Secure communication methods, terminal, UDM, AUSF, AMF, access network device, system and medium
The security capability information is sent to the core network through the terminal, and the actual security capability is determined in combination with the number of bits of USIM and ME. The 256-bit security algorithm is used to solve the problem of insufficient security in the existing communication system, achieving more efficient secure communication.
Patent Information
- Application Number
- PCT/CN2024/078467
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-25
- Publication Date
- 2025-08-28
AI Technical Summary
In the existing communication systems, the negotiation process of the 128-bit security algorithm cannot effectively improve the security of NAS/AS messages, resulting in insufficient communication security.
The terminal sends security capability information to the network function of the core network, combines the first key supported by USIM and the number of bits of the security algorithm supported by ME to determine the actual security capability of the terminal, and uses the corresponding 256-bit security algorithm for integrity protection during the communication process.
It improves the security and efficiency of communication, ensures the accurate determination of security capabilities during communication and the selection of authentication algorithms, and enhances the security of the communication system.
Smart Images

Figure CN2024078467_28082025_PF_FP_ABST
Abstract
Description
Secure communication method, terminal, UDM, AUSF, AMF, access network equipment, system and medium Technical Field
[0001] The present disclosure relates to the field of communication technology, and in particular to secure communication methods, terminals, UDM, AUSF, AMF, access network equipment, systems and media. Background Art
[0002] In related technologies, communication systems support the negotiation process of 128-bit security algorithms. Specifically, network devices use the NAS (Non Access Stratum) SMC (Security Mode Control) process to negotiate a 128-bit security algorithm (e.g., 128-NEA1) with the UE to implement NAS security. Negotiation of AS security for a 128-bit security algorithm (e.g., 128-NEA1) is implemented through the AS (Access Stratum) SMC process.
[0003] In order to improve the security of NAS / AS messages, a 256-bit security algorithm can be introduced into the communication system.
[0004] Summary of the Invention
[0005] How to determine the actual security capabilities of a terminal is a technical problem that needs to be solved.
[0006] The embodiments of the present disclosure provide a secure communication method, terminal, UDM, AUSF, AMF, access network equipment, system and medium.
[0007] According to a first aspect of an embodiment of the present disclosure, a secure communication method is proposed, the method comprising: a terminal sending security capability information to a network function of a core network through an access network.
[0008] According to a second aspect of an embodiment of the present disclosure, a secure communication method is proposed, the method including: a UDM receiving security capability information.
[0009] According to a third aspect of an embodiment of the present disclosure, a secure communication method is proposed, which includes: UDM sending the number of bits of a first key to AUSF, and the AUSF is used to send the number of bits of the first key to AMF.
[0010] According to a fourth aspect of the embodiment of the present disclosure, a secure communication method is proposed, the method comprising: AUSF receiving security capability information sent by AMF; the AUSF sending the security capability information to UDM
[0011] According to the fifth aspect of an embodiment of the present disclosure, a secure communication method is proposed, the method including: an AMF receives security capability information sent by a terminal.
[0012] According to the sixth aspect of an embodiment of the present disclosure, a secure communication method is proposed, the method including: an access network device receives security capability information sent by an AMF.
[0013] According to a seventh aspect of an embodiment of the present disclosure, a terminal is proposed, including: a transceiver module, configured to send security capability information.
[0014] According to an eighth aspect of an embodiment of the present disclosure, a UDM is proposed, including: a transceiver module, configured to receive security capability information.
[0015] According to the ninth aspect of an embodiment of the present disclosure, a UDM is proposed, including: a transceiver module, used to send the number of bits of a first key to the AUSF, and the AUSF is used to send the number of bits of the first key to the AMF.
[0016] According to the tenth aspect of the embodiment of the present disclosure, an AUSF is proposed, including: a transceiver module for receiving security capability information sent by AMF.
[0017] According to the eleventh aspect of an embodiment of the present disclosure, an AMF is proposed, including: a transceiver module for receiving security capability information sent by a terminal.
[0018] According to the twelfth aspect of an embodiment of the present disclosure, an access network device is proposed, including: a transceiver module for receiving security capability information sent by AMF.
[0019] According to the thirteenth aspect of an embodiment of the present disclosure, a communication system is proposed, including a terminal, a UDM, an AUSF, an AMF and an access network device, wherein the terminal is configured to implement the communication method of the first aspect, the UDM is configured to implement the communication method of the second aspect or the third aspect, the AUSF is configured to implement the communication method of the fourth aspect, the AMF is configured to implement the communication method of the fifth aspect, and the access network device is configured to implement the communication method of the sixth aspect.
[0020] According to the fourteenth aspect of an embodiment of the present disclosure, a storage medium is proposed, which stores instructions, and is characterized in that when the instructions are executed on a communication device, the communication device executes the communication method of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the sixth aspect.
[0021] Through the embodiments of the present disclosure, the terminal sends security capability information to the network function of the core network through the access network, which can improve the security of communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following drawings required for describing the embodiments are introduced. The following drawings are merely some embodiments of the present disclosure and do not impose specific limitations on the protection scope of the present disclosure.
[0023] FIG1 is an exemplary schematic diagram of the architecture of a communication system provided according to an embodiment of the present disclosure.
[0024] FIG2A is an interactive diagram illustrating a secure communication method according to an embodiment of the present disclosure.
[0025] FIG2B is an interactive diagram illustrating a secure communication method according to an embodiment of the present disclosure.
[0026] FIG2C is an interactive diagram illustrating a secure communication method according to an embodiment of the present disclosure.
[0027] FIG2D is an interactive diagram illustrating a secure communication method according to an embodiment of the present disclosure.
[0028] FIG3 is a flow chart of a secure communication method according to an embodiment of the present disclosure.
[0029] FIG4A is a flow chart illustrating a secure communication method according to an embodiment of the present disclosure.
[0030] FIG4B is a flow chart illustrating a secure communication method according to an embodiment of the present disclosure.
[0031] FIG4C is a flow chart illustrating a secure communication method according to an embodiment of the present disclosure.
[0032] FIG5A is a schematic flow chart of a secure communication method according to an embodiment of the present disclosure.
[0033] FIG5B is a flow chart illustrating a secure communication method according to an embodiment of the present disclosure.
[0034] FIG5C is a flow chart illustrating a secure communication method according to an embodiment of the present disclosure.
[0035] FIG6A is a flow chart illustrating a secure communication method according to an embodiment of the present disclosure.
[0036] FIG6B is a flow chart illustrating a secure communication method according to an embodiment of the present disclosure.
[0037] FIG6C is a flow chart illustrating a secure communication method according to an embodiment of the present disclosure.
[0038] FIG7 is a flow chart of a secure communication method according to an embodiment of the present disclosure.
[0039] FIG8 is an interactive diagram illustrating a secure communication method according to an embodiment of the present disclosure.
[0040] FIG9A is an interactive diagram illustrating a secure communication method according to an embodiment of the present disclosure.
[0041] FIG9B is an interactive diagram illustrating a secure communication method according to an embodiment of the present disclosure.
[0042] FIG9C is an interactive diagram illustrating a secure communication method according to an embodiment of the present disclosure.
[0043] FIG10A is a schematic structural diagram of a terminal proposed in an embodiment of the present disclosure.
[0044] FIG10B is a schematic diagram of the structure of the UDM proposed in an embodiment of the present disclosure.
[0045] FIG10C is a schematic diagram of the structure of the AUSF proposed in an embodiment of the present disclosure.
[0046] FIG10D is a schematic diagram of the structure of the AMF proposed in an embodiment of the present disclosure.
[0047] FIG10E is a schematic structural diagram of an access network device proposed in an embodiment of the present disclosure.
[0048] FIG11A is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure.
[0049] FIG11B is a schematic diagram of the structure of a chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0050] The embodiments of the present disclosure provide a secure communication method, terminal, UDM, AUSF, AMF, access network equipment, system and medium.
[0051] In a first aspect, an embodiment of the present disclosure proposes a secure communication method, the method comprising: a terminal sending security capability information to a network function of a core network through an access network.
[0052] In the above embodiment, the terminal sends security capability information to the network function of the core network through the access network, which can improve the security of communication.
[0053] In combination with some embodiments of the first aspect, in some embodiments, the security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on at least one of the number of bits of the first key supported by the user identity module USIM of the terminal and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal.
[0054] In combination with some embodiments of the first aspect, in some embodiments, the actual security capability is determined by at least one of the following methods: if the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits and the second number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits and the second number of bits, then the actual security capability of the terminal is determined to support the first capability and support the second capability; wherein, the number of bits of the security algorithm supported by the terminal corresponding to the first capability is the first number of bits, and the number of bits of the security algorithm supported by the terminal corresponding to the second capability is the second number of bits.
[0055] In the above embodiment, when the number of bits of the first key supported by the USIM is inconsistent with the security algorithm supported by the ME, the actual security capability of the terminal can be determined, thereby improving the security of communication.
[0056] In combination with some embodiments of the first aspect, in some embodiments, when the terminal supports the first capability, the security capability information includes at least one of the following: a non-access stratum NAS security algorithm indicator of the first bit number, an access stratum AS security algorithm indicator of the first bit number; an authentication algorithm indicator of the first bit number; an indicator indicating that the terminal supports the security algorithm of the first bit number; the first bit number; when the terminal supports the second capability, the security capability information includes at least one of the following: a non-access stratum NAS security algorithm indicator of the second bit number, an access stratum AS security algorithm indicator of the second bit number; an authentication algorithm indicator of the second bit number; an indicator indicating that the terminal supports the security algorithm of the second bit number; the second bit number.
[0057] In combination with some embodiments of the first aspect, in some embodiments, the actual security capability is determined by the terminal, and the security capability information includes the actual security capability of the terminal.
[0058] In the above embodiment, the terminal can determine the actual security capability of the terminal and report it to the core network, which can improve communication efficiency.
[0059] In combination with some embodiments of the first aspect, in some embodiments, the security capability information is sent after being integrity protected by the terminal through a security algorithm, and the number of bits of the security algorithm is the second number of bits.
[0060] In the above embodiment, the terminal performs integrity protection on the security capability information through a security algorithm, thereby providing communication security.
[0061] In combination with some embodiments of the first aspect, in some embodiments, the security capability information is used to determine an authentication algorithm.
[0062] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: when the security capability information indicates that the terminal supports a security algorithm of a first bit number, the terminal and the UDM perform authentication based on the authentication algorithm of the first bit number selected by the UDM; when the security capability information indicates that the terminal supports a security algorithm of a second bit number, the terminal and the UDM perform authentication based on the authentication algorithm of the second bit number selected by the UDM.
[0063] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: the terminal performs secure communication based on security information; wherein, the security information is determined based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal, and the security information includes first security information and second security information, the first security information is determined by the terminal, and the second security information is determined by the network function of the core network.
[0064] In combination with some embodiments of the first aspect, in some embodiments, the security information is determined based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the ME security algorithm of the terminal in the following manner: if the number of bits of the first key is the second number of bits and the actual security capability of the terminal is to support the second capability, the security information is determined according to the first key and the security algorithm of the second number of bits; if the number of bits of the first key is the second number of bits and the actual security capability of the terminal is to support the first capability, the first key is truncated to generate a first key of the first number of bits, and the security information is determined according to the first key of the first number of bits and the security algorithm of the first number of bits; or, the security information is determined according to the security algorithm of the second number of bits, and the security information is truncated to security information of the first number of bits.
[0065] In combination with some embodiments of the first aspect, in some embodiments, the actual security capability is determined by a network function of a core network, and the security capability information includes security capability information supported by the terminal or the ME of the terminal.
