Wireless communication method and apparatus, and device and storage medium
By optimizing the information exchange process between the terminal and the core network, using challenge information and keys to generate authentication information and integrity verification information, the problem of low efficiency of terminal access network is solved and faster network access is achieved.
Patent Information
- Application Number
- PCT/CN2025/076192
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-07
- Filing Date
- 2025-02-07
- Publication Date
- 2025-08-14
AI Technical Summary
There are many interaction steps between the terminal and the core network, resulting in less efficiency in the terminal accessing the network.
By reducing the interaction steps between the terminal and the core network, a new wireless communication method is adopted, including information exchange between the terminal device and the communication node, and the challenge information and keys are used to generate authentication information and integrity verification information to achieve rapid authentication and data transmission.
The efficiency of terminal access to the network is improved, interactive steps are reduced, and network access speed is improved.
Smart Images

Figure CN2025076192_14082025_PF_FP_ABST
Abstract
Description
Wireless communication method, device, equipment and storage medium
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on February 7, 2024, with application number 202410175333.1 and invention name “Wireless Communication Method, Apparatus, Equipment and Storage Medium”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application belongs to the field of communication technology, and specifically relates to a wireless communication method, apparatus, device and storage medium. Background Art
[0003] Currently, from the Non-Access-Stratum (NAS) layer, the terminal access network process includes: 1. A two-way authentication process between the terminal and the core network; 2. A Security Mode Control (SMC) process at the NAS layer.
[0004] Figure 1 is a schematic diagram of the terminal access network process. As shown in Figure 1, the terminal and the Unified Data Management (UDM) have a shared key, namely key 1. The two-way authentication NAS process between the terminal and the core network includes: S1, the terminal sends a NAS message (NAS 1) to the Access and Mobility Management Function (AMF) 1. The AMF receives an authentication message (MSG) 1 from the UDM, which includes the terminal identifier and the algorithm information supported by the terminal. S2. The AMF obtains authentication data from the UDM, including the challenge information (RAND), the second authentication information (AUTN), and the third authentication information (XRES). S3. The AMF sends a NAS message (MSG) 2 to the terminal, which includes the challenge information (RAND) and the second authentication information (AUTN). S4. The terminal verifies the second authentication information (AUTN) to authenticate the network side. If the authentication is successful, the terminal generates the first authentication information (RES) based on the key 1 and the challenge information (RAND). S5. The terminal sends a NAS message (MSG) 3 to the AMF, which includes the first authentication information (RES). S6. The AMF verifies the first authentication information (RES) based on the third authentication information (XRES) to authenticate the terminal, where the third authentication information (XRES) is also generated based on the key 1 and the challenge information (RAND).
[0005] The NAS process (SMC process) for enabling NAS security between the terminal and the core network includes: S7. After the AMF successfully authenticates the terminal, the AMF sends a NAS message (msg) 4 to the terminal, and the msg4 includes: the algorithm information of the encryption algorithm and the algorithm information of the integrity protection algorithm selected by the AMF; S8. The terminal verifies msg4. If the verification is successful, the terminal enables the confidentiality and integrity protection of the NAS message based on the above-selected encryption algorithm and integrity protection algorithm; S9. The terminal sends a NAS message (msg) 5 to the AMF, and the msg5 includes: ciphertext and message authentication code (Message Authentication Code, MAC); S10. The AMF decrypts and performs integrity protection verification on msg5 based on the above-selected encryption algorithm and integrity protection algorithm.
[0006] The above msg1-msg5 are all NAS messages. It can be seen that currently, the terminal and the core network need to interact for at least 5 steps before the terminal can access the network and transmit information. However, the large number of interaction steps leads to low efficiency of terminal access to the network. Summary of the Invention
[0007] The embodiments of the present application provide a wireless communication method, apparatus, device, and storage medium, which can solve the problem of low efficiency of terminal access to the network.
[0008] In a first aspect, a wireless communication method is provided, which is performed by a first terminal device. The method includes: the first terminal device receiving first information; wherein the first information includes: first challenge information;
[0009] The first terminal device sends the first authentication information and the second information to the first communication node;
[0010] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0011] The first authentication information is generated based on the first challenge information and the first key;
[0012] The third information is generated by encrypting the fifth information based on the second key;
[0013] The first message integrity check information is generated based on the third key, the third information or the fifth information, and at least one of the following:
[0014] First challenge information;
[0015] First authentication information;
[0016] The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following:
[0017] First challenge information;
[0018] First authentication information;
[0019] The sixth information is the encrypted information of the fourth information.
[0020] In a second aspect, a wireless communication method is provided, which is performed by a first communication node. The method includes: the first communication node sending first information by any one of the following:
[0021] Sending first information to the first terminal device;
[0022] forwarding or broadcasting the first information through the second communication node;
[0023] After the first communication node sends the first information, the method further includes:
[0024] The first communication node receives the first authentication information and the second information sent by the first terminal device;
[0025] The first information includes: first challenge information;
[0026] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0027] The first communication node performs a first operation and a second operation;
[0028] The first operation includes verifying the first authentication information based on the third authentication information;
[0029] The second operation includes at least one of the following:
[0030] decrypting the third information based on the second key;
[0031] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information;
[0032] verifying the second message integrity verification information based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information;
[0033] The fifth information is generated by decrypting the third information based on the second key;
[0034] The sixth information is the encrypted information of the fourth information;
[0035] The third authentication information is generated based on the first key and the first challenge information, and the first key is known to the first terminal device.
[0036] In a third aspect, a wireless communication method is provided, which is performed by a first terminal device. The method includes: the first terminal device receiving first information; wherein the first information includes: first challenge information;
[0037] The first terminal device sends second information to the first communication node;
[0038] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0039] The third information is generated by encrypting the fifth information based on the second key;
[0040] The first message integrity check information is generated based on the third key, the third information or the fifth information, and the first challenge information;
[0041] The second message integrity verification information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0042] The sixth information is the encrypted information of the fourth information.
[0043] According to a fourth aspect, a wireless communication method is provided, which is performed by a first communication node. The method includes: the first communication node sending first information by any one of the following:
[0044] Sending first information to the first terminal device;
[0045] forwarding or broadcasting the first information through the second communication node;
[0046] After the first communication node sends the first information, the method further includes:
[0047] The first communication node receives second information sent by the first terminal device;
[0048] The first information includes: first challenge information;
[0049] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0050] The first communication node performs a target operation;
[0051] The target operation includes at least one of the following:
[0052] decrypting the third information based on the second key;
[0053] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and the first challenge information;
[0054] verifying the second message integrity verification information based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0055] The fifth information is generated by decrypting the third information based on the second key;
[0056] The sixth information is the encrypted information of the fourth information.
[0057] In a fifth aspect, a wireless communication device is provided, including: a communication module, configured to:
[0058] Receive first information; wherein the first information includes: first challenge information;
[0059] Sending first authentication information and second information to the first communication node;
[0060] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0061] The first authentication information is generated based on the first challenge information and the first key;
[0062] The third information is generated by encrypting the fifth information based on the second key;
[0063] The first message integrity check information is generated based on the third key, the third information or the fifth information, and at least one of the following:
[0064] First challenge information;
[0065] First authentication information;
[0066] The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following:
[0067] First challenge information;
[0068] First authentication information;
[0069] The sixth information is the encrypted information of the fourth information.
[0070] In a sixth aspect, a wireless communication device is provided, comprising: a communication module and a processing module;
[0071] Communication modules are used for:
[0072] Send the first message by any of the following:
[0073] Sending first information to the first terminal device;
[0074] forwarding or broadcasting the first information through the second communication node;
[0075] After sending the first information, the communication module is further configured to:
[0076] Receiving first authentication information and second information sent by the first terminal device;
[0077] The first information includes: first challenge information;
[0078] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0079] The processing module is used to:
[0080] performing a first operation and a second operation;
[0081] The first operation includes verifying the first authentication information based on the third authentication information;
[0082] The second operation includes at least one of the following:
[0083] decrypting the third information based on the second key;
[0084] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information;
[0085] verifying the second message integrity verification information based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information;
[0086] The fifth information is generated by decrypting the third information based on the second key;
[0087] The sixth information is the encrypted information of the fourth information;
[0088] The third authentication information is generated based on the first key and the first challenge information, and the first key is known to the first terminal device.
[0089] In a seventh aspect, a wireless communication device is provided, including: a communication module, configured to:
[0090] Receive first information; wherein the first information includes: first challenge information;
[0091] sending second information to the first communication node;
[0092] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0093] The third information is generated by encrypting the fifth information based on the second key;
[0094] The first message integrity check information is generated based on the third key, the third information or the fifth information, and the first challenge information;
[0095] The second message integrity verification information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0096] The sixth information is the encrypted information of the fourth information.
[0097] In an eighth aspect, a wireless communication device is provided, comprising: a communication module and a processing module;
[0098] Communication modules are used for:
[0099] Send the first message by any of the following:
[0100] Sending first information to the first terminal device;
[0101] forwarding or broadcasting the first information through the second communication node;
[0102] After sending the first information, the communication module is further configured to:
[0103] receiving second information sent by the first terminal device;
[0104] The first information includes: first challenge information;
[0105] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0106] The processing module is used to:
[0107] Execute the target operation;
[0108] The target operation includes at least one of the following:
[0109] decrypting the third information based on the second key;
[0110] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and the first challenge information;
[0111] verifying the second message integrity verification information based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0112] The fifth information is generated by decrypting the third information based on the second key;
[0113] The sixth information is the encrypted information of the fourth information.
[0114] In a ninth aspect, a terminal is provided, comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method of the first aspect or the third aspect are implemented.
[0115] In a tenth aspect, a terminal is provided, comprising a communication interface, wherein the communication interface is configured to:
[0116] Receive first information; wherein the first information includes: first challenge information;
[0117] Sending first authentication information and second information to the first communication node;
[0118] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0119] The first authentication information is generated based on the first challenge information and the first key;
[0120] The third information is generated by encrypting the fifth information based on the second key;
[0121] The first message integrity check information is generated based on the third key, the third information or the fifth information, and at least one of the following:
[0122] First challenge information;
[0123] First authentication information;
[0124] The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following:
[0125] First challenge information;
[0126] First authentication information;
[0127] The sixth information is the encrypted information of the fourth information.
[0128] In an eleventh aspect, a terminal is provided, comprising a communication interface, wherein the communication interface is configured to:
[0129] Receive first information; wherein the first information includes: first challenge information;
[0130] sending second information to the first communication node;
[0131] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0132] The third information is generated by encrypting the fifth information based on the second key;
[0133] The first message integrity check information is generated based on the third key, the third information or the fifth information, and the first challenge information;
[0134] The second message integrity verification information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0135] The sixth information is the encrypted information of the fourth information.
[0136] In the twelfth aspect, a communication device is provided, which includes a processor and a memory, the memory storing programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method of the second aspect or the fourth aspect are implemented.
[0137] In a thirteenth aspect, a communication device is provided, including a processor and a communication interface, wherein the communication interface is configured to send first information by any one of the following:
[0138] Sending first information to the first terminal device;
[0139] forwarding or broadcasting the first information through the second communication node;
[0140] After the communication interface sends the first information, the communication interface is further used to: receive the first authentication information and the second information sent by the first terminal device;
[0141] The first information includes: first challenge information;
[0142] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0143] The processor is configured to perform a first operation and a second operation;
[0144] The first operation includes verifying the first authentication information based on the third authentication information;
[0145] The second operation includes at least one of the following:
[0146] decrypting the third information based on the second key;
[0147] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information;
[0148] verifying the second message integrity verification information based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information;
[0149] The fifth information is generated by decrypting the third information based on the second key;
[0150] The sixth information is the encrypted information of the fourth information;
[0151] The third authentication information is generated based on the first key and the first challenge information, and the first key is known to the first terminal device.
