Identifier indication methods, apparatus, terminal device, and first network node
Patent Information
- Application Number
- PCT/CN2025/081056
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-08
- Filing Date
- 2025-03-06
- Publication Date
- 2025-10-02
AI Technical Summary
Some terminal devices do not have the ability to encrypt identification and cannot guarantee the security of identification information, especially when they do not have the network public key or the public key encryption computing power.
The terminal device generates first encrypted identification information using its stored information and information received from the second network node, and decrypts it through the first network node; at the same time, the first network node generates and sends second encrypted identification information to the terminal device to prevent the terminal device from performing encryption operations directly.
Even if the terminal device does not have encryption capabilities, it can still ensure the security of identification information. By using existing information for encryption, the security and integrity of information transmission can be ensured.
Smart Images

Figure CN2025081056_02102025_PF_FP_ABST
Abstract
Description
Identification indication method, device, terminal equipment and first network node
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on March 8, 2024, with application number 202410267951.9 and invention name “Identification indication method, device, terminal equipment and first network node”, the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communications, and more specifically, to an identification indication method, apparatus, terminal equipment, and a first network node. Background Art
[0004] In related technologies, a terminal device encrypts its identifier using the network's public key and sends the encrypted identifier to the network. Upon receiving the encrypted identifier, the network decrypts it using its private key to obtain the terminal device's identifier.
[0005] However, some terminal devices do not have the ability to encrypt identification, such as not having the network's public key or not having the computing power to use public key encryption, which makes it impossible to ensure the security of the terminal device's indication identification information. Summary of the Invention
[0006] The embodiments of the present application provide an identification indication method, apparatus, terminal device, and first network node, which can ensure the security of identification information indicated by the terminal device.
[0007] In a first aspect, a method for indicating an identity is provided, comprising at least one of the following:
[0008] The terminal device sends first information to the first network node;
[0009] The terminal device receives second information from the first network node;
[0010] The first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
[0011] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0012] In a second aspect, a method for identifying and indicating is provided, comprising at least one of the following:
[0013] The first network node receives first information from the terminal device;
[0014] The first network node sends second information to the terminal device;
[0015] The first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device;
[0016] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0017] In a third aspect, a marking indicating device is provided, comprising at least one of the following:
[0018] A first sending unit, configured to send first information to a first network node;
[0019] a receiving unit, configured to receive second information from the first network node;
[0020] The first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
[0021] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0022] In a fourth aspect, a marking indicating device is provided, comprising at least one of the following:
[0023] A receiving unit, configured to receive first information from a terminal device;
[0024] A sending unit, configured to send second information to a terminal device;
[0025] The first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device;
[0026] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0027] In a fifth aspect, a terminal device is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.
[0028] In a sixth aspect, a terminal device is provided, comprising a processor and a communication interface, wherein the communication interface is configured to perform at least one of the following:
[0029] Sending first information to the first network node;
[0030] receiving second information from the first network node;
[0031] The first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information is included in at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
[0032] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0033] In a seventh aspect, a first network node is provided, comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the second aspect are implemented.
[0034] In an eighth aspect, a first network node is provided, comprising a processor and a communication interface, wherein the communication interface is configured to perform at least one of the following:
[0035] receiving first information from a terminal device;
[0036] Sending second information to the terminal device;
[0037] The first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device;
[0038] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0039] In the ninth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented.
[0040] In the tenth aspect, a wireless communication system is provided, comprising: a terminal device and a first network node, wherein the terminal device can be used to execute the steps of the method described in the first aspect, and the first network node can be used to execute the steps of the method described in the second aspect.
[0041] In the eleventh aspect, a chip is provided, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect.
[0042] In a twelfth aspect, a computer program / program product is provided, wherein the computer program / program product is stored in a storage medium, and the program / program product is executed by at least one processor to implement the steps of the method described in the first aspect.
[0043] In an embodiment of the present application, a terminal device sends first information to a first network node; wherein the first information includes first encrypted identification information, which is generated based on the first identifier and a first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from a second network node. In other words, the terminal device can obtain the first information or the first encrypted identification information from at least one of the stored information of the terminal device and the information received by the terminal device from the second network node. Thus, even if the terminal device does not have the ability to encrypt the identifier, the security of the identifier information indicated by the terminal device can be guaranteed. In other words, by encrypting the identifier using the terminal's stored information or the information received by the terminal, the identifier can be encrypted or decrypted based on the terminal's existing information, regardless of whether the terminal has a public key or public key decryption capability. The terminal device receives second information from the first network node; wherein the second information includes second encrypted identification information, which is generated based on the terminal device's first identifier and the second key. This is equivalent to the terminal device receiving the second encrypted identification information from the first network node. Therefore, even if the terminal device does not have the ability to encrypt the identification, the security of the identification information indicated by the terminal device can be guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0045] FIG1 is a schematic diagram of a system architecture provided in an embodiment of the present application.
[0046] FIG2 is a schematic flowchart of an identification indication method provided in an embodiment of the present application.
[0047] FIG3 is a schematic flowchart of another identification indication method provided in an embodiment of the present application.
[0048] FIG4 is a schematic flowchart of another identification indication method provided in an embodiment of the present application.
[0049] FIG5 is a schematic block diagram of an identification indicating device provided in an embodiment of the present application.
[0050] FIG6 is a schematic block diagram of another identification indicating device provided in an embodiment of the present application.
[0051] FIG7 is a schematic block diagram of a communication device provided in an embodiment of the present application.
[0052] FIG8 is a schematic diagram of the hardware structure of a terminal provided in an embodiment of the present application.
[0053] FIG9 is a schematic block diagram of a network-side device provided in an embodiment of the present application.
