Information processing method, communication device and storage medium

By introducing the authenticated encryption (AE) algorithm into the communication system and using the first indicator to determine the key type, the problem of low efficiency in confidentiality and integrity protection of NAS and AS messages in the existing technology is solved, unified key stream calculation is achieved, and communication security is improved.

WO2025208534A1PCT designated stage Publication Date: 2025-10-09BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/086122
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-03
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

In the field of communications technology, existing technologies have difficulty in effectively protecting the confidentiality and integrity of messages in the non-access stratum (NAS) and/or access stratum (AS). In particular, when introducing the authenticated encryption (AE) algorithm, the key stream calculation input is inconsistent, resulting in inefficient security protection.

Method used

An authenticated encryption (AE) algorithm is used to determine different key types through a first indicator, and confidentiality and integrity-related processing is performed on the information based on the AE algorithm to generate second information, including operations such as encryption, decryption, integrity protection, and integrity authentication.

Benefits of technology

It implements confidentiality and integrity protection for NAS, RRC, and UP messages, improves the security and efficiency of the communication system, simplifies key stream calculation, and unifies the generation of session keys for confidentiality and integrity protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024086122_09102025_PF_FP_ABST
    Figure CN2024086122_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure provide an information processing method, a communication device and a storage medium. The information processing method is executed by a first device, and comprises: on the basis of a first indicator, determining a key for security-related processing; and on the basis of the key and an AE algorithm, performing the security-related processing on first information, in order to generate second information. Thus, data can be input into an AE algorithm for different types of security-related processing on the basis of different keys.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, communication device and storage medium Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to an information processing method, a communication device, and a storage medium. Background Art

[0002] In the field of communication technology, it is necessary to perform security protection on messages of the Non-Access Stratum (NAS) and / or the Access Stratum (AS); the security protection may include confidentiality protection and / or integrity protection.

[0003] Summary of the Invention

[0004] The embodiments of the present disclosure need to solve the problem of introducing an Authenticated Encryption (AE) algorithm into a communication system to perform security-related processing on data.

[0005] According to a first aspect of an embodiment of the present disclosure, an information processing method is proposed, which is executed by a first device, including: determining a key for security-related processing based on a first indicator; performing security-related processing on the first information based on the key and an AE algorithm to generate second information.

[0006] According to the second aspect of an embodiment of the present disclosure, a first device is proposed, including: a processing module, configured to determine a key for security-related processing based on a first indicator; and perform security-related processing on the first information based on the key and the AE algorithm to generate second information.

[0007] According to a third aspect of an embodiment of the present disclosure, a communication device is proposed, comprising one or more processors; wherein the above-mentioned communication device is used to execute the optional implementation method of the first aspect.

[0008] According to a fourth aspect of an embodiment of the present disclosure, a storage medium is proposed, wherein the storage medium stores instructions. When the instructions are executed on a communication device, the communication device executes the method described in the optional implementation manner of the first aspect.

[0009] According to a fifth aspect of an embodiment of the present disclosure, a computer program product is proposed. The computer program product includes a computer program or instructions. When the computer program or instructions are executed by a processor, the method described in the optional implementation manner of the first aspect is implemented.

[0010] The embodiments of the present disclosure can introduce the AE algorithm into the communication system to perform security-related processing on data, and can clearly input data into the AE algorithm based on different keys to perform different types of security-related processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following drawings required for describing the embodiments are introduced. The following drawings are merely some embodiments of the present disclosure and do not impose specific limitations on the protection scope of the present disclosure.

[0012] FIG1 is a schematic structural diagram of an information processing system according to an embodiment of the present disclosure.

[0013] FIG2A is a flow chart illustrating an information processing method according to an embodiment of the present disclosure.

[0014] FIG2B is a schematic diagram showing an encryption operation based on the AE algorithm according to an embodiment of the present disclosure.

[0015] FIG2C is a schematic diagram showing a decryption operation based on the AE algorithm according to an embodiment of the present disclosure.

[0016] FIG2D is a schematic diagram showing information generation for integrity protection based on the AE algorithm according to an embodiment of the present disclosure.

[0017] FIG2E is a schematic diagram showing information authentication for integrity protection based on the AE algorithm according to an embodiment of the present disclosure.

[0018] FIG2F is a schematic diagram illustrating information generation based on the AE algorithm for encryption and integrity protection according to an embodiment of the present disclosure.

[0019] FIG2G is a schematic diagram showing information authentication based on decryption and integrity protection based on the AE algorithm according to an embodiment of the present disclosure.

[0020] FIG2H is a flow chart illustrating an information processing method according to an embodiment of the present disclosure.

[0021] FIG3 is an interactive schematic diagram illustrating an information processing method according to an embodiment of the present disclosure.

[0022] FIG4A is a schematic diagram showing the relationship between an AE algorithm and input / output parameters according to an embodiment of the present disclosure.

[0023] FIG4B is a schematic diagram showing an AE generating a MAC using a message and associated data according to an embodiment of the present disclosure.

[0024] FIG5 is a schematic structural diagram of a first device according to an embodiment of the present disclosure.

[0025] FIG6A is a schematic structural diagram of a communication device provided according to an embodiment of the present disclosure.

[0026] FIG6B is a schematic structural diagram of a chip provided according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0027] The embodiments of the present disclosure provide an information processing method, a communication device, and a storage medium.

[0028] In a first aspect, an embodiment of the present disclosure proposes an information processing method, which is executed by a first device, including: determining a key for security-related processing based on a first indicator; performing security-related processing on the first information based on the key and the AE algorithm to generate second information.

[0029] In the above embodiment, the AE algorithm may be introduced into the communication system, and different types of security-related processing may be performed on the first information based on the AE algorithm and different keys, thereby obtaining appropriate second information.

[0030] In combination with some embodiments of the first aspect, in some embodiments, the AE algorithm is an Authenticated Encryption with Associated Data (AEAD) algorithm.

[0031] In combination with some embodiments of the first aspect, in some embodiments, determining a key for security-related processing based on a first indicator includes: determining a key for security-related processing based on the first indicator and a first parameter; wherein the first parameter includes at least one of the following: a first key; a first length, the first length is used to indicate the length of the first indicator; a second indicator, the second indicator is used to indicate the AE algorithm; and a second length, the second length is used to indicate the length of the second indicator.

[0032] In the above embodiment, an accurate key can be obtained based on the first indicator and the first parameter; and different types of keys can be obtained based on different first indicators.

[0033] In combination with some embodiments of the first aspect, in some embodiments, the second indicator includes one of the following: a first algorithm identifier, the first algorithm identifier is used to indicate an AE algorithm based on Snow 5G; a second algorithm identifier, the second algorithm identifier is used to indicate an AE algorithm based on AES-256; and a third algorithm identifier, the third algorithm identifier is used to indicate an AE algorithm based on ZUC-256.

[0034] In the above embodiments, some adaptive AE algorithm types are defined.

[0035] In combination with some embodiments of the first aspect, in some embodiments, the security-related processing is: confidentiality-related processing; based on the first indicator, determining the key used for security-related processing, including: when the first indicator is a first-class identifier, determining the second key used for confidentiality-related processing; performing security-related processing on the first information based on the key and the authenticated encryption AE algorithm to generate second information, including: performing confidentiality-related processing on the first information based on the second key and the AE algorithm to generate second information.

[0036] In the above embodiment, when the first indicator is a first type identifier, it can be determined that the key is the second key for confidentiality-related processing, so that confidentiality-related processing can be performed on the first information based on the AE algorithm.

[0037] In combination with some embodiments of the first aspect, in some embodiments, the first type of identifier includes at least one of the following: a first indication, the first indication is used to indicate confidentiality-related processing of non-access stratum (NAS) messages; a second indication, the second indication is used to indicate confidentiality-related processing of radio resource control (RRC) messages; and a third indication, the third indication is used to indicate confidentiality-related processing of user plane (UP) messages.

[0038] In the above embodiment, confidentiality-related processing of NAS messages, RRC messages and / or UP messages can be implemented according to the difference of the first type identifiers.

[0039] In combination with some embodiments of the first aspect, in some embodiments, confidentiality-related processing is performed on the first information based on the second key and the AE algorithm to generate the second information, including: confidentiality-related processing is performed on the first information based on the second key, the second parameter and the AE algorithm to generate the second information; wherein the second parameter includes at least one of the following: a count value, the count value is used to indicate the number of times the message containing the second information is sent; a bearer identifier, the bearer identifier is used to indicate the bearer for sending the message containing the second information; direction information, the direction information is used to indicate whether the message containing the second information is sent to the uplink or the downlink; a third length, the third length is used to indicate the length of the information that requires confidentiality-related processing; and a first work indication, the first work indication is used to indicate that the security-related processing is confidentiality-related processing.

[0040] In the above embodiment, confidentiality-related processing of the first information can be accurately implemented according to the second key and the second parameter.

[0041] In combination with some embodiments of the first aspect, in some embodiments, the confidentiality-related processing is an encryption operation, and the second information includes the encrypted first information; or, the confidentiality-related processing is a decryption operation, and the second information includes the decrypted first information.

[0042] In the above embodiment, the encryption operation or the decryption operation on the first information can be accurately implemented.

[0043] In combination with some embodiments of the first aspect, in some embodiments, the security-related processing is: integrity protection-related processing; based on the first indicator, determining the key used for security-related processing, including: when the first indicator is a second-class identifier, determining the third key used for integrity protection-related processing; performing security-related processing on the first information based on the key and the authenticated encryption AE algorithm to generate second information, including: performing integrity protection-related processing on the first information based on the third key and the AE algorithm to generate second information.