[0152] In a fourteenth aspect, a communication device is provided, including a processor and a communication interface, wherein the communication interface is configured to:
[0153] Send the first message by any of the following:
[0154] Sending first information to the first terminal device;
[0155] forwarding or broadcasting the first information through the second communication node;
[0156] After sending the first information, the communication interface is further used to:
[0157] receiving second information sent by the first terminal device;
[0158] The first information includes: first challenge information;
[0159] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0160] The processor is used to:
[0161] Execute the target operation;
[0162] The target operation includes at least one of the following:
[0163] decrypting the third information based on the second key;
[0164] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and the first challenge information;
[0165] verifying the second message integrity verification information based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0166] The fifth information is generated by decrypting the third information based on the second key;
[0167] The sixth information is the encrypted information of the fourth information.
[0168] In the fifteenth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect or the third aspect are implemented, or the steps of the method described in the second aspect or the fourth aspect are implemented.
[0169] In the sixteenth aspect, a wireless communication system is provided, including: a terminal and a network side device, wherein the terminal can be used to execute the steps of the method described in the first aspect or the third aspect, and the network side device can be used to execute the steps of the method described in the second aspect or the fourth aspect.
[0170] In the seventeenth aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect or the third aspect, or to implement the method described in the second aspect or the fourth aspect.
[0171] In aspect 18, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the steps of the wireless communication method as described in any one of aspects 1 to 4.
[0172] In an embodiment of the present application, the efficiency of terminal access to the network is improved by reducing the interaction steps between the terminal and the core network. BRIEF DESCRIPTION OF THE DRAWINGS
[0173] Figure 1 is a schematic diagram of the process of terminal accessing the network;
[0174] FIG2 shows a block diagram of a wireless communication system applicable to embodiments of the present application;
[0175] FIG3 is an interactive flow chart of a wireless communication method provided in an embodiment of the present application;
[0176] FIG4 is an interaction flow chart of another wireless communication method provided in an embodiment of the present application;
[0177] FIG5 is an interaction flow chart of another wireless communication method provided in an embodiment of the present application;
[0178] FIG6 is an interaction flow chart of another wireless communication method provided in an embodiment of the present application;
[0179] FIG7 is an interactive flow chart of a wireless communication method provided in an embodiment of the present application;
[0180] FIG8 is an interactive flow chart of another wireless communication method provided in an embodiment of the present application;
[0181] FIG9 is a schematic diagram of a wireless communication device 900 provided in an embodiment of the present application;
[0182] FIG10 is a schematic diagram of a wireless communication device 1000 provided in an embodiment of the present application;
[0183] FIG11 is a schematic diagram of a wireless communication device 1100 provided in an embodiment of the present application;
[0184] FIG12 is a schematic diagram of a wireless communication device 1200 provided in an embodiment of the present application;
[0185] FIG13 is a schematic block diagram of a communication device provided in an embodiment of the present application;
[0186] FIG14 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application;
[0187] FIG15 is a schematic diagram of the hardware structure of a communication device implementing an embodiment of the present application. DETAILED DESCRIPTION
[0188] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.
[0189] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0190] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.
[0191] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for illustrative purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as 6th generation (6G) systems. th Generation, 6G) communication system.
[0192] FIG2 shows a block diagram of a wireless communication system applicable to an embodiment of the present application. The wireless communication system includes a terminal 21 and a communication node 22. The terminal 21 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device (Wearable Device), an aircraft (flight vehicle), a vehicle user equipment (VUE), a shipborne device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture, etc.), a game console, a personal computer (PC), a teller machine, or a self-service machine, and other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 21 is not limited in the embodiment of the present application. The communication node 22 may include a switching terminal, an access network device and a core network node, wherein the switching terminal is a terminal with switching capability. Among them, the access network device may also be called a radio access network (Radio Access Network, RAN) device, a radio access network function or a radio access network unit. The access network device may include a base station, a wireless local area network (Wireless Local Area Network, WLAN) access point (Access Point, AP) or a wireless fidelity (Wireless Fidelity, WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
[0193] The core network node may include but is not limited to at least one of the following: core network equipment, core network functions, mobility management entity (MME), access and mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application server discovery function (EASDF), UDM, unified data repository (UDR), home subscriber server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (BSF), application function (AF), etc. It should be noted that in the embodiments of this application, only the core network function in the NR system is introduced as an example, and the specific type of the core network node is not limited.
[0194] As mentioned above, currently, the terminal and the core network need to interact for at least five steps before the terminal can access the network and then transmit information. However, the large number of interaction steps results in low efficiency in terminal access to the network.
[0195] In order to solve the above technical problems, the embodiments of the present application propose to reduce the interaction steps between the terminal and the core network to improve the efficiency of the terminal accessing the network.
[0196] The wireless communication method provided in the embodiments of the present application is described in detail below through some embodiments and their application scenarios in conjunction with the accompanying drawings.
[0197] FIG3 is an interactive flow chart of a wireless communication method provided in an embodiment of the present application. As shown in FIG3 , the method includes:
[0198] S310-1A: The first communication node sends first information to the first terminal device; wherein the first information includes: first challenge information; or,
[0199] S310-1B: The first communication node sends first information to the second communication node, wherein the first information includes: first challenge information;
[0200] S310-2B: The second communication node forwards or broadcasts the first information;
[0201] S320: The first terminal device sends first authentication information and second information to the first communication node; wherein the first authentication information is generated based on the first challenge information and the first key; wherein the second information includes: third information and first message integrity verification information; or, the second information includes: fourth information and second message integrity verification information; wherein the third information is generated by encrypting the fifth information based on the second key; wherein the first message integrity verification information is generated based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information; the first authentication information; wherein the second message integrity verification information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information; the first authentication information; wherein the sixth information is the encrypted information of the fourth information;
[0202] It should be understood that since the first authentication information is generated based on the first challenge information, when the first challenge information is used to generate the first message integrity verification information, the first message integrity verification information can also be used as the first authentication information, for example, for the first communication node to authenticate the first terminal device. At this time, the first authentication information is the first message integrity verification information, that is, the first authentication information is included in the second information.
[0203] It should be understood that since the first authentication information is generated based on the first challenge information, when the first challenge information is used to generate the second message integrity verification information, the second message integrity verification information can also be used as the first authentication information, for example, for the first communication node to authenticate the first terminal device. At this time, the first authentication information is the second message integrity verification information, that is, the first authentication information is included in the second information.
[0204] S330: The first communication node performs the first operation and the second operation;
[0205] The first operation includes verifying the first authentication information based on the third authentication information; wherein the third authentication information is generated based on the first key and the first challenge information, and the first key is known to the first terminal device;
[0206] The second operation includes at least one of the following:
[0207] decrypting the third information based on the second key;
[0208] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information;
[0209] The second message integrity verification information is verified based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information.
[0210] It should be understood that S310 - 1A is one possible way for the first communication node to send the first information, and S310 - 1B and S310 - 2B constitute another possible way for the first communication node to send the first information.
[0211] In some implementations, before executing S310-1A, the first terminal device may send an identifier of the first terminal device to the first communication node, so that the first communication node can send the first information to the first terminal device. In this case, both the identifier of the first terminal device and the first information can be understood as NAS messages, that is, the first terminal device can transparently transmit the identifier of the first terminal device to the first communication node via the second communication node, and the first communication node can transparently transmit the first information to the first terminal device via the second communication node.
[0212] In some implementations, before executing S310 - 1B, the first communication node fails to obtain the identification of the first terminal device, and therefore, it may send the first information to the second communication node so that the second communication node forwards or broadcasts the first information.
[0213] It should be understood that the first communication node may also be referred to as a first communication device, a first communication entity, etc., but is not limited thereto.
[0214] In some implementations, the first communication node may be an AMF, a UDM, or an authentication service function (AUSF), but is not limited thereto.
[0215] It should be understood that the second communication node may also be referred to as a second communication device, a second communication entity, etc., but is not limited thereto.
[0216] In some implementations, the second communication node is a base station system, a second terminal device, or other access network device, etc., but is not limited thereto. The base station system may include one or more base stations.
[0217] It should be understood that the first challenge information is also referred to as first random information or first random number (RAND1), etc., but is not limited thereto, such as character string information, sequentially increasing or decreasing quantity information, etc.
[0218] In some implementations, the first authentication information is used for the first communication node to authenticate the first terminal device. For example, the first authentication information is RES.
[0219] It should be understood that the third information can be understood as ciphertext, and the fifth information can be understood as the plaintext corresponding to the third information, but is not limited to this. In some implementations, the third information can be application / service data sent by the first terminal device, but is not limited to this. The application data can be carried, for example, via the Application Container (AC) field, but is not limited to this.
[0220] It should be understood that the first message integrity check information is also referred to as a first message authentication code (MAC), but is not limited thereto.
[0221] It should be understood that the first message integrity check information is generated based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information; the first authentication information, including two cases:
[0222] Case 1: The first message integrity check information is generated based on the third key, the third information, and at least one of the following: the first challenge information; the first authentication information.
[0223] Case 2: The first message integrity check information is generated based on the third key, the fifth information, and at least one of the following: the first challenge information; the first authentication information.
[0224] The following describes the situation:
[0225] In other words, the calculation parameters of the first message integrity check information include: the third key, the third information and at least one of the following: the first challenge information; the first authentication information.
[0226] The following describes the second scenario:
[0227] In other words, the calculation parameters of the first message integrity check information include: the third key, the fifth information and at least one of the following: the first challenge information; the first authentication information.
[0228] It should be understood that the third key may be an integrity protection key.
[0229] It should be understood that the fourth information can be understood as plain text, and the sixth information can be understood as cipher text of the fourth information, but is not limited thereto.
[0230] It should be understood that the second message integrity check information is also referred to as a second message authentication code (MAC), but is not limited thereto.
[0231] It should be understood that the second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information; the first authentication information, including two cases:
[0232] Case 1: The second message integrity check information is generated based on the fourth key, the fourth information, and at least one of the following: the first challenge information; the first authentication information.
[0233] Case 2: The second message integrity check information is generated based on the fourth key, the sixth information, and at least one of the following: the first challenge information; the first authentication information.
[0234] The following describes the situation:
[0235] In other words, the calculation parameters of the second message integrity check information include: the fourth key, the fourth information, and at least one of the following: the first challenge information; the first authentication information.
[0236] The following describes the second scenario:
[0237] In other words, the calculation parameters of the second message integrity check information include: the fourth key, the sixth information, and at least one of the following: the first challenge information; the first authentication information.
[0238] It should be understood that the fourth key may be an integrity protection key.
[0239] In some implementations, the third authentication information is also used for the first communication node to authenticate the first terminal device. The difference between the third authentication information and the first authentication information is that the first authentication information is the authentication information calculated by the first terminal device, and the third authentication information is the authentication information calculated by the UDM. For example, the third authentication information is XRES or the hash value of XRES (HRES).
[0240] In some possible implementations, the first communication node verifies the first authentication information based on the third authentication information, including: the first communication node can compare whether the first authentication information is consistent with the third authentication information; if they are consistent, the first communication node determines that the authentication of the first terminal device is successful; if they are inconsistent, the first communication node determines that the authentication of the first terminal device has failed.
[0241] In some implementations, the first key is a shared key between the first terminal device and the UMD, or in other words, the first key is a shared key between the first terminal device and the core network side.
[0242] It should be understood that in the embodiment of the present application, the first key and the subsequent fifth key are keys that are known in advance by the first terminal device and the core network side. For example, they can be derived from one or two keys that are known in advance by both parties, or they can be pre-configured on both parties. The second key, third key, fourth key, sixth key and seventh key are all derived from the first key or the fifth key in an agreed / prescribed manner, so the two parties do not need to exchange the second key, third key, fourth key, sixth key and seventh key.