[0054] FIG10 is a schematic block diagram of another network-side device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0055] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.
[0056] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0057] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.
[0058] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for illustrative purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as 6th generation (6G) systems. th Generation, 6G) communication system.
[0059] FIG1 shows a block diagram of a wireless communication system applicable to an embodiment of the present application.
[0060] As shown in FIG1 , the wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 may be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipborne equipment, pedestrian user equipment (PUE), smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, self-service kiosk, or other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle-mounted device can also be called a vehicle-mounted terminal, vehicle-mounted controller, vehicle-mounted module, vehicle-mounted component, vehicle-mounted chip or vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application.
[0061] The network side device 12 may include an access network device or a core network device.
[0062] Access network equipment may also be referred to as radio access network (RAN) equipment, radio access network functions, or radio access network units. Access network equipment may include base stations, wireless local area network (WLAN) access points (APs), or wireless fidelity (WiFi) nodes. Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
[0063] The core network device may include but is not limited to at least one of the following: core network node, core network function, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application server discovery function (EASDF), unified data management (UDM), unified data storage (UDR), home user server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (BNSF), network access function (UE ... Function, BSF), application function (Application Function, AF), etc. It should be noted that in the embodiment of the present application, only the core network device in the NR system is introduced as an example, and the specific type of the core network device is not limited.But not limited to at least one of the following: core network node, core network function, Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized Network Configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), etc. It should be noted that in the embodiments of this application, only the core network equipment in the NR system is introduced as an example, and the specific type of the core network equipment is not limited.
[0064] The identification indication method provided by the embodiment of the present application is described in detail below through some embodiments and their application scenarios in combination with the accompanying drawings.
[0065] FIG2 is a schematic flowchart of a method 210 for indicating an identity according to an embodiment of the present application.
[0066] As shown in FIG2 , the identification indication method 210 may include at least part of the following contents:
[0067] S211, the terminal device sends first information to the first network node;
[0068] The first information includes first encrypted identification information, which is generated based on the first identification and first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the storage information of the terminal device and the information received by the terminal device from the second network node.
[0069] Exemplarily, the first network node includes at least one of the following: UE, access network equipment, AMF, UDM, AF, AuC.
[0070] Exemplarily, the first network to which the first network node belongs may be a 3GPP network, such as a 5G network or a future 6G network.
[0071] Exemplarily, the second network node includes at least one of the following: UE, access network equipment, AMF, UDM, AF, AuC, AUSF.
[0072] Exemplarily, the second network to which the second network node belongs may be the same as or different from the first network. For example, the second network may be a 3GPP network, such as a 5G network or a future 6G network, or may even be a non-3GPP network.
[0073] Exemplarily, the first encrypted identification information may be generated by encrypting the first identification based on the first key, or the first encrypted identification information may be generated by using an encryption algorithm with the first identification and the first key as input.
[0074] In an embodiment of the present application, the terminal device can obtain the first encrypted identification information from at least one of the stored information of the terminal device and the information received by the terminal device from the second network node. Thus, even if the terminal device does not have the ability to encrypt the identification, the security of the identification information indicated by the terminal device can be guaranteed.
[0075] In some embodiments, the first network node decrypts the first encrypted identification information based on at least one of the following:
[0076] the first key;
[0077] An associated key of the first key.
[0078] Exemplarily, when the first key is not a symmetric key (ie, the first key is a public key), the associated key is a corresponding private key.
[0079] In some embodiments, the first information further includes fourth information, and the first encrypted identification information is further generated based on the fourth information.
[0080] Exemplarily, the first encrypted identification information is generated based on the first identification, the first key and the fourth information.
[0081] In some embodiments, the first information further includes fourth information, and the method 210 further includes:
[0082] The first network node decrypts the first encrypted identification information based on at least one of the following:
[0083] the first key and the fourth information;
[0084] an associated key of the first key and the fourth information.
[0085] Exemplarily, when the first key is not a symmetric key (ie, the first key is a public key), the associated key is a corresponding private key.
[0086] In some embodiments, the first information further includes a first verification code, where the first verification code is generated based on at least one of the following:
[0087] the first identifier and the first key;
[0088] The first encrypted identification information and the third key.
[0089] In some embodiments, the method 210 further includes:
[0090] The terminal device generates the first verification code based on the first encryption identifier and the third key.
[0091] Of course, in other alternative embodiments, a network node (which may be the first network node, the second network node, or other network nodes) may generate the first verification code based on the first encryption identifier and the third key, and configure it to the terminal device.
[0092] In some embodiments, the first information further includes a first verification code, and the method 210 further includes:
[0093] The first network node verifies the first verification code based on at least one of the following:
[0094] the first identifier and the first key;
[0095] an associated key between the first identifier and the first key;
[0096] The first encrypted identification information and the third key.
[0097] Exemplarily, the first verification code is a verification code generated by a network node (which may be a first network node, a second network node, or another network node) and preconfigured for the terminal device, and the first network node verifies the first verification code based on at least one of the following:
[0098] the first identifier and the first key;
[0099] The first identifier and an associated key of the first key.
[0100] Exemplarily, the first verification code is a verification code generated by the terminal device, and the first network node verifies the first verification code based on the first encrypted identification information and a third key.
[0101] In some embodiments, the first information further includes a first verification code and fourth information, where the first verification code is generated based on at least one of the following:
[0102] the first identifier, the first key, and the fourth information;
[0103] The first encrypted identification information, the third key and the fourth information.
[0104] In some embodiments, the method 210 further includes:
[0105] The terminal device generates the first verification code based on the first encryption identifier, the third key and the fourth information.
[0106] Of course, in other alternative embodiments, a network node (which may be the first network node, the second network node, or other network node) may generate the first verification code based on the first encryption identifier, the third key and the fourth information, and configure it to the terminal device.