[0066] In combination with some embodiments of the first aspect, in some embodiments, when the terminal or the ME of the terminal supports a security algorithm of a first bit number, the security capability information includes at least one of the following: a non-access stratum NAS security algorithm indicator of a first bit number, an access stratum AS security algorithm indicator of a first bit number; an authentication algorithm indicator of a first bit number; an indicator indicating that the terminal supports the security algorithm of the first bit number; the first bit number; when the terminal or the ME of the terminal supports a security algorithm of a second bit number, the security capability information includes at least one of the following: a non-access stratum NAS security algorithm indicator of a second bit number, an access stratum AS security algorithm indicator of a second bit number; an authentication algorithm indicator of a second bit number; an indicator indicating that the terminal supports the security algorithm of the second bit number; the second bit number.
[0067] In combination with some embodiments of the first aspect, in some embodiments, the network functions of the core network include unified data management UDM, unified data warehouse UDR, authentication credential repository and processing function ARPF, access and mobility management function AMF and at least one of the following.
[0068] In combination with some embodiments of the first aspect, in some embodiments, the network function of the core network includes an AMF, and the AMF is used to receive the number of bits of the first key supported by the USIM sent by the UDM network element or the actual security capability information of the terminal.
[0069] In a second aspect, an embodiment of the present disclosure proposes a secure communication method, the method comprising: a UDM receives security capability information; the security capability information is used to determine the actual security capability of a terminal.
[0070] In combination with some embodiments of the second aspect, in some embodiments, the actual security capability is determined based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0071] In the above embodiment, the actual security capability of the terminal can be determined according to the number of bits of the first key supported by the USIM and the number of bits of the security algorithm supported by the ME, thereby improving the security of communications.
[0072] In combination with some embodiments of the second aspect, in some embodiments, the actual security capability is determined by at least one of the following methods: if the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits and the second number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits and the second number of bits, then the actual security capability of the terminal is determined to support the first capability and support the second capability; wherein, the number of bits of the security algorithm supported by the terminal corresponding to the first capability is the first number of bits, and the number of bits of the security algorithm supported by the terminal corresponding to the second capability is the second number of bits.
[0073] In combination with some embodiments of the second aspect, in some embodiments, the actual security capability is determined by the terminal, and the security capability information includes the actual security capability of the terminal.
[0074] In combination with some embodiments of the second aspect, in some embodiments, the security capability information is sent after being integrity protected by the terminal through a security algorithm, and the number of bits of the security algorithm is the second number of bits.
[0075] In combination with some embodiments of the second aspect, in some embodiments, the security capability information is used to determine an authentication algorithm.
[0076] In combination with some embodiments of the second aspect, in some embodiments, the method also includes: when the security capability information indicates that the terminal supports a security algorithm of a first bit number, the UDM selects an authentication algorithm of the first bit number to authenticate with the terminal; when the security capability information indicates that the terminal supports a security algorithm of a second bit number, the UDM selects an authentication algorithm of the second bit number to authenticate with the terminal.
[0077] In combination with some embodiments of the second aspect, in some embodiments, the method further includes: the UDM determining the security information based on the number of bits of the first key and the number of bits of the security algorithm.
[0078] In combination with some embodiments of the second aspect, in some embodiments, security information is determined based on the number of bits of the first key and the number of bits of the security algorithm, including: if the number of bits of the first key is the second number of bits and the actual security capability of the terminal is to support the second capability, then the security information is determined according to the first key and the security algorithm of the second bit number; if the number of bits of the first key is the second number of bits and the actual security capability of the terminal is to support the first capability, then the first key is truncated to the first key of the first bit number, and the security information is determined according to the first key of the first bit number and the security algorithm of the first bit number; or, the security information is determined according to the security algorithm of the second bit number, and the security information is truncated to the security information of the first bit number.
[0079] In combination with some embodiments of the second aspect, in some embodiments, the actual security capability is determined by the UDM, and the security capability information includes the number of bits of the security algorithm supported by the ME of the terminal.
[0080] In combination with some embodiments of the second aspect, in some embodiments, the method further includes: sending indication information of the actual security capabilities of the terminal to the AMF or access network device through the AUSF.
[0081] In combination with some embodiments of the second aspect, in some embodiments, when the actual security capability of the terminal is to support the first capability, the indication information includes at least one of the following: a non-access stratum NAS security algorithm indicator of the first bit number, an access stratum AS security algorithm indicator of the first bit number; an authentication algorithm indicator of the first bit number; an indicator indicating that the terminal supports the security algorithm of the first bit number; the first bit number; when the actual security capability of the terminal is to support the second capability, the indication information includes at least one of the following: a non-access stratum NAS security algorithm indicator of the second bit number, an access stratum AS security algorithm indicator of the second bit number; an authentication algorithm indicator of the second bit number; an indicator indicating that the terminal supports the security algorithm of the second bit number; the second bit number.
[0082] In combination with some embodiments of the second aspect, in some embodiments, the UDM sends the number of bits of the first key to AUSF, and the AUSF is used to send the number of bits of the first key to AMF.
[0083] In a third aspect, an embodiment of the present disclosure provides a secure communication method, comprising: a UDM sending a number of bits of a first key to an AUSF, and the AUSF sending the number of bits of the first key to an AMF.
[0084] In a fourth aspect, an embodiment of the present disclosure proposes a secure communication method, where AUSF receives security capability information sent by AMF; and the AUSF sends the security capability information to UDM.
[0085] In combination with some embodiments of the fourth aspect, in some embodiments, the security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0086] In combination with some embodiments of the fourth aspect, in some embodiments, the method also includes: the AUSF receives the number of bits of the first key sent by the UDM or the actual security capability of the terminal; the AUSF sends the number of bits of the first key or the actual security capability of the terminal to the AMF.
[0087] In combination with some embodiments of the fourth aspect, in some embodiments, the security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0088] In combination with some embodiments of the fourth aspect, in some embodiments, when the ME of the terminal supports the first capability, the security capability information includes at least one of the following: a non-access stratum NAS security algorithm indicator of the first bit number, an access stratum AS security algorithm indicator of the first bit number; an authentication algorithm indicator of the first bit number; an indicator indicating that the terminal supports the security algorithm of the first bit number; the first bit number; when the ME of the terminal supports the second capability, the security capability information includes at least one of the following: a non-access stratum NAS security algorithm indicator of the second bit number, an access stratum AS security algorithm indicator of the second bit number; an authentication algorithm indicator of the second bit number; an indicator indicating that the terminal supports the security algorithm of the second bit number; the second bit number.
[0089] In a fifth aspect, an embodiment of the present disclosure proposes a secure communication method, in which the AMF receives security capability information sent by the terminal.
[0090] In combination with some embodiments of the fifth aspect, in some embodiments, the security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0091] In combination with some embodiments of the fifth aspect, in some embodiments, the method also includes: the AMF sends the security capability information to the AUSF.
[0092] In combination with some embodiments of the fifth aspect, in some embodiments, the method also includes at least one of the following: the AMF receives the number of bits of the first key sent by the AUSF or the actual security capability of the terminal; the AMF sends the number of bits of the first key or the actual security capability of the terminal to the access network device.
[0093] In combination with some embodiments of the fifth aspect, in some embodiments, the AMF determines the actual security capability based on the number of bits of the first key and the number of bits of the security algorithm; or, the AMF determines the actual security capability based on the number of bits of the first key and the number of bits of the security algorithm; wherein the security capability information sent by the terminal includes the number of bits of the first key.
[0094] In combination with some embodiments of the fifth aspect, in some embodiments, the method also includes at least one of the following: the AMF receives the actual security capabilities of the terminal sent by the AUSF; the AMF sends the actual security capabilities of the terminal to the access network device.
[0095] In combination with some embodiments of the fifth aspect, in some embodiments, the actual security capability is determined by at least one of the following methods: if the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits and the second number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits and the second number of bits, then the actual security capability of the terminal is determined to support the first capability and support the second capability; wherein, the number of bits of the security algorithm supported by the terminal corresponding to the first capability is the first number of bits, and the number of bits of the security algorithm supported by the terminal corresponding to the second capability is the second number of bits.
[0096] In combination with some embodiments of the fifth aspect, in some embodiments, the security capability information includes actual security capabilities of the terminal.
[0097] In the sixth aspect, an embodiment of the present disclosure proposes a secure communication method, in which an access network device receives security capability information sent by AMF.
[0098] In combination with some embodiments of the sixth aspect, in some embodiments, the security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0099] In combination with some embodiments of the sixth aspect, in some embodiments, the security capability information includes the number of bits of the first key, and the actual security capability is determined by the access network device.
[0100] In combination with some embodiments of the sixth aspect, in some embodiments, the actual security capability is determined by at least one of the following methods: if the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits and the second number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits, then the actual security capability of the terminal is determined to support the first capability; if the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile device ME of the terminal is the first number of bits and the second number of bits, then the actual security capability of the terminal is determined to support the first capability and support the second capability; wherein, the number of bits of the security algorithm supported by the terminal corresponding to the first capability is the first number of bits, and the number of bits of the security algorithm supported by the terminal corresponding to the second capability is the second number of bits.
[0101] In combination with some embodiments of the sixth aspect, in some embodiments, the security capability information includes actual security capabilities of the terminal.
[0102] In a seventh aspect, an embodiment of the present disclosure proposes a terminal, comprising: a transceiver module for sending security capability information.
[0103] In an eighth aspect, an embodiment of the present disclosure proposes a UDM, including: a transceiver module for receiving security capability information.
[0104] In the ninth aspect, an embodiment of the present disclosure proposes a UDM, including: a transceiver module, used to send the number of bits of a first key to AUSF, and the AUSF is used to send the number of bits of the first key to AMF.
[0105] In a tenth aspect, an embodiment of the present disclosure proposes an AUSF, comprising: a transceiver module.
[0106] In the eleventh aspect, an embodiment of the present disclosure proposes an AMF, including: a transceiver module for receiving security capability information sent by a terminal.
[0107] In the twelfth aspect, an embodiment of the present disclosure proposes an access network device, including: a transceiver module for receiving security capability information sent by AMF.
[0108] In the thirteenth aspect, an embodiment of the present disclosure proposes a communication system, including a terminal, a UDM, an AUSF, an AMF and an access network device, wherein the terminal is configured to implement the communication method of the first aspect, the UDM is configured to implement the communication method of the second aspect or the third aspect, the AUSF is configured to implement the communication method of the fourth aspect, the AMF is configured to implement the communication method of the fifth aspect, and the access network device is configured to implement the communication method of the sixth aspect.
[0109] In the fourteenth aspect, an embodiment of the present disclosure proposes a storage medium storing instructions, characterized in that when the instructions are executed on a communication device, the communication device executes the communication method of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the sixth aspect.
[0110] In the fifteenth aspect, an embodiment of the present disclosure proposes a program product. When the program product is executed by a communication device, the communication device executes the method described in the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the sixth aspect.
[0111] In the sixteenth aspect, an embodiment of the present disclosure proposes a computer program, which, when running on a computer, enables the computer to execute the method described in the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the sixth aspect.
[0112] In a seventeenth aspect, an embodiment of the present disclosure provides a chip or a chip system. The chip or chip system includes a processing circuit configured to execute the method described in the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the sixth aspect.
[0113] It is understandable that the above-mentioned terminal, UDM, AUSF, AMF, access network equipment, communication system, storage medium, program product, computer program, chip or chip system are all used to perform the method proposed in the embodiment of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method and will not be repeated here.