[0044] In the above embodiment, when the first indicator is a second type identifier, it can be determined that the key is the third key for integrity protection related processing, so that integrity protection related processing can be performed on the first information based on the AE algorithm.

[0045] In combination with some embodiments of the first aspect, in some embodiments, the second type of identifier includes at least one of the following: a fourth indication, the fourth indication is used to indicate that integrity protection-related processing is performed on the NAS message; a fifth indication, the fifth indication is used to indicate that integrity protection-related processing is performed on the RRC message; and a sixth indication, the sixth indication is used to indicate that integrity protection-related processing is performed on the UP message.

[0046] In the above embodiment, the integrity protection related processing of the NAS message, the RRC message and / or the UP message can be implemented according to the difference of the first type identifier.

[0047] In combination with some embodiments of the first aspect, in some embodiments, integrity protection-related processing is performed on the first information based on the third key and the AE algorithm to generate second information, including: integrity-related processing is performed on the first information based on the third key, the third parameter and the AE to generate the second information; wherein the third parameter includes at least one of the following: a random number; a count value, the count value is used to indicate the number of times a message containing the second information is sent; a bearer identifier, the bearer identifier is used to indicate the bearer for sending the message containing the second information; direction information, the direction information is used to indicate whether the message containing the second information is sent to the uplink or the downlink; a fourth length, the fourth length is used to indicate the length of the information for which integrity protection-related processing is required; and a second work indication, the second work indication is used to indicate that the security-related processing is integrity protection-related processing.

[0048] In the above embodiment, the processing related to the integrity protection of the first information can be accurately implemented according to the second key and the third parameter.

[0049] In combination with some embodiments of the first aspect, in some embodiments, the second information is information used for integrity protection.

[0050] In the above embodiment, the second information related to integrity protection can be accurately determined.

[0051] In combination with some embodiments of the first aspect, in some embodiments, the security-related processing is confidentiality-related processing and integrity protection-related processing; based on the first indicator, determining the key for security-related processing, including: when the first indicator is a third-category identifier, determining the fourth key for confidentiality-related processing and integrity protection-related processing; performing security-related processing on the first information based on the key and the authenticated encryption AE algorithm to generate second information, including: performing confidentiality-related processing and integrity protection-related processing on the first information based on the fourth key and the AE algorithm to generate second information.

[0052] In the above embodiment, when the first indicator is a first-type identifier, the key can be determined to be the fourth key for confidentiality-related processing and integrity verification-related processing, so that the first information can be processed with confidentiality-related processing and integrity protection-related processing based on the AE algorithm.

[0053] In combination with some embodiments of the first aspect, in some embodiments, the third category identifier includes at least one of the following: a seventh indication, the seventh indication is used to indicate confidentiality-related processing and integrity protection-related processing of NAS messages; an eighth indication, the eighth indication is used to indicate confidentiality-related processing and integrity protection-related processing of RRC messages; a ninth indication, the ninth indication is used to indicate confidentiality-related processing and integrity protection-related processing of UP messages; a tenth indication, the tenth indication is used to indicate partial confidentiality-related processing of NAS messages; an eleventh indication, the eleventh indication is used to indicate partial confidentiality-related processing of RRC messages; a twelfth indication, the twelfth indication is used to indicate partial confidentiality-related processing of UP messages; a thirteenth indication, the thirteenth indication is used to indicate AE-related processing of NAS messages; a fourteenth indication, the fourteenth indication is used to indicate AE-related processing of RRC messages; and a fifteenth indication, the fifteenth indication is used to indicate AE-related processing of UP messages.

[0054] In the above embodiment, based on the difference of the first type of identifier, confidentiality-related processing and integrity protection-related processing of NAS messages, RRC messages and / or UP messages can be implemented, or confidentiality-related processing of NAS messages, RRC messages and / or UP messages or security protection of AE can be implemented.

[0055] In combination with some embodiments of the first aspect, in some embodiments, confidentiality-related processing and integrity protection-related processing are performed on the first information based on the fourth key and the AE algorithm to generate second information, including: confidentiality-related processing and integrity protection-related processing are performed on the first information based on the fourth key, the fourth parameter and the AE to generate the second information; wherein the fourth parameter includes at least one of the following: a random number; a count value, the count value is used to indicate the number of times a message containing the second information is sent; a bearer identifier, the bearer identifier is used to indicate the bearer of the message containing the second information; direction information, the direction information is used to indicate whether the message containing the second information is transmitted uplink or downlink; a third length, the third length is used to indicate the length of information that requires confidentiality-related processing; a fourth length, the fourth length is used to indicate the length of information that requires integrity protection-related processing; a third work indication, the third work indication is used to indicate that the security-related processing is confidentiality-related processing and integrity protection-related processing; and associated data, the associated data is used for information related to integrity protection processing.

[0056] In the above embodiment, confidentiality-related processing and integrity protection-related processing of the first information can be accurately implemented according to the second key and the third parameter.

[0057] In combination with some embodiments of the first aspect, in some embodiments, the confidentiality-related processing includes an encryption operation, and the second information includes at least one of the following: the encrypted first information, associated data, and information for integrity protection; or, the confidentiality-related operation includes a decryption operation, and the second information includes at least one of the following: the decrypted first information, associated data, and information for integrity protection.

[0058] In the above embodiment, the operations of encrypting and generating integrity-protected information for the first information, or the operations of decrypting and checking the integrity of the first information can be accurately implemented.

[0059] In combination with some embodiments of the first aspect, in some embodiments, the information used for integrity protection is: the integrity protection information related to the ciphertext of the first information and the associated data; or, the information used for integrity protection is: the integrity protection information of the first information and the associated data.

[0060] In the above embodiment, the associated data may only be processed for integrity protection, or the associated data may be processed for confidentiality and integrity protection.

[0061] In combination with some embodiments of the first aspect, in some embodiments, the first device is: a terminal, or an access network device, or a core network device.

[0062] In the above embodiments, the AE algorithm may be introduced into the terminal, access network equipment and / or core network equipment to perform data security protection.

[0063] In a second aspect, an embodiment of the present disclosure proposes a first device, comprising: a processing module, configured to determine a key for security-related processing based on a first indicator; and perform security-related processing on the first information based on the key and the AE algorithm to generate second information.

[0064] In a third aspect, an embodiment of the present disclosure proposes a communication device comprising one or more processors; wherein the above-mentioned communication device is used to execute the optional implementation method of the first aspect.

[0065] In a fourth aspect, an embodiment of the present disclosure proposes a storage medium, which stores instructions. When the instructions are executed on a communication device, the communication device executes the method described in the optional implementation manner of the first aspect.

[0066] In a fifth aspect, an embodiment of the present disclosure proposes a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a processor, they implement the method described in the optional implementation manner of the first aspect.

[0067] In a sixth aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the information processing method as described in the optional implementation manner of the first aspect.

[0068] In a seventh aspect, an embodiment of the present disclosure proposes a chip or a chip system; the chip or chip system includes a processing circuit configured to execute the method described in the optional implementation manner of the above-mentioned first aspect.

[0069] It is understood that the first device, communication device, storage medium, program product, computer program, chip, or chip system described above are all used to perform the methods provided in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods and will not be repeated here.

[0070] The present disclosure provides an information processing method, a communication device, and a storage medium. In some embodiments, the terms information processing method and communication method are interchangeable, the terms information processing device and communication device are interchangeable, and the terms information processing system and communication system are interchangeable.

[0071] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0072] In each embodiment of the present disclosure, unless otherwise specified or provided for, the terms and / or descriptions between the embodiments are consistent and can be used interchangeably. The technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0073] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0074] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0075] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0076] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.

[0077] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.

[0078] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.

[0079] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.

[0080] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0081] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0082] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0083] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.

[0084] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).

[0085] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.

[0086] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.

[0087] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, it can also be called device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it can also be set as a structure in which the terminal has all or part of the functions of the access network device. In addition, language such as "uplink" and "downlink" can also be replaced by language corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.

[0088] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.

[0089] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0090] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0091] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.

[0092] FIG1 is a schematic diagram showing the structure of an information processing system 100 according to an embodiment of the present disclosure. As shown in FIG1 , the information processing system 100 may include: a terminal 101 and a network device 102 .

[0093] In some embodiments, the network device 102 may include at least one of an access network device and a core network device.

[0094] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things (IOT) device or terminal, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.

[0095] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0096] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0097] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0098] In some embodiments, the core network device may be a device including a first device, a second device, etc., or may be a plurality of devices or a device group, each including all or part of the first device and the second device. The first device and the second device may be network elements; the network element may be virtual or physical. The core network may include, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0099] It can be understood that the information processing system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.

[0100] The following embodiments of the present disclosure may be applied to the information processing system 100 shown in FIG1 , or a portion thereof, but are not limited thereto. The entities shown in FIG1 are illustrative only. The information processing system may include all or a portion of the entities shown in FIG1 , or may include other entities outside of FIG1 . The number and form of the entities may be arbitrary. The connection relationships between the entities are illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.

[0101] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).

[0102] In some embodiments, in traditional communication systems (such as 5G systems), two types of security mechanisms (confidentiality mechanisms and integrity mechanisms) can be used to protect NAS messages and / or AS messages; in order to provide confidentiality and integrity protection of messages through these mechanisms, the messages can be confidentiality protected and integrity protected respectively.

[0103] In some embodiments, Authenticated Encryption (AE) is an encryption scheme that ensures both confidentiality and authenticity. Authenticated Encryption with Associated Data (AE) is a variation of AE that allows messages to include "Associated Data" (AD). Associated Data is additional non-confidential information; it is also called Attachment Authentication Data (AD).