[0107] In some embodiments, the first information further includes a first check code and fourth information, and the method 210 further includes:
[0108] The first network node verifies the first verification code based on at least one of the following:
[0109] the first identifier, the first key, and the fourth information;
[0110] the first identifier, a key associated with the first key, and the fourth information;
[0111] The first encrypted identification information, the third key and the fourth information.
[0112] Exemplarily, the first verification code is a verification code generated by a network node (which may be a first network node, a second network node, or another network node) and preconfigured for the terminal device, and the first network node verifies the first verification code based on at least one of the following:
[0113] the first identifier, the first key, and the fourth information;
[0114] the first identifier, a key associated with the first key, and the fourth information;
[0115] Exemplarily, the first verification code is a verification code generated by the terminal device, and the first network node verifies the first verification code based on the first encryption identification information, the third key and the fourth information.
[0116] In some embodiments, the first information further includes at least one of the following:
[0117] a first key identifier, index, or indication corresponding to the first key;
[0118] A third key identifier, index, or indication corresponding to the third key.
[0119] Exemplarily, the first key corresponding to the first key indicates an index or identifier of the first key.
[0120] Exemplarily, the third key corresponding to the third key indicates an index or identifier of the first key.
[0121] In some embodiments, the terminal device is unknown to the first key.
[0122] Exemplarily, the terminal device is unaware of the first key because it has not obtained or received the first key from the network side, and thus will not generate the first information and / or the first encryption identifier, because the first information and / or the first encryption identifier need to be generated based on the first key.
[0123] In some embodiments, the first key is a symmetric key, or a shared key, or is not an asymmetric key or is not a public key.
[0124] Exemplarily, the first key may be a public key of an asymmetric key, or may be a symmetric key.
[0125] For example, symmetric-key algorithms and shared keys use the same key for both encryption and decryption. Asymmetric-key cryptography, also known as public-key cryptography, is a different type of encryption. In this method, keys are divided into a pair: a public key and a private key. The public key is public and can be freely distributed to anyone, while the private key is kept secret and known only to the holder. The public key is used to encrypt information, while the private key is used to decrypt it.
[0126] It should be understood that in the present application, the fourth information may be any information used for or involved in generating the first encryption identifier, and the present application does not limit its specific content.
[0127] In addition, the verification code involved in this application can be used to verify the integrity and accuracy of data. For example, taking the first verification code as an example, which is generated based on the first identifier and the first key, after receiving the first information, the first network node regenerates the verification code based on the first identifier and the first key, and verifies the first verification code based on the regenerated verification code. If the regenerated verification code successfully matches the first verification code, it means that the information has not been tampered with or damaged during transmission, and the information is complete and accurate. This is because only when the correct identifier and key are used and the information itself has not changed can the generated verification code be guaranteed to be the same as the first verification code. If the regenerated verification code does not successfully match the first verification code, it means that the information has been tampered with or damaged during transmission, or that the identifier and key used by the terminal device and the first network node are inconsistent. In this case, the first network node can determine that the information transmission has failed, or require the terminal device to resend or retransmit the first information.
[0128] FIG3 is a schematic flowchart of the identification indication method 220 according to an embodiment of the present application.
[0129] As shown in FIG3 , the identification indication method 220 may include at least part of the following contents:
[0130] S221, the terminal device receives second information from the first network node;
[0131] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0132] Exemplarily, the first network node includes at least one of the following: UE, access network equipment, AMF, UDM, AF, AuC.
[0133] Exemplarily, the first network to which the first network node belongs may be a 3GPP network, such as a 5G network or a future 6G network.
[0134] Exemplarily, after the first network node obtains or generates the second encrypted identification information, it sends the second information to the terminal device.
[0135] Exemplarily, the first network node may receive the second information from a third communication node; or the first network node may decrypt the second encrypted identification information received from the third communication node; or the first network node may generate the second encrypted identification; or the first network node may send the second encrypted identification generated by the first network node to the third network node. Optionally, the third communication node includes at least one of the following: AUSF, UDM, AF, and AuC.
[0136] Exemplarily, the second encrypted identification information may be generated by encrypting the first identification based on the second key, or the second encrypted identification information may be generated by using an encryption algorithm with the first identification and the second key as input.
[0137] In this embodiment, the terminal device receives the second encrypted identification information from the first network node, which avoids the terminal device from encrypting the identification of the terminal device. Therefore, even if the terminal device does not have the ability to encrypt the identification, the security of the identification information indicated by the terminal device can be guaranteed.
[0138] In some embodiments, the method 220 further includes at least one of the following:
[0139] The terminal device stores the second encrypted identification information or the second information;
[0140] The terminal device sends third information to a third network node, where the third information includes the second encryption identification information or the second information.
[0141] In some embodiments, the method 220 further includes:
[0142] The first network node generates the second encrypted identification information based on the second key and the first identification.
[0143] Exemplarily, before sending the second information, the first network node generates the second encrypted identification information based on the second key and the first identification.
[0144] In some embodiments, the second information further includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
[0145] In some embodiments, the method 220 further includes:
[0146] The first network node generates the second encrypted identification information based on the second key, the first identification and the fifth information.
[0147] Exemplarily, before sending the second information, the first network node generates the second encrypted identification information based on the second key, the first identification and the fifth information.
[0148] In some embodiments, the second information further includes a second verification code, where the second verification code is generated based on at least one of the following:
[0149] the first identifier and the second key;
[0150] The second encrypted identification information and the fourth key.
[0151] In some embodiments, the method 220 further includes:
[0152] The terminal device verifies the second verification code based on the second encrypted identification information and the fourth key.