[0114] The embodiments of the present disclosure provide a terminal, a UDM, an AUSF, an AMF, an access network device, a communication system, and a storage medium. In some embodiments, the terms "communication method" and "secure communication method" and "information processing method" are interchangeable, and the terms "information processing system" and "communication system" and "secure communication system" are interchangeable.
[0115] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0116] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.
[0117] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.
[0118] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.
[0119] In the embodiments of the present disclosure, “plurality” refers to two or more.
[0120] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.
[0121] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.
[0122] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.
[0123] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.
[0124] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0125] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.
[0126] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.
[0127] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.
[0128] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
[0129] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)" "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.
[0130] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.
[0131] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.
[0132] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.
[0133] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
[0134] In some embodiments, data, information, etc. may be obtained with the user's consent.
[0135] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.
[0136] FIG1 is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.
[0137] As shown in FIG1 , a communication system 100 includes a terminal 101 and a network device 102 .
[0138] In some embodiments, the terminal 101 can be at least one of a user equipment (UE), a mobile phone, a wearable device, an Internet of Things device, a car with communication capabilities, a smart car, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and a wireless terminal device in a smart home, but is not limited thereto.
[0139] In some embodiments, the network device 102 may be a single device including a first network element, a second network element, a third network element, etc., or may be a plurality of devices or a group of devices including all or part of the first network element, the second network element, the third network element, etc. The network element may be virtual or physical. The core network may include, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0140] In some embodiments, the first network element is, for example, an Access and Mobility Management Function (AMF) or a Security Anchor Function (SEAF).
[0141] In some embodiments, the second network element is, for example, an Authentication Server Function (AUSF).
[0142] In some embodiments, the third network element is, for example, a Unified Data Management (UDM) or an Authentication Credential Repository and Processing Function (ARPF) or a Subscription Identifier De-concealing Function (SIDF).
[0143] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.
[0144] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1 , or a portion thereof, but are not limited thereto. The entities shown in FIG1 are illustrative only. The communication system may include all or part of the entities shown in FIG1 , or may include other entities outside of FIG1 . The number and form of the entities are arbitrary, and the entities may be physical or virtual. The connection relationships between the entities are illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.
[0145] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).
[0146] In related technologies, communication systems (e.g., 5GS) support the negotiation process of a 128-bit security algorithm. Specifically, the network device uses the NAS (Non Access Stratum) SMC (Security Mode Control) process to negotiate a 128-bit security algorithm (e.g., 128-NEA1) with the UE to implement NAS security. The AS (Access Stratum) SMC process is used to implement AS security negotiation of a 128-bit security algorithm (e.g., 128-NEA1).
[0147] To protect NAS / AS messages from potential quantum threats, 256-bit security algorithms (e.g., zuc256) can be introduced into the communication system. In addition, to mitigate potential quantum threats in the authentication process, 256-bit security algorithms (e.g., MILENAGE-256, TUAK) are also planned to be used in the communication system.
[0148] Compared with the scenario where only a 128-bit long-term key K and a 128-bit security algorithm are applied, the following four possible situations need to be considered in the 256-bit communication scenario.
[0149] The long-term key K in the USIM (Universal Subscriber Identity Module) is 128 bits, and the ME (Mobile Equipment) supports both 128-bit and 256-bit security algorithms.
[0150] The long-term key K in the USIM is 128 bits, and the ME only supports 128-bit security algorithms;
[0151] The long-term key K in the USIM is 256 bits, and the ME supports both 128-bit and 256-bit security algorithms;
[0152] The long-term key K in the USIM is 256 bits, and the ME only supports 128-bit security algorithms.
[0153] When the security levels of the USIM and ME are different (for example, the long-term key K in the USIM is 256 bits, and the ME only supports 128-bit security algorithms), how to determine the security capabilities supported by the UE during the algorithm negotiation and authentication processes is a technical problem that needs to be solved.
[0154] The embodiment of the present disclosure provides a secure communication method, in which a terminal sends security capability information to a network function of a core network via an access network. Based on the secure communication method provided by the embodiment of the present disclosure, the security of communication can be improved.
[0155] FIG2A is an interactive diagram of a secure communication method according to an embodiment of the present disclosure. As shown in FIG2A , the present disclosure embodiment relates to a secure communication method, which includes:
[0156] Step S2101: The terminal determines the actual security capability of the terminal.
[0157] In some embodiments, the UE includes a USIM and an ME, and the terminal may determine the actual security capability of the terminal according to at least one of the number of bits of the first key supported by the USIM and the number of bits of the security algorithm supported by the ME.
[0158] In some embodiments, the actual security capability of the terminal may be determined in at least one of the following ways:
[0159] If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability;
[0160] If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits and the second number of bits, it is determined that the actual security capability of the terminal is to support the first capability;
[0161] If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability;
[0162] If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits and the second number of bits, it is determined that the actual security capability of the terminal is to support the first capability and the second capability;
[0163] The first capability corresponds to a first bit number for the security algorithm supported by the terminal, and the second capability corresponds to a second bit number for the security algorithm supported by the terminal.
[0164] In some embodiments, the first bit number may be 128 bits, and the second bit number may be 256 bits, which is not limited in the present disclosure. For example, the first bit number may also be 256 bits, and the second bit number may also be 256 bits.
[0165] In some embodiments, the first key can be a long-term key, a subscriber key, an authentication key, or other types of keys. In the following examples, the first key is taken as a long-term key, but this disclosure does not limit this.
[0166] In some embodiments, the number of bits of the first key refers to the key length of the first key, such as 128 or 256 of the number of bits of the first key; the number of bits of the security algorithm supported by the ME refers to the number of bits corresponding to the security algorithm, such as the number of bits of zuc-256 is 256, the number of bits of MILENAGE-256 is 256, and the number of bits of MILENAGE is 128.
[0167] For example, the UE determines the actual security capability of the UE according to the following policy:
[0168] If the long-term key K stored in the USIM is 128 bits and the ME supports both 128-bit and 256-bit security algorithms, the actual security capability of the UE is based on the 128-bit security capability.
[0169] If the long-term key K stored in the USIM is 128 bits and the ME only supports 128-bit security algorithms, the actual security capabilities of the UE are based on the 128-bit security capabilities.
[0170] If the long-term key K stored in the USIM is 256 bits and the ME supports both 128-bit and 256-bit security algorithms, the actual security capabilities of the UE are based on the 128-bit and 256-bit security capabilities.
[0171] If the long-term key K stored in the USIM is 256 bits and the ME only supports 128-bit security algorithms, the actual security capabilities of the UE are based on 128-bit security capabilities.
[0172] In some embodiments, the terminal may determine the security information based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0173] In some embodiments, the security information is determined based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the ME security algorithm of the terminal in the following manner:
[0174] If the number of bits of the first key is the second number of bits, and the actual security capability of the terminal is to support the second capability, determining the security information according to the security algorithm of the first key and the second number of bits;
[0175] If the number of bits of the first key is the second number of bits and the actual security capability of the terminal is to support the first capability, the first key is truncated to generate a first key of the first number of bits, and the security information is determined based on the first key of the first number of bits and the security algorithm of the first number of bits; or, the security information is determined based on the security algorithm of the second number of bits, and the security information is truncated to security information of the first number of bits.
[0176] In some embodiments, the security information includes at least one of the following: an authentication vector, a CK (Cipher Key, confidentiality protection key), and an IK (integrity key, integrity protection key).
[0177] For example, after the terminal determines the actual security capability of the terminal, the terminal may derive at least one of the authentication vector, CK, and IK in the following manner.
[0178] If the long-term key length is 256 bits and the actual security capability of the terminal is to support the 256-bit algorithm, the terminal calculates at least one of the following based on the 256-bit security algorithm: authentication vector, CK, IK.
[0179] If the long-term key is 256 bits long and the terminal's actual security capabilities do not support 256-bit algorithms, the terminal truncates the long-term key to 128 bits to calculate at least one of the following: the authentication vector, CK, or IK. Specifically, the terminal utilizes a 128-bit security algorithm (e.g., TUAK, MILENAGE-128) to derive at least one of the following: a 128-bit authentication vector, a 128-bit CK, or a 128-bit IK.
[0180] or
[0181] If the long-term key length is 256 bits and the terminal's actual security capabilities do not support 256-bit algorithms, the terminal truncates the long-term key to 128 bits to calculate at least one of the following: the authentication vector, CK, or IK. Specifically, the terminal utilizes a 256-bit security algorithm (e.g., TUAK, MILENAGE-256) to derive a 256-bit CK and a 256-bit IK. The 256-bit CK / IK is then truncated to at least one of the following: a 128-bit authentication vector, a 128-bit CK, or a 128-bit IK.
[0182] Step S2102: The terminal sends security capability information to AMF / SEAF.
[0183] In some embodiments, the terminal sends security capability information to a network function of the core network through the access network.
[0184] In some embodiments, the network functions of the core network include at least one of unified data management UDM, unified data warehouse UDR, authentication credential repository and processing function ARPF, and access and mobility management function AMF.
[0185] In some embodiments, the AMF / SEAF receives security capability information sent by the terminal.
[0186] In some embodiments, the security capability information may include the actual security capabilities of the terminal, that is, the terminal may report the actual security capabilities of the terminal to the AMF / SEAF.
[0187] In some embodiments, the security capability information may include security capability information supported by the terminal or the ME of the terminal, such as the number of bits of the security algorithm supported by the terminal or the ME of the terminal. The network side device can determine the actual security capability of the terminal based on the number of bits of the security algorithm supported by the terminal or the ME of the terminal reported by the terminal.
[0188] In some embodiments, the security capability information is sent after being integrity protected by a security algorithm by the terminal, and the number of bits of the security algorithm is the second number of bits.
[0189] In some embodiments, when the terminal supports the first capability, the security capability information includes at least one of the following:
[0190] The first bit of the non-access stratum NAS security algorithm indicator and the first bit of the access stratum AS security algorithm indicator;
[0191] The first bit of the authentication algorithm indicator;
[0192] An indicator indicating that the terminal supports the security algorithm of the first bit;
[0193] The first bit position.
[0194] In some embodiments, when the terminal supports the second capability, the security capability information includes at least one of the following:
[0195] The second bit of the non-access stratum NAS security algorithm indicator and the second bit of the access stratum AS security algorithm indicator;
[0196] The second bit is the authentication algorithm indicator;
[0197] An indicator indicating that the terminal supports the security algorithm of the second bit number;
[0198] The second bit.
[0199] For example, if the terminal supports 128-bit security capabilities, the security capability information includes at least one of the following:
[0200] 128-bit NAS security algorithm indicator, 128-bit AS security algorithm indicator;
[0201] 128-bit authentication algorithm indicator, indicating the specific authentication algorithm supported, 128-bit 5G AKA algorithm or specific 128-bit EAP-AKA' algorithm;
[0202] An indicator indicating that the terminal supports 128-bit security algorithms. This indicator only indicates that the terminal supports 128-bit NAS, AS, and authentication algorithms, but does not indicate the specific algorithms.
[0203] Indicates the number of bits of the supported algorithm: 128 bits or 256 bits.
[0204] For example, if the terminal supports 256-bit security capabilities, the security capability information includes at least one of the following:
[0205] 256-bit NAS security algorithm indicator, 256-bit AS security algorithm indicator;
[0206] 256-bit authentication algorithm indicator, 256-bit 5G AKA algorithm or specific 256-bit EAP-AKA algorithm;
[0207] Indicates that the terminal supports 256-bit security algorithms and 256-bit NAS, AS, and authentication algorithms;
[0208] Indicates the number of bits of the supported algorithm: 128 bits or 256 bits.