[0104] In some embodiments, the AE algorithm can be introduced into a communication system to improve the efficiency of security procedures, among other things. Prior to adopting the AE algorithm in a communication system, the following observations were made: 1) Currently, different key streams must be generated using NEA and NIA for NAS and / or AS encryption and integrity protection. The inputs for the key stream calculations using NEA and NIA (e.g., count, bearer, direction, and key stream length) are not identical; when using the AE algorithm, only a single unified input set is required. 2) Six different keys (e.g., Knas_enc / Knas_int, Krrc_enc / Krrc_int, and Kup_enc / Kup_int) are used to generate session keys for confidentiality protection and / or integrity protection for NAS and / or AS, respectively. The confidentiality (Knas_enc / Krrc_enc / Kup_enc) and integrity (Knas_int / Krrc_int / Kup_int) session keys are used to generate the confidentiality and integrity protection key streams, respectively. When using the AE algorithm, since only a unified input set containing the session key is required, separate session keys for confidentiality protection and integrity protection may no longer be required. Only one session key is needed to generate the key stream for encryption protection and integrity protection.

[0105] In some embodiments, the communication system does not support direct use of AE-based algorithms for confidentiality protection and / or integrity protection.

[0106] FIG2A is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG2A , the present disclosure embodiment relates to an information processing method, which is executed by a first device and includes:

[0107] Step S2101: The first device determines a key for security-related processing.

[0108] In some embodiments, the first device determines a key for security-related processing based on the first indicator.

[0109] In some embodiments, the first device is a terminal, an access network device, or a core network device. Optionally, the access network device may be a base station. Optionally, the core network device may be an access and mobility management function (AMF).

[0110] Optionally, the security-related processing may be security protection. Exemplarily, the first device determines a key for security protection based on the first indicator.

[0111] Optionally, security-related processing may include confidentiality-related processing and / or integrity protection-related processing. The confidentiality-related processing may include encryption or decryption operations. The integrity protection-related processing may include generation of integrity-protected information or authentication of integrity-protected information. Authentication of integrity-protected information may include integrity check information checking or authentication of integrity verification information.

[0112] Optionally, the confidentiality-related processing may be confidentiality protection; and the integrity protection-related processing may be integrity protection.

[0113] In some embodiments, the first indicator is used to determine a key for security-related processing.

[0114] In some embodiments, the first indicator includes at least one of the following: a first type of identification, a second type of identification, and a third type of identification.

[0115] In some embodiments, the name of the first indicator is not limited, and it can be, for example, an algorithm type distinguisher.

[0116] Optionally, the first type of identifier is used to indicate confidentiality-related processing, or the first type of identifier is used to determine confidentiality-related processing.

[0117] Optionally, the second type of identifier is used to indicate integrity protection related processing, or the second type of identifier is used to determine integrity protection related processing.

[0118] Optionally, the third type of identifier is used to indicate confidentiality-related processing and integrity-related processing, or the third type of identifier is used to determine confidentiality-related processing and integrity-related processing.

[0119] Optionally, the first type of identification includes at least one of the following: a first indication, a second indication, and a third indication.

[0120] Optionally, the name of the first type of identifier is not limited, and it can be, for example, a confidentiality processing identifier or N-enc-alg.

[0121] Exemplarily, the first indication is used to instruct to perform confidentiality-related processing on the NAS message.

[0122] Exemplarily, the second indication is used to instruct confidentiality-related processing of the RRC message.

[0123] Exemplarily, the third indication is used to instruct confidentiality-related processing to be performed on the user plane UP message.

[0124] For example, the names of the first indication, the second indication and the third indication are not limited; the first indication is, for example, a NAS confidentiality processing identifier or N-NAS-enc-alg, etc.; the second indication is, for example, an RRC confidentiality processing identifier or N-RRC-enc-alg, etc.; the third indication is, for example, a UP confidentiality processing identifier or N-UP-enc-alg, etc.

[0125] Optionally, the second type of identification includes at least one of the following: a fourth indication, a fifth indication, and a sixth indication.

[0126] Optionally, the name of the second type of identifier is not limited, and it can be, for example, an integrity check identifier or N-int-alg.

[0127] Exemplarily, the fourth indication is used to instruct to perform integrity protection-related processing on the NAS message.

[0128] Exemplarily, the fifth indication is used to instruct to perform integrity protection-related processing on the RRC message.

[0129] Exemplarily, the sixth indication is used to instruct to perform integrity protection-related processing on the UP message.

[0130] For example, the names of the fourth indication, the fifth indication, and the sixth indication are not limited; the fourth indication is, for example, a NAS integrity check identifier or N-NAS-int-alg, etc.; the fifth indication is, for example, an RRC integrity check identifier or N-RRC-int-alg, etc.; the sixth indication is, for example, a UP integrity check identifier or N-UP-int-alg, etc.

[0131] Optionally, the third type of identification includes at least one of the following: a seventh indication, an eighth indication, a ninth indication, a tenth indication, an eleventh indication, a twelfth indication, a thirteenth indication, a fourteenth indication, and a fifteenth indication.

[0132] Exemplarily, the seventh indication is used to instruct to perform confidentiality-related processing and integrity protection-related processing on the NAS message.

[0133] Exemplarily, the eighth indication is used to instruct confidentiality-related processing and integrity protection-related processing to be performed on the RRC message.

[0134] Exemplarily, the ninth indication is used to instruct to perform confidentiality-related processing and integrity protection-related processing on the UP message.

[0135] Exemplarily, the tenth indication is used to instruct to perform partial confidentiality-related processing on the NAS message.

[0136] Exemplarily, the eleventh indication is used to instruct partial confidentiality-related processing of the RRC message.

[0137] Exemplarily, the twelfth indication is used to instruct to perform partial confidentiality-related processing on the UP message.

[0138] Exemplarily, the thirteenth indication is used to instruct to perform AE-related processing on the NAS message.

[0139] Exemplarily, the fourteenth indication is used to instruct AE-related processing of the RRC message.

[0140] Exemplarily, the fifteenth indication is used to instruct to perform AE-related processing on the UP message.

[0141] For example, the names of the seventh indication, the eighth indication, the ninth indication, the tenth indication, the eleventh indication, the twelfth indication, the thirteenth indication, the fourteenth indication and the fifteenth indication are not limited; the seventh indication is, for example, a NAS security protection identifier or N-NAS-enc-inc-alg, etc.; the eighth indication is, for example, an RRC security protection identifier or N-RRC-enc-inc-alg, etc.; the ninth indication is, for example, a UP security identifier or N-UP-enc-inc-alg, etc.

[0142] In some embodiments, the first indicator may include at least one of the following: a first indication, a second indication, a third indication, a fourth indication, a fifth indication, a sixth indication, a seventh indication, an eighth indication, a ninth indication, a tenth indication, an eleventh indication, a twelfth indication, a thirteenth indication, a fourteenth indication, and a fifteenth indication.

[0143] In some embodiments, the first indication, the second indication, the third indication, the fourth indication, the fifth indication, the sixth indication, the seventh indication, the eighth indication, the ninth indication, the tenth indication, the eleventh indication, the twelfth indication, the thirteenth indication, the fourteenth indication and the fifteenth indication may each be one or more bits.

[0144] In some embodiments, the keys used for security-related processing include a second key, a third key, and / or a fourth key.

[0145] In some embodiments, the first device determines a second key for confidentiality-related processing when the first indicator is a first type of identification.

[0146] Optionally, the name of the second key is not limited, and it can be, for example, a confidentiality key or a cipher key (Cipher Key, CK) or an encryption key (Encryption Key) or a decryption key, etc.

[0147] Optionally, when the first indicator is the first indication, the first device determines a second key for performing confidentiality-related processing on the NAS message.

[0148] Optionally, when the first indicator is the second indication, the first device determines a second key for performing confidentiality-related processing on the RRC message.

[0149] Optionally, when the first indicator is the third indication, the first device determines a second key for performing confidentiality-related processing on the UP message.

[0150] In some embodiments, the first device determines a third key for integrity-related processing when the first indicator is a second-type identification.

[0151] Optionally, the name of the third key is not limited, and it may be, for example, an integrity key (Integrity Key, IK).

[0152] Optionally, when the first indicator is the fourth indication, the first device determines a third key for performing integrity-related processing on the NAS message.

[0153] Optionally, when the first indicator is a fifth indication, the first device determines a third key for performing integrity-related processing on the RRC message.

[0154] Optionally, when the first indicator is the sixth indication, the first device determines a third key for performing integrity-related processing on the UP message.

[0155] In some embodiments, when the first indicator is a third type identification, the first device determines a fourth key for confidentiality-related processing and integrity protection-related processing.

[0156] Optionally, the name of the fourth key is not limited, and it can be, for example, a unified key (UK).

[0157] Optionally, when the first indicator is the seventh indication, the first device determines to perform confidentiality-related processing and integrity protection-related processing on the NAS message.

[0158] Optionally, when the first indicator is the eighth indication, the first device determines to perform confidentiality-related processing and integrity protection-related processing on the RRC message.

[0159] Optionally, when the first indicator is the ninth indication, the first device determines to perform confidentiality-related processing and integrity protection-related processing on the UP message.

[0160] Optionally, when the first indicator is the tenth indication, the first device determines to perform partial confidentiality-related processing on the NAS message.

[0161] Optionally, when the first indicator is the eleventh indication, the first device determines to perform partial confidentiality-related processing on the RRC message.

[0162] Optionally, when the first indicator is the twelfth indication, the first device determines to perform partial confidentiality-related processing on the UP message.

[0163] Optionally, when the first indicator is the thirteenth indication, the first device determines to perform AE-related processing on the NAS message.