[0153] Exemplarily, after receiving the second information, the terminal device verifies the second verification code based on the second encryption identification information and the fourth key.
[0154] In some embodiments, the method 220 further includes:
[0155] The first network node generates the second verification code based on at least one of the following:
[0156] the first identifier and the second key;
[0157] The second encrypted identification information and the fourth key.
[0158] Exemplarily, before sending the second information, the first network node generates the second check code based on at least one of the following:
[0159] the first identifier and the second key;
[0160] The second encrypted identification information and the fourth key.
[0161] In some embodiments, the second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following:
[0162] the first identifier, the second key, and the fifth information;
[0163] The second encrypted identification information, the fourth key and the fifth information.
[0164] In some embodiments, the method 220 further includes:
[0165] The terminal device verifies the second verification code based on the second encryption identification information, the fourth key and the fifth information.
[0166] Exemplarily, before sending the second information, the terminal device verifies the second verification code based on the second encryption identification information, the fourth key and the fifth information.
[0167] In some embodiments, the method 220 further includes:
[0168] The first network node generates the second verification code based on at least one of the following:
[0169] the first identifier, the second key, and the fifth information;
[0170] The second encrypted identification information, the fourth key and the fifth information.
[0171] Of course, in other alternative embodiments, the second check code may also be generated by a network node other than the first network node, and this application does not make any specific limitation on this.
[0172] In some embodiments, the second information further includes at least one of the following:
[0173] a second key identifier, index, or indication corresponding to the second key;
[0174] A fourth key identifier, index, or indication corresponding to the fourth key.
[0175] In some embodiments, the terminal device is unaware of the second key.
[0176] Exemplarily, the terminal device is unaware of the second key because it has not obtained or received the second key from the network side, and thus will not generate the second information and / or the second encryption identifier, because the second information and / or the second encryption identifier need to be generated based on the second key.
[0177] In some embodiments, the second key is a symmetric key, or a shared key, or is not an asymmetric key or is not a public key.
[0178] Exemplarily, the second key may be a public key of an asymmetric key, or may be a symmetric key.
[0179] For example, symmetric-key algorithms and shared keys use the same key for both encryption and decryption. Asymmetric-key cryptography, also known as public-key cryptography, is a different type of encryption. In this method, keys are divided into a pair: a public key and a private key. The public key is public and can be freely distributed to anyone, while the private key is kept secret and known only to the holder. The public key is used to encrypt information, while the private key is used to decrypt it.
[0180] It should be understood that the third information may be any information used to carry the second encrypted identification information, and this application does not limit its specific content. Similarly, the fifth information may be any information used for or involved in generating the second encrypted identification, and this application does not limit its specific content.
[0181] In addition, the verification code involved in this application can be used to verify the integrity and accuracy of data. For example, taking the second verification code as an example, which is generated based on the second encrypted identification information and the fourth key, after the terminal device receives the second information, it regenerates the verification code based on the second encrypted identification information and the fourth key, and verifies the second verification code based on the regenerated verification code. If the regenerated verification code and the second verification code match successfully, it means that the information has not been tampered with or damaged during the transmission process, and the information is complete and accurate. This is because only when the correct identifier and key are used and the information itself has not changed can the generated verification code be guaranteed to be the same as the first verification code. If the regenerated verification code does not match the second verification code successfully, it means that the information has been tampered with or damaged during the transmission process, or the identifier and key used by the terminal device are inconsistent. In this case, the terminal device can determine that the information transmission has failed, or request the first network node to resend or retransmit the second information.
[0182] In addition, the third key and the fourth key mentioned above may be different or the same, and this application does not make any specific limitations on this.
[0183] FIG4 is a schematic flowchart of the identification indication method 230 according to an embodiment of the present application.
[0184] As shown in FIG4 , the identification indication method 230 may include at least part of the following contents:
[0185] S231, the terminal device receives second information from the first network node;
[0186] The second information includes second encrypted identification information and a second verification code, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0187] Exemplarily, the first network node includes at least one of the following: UE, access network equipment, AMF, UDM, AF, AuC.
[0188] Exemplarily, the first network to which the first network node belongs may be a 3GPP network, such as a 5G network or a future 6G network.
[0189] Exemplarily, after the first network node obtains or generates the second encrypted identification information, it sends the second information to the terminal device.
[0190] Exemplarily, after the first network node obtains or generates the second verification code, it sends the second information to the terminal device.
[0191] Exemplarily, the first network node may receive the second information from a third communication node; or the first network node may decrypt the second encrypted identification information received from the third communication node; or the first network node may generate the second encrypted identification; or the first network node may send the second encrypted identification generated by the first network node to the third network node. Optionally, the third communication node includes at least one of the following: AUSF, UDM, AF, and AuC.
[0192] Exemplarily, the second encrypted identification information may be generated by encrypting the first identification based on the second key, or the second encrypted identification information may be generated by using an encryption algorithm with the first identification and the second key as input.
[0193] In this embodiment, the terminal device receives the second encrypted identification information from the first network node, which avoids the terminal device from encrypting the identification of the terminal device. Therefore, even if the terminal device does not have the ability to encrypt the identification, the security of the identification information indicated by the terminal device can be guaranteed.
[0194] S232, the terminal device verifies the second verification code. For example, when the second verification code is generated based on the third key and the second encryption identifier, the terminal device verifies the second verification code based on the third key and the second encryption identifier information.
[0195] S233: The terminal device generates a first verification code based on the fourth key and the second encryption identification information.
[0196] S234, the terminal device sends third information to the second network node, wherein the third information includes the second encrypted identification information and the first verification code.
[0197] S235: The second network node verifies the first verification code based on the fourth key and the second encryption identification information.
[0198] It should be understood that the third key and the fourth key may be the same or different.