[0209] Step S2103, AMF / SEAF sends security capability information to AUSF.
[0210] In some embodiments, the AUSF receives security capability information sent by the AMF / SEAF.
[0211] Step S2104: AUSF sends security capability information to UDM / ARPF / SIDF.
[0212] In some embodiments, the UDM / ARPF / SIDF receives the security capability information sent by the AUSF.
[0213] In some embodiments, if the security capability information includes the actual security capability of the terminal, the UDM can directly obtain the actual security capability of the terminal; if the security capability information includes the number of bits of the security algorithm supported by the ME of the terminal, the UDM can determine the actual security capability of the terminal based on the number of bits of the security algorithm supported by the ME reported by the terminal and the number of bits of the first key supported by the USIM of the terminal stored in the UDM.
[0214] Step S2105: UDM / ARPF / SIDF determines security information.
[0215] In some embodiments, the UDM / ARPF / SIDF may determine the security information based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0216] In some embodiments, the security information is determined based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the ME security algorithm of the terminal in the following manner:
[0217] If the number of bits of the first key is the second number of bits, and the actual security capability of the terminal is to support the second capability, determining the security information according to the security algorithm of the first key and the second number of bits;
[0218] If the number of bits of the first key is the second number of bits and the actual security capability of the terminal is to support the first capability, the first key is truncated to generate a first key of the first number of bits, and the security information is determined based on the first key of the first number of bits and the security algorithm of the first number of bits; or, the security information is determined based on the security algorithm of the second number of bits, and the security information is truncated to security information of the first number of bits.
[0219] In some embodiments, security capability information is used to determine an authentication algorithm.
[0220] In some embodiments, when the security capability information indicates that the terminal supports a security algorithm of a first bit number, the UDM selects an authentication algorithm of a first bit number to authenticate with the terminal; when the security capability information indicates that the terminal supports a security algorithm of a second bit number, the UDM selects an authentication algorithm of a second bit number to authenticate with the terminal.
[0221] In some embodiments, the security information includes at least one of the following: an authentication vector, CK, and IK. For example, the UDM may derive CK and IK in the following manner.
[0222] If the long-term key length is 256 bits and the actual security capability of the terminal is to support the 256-bit algorithm, the terminal calculates at least one of the following according to the 256-bit security algorithm: the authentication vector, CK, and IK.
[0223] If the long-term key is 256 bits long and the terminal's actual security capabilities do not support 256-bit algorithms, the terminal truncates the long-term key to 128 bits to calculate at least one of the following: the authentication vector, CK, or IK. Specifically, the terminal utilizes a 128-bit security algorithm (e.g., TUAK, MILENAGE-128) to derive at least one of the following: a 128-bit authentication vector, a 128-bit CK, and a 128-bit IK.
[0224] or
[0225] If the long-term key length is 256 bits and the terminal's actual security capabilities do not support 256-bit algorithms, the terminal truncates the long-term key to 128 bits to calculate at least one of the following: the authentication vector, CK, or IK. Specifically, the terminal utilizes a 256-bit security algorithm (e.g., TUAK, MILENAGE-256) to derive at least one of the following: a 256-bit authentication vector, a 256-bit CK, and a 256-bit IK. The 256-bit authentication vector / CK / IK is then truncated to a 128-bit authentication vector / CK / IK.
[0226] In some embodiments, the truncation can be done by taking the most significant 128 bits as the first key, or taking the least significant 128 bits as the first key, or extracting 128 bits from 256 bits as the first key, that is, the present disclosure does not limit the truncation rules.
[0227] In some embodiments, the above method may further include: the terminal performing secure communication based on the security information.
[0228] Among them, the security information is determined based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal. The security information includes first security information and second security information. The first security information is determined by the terminal, and the second security information is determined by the network function of the core network.
[0229] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codeword", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.
[0230] In some embodiments, terms such as "moment", "time point", "time", and "time position" can be replaced with each other, and terms such as "duration", "period", "time window", "window", and "time" can be replaced with each other.
[0231] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, etc.
[0232] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.
[0233] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "a certain", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, a certain A, any A, or first A, etc., but not limited to this.
[0234] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited thereto.
[0235] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the recipient to respond to the content sent.
[0236] The secure communication method according to the embodiments of the present disclosure may include at least one of steps S2101 to S2105. For example, step S2101 may be implemented as an independent embodiment, step S2102 may be implemented as an independent embodiment, step S2105 may be implemented as an independent embodiment, steps S2101+S2102 may be implemented as an independent embodiment, steps S2101+S2102+S2103 may be implemented as an independent embodiment, and steps S2101+S2102+S2103+S2104 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0237] In some embodiments, steps S2103, S2104, and S2105 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0238] In some embodiments, reference may be made to other optional implementations described before or after the description corresponding to FIG. 2A .
[0239] FIG2B is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2B , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0240] Step S2201: The terminal sends security capability information to AMF / SEAF.
[0241] In some embodiments, the AMF / SEAF receives security capability information sent by the terminal.
[0242] In some embodiments, the security capability information may include security capability information supported by the terminal or the ME of the terminal, such as the number of bits of the security algorithm supported by the terminal or the ME of the terminal. The network side device can determine the actual security capability of the terminal based on the number of bits of the security algorithm supported by the ME reported by the terminal.
[0243] Step S2202: AMF / SEAF sends security capability information to AUSF.
[0244] In some embodiments, the AUSF receives security capability information sent by the AMF / SEAF.
[0245] Step S2203: AUSF sends security capability information to UDM / ARPF / SIDF.
[0246] In some embodiments, the UDM / ARPF / SIDF receives the security capability information sent by the AUSF.
[0247] Step S2204: UDM / ARPF / SIDF determines the actual security capability of the terminal.
[0248] In some embodiments, the UDM / ARPF / SIDF may determine the actual security capability based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0249] In some embodiments, the actual security capability of the terminal may be determined in at least one of the following ways:
[0250] If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability;
[0251] If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits and the second number of bits, it is determined that the actual security capability of the terminal is to support the first capability;
[0252] If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability;
[0253] If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits and the second number of bits, it is determined that the actual security capability of the terminal is to support the first capability and the second capability;
[0254] The first capability corresponds to a first bit number for the security algorithm supported by the terminal, and the second capability corresponds to a second bit number for the security algorithm supported by the terminal.
[0255] Step S2205: UDM / ARPF / SIDF sends the actual security capabilities of the terminal to AUSF.
[0256] In some embodiments, the AUSF receives the actual security capabilities of the terminal sent by the UDM / ARPF / SIDF.
[0257] Step S2206: AUSF sends the actual security capabilities of the terminal to AMF / SEAF.
[0258] In some embodiments, the AMF / SEAF receives the actual security capabilities of the terminal sent by the AUSF.
[0259] In step S2207, the AMF sends the actual security capabilities of the terminal to the gNB.
[0260] In some embodiments, the gNB receives the actual security capabilities of the terminal sent by the AMF.
[0261] The optional implementation of FIG2B can refer to other related parts of the embodiment involved in FIG2A and will not be described in detail here.
[0262] The secure communication method according to the embodiments of the present disclosure may include at least one of steps S2201 to S2208. For example, step S2201 may be implemented as an independent embodiment, step S2205 may be implemented as an independent embodiment, steps S2201+S2202+S2203+S2104+S2205 may be implemented as an independent embodiment, and steps S2201+S2205 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0263] In some embodiments, steps S2201, S2202, S2203, and S2104 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0264] In some embodiments, steps S2206, S2207, and S2208 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0265] FIG2C is an interactive diagram of a secure communication method according to an embodiment of the present disclosure. As shown in FIG2C , the present disclosure embodiment relates to a secure communication method, which includes:
[0266] Step S2301: The UE sends security capability information to the AMF / SEAF.
[0267] In some embodiments, the AMF / SEAF receives security capability information sent by the terminal.
[0268] In some embodiments, the security capability information may include security capability information supported by the terminal or the ME of the terminal, such as the number of bits of the security algorithm supported by the terminal or the ME of the terminal. Other devices can determine the actual security capability of the terminal based on the number of bits of the security algorithm supported by the ME reported by the terminal.
[0269] Step S2302: UDM / ARPF / SIDF sends the number of bits of the first key supported by the USIM to the AUSF.
[0270] In some embodiments, the AUSF receives the number of bits of the first key supported by the USIM sent by the UDM / ARPF / SIDF.
[0271] In some embodiments, the UDM / ARPF / SIDF stores the number of bits of the first key supported by the USIM of the terminal.
[0272] Step S2303: AUSF sends the number of bits of the first key supported by USIM to AMF / SEAF.
[0273] In some embodiments, the AMF / SEAF receives the number of bits of the first key supported by the USIM sent by the AUSF.
[0274] Step S2304: AMF / SEAF determines the actual security capabilities of the terminal.
[0275] In some embodiments, the AMF / SEAF may determine the actual security capability based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
[0276] In some embodiments, the actual security capability of the terminal may be determined in at least one of the following ways:
[0277] If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability;
[0278] If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits and the second number of bits, it is determined that the actual security capability of the terminal is to support the first capability;
[0279] If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability;
[0280] If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits and the second number of bits, it is determined that the actual security capability of the terminal is to support the first capability and the second capability;
[0281] The first capability corresponds to a first bit number for the security algorithm supported by the terminal, and the second capability corresponds to a second bit number for the security algorithm supported by the terminal.
[0282] In step S2305, the AMF / SEAF sends the number of bits of the first key or the actual security capabilities of the terminal to the gNB.
[0283] In some embodiments, the gNB receives the number of bits of the first key sent by the AMF / SEAF or the actual security capability of the terminal.
[0284] In step S2306, the gNB determines the actual security capabilities of the terminal.
[0285] In some embodiments, if the AMF / SEAF sends the gNB the number of bits of the first key, the gNB determines the actual security capability based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal. The security algorithm supported by the ME of the terminal may be sent by the AMF / SEAF to the gNB.
[0286] In some embodiments, the actual security capability of the terminal may be determined in at least one of the following ways:
[0287] If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability;
[0288] If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits and the second number of bits, it is determined that the actual security capability of the terminal is to support the first capability;
[0289] If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability;
[0290] If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the ME of the terminal is the first number of bits and the second number of bits, it is determined that the actual security capability of the terminal is to support the first capability and the second capability;
[0291] The first capability corresponds to a first bit number for the security algorithm supported by the terminal, and the second capability corresponds to a second bit number for the security algorithm supported by the terminal.
[0292] The optional implementation of FIG2C can refer to other related parts in the embodiments involved in FIG2A and FIG2B , which will not be described in detail here.
[0293] The secure communication method according to the embodiments of the present disclosure may include at least one of steps S2301 to S2306. For example, step S2304 may be implemented as an independent embodiment, step S2306 may be implemented as an independent embodiment, steps S2301+S2304 may be implemented as independent embodiments, and steps S2301+S2305+S2306 may be implemented as independent embodiments, but the present invention is not limited thereto.
[0294] In some embodiments, steps S2302, S2203, S2205, and S2106 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0295] In some embodiments, steps S2302, S2203, and S2204 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0296] Figure 2D is an interactive diagram of a secure communication method according to an embodiment of the present disclosure. As shown in Figure 2D, the embodiment of the present disclosure relates to a secure communication method, which includes:
[0297] Step S2401: The UE sends security capability information to the UDM / ARPF / SIDF.
[0298] In some embodiments, the UE may send security capability information to the UDM / ARPF / SIDF via the AMF and AUSF.