[0164] Optionally, when the first indicator is the fourteenth indication, the first device determines to perform AE-related processing on the RRC message.

[0165] Optionally, when the first indicator is the fifteenth indication, the first device determines to perform AE-related processing on the UP message.

[0166] In some embodiments, the first device determines a key for security-related processing based on the first indicator and the first parameter. Optionally, the first indicator and the first parameter are input into a key derivation function (KDF) to generate the key for security-related processing.

[0167] In some embodiments, the first parameter includes at least one of: a first key, a first length, a second indicator, and a second length.

[0168] In some embodiments, the name of the first parameter is not limited.

[0169] Optionally, the first key may be a root key or a long-term credential.

[0170] Optionally, the first key may be a 256-bit KgNB or K SN . or 256-bit K AMF wait.

[0171] For example, for the derivation of integrity and encryption keys used between the terminal and the base station, the input key shall be 256 bits KgNB / / KSN. For the derivation of integrity and encryption keys used between the terminal and the AMF, the input key shall be 256 bits K AMF .

[0172] Optionally, the first length is used to indicate the length of the first indicator. Here, the length may be the number of bits occupied.

[0173] Optionally, the second indicator is used to indicate an AE algorithm.

[0174] Optionally, the AE algorithm is an AEAD algorithm. Exemplarily, the second indicator indicates the AEAD algorithm.

[0175] Optionally, the name of the second indicator is not limited, and it can be, for example, an algorithm identity.

[0176] Exemplarily, the second indicator includes a first algorithm identifier, a second algorithm identifier, and a third algorithm identifier.

[0177] Exemplarily, the first algorithm identifier is used to indicate an AE algorithm based on Snow 5G. Exemplarily, the first algorithm identifier is used to indicate an AEAD algorithm based on Snow 5G.

[0178] Exemplarily, the second algorithm identifier is used to indicate an AE algorithm based on AES-256. Exemplarily, the second algorithm identifier is used to indicate an AEAD algorithm based on AES-256.

[0179] Exemplarily, the third algorithm identifier is used to indicate an AE algorithm based on ZUC-256. Exemplarily, the third algorithm identifier is used to indicate an AEAD algorithm based on ZUC-256.

[0180] Optionally, the second length is used to indicate the length of the second indicator.

[0181] Optionally, the names of the first indicator, the first algorithm identifier, the second algorithm identifier, the third algorithm identifier, the first length, and the second length are not limited.

[0182] Optionally, the first indicator, the first algorithm identifier, the second algorithm identifier, the third algorithm identifier, the first length, and the second length name may each be one or more bits.

[0183] In step S2102 , the first device performs security-related processing on the first information based on the key and the AE algorithm to generate second information.

[0184] In the embodiment of the present disclosure, AE may include AEAD; and the AE algorithm may include an AEAD algorithm.

[0185] Optionally, many (but not all) AE algorithm implementations allow messages to include "associated data (ADD)" that does not require encryption but only integrity protection (i.e., it is readable, but tampering with it will be detected). AE algorithms that allow associated data provide authenticated encryption features that support associated data, or such AE algorithms may be called AEAD-based algorithms.

[0186] In some embodiments, the first device performs confidentiality-related processing on the first information based on the second key and the AE algorithm to generate second information.

[0187] In some embodiments, the first device performs confidentiality-related processing on the first information based on the second key, the second parameter, and the AE algorithm to generate the second information. In this case, the first indicator is a first type identifier.

[0188] Optionally, the second parameter includes at least one of the following: a count value (Count), a bearer (Bearer) identifier, direction (Direction) information, a third length (Length-A), and a first working instruction.

[0189] Optionally, the name of the second parameter is not limited.

[0190] Optionally, the count value is used to indicate the number of times the message containing the second information is sent. Exemplarily, the count value is incremented by 1 each time the message containing the second information is sent.

[0191] Optionally, the bearer identifier is used to indicate a bearer for sending the message containing the second information. Exemplarily, when the bearer identifier has different values, it is used to indicate different bearers.

[0192] Optionally, the direction information is used to indicate whether the message containing the second information is transmitted in the uplink or in the downlink. Exemplarily, when the direction information has a first value, it is used to indicate that the message containing the second information is transmitted in the uplink; or, when the direction information has a second value, it is used to indicate that the message containing the second information is transmitted in the downlink.

[0193] Optionally, the third length is used to indicate the length of information requiring confidentiality-related processing.

[0194] Optionally, the first work instruction is used to indicate that the security-related processing is confidentiality-related processing.

[0195] Optionally, the count value, the bearer identifier, the direction information, the third length, and the name of the first work instruction are not limited.

[0196] Optionally, the count value, the bearer identifier, the direction information, the third length, and the first working indication may be one or more bits respectively.

[0197] In some embodiments, the confidentiality-related processing is an encryption operation, and the second information includes the encrypted first information.

[0198] Optionally, as shown in FIG2B , a schematic diagram of an encryption operation based on the AE algorithm is provided; the key is a second key (e.g., Knas_enc, Krrc_enc, and / or Kup_enc); an encryption operation is performed on the message (message) based on the second key (e.g., CK), a count value (Count), a bearer identifier (Bearer), direction information (Direction), a third length (Length-A), a first working instruction (e.g., WorkMode), and the AE algorithm to generate a ciphertext (OBS). Here, the message is the first information; the ciphertext is the second message, i.e., the encrypted first information. Here, Knas_enc is the key for performing confidentiality-related processing on NAS messages; Krrc_enc is the key for performing confidentiality-related processing on RRC messages; and Kup_enc is the key for performing confidentiality-related processing on UP messages.

[0199] In some embodiments, the confidentiality-related processing is a decryption operation, and the second information includes the decrypted first information.

[0200] Optionally, as shown in FIG2C , a schematic diagram of a decryption operation based on the AE algorithm is provided; the key is a second key (e.g., Knas_enc, Krrc_enc, and / or Kup_enc); a decryption operation is performed on the ciphertext (OBS) based on the second key, the count value, the bearer identifier, the direction information, the third length, the working mode (WorkMode), and the AE algorithm to generate a message. Here, the ciphertext is the first message; the message is the second message, i.e., the decrypted first message.

[0201] In some embodiments, the first device performs integrity protection-related processing on the first information based on the third key and the AE algorithm to generate second information.

[0202] In some embodiments, the first device performs integrity-related processing on the first information based on the third key, the third parameter, and the AE to generate the second information. In this case, the first indicator is a second type identifier.

[0203] Optionally, the third parameter may include at least one of the following: a random number (Fresh), a count value, a bearer identifier, direction information, a fourth length (Length-MAC), and a second working indication.

[0204] Optionally, the name of the third parameter is not limited.

[0205] Optionally, the random number may be a random number of any bits.

[0206] Optionally, the fourth length is used to indicate the length of information used for processing requiring integrity protection. Exemplarily, the fourth length may be 32 bits or 64 bits, etc. Exemplarily, the fourth length may be the length of a message authentication code (MAC). Exemplarily, the fourth length may be the length of an authentication tag.

[0207] Optionally, the second work instruction is used to indicate that the security-related processing is integrity protection-related processing.

[0208] Optionally, the count value, the bearer identifier, the direction information, the fourth length, and the name of the second work instruction are not limited.

[0209] Optionally, the random data, the count value, the bearer identifier, the direction information, the fourth length, and the second working indication may be one or more bits respectively.

[0210] In some embodiments, the second information is information used for integrity protection. For example, the second information may be a message authentication code (MAC) or an authentication tag.

[0211] Optionally, as shown in FIG2D , a schematic diagram of information generation for integrity protection based on the AE algorithm is provided; the key is a third key (Knas_int, Krrc_int, and / or Kup_int); a MAC is generated based on the third key (e.g., IK), a random number (Fresh), a count value, a bearer identifier, direction information, a fourth length (e.g., Length-MAC), a second work instruction (e.g., Length-MAC), and integrity protection of the message. Here, the message is the first information; the MAC is the second information. Here, Knas_int is the key for performing integrity protection-related processing on NAS messages; Krrc_int is the key for performing integrity protection-related processing on RRC messages; and Kup_int is the key for performing integrity protection-related processing on UP messages.

[0212] Optionally, as shown in FIG2E , a schematic diagram of message authentication using integrity protection based on the AE algorithm is provided; the key is a third key (Knas_int, Krrc_int, and / or Kup_int); based on the third key, a random number, a count value, a bearer identifier, direction information, a fourth length, a second working instruction, and integrity protection of the message, an expected MAC is generated. Here, the message is the first message, and the expected MAC is the second message.

[0213] Optionally, if the MAC in FIG. 2D is the same as the expected MAC in FIG. 2E , it is determined that the integrity check for the message passes; or, if the MAC in FIG. 2D is different from the expected MAC in FIG. 2E , it is determined that the integrity check for the message fails.

[0214] In some embodiments, the first device performs confidentiality-related processing and integrity protection-related processing on the first information based on the fourth key and the AE algorithm to generate second information.

[0215] In some embodiments, the first device performs confidentiality-related processing and integrity protection-related processing on the first information based on the fourth key, the fourth parameter, and the AE to generate the second information. In this case, the first indicator is a third-category identifier.

[0216] Optionally, the fourth parameter may include at least one of the following: a random number, a count value, a bearer identifier, direction information, a third length, a fourth length, a third work representation, and associated data.

[0217] Optionally, the name of the fourth parameter is not limited.

[0218] Optionally, the third work instruction is used to indicate that the security-related processing is confidentiality-related processing and integrity protection-related processing;

[0219] Optionally, the associated data is information used for integrity protection related processing.

[0220] Optionally, the name of the third work instruction is not limited.

[0221] Optionally, the third work indication is one or more bits.