[0243] An embodiment of the present application provides a wireless communication method, wherein if S310 includes: S310-1A, then before executing S310-1A, the first terminal device may send an identifier of the first terminal device to the first communication node so that the first communication node can send the first information to the first terminal device. In this case, the identifier of the first terminal device and the first information can both be understood as NAS messages, and the second information in S320 can also be a NAS message. Therefore, it can be seen that the wireless communication method provided by this implementable method includes three NAS messages. In other words, the first terminal device and the core network can interact in three steps before the first terminal device can access the network and transmit information. Since the number of interaction steps between the first terminal device and the core network is reduced, the efficiency of the first terminal device accessing the network can be improved. If S310 includes: S310-1B and S310-2B, then the first information cannot be understood as a NAS message, and the second information in S320 can be a NAS message. It can be seen that the wireless communication method provided by this implementable method includes 1 NAS message. In other words, the first terminal device can interact with the core network in 1 step, and the first terminal device can then access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0244] In some possible implementations, the second information also includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; wherein the first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
[0245] It should be understood that the second challenge information is also referred to as second random information or a second random number (RAND2), etc., but is not limited thereto, such as character string information, sequentially increasing or decreasing quantity information, etc.
[0246] In some implementations, the first algorithm information is algorithm information of at least one of the following used by the first terminal device: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
[0247] It should be understood that an encryption algorithm is used to encrypt plain text.
[0248] It should be understood that the integrity protection algorithm is used to perform integrity protection on information, and can be used to calculate MAC, for example.
[0249] It should be understood that the key derivation algorithm is used to generate derived keys. For example, the second key, the third key, the fourth key, and at least one of the sixth key and the seventh key to be mentioned below can be generated based on the first key and the key derivation algorithm.
[0250] It should be understood that the authentication information generation algorithm is used to generate authentication information, for example, to generate the first authentication information or the second authentication information.
[0251] A first implementation method is that after the first terminal device sends the first authentication information to the first communication node, and before the first terminal device sends the second information to the first communication node, the wireless communication method also includes: the first terminal device receives seventh information from the first communication node; based on this, the first terminal device sends the second information to the first communication node, including: the first terminal device sends the second information to the first communication node based on the seventh information; wherein the seventh information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0252] In some implementations, the second authentication information is used for the first terminal device to authenticate the first communication node. For example, the second authentication information is an authentication token (AUTN).
[0253] In some implementations, the second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node, and the algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, authentication information generation algorithm.
[0254] It should be understood that the explanations of the encryption algorithm, integrity protection algorithm, key derivation algorithm, and authentication information generation algorithm can be referred to above, and the embodiments of the present application will not go into details therein.
[0255] In some implementations, the ninth information may be plaintext or ciphertext, and may be, but is not limited to, application / service data sent by the first communication node. The application data may be, for example, carried by, but is not limited to, an application container (AC) field.
[0256] It should be understood that the third message integrity check information is also referred to as a third message authentication code (MAC), but is not limited thereto.
[0257] In some implementations, the third message integrity check information is generated based on the seventh key, the ninth information or the eleventh information, and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0258] The third message integrity check information is generated based on the seventh key, the ninth information or the eleventh information, and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information, including two cases:
[0259] Case 1: The third message integrity verification information is generated based on the seventh key, the ninth information, and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0260] Case 2: The third message integrity verification information is generated based on the seventh key, the eleventh information, and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0261] The following describes the situation:
[0262] In other words, the calculation parameters of the third message integrity check information include: the seventh key, the ninth information, and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0263] The following describes the second scenario:
[0264] In other words, the calculation parameters of the third message integrity check information include: the seventh key, the eleventh information, and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0265] It should be understood that the seventh key may be an integrity protection key.
[0266] It should be understood that when the ninth information is plain text, the eleventh information is the ciphertext corresponding to the ninth information. When the ninth information is ciphertext, the eleventh information is the plain text corresponding to the ninth information.
[0267] In some implementations, when the seventh information includes: second authentication information, the first terminal device sends the second information to the first communication node based on the seventh information, including: the first terminal device sends the second information to the first communication node based on the authentication result of the second authentication information.
[0268] In some implementations, when the first terminal device successfully authenticates the second authentication information, the first terminal device sends the second information to the first communication node. When the first terminal device fails to authenticate the second authentication information, the first terminal device does not send the second information to the first communication node.
[0269] It should be understood that the embodiment of the present application does not limit the authentication method of the second authentication information.
[0270] In some implementations, when the seventh information includes: second algorithm information, the first terminal device sends the second information to the first communication node based on the seventh information, including: the first terminal device selects the first algorithm information in the second algorithm information and sends the first algorithm information to the first communication node.
[0271] In some implementations, when the seventh information includes: the ninth information and the third message integrity verification information, the first terminal device sends the second information to the first communication node based on the seventh information, including: the first terminal device verifies the third message integrity verification information based on the ninth information, and when the third message integrity verification information is successfully verified, sends the second information to the first communication node.
[0272] In a second implementation method, the first information further includes at least one of the following: second authentication information and second algorithm information.
[0273] It should be understood that the explanation of the second authentication information and the second algorithm information can be referred to above, and the embodiments of the present application will not be repeated here.
[0274] In some implementations, when the first information also includes at least one of the following: second authentication information, second algorithm information, the wireless communication method also includes: the first terminal device receives tenth information sent by the first communication node; wherein the tenth information includes: ninth information, third message integrity verification information.
[0275] It should be understood that the explanation of the ninth information and the third message integrity verification information can be referred to above, and the embodiments of the present application will not go into details therein.
[0276] A third implementation method is that the wireless communication method further includes: the first terminal device receives the eighth information sent by the first communication node; wherein the eighth information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0277] It should be understood that the explanation of the second authentication information, the second algorithm information, the ninth information and the third message integrity verification information can be referred to above, and the embodiments of the present application will not go into details therein.
[0278] In some implementations, the wireless communication method further includes: the first terminal device performing at least one of the following:
[0279] verifying the second authentication information based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information;
[0280] verifying the third message integrity check information based on the seventh key and the ninth information;
[0281] verifying the third message integrity verification information based on the seventh key and the eleventh information;
[0282] decrypting the ninth information based on the sixth key;
[0283] The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information;
[0284] The fifth key is known by the first terminal device.
[0285] In other words, the second authentication information is generated based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0286] The third message integrity check information is generated based on the seventh key and the ninth information; or,
[0287] The third message integrity check information is generated based on the seventh key and the eleventh information; or,
[0288] The ninth information is generated by encrypting based on the sixth key;
[0289] The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information;
[0290] The fifth key is known by the first terminal device.
[0291] It should be understood that the fifth key is used to generate the second authentication information.
[0292] In some implementations, the fifth key is a shared key between the first terminal device and the UDM, or in other words, the fifth key is a shared key between the first terminal device and the core network side.
[0293] In some implementations, the fifth key may be the same as or different from the first key, and this embodiment of the present application does not impose any limitation on this.
[0294] In some implementations, verifying the third message integrity verification information based on the seventh key and the ninth information includes: verifying the third message integrity verification information based on the seventh key, the ninth information and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0295] In some implementations, verifying the third message integrity verification information based on the seventh key and the eleventh information includes: verifying the third message integrity verification information based on the seventh key, the eleventh information and at least one of the following: the seventh key, the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0296] In other words, the third message integrity verification information is also generated based on at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0297] In some implementations, decrypting the ninth information based on the sixth key includes: decrypting the ninth information based on the sixth key and at least one of the following: first challenge information, second challenge information, first authentication information, second authentication information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0298] In other words, the ninth information is also generated based on encryption of at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0299] In some implementations, the second key is the first key, or the fifth key, or a derivative of the first key, or a derivative of the fifth key.
[0300] In some implementations, the third key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
[0301] In some implementations, the fourth key is the first key, or the fifth key, or a derivative of the first key, or a derivative of the fifth key.
[0302] In some implementations, the sixth key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
[0303] In some implementations, the seventh key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
[0304] In some implementations, the second key is further generated based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0305] In some implementations, the third key is also generated based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0306] In some implementations, the fourth key is also generated based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0307] In some implementations, the sixth key is further derived based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0308] In some implementations, the seventh key is further derived based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0309] In some implementations, the first authentication information is further generated based on at least one of the following: second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0310] In some implementations, the first message integrity check information is further generated based on at least one of the following: second authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0311] Accordingly, in some possible implementations, the wireless communication method further includes: the first communication node also verifies the first message integrity verification information based on at least one of the following: second authentication information, second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0312] In some implementations, the second message integrity check information is further generated based on at least one of the following: second authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0313] Accordingly, in some possible implementations, the wireless communication method further includes: the first communication node also verifies the second message integrity verification information based on at least one of the following: second authentication information, second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0314] In some implementations, the third authentication information is further generated based on at least one of the following: the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0315] In some implementations, the third information is also generated based on encryption of at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0316] Correspondingly, in some feasible embodiments, the wireless communication method further includes: the first communication node also decrypts the third information based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, the identification of the first terminal device, first algorithm information, and second algorithm information.
[0317] An embodiment of the present application provides a wireless communication method, wherein, based on the method embodiment corresponding to FIG3 , in an implementable manner, after the first terminal device sends the first authentication information to the first communication node, and before the first terminal device sends the second information to the first communication node, the wireless communication method further includes: the first terminal device receives the seventh information from the first communication node; based on this, the first terminal device sends the second information to the first communication node, including: the first terminal device sends the second information to the first communication node based on the seventh information. Wherein, the seventh information can be understood as a NAS message. In combination with the method embodiment corresponding to FIG3 , the first terminal device and the core network can interact in 4 or 2 steps, and the first terminal device can then access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0318] In another possible implementation, the first information also includes at least one of the following: second authentication information, second algorithm information. In combination with the method embodiment corresponding to Figure 3, the first terminal device and the core network can interact for 3 or 1 steps before the first terminal device can access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved. Further, in the case where the first information also includes at least one of the following: second authentication information, second algorithm information, the wireless communication method also includes: the first terminal device receives the tenth information sent by the first communication node; wherein the tenth information includes: ninth information, third message integrity verification information. If the tenth information is understood as a NAS message, then the first terminal device and the core network can interact for 4 or 2 steps before the first terminal device can access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0319] In another possible implementation, the wireless communication method further includes: the first terminal device receiving eighth information sent by the first communication node; wherein the eighth information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity check information. If the eighth information is understood as an NAS message, in conjunction with the method embodiment corresponding to FIG3 , the first terminal device and the core network can interact in four or two steps before the first terminal device can access the network and transmit information. Since the number of interaction steps between the first terminal device and the core network is reduced, the efficiency of the first terminal device's network access can be improved.
[0320] It should be noted that the core idea of the embodiment of the present application is to improve the efficiency of the terminal accessing the network by reducing the interaction steps between the terminal and the core network. There are various ways to reduce the interaction steps between the terminal and the core network, including at least one of the following, but not limited to: the terminal may not need to receive the second authentication information, the terminal may send the first authentication information and the second information to the core network at the same time, and the first information received by the terminal may carry the first challenge information and at least one of the following information: the second authentication information and the second algorithm information. The wireless communication method provided in the embodiment of the present application is exemplified below through several examples:
[0321] In Example 1, a first shared key, namely, a first key, exists between the first terminal device and the UDM. FIG4 is an interactive flow chart of another wireless communication method provided in an embodiment of the present application. As shown in FIG4 , the wireless communication method includes:
[0322] S410: The first terminal device sends first information to the first communication node, where the first information includes: first challenge information, and optionally, the first information may further include: second algorithm information;
[0323] S420: The first terminal device calculates first authentication information based on the first key and the first challenge information;
[0324] S430: The first terminal device encrypts the fifth information based on the second key to obtain third information, and generates first message integrity check information based on the third key, the third information or the fifth information, and at least one of the following: first challenge information and first authentication information; or generates second message integrity check information based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information and the first authentication information;
[0325] S440: The first terminal device sends first authentication information and second information, where the second information includes: third information and first message integrity verification information; or the second information includes: fourth information and second message integrity verification information; optionally, the second information further includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information;
[0326] S450: The first communication node performs the first operation and the second operation;
[0327] The first operation includes verifying the first authentication information based on the third authentication information;
[0328] The second operation includes at least one of the following:
[0329] decrypting the third information based on the second key;
[0330] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information;
[0331] The second message integrity verification information is verified based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information.