[0299] In some embodiments, security capability information may be used to determine an authentication algorithm.
[0300] In some embodiments, the security capability information may indicate security algorithms supported by the terminal.
[0301] For example, the security capability information indicates that the terminal supports a security algorithm with a first number of bits, or the security capability information indicates that the terminal supports a security algorithm with a second number of bits.
[0302] Step S2402: UDM / ARPF / SIDF selects a security algorithm.
[0303] In some embodiments, UDM / ARPF / SIDF selects a security algorithm based on security capability information.
[0304] In some embodiments, when the security capability information indicates that the terminal supports a security algorithm of a first bit number, the UDM selects an authentication algorithm of the first bit number to perform authentication with the terminal.
[0305] In some embodiments, when the security capability information indicates that the terminal supports the security algorithm of the second bit number, the UDM selects the authentication algorithm of the second bit number to perform authentication with the terminal.
[0306] In some embodiments, the UDM / ARPF / SIDF selects a security algorithm based on its own security capabilities and terminal-side security capability information provided by the terminal.
[0307] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S2401 to S2402. For example, step S2401 may be implemented as an independent embodiment, and step S2402 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0308] FIG3 is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG3 , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0309] Step S3101: Determine the actual security capability of the terminal.
[0310] The optional implementation of step S3101 can be found in step S2101 of FIG. 2A and other related parts of the embodiment involved in FIG. 2A , which will not be described in detail here.
[0311] Step S3102: Send security capability information.
[0312] The optional implementation of step S3102 can be found in the optional implementation of step S2102 in Figure 2A, step S2201 in Figure 2B, step S2301 in Figure 2C, and other related parts in the embodiments involved in Figures 2A, 2B and 2C, which will not be repeated here.
[0313] In some embodiments, the terminal sends security capability information to the AMF / SEAF.
[0314] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S3101 to S3102. For example, step S3101 may be implemented as an independent embodiment, and step S3102 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0315] In some embodiments, step S3101 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0316] FIG4A is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG4A , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0317] Step S4101: Obtain security capability information.
[0318] In some embodiments, the UDM / ARPF / SIDF receives the security capability information sent by the AUSF.
[0319] Optional implementations of step S4101 may refer to step S2104 in FIG. 2A and other related parts of the embodiment involved in FIG. 2A , which will not be described in detail here.
[0320] Step S4102, determine security information.
[0321] In some embodiments, UDM / ARPF / SIDF may determine security information.
[0322] The optional implementation of step S4102 can be found in step S2105 of FIG. 2A and other related parts of the embodiment involved in FIG. 2A , which will not be described in detail here.
[0323] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S4101 to S4102. For example, step S4101 may be implemented as an independent embodiment, and step S4102 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0324] In some embodiments, step S4102 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0325] FIG4B is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG4B , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0326] Step S4201: Obtain security capability information.
[0327] In some embodiments, the UDM / ARPF / SIDF receives the security capability information sent by the AUSF.
[0328] The optional implementation of step S4201 can be found in step S2203 of FIG. 2B and other related parts of the embodiment involved in FIG. 2B , which will not be described in detail here.
[0329] Step S4202: Determine the actual security capability of the terminal.
[0330] In some embodiments, UDM / ARPF / SIDF determines the actual security capabilities of the terminal.
[0331] The optional implementation of step S4202 can be found in step S2204 of FIG. 2B and other related parts of the embodiment involved in FIG. 2B , which will not be described in detail here.
[0332] Step S4203: Send the actual security capability of the terminal.
[0333] In some embodiments, the UDM / ARPF / SIDF sends the actual security capabilities of the terminal to the AUSF.
[0334] The optional implementation of step S4203 can be found in step S2205 of FIG. 2B and other related parts of the embodiment involved in FIG. 2B , which will not be described in detail here.
[0335] The secure communication method involved in the embodiments of the present disclosure may include at least one of steps S4201 to S4203. For example, step S4202 may be implemented as an independent embodiment, and steps S4201+S4202 may be implemented as independent embodiments, but are not limited thereto.
[0336] In some embodiments, step S4202 and step S4203 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0337] FIG4C is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG4C , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0338] Step S4301: Send the number of bits of the first key supported by the USIM.
[0339] In some embodiments, the UDM / ARPF / SIDF sends the AUSF the number of bits of the first key supported by the USIM.
[0340] In some embodiments, the UDM / ARPF / SIDF may send indication information to the AMF and / or gNB without any triggering condition, where the indication information is used to indicate the number of bits of the first key supported by the USIM, or the indication information is used to indicate the capability information of the USIM (for example, the USIM supports a 256-bit security algorithm).
[0341] The optional implementation of step S4301 can be found in step S2302 of FIG. 2C and other related parts of the embodiment involved in FIG. 2C , which will not be described in detail here.
[0342] FIG5A is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG5A , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0343] Step S5101: Obtain security capability information.
[0344] In some embodiments, the AUSF receives security capability information sent by the AMF / SEAF.
[0345] Optional implementations of step S5101 may refer to step S2103 of FIG. 2A , step S2202 of FIG. 2B , and other related parts of the embodiments involved in FIG. 2A and FIG. 2B , which will not be described in detail here.
[0346] Step S5102: Send security capability information.
[0347] In some embodiments, the AUSF sends security capability information to the UDM / ARPF / SIDF.
[0348] Optional implementations of step S5102 may refer to step S2104 in FIG. 2A , step S2203 in FIG. 2B , and other related parts in the embodiments involved in FIG. 2A and FIG. 2B , which will not be described in detail here.
[0349] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S5101 to S5102. For example, step S5101 may be implemented as an independent embodiment, and step S5102 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0350] FIG5B is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG5B , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0351] Step S5201: Acquire the actual security capability of the terminal.
[0352] In some embodiments, the AUSF receives the actual security capabilities of the terminal sent by the UDM / ARPF / SIDF.
[0353] The optional implementation of step S5201 can be found in step S2205 of FIG. 2B and other related parts of the embodiment involved in 2B, which will not be described in detail here.
[0354] Step S5202: Send the actual security capability of the terminal.
[0355] In some embodiments, the AMF / SEAF receives the actual security capabilities of the terminal sent by the AUSF.
[0356] The optional implementation of step S5202 can be found in step S2206 of FIG. 2B and other related parts of the embodiment involved in 2B, which will not be described in detail here.
[0357] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S5201 and S5202. For example, step S5201 may be implemented as an independent embodiment, and step S5202 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0358] FIG5C is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG5C , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0359] Step S5301: Obtain the number of bits of the first key supported by the USIM.
[0360] In some embodiments, the AUSF receives the number of bits of the first key supported by the USIM sent by the UDM / ARPF / SIDF.
[0361] The optional implementation of step S5301 can be found in step S2302 of FIG. 2C and other related parts of the embodiment involved in 2C, which will not be repeated here.
[0362] Step S5302: Send the number of bits of the first key supported by the USIM.
[0363] In some embodiments, the AMF / SEAF receives the number of bits of the first key supported by the USIM sent by the AUSF.
[0364] The optional implementation of step S5302 can be found in step S2303 of FIG. 2C and other related parts of the embodiment involved in 2C, which will not be described in detail here.
[0365] The secure communication method involved in the embodiments of the present disclosure may include at least one of steps S5301 to S5302. For example, step S5301 may be implemented as an independent embodiment, and step S5302 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0366] FIG6A is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG6A , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0367] Step S6101: Obtain security capability information.
[0368] In some embodiments, the AMF / SEAF receives security capability information sent by the terminal.
[0369] Optional implementations of step S6101 may refer to step S2102 in FIG. 2A , step S2201 in FIG. 2B , and other related parts of the embodiments involved in FIG. 2A and FIG. 2B , which will not be described in detail here.
[0370] Step S6102: Send security capability information.
[0371] In some embodiments, the AMF / SEAF sends security capability information to the AUSF.
[0372] Optional implementations of step S6102 may refer to step S2103 in FIG. 2A , step S2202 in FIG. 2B , and other related parts of the embodiments involved in FIG. 2A and FIG. 2B , which will not be described in detail here.
[0373] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S6101 to S6102. For example, step S6101 may be implemented as an independent embodiment, and step S6102 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0374] FIG6B is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG6B , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0375] Step S6201: Acquire the actual security capabilities of the terminal.
[0376] In some embodiments, the AMF / SEAF receives the actual security capabilities of the terminal sent by the AUSF.
[0377] In some embodiments, after AMF / SEAF obtains the actual security capabilities of the terminal, it determines the security algorithm used to communicate with the terminal based on the actual security capabilities of the terminal.
[0378] The optional implementation of step S6201 can be found in step S2206 of FIG. 2B and other related parts of the embodiment involved in 2B, which will not be described in detail here.
[0379] Step S6202: Send the actual security capability of the terminal.
[0380] In some embodiments, the actual security capabilities of the terminal are sent by the AMF / SEAF to the gNB.
[0381] The optional implementation of step S6202 can be found in step S2207 of FIG. 2B and other related parts of the embodiment involved in 2B, which will not be described in detail here.
[0382] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S6201 and S6202. For example, step S6201 may be implemented as an independent embodiment, and step S6202 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0383] FIG6C is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG6C , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0384] Step S6301: Obtain security capability information.
[0385] In some embodiments, the AMF / SEAF receives security capability information sent by the terminal.
[0386] The optional implementation of step S6301 can be found in step S2301 of FIG. 2C and other related parts of the embodiment involved in 2C, which will not be described in detail here.
[0387] Step S6302: Obtain the number of bits of the first key supported by the USIM.
[0388] In some embodiments, the AMF / SEAF receives the number of bits of the first key supported by the USIM sent by the AUSF.
[0389] The optional implementation of step S6302 can be found in step S2303 of FIG. 2C and other related parts of the embodiment involved in 2C, which will not be described again here.
[0390] Step S6303: Determine the actual security capability of the terminal.
[0391] In some embodiments, the AMF / SEAF determines the actual security capabilities of the terminal.
[0392] The optional implementation of step S6303 can be found in step S2304 of FIG. 2C and other related parts of the embodiment involved in 2C, which will not be repeated here.
[0393] Step S6304: Send the number of bits of the first key supported by the USIM or the actual security capability of the terminal.
[0394] In some embodiments, the number of bits of the first key supported by the USIM or the actual security capability of the terminal sent by the AMF / SEAF to the gNB.
[0395] The optional implementation of step S6304 can be found in step S2305 of FIG. 2C and other related parts of the embodiment involved in 2C, which will not be repeated here.
[0396] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S6301 to S6304. For example, step S6302 may be implemented as an independent embodiment, and steps S6301+S6302 may be implemented as independent embodiments, but are not limited thereto.
[0397] FIG7 is a flow chart of a secure communication method according to an embodiment of the present disclosure. As shown in FIG7 , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0398] Step S7101: Obtain the number of bits of the first key supported by the USIM or the actual security capability of the terminal.
[0399] In some embodiments, the number of bits of the first key supported by the USIM or the actual security capability of the terminal sent by the AMF / SEAF to the gNB.
[0400] The optional implementation of step S7101 can be found in step S2305 of FIG. 2C and other related parts of the embodiment involved in 2C, which will not be repeated here.
[0401] Step S7102: Determine the actual security capability of the terminal.
[0402] In some embodiments, the gNB determines the actual security capabilities of the terminal.
[0403] The optional implementation of step S7101 can be found in step S2306 of FIG. 2C and other related parts of the embodiment involved in 2C, which will not be described in detail here.