[0222] Optionally, the associated data is attachment information, and the associated data is used for integrity-related processing.

[0223] In some embodiments, the confidentiality-related processing includes an encryption operation, and the second information includes at least one of the following: the encrypted first information, associated data, and information for integrity protection.

[0224] Optionally, as shown in Figure 2F, a schematic diagram of information generation for encryption and integrity protection based on the AE algorithm is provided; the key is a fourth key (e.g., UK); based on the fourth key, a random number, a count value, a bearer identifier, direction information, a third length, a fourth length, and a third work mode, the message and associated data are processed for confidentiality protection and / or integrity verification to generate an OBS and a MAC. Here, the message is the first information; the OBS and MAC are the second information.

[0225] In some embodiments, the confidentiality-related operation includes a decryption operation, and the second information includes at least one of the following: the decrypted first information, associated data, and information for integrity protection.

[0226] Optionally, as shown in FIG2G , a schematic diagram of information authentication for decryption and integrity protection based on the AE algorithm is provided; the key is a fourth key (e.g., a unified key); based on the fourth key, a random number, a count value, a bearer identifier, direction information, a third length, a fourth length, and a third work instruction, confidentiality protection and / or integrity verification related processing is performed on the ciphertext (OBS) and associated data to generate the ciphertext (OBS) and the expected MAC. Here, the message is the first information; the OBS and MAC are the second information.

[0227] Optionally, the information used for integrity protection is: the ciphertext of the first information and the integrity protection information related to the associated data; or, the information used for integrity protection is: the integrity protection information of the first information and the associated data.

[0228] Exemplarily, the working mode of the AE algorithm is as follows: the input is the first information and associated data, and the output is the ciphertext of the first information, the associated data, and MAC; wherein, MAC is the integrity protection information of the ciphertext of the first information and the associated data; in this way, the first information achieves confidentiality protection and integrity protection, and the associated data achieves integrity protection.

[0229] Exemplarily, the working mode of the AE algorithm is as follows: the input is the first information and associated data, and the output is the ciphertext of the first information and associated data, and MAC; wherein, MAC is the integrity protection information of the first information and associated data; in this way, the first information achieves confidentiality protection and integrity protection, and the associated data achieves confidentiality protection and integrity protection.

[0230] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codeword", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0231] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, etc.

[0232] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.

[0233] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "some", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "some A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, some A, any A, or first A, etc., but not limited to this.

[0234] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values ​​(for example, comparison with a predetermined value), but is not limited thereto.

[0235] The information processing method involved in the embodiments of the present disclosure may include at least one of steps S2101 and S2102. For example, step S2101 may be implemented as an independent embodiment; step S2102 may be implemented as an independent embodiment; or a combination of step S2101 and step S2102 may be implemented as an independent embodiment.

[0236] In some embodiments, step S2101 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0237] In some embodiments, step S2102 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0238] In the embodiments of the present disclosure, each embodiment can be implemented individually or in combination with each other, and the steps in each embodiment can be distinguished in order.

[0239] FIG2H is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG2H , the present disclosure embodiment relates to an information processing method, which is executed by a terminal and includes:

[0240] Step S2201: Determine a security-related processing key based on the first indicator.

[0241] The optional implementation of step S2201 can refer to the optional implementation of step S2101 in Figure 2A and other related parts of the embodiment involved in Figure 2A, which will not be repeated here.

[0242] In some embodiments, the AE algorithm is an AEAD algorithm. In the embodiments of the present disclosure, AE may include AEAD; the AE algorithm may include an AEAD algorithm.

[0243] In some embodiments, the first device performs security-related processing on the first information based on the key and the AE algorithm to generate the second information.

[0244] In some embodiments, determining a key for security-related processing based on a first indicator includes: determining a key for security-related processing based on the first indicator and a first parameter; wherein the first parameter includes at least one of the following: a first key; a first length, the first length is used to indicate the length of the first indicator; a second indicator, the second indicator is used to indicate the AE algorithm; and a second length, the second length is used to indicate the length of the second indicator.

[0245] In some embodiments, the second indicator includes one of the following: a first algorithm identifier, the first algorithm identifier is used to indicate an AE algorithm based on Snow 5G; a second algorithm identifier, the second algorithm identifier is used to indicate an AE algorithm based on AES-256; and a third algorithm identifier, the third algorithm identifier is used to indicate an AE algorithm based on ZUC-256.

[0246] In some embodiments, security-related processing is: confidentiality-related processing; based on a first indicator, determining a key for security-related processing, including: when the first indicator is a first type of identifier, determining a second key for confidentiality-related processing; performing security-related processing on the first information based on the key and the authenticated encryption AE algorithm to generate second information, including: performing confidentiality-related processing on the first information based on the second key and the AE algorithm to generate second information.

[0247] In some embodiments, the first type of identifier includes at least one of the following: a first indication, the first indication is used to indicate confidentiality-related processing of non-access stratum NAS messages; a second indication, the second indication is used to indicate confidentiality-related processing of radio resource control RRC messages; and a third indication, the third indication is used to indicate confidentiality-related processing of user plane UP messages.

[0248] In some embodiments, confidentiality-related processing is performed on the first information based on the second key and the AE algorithm to generate the second information, including: confidentiality-related processing is performed on the first information based on the second key, the second parameter and the AE algorithm to generate the second information; wherein the second parameter includes at least one of the following: a count value, the count value is used to indicate the number of times the message containing the second information is sent; a bearer identifier, the bearer identifier is used to indicate the bearer for sending the message containing the second information; direction information, the direction information is used to indicate whether the message containing the second information is sent to the uplink or the downlink; a third length, the third length is used to indicate the length of the information that requires confidentiality-related processing; and a first work indication, the first work indication is used to indicate that the security-related processing is confidentiality-related processing.

[0249] In some embodiments, the confidentiality-related processing is an encryption operation, and the second information includes the encrypted first information; or, the confidentiality-related processing is a decryption operation, and the second information includes the decrypted first information.

[0250] In some embodiments, the security-related processing is: integrity protection-related processing; based on the first indicator, determining the key for security-related processing, including: when the first indicator is a second-class identifier, determining the third key for integrity protection-related processing; performing security-related processing on the first information based on the key and the authenticated encryption AE algorithm to generate second information, including: performing integrity protection-related processing on the first information based on the third key and the AE algorithm to generate second information.

[0251] In some embodiments, the second type of identifier includes at least one of the following: a fourth indication, the fourth indication is used to indicate that integrity protection-related processing is performed on the NAS message; a fifth indication, the fifth indication is used to indicate that integrity protection-related processing is performed on the RRC message; and a sixth indication, the sixth indication is used to indicate that integrity protection-related processing is performed on the UP message.

[0252] In some embodiments, integrity protection-related processing is performed on the first information based on a third key and an AE algorithm to generate second information, including: integrity protection-related processing is performed on the first information based on the third key, a third parameter and AE to generate second information; wherein the third parameter includes at least one of the following: a random number; a count value, the count value is used to indicate the number of times a message containing the second information is sent; a bearer identifier, the bearer identifier is used to indicate the bearer for sending the message containing the second information; direction information, the direction information is used to indicate whether the message containing the second information is sent to the uplink or downlink; a fourth length, the fourth length is used to indicate the length of information for which integrity protection-related processing is required; and a second work indication, the second work indication is used to indicate that the security-related processing is integrity protection-related processing.

[0253] In some embodiments, the second information is information used for integrity protection.

[0254] In some embodiments, the security-related processing is confidentiality-related processing and integrity protection-related processing; based on the first indicator, determining the key for security-related processing, including: when the first indicator is a third-category identifier, determining the fourth key for confidentiality-related processing and integrity protection-related processing; performing security-related processing on the first information based on the key and the authenticated encryption AE algorithm to generate second information, including: performing confidentiality-related processing and integrity protection-related processing on the first information based on the fourth key and the AE algorithm to generate second information.

[0255] In some embodiments, the third category identifier includes at least one of the following: a seventh indication, the seventh indication is used to indicate confidentiality-related processing and integrity protection-related processing of NAS messages; an eighth indication, the eighth indication is used to indicate confidentiality-related processing and integrity protection-related processing of RRC messages; a ninth indication, the ninth indication is used to indicate confidentiality-related processing and integrity protection-related processing of UP messages; a tenth indication, the tenth indication is used to indicate partial confidentiality-related processing of NAS messages; an eleventh indication, the eleventh indication is used to indicate partial confidentiality-related processing of RRC messages; a twelfth indication, the twelfth indication is used to indicate partial confidentiality-related processing of UP messages; a thirteenth indication, the thirteenth indication is used to indicate AE-related processing of NAS messages; a fourteenth indication, the fourteenth indication is used to indicate AE-related processing of RRC messages; and a fifteenth indication, the fifteenth indication is used to indicate AE-related processing of UP messages.

[0256] In some embodiments, confidentiality-related processing and integrity protection-related processing are performed on the first information based on the fourth key and the AE algorithm to generate second information, including: confidentiality-related processing and integrity protection-related processing are performed on the first information based on the fourth key, the fourth parameter and the AE to generate the second information; wherein the fourth parameter includes at least one of the following: a random number; a count value, the count value is used to indicate the number of times a message containing the second information is sent; a bearer identifier, the bearer identifier is used to indicate the bearer for sending the message containing the second information; direction information, the direction information is used to indicate whether the message containing the second information is sent to the uplink or downlink; a third length, the third length is used to indicate the length of information that requires confidentiality-related processing; a fourth length, the fourth length is used to indicate the length of information that requires integrity protection-related processing; a third work indication, the third work indication is used to indicate that the security-related processing is confidentiality-related processing and integrity protection-related processing; and associated data, the associated data is information that is only integrity protected but not confidentiality protected.