[0199] The identification indication method provided in the embodiment of the present application can be executed by an identification indication device. In the embodiment of the present application, the identification indication device provided in the embodiment of the present application is described by taking the identification indication method executed by the identification indication device as an example.
[0200] FIG5 is a schematic block diagram of an identification indicating device 300 provided according to an embodiment of the present application.
[0201] As shown in FIG5 , the identification indicating device 300 includes at least one of the following:
[0202] A first sending unit 310 is configured to send first information to a first network node;
[0203] The receiving unit 320 is configured to receive second information from the first network node;
[0204] The first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
[0205] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0206] In some embodiments, the apparatus 300 further includes at least one of the following:
[0207] a storage unit, configured to store the second encrypted identification information or the second information;
[0208] The second sending unit is configured to send third information to a third network node, where the third information includes the second encryption identification information or the second information.
[0209] In some embodiments, the first information further includes fourth information, and the first encrypted identification information is further generated based on the fourth information.
[0210] In some embodiments, the first information further includes a first verification code, where the first verification code is generated based on at least one of the following:
[0211] the first identifier and the first key;
[0212] The first encrypted identification information and the third key.
[0213] In some embodiments, the apparatus 300 further includes:
[0214] The first generating unit is configured to generate the first verification code based on the first encryption identifier and the third key.
[0215] In some embodiments, the first information further includes a first verification code and fourth information, where the first verification code is generated based on at least one of the following:
[0216] the first identifier, the first key, and the fourth information;
[0217] The first encrypted identification information, the third key and the fourth information.
[0218] In some embodiments, the apparatus 300 further includes:
[0219] The second generating unit is configured to generate the first verification code based on the first encryption identifier, the third key, and the fourth information.
[0220] In some embodiments, the first information further includes at least one of the following:
[0221] a first key identifier, index, or indication corresponding to the first key;
[0222] A third key identifier, index, or indication corresponding to the third key.
[0223] In some embodiments, the second information further includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
[0224] In some embodiments, the second information further includes a second verification code, where the second verification code is generated based on at least one of the following:
[0225] the first identifier and the second key;
[0226] The second encrypted identification information and the fourth key.
[0227] In some embodiments, the apparatus 300 further includes:
[0228] A first verification unit is configured to verify the second verification code based on the second encryption identification information and the fourth key.
[0229] In some embodiments, the second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following:
[0230] the first identifier, the second key, and the fifth information;
[0231] The second encrypted identification information, the fourth key and the fifth information.
[0232] In some embodiments, the apparatus 300 further includes:
[0233] A second verification unit is configured to verify the second verification code based on the second encryption identification information, the fourth key, and the fifth information.
[0234] In some embodiments, the second information further includes at least one of the following:
[0235] a second key identifier, index, or indication corresponding to the second key;
[0236] A fourth key identifier, index, or indication corresponding to the fourth key.
[0237] In some embodiments, the terminal device is unaware of at least one of the first key and the second key.
[0238] It should be understood that the identification indication device 300 provided in the embodiment of the present application may correspond to the terminal device in the method embodiment of the present application, and the various units in the identification indication device 300 are respectively for implementing the corresponding processes of method 210 shown in Figure 2, method 220 shown in Figure 3 or method 230 shown in Figure 4. For the sake of brevity, they will not be repeated here.
[0239] In the embodiments of this application,
[0240] FIG6 is a schematic block diagram of an identification indicating device 400 provided according to an embodiment of the present application.
[0241] As shown in FIG6 , the identification indicating device 400 includes at least one of the following:
[0242] The receiving unit 410 is configured to receive first information from a terminal device;
[0243] The sending unit 420 is configured to send the second information to the terminal device;
[0244] The first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device;
[0245] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0246] In some embodiments, the apparatus 400 further includes:
[0247] A first decryption unit is configured to decrypt the first encrypted identification information based on at least one of the following:
[0248] the first key;
[0249] An associated key of the first key.
[0250] In some embodiments, the first information further includes fourth information, and the apparatus 400 further includes:
[0251] A second decryption unit is configured to decrypt the first encrypted identification information based on at least one of the following:
[0252] the first key and the fourth information;
[0253] an associated key of the first key and the fourth information.
[0254] In some embodiments, the first information further includes a first verification code, and the apparatus 400 further includes:
[0255] A first verification unit is configured to verify the first verification code based on at least one of the following:
[0256] the first identifier and the first key;
[0257] an associated key between the first identifier and the first key;
[0258] The first encrypted identification information and the third key.
[0259] In some embodiments, the first information further includes a first check code and fourth information, and the apparatus 400 further includes:
[0260] A second verification unit is configured to verify the first verification code based on at least one of the following:
[0261] the first identifier, the first key, and the fourth information;
[0262] the first identifier, a key associated with the first key, and the fourth information;
[0263] The first encrypted identification information, the third key and the fourth information.
[0264] In some embodiments, the first information further includes at least one of the following:
[0265] a first key identifier, index, or indication corresponding to the first key;
[0266] A third key identifier, index, or indication corresponding to the third key.
[0267] In some embodiments, the apparatus 400 further includes:
[0268] The first generating unit is configured to generate the second encrypted identification information based on the second key and the first identification.
[0269] In some embodiments, the second information further includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
[0270] In some embodiments, the apparatus 400 further includes:
[0271] The second generating unit is configured to generate the second encrypted identification information based on the second key, the first identification and the fifth information.
[0272] In some embodiments, the second information further includes a second verification code, where the second verification code is generated based on at least one of the following:
[0273] the first identifier and the second key;
[0274] The second encrypted identification information and the fourth key.