[0404] The secure communication method involved in the embodiment of the present disclosure may include at least one of steps S7101 to S7102. For example, step S7101 may be implemented as an independent embodiment, and step S7102 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0405] Figure 8 is an interactive diagram of a secure communication method according to an embodiment of the present disclosure. As shown in Figure 8, the embodiment of the present disclosure relates to a secure communication method, which includes:
[0406] Step S8101: Send security capability information.
[0407] In some embodiments, the terminal sends security capability information to a network function of the core network.
[0408] The optional implementation of step S8101 can be found in the optional implementation of step S2102 in Figure 2A, step S2101 in Figure 2B, step S2101 in Figure 2C, step S3102 in Figure 3, and other related parts in the embodiments involved in Figures 2A, 2B, and 3, which will not be repeated here.
[0409] In some embodiments, the above method may include the methods of the above-mentioned terminal side, UDM side, AMF side, AUSF side, gNB side, etc., which will not be repeated here.
[0410] FIG9A is an interactive diagram of a secure communication method according to an embodiment of the present disclosure. As shown in FIG9A , the embodiment of the present disclosure relates to a secure communication method, which includes:
[0411] Step S9101: The UE determines the UE security capability.
[0412] The UE includes a USIM and an ME. The UE determines the security capability of the UE according to the long-term key length stored in the USIM and the security algorithm type supported by the ME.
[0413] Specifically, the UE makes judgments based on the following strategies:
[0414] If the long-term key K stored in the USIM is 128 bits and the ME supports both 128-bit and 256-bit security algorithms, the actual capability of the UE is based on the 128-bit security capability.
[0415] If the long-term key K stored in the USIM is 128 bits and the ME only supports 128-bit security algorithms, the actual capability of the UE is based on the 128-bit security capability.
[0416] If the long-term key K stored in the USIM is 256 bits and the ME supports both 128-bit and 256-bit security algorithms, the actual capabilities of the UE are based on the 128-bit and 256-bit security capabilities.
[0417] If the long-term key K stored in the USIM is 256 bits and the ME only supports 128-bit security algorithms, the actual capabilities of the UE are based on 128-bit security capabilities.
[0418] After the terminal determines the actual security capability of the terminal, the terminal may derive at least one of the following in the following manner: an authentication vector, CK, and IK.
[0419] If the long-term key length is 256 bits and the actual security capability of the terminal is to support the 256-bit algorithm, the terminal calculates at least one of the following according to the 256-bit security algorithm: the authentication vector, CK, and IK.
[0420] If the long-term key is 256 bits long and the actual security capabilities of the terminal do not support a 256-bit algorithm, the terminal truncates the long-term key to 128 bits to calculate at least one of the following: the authentication vector, the CK, and the IK. Specifically, the terminal utilizes a 128-bit security algorithm (e.g., TUAK, MILENAGE-128) to derive at least one of the following: a 128-bit authentication vector, a 128-bit CK, and a 128-bit IK.
[0421] or
[0422] If the long-term key length is 256 bits and the terminal's actual security capabilities do not support 256-bit algorithms, the terminal truncates the long-term key to 128 bits to calculate at least one of the following: the authentication vector, CK, and IK. Specifically, the terminal utilizes a 256-bit security algorithm (e.g., TUAK, MILENAGE-256) to derive at least one of the following: a 256-bit authentication vector, a 256-bit CK, and a 256-bit IK. The 256-bit authentication vector / CK / IK is then truncated to a 128-bit authentication vector / CK / IK.
[0423] In step S9102, the UE sends a UE identity (e.g., SUCI or 5G-GUTI), UE security capabilities (e.g., UE supports 128-bit security algorithms and / or UE supports 256-bit security algorithms), and an indication that the UE supports 256-bit algorithms to the AMF / SEAF.
[0424] The indication that the UE supports the 256-bit algorithm is sent when the actual capability of the UE supports the 256-bit algorithm; that is, if the actual capability of the UE is based on 256-bit security capability, the UE will send an indication of support for the 256-bit algorithm to the AMF / SEAF.
[0425] In some embodiments, the UE may send the above information to the AMF / SEAF via N1message.
[0426] In step S9103, AMF / SEAF sends the UE identity (e.g., SUCI or SUPI), SN-name (Serving Network Name), UE security capabilities, and an indication of support for 256-bit algorithms (optional) to the AUSF.
[0427] The AMF / SEAF sends the UE identity (e.g., SUCI, 5G-GUTI), SN-name, and UE security capabilities (e.g., UE supports 128-bit security algorithms and 256-bit security algorithms) to the AUSF.
[0428] In some embodiments, AMF / SEAF may send the above information to AUSF via a Nausf_UEAuthentication_Authenticate Request message.
[0429] In step S9104, the AUSF sends the UE identity (such as SUCI or SUPI), SN-name, UE security capabilities, and an indication of support for 256-bit algorithms (optional) to the UDM / APRF / SIDF.
[0430] In some embodiments, the AUSF may send the above information to the UDM / APRF / SIDF via a Nudm_UEAuthentication_Get Request message.
[0431] In step S9105 , UDM / APRF / SIDF performs SUCI to SUPI de-concealment.
[0432] Step S9106: UDM / APRF / SIDF selects the authentication method.
[0433] In some embodiments, security capability information is used to determine an authentication algorithm.
[0434] Specifically, when the security capability information indicates that the terminal supports a security algorithm with a first bit number (for example, 128 bits), the UDM selects the authentication algorithm with the first bit number to authenticate with the terminal; when the security capability information indicates that the terminal supports a security algorithm with a second bit number (for example, 256 bits), the UDM selects the authentication algorithm with the second bit number to authenticate with the terminal.
[0435] The UDM / ARPF / SIDF selects the authentication method based on the SUCI / SUPI and an indication of support for 256-bit algorithms (optional).
[0436] Specifically, UDM / ARPF / SIDF uses SUCI / SUPI to retrieve the UE's long-term key K.
[0437] If the long-term key length is 256 bits and the UDM receives an indication that the 256-bit algorithm is supported, the UDM / ARPF / SIDF calculates the authentication vector based on the 256-bit security algorithm.
[0438] If the long-term key is 256 bits long and the UDM does not receive an indication that it supports 256-bit algorithms, the UDM / ARPF / SIDF computes at least one of the following by truncating the long-term key to 128 bits: the authentication vector, the CK, or the IK. Specifically, the UDM / ARPF / SIDF utilizes a 128-bit security algorithm to derive at least one of the following: a 128-bit authentication vector, a 128-bit CK, and a 128-bit IK.
[0439] or
[0440] If the long-term key length is 256 bits and the UDM does not receive an indication that the 256-bit algorithm is supported, the UDM / ARPF / SIDF calculates at least one of the following based on the 256-bit security algorithm: authentication vector, CK, IK. Specifically, the UDM / ARPF / SIDF uses a 256-bit security algorithm (e.g., TUAK, MILENAGE-256) to derive at least one of the following: a 256-bit authentication vector, a 256-bit CK, and a 256-bit IK. Then, the AUSF / ARPF truncates the 256-bit authentication vector / CK / IK to a 128-bit authentication vector / CK / IK. In the embodiment of the present disclosure, when the security levels of the USIM and the ME are inconsistent, during the algorithm negotiation process, the UE can indicate the security algorithms it supports; when the security levels of the USIM and the ME are inconsistent, the core network can select the correct key derivation mechanism.
[0441] Figure 9B is an interactive diagram of a secure communication method according to an embodiment of the present disclosure. As shown in Figure 9B, the embodiment of the present disclosure relates to a secure communication method, which includes:
[0442] In step S9201, the UE sends the UE identity (e.g., SUCI or 5G-GUTI), the UE's security capabilities, or the UE's ME's security capabilities (e.g., the UE supports 128-bit security algorithms and / or the UE supports 256-bit security algorithms) to the AMF / SEAF.
[0443] In some embodiments, the UE may send the above information to the AMF / SEAF via N1message.
[0444] In step S9202, the AMF / SEAF sends the UE identity (e.g., SUCI or SUPI), SN-name, and UE security capabilities to the AUSF.
[0445] The AMF / SEAF sends the UE identity (e.g., SUCI, 5G-GUTI), SN-name, and UE security capabilities (e.g., UE supports 128-bit security algorithms and 256-bit security algorithms) to the AUSF.
[0446] In some embodiments, AMF / SEAF may send the above information to AUSF via a Nausf_UEAuthentication_Authenticate Request message.
[0447] Step S9203: AUSF sends the UE identity (eg, SUCI or SUPI), SN-name, and UE security capabilities to UDM / APRF / SIDF.
[0448] In some embodiments, the AUSF may send the above information to the UDM / APRF / SIDF via a Nudm_UEAuthentication_Get Request message.
[0449] In step S9204, UDM / APRF / SIDF performs SUCI to SUPI de-concealment.
[0450] Step S9205: UDM / APRF / SIDF selects the authentication method.
[0451] UDM / ARPF / SIDF selects the authentication method based on SUCI / SUPI and UE security capabilities.
[0452] Specifically, UDM / ARPF / SIDF uses SUCI / SUPI to retrieve the UE's long-term key K.
[0453] UDM determines the security capabilities of the terminal through the following strategies.
[0454] If the retrieved long-term key K is 128 bits and the ME of the terminal supports both 128-bit security algorithms and 256-bit security algorithms, the actual security capability of the UE is the security capability based on 128 bits.
[0455] If the retrieved long-term key K is 128 bits and the ME of the terminal only supports 128-bit security algorithms, the actual security capability of the UE is based on the 128-bit security capability.
[0456] If the retrieved long-term key K is 256 bits and the ME of the terminal supports both 128-bit and 256-bit security algorithms, the actual security capability of the UE is the security capability based on 128-bit and 256-bit.
[0457] If the retrieved long-term key K is 256 bits and the ME of the terminal only supports 128-bit security algorithms, the actual security capability of the UE is the security capability based on 128 bits.
[0458] If the long-term key length is 256 bits and the UDM determines that the actual capability of the terminal is to support 256-bit security capabilities, the UDM / ARPF / SIDF calculates at least one of the following according to the 256-bit security algorithm: the authentication vector, CK, and IK.
[0459] If the long-term key is 256 bits long and the UDM determines that the terminal's actual capability supports 128-bit security, the UDM / ARPF / SIDF truncates the long-term key to 128 bits to calculate at least one of the following: the authentication vector, the CK, and the IK. Specifically, the UDM / ARPF / SIDF utilizes a 128-bit security algorithm (e.g., TUAK, MILENAGE-128) to derive at least one of the following: a 128-bit authentication vector, a 128-bit CK, and a 128-bit IK.
[0460] or
[0461] If the long-term key length is 256 bits and the UDM determines that the terminal's actual capability supports 128-bit security, the UDM / ARPF / SIDF calculates at least one of the following based on a 256-bit security algorithm: the authentication vector, CK, and IK. Specifically, the UDM / ARPF / SIDF utilizes a 256-bit security algorithm (e.g., TUAK, MILENAGE-256) to derive at least one of the following: a 256-bit authentication vector, a 256-bit CK, and a 256-bit IK. The AUSF / ARPF then truncates the 256-bit authentication vector / CK / IK to a 128-bit authentication vector / CK / IK.
[0462] Step S9206: UDM / APRF / SIDF sends the actual security capabilities of the UE to AUSF.
[0463] Step S9207, AUSF sends the actual security capabilities of the UE to AMF / SEAF.
[0464] The AMF selects the security algorithm used in the NAS security process based on the actual security capabilities of the UE provided by the UDM.