[0257] In some embodiments, the confidentiality-related processing includes an encryption operation, and the second information includes at least one of the following: the encrypted first information, associated data, and information for integrity protection; or, the confidentiality-related operation includes a decryption operation, and the second information includes at least one of the following: the decrypted first information, associated data, and information for integrity protection.

[0258] In some embodiments, the information used for integrity protection is: the ciphertext of the first information and the integrity protection information related to the associated data; or, the information used for integrity protection is: the integrity protection information of the first information and the associated data.

[0259] In some embodiments, the first device is: a terminal, or an access network device, or a core network device.

[0260] The above embodiments may be implemented individually or in combination with each other. For optional implementations, please refer to the optional implementations of the steps in FIG. 2A , which will not be described in detail here.

[0261] FIG3 is an interactive diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG3 , the present disclosure embodiment relates to an information processing method for an information processing system 100, and the method includes:

[0262] Step S3101: The first device determines a key for security-related processing based on a first indicator.

[0263] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in Figure 2A and other related parts of the embodiment involved in Figure 2A, which will not be repeated here.

[0264] In step S3102, the first device performs security-related processing on the first information based on the key and the AE algorithm to generate second information. Here, performing security-related processing includes performing an encryption operation on the first information, generating information protected by integrity check, or performing an encryption operation and generating information protected by integrity check. The first information is plaintext, and the second information is ciphertext and / or information related to integrity protection.

[0265] The optional implementation of step S3102 can refer to the optional implementation of step S2102 in Figure 2A and other related parts of the embodiment involved in Figure 2A, which will not be repeated here.

[0266] Step S3103: The first device sends a first message carrying second information to the second device.

[0267] Optionally, the second device receives the first message sent by the first device.

[0268] Optionally, the first device is a terminal, and the second device is an access device or a core network device.

[0269] Optionally, the first device is an access network device or a core network device, and the second device is a terminal.

[0270] Step S3104: The second device determines a key for security-related processing based on the first indicator.

[0271] In step S3105 , the second device performs security-related processing on the second information based on the key and the AE algorithm to generate first information.

[0272] Here, processing the relevant security information is performing a decryption operation, integrity protection-related verification, or a decryption operation and integrity protection-related verification on the second information. The second information is ciphertext and / or integrity protection-related information, and the first information is plaintext and / or integrity protection-related information.

[0273] The optional implementation of step S3105 can refer to the optional implementation of step S2102 in Figure 2A and other related parts of the embodiment involved in Figure 2A, which will not be repeated here.

[0274] The information processing method involved in the embodiments of the present disclosure may include at least one of steps S3101 to S3105. For example, step S3101 can be implemented as an independent embodiment; step S3102 can be implemented as an independent embodiment; step S3103 can be implemented as an independent embodiment; step S3104 can be implemented as an independent embodiment; step S3105 can be implemented as an independent embodiment; step S3104 can be implemented as an independent embodiment; the combination of step S3101 and step S3102 can be implemented as an independent embodiment; the combination of step S3101, step S3102, and step S3103 can be implemented as an independent embodiment; the combination of step S3103, step S3104, and step S3105 can be implemented as an independent embodiment; the combination of step S3104 and step S3105 can be implemented as an independent embodiment; and the combination of steps S3101 to S3105 can be implemented as an independent embodiment.

[0275] In some embodiments, step S3104 and step S3105 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0276] In some embodiments, step S3101 and step S3102 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0277] In the embodiments of the present disclosure, each embodiment can be implemented individually or in combination with each other, and the steps in each embodiment can be distinguished in order.

[0278] The present disclosure relates to an information processing method, which includes:

[0279] In some embodiments, an AE algorithm is introduced into a communication system.

[0280] Option 1: The Network combined algorithm (NCA) uses one key for confidentiality protection (i.e., confidentiality-related processing) and one key for integrity protection (i.e., integrity-related processing). That is, the confidentiality key (Cipher Key, CK) is used for encryption and / or decryption operations, and the integrity key (Integrity Key, IK) is used for integrity protection-related operations.

[0281] Option 2: Using the same key (Unified Key, UK) for confidentiality and integrity protection. This means that confidentiality and integrity protection are achieved through combined calculations using NCA, that is, using one key to perform encryption or decryption calculations and integrity protection.

[0282] In some embodiments, new input parameters (e.g., operating mode) are proposed for Option 1 and Option 2 to determine which calculations will be performed using NCA. For example, when the operating mode is "0x01," it is used only for confidentiality calculations, when the operating mode is "0x10," it is used only for integrity calculations, or when the operating mode is "0x11," it is used for both confidentiality and integrity calculations. The operating mode of "0x00" may be a reserved value. Optionally, as shown in FIG4A , a relationship between an AE algorithm and input / output parameters is provided. The input parameters may be a key (Key(s)) and other parameters, and the key may be CK, IK, or UK.

[0283] In some embodiments, an input / output based on a 256-bit AE algorithm is used.

[0284] As an embodiment, CK is included in the input.

[0285] CK (i.e., Knas_enc, Krrc_enc, and / or Kup_enc) is a key used for encryption or decryption. As shown in Figure 2B, the input parameters of the AE-based algorithm are a 256-bit key named CK (i.e., Knas_enc, Krrc_enc, and / or Kup_enc), a 32-bit count value, a 5-bit bearer identifier, a 1-bit transmission direction (i.e., Direction), a 2-bit working mode (WorkMode), the required key stream length (i.e., Length-A), and the message itself. Optionally, if the transmission direction is "0", it is used to indicate uplink transmission; or, if the transmission direction is "1", it is used to indicate downlink transmission; the transmission direction is the direction information in the previous embodiment. The working mode is used to indicate that the algorithm should only perform encryption, for example, 0x01; the working mode can be the first working indication in the previous embodiment. As shown in Figure 2C, the same key stream generated with the same input parameters can be used to decrypt the message.

[0286] As an embodiment, IK is included in the input.

[0287] IK (i.e., Knas_int, Krrc_int, and / or Kup_int) is a key used for integrity protection or integrity checking. As shown in Figure 2D, the input parameters of the AE-based algorithm are a 256-bit integrity key named IK (i.e., Knas_int, Krrc_int, and / or Kup_int), a 32-bit count value, a 5-bit bearer identifier, a 1-bit transmission direction (i.e., Direction), a 2-bit operating mode (WorkMode), a 32-bit random number (Fresh), Length-MAC, and the message itself. Optionally, if the transmission direction is "0," it indicates uplink transmission; or, if the transmission direction is "1," it indicates downlink transmission; the transmission direction is the direction information in the previous embodiment. The operating mode is used to indicate that the algorithm should only perform integrity protection, for example, 0x10; this operating mode can be the second operating indication in the previous embodiment. Length-MAC is the fourth length in the previous embodiment; Length-MAC is the length of the output MAC. The 32-bit Fresh is the random number used in the integrity protection portion. As shown in Figure 2E, the input parameters of the AE-based algorithm are integrity checked using a 256-bit integrity key named IK.

[0288] Based on these input parameters, the sender calculates a 32-bit or 64-bit message authentication code (MAC) using an AE-based algorithm. The message authentication code is then appended to the message when it is sent. The receiver calculates the expected message authentication code (expected MAC) of the received message in the same way as the sender calculated the message authentication code (MAC) of the message it sent, and verifies the data integrity of the message by comparing it with the received message authentication code (i.e., MAC).

[0289] As an embodiment, the UK is included in the input.

[0290] UK (Uniform Key) is a key used for both encryption / decryption and integrity protection / integrity checking. As shown in Figure 2F, the input parameters for the AE-based algorithm are a 256-bit key named UK, a 32-bit counter, a 5-bit bearer identifier, a 1-bit transmission direction (i.e., Direction), a 2-bit operating mode (WorkMode), a 32-bit random number (Fresh), the message to be encrypted (message), Length-A, associated data (Associated Data), and Length-MAC. Optionally, if the transmission direction is "0," it indicates uplink transmission; or if the transmission direction is "1," it indicates downlink transmission; the transmission direction is the direction information in the previous embodiment. The operating mode indicates that the algorithm should only perform encryption and integrity protection, for example, 0x11; this operating mode can be the third operating mode indication in the previous embodiment. Length-MAC is the fourth length in the previous embodiment; Length-MAC is the length of the output MAC. The 32-bit Fresh is the random number used in the integrity protection portion. The associated data is the portion that requires only integrity protection. The MAC or expected MAC is generated based on the message and associated data. As shown in Figure 2G, the input parameters of the AE-based algorithm are decrypted and integrity checked using a 256-bit unified key named UK.

[0291] Based on the input parameters shown in Figure 2F or Figure 2G, the sender calculates a 32-bit or 64-bit message authentication code (MAC) using an AE-based algorithm. The MAC is then appended to the message when it is sent. The receiver calculates the expected message authentication code (expected MAC) on the OBS and the received associated data in the same way as the sender calculates the MAC on its outgoing message, and verifies the message's data integrity by comparing it with the received MAC.

[0292] In some embodiments, as shown in FIG4B , a schematic diagram of AE using message (i.e., plain text) and associated data (i.e., ADD) to generate MAC (i.e., Auth tag T) is provided. To verify the MAC, the receiver can use OBS (i.e., ciphertext) and associated data (i.e., ADD) to generate the expected MAC (i.e., AuthTag T). In FIG4B , Z (0) 、Z (1) 、Z (2) 、Z (3) 、Z (n+1) is the key stream; Plaintext1, Plaintext2, Plaintext n is the input message; Ciphertext1, Ciphertext2, Ciphertextn are the ciphertexts based on the message; MUL HIt is a mapping operation; ADD is associated data; Auth tag T is the authentication tag, that is, Auth tag T is MAC.