[0275] In some embodiments, the apparatus 400 further includes:
[0276] The third generating unit is configured to generate the second verification code based on at least one of the following:
[0277] the first identifier and the second key;
[0278] The second encrypted identification information and the fourth key.
[0279] In some embodiments, the second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following:
[0280] the first identifier, the second key, and the fifth information;
[0281] The second encrypted identification information, the fourth key and the fifth information.
[0282] In some embodiments, the apparatus 400 further includes:
[0283] A fourth generating unit is configured to generate the second verification code based on at least one of the following:
[0284] the first identifier, the second key, and the fifth information;
[0285] The second encrypted identification information, the fourth key and the fifth information.
[0286] In some embodiments, the second information further includes at least one of the following:
[0287] a second key identifier or index or indication corresponding to the second key;
[0288] A fourth key identifier, index, or indication corresponding to the fourth key.
[0289] It should be understood that the identification and indication device 400 provided in the embodiment of the present application may correspond to the first network node in the method embodiment of the present application, and the various units in the identification and indication device 400 are respectively for implementing the corresponding processes of method 210 shown in Figure 2, method 220 shown in Figure 3 or method 230 shown in Figure 4. For the sake of brevity, they will not be repeated here.
[0290] In the embodiments of this application,
[0291] The identification indicating device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal device or a first network node, and the first network node can be a network-side device or other device. For example, the type of terminal can include but is not limited to the type of terminal 11 listed above, the type of network-side device can include but is not limited to the type of network-side device 12 listed above, and other devices can be servers, network attached storage (NAS), etc., which are not specifically limited in the embodiment of the present application.
[0292] The identification indication device provided in the embodiment of the present application can implement the various processes implemented in the method embodiments of Figures 2 to 4 and achieve the same technical effects. To avoid repetition, they will not be described here.
[0293] The embodiment of the present application also provides a communication device 500, as shown in Figure 7, the communication device 500 includes a processor 501 and a memory 502, and the memory 502 stores a program or instruction that can be run on the processor 501, and the program or instruction, when executed by the processor 501, implements the various steps of the above-mentioned identification indication method embodiment. For example, when the communication device 500 is a terminal device, when the program or instruction is executed by the processor 501, it implements the various steps performed by the terminal device in the above-mentioned identification indication method embodiment, and can achieve the same technical effect. When the communication device 500 is a first network node, when the program or instruction is executed by the processor 501, it implements the various steps performed by the first network node in the above-mentioned identification indication method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0294] The present application also provides a terminal including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the identification indication method embodiment described above. This terminal embodiment corresponds to the above-described terminal-side method embodiment, and each implementation process and implementation method of the above-described method embodiment is applicable to this terminal embodiment and can achieve the same technical effects.
[0295] Specifically, FIG8 is a schematic diagram of the hardware structure of a terminal 600 implementing an embodiment of the present application.
[0296] As shown in Figure 8, the terminal 600 includes but is not limited to: a radio frequency unit 601, a network module 602, an audio output unit 603, an input unit 604, a sensor 605, a display unit 606, a user input unit 607, an interface unit 608, a memory 609 and at least some of the components of the processor 610.
[0297] Those skilled in the art will appreciate that the terminal 600 may also include a power supply (such as a battery) to power various components. The power supply may be logically connected to the processor 610 through a power management system, thereby implementing functions such as charging, discharging, and power consumption management through the power management system. The terminal structure shown in FIG8 does not constitute a limitation of the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be described in detail here.
[0298] It should be understood that in an embodiment of the present application, the input unit 604 may include a graphics processing unit (GPU) 6041 and a microphone 6042, and the graphics processor 6041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 606 may include a display panel 6061, and the display panel 6061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 607 includes a touch panel 6071 and at least one of other input devices 6072. The touch panel 6071 is also called a touch screen. The touch panel 6071 may include two parts: a touch detection device and a touch controller. Other input devices 6072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.
[0299] In the embodiment of the present application, after receiving downlink data from a network-side device, the radio frequency unit 601 may transmit the data to the processor 610 for processing. Furthermore, the radio frequency unit 601 may send uplink data to the network-side device. Typically, the radio frequency unit 601 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.
[0300] The memory 609 can be used to store software programs or instructions and various data. The memory 609 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 609 may include a volatile memory or a non-volatile memory. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a single link dynamic random access memory (SLDRAM), and a direct memory bus random access memory (DRRAM). The memory 609 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
[0301] Processor 610 may include one or more processing units. Optionally, processor 610 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 610.
[0302] In one implementation, the radio frequency unit 601 is configured to perform at least one of the following:
[0303] Sending first information to the first network node;
[0304] receiving second information from the first network node;
[0305] The first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
[0306] The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
[0307] In another implementation, the terminal 600 may serve as the first communication node mentioned above. Based on this, the radio frequency unit 601 is configured to perform at least one of the following:
[0308] receiving first information from a terminal device;
[0309] Sending second information to the terminal device;
[0310] The first information includes first encrypted identification information, which is generated based on the first identification and first key of the terminal device; the second information includes second encrypted identification information, which is generated based on the first identification and second key.
[0311] In an embodiment of the present application, a terminal device sends first information to a first network node; wherein the first information includes first encrypted identification information, which is generated based on the first identifier and a first key of the terminal device, and the first information or the first encrypted identification information includes at least one item of stored information on the terminal device and information received by the terminal device from a second network node. In other words, the terminal device can obtain the first information or the first encrypted identification information from at least one item of stored information on the terminal device and information received from the second network node. Thus, even if the terminal device does not have the ability to encrypt the identifier, the security of the identifier information indicated by the terminal device can be guaranteed. The terminal device receives second information from the first network node; wherein the second information includes second encrypted identification information, which is generated based on the first identifier and a second key of the terminal device. In other words, the terminal device receives the second encrypted identification information from the first network node. Thus, even if the terminal device does not have the ability to encrypt the identifier, the security of the identifier information indicated by the terminal device can be guaranteed.