[0465] In some embodiments, after AMF / SEAF obtains the actual security capabilities of the terminal, it determines the security algorithm used to communicate with the terminal based on the actual security capabilities of the terminal.
[0466] In step S9208, the AMF / SEAF sends the actual security capabilities of the UE to the gNB.
[0467] The gNB selects the security algorithm used in the application server security process based on the actual security capabilities of the UE provided by the UDM.
[0468] It can be understood that the UE security capabilities in the above steps S9201, S9202, and S9203 refer to the security algorithms supported by the UE (for example, 128-bit security algorithms and / or 256-bit security algorithms), and the UE security capabilities in steps S9206, S9207, and S9208 refer to the actual security capabilities of the UE.
[0469] Figure 9C is an interactive diagram of a secure communication method according to an embodiment of the present disclosure. As shown in Figure 9C, the embodiment of the present disclosure relates to a secure communication method, which includes:
[0470] In step S9301, the UE sends the UE identity (e.g., SUCI or 5G-GUTI) and UE security capabilities (e.g., UE supports 128-bit security algorithms and / or UE supports 256-bit security algorithms) to the AMF / SEAF.
[0471] In some embodiments, the UE may send the above information to the AMF / SEAF via N1message.
[0472] Step S9302: AMF / SEAF sends the UE identity (e.g., SUCI or SUPI) and SN-name to AUSF.
[0473] AMF / SEAF sends the UE identity (e.g., SUCI, 5G-GUTI) and SN-name to AUSF.
[0474] In some embodiments, AMF / SEAF may send the above information to AUSF via a Nausf_UEAuthentication_Authenticate Request message.
[0475] Step S9303: AUSF sends the UE identity (eg, SUCI or SUPI) and SN-name to UDM / APRF / SIDF.
[0476] In some embodiments, the AUSF may send the above information to the UDM / APRF / SIDF via a Nudm_UEAuthentication_Get Request message.
[0477] In step S9304, UDM / APRF / SIDF performs SUCI to SUPI de-concealment.
[0478] Step S9305: UDM / APRF / SIDF selects the authentication method.
[0479] UDM / ARPF / SIDF selects the authentication method based on SUCI / SUPI and UE security capabilities.
[0480] Specifically, UDM / ARPF / SIDF uses SUCI / SUPI to retrieve the UE's long-term key K.
[0481] Step S9306, UDM / APRF / SIDF sends a key length indication to AUSF.
[0482] If the retrieved long-term key K is 256 bits, the UDM sends the length of the long-term key to the AUSF.
[0483] Step S9307, AUSF sends a key length indication to AMF / SEAF.
[0484] The AUSF sends the length of the long-term key to the AMF.
[0485] The AMF can use the same mechanism as the UDM in step S9205 to determine the actual security capabilities of the UE based on the long-term key length provided by the UDM and the security capability information provided by the UE. The AMF selects the security algorithm used in the NAS security process based on the actual security capabilities of the UE.
[0486] In some embodiments, after AMF / SEAF obtains the actual security capabilities of the terminal, it determines the security algorithm used to communicate with the terminal based on the actual security capabilities of the terminal.
[0487] In step S9308, the AMF / SEAF sends a key length indication to the gNB.
[0488] The AMF sends the length of the long-term key to the gNB.
[0489] The gNB may determine the UE's actual security capabilities based on the long-term key length and the UE's security capabilities information provided by the AMF using the same mechanism as for UDM in step S9205. Alternatively, the AMF may send the UE's actual security capabilities determined by itself to the gNB instead of sending the long-term key length and the UE's security capabilities provided by the gNB.
[0490] In some embodiments, the gNB selects a security algorithm to be used in communications with the terminal based on the newly determined actual security capabilities of the UE. If the AMF / gNB does not receive the key length information sent by the UDM, the AMF / gNB may determine that the key length is 128 bits.
[0491] The secure communication method of FIG. 9A may be used in an authentication process, and the secure communication methods of FIG. 9B and FIG. 9C may be used in a NAS / AS communication process.
[0492] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations of other embodiments.
[0493] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0494] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.
[0495] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
[0496] Figure 10A is a schematic diagram of the structure of a terminal proposed in an embodiment of the present disclosure. As shown in Figure 10A, terminal 10100 may include a transceiver module 10101. In some embodiments, transceiver module 10101 is used to send security capability information. Optionally, the transceiver module is used to perform at least one of the steps (such as, but not limited to, steps S2102 and S2201) of processing network function execution in any of the above methods, which will not be repeated here.
[0497] Figure 10B is a schematic diagram of the structure of the UDM proposed in an embodiment of the present disclosure. As shown in Figure 10B, UDM 10200 may include: a transceiver module 10201. In some embodiments, the transceiver module 10201 is used to receive security capability information or send the number of bits of the first key to the AUSF. Optionally, the transceiver module is used to perform at least one of the steps (such as step S2102, step S2201, but not limited to) of the processing performed by the network function in any of the above methods, which will not be repeated here.
[0498] FIG10C is a schematic diagram of the structure of the AUSF proposed in an embodiment of the present disclosure. As shown in FIG10C , the AUSF 10300 may include a transceiver module 10301. In some embodiments, the transceiver module 10301 is used to receive security capability information. Optionally, the transceiver module is used to perform at least one of the steps (such as step S2202, but not limited thereto) of processing the network function execution in any of the above methods, which will not be repeated here.
[0499] Figure 10D is a schematic diagram of the AMF structure proposed in an embodiment of the present disclosure. As shown in Figure 10D, AMF 10400 may include a transceiver module 10401. In some embodiments, transceiver module 10401 is configured to receive security capability information. Optionally, the transceiver module is configured to perform at least one of the steps (e.g., but not limited to, step S2203) of processing the network function execution in any of the above methods, which will not be further described here.
[0500] Figure 10E is a schematic diagram of the structure of an access network device proposed in an embodiment of the present disclosure. As shown in Figure 10E, access network device 10500 may include a transceiver module 10501. In some embodiments, transceiver module 10501 is configured to receive security capability information. Optionally, the transceiver module is configured to perform at least one of the steps (e.g., but not limited to, step S2207) of processing network function execution in any of the above methods, which will not be further described here.
[0501] Figure 11A is a schematic diagram of the structure of a communication device 11100 proposed in an embodiment of the present disclosure. Communication device 11100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 11100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.
[0502] As shown in Figure 11A, the communication device 11100 includes one or more processors 11101. The processor 11101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process the communication protocol and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. Optionally, the communication device 11100 is used to perform any of the above methods. Optionally, one or more processors 11101 are used to call instructions to enable the communication device 11100 to perform any of the above methods.
[0503] In some embodiments, the communication device 11100 further includes one or more transceivers 11102. When the communication device 11100 includes one or more transceivers 11102, the transceiver 11102 performs at least one of the communication steps such as sending and / or receiving in the above method (for example, step S2102 and step S2103, but not limited thereto), and the processor 11101 performs at least one of the other steps (for example, step S2101, but not limited thereto). In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface may be interchangeable, the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be interchangeable, and the terms receiver, receiving unit, receiver, and receiving circuit may be interchangeable.
[0504] In some embodiments, the communication device 11100 further includes one or more memories 11103 for storing data. Alternatively, all or part of the memories 11103 may be located outside the communication device 11100. In alternative embodiments, the communication device 11100 may include one or more interface circuits 11104. Optionally, the interface circuits 11104 are connected to the memories 11103 and may be configured to receive data from the memories 11103 or other devices, or to send data to the memories 11103 or other devices. For example, the interface circuits 11104 may read data stored in the memories 11103 and send the data to the processor 11101.
[0505] The communication device 11100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 11100 described in the present disclosure is not limited thereto, and the structure of the communication device 11100 may not be limited to FIG. 11A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
[0506] FIG11B is a schematic diagram of the structure of a chip 11200 according to an embodiment of the present disclosure. If the communication device 11100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 11200 shown in FIG11B , but the present disclosure is not limited thereto.
[0507] The chip 11200 includes one or more processors 11201. The chip 11200 is configured to execute any of the above methods.
[0508] In some embodiments, chip 11200 further includes one or more interface circuits 11202. Alternatively, the terms interface circuit, interface, and transceiver pins may be used interchangeably. In some embodiments, chip 11200 further includes one or more memories 11203 for storing data. Alternatively, all or part of memory 11203 may be located external to chip 11200. Optionally, interface circuit 11202 is connected to memory 11203. Interface circuit 11202 may be configured to receive data from memory 11203 or other devices, or to send data to memory 11203 or other devices. For example, interface circuit 11202 may read data stored in memory 11203 and send the data to processor 11201.
[0509] In some embodiments, interface circuit 11202 performs at least one of the communication steps (e.g., step S2102 and step S2103, but not limited thereto) of sending and / or receiving in the above method. Interface circuit 11202 performing the communication steps (e.g., step S2102 and step S2103, but not limited thereto) of sending and / or receiving in the above method, for example, means that interface circuit 11202 performs data exchange between processor 11201, chip 11200, memory 11203, or a transceiver device. In some embodiments, processor 11201 performs at least one of the other steps (e.g., step S2101, but not limited thereto).
[0510] The modules and / or devices described in various embodiments, such as virtual devices, physical devices, and chips, can be arbitrarily combined or separated according to circumstances. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.
[0511] The present disclosure also provides a storage medium having instructions stored thereon. When the instructions are executed on the communication device 11100, the communication device 11100 is caused to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto and may also be a transient storage medium.
[0512] The present disclosure also provides a program product, which, when executed by the communication device 11100, enables the communication device 11100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0513] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.
Claims
1. A secure communication method, characterized in that: The method comprises: The terminal sends security capability information to the network function of the core network through the access network.
2. The method according to claim 1, characterized in that The security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on at least one of the number of bits of the first key supported by the user identity module USIM of the terminal and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal.
3. The method according to claim 2, characterized in that The actual security capability is determined by at least one of the following methods: If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits and the second number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits and the second number of bits, determining that the actual security capability of the terminal is to support the first capability and the second capability; The first capability corresponds to a first number of bits of a security algorithm supported by the terminal, and the second capability corresponds to a second number of bits of a security algorithm supported by the terminal.
4. The method according to claim 3, characterized in that When the terminal supports the first capability, the security capability information includes at least one of the following: The first bit of the non-access stratum NAS security algorithm indicator and the first bit of the access stratum AS security algorithm indicator; The first bit of the authentication algorithm indicator; An indicator indicating that the terminal supports the security algorithm of the first bit; The first bit number; When the terminal supports the second capability, the security capability information includes at least one of the following: The second bit of the non-access stratum NAS security algorithm indicator and the second bit of the access stratum AS security algorithm indicator; The second bit is the authentication algorithm indicator; An indicator indicating that the terminal supports the security algorithm of the second bit number; The second bit.
5. The method according to claim 3, characterized in that The actual security capability is determined by the terminal, and the security capability information includes the actual security capability of the terminal.
6. The method according to claim 5, characterized in that The security capability information is sent after being integrity protected by the terminal using a security algorithm, and the number of bits of the security algorithm is the second number of bits.
7. The method according to claim 1, characterized in that The security capability information is used to determine an authentication algorithm.
8. The method according to claim 7, characterized in that The method further comprises: When the security capability information indicates that the terminal supports the security algorithm of the first bit number, the terminal and the UDM perform authentication based on the authentication algorithm of the first bit number selected by the UDM; When the security capability information indicates that the terminal supports the security algorithm of the second bit number, the terminal and the UDM perform authentication with the terminal based on the authentication algorithm of the second bit number selected by the UDM.