[0332] It should be noted that for the explanation of the various information in this example, please refer to the above and will not be repeated here.
[0333] It should be understood that in this example, the first authentication information and the second information can be transmitted through a NAS message, that is, the wireless communication method provided in Example 1 includes a NAS interaction, then the first terminal device and the core network can interact for one step, and the first terminal device can then access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0334] Example 2: There is a first shared key, i.e., a first key, between the first terminal device and the UDM. FIG5 is an interaction flow chart of another wireless communication method provided in an embodiment of the present application. As shown in FIG5 , the wireless communication method includes:
[0335] S510: The first terminal device sends first information, including: first challenge information;
[0336] S520: The first terminal device calculates first authentication information based on the first key and the first challenge information;
[0337] S530: The first terminal device sends first authentication information and an identifier of the first terminal device;
[0338] S540: The first communication node verifies the first authentication information based on the third authentication information;
[0339] S550: The first communication node sends seventh information, including second authentication information. Optionally, the seventh information may further include second algorithm information.
[0340] S560: The first terminal device verifies the second authentication information and, if the verification is successful, encrypts the fifth information based on the second key to obtain third information, and generates first message integrity check information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information and the first authentication information; or generates second message integrity check information based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information and the first authentication information.
[0341] S570: The first terminal device sends second information, where the second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information; optionally, the second information further includes at least one of the following: an identifier of the first terminal device, the second challenge information, and the first algorithm information;
[0342] S580: The first communication node performs a second operation;
[0343] The second operation includes at least one of the following:
[0344] decrypting the third information based on the second key;
[0345] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information;
[0346] The second message integrity verification information is verified based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information.
[0347] It should be noted that for the explanation of the various information in this example, please refer to the above and will not be repeated here.
[0348] It should be understood that in this example, the first authentication information and the identification of the first terminal device can be transmitted through a NAS message, the seventh information can be a NAS message, and the second information can also be a NAS message. That is to say, the wireless communication method provided in Example 2 includes three NAS interactions, so the first terminal device and the core network can interact for 3 steps, and the first terminal device can then access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0349] Example 3: There is a first shared key, i.e., a first key, between the first terminal device and the UDM. FIG6 is an interaction flow chart of another wireless communication method provided in an embodiment of the present application. As shown in FIG6 , the wireless communication method includes:
[0350] S610: The first terminal device sends an identifier of the first terminal device;
[0351] S620: The first communication node sends first information, including: first challenge information. Optionally, the first information may further include at least one of the following: second authentication information and second algorithm information.
[0352] S630: The first terminal device calculates first authentication information based on the first key and the first challenge information;
[0353] S640: The first terminal device verifies the second authentication information and, if the verification is successful, encrypts the fifth information based on the second key to obtain third information, and generates first message integrity check information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information and the first authentication information; or generates second message integrity check information based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information and the first authentication information.
[0354] S650: The first terminal device sends first authentication information and second information, where the second information includes: third information and first message integrity verification information; or the second information includes: fourth information and second message integrity verification information; optionally, the second information further includes at least one of the following: second challenge information and first algorithm information;
[0355] S660: The first communication node performs the first operation and the second operation;
[0356] The first operation includes verifying the first authentication information based on the third authentication information;
[0357] The second operation includes at least one of the following:
[0358] decrypting the third information based on the second key;
[0359] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information;
[0360] The second message integrity verification information is verified based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information.
[0361] It should be noted that for the explanation of the various information in this example, please refer to the above and will not be repeated here.
[0362] It should be understood that in this example, the identification of the first terminal device can be transmitted through a NAS message, the first information can be a NAS message, and the second information and the first authentication information can also be transmitted through a NAS message. That is to say, the wireless communication method provided in Example 3 includes three NAS interactions, so the first terminal device and the core network can interact for 3 steps, and the first terminal device can then access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0363] FIG7 is an interactive flow chart of a wireless communication method provided in an embodiment of the present application. As shown in FIG7 , the method includes:
[0364] S710-1A: The first communication node sends first information to the first terminal device; wherein the first information includes: first challenge information; or,
[0365] S710-1B: The first communication node sends first information to the second communication node, wherein the first information includes: first challenge information;
[0366] S710-2B: The second communication node forwards or broadcasts the first information;
[0367] S720: The first terminal device sends second information to the first communication node; wherein the second information includes: third information and first message integrity verification information; or the second information includes: fourth information and second message integrity verification information; wherein the third information is generated by encrypting the fifth information based on the second key; wherein the first message integrity verification information is generated based on the third key, the third information or the fifth information, and the first challenge information; wherein the second message integrity verification information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0368] S730: The first communication node performs a target operation;
[0369] The target operation includes at least one of the following:
[0370] decrypting the third information based on the second key;
[0371] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and the first challenge information;
[0372] The second message integrity verification information is verified based on the fourth key, the fourth information or the sixth information, and the first challenge information.
[0373] It should be understood that S710 - 1A is one possible implementation manner for the first communication node to send the first information, and S710 - 1B and S710 - 2B constitute another possible implementation manner for the first communication node to send the first information.
[0374] In some implementations, before executing S710-1A, the first terminal device may send an identifier of the first terminal device to the first communication node, so that the first communication node can send the first information to the first terminal device. In this case, both the identifier of the first terminal device and the first information can be understood as NAS messages, that is, the first terminal device can transparently transmit the identifier of the first terminal device to the first communication node via the second communication node, and the first communication node can transparently transmit the first information to the first terminal device via the second communication node.
[0375] In some implementations, before executing S710 - 1B, the first communication node fails to obtain the identification of the first terminal device, and therefore, it may send the first information to the second communication node so that the second communication node forwards or broadcasts the first information.
[0376] It should be understood that the first communication node may also be referred to as a first communication device, a first communication entity, etc., but is not limited thereto.
[0377] In some implementations, the first communication node may be an AMF entity, a UDM entity, an AUSF entity, etc., but is not limited thereto.
[0378] It should be understood that the second communication node may also be referred to as a second communication device, a second communication entity, etc., but is not limited thereto.
[0379] In some implementations, the second communication node is a base station system, a second terminal device, or other access network device, etc., but is not limited thereto. The base station system may include one or more base stations.
[0380] It should be understood that the first challenge information is also referred to as first random information or a first random number (RAND1), etc., but is not limited thereto.
[0381] It should be understood that the third information can be understood as ciphertext, and the fifth information can be understood as the plaintext corresponding to the third information, but is not limited thereto.
[0382] It should be understood that the first message integrity check information is also referred to as a first message authentication code (MAC), but is not limited thereto.
[0383] It should be understood that the first message integrity check information is generated based on the third key, the third information or the fifth information, and the first challenge information in two cases:
[0384] Case 1: The first message integrity verification information is generated based on the third key, the third information, and the first challenge information.
[0385] Case 2: The first message integrity verification information is generated based on the third key, the fifth information, and the first challenge information.
[0386] The following describes the situation:
[0387] In other words, the calculation parameters of the first message integrity check information include: the third key, the third information and the first challenge information.
[0388] The following describes the second scenario:
[0389] In other words, the calculation parameters of the first message integrity check information include: the third key, the fifth information and the first challenge information.
[0390] It should be understood that the third key may be an integrity protection key.
[0391] It should be understood that the sixth information can be understood as ciphertext, and the fourth information can be understood as plaintext corresponding to the sixth information, but is not limited thereto.
[0392] It should be understood that the second message integrity check information is also referred to as a second message authentication code (MAC), but is not limited thereto.
[0393] It should be understood that the second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information in two cases:
[0394] Case 1: The second message integrity verification information is generated based on the fourth key, the fourth information, and the first challenge information.
[0395] Case 2: The second message integrity verification information is generated based on the fourth key, the sixth information, and the first challenge information.
[0396] The following describes the situation:
[0397] In other words, the calculation parameters of the second message integrity check information include: the fourth key, the fourth information, and the first challenge information.
[0398] The following describes the second scenario:
[0399] In other words, the calculation parameters of the second message integrity check information include: the fourth key, the sixth information, and the first challenge information.
[0400] It should be understood that the fourth key may be an integrity protection key.
[0401] In some implementations, the first key is a shared key between the first terminal device and the first communication node, or in other words, the first key is a shared key between the first terminal device and the core network side.
[0402] It should be noted that the difference between the method embodiment corresponding to Figure 7 and the method embodiment corresponding to Figure 3 is that the function of the first challenge information is different. In the method embodiment corresponding to Figure 7, the first challenge information can be used to generate first message integrity verification information or second message integrity verification information. In the method embodiment corresponding to Figure 3, the first challenge information can be used to generate first authentication information, and then used to authenticate the first terminal device.
[0403] An embodiment of the present application provides a wireless communication method, wherein if S710 includes: S710-1A, then before executing S710-1A, the first terminal device may send an identifier of the first terminal device to the first communication node so that the first communication node can send the first information to the first terminal device. In this case, the identifier of the first terminal device and the first information can both be understood as NAS messages, and the second information in S720 can also be a NAS message. Therefore, it can be seen that the wireless communication method provided by this implementable method includes three NAS messages. In other words, the first terminal device and the core network can interact in three steps before the first terminal device can access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved. If S710 includes: S710-1B and S710-2B, then the first information cannot be understood as a NAS message, and the second information in S720 can be a NAS message. It can be seen that the wireless communication method provided by this implementable method includes 1 NAS message. In other words, the first terminal device can interact with the core network in 1 step, and the first terminal device can then access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0404] In some possible implementations, the second information also includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; wherein the first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
[0405] It should be understood that the second challenge information is also referred to as second random information or a second random number (RAND2), etc., but is not limited thereto.
[0406] In some implementations, the first algorithm information is algorithm information of at least one of the following used by the first terminal device: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
[0407] It should be understood that an encryption algorithm is used to encrypt plain text.
[0408] It should be understood that the integrity protection algorithm is used to perform integrity protection on information, and can be used to calculate MAC, for example.
[0409] It should be understood that the key derivation algorithm is used to generate derived keys. For example, the second key, the third key, the fourth key, and at least one of the sixth key and the seventh key to be mentioned below can be generated based on the first key and the key derivation algorithm.
[0410] It should be understood that the authentication information generation algorithm is used to generate authentication information, for example, to generate the first authentication information or the second authentication information.
[0411] A first achievable method is that before the first terminal device sends the second information to the first communication node, the wireless communication method also includes: the first terminal device receives seventh information from the first communication node; based on this, the first terminal device sends the second information to the first communication node, including: the first terminal device sends the second information to the first communication node based on the seventh information; wherein the seventh information includes at least one of the following: second authentication information, second algorithm information.
[0412] In some implementations, the second authentication information is used for the first terminal device to authenticate the first communication node. For example, the second authentication information is an authentication token (AUTN).
[0413] In some implementations, the second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node, and the algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, authentication information generation algorithm.
[0414] It should be understood that the explanations of the encryption algorithm, integrity protection algorithm, key derivation algorithm, and authentication information generation algorithm can be referred to above, and the embodiments of the present application will not go into details therein.
[0415] In some implementations, when the seventh information includes: second authentication information, the first terminal device sends the second information to the first communication node based on the seventh information, including: the first terminal device sends the second information to the first communication node based on the authentication result of the second authentication information.
[0416] In some implementations, when the first terminal device successfully authenticates the second authentication information, the first terminal device sends the second information to the first communication node. When the first terminal device fails to authenticate the second authentication information, the first terminal device does not send the second information to the first communication node.
[0417] It should be understood that the embodiment of the present application does not limit the authentication method of the second authentication information.