[0293] In some embodiments, the session key (Knas_enc or Knas_int, Krrc_enc or Krrc_int, Kup_enc or Kup_int) is derived as follows: The following parameters will be used to form the string S of the KDF:

[0294] FC=0x69;

[0295] P0 = algorithm type distinguisher;

[0296] L0 = length of algorithm type distinguisher (e.g., 0x00 or 0x01);

[0297] P1 = algorithm identity;

[0298] L1 = length of algorithm identity (eg, 0x00 or 0x01).

[0299] Optionally, the first key in the previous embodiment may also be input.

[0300] In some embodiments, for a NAS encryption or decryption algorithm, the algorithm type identifier may be N-NAS-enc-alg; for a NAS integrity protection algorithm, the algorithm type identifier may be N-NAS-int-alg. For an RRC encryption or decryption algorithm, the algorithm type identifier may be N-RRC-enc-alg; for an RRC integrity protection algorithm, the algorithm type identifier may be N-RRC-int-alg. For a UP encryption or decryption algorithm, the algorithm type identifier may be N-UP-enc-alg; for a UP integrity protection algorithm, the algorithm type identifier may be N-UP-int-alg. Specific algorithm type identifiers are shown in Table 1. Here, the values ​​0x00 and 0x07 to 0xf0 corresponding to the algorithm type identifier are reserved for future use, and the values ​​0xf1 to 0xff are reserved for private use.

[0301] Optionally, the algorithm type identifier of the NAS AE algorithm may be N-NAS-enc-inc-alg, which may be used to simultaneously perform encryption / decryption and integrity protection on NAS signaling messages.

[0302] Optionally, the algorithm type identifier of the RRC AE algorithm may be N-RRC-enc-inc-alg, which may be used to simultaneously perform encryption / decryption and integrity protection on the AS signaling message.

[0303] Optionally, for the UP AE algorithm, the algorithm type identifier may be N-UP-enc-inc-alg, which may be used to simultaneously perform encryption / decryption and integrity protection on AS user plane messages.

[0304] Optionally, as shown in Table 1 below, a relationship between an algorithm type identifier and a value is provided:

[0305] Table 1

[0306] Optionally, the algorithm identifier shall be placed in the four least significant bits of the octet. The two least significant bits of the four most significant bits are reserved for future use, and the two most significant bits of the most significant nibble are reserved for special use. All four most significant bits shall be set to all zeros.

[0307] Alternatively, if the algorithm identifier is set to N-NAS-enc-alg, N-RRC-enc-alg, or N-UP-enc-alg, and the algorithm identifier is associated with an AE-based algorithm, the generated key is set to the CK of the AE-based algorithm.

[0308] Optionally, if the algorithm identifier is set to N-NAS-int-alg, N-RRC-int-alg or N-UP-int-alg, and the algorithm identifier is related to an AE-based algorithm, the generated key is set to the IK of the AE-based algorithm.

[0309] Optionally, if the algorithm identifier is set to N-NAS-enc-inc-alg, N-RRC-enc-inc-alg, or N-NAS-enc-inc-alg, when the algorithm identifier is associated with an AE-based algorithm, the generated key is set to the UK pair key of the AE-based algorithm. A summary is shown in Table 2.

[0310] Optionally, as shown in Table 2, a summary of keys is provided.

[0311] Table 2

[0312] Alternatively, as shown in Table 3, for the AE algorithm, 256-NCA1, 256-NCA2, and 256-NAC3 may be used as algorithm identifiers.

[0313] Table 3

[0314] Optionally, for the derivation of integrity and encryption keys used between the UE (e.g., the terminal in the previous embodiment) and the gNB (e.g., the access network device in the previous embodiment), the input key should be 256-bit KgNB or KSN. For the derivation of integrity and encryption keys used between the UE and the AMF (e.g., the core network device in the previous embodiment), the input key should be 256-bit K AMF.

[0315] Optionally, for an algorithm key of length n bits, where n is less than or equal to 256, the n least significant bits of the 256 bits output by the KDF are used as the algorithm key.

[0316] In some embodiments, if CK is included in the input of the AE algorithm, the input may be as shown in Table 4.

[0317] Table 4

[0318] If CK is included in the input, the output is shown in Table 5.

[0319] Table 5

[0320] In some embodiments, if IK is included in the input of the AE algorithm, the input may be as shown in Table 6.

[0321] Table 6

[0322] If IK is included in the input, the output is shown in Table 7.

[0323] Table 7

[0324] In some embodiments, if UK is included in the input of the AE algorithm, the input may be as shown in Table 8.

[0325] Table 8

[0326] If UK is included in the input, the output is shown in Table 9.

[0327] Table 9

[0328] In some embodiments, it is directed to UE or access network equipment (e.g., NG-RAN) or mobility management related functions (e.g., AMF).

[0329] Optionally, the UE / access network device / mobility management related functions should be able to generate inputs for the AE algorithm in the previous embodiment.

[0330] Optionally, when the algorithm type identifier is set to N-NAS-enc-alg, N-RRC-inc-alg or N-UP-inc-alg and the algorithm identifier is related to an AE-based algorithm, the UE or access network device or mobility management related function should be able to generate CK for the AE algorithm.

[0331] Optionally, when the algorithm type identifier is set to N-NAS-int-alg, N-RRC-int-alg or N-UP-int-alg and the algorithm identifier is related to an AE-based algorithm, the UE or access network device or mobility management related function should be able to generate an IK for the AE algorithm.

[0332] Optionally, when the algorithm type identifier is set to N-NAS-enc-inc-alg, N-RRC-enc-inc-alg or N-NAS-enc-inc-alg and the algorithm identifier is related to an AE-based algorithm, the UE or access network equipment or mobility management related functions should be able to generate a UK for the AE algorithm.

[0333] Optionally, the algorithm type identifier may be the first indicator in the previous embodiment.

[0334] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, and may also be arbitrarily combined with the optional implementations of other embodiments.

[0335] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0336] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), and the functions of some or all of the above units or modules are realized by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0337] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit, and the logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by a processor as an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0338] Figure 5 is a structural diagram of the first device 5100 provided by an embodiment of the present disclosure. As shown in Figure 5, the first device 5100 includes: a processing module 5101. In some embodiments, the processing module 5101 is used to determine the key; based on the key and AE, security-related processing is performed on the first information to generate the second information. Optionally, the above-mentioned processing module 5101 is used to execute at least one of the processing steps (such as step S2101 and / or step S2102, but not limited to these) performed by the first device in any of the above methods, which will not be repeated here. In some embodiments, the first device 5100 may also include a transceiver module for sending a message including the second information. Optionally, the above-mentioned transceiver module is used to execute at least one of the receiving and / or sending steps performed by the first device in any of the above methods, which will not be repeated here.

[0339] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module. The transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module and the transceiver may be interchangeable. Exemplarily, the first transceiver module includes a first transmitting module and / or a first receiving module. Exemplarily, the second transceiver module includes a second transmitting module and / or a second receiving module.

[0340] In some embodiments, the processing module can be a single module or can include multiple submodules. Optionally, the multiple submodules respectively execute all or part of the steps required to be executed by the processing module. Optionally, the processing module can be interchangeable with the processor.

[0341] Figure 6A is a schematic diagram of the structure of a communication device 6100 proposed in an embodiment of the present disclosure. Communication device 6100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal, etc., or a chip, chip system, or processor that supports a network device in implementing any of the above methods. It can also be a chip, chip system, or processor that supports a terminal in implementing any of the above methods. Communication device 6100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0342] As shown in Figure 6A, the communication device 6100 includes one or more processors 6101. The processor 6101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process the communication protocol and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. Optionally, the communication device 6100 is used to perform any of the above methods. Optionally, one or more processors 6101 are used to call instructions to enable the communication device 6100 to perform any of the above methods.

[0343] In some embodiments, the communication device 6100 further includes one or more transceivers 6102. When the communication device 6100 includes one or more transceivers 6102, the transceiver 6102 performs at least one of the communication steps of sending and / or receiving in the above method, and the processor 6101 performs at least one of the other steps (such as steps S2101 and / or step S2102, but not limited thereto). In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface may be interchangeable, the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be interchangeable, and the terms receiver, receiving unit, receiver, and receiving circuit may be interchangeable.

[0344] In some embodiments, the communication device 6100 further includes one or more memories 6103 for storing data. Alternatively, all or part of the memories 6103 may be located outside the communication device 6100. In alternative embodiments, the communication device 6100 may include one or more interface circuits 6104. Optionally, the interface circuits 6104 are connected to the memories 6103 and may be configured to receive data from the memories 6103 or other devices, or to send data to the memories 6103 or other devices. For example, the interface circuits 6104 may read data stored in the memories 6103 and send the data to the processor 6101.

[0345] The communication device 6100 described in the above embodiment may be a network device or a terminal, but the scope of the communication device 6100 described in the present disclosure is not limited thereto, and the structure of the communication device 6100 may not be limited to FIG6A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: (1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0346] 6B is a schematic diagram of the structure of a chip 6200 according to an embodiment of the present disclosure. If the communication device 6100 can be a chip or a chip system, reference can be made to the schematic diagram of the structure of the chip 6200 shown in FIG6B , but the present disclosure is not limited thereto.

[0347] The chip 6200 includes one or more processors 6201. The chip 6200 is configured to execute any of the above methods.