9. The method according to claim 1 or 8, characterized in that The method further comprises: The terminal performs secure communication based on the security information; The security information is determined based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal. The security information includes first security information and second security information. The first security information is determined by the terminal, and the second security information is determined by the network function of the core network.
10. The method according to claim 9, characterized in that The security information is determined based on the number of bits of the first key supported by the USIM of the terminal and the number of bits of the ME security algorithm of the terminal in the following manner: If the number of bits of the first key is the second number of bits, and the actual security capability of the terminal is to support the second capability, determining the security information according to the security algorithm of the first key and the second number of bits; If the first key bit number is the second bit number and the actual security capability of the terminal is to support the first capability, then truncating the first key to generate a first key of a first bit number, and determining security information according to the first key of the first bit number and a security algorithm of the first bit number; Alternatively, the security information is determined according to a security algorithm of the second bit number, and the security information is truncated into security information of the first bit number.
11. The method according to claim 2, characterized in that The actual security capability is determined by a network function of a core network, and the security capability information includes security capability information supported by the terminal or the ME of the terminal.
12. The method according to claim 11, characterized in that When the terminal or the ME of the terminal supports a security algorithm of a first bit number, the security capability information includes at least one of the following: The first bit of the non-access stratum NAS security algorithm indicator and the first bit of the access stratum AS security algorithm indicator; The first bit of the authentication algorithm indicator; An indicator indicating that the terminal supports the security algorithm of the first bit; The first bit number; When the terminal or the ME of the terminal supports the security algorithm of the second bit number, the security capability information includes at least one of the following: The second bit of the non-access stratum NAS security algorithm indicator and the second bit of the access stratum AS security algorithm indicator; The second bit is the authentication algorithm indicator; An indicator indicating that the terminal supports the security algorithm of the second bit number; The second bit.
13. The method according to claim 11, characterized in that The network functions of the core network include at least one of unified data management UDM, unified data warehouse UDR, authentication credential repository and processing function ARPF, and access and mobility management function AMF.
14. The method according to claim 11 or 13, characterized in that The network function of the core network includes an AMF, which is used to receive the number of bits of the first key supported by the USIM sent by the UDM network element or the actual security capability information of the terminal.
15. A secure communication method, characterized in that: The method comprises: The UDM receives security capability information.
16. The method according to claim 15, characterized in that The security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
17. The method according to claim 16, characterized in that The actual security capability is determined by at least one of the following methods: If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits and the second number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits and the second number of bits, determining that the actual security capability of the terminal is to support the first capability and the second capability; The first capability corresponds to a first number of bits of a security algorithm supported by the terminal, and the second capability corresponds to a second number of bits of a security algorithm supported by the terminal.
18. The method according to claim 17, characterized in that The actual security capability is determined by the terminal, and the security capability information includes the actual security capability of the terminal.
19. The method according to claim 18, characterized in that The security capability information is sent after being integrity protected by the terminal using a security algorithm, and the number of bits of the security algorithm is the second number of bits.
20. The method according to claim 15, wherein The security capability information is used to determine an authentication algorithm.
21. The method according to claim 20, characterized in that The method further comprises: When the security capability information indicates that the terminal supports the security algorithm of the first bit number, the UDM selects the authentication algorithm of the first bit number to perform authentication with the terminal; When the security capability information indicates that the terminal supports the security algorithm of the second bit number, the UDM selects the authentication algorithm of the second bit number to perform authentication with the terminal.
22. The method according to claim 15 or 21, characterized in that The method further comprises: The UDM determines security information based on the number of bits of the first key and the number of bits of the security algorithm.
23. The method according to claim 22, characterized in that Determining security information based on at least one of the number of bits of the first key and the number of bits of the security algorithm includes: If the number of bits of the first key is the second number of bits, and the actual security capability of the terminal is to support the second capability, determining the security information according to the security algorithm of the first key and the second number of bits; If the number of bits of the first key is the second number of bits and the actual security capability of the terminal is to support the first capability, the first key is truncated to the first key of the first number of bits, and the security information is determined based on the first key of the first number of bits and the security algorithm of the first number of bits; or, the security information is determined based on the security algorithm of the second number of bits, and the security information is truncated to the security information of the first number of bits.
24. The method according to claim 16, wherein The actual security capability is determined by the UDM, and the security capability information includes the number of bits of the security algorithm supported by the ME of the terminal.
25. The method according to claim 24, characterized in that The method further comprises: The indication information of the actual security capabilities of the terminal is sent to the AMF or access network device through the AUSF.
26. The method according to claim 25, characterized in that When the actual security capability of the terminal is to support the first capability, the indication information includes at least one of the following: The first bit of the non-access stratum NAS security algorithm indicator and the first bit of the access stratum AS security algorithm indicator; The first bit of the authentication algorithm indicator; An indicator indicating that the terminal supports the security algorithm of the first bit; The first bit number; When the actual security capability of the terminal is to support the second capability, the indication information includes at least one of the following: The second bit of the non-access stratum NAS security algorithm indicator and the second bit of the access stratum AS security algorithm indicator; The second bit of the authentication algorithm indicator; An indicator indicating that the terminal supports the security algorithm of the second bit number; The second bit.
27. The method according to claim 16, wherein The method further comprises: The UDM sends the number of bits of the first key to the AUSF, and the AUSF is used to send the number of bits of the first key to the AMF.
28. A secure communication method, characterized in that: The method comprises: UDM sends the number of bits of the first key to AUSF, and the AUSF is used to send the number of bits of the first key to AMF.
29. A secure communication method, characterized in that: The method comprises: AUSF receives the security capability information sent by AMF; The AUSF sends the security capability information to the UDM.
30. The method according to claim 29, wherein The security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
31. The method according to claim 30, wherein When the ME of the terminal supports the first capability, the security capability information includes at least one of the following: The first bit of the non-access stratum NAS security algorithm indicator and the first bit of the access stratum AS security algorithm indicator; The first bit of the authentication algorithm indicator; An indicator indicating that the terminal supports the security algorithm of the first bit; The first bit number; When the ME of the terminal supports the second capability, the security capability information includes at least one of the following: The second bit of the non-access stratum NAS security algorithm indicator and the second bit of the access stratum AS security algorithm indicator; The second bit of the authentication algorithm indicator; An indicator indicating that the terminal supports the security algorithm of the second bit number; The second bit.
32. The method according to claim 30, wherein The method further comprises: The AUSF receives the number of bits of the first key sent by the UDM or the actual security capability of the terminal; The AUSF sends the number of bits of the first key or the actual security capability of the terminal to the AMF.
33. A secure communication method, characterized in that: The method comprises: The AMF receives the security capability information sent by the terminal.
34. The method according to claim 33, wherein The security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
35. The method according to claim 33, wherein The method further comprises: The AMF sends the security capability information to the AUSF.
36. The method according to claim 33, wherein The method further comprises at least one of the following: The number of bits of the first key sent by the AUSF or the actual security capability of the terminal received by the AMF; The AMF sends the number of bits of the first key or the actual security capabilities of the terminal to the access network device.
37. The method according to claim 36, wherein The AMF determines the actual security capability based on the number of bits of the first key and the number of bits of the security algorithm; alternatively, the AMF determines the actual security capability based on the number of bits of the first key and the number of bits of the security algorithm; The security capability information sent by the terminal includes the number of bits of the first key.
38. The method according to claim 33, wherein The method further comprises at least one of the following: The AMF receives the actual security capabilities of the terminal sent by the AUSF; The AMF sends the actual security capabilities of the terminal to the access network device.
39. The method according to claim 37, wherein The actual security capability is determined by at least one of the following methods: If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits and the second number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits and the second number of bits, determining that the actual security capability of the terminal is to support the first capability and the second capability; The first capability corresponds to a first number of bits of a security algorithm supported by the terminal, and the second capability corresponds to a second number of bits of a security algorithm supported by the terminal.
40. The method according to claim 33, wherein The security capability information includes the actual security capability of the terminal.
41. A secure communication method, characterized in that: The method comprises: The access network device receives the security capability information sent by the AMF.
42. The method according to claim 41, wherein The security capability information is used to determine the actual security capability of the terminal, and the actual security capability is determined based on at least one of the number of bits of the first key supported by the USIM of the terminal and the number of bits of the security algorithm supported by the ME of the terminal.
43. The method according to claim 42, characterized in that The security capability information includes the number of bits of the first key, and the actual security capability is determined by the access network device.
44. The method according to claim 43, wherein The actual security capability is determined by at least one of the following methods: If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the first number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits and the second number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits, determining that the actual security capability of the terminal is to support the first capability; If the number of bits of the first key is the second number of bits, and the number of bits of the security algorithm supported by the mobile equipment ME of the terminal is the first number of bits and the second number of bits, determining that the actual security capability of the terminal is to support the first capability and the second capability; The first capability corresponds to the first bit number of the security algorithm supported by the terminal, and the second capability corresponds to the first bit number of the security algorithm supported by the terminal. The number of bits of the security algorithm supported by the terminal should be the second number of bits.
45. The method according to claim 44, wherein The security capability information includes the actual security capability of the terminal.
46. A terminal, characterized in that include: The transceiver module is used to send security capability information.
47. A UDM, characterized in that include: The transceiver module is used to receive security capability information.
48. A UDM, characterized in that include: The transceiver module is used to send the number of bits of the first key to the AUSF, and the AUSF is used to send the number of bits of the first key to the AMF.
49. An AUSF, characterized in that include: Transceiver module, used to receive security capability information sent by AMF; The security capability information is sent to the UDM.
50. An AMF, characterized in that include: The transceiver module is used to receive security capability information sent by the terminal.
51. An access network device, characterized in that: include: The transceiver module is used to receive security capability information sent by AMF.
52. A terminal, characterized in that: include: one or more processors; The terminal is configured to execute the communication method according to any one of claims 1 to 14.
53. A UDM, characterized in that: include: one or more processors; The UDM is used to execute the communication method according to any one of claims 15 to 27.
54. A UDM, characterized in that include: one or more processors; Wherein, the UDM is used to execute the communication method described in claim 28.
55. An AUSF, characterized in that include: one or more processors; The AUSF is used to execute the communication method described in any one of claims 29 to 32.
56. An AMF, characterized in that include: one or more processors; The AMF is used to execute the communication method described in any one of claims 33 to 40.
57. An access network device, characterized in that: include: one or more processors; The access network device is used to execute the communication method described in any one of claims 41 to 45.
58. A communication system, characterized in that It includes a terminal, a UDM, an AUSF, an AMF and an access network device, wherein the terminal is configured to implement the secure communication method described in any one of claims 1 to 14, the UDM is configured to implement the secure communication method described in any one of claims 15 to 28, the AUSF is configured to implement the secure communication method described in any one of claims 29 to 32, the AMF is configured to implement the secure communication method described in any one of claims 33 to 40, and the access network device is configured to implement the secure communication method described in any one of claims 41 to 45.
59. A storage medium storing instructions, characterized in that: When the instruction is executed on the communication device, the communication device executes the secure communication method according to any one of claims 1 to 14, or the secure communication method according to any one of claims 15 to 28, or the secure communication method according to any one of claims 29 to 32, or the secure communication method according to any one of claims 33 to 40, or the secure communication method according to any one of claims 41 to 45.
Citation Information
Patent Citations
Parameter protection method, device and system
CN109587680A
Security negotiation method, terminal equipment and network equipment
CN110366175A
Method for negotiating security capability of 5G mobile communication network
CN111787532A
Method, UE, and network for providing KDF negotiation
US20210409939A1