[0418] In some implementations, when the seventh information includes: second algorithm information, the first terminal device sends the second information to the first communication node based on the seventh information, including: the first terminal device selects the first algorithm information in the second algorithm information and sends the first algorithm information to the first communication node.
[0419] In some implementations, when the first terminal device sends the second information to the first communication node based on the seventh information, the wireless communication method further includes: the first terminal device receiving tenth information sent by the first communication node; wherein the tenth information includes the ninth information and the third message integrity check information. The first terminal device receiving the tenth information sent by the first communication node may be performed after the first terminal device sends the second information, but is not limited thereto.
[0420] In some implementations, the ninth information may be plain text or cipher text, and may be application / service data sent by the first communication node, but is not limited thereto. The application data may be carried, for example, by the AC field, but is not limited thereto.
[0421] It should be understood that the third message integrity check information is also referred to as a third message authentication code (MAC), but is not limited thereto.
[0422] In some implementations, the third message integrity check information is generated based on the seventh key, the ninth information or the eleventh information, and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0423] The third message integrity check information is generated based on the seventh key, the ninth information or the eleventh information, and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information, including two cases:
[0424] Case 1: The third message integrity verification information is generated based on the seventh key, the ninth information, and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0425] Case 2: The third message integrity verification information is generated based on the seventh key, the eleventh information, and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0426] The following describes the situation:
[0427] In other words, the calculation parameters of the third message integrity check information include: the seventh key, the ninth information, and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0428] The following describes the second scenario:
[0429] In other words, the calculation parameters of the third message integrity check information include: the seventh key, the eleventh information, and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0430] It should be understood that the seventh key may be an integrity protection key.
[0431] It should be understood that when the ninth information is plain text, the eleventh information is the ciphertext corresponding to the ninth information. When the ninth information is ciphertext, the eleventh information is the plain text corresponding to the ninth information.
[0432] The second implementation method is that the wireless communication method also includes: the first terminal device receives the eighth information sent by the first communication node; wherein the eighth information includes at least one of the following: authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0433] It should be understood that the explanation of the authentication information, the second algorithm information, the ninth information and the third message integrity verification information can be referred to above, and the embodiments of the present application will not go into details therein.
[0434] In some implementations, the wireless communication method further includes: the first terminal device performing at least one of the following:
[0435] verifying the authentication information based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information;
[0436] Verifying the third message integrity verification information based on the seventh key and the ninth information, or verifying the third message integrity verification information based on the seventh key and the eleventh information;
[0437] decrypting the ninth information based on the sixth key;
[0438] The eleventh information is the encrypted version of the ninth information, or the encrypted version of the eleventh information is the ninth information;
[0439] The fifth key is known by the first terminal device.
[0440] In other words, the authentication information is generated based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0441] The third message integrity check information is generated based on the seventh key and the ninth information; or,
[0442] The third message integrity check information is generated based on the seventh key and the eleventh information; or,
[0443] The ninth information is generated by encrypting based on the sixth key;
[0444] The eleventh information is the encrypted version of the ninth information, or the encrypted version of the eleventh information is the ninth information;
[0445] The fifth key is known by the first terminal device.
[0446] It should be understood that the fifth key is used to generate the authentication information.
[0447] In some implementations, the fifth key is a shared key between the first terminal device and the first communication node, or in other words, the fifth key is a shared key between the first terminal device and the core network side.
[0448] In some implementations, the fifth key may be the same as or different from the first key, and this embodiment of the present application does not impose any limitation on this.
[0449] In some implementations, verifying the third message integrity verification information based on the seventh key and the ninth information includes: verifying the third message integrity verification information based on the seventh key, the ninth information and at least one of the following: first challenge information, second challenge information, authentication information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0450] In some implementations, verifying the third message integrity verification information based on the seventh key and the eleventh information includes: verifying the third message integrity verification information based on the seventh key, the eleventh information and at least one of the following: the seventh key, the first challenge information, the second challenge information, the authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
[0451] In other words, the third message integrity verification information is also generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0452] In some implementations, decrypting the ninth information based on the sixth key includes: decrypting the ninth information based on the sixth key and at least one of the following: first challenge information, second challenge information, authentication information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0453] In other words, the ninth information is also generated based on encryption of at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0454] In some implementations, the second key is the first key, or the fifth key, or a derivative of the first key, or a derivative of the fifth key.
[0455] In some implementations, the third key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
[0456] In some implementations, the fourth key is the first key, or the fifth key, or a derivative of the first key, or a derivative of the fifth key.
[0457] In some implementations, the sixth key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
[0458] In some implementations, the seventh key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
[0459] In some implementations, the second key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0460] In some implementations, the third key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0461] In some implementations, the fourth key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0462] In some implementations, the sixth key is further derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0463] In some implementations, the seventh key is further derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0464] In some implementations, the first message integrity check information is further generated based on at least one of the following: authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0465] Accordingly, in some possible implementations, the wireless communication method further includes: the first communication node also verifies the first message integrity verification information based on at least one of the following: authentication information, second challenge information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0466] In some implementations, the second message integrity verification information is further generated based on at least one of the following: authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0467] Accordingly, in some possible implementations, the wireless communication method further includes: the first communication node also verifies the second message integrity verification information based on at least one of the following: authentication information, second challenge information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0468] In some implementations, the third information is also generated by encryption based on at least one of the following: first challenge information, second challenge information, authentication information, an identifier of the terminal device, first algorithm information, and second algorithm information.
[0469] Accordingly, in some possible implementations, the wireless communication method further includes: the first communication node also decrypts the third information based on at least one of the following: first challenge information, second challenge information, authentication information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0470] An embodiment of the present application provides a wireless communication method, wherein, based on the method embodiment corresponding to FIG7 , in an implementable manner, before the first terminal device sends the second information to the first communication node, the wireless communication method further includes: the first terminal device receives seventh information from the first communication node; based on this, the first terminal device sends the second information to the first communication node, including: the first terminal device sends the second information to the first communication node based on the seventh information. The seventh information can be understood as a NAS message. In combination with the method embodiment corresponding to FIG7 , the first terminal device and the core network can interact in 4 or 2 steps, and the first terminal device can then access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0471] In another possible implementation, the wireless communication method further includes: the first terminal device receiving eighth information sent by the first communication node; wherein the eighth information includes at least one of the following: authentication information, second algorithm information, ninth information, and third message integrity check information. If the eighth information is understood as an NAS message, in conjunction with the method embodiment corresponding to FIG7 , the first terminal device and the core network can interact in four or two steps before the first terminal device can access the network and transmit information. Since the number of interaction steps between the first terminal device and the core network is reduced, the efficiency of the first terminal device's network access can be improved.
[0472] It should be noted that the core idea of the embodiment of the present application is to improve the efficiency of the terminal accessing the network by reducing the interaction steps between the terminal and the core network. There are various ways to reduce the interaction steps between the terminal and the core network, including at least one of the following, but not limited to: the terminal may not need to receive the second authentication information, the terminal may not need to send the first authentication information, the first information received by the terminal may simultaneously carry the first challenge information and at least one of the following information: the second authentication information, the second algorithm information. The following example illustrates the wireless communication method provided in the embodiment of the present application:
[0473] In Example 4, a first shared key, namely a first key, is established between the first terminal device and the UDM. FIG8 is an interactive flow chart of another wireless communication method provided in an embodiment of the present application. As shown in FIG8 , the wireless communication method includes:
[0474] S810: The first communication node sends first information to the first terminal device, including first challenge information. Optionally, the first information may further include second algorithm information.
[0475] S820: The first terminal device encrypts the fifth information based on the second key to obtain third information, and generates first message integrity verification information based on the third key, the third information or the fifth information, and the first challenge information; or generates second message integrity verification information based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0476] S830: The first terminal device sends the second information, wherein the second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information; optionally, the second information also includes at least one of the following: the identification of the first terminal device, the second challenge information, and the first algorithm information.
[0477] S840: The first communication device performs a target operation;
[0478] The target operation includes at least one of the following:
[0479] decrypting the third information based on the second key;
[0480] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and the first challenge information;
[0481] The second message integrity verification information is verified based on the fourth key, the fourth information or the sixth information, and the first challenge information.
[0482] It should be noted that for the explanation of the various information in this example, please refer to the above and will not be repeated here.
[0483] It should be understood that in this example, the first terminal device can send the second information through a NAS message, that is, the wireless communication method provided in Example 4 includes a NAS interaction, then the first terminal device and the core network can interact for one step, and the first terminal device can then access the network and transmit information. Since the interaction steps between the first terminal device and the core network are reduced, the efficiency of the first terminal device accessing the network can be improved.
[0484] The wireless communication method provided in the embodiment of the present application can be executed by a wireless communication device. In the embodiment of the present application, the wireless communication device provided in the embodiment of the present application is described by taking the wireless communication method executed by the wireless communication device as an example.
[0485] FIG9 is a schematic diagram of a wireless communication device 900 provided in an embodiment of the present application. The device 900 may be a first terminal device. As shown in FIG9 , the device 900 includes: a communication module 910 configured to:
[0486] Receive first information; wherein the first information includes: first challenge information;
[0487] Sending first authentication information and second information to the first communication node;
[0488] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0489] The first authentication information is generated based on the first challenge information and the first key;
[0490] The third information is generated by encrypting the fifth information based on the second key;
[0491] The first message integrity check information is generated based on the third key, the third information or the fifth information, and at least one of the following:
[0492] First challenge information;
[0493] First authentication information;
[0494] The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following:
[0495] First challenge information;
[0496] First authentication information;
[0497] The sixth information is the encrypted information of the fourth information.
[0498] In some implementations, the communication module 910 is specifically configured to:
[0499] receiving first information broadcast or sent by a second communication node; or,
[0500] First information is received from a first communication node.
[0501] In some implementations, the second communication node is a base station system or a second terminal device.
[0502] In some possible implementations, the second information also includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; wherein the first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
[0503] In some implementations, the communication module 910 is also used to: receive seventh information from the first communication node after sending the first authentication information to the first communication node and before sending the second information to the first communication node; accordingly, the communication module 910 is specifically used to: send the second information to the first communication node based on the seventh information; wherein the seventh information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0504] In some implementations, the first information further includes at least one of the following: second authentication information, and second algorithm information.
[0505] In some implementations, the communication module 910 is further used to: receive eighth information sent by the first communication node; wherein the eighth information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0506] In some implementations, the communication module 910 is further configured to: receive tenth information sent by the first communication node; wherein the tenth information includes: the ninth information and the third message integrity check information.
[0507] In some implementations, the second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node, and the algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, authentication information generation algorithm.
[0508] In some implementations, the apparatus 900 further includes a processing module 920 configured to perform at least one of the following:
[0509] verifying the second authentication information based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information;
[0510] verifying the third message integrity check information based on the seventh key and the ninth information;
[0511] verifying the third message integrity check information based on the seventh key and the eleventh information;
[0512] decrypting the ninth information based on the sixth key;
[0513] The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information;
[0514] The fifth key is known by the first terminal device.
[0515] In some implementations, verifying the third message integrity verification information based on the seventh key and the ninth information includes: verifying the third message integrity verification information based on the seventh key, the ninth information, and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0516] Verifying the third message integrity verification information based on the seventh key and the eleventh information includes: verifying the third message integrity verification information based on the seventh key, the eleventh information, and at least one of the following: the seventh key, the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or
[0517] Decrypting the ninth information based on the sixth key includes: decrypting the ninth information based on the sixth key and at least one of the following: first challenge information, second challenge information, first authentication information, second authentication information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0518] In some implementations, the second key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0519] The third key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0520] The fourth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0521] The sixth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0522] The seventh key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key.