[0312] It can be understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the method embodiment and achieve the same or corresponding technical effects. To avoid repetition, it will not be described here.
[0313] The present application also provides a network-side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the identification indication method embodiment shown above. This network-side device embodiment corresponds to the above-mentioned network-side device method embodiment, and each implementation process and implementation method of the above-mentioned method embodiment can be applied to this network-side device embodiment and can achieve the same technical effects.
[0314] Specifically, embodiments of the present application also provide a network-side device. As shown in Figure 9, the network-side device 700 includes an antenna 71, a radio frequency device 72, a baseband device 73, a processor 74, and a memory 75. Antenna 71 is connected to radio frequency device 72. In the uplink direction, radio frequency device 72 receives information via antenna 71 and sends the received information to baseband device 73 for processing. In the downlink direction, baseband device 73 processes the information to be transmitted and sends it to radio frequency device 72. Radio frequency device 72 processes the received information and then sends it through antenna 71.
[0315] The method executed by the network-side device in the above embodiment may be implemented in the baseband device 73 , which includes a baseband processor.
[0316] The baseband device 73 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 8, one of the chips is, for example, a baseband processor, which is connected to the memory 75 through a bus interface to call the program in the memory 75 to execute the network device operations shown in the above method embodiment.
[0317] The network side device may further include a network interface 76, which is, for example, a Common Public Radio Interface (CPRI).
[0318] Specifically, the network side device 700 of the embodiment of the present application also includes: instructions or programs stored in the memory 75 and executable on the processor 74. The processor 74 calls the instructions or programs in the memory 75 to execute the methods of executing the modules shown in FIG6 and achieve the same technical effect. To avoid repetition, it will not be described here.
[0319] Specifically, the embodiment of the present application further provides a network side device. As shown in Figure 10, the network side device 800 includes: a processor 801, a network interface 802, and a memory 803. The network interface 802 is, for example, a common public radio interface (CPRI).
[0320] Specifically, the network side device 800 of the embodiment of the present application also includes: instructions or programs stored in the memory 803 and can be run on the processor 801. The processor 801 calls the instructions or programs in the memory 803 to execute the method of execution of each module shown in Figure 6 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0321] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned identification indication method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0322] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0323] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned identification indication method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0324] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0325] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned identification indication method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0326] An embodiment of the present application also provides a communication system, including: a terminal and a first communication node, wherein the terminal can be used to execute the corresponding steps of the identification indication method described above, and the first communication node can be used to execute the corresponding steps of the identification indication method described above.
[0327] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0328] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general-purpose hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.
[0329] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.
Claims
1. A marking method, wherein: Include at least one of the following: The terminal device sends first information to the first network node; The terminal device receives second information from the first network node; The first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node; The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
2. The method according to claim 1, wherein The method further comprises at least one of the following: The terminal device stores the second encrypted identification information or the second information; The terminal device sends third information to a third network node, where the third information includes the second encryption identification information or the second information.
3. The method according to claim 1 or 2, wherein The first information also includes fourth information, and the first encrypted identification information is further generated based on the fourth information.
4. The method according to any one of claims 1 to 3, wherein The first information further includes a first verification code, where the first verification code is generated based on at least one of the following: the first identifier and the first key; The first encrypted identification information and the third key.
5. The method according to claim 4, wherein The method further comprises: The terminal device generates the first verification code based on the first encryption identifier and the third key.
6. The method according to any one of claims 1 to 3, wherein The first information further includes a first check code and fourth information, where the first check code is generated based on at least one of the following: the first identifier, the first key, and the fourth information; The first encrypted identification information, the third key and the fourth information.
7. The method according to claim 6, wherein: The method further comprises: The terminal device generates the first verification code based on the first encryption identifier, the third key and the fourth information.
8. The method according to any one of claims 1 to 7, wherein The first information also includes at least one of the following: a first key identifier, index, or indication corresponding to the first key; A third key identifier, index, or indication corresponding to the third key.
9. The method according to any one of claims 1 to 8, wherein The second information also includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
10. The method according to any one of claims 1 to 9, wherein The second information further includes a second verification code, where the second verification code is generated based on at least one of the following: the first identifier and the second key; The second encrypted identification information and the fourth key.
11. The method according to claim 10, wherein: The method further comprises: The terminal device verifies the second verification code based on the second encrypted identification information and the fourth key.
12. The method according to any one of claims 1 to 9, wherein The second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following: the first identifier, the second key, and the fifth information; The second encrypted identification information, the fourth key and the fifth information.
13. The method according to claim 12, wherein: The method further comprises: The terminal device verifies the second verification code based on the second encryption identification information, the fourth key and the fifth information.
14. The method according to any one of claims 1 to 13, wherein The second information further includes at least one of the following: a second key identifier, index, or indication corresponding to the second key; A fourth key identifier, index, or indication corresponding to the fourth key.
15. The method according to any one of claims 1 to 14, wherein The terminal device is unaware of at least one of the first key and the second key.
16. A marking method, wherein: Include at least one of the following: The first network node receives first information from the terminal device; The first network node sends second information to the terminal device; The first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device; The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
17. The method according to claim 16, wherein The method further comprises: The first network node decrypts the first encrypted identification information based on at least one of the following: the first key; An associated key of the first key.
18. The method according to claim 16, wherein The first information further includes fourth information, and the method further includes: The first network node decrypts the first encrypted identification information based on at least one of the following: the first key and the fourth information; an associated key of the first key and the fourth information.
