, where the fourth indication information indicates a first authentication method, and the first authentication method is one of the at least one authentication method, and the first authentication method corresponds to the first authentication information.
135. The communication device according to claim 133 or 134, characterized in that, The authentication information indicates any one of the following information: The certificate of the communication device, cryptographic algorithms; Wherein, the certificate of the communication device includes the public key of the communication device, and the cryptographic algorithms include signature algorithms applicable to the communication device.
136. The communication device according to claim 135, characterized in that, The type of the first identifier indicated by each authentication method in the at least one authentication method is different, and the first identifier includes at least one of the following: The first type of identifier of the communication device, the second type of identifier of the communication device, the identifier of a block or a transaction, the virtual identifier of the communication device; Wherein, the first type of identifier has a first corresponding relationship with the root key of the communication device, the second type of identifier has a second corresponding relationship with at least one certificate of the communication device, the identifier of the block or the transaction is used to obtain the second corresponding relationship stored on the blockchain, and the virtual identifier has a corresponding relationship with the second type of identifier. The communication device according to any one of claims 134 to 136, characterized in that, The first authentication method is determined according to second information and the third indication information, and the second information includes at least one of the following information: The issuer of the certificate of the communication device, the security level of the certificate of the communication device, the cryptographic algorithm corresponding to the certificate of the communication device. The communication device according to any one of claims 133 to 137, characterized in that The transceiver unit is further configured to: Send a second digital signature to the verification network element, where the second digital signature is the signature of the second message by the private key of the communication device, and the second message includes the messages interacted between the communication device and the verification network element, and the second digital signature is used for the verification network element to authenticate the communication device.
139. A communication device, characterized in that, The device is configured to execute the method according to any one of claims 1 to 69.
140. A communication device, characterized in that, Comprising: A processor, where the processor is configured to cause the device to execute the method according to any one of claims 1 to 69 by executing a computer program stored in a memory and / or by a logic circuit.
141. The device according to claim 140, characterized in that, The device further includes the memory.
142. A communication device, characterized in that, Comprising: A processor and a communication interface; Among them, the communication interface is used to receive code instructions and transmit them to the processor, and the processor is used to cause the device to execute the method described in any one of claims 1 to 69 by executing the computer program stored in the memory and / or through logic circuits.
143. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a computer program or instruction, which, when running on a computer, causes the computer to execute the method described in any one of claims 1 to 69.
144. A computer program product, characterized in that, The computer program product includes a computer program or instruction, which, when running on a computer, causes the computer to execute the method described in any one of claims 1 to 69.
145. A communication system, characterized in that, It includes an authentication entity and a first terminal device. The authentication entity is used to execute the method described in any one of claims 1 to 35, and the first terminal device is used to execute the method described in any one of claims 36 to 69.
Citation Information
Patent Citations
Communication method and communication device
CN120358491A
Efficient methods for authenticated communication
CN106664206A
Negotiation method and device for key derivation algorithm
CN109560919A
Secure communication method and device
CN112753203A
Security negotiation method, terminal device and network device
CN113423104A