[0523] In some implementations, the second key is further generated based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information; or,
[0524] The third key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or
[0525] The fourth key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0526] The sixth key is further derived based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0527] The seventh key is also derived based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0528] In some implementations, the first authentication information is further generated based on at least one of the following: second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information; or,
[0529] The first message integrity check information is further generated based on at least one of the following: the second authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or
[0530] The second message integrity verification information is also generated based on at least one of the following: second authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0531] In some implementations, the third information is also generated based on encryption of at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0532] The wireless communication device in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or chip. The electronic device can be a terminal or other device other than a terminal. For example, the terminal can include but is not limited to the types of the first terminal device listed above, and the other device can be a server, a network attached storage (NAS), etc., which is not specifically limited in the embodiments of the present application.
[0533] The wireless communication device provided in the embodiment of the present application can implement the various processes implemented by the first terminal device in the method embodiments shown in Figures 3 to 6, and achieve the same technical effects. To avoid repetition, they will not be repeated here.
[0534] FIG10 is a schematic diagram of a wireless communication device 1000 provided in an embodiment of the present application. The device 1000 may be a first communication node. As shown in FIG10 , the device 1000 includes: a communication module 1010 and a processing module 1020 .
[0535] The communication module 1010 is used to:
[0536] Send the first message by any of the following:
[0537] Sending first information to the first terminal device;
[0538] forwarding or broadcasting the first information through the second communication node;
[0539] After sending the first information, the communication module 1010 is further configured to:
[0540] Receiving first authentication information and second information sent by the first terminal device;
[0541] The first information includes: first challenge information;
[0542] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0543] The processing module 1020 is used to:
[0544] performing a first operation and a second operation;
[0545] The first operation includes verifying the first authentication information based on the third authentication information;
[0546] The second operation includes at least one of the following:
[0547] decrypting the third information based on the second key;
[0548] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information;
[0549] verifying the second message integrity verification information based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information;
[0550] The fifth information is generated by decrypting the third information based on the second key;
[0551] The sixth information is the encrypted information of the fourth information;
[0552] The third authentication information is generated based on the first key and the first challenge information, and the first key is known to the first terminal device.
[0553] In some implementations, the second communication node is a base station system or a second first terminal device.
[0554] In some possible implementations, the second information also includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; wherein the first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
[0555] In some implementations, the communication module 1010 is further configured to: after receiving the first authentication information sent by the first terminal device and before receiving the second information sent by the first terminal device, send seventh information to the first terminal device;
[0556] The seventh information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0557] In some implementations, the first information further includes at least one of the following: second authentication information, and second algorithm information.
[0558] In some implementations, the communication module 1010 is further used to: send eighth information to the first terminal device; wherein the eighth information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0559] In some implementations, the communication module 1010 is further used to: send tenth information to the first terminal device; wherein the tenth information includes: the ninth information and the third message integrity verification information.
[0560] In some implementations, the second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node, and the algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, authentication information generation algorithm.
[0561] In some implementations, the second authentication information is generated based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0562] The third message integrity check information is generated based on the seventh key and the ninth information; or,
[0563] The third message integrity check information is generated based on the seventh key and the eleventh information; or,
[0564] The ninth information is generated by encrypting based on the sixth key;
[0565] The eleventh information is the encrypted version of the ninth information, or the encrypted version of the eleventh information is the ninth information;
[0566] The fifth key is known by the first terminal device.
[0567] In some implementations, the third message integrity check information is further generated based on at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0568] The ninth information is also generated by encryption based on at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0569] In some implementations, the second key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0570] The third key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0571] The fourth key is the first key, or the fifth key, or a derivative of the first key, or a derivative of the fifth key; or,
[0572] The sixth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0573] The seventh key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key.
[0574] In some implementations, the second key is further generated based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information; or,
[0575] The third key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or
[0576] The fourth key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0577] The sixth key is further derived based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0578] The seventh key is also derived based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0579] In some implementations, the third authentication information is further generated based on at least one of the following: the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0580] In some implementations, the processing module 1020 is further used to: verify the first message integrity verification information based on at least one of the following: second authentication information, second challenge information, the identifier of the first terminal device, first algorithm information, and second algorithm information; or, verify the second message integrity verification information based on at least one of the following: second authentication information, second challenge information, the identifier of the first terminal device, first algorithm information, and second algorithm information.
[0581] In some implementations, the processing module 1020 is further used to: decrypt third information based on at least one of the following: first challenge information, first authentication information, second challenge information, second authentication information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0582] The wireless communication device in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or chip. The electronic device can be a communication node or other device other than a communication device. For example, the communication node can include but is not limited to the first communication node listed above, and the other device can be a server, NAS, etc., which is not specifically limited in the embodiments of the present application.
[0583] The wireless communication device provided in the embodiment of the present application can implement the various processes implemented by the first communication node in the method embodiments shown in Figures 3 to 6, and achieve the same technical effects. To avoid repetition, they will not be described here.
[0584] FIG11 is a schematic diagram of a wireless communication device 1100 provided in an embodiment of the present application. The device 1100 may be a first terminal device. As shown in FIG11 , the device 1100 includes: a communication module 1110 configured to:
[0585] Receive first information; wherein the first information includes: first challenge information;
[0586] sending second information to the first communication node;
[0587] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0588] The third information is generated by encrypting the fifth information based on the second key;
[0589] The first message integrity check information is generated based on the third key, the third information or the fifth information, and the first challenge information;
[0590] The second message integrity verification information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0591] The sixth information is the encrypted information of the fourth information.
[0592] In some implementations, the communication module 1110 is specifically configured to:
[0593] receiving first information broadcast or sent by a second communication node; or,
[0594] First information is received from a first communication node.
[0595] In some implementations, the second communication node is a base station system or a second terminal device.
[0596] In some possible implementations, the second information also includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; wherein the first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
[0597] In some implementations, the communication module 1110 is also used to: receive seventh information from the first communication node before sending the second information to the first communication node; accordingly, the communication module 1110 is specifically used to: send the second information to the first communication node based on the seventh information; wherein the seventh information includes at least one of the following: authentication information, second algorithm information.
[0598] In some implementations, the communication module 1110 is further used to: receive eighth information sent by the first communication node; wherein the eighth information includes at least one of the following: authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0599] In some implementations, the communication module 1110 is further configured to: receive tenth information sent by the first communication node; wherein the tenth information includes: the ninth information and the third message integrity verification information.
[0600] In some implementations, the second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node, and the algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, authentication information generation algorithm.
[0601] In some implementations, the apparatus 1100 further includes a processing module 1120 configured to perform at least one of the following:
[0602] verifying the authentication information based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information;
[0603] Verifying the third message integrity verification information based on the seventh key and the ninth information, or verifying the third message integrity verification information based on the seventh key and the eleventh information;
[0604] decrypting the ninth information based on the sixth key;
[0605] The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information;
[0606] The fifth key is known by the first terminal device.
[0607] In some implementations, verifying the third message integrity verification information based on the seventh key and the ninth information includes: verifying the third message integrity verification information based on the seventh key, the ninth information, and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0608] Verifying the third message integrity verification information based on the seventh key and the eleventh information includes: verifying the third message integrity verification information based on the seventh key, the eleventh information, and at least one of the following: the seventh key, the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or
[0609] Decrypting the ninth information based on the sixth key includes: decrypting the ninth information based on the sixth key and at least one of the following: first challenge information, second challenge information, authentication information, identification of the first terminal device, first algorithm information, and second algorithm information.
[0610] In some implementations, the second key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0611] The third key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0612] The fourth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0613] The sixth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0614] The seventh key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key.
[0615] In some implementations, the second key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0616] The third key is also generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0617] The fourth key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0618] The sixth key is further derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0619] The seventh key is also derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0620] In some implementations, the first message integrity check information is further generated based on at least one of the following: authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information; or,
[0621] The second message integrity verification information is also generated based on at least one of the following: authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0622] In some implementations, the third information is further generated by encryption based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the terminal device, the first algorithm information, and the second algorithm information.
[0623] The wireless communication device in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or chip. The electronic device can be a terminal or other device other than a terminal. For example, the terminal can include but is not limited to the types of the first terminal device listed above, and the other device can be a server, a network attached storage (NAS), etc., which is not specifically limited in the embodiments of the present application.
[0624] The wireless communication device provided in the embodiment of the present application can implement the various processes implemented by the first terminal device in the method embodiments shown in Figures 7 to 8, and achieve the same technical effects. To avoid repetition, they will not be repeated here.
[0625] FIG12 is a schematic diagram of a wireless communication device 1200 provided in an embodiment of the present application. The device 1200 may be a first communication node. As shown in FIG12 , the device 1200 includes: a communication module 1210 and a processing module 1220 .
[0626] The communication module 1210 is used to:
[0627] Send the first message by any of the following:
[0628] Sending first information to the first terminal device;
[0629] forwarding or broadcasting the first information through the second communication node;
[0630] After sending the first information, the communication module is further configured to:
[0631] receiving second information sent by the first terminal device;
[0632] The first information includes: first challenge information;
[0633] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0634] The processing module 1220 is used to:
[0635] Execute the target operation;
[0636] The target operation includes at least one of the following:
[0637] decrypting the third information based on the second key;
[0638] verifying the first message integrity verification information based on the third key, the third information or the fifth information, and the first challenge information;
[0639] verifying the second message integrity verification information based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0640] The fifth information is generated by decrypting the third information based on the second key;
[0641] The sixth information is the encrypted information of the fourth information.
[0642] In some implementations, the second communication node is a base station system or a second terminal device.
[0643] In some possible implementations, the second information also includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; wherein the first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
[0644] In some implementations, the communication module 1210 is further used to: before receiving the second information sent by the first terminal device, send seventh information to the first terminal device; wherein the seventh information includes at least one of the following: authentication information, second algorithm information.
[0645] In some implementations, the communication module 1210 is further used to: send eighth information to the first terminal device; wherein the eighth information includes at least one of the following: authentication information, second algorithm information, ninth information, and third message integrity verification information.
[0646] In some implementations, the communication module 1210 is further used to: send tenth information to the first terminal device; wherein the tenth information includes: the ninth information and the third message integrity verification information.
[0647] In some implementations, the second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node, and the algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, authentication information generation algorithm.
[0648] In some implementations, the authentication information is generated based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0649] The third message integrity check information is generated based on the seventh key and the ninth information; or,
[0650] The third message integrity check information is generated based on the seventh key and the eleventh information; or,
[0651] The ninth information is generated by encrypting based on the sixth key;
[0652] The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information;
[0653] The fifth key is known by the first terminal device.
[0654] In some implementations, the third message integrity check information is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0655] The ninth information is also generated by encryption based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0656] In some implementations, the second key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0657] The third key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0658] The fourth key is the first key, or the fifth key, or a derivative of the first key, or a derivative of the fifth key; or,
[0659] The sixth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or,
[0660] The seventh key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key;
[0661] The first key is known by the first terminal device.
[0662] In some implementations, the second key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0663] The third key is also generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0664] The fourth key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0665] The sixth key is further derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or,
[0666] The seventh key is also derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
[0667] In some implementations, the processing module 1220 is further configured to: verify the first message integrity verification information based on at least one of the following: authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information; or,
[0668] The second message integrity verification information is verified based on at least one of the following: authentication information, second challenge information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0669] In some implementations, the processing module 1220 is further configured to: decrypt third information based on at least one of the following: first challenge information, second challenge information, authentication information, an identifier of the first terminal device, first algorithm information, and second algorithm information.
[0670] The wireless communication device in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or chip. The electronic device can be a communication node or other device other than a communication device. For example, the communication node can include but is not limited to the first communication node listed above, and the other device can be a server, NAS, etc., which is not specifically limited in the embodiments of the present application.
[0671] The wireless communication device provided in the embodiment of the present application can implement the various processes implemented by the first communication node in the method embodiments shown in Figures 7 to 8, and achieve the same technical effects. To avoid repetition, they will not be repeated here.