19. The method according to any one of claims 16 to 18, wherein The first information further includes a first check code, and the method further includes: The first network node verifies the first verification code based on at least one of the following: the first identifier and the first key; an associated key between the first identifier and the first key; The first encrypted identification information and the third key.
20. The method according to any one of claims 16 to 18, wherein The first information further includes a first check code and fourth information, and the method further includes: The first network node verifies the first verification code based on at least one of the following: the first identifier, the first key, and the fourth information; the first identifier, a key associated with the first key, and the fourth information; The first encrypted identification information, the third key and the fourth information.
21. The method according to any one of claims 16 to 20, wherein The first information also includes at least one of the following: a first key identifier, index, or indication corresponding to the first key; A third key identifier, index, or indication corresponding to the third key.
22. The method according to any one of claims 16 to 21, wherein The method further comprises: The first network node generates the second encrypted identification information based on the second key and the first identification.
23. The method according to any one of claims 16 to 21, wherein The second information also includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
24. The method according to claim 23, wherein The method further comprises: The first network node generates the second encrypted identification information based on the second key, the first identification and the fifth information.
25. The method according to any one of claims 16 to 24, wherein The second information further includes a second verification code, where the second verification code is generated based on at least one of the following: the first identifier and the second key; The second encrypted identification information and the fourth key.
26. The method according to claim 25, wherein The method further comprises: The first network node generates the second verification code based on at least one of the following: the first identifier and the second key; The second encrypted identification information and the fourth key.
27. The method according to any one of claims 16 to 24, wherein The second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following: the first identifier, the second key, and the fifth information; The second encrypted identification information, the fourth key and the fifth information.
28. The method according to claim 27, wherein The method further comprises: The first network node generates the second verification code based on at least one of the following: the first identifier, the second key, and the fifth information; The second encrypted identification information, the fourth key and the fifth information.
29. The method according to any one of claims 16 to 28, wherein The second information further includes at least one of the following: a second key identifier or index or indication corresponding to the second key; A fourth key identifier, index, or indication corresponding to the fourth key.
30. A marking indicating device, wherein: Include at least one of the following: A first sending unit, configured to send first information to a first network node; a receiving unit, configured to receive second information from the first network node; The first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node; The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
31. The device according to claim 30, wherein The device further comprises at least one of the following: a storage unit, configured to store the second encrypted identification information or the second information; The second sending unit is configured to send third information to a third network node, where the third information includes the second encryption identification information or the second information.
32. The device according to claim 30 or 31, wherein The first information also includes fourth information, and the first encrypted identification information is further generated based on the fourth information.
33. The device according to any one of claims 30 to 32, wherein The first information further includes a first verification code, where the first verification code is generated based on at least one of the following: the first identifier and the first key; The first encrypted identification information and the third key.
34. The device according to any one of claims 30 to 32, wherein The first information further includes a first check code and fourth information, where the first check code is generated based on at least one of the following: the first identifier, the first key, and the fourth information; The first encrypted identification information, the third key and the fourth information.
35. The device according to any one of claims 30 to 34, wherein The second information also includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
36. The device according to any one of claims 30 to 35, wherein The second information further includes a second verification code, where the second verification code is generated based on at least one of the following: the first identifier and the second key; The second encrypted identification information and the fourth key.
37. The device according to any one of claims 30 to 35, wherein The second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following: the first identifier, the second key, and the fifth information; The second encrypted identification information, the fourth key and the fifth information.
38. A marking indicating device, wherein: Include at least one of the following: A receiving unit, configured to receive first information from a terminal device; A sending unit, configured to send second information to a terminal device; The first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device; The second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
39. The apparatus according to claim 38, wherein The device further comprises: A first decryption unit is configured to decrypt the first encrypted identification information based on at least one of the following: the first key; An associated key of the first key.
40. The apparatus of claim 38, wherein The first information further includes fourth information, and the apparatus further includes: A second decryption unit is configured to decrypt the first encrypted identification information based on at least one of the following: the first key and the fourth information; an associated key of the first key and the fourth information.
41. The device according to any one of claims 38 to 40, wherein The first information further includes a first verification code, and the device further includes: A first verification unit is configured to verify the first verification code based on at least one of the following: the first identifier and the first key; an associated key between the first identifier and the first key; The first encrypted identification information and the third key.
42. The apparatus according to any one of claims 38 to 40, wherein The first information further includes a first check code and fourth information, and the device further includes: A second verification unit is configured to verify the first verification code based on at least one of the following: the first identifier, the first key, and the fourth information; the first identifier, a key associated with the first key, and the fourth information; The first encrypted identification information, the third key and the fourth information.
43. The device according to any one of claims 38 to 42, wherein The device further comprises: The first generating unit is configured to generate the second encrypted identification information based on the second key and the first identification.
44. The apparatus according to any one of claims 38 to 42, wherein The second information also includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
45. The apparatus of claim 44, wherein: The device further comprises: The second generating unit is configured to generate the second encrypted identification information based on the second key, the first identification and the fifth information.
46. The device according to any one of claims 38 to 45, wherein The second information further includes a second verification code, where the second verification code is generated based on at least one of the following: the first identifier and the second key; The second encrypted identification information and the fourth key.
47. The apparatus according to any one of claims 38 to 46, wherein The second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following: the first identifier, the second key, and the fifth information; The second encrypted identification information, the fourth key and the fifth information.
48. A terminal device, wherein: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the identification indication method according to any one of claims 1 to 15 are implemented.
49. A first network node, wherein: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the identification indication method according to any one of claims 16 to 29 are implemented.
50. A readable storage medium, wherein: The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the identification indication method according to any one of claims 1 to 15 are implemented, or the steps of the identification indication method according to any one of claims 16 to 29 are implemented.