[0348] In some embodiments, chip 6200 further includes one or more interface circuits 6202. Terms such as interface circuit, interface, and transceiver pins may be used interchangeably. In some embodiments, chip 6200 further includes one or more memories 6203 for storing data. Alternatively, all or part of memory 6203 may be located external to chip 6200. Optionally, interface circuit 6202 is connected to memory 6203 and may be used to receive data from memory 6203 or other devices, or may be used to send data to memory 6203 or other devices. For example, interface circuit 6202 may read data stored in memory 6203 and send the data to processor 6201.

[0349] In some embodiments, the interface circuit 6202 performs at least one of the communication steps, such as sending and / or receiving, in the above-described method. For example, the interface circuit 6202 performing the communication steps, such as sending and / or receiving, in the above-described method means that the interface circuit 6202 performs data exchange between the processor 6201, the chip 6200, the memory 6203, or the transceiver device. In some embodiments, the processor 6201 performs at least one of the other steps (such as, but not limited to, steps S2101 and / or S2102).

[0350] The modules and / or devices described in various embodiments, such as virtual devices, physical devices, and chips, can be arbitrarily combined or separated according to circumstances. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0351] The present disclosure also proposes a storage medium having instructions stored thereon. When the instructions are executed on the communication device 6100, the communication device 6100 executes any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto and may also be a transient storage medium.

[0352] The present disclosure also provides a program product, which, when executed by the communication device 6100, enables the communication device 6100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0353] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.

Claims

1. An information processing method, characterized in that: Executed by a first device, including: determining a key for security-related processing based on the first indicator; The security-related processing is performed on the first information based on the key and the authenticated encryption (AE) algorithm to generate second information.

2. The method according to claim 1, characterized in that The AE algorithm is an AEAD algorithm with authenticated encryption of associated data.

3. The method according to claim 1 or 2, characterized in that The determining, based on the first indicator, a key for security-related processing, comprises: Determining the key for the security-related processing based on the first indicator and a first parameter; wherein the first parameter includes at least one of the following: First key; a first length, where the first length is used to indicate a length of the first indicator; a second indicator, wherein the second indicator is used to indicate the AE algorithm; A second length is used to indicate a length of the second indicator.

4. The method according to claim 3, characterized in that The second indicator includes one of the following: A first algorithm identifier, where the first algorithm identifier is used to indicate an AE algorithm based on Snow 5G; A second algorithm identifier, where the second algorithm identifier is used to indicate an AE algorithm based on AES-256; A third algorithm identifier is used to indicate an AE algorithm based on ZUC-256.

5. The method according to any one of claims 1 to 4, characterized in that The security-related processing is: confidentiality-related processing; The determining, based on the first indicator, a key for security-related processing includes: determining a second key for confidentiality-related processing when the first indicator is a first-category identifier; The performing security-related processing on the first information based on the key and the authenticated encryption AE algorithm to generate the second information includes: performing confidentiality-related processing on the first information based on the second key and the AE algorithm to generate the second information.

6. The method according to claim 5, characterized in that The first type of identification includes at least one of the following: A first indication, where the first indication is used to instruct confidentiality-related processing to be performed on a non-access stratum (NAS) message; A second indication, where the second indication is used to instruct confidentiality-related processing to be performed on a radio resource control RRC message; The third indication is used to instruct confidentiality-related processing to be performed on the user plane UP message.

7. The method according to claim 5 or 6, characterized in that The performing confidentiality-related processing on the first information based on the second key and the AE algorithm to generate the second information includes: Perform confidentiality-related processing on the first information based on the second key, the second parameter, and the AE algorithm to generate the second information; wherein the second parameter includes at least one of the following: a count value, where the count value indicates the number of times a message including the second information is sent; a bearer identifier, where the bearer identifier is used to indicate a bearer for sending a message including the second information; Direction information, where the direction information is used to indicate whether the message containing the second information is sent for uplink transmission or downlink transmission; a third length, where the third length is used to indicate the length of information requiring confidentiality-related processing; A first work instruction is used to indicate that the security-related processing is confidentiality-related processing.

8. The method according to any one of claims 5 to 7, characterized in that The confidentiality-related processing is an encryption operation, and the second information includes the encrypted first information; or, The confidentiality-related processing is a decryption operation, and the second information includes the decrypted first information.

9. The method according to any one of claims 1 to 4, characterized in that The security-related processing is: integrity protection-related processing; The determining, based on the first indicator, a key for security-related processing includes: determining a third key for integrity protection-related processing when the first indicator is a second-type identifier; The performing security-related processing on the first information based on the key and the authenticated encryption AE algorithm to generate the second information includes: performing integrity protection-related processing on the first information based on the third key and the AE algorithm to generate the second information.

10. The method according to claim 9, characterized in that The second type of identification includes at least one of the following: A fourth indication, where the fourth indication is used to instruct to perform integrity protection-related processing on the NAS message; A fifth indication, wherein the fifth indication is used to instruct to perform integrity protection-related processing on the RRC message; The sixth indication is used to instruct to perform integrity protection-related processing on the UP message.

11. The method according to claim 9 or 10, characterized in that The performing integrity protection-related processing on the first information based on the third key and the AE algorithm to generate the second information includes: Performing integrity-related processing on the first information based on the third key, the third parameter, and the AE to generate the second information; wherein the third parameter includes at least one of the following: Random numbers; a count value, where the count value indicates the number of times a message including the second information is sent; a bearer identifier, where the bearer identifier is used to indicate a bearer for sending a message including the second information; Direction information, where the direction information is used to indicate whether the message containing the second information is sent for uplink transmission or downlink transmission; a fourth length, where the fourth length is used to indicate the length of information used for processing requiring integrity protection; The second work instruction is used to indicate that the security-related processing is integrity protection-related processing.

12. The method according to any one of claims 9 to 11, characterized in that The second information is information used for integrity protection.

13. The method according to any one of claims 1 to 4, characterized in that The security-related processing refers to confidentiality-related processing and integrity protection-related processing; The determining, based on the first indicator, a key for security-related processing includes: when the first indicator is a third-category identifier, determining a fourth key for confidentiality-related processing and integrity protection-related processing; The security-related processing of the first information based on the key and the authenticated encryption AE algorithm to generate the second information includes: performing confidentiality-related processing and integrity protection-related processing on the first information based on the fourth key and the AE algorithm to generate the second information.

14. The method according to claim 13, wherein: The third category of identification includes at least one of the following: a seventh indication, the seventh indication being used to instruct confidentiality-related processing and integrity protection-related processing to be performed on the NAS message; An eighth indication, wherein the eighth indication is used to instruct confidentiality-related processing and integrity protection-related processing to be performed on the RRC message; A ninth indication, wherein the ninth indication is used to instruct confidentiality-related processing and integrity protection-related processing to be performed on the UP message; a tenth indication, the tenth indication being used to instruct partial confidentiality-related processing to be performed on the NAS message; An eleventh indication, the eleventh indication being used to instruct partial confidentiality-related processing to be performed on the RRC message; A twelfth indication is used to instruct to perform partial confidentiality-related processing on the UP message; A thirteenth indication is used to instruct to perform AE-related processing on the NAS message; A fourteenth indication, the fourteenth indication is used to instruct to perform AE-related processing on the RRC message; The fifteenth indication is used to instruct to perform AE-related processing on the UP message.

15. The method according to claim 13 or 14, characterized in that The performing confidentiality-related processing and integrity protection-related processing on the first information based on the fourth key and the AE algorithm to generate the second information includes: Perform confidentiality-related processing and integrity protection-related processing on the first information based on the fourth key, the fourth parameter, and the AE to generate the second information; wherein the fourth parameter includes at least one of the following: Random numbers; a count value, where the count value indicates the number of times a message including the second information is sent; a bearer identifier, where the bearer identifier is used to indicate a bearer for sending a message including the second information; Direction information, where the direction information is used to indicate whether the message containing the second information is sent for uplink transmission or downlink transmission; a third length, where the third length is used to indicate the length of information requiring confidentiality-related processing; a fourth length, where the fourth length is used to indicate the length of information requiring integrity protection related processing; a third work instruction, where the third work instruction is used to indicate that the security-related processing is confidentiality-related processing and integrity protection-related processing; The associated data is used for integrity protection of related processing information.

16. The method according to any one of claims 13 to 15, characterized in that The confidentiality-related processing includes an encryption operation, and the second information includes at least one of the following: the encrypted first information, associated data, and information for integrity protection; or, The confidentiality-related operation includes a decryption operation, and the second information includes at least one of the following: the decrypted first information, associated data, and information for integrity protection.

17. The method according to claim 16, characterized in that The information used for integrity protection is: the ciphertext of the first information and the integrity protection information related to the associated data; or, The information used for integrity protection is: the integrity protection information of the first information and the associated data.

18. A communication device, characterized in that: include: a processing module configured to determine a key for security-related processing based on the first indicator; The processing module is configured to perform the security-related processing on the first information based on the key and the authenticated encryption (AE) algorithm to generate second information.

19. A communication device, characterized in that: include: one or more processors; The communication device is used to execute the information processing method according to any one of claims 1 to 17.

20. A storage medium storing instructions, characterized in that: When the instruction is executed on a communication device, the communication device is caused to execute the information processing method according to any one of claims 1 to 17.

21. A computer program product, comprising a computer program or instructions, characterized in that: When the computer program or instruction is executed by a processor, the information processing method according to any one of claims 1 to 17 is implemented.

Citation Information

Patent Citations

  • Content security at service layer

    CN107852405A

  • Stateless access stratum security for cellular internet of things

    CN108432206A

  • Communication method and device

    CN113455032A

  • Information processing method and device and storage medium

    CN117322027A

  • Low-cost and high-reliability vehicle-mounted CAN bus safety communication method and safety communication system

    CN117395003A