[0672] Figure 13 is a schematic block diagram of a communication device provided in an embodiment of the present application; as shown in Figure 13, an embodiment of the present application further provides a communication device 1300, including a processor 1301 and a memory 1302, wherein the memory 1302 stores a program or instruction that can be run on the processor 1301. For example, when the communication device 1300 is a terminal, the program or instruction is executed by the processor 1301 to implement the various steps performed by the target terminal in the method embodiments shown in Figures 3 to 8 above, and can achieve the same technical effect. When the communication device 1300 is a first terminal device, the program or instruction is executed by the processor 1301 to implement the various steps performed by the first terminal device in the method embodiments shown in Figures 3 to 8 above, and can achieve the same technical effect. To avoid repetition, it is not repeated here. When the communication device 1300 is a first communication node, the program or instruction is executed by the processor 1301 to implement the various steps performed by the first communication node in the method embodiments shown in Figures 3 to 8 above, and can achieve the same technical effect. To avoid repetition, it is not repeated here.
[0673] The present application also provides a terminal comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the various steps performed by the first terminal device in the method embodiments shown in Figures 3 to 8 above. This terminal embodiment corresponds to the aforementioned terminal-side method embodiment, and the various implementation processes and implementation methods of the aforementioned method embodiments are applicable to this terminal embodiment and can achieve the same technical effects. Specifically, Figure 14 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application.
[0674] The terminal 1000 includes but is not limited to: a radio frequency unit 1401, a network module 1402, an audio output unit 1403, an input unit 1404, a sensor 1405, a display unit 1406, a user input unit 1407, an interface unit 1408, a memory 1409 and at least some of the components of the processor 1410.
[0675] Those skilled in the art will appreciate that the terminal 1000 may also include a power supply (such as a battery) to power various components. The power supply may be logically connected to the processor 1410 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The terminal structure shown in FIG14 does not limit the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be described in detail here.
[0676] It should be understood that in an embodiment of the present application, the input unit 1404 may include a graphics processing unit (GPU) 14041 and a microphone 14042, and the graphics processor 14041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 1406 may include a display panel 14061, and the display panel 10061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 1407 includes a touch panel 14071 and at least one of other input devices 14072. The touch panel 14071 is also called a touch screen. The touch panel 14071 may include two parts: a touch detection device and a touch controller. Other input devices 14072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and an operating stick, which will not be repeated here.
[0677] In the embodiment of the present application, after receiving downlink data from a network device, the radio frequency unit 1401 may transmit the data to the processor 1410 for processing. Furthermore, the radio frequency unit 1401 may send uplink data to the network device. Typically, the radio frequency unit 1401 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.
[0678] The memory 1409 can be used to store software programs or instructions and various data. The memory 1409 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 1409 may include a volatile memory or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DRRAM). The memory 1409 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
[0679] Processor 1410 may include one or more processing units. Optionally, processor 1410 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 1410.
[0680] The radio frequency unit 1401 is used for:
[0681] Receive first information; wherein the first information includes: first challenge information;
[0682] Sending first authentication information and second information to the first communication node;
[0683] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0684] The first authentication information is generated based on the first challenge information and the first key;
[0685] The third information is generated by encrypting the fifth information based on the second key;
[0686] The first message integrity check information is generated based on the third key, the third information or the fifth information, and at least one of the following:
[0687] First challenge information;
[0688] First authentication information;
[0689] The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following:
[0690] First challenge information;
[0691] First authentication information;
[0692] The sixth information is the encrypted information of the fourth information.
[0693] or,
[0694] The radio frequency unit 1401 is used for:
[0695] Receive first information; wherein the first information includes: first challenge information;
[0696] sending second information to the first communication node;
[0697] The second information includes: the third information and the first message integrity verification information; or the second information includes: the fourth information and the second message integrity verification information;
[0698] The third information is generated by encrypting the fifth information based on the second key;
[0699] The first message integrity check information is generated based on the third key, the third information or the fifth information, and the first challenge information;
[0700] The second message integrity verification information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information;
[0701] The sixth information is the encrypted information of the fourth information.
[0702] It can be understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the corresponding method embodiment on the terminal side, and achieve the same or corresponding technical effect. To avoid repetition, it will not be repeated here.
[0703] An embodiment of the present application further provides a communication device, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the various processes implemented by the first communication node in the method embodiments shown in Figures 3 to 8. This communication device embodiment corresponds to the method embodiment executed by the first communication node, and each implementation process and implementation method of the aforementioned method embodiment are applicable to this communication device embodiment and can achieve the same technical effects.
[0704] Specifically, an embodiment of the present application further provides a communication device. As shown in Figure 15, the communication device 1500 includes: an antenna 151, a radio frequency device 152, a baseband device 153, a processor 154, and a memory 155. The antenna 151 is connected to the radio frequency device 152. In the uplink direction, the radio frequency device 152 receives information via the antenna 151 and sends the received information to the baseband device 153 for processing. In the downlink direction, the baseband device 153 processes the information to be transmitted and sends it to the radio frequency device 152. The radio frequency device 152 processes the received information and then sends it through the antenna 151.
[0705] The method executed by the communication device in the above embodiment may be implemented in the baseband device 153 , which includes a baseband processor.
[0706] The baseband device 153 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 15, one of the chips is, for example, a baseband processor, which is connected to the memory 155 through a bus interface to call the program in the memory 155 and execute the communication device operations shown in the above method embodiment.
[0707] The communication device may further include a network interface 156 , such as a Common Public Radio Interface (CPRI).
[0708] Specifically, the communication device 1500 of the embodiment of the present application also includes: instructions or programs stored in the memory 155 and executable on the processor 154. The processor 154 calls the instructions or programs in the memory 155 to execute the steps performed by the first communication node in the method embodiments shown in Figures 3 to 8, and achieves the same technical effect. To avoid repetition, they will not be described here.
[0709] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the method embodiments shown in Figures 3 to 8 above are implemented, and the same technical effect can be achieved. To avoid repetition, they will not be repeated here.
[0710] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0711] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the method embodiments shown in Figures 3 to 8 above, and can achieve the same technical effects. To avoid repetition, they will not be repeated here.
[0712] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0713] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the method embodiments shown in Figures 3 to 8 above, and can achieve the same technical effects. To avoid repetition, they are not described here.
[0714] An embodiment of the present application also provides a wireless communication system, including: a first terminal device and a first communication node, wherein the first terminal device can be used to execute the various processes corresponding to the first terminal device in the method embodiments shown in Figures 3 to 8 as described above, and the first communication node can be used to execute the various processes corresponding to the first communication node in the method embodiments shown in Figures 3 to 8 as described above.
[0715] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0716] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for causing the terminal or the first communication device to execute the methods described in each embodiment of the present application.
[0717] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.
Claims
1. A wireless communication method, wherein: include: The first terminal device receives first information; wherein the first information includes: first challenge information; The first terminal device sends first authentication information and second information to the first communication node; The second information includes: the third information and the first message integrity check information; or the second information includes: the fourth information and the second message integrity check information; Wherein, the first authentication information is generated based on the first challenge information and a first key; The third information is generated by encrypting the fifth information based on the second key; The first message integrity check information is generated based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information; the first authentication information; The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information; the first authentication information; The sixth information is encrypted information of the fourth information.
2. The method according to claim 1, wherein The first terminal device receives the first information, including: The first terminal device receives the first information broadcast or sent by the second communication node; or, The first terminal device receives the first information from the first communication node.
3. The method according to claim 2, wherein: The second communication node is a base station system or a second terminal device.
4. The method according to any one of claims 1 to 3, wherein: The second information further includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
5. The method according to any one of claims 1 to 4, wherein: After the first terminal device sends the first authentication information to the first communication node and before the first terminal device sends the second information to the first communication node, the method further includes: The first terminal device receives seventh information from the first communication node; The first terminal device sending the second information to the first communication node includes: The first terminal device sends the second information to the first communication node based on the seventh information; The seventh information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
6. The method according to any one of claims 1 to 4, wherein: The first information also includes at least one of the following: second authentication information and second algorithm information.
7. The method according to any one of claims 1 to 4, wherein: The method further comprises: The first terminal device receives the eighth information sent by the first communication node; wherein the eighth information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
8. The method according to claim 5 or 6, wherein: The method further comprises: The first terminal device receives the tenth information sent by the first communication node; wherein the tenth information includes: the ninth information and the third message integrity verification information.
9. The method according to any one of claims 5 to 8, wherein: The second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node. The algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, and authentication information generation algorithm.
10. The method according to any one of claims 5 to 9, wherein: The method further comprises: The first terminal device performs at least one of the following: verifying the second authentication information based on a fifth key and at least one of the following: the first challenge information, the second challenge information, an identifier of the first terminal device, the first algorithm information, and the second algorithm information; verifying the third message integrity check information based on the seventh key and the ninth information; verifying the third message integrity check information based on the seventh key and the eleventh information; decrypting the ninth information based on the sixth key; The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information.
11. The method according to claim 10, wherein: The verifying the third message integrity check information based on the seventh key and the ninth information includes: verifying the third message integrity check information based on the seventh key, the ninth information, and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or, The verifying the third message integrity check information based on the seventh key and the eleventh information includes: verifying the third message integrity check information based on the seventh key, the eleventh information, and at least one of the following: the seventh key, the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or, The decrypting the ninth information based on the sixth key includes: decrypting the ninth information based on the sixth key and at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identification of the first terminal device, the first algorithm information, and the second algorithm information.
12. The method according to any one of claims 1 to 11, wherein: The second key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or The third key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or, The fourth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or The sixth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or The seventh key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
13. The method according to claim 12, wherein: The second key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The third key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The fourth key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The sixth key is further derived based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The seventh key is also derived based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
14. The method according to any one of claims 4 to 13, wherein: The first authentication information is further generated based on at least one of the following: the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The first message integrity check information is further generated based on at least one of the following: the second authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The second message integrity check information is also generated based on at least one of the following: the second authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
15. The method according to any one of claims 1 to 14, wherein: The third information is also generated by encryption based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
16. The method according to claim 1, wherein the first message integrity check information or the second message integrity check information is the first authentication information.
17. A wireless communication method, wherein: include: The first communication node sends the first information by any of the following methods: Sending the first information to a first terminal device; forwarding or broadcasting the first information through a second communication node; After the first communication node sends the first information, the method further includes: The first communication node receives first authentication information and second information sent by the first terminal device; Wherein, the first information includes: first challenge information; The second information includes: the third information and the first message integrity check information; or the second information includes: the fourth information and the second message integrity check information; The first communication node performs a first operation and a second operation; The first operation includes verifying the first authentication information based on third authentication information; The second operation includes at least one of the following: decrypting the third information based on the second key; verifying the first message integrity verification information based on a third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information; verifying the second message integrity verification information based on a fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information; The fifth information is generated by decrypting the third information based on the second key; Wherein, the sixth information is the encrypted information of the fourth information; The third authentication information is generated based on a first key and the first challenge information, and the first key is known by the first terminal device.
18. The method according to claim 17, wherein The second communication node is a base station system or a second first terminal device.
19. The method according to claim 17 or 18, wherein The second information further includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
20. The method according to any one of claims 17 to 19, wherein: After the first communication node receives the first authentication information sent by the first terminal device, and before the first communication node receives the second information sent by the first terminal device, the method further includes: The first communication node sends seventh information to the first terminal device; The seventh information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
21. The method according to any one of claims 17 to 19, wherein: The first information also includes at least one of the following: second authentication information and second algorithm information.
22. The method according to any one of claims 17 to 19, wherein: The method further comprises: The first communication node sends eighth information to the first terminal device; wherein the eighth information includes at least one of the following: second authentication information, second algorithm information, ninth information, and third message integrity verification information.
23. The method according to claim 20 or 21, wherein The method further comprises: The first communication node sends tenth information to the first terminal device; wherein the tenth information includes: ninth information and third message integrity verification information.
24. The method according to any one of claims 20 to 23, wherein: The second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node. The algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, and authentication information generation algorithm.
25. The method according to any one of claims 20 to 24, wherein: The second authentication information is generated based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The third message integrity check information is generated based on the seventh key and the ninth information; or, The third message integrity check information is generated based on the seventh key and the eleventh information; or, The ninth information is generated by encrypting based on the sixth key; The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information; The fifth key is known by the first terminal device.
26. The method according to claim 25, wherein The third message integrity check information is further generated based on at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or, The ninth information is also generated by encryption based on at least one of the following: the first challenge information, the second challenge information, the first authentication information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
27. The method according to any one of claims 17 to 26, wherein: The second key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or The third key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or, The fourth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or The sixth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or The seventh key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
28. The method according to claim 27, wherein The second key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The third key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The fourth key is further generated based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The sixth key is further derived based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The seventh key is also derived based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
29. The method according to any one of claims 19 to 28, wherein: The third authentication information is also generated based on at least one of the following: the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
30. The method according to any one of claims 19 to 29, wherein: The method further comprises: The first communication node further verifies the first message integrity verification information based on at least one of the following: the second authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The first communication node also verifies the second message integrity verification information based on at least one of the following: the second authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
31. The method according to any one of claims 17 to 30, wherein: The method further comprises: The first communication node also decrypts the third information based on at least one of the following: the first challenge information, the first authentication information, the second challenge information, the second authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
32. The method according to claim 17, wherein the first message integrity check information or the second message integrity check information is the first authentication information.
33. A wireless communication method, wherein: include: The first terminal device receives first information; wherein the first information includes: first challenge information; The first terminal device sends second information to the first communication node; The second information includes: the third information and the first message integrity check information; or the second information includes: the fourth information and the second message integrity check information; The third information is generated by encrypting the fifth information based on the second key; The first message integrity check information is generated based on the third key, the third information or the fifth information, and the first challenge information; The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information; The sixth information is encrypted information of the fourth information.
34. The method according to claim 33, wherein The first terminal device receives the first information, including: The first terminal device receives the first information broadcast or sent by the second communication node; or, The first terminal device receives the first information from the first communication node.
35. The method according to claim 34, wherein The second communication node is a base station system or a second terminal device.
36. The method according to any one of claims 33 to 35, wherein: The second information further includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
37. The method according to any one of claims 33 to 36, wherein: Before the first terminal device sends the second information to the first communication node, the method further includes: The first terminal device receives seventh information from the first communication node; The first terminal device sending second information to the first communication node includes: The first terminal device sends the second information to the first communication node based on the seventh information; The seventh information includes at least one of the following: authentication information and second algorithm information.
38. The method according to any one of claims 33 to 36, wherein: The method further comprises: The first terminal device receives the eighth information sent by the first communication node; wherein the eighth information includes at least one of the following: authentication information, second algorithm information, ninth information, and third message integrity verification information.
39. The method of claim 37, wherein: The method further comprises: The first terminal device receives the tenth information sent by the first communication node; wherein the tenth information includes: the ninth information and the third message integrity verification information.
40. The method according to any one of claims 37 to 39, wherein: The second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node. The algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, and authentication information generation algorithm.
41. The method according to any one of claims 37 to 40, wherein: The method further comprises: The first terminal device performs at least one of the following: verifying the authentication information based on a fifth key and at least one of the following: the first challenge information, the second challenge information, an identifier of the first terminal device, the first algorithm information, and the second algorithm information; verifying the third message integrity check information based on the seventh key and the ninth information, or verifying the third message integrity check information based on the seventh key and the eleventh information; decrypting the ninth information based on the sixth key; The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information.
42. The method according to claim 41, wherein The verifying the third message integrity check information based on the seventh key and the ninth information includes: verifying the third message integrity check information based on the seventh key, the ninth information, and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or, The verifying the third message integrity check information based on the seventh key and the eleventh information includes: verifying the third message integrity check information based on the seventh key, the eleventh information, and at least one of the following: the seventh key, the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or, The decrypting the ninth information based on the sixth key includes: decrypting the ninth information based on the sixth key and at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
43. The method according to any one of claims 33 to 42, wherein: The second key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or The third key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or, The fourth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or, The sixth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or, The seventh key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key.
44. The method according to claim 43, wherein The second key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The third key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The fourth key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The sixth key is further derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The seventh key is also derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
45. The method according to any one of claims 36 to 44, wherein: The first message integrity check information is further generated based on at least one of the following: the authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The second message integrity check information is also generated based on at least one of the following: the authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
46. The method according to any one of claims 33 to 45, wherein: The third information is also generated by encryption based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the terminal device, the first algorithm information, and the second algorithm information.
47. The method according to claim 33, wherein the first message integrity check information or the second message integrity check information is the first authentication information.
48. A wireless communication method, wherein: include: The first communication node sends the first information by any of the following methods: Sending the first information to a first terminal device; forwarding or broadcasting the first information through a second communication node; After the first communication node sends the first information, the method further includes: The first communication node receives second information sent by the first terminal device; Wherein, the first information includes: first challenge information; The second information includes: the third information and the first message integrity check information; or the second information includes: the fourth information and the second message integrity check information; The first communication node performs a target operation; The target operation includes at least one of the following: decrypting the third information based on the second key; verifying the first message integrity verification information based on a third key, the third information or the fifth information, and the first challenge information; verifying the second message integrity verification information based on a fourth key, the fourth information or the sixth information, and the first challenge information; The fifth information is generated by decrypting the third information based on the second key; The sixth information is encrypted information of the fourth information.
49. The method according to claim 48, wherein The second communication node is a base station system or a second terminal device.
50. The method according to claim 48 or 49, wherein The second information further includes at least one of the following: an identifier of the first terminal device, second challenge information, and first algorithm information; The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, and an authentication information generation algorithm.
51. The method according to any one of claims 48 to 50, wherein: Before the first communication node receives the second information sent by the first terminal device, the method further includes: The first communication node sends seventh information to the first terminal device; The seventh information includes at least one of the following: authentication information and second algorithm information.
52. The method according to any one of claims 48 to 50, wherein: The method further comprises: The first communication node sends eighth information to the first terminal device; wherein the eighth information includes at least one of the following: authentication information, second algorithm information, ninth information, and third message integrity verification information.
53. The method of claim 51, wherein The method further comprises: The first communication node sends tenth information to the first terminal device; wherein the tenth information includes: ninth information and third message integrity verification information.
54. The method according to any one of claims 51 to 53, wherein: The second algorithm information is used to indicate the algorithm supported, allowed or selected by the first communication node. The algorithm supported, allowed or selected by the first communication node includes at least one of the following: encryption algorithm, integrity protection algorithm, key derivation algorithm, and authentication information generation algorithm.
55. The method according to any one of claims 51 to 54, wherein: The authentication information is generated based on the fifth key and at least one of the following: the first challenge information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The third message integrity check information is generated based on the seventh key and the ninth information; or, The third message integrity check information is generated based on the seventh key and the eleventh information; or, The ninth information is generated by encrypting based on the sixth key; The eleventh information is the encrypted ninth information, or the eleventh information is the encrypted ninth information; The fifth key is known by the first terminal device.
56. The method of claim 55, wherein: The third message integrity check information is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The ninth information is also generated by encryption based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
57. The method according to any one of claims 48 to 56, wherein: The second key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or The third key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or, The fourth key is the first key, or the fifth key, or a derived key of the first key, or a derived key of the fifth key; or, The sixth key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key; or, The seventh key is the first key, or the fifth key, or a derivative key of the first key, or a derivative key of the fifth key; The first key is known by the first terminal device.
58. The method of claim 57, wherein The second key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The third key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The fourth key is further generated based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The sixth key is further derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The seventh key is also derived based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
59. The method according to any one of claims 50 to 58, wherein: The method further comprises: The first communication node further verifies the first message integrity verification information based on at least one of the following: the authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information; or The first communication node also verifies the second message integrity verification information based on at least one of the following: the authentication information, the second challenge information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
60. The method according to any one of claims 48 to 59, wherein: The method further comprises: The first communication node also decrypts the third information based on at least one of the following: the first challenge information, the second challenge information, the authentication information, the identifier of the first terminal device, the first algorithm information, and the second algorithm information.
61. The method according to claim 48, wherein the first message integrity check information or the second message integrity check information is the first authentication information.
62. A wireless communication device, wherein: include: Communication modules for: Receive first information; wherein the first information includes: first challenge information; Sending first authentication information and second information to the first communication node; The second information includes: the third information and the first message integrity check information; or the second information includes: the fourth information and the second message integrity check information; Wherein, the first authentication information is generated based on the first challenge information and a first key; The third information is generated by encrypting the fifth information based on the second key; The first message integrity check information is generated based on the third key, the third information or the fifth information, and at least one of the following: the first challenge information; the first authentication information; The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information; the first authentication information; The sixth information is encrypted information of the fourth information.
63. A wireless communication device, wherein: include: Communication module and processing module; The communication module is used for: Send the first message by any of the following: Sending the first information to a first terminal device; forwarding or broadcasting the first information through a second communication node; After sending the first information, the communication module is further configured to: receiving first authentication information and second information sent by the first terminal device; Wherein, the first information includes: first challenge information; The second information includes: the third information and the first message integrity check information; or the second information includes: the fourth information and the second message integrity check information; The processing module is used for: performing a first operation and a second operation; The first operation includes verifying the first authentication information based on third authentication information; The second operation includes at least one of the following: decrypting the third information based on the second key; verifying the first message integrity verification information based on a third key, the third information or the fifth information, and at least one of the following: the first challenge information, the first authentication information; verifying the second message integrity verification information based on a fourth key, the fourth information or the sixth information, and at least one of the following: the first challenge information, the first authentication information; The fifth information is generated by decrypting the third information based on the second key; Wherein, the sixth information is the encrypted information of the fourth information; The third authentication information is generated based on a first key and the first challenge information, and the first key is known by the first terminal device.
64. A wireless communication device, wherein: include: Communication modules for: Receive first information; wherein the first information includes: first challenge information; sending second information to the first communication node; The second information includes: the third information and the first message integrity check information; or the second information includes: the fourth information and the second message integrity check information; The third information is generated by encrypting the fifth information based on the second key; The first message integrity check information is generated based on the third key, the third information or the fifth information, and the first challenge information; The second message integrity check information is generated based on the fourth key, the fourth information or the sixth information, and the first challenge information; The sixth information is encrypted information of the fourth information.
65. A wireless communication device, wherein: include: Communication module and processing module; The communication module is used for: Send the first message by any of the following: Sending the first information to a first terminal device; forwarding or broadcasting the first information through a second communication node; After sending the first information, the communication module is further configured to: receiving second information sent by the first terminal device; Wherein, the first information includes: first challenge information; The second information includes: the third information and the first message integrity check information; or the second information includes: the fourth information and the second message integrity check information; The processing module is used for: Execute the target operation; The target operation includes at least one of the following: decrypting the third information based on the second key; verifying the first message integrity verification information based on a third key, the third information or the fifth information, and the first challenge information; verifying the second message integrity verification information based on a fourth key, the fourth information or the sixth information, and the first challenge information; The fifth information is generated by decrypting the third information based on the second key; The sixth information is encrypted information of the fourth information.
66. A terminal device, wherein: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the wireless communication method according to any one of claims 1 to 16 and 33 to 47 are implemented.
67. A communication node, wherein The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the wireless communication method according to any one of claims 17 to 32 and 48 to 61 are implemented.
68. A readable storage medium, wherein: The readable storage medium stores a program or instruction, which, when executed by a processor, implements the wireless communication method according to any one of claims 1 to 16 and 33 to 47, or implements the steps of the wireless communication method according to any one of claims 17 to 32 and 48 to 61.
Citation Information
Patent Citations
An authentication method
CN101641976A
Communication method, device and system
CN115380570A
Sensor network node authentication method, node, system, medium and equipment
CN116208329A
Multiple trusted computing environments with verifiable environment identities
US20020